Digital Fraud & Account Takeover Flashcards
7 cards from real CFA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Digital Fraud & Account Takeover flashcards as text
Which technique do fraudsters use to test whether a stolen card number is valid by making small, low-risk online purchases?
Answer: Carding or card testing
Card testing (carding) involves making small transactions to verify stolen card details are active before committing larger fraudulent purchases.
A company finds that fraudsters used legitimate employee credentials obtained through a spear phishing email to access payroll systems. The FIRST recommended containment step is:
Answer: Force a password reset and revoke all active sessions for compromised accounts
Forcing a password reset and invalidating active sessions immediately terminates the fraudster's unauthorized access before further damage occurs.
In the context of ATO fraud, what is 'account enumeration'?
Answer: Probing a login page to discover valid usernames
Account enumeration exploits different error messages on login pages (e.g., 'user not found' vs. 'wrong password') to identify valid usernames.
Which type of fraud involves using a legitimate user's session token after they have authenticated, without needing their password?
Answer: Session hijacking
Session hijacking involves stealing a valid session token (via XSS, network sniffing, or cookie theft) to impersonate an authenticated user.
A fraud examiner investigating a cryptocurrency exchange ATO finds transactions routed through multiple wallets rapidly. This technique is called:
Answer: Layering via crypto mixing
Crypto mixing (or tumbling) routes funds through multiple wallets and transactions to obscure the origin of stolen funds and hinder tracing.
Which of the following is the STRONGEST authentication control against SIM swap-based account takeover?
Answer: FIDO2 hardware security key
FIDO2 hardware security keys are bound to the physical device and domain, making them immune to SIM swapping and phishing attacks.
A bank's fraud team identifies a pattern where compromised accounts always have their mailing address changed 48 hours before a check order. This is an example of:
Answer: A fraud precursor pattern
Fraud precursor patterns are sequences of low-risk events that consistently precede a fraudulent act, used to build predictive detection rules.