← All CFA Flashcard Decks

Digital Fraud & Account Takeover Flashcards

7 cards from real CFA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Digital Fraud & Account Takeover flashcards as text
  1. Which technique do fraudsters use to test whether a stolen card number is valid by making small, low-risk online purchases?

    Answer: Carding or card testing

    Card testing (carding) involves making small transactions to verify stolen card details are active before committing larger fraudulent purchases.

  2. A company finds that fraudsters used legitimate employee credentials obtained through a spear phishing email to access payroll systems. The FIRST recommended containment step is:

    Answer: Force a password reset and revoke all active sessions for compromised accounts

    Forcing a password reset and invalidating active sessions immediately terminates the fraudster's unauthorized access before further damage occurs.

  3. In the context of ATO fraud, what is 'account enumeration'?

    Answer: Probing a login page to discover valid usernames

    Account enumeration exploits different error messages on login pages (e.g., 'user not found' vs. 'wrong password') to identify valid usernames.

  4. Which type of fraud involves using a legitimate user's session token after they have authenticated, without needing their password?

    Answer: Session hijacking

    Session hijacking involves stealing a valid session token (via XSS, network sniffing, or cookie theft) to impersonate an authenticated user.

  5. A fraud examiner investigating a cryptocurrency exchange ATO finds transactions routed through multiple wallets rapidly. This technique is called:

    Answer: Layering via crypto mixing

    Crypto mixing (or tumbling) routes funds through multiple wallets and transactions to obscure the origin of stolen funds and hinder tracing.

  6. Which of the following is the STRONGEST authentication control against SIM swap-based account takeover?

    Answer: FIDO2 hardware security key

    FIDO2 hardware security keys are bound to the physical device and domain, making them immune to SIM swapping and phishing attacks.

  7. A bank's fraud team identifies a pattern where compromised accounts always have their mailing address changed 48 hours before a check order. This is an example of:

    Answer: A fraud precursor pattern

    Fraud precursor patterns are sequences of low-risk events that consistently precede a fraudulent act, used to build predictive detection rules.