← All CFA Flashcard Decks

Digital Fraud & Account Takeover Flashcards

7 cards from real CFA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Digital Fraud & Account Takeover flashcards as text
  1. A telecom company's customer service representative is convinced by a caller to transfer a phone number to a new SIM without proper verification. The fraud examiner should classify this as:

    Answer: Social engineering-enabled SIM swap

    Social engineering-enabled SIM swapping occurs when fraudsters manipulate telecom employees into porting a victim's number without proper authentication.

  2. Which digital fraud scheme involves creating fictitious vendor accounts in an organization's ERP system to redirect payments?

    Answer: Ghost vendor fraud

    Ghost vendor fraud involves creating fake supplier records in an accounting or ERP system to generate fraudulent payments to attacker-controlled accounts.

  3. An investigator finds that a fraudster used a valid employee's VPN credentials from a foreign IP address during off-hours to exfiltrate data. The MOST important log source to review first is:

    Answer: VPN authentication and session logs

    VPN authentication logs will show the IP geolocation, login timestamp, and session duration, directly confirming the unauthorized access event.

  4. Under the FTC's Red Flags Rule, which of the following is an example of a covered 'red flag' for identity theft?

    Answer: An alert from a consumer reporting agency about fraud on the account

    The FTC Red Flags Rule requires covered entities to respond to alerts from consumer reporting agencies indicating fraud or active duty alerts as identity theft red flags.

  5. What distinguishes 'friendly fraud' (first-party fraud) from third-party account takeover fraud?

    Answer: In friendly fraud, the legitimate account holder commits the fraud themselves

    Friendly fraud occurs when the true account owner makes a purchase and then falsely disputes the charge, unlike ATO where an unauthorized third party accesses the account.

  6. A fraud analyst is reviewing bot traffic that bypasses CAPTCHA to create accounts. The most effective countermeasure beyond CAPTCHA is:

    Answer: Device fingerprinting combined with behavioral analysis during registration

    Combining device fingerprinting with behavioral analysis (e.g., mouse movement, typing cadence) during registration detects automated bots that solve CAPTCHAs.

  7. A fraudster calls a bank's IVR system and uses the victim's Social Security Number and date of birth to reset the account PIN. What control failure does this represent?

    Answer: Lack of multi-factor authentication on the IVR channel

    Relying solely on static data (SSN, DOB) for IVR authentication lacks a second factor, making it vulnerable to social engineering and data breach exploitation.