โ† All CFP Flashcard Decks

Digital Payments & Financial Services Flashcards

7 cards from real CFP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Digital Payments & Financial Services flashcards as text
  1. Which technology allows a mobile device to emulate a physical payment card by storing credentials in a secure element or cloud?

    Answer: Host Card Emulation (HCE)

    Host Card Emulation (HCE) lets Android devices emulate NFC payment cards without a hardware secure element, using cloud-based credentials.

  2. A BNPL (Buy Now Pay Later) provider must be most cautious about which regulatory risk when offering credit to consumers?

    Answer: Truth in Lending Act (TILA) / Regulation Z disclosure requirements

    BNPL products may qualify as credit under TILA/Reg Z, requiring clear APR disclosures; regulators have increased scrutiny on BNPL for compliance gaps.

  3. In the context of payment fraud, what is 'synthetic identity fraud'?

    Answer: Combining real and fictitious information to create a new identity

    Synthetic identity fraud involves blending real data (like an SSN) with fabricated details to create a fake but plausible identity used to obtain credit.

  4. What is the primary purpose of a payment orchestration layer in a merchant's technology stack?

    Answer: To route transactions across multiple PSPs and acquirers for optimization

    Payment orchestration platforms sit above PSPs, intelligently routing transactions to optimize for authorization rates, cost, and redundancy across multiple processors.

  5. Which financial crime typology is most directly countered by transaction monitoring systems in digital payment platforms?

    Answer: Money laundering via structuring (smurfing)

    Transaction monitoring systems are designed to detect structuring (breaking large cash amounts into smaller transactions to evade BSA reporting thresholds).

  6. A digital wallet provider stores payment credentials on behalf of users. Under PCI DSS, what is this provider classified as?

    Answer: Service Provider

    Entities that store, process, or transmit cardholder data on behalf of others are classified as service providers under PCI DSS and must comply accordingly.

  7. What distinguishes a 'push payment' from a 'pull payment' in digital financial services?

    Answer: Push payments are initiated by the payer; pull payments are initiated by the payee

    In push payments the sender initiates the transfer (e.g., wire transfer, Zelle), while in pull payments the recipient requests funds from the payer's account (e.g., direct debit).