← All CFP Flashcard Decks

Open Banking & API Integration Flashcards

7 cards from real CFP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Open Banking & API Integration flashcards as text
  1. Why is 'screen scraping' controversial in the context of financial data access?

    Answer: It accesses bank portals by simulating user logins, bypassing security controls and posing data privacy risks

    Screen scraping accesses financial data by mimicking user credentials on bank portals, bypassing official APIs and security controls, which creates significant data privacy and security risks.

  2. What is the Financial Data Exchange (FDX) in the context of US open banking?

    Answer: An industry-led nonprofit consortium that develops standardized APIs for secure financial data sharing

    FDX is a nonprofit, industry-led consortium that develops and promotes standardized, secure APIs (based on the FDX API standard) to enable financial data sharing in the US without relying on screen scraping.

  3. Which security protocol is required to protect data in transit between open banking APIs and third-party providers?

    Answer: TLS 1.2 or higher (preferably TLS 1.3)

    TLS 1.2 or higher (with TLS 1.3 preferred) is required to encrypt data in transit between open banking APIs and third-party applications, ensuring confidentiality and integrity of financial data.

  4. In open banking, what is the purpose of a 'sandbox environment' provided by banks or open banking platforms?

    Answer: A testing environment where developers can integrate and validate APIs using mock data without accessing real customer accounts

    A sandbox environment provides developers with an isolated, safe testing space using mock data, allowing them to build and validate API integrations before accessing live production systems with real customer data.

  5. What is 'Banking as a Service' (BaaS) and how does it leverage open banking principles?

    Answer: A model where banks expose their regulated infrastructure and financial services via APIs to enable non-bank businesses to embed banking capabilities

    BaaS enables non-bank companies (e.g., fintechs, retailers) to embed banking services like accounts, payments, and lending into their own products by accessing bank infrastructure through APIs, extending open banking to full-service provision.

  6. Which of the following best describes 'tokenization' as applied in open banking security?

    Answer: Replacing sensitive financial data with non-sensitive surrogate tokens that map back to the original data in a secure vault

    Tokenization replaces sensitive data such as account numbers or card details with unique, non-sensitive tokens, reducing exposure of sensitive financial data while preserving system functionality.

  7. What does 'Strong Customer Authentication' (SCA) require under PSD2?

    Answer: Authentication using at least two independent factors from knowledge, possession, and inherence categories

    SCA under PSD2 mandates multi-factor authentication using at least two of three factor types—knowledge (PIN/password), possession (device/token), and inherence (biometrics)—to enhance the security of electronic payments.