CFP Digital Payments & Financial Services 3 — Questions and Answers
Question 1: Which technology allows a mobile device to emulate a physical payment card by storing credentials in a secure element or cloud?
- QR code payments
- Host Card Emulation (HCE) (Correct answer)
- Dynamic CVV
- Tokenization vault
Correct answer: Host Card Emulation (HCE)
Host Card Emulation (HCE) lets Android devices emulate NFC payment cards without a hardware secure element, using cloud-based credentials.
Question 2: A BNPL (Buy Now Pay Later) provider must be most cautious about which regulatory risk when offering credit to consumers?
- PCI DSS non-compliance
- Truth in Lending Act (TILA) / Regulation Z disclosure requirements (Correct answer)
- Bank Secrecy Act reporting thresholds
- NACHA operating rules violations
Correct answer: Truth in Lending Act (TILA) / Regulation Z disclosure requirements
BNPL products may qualify as credit under TILA/Reg Z, requiring clear APR disclosures; regulators have increased scrutiny on BNPL for compliance gaps.
Question 3: In the context of payment fraud, what is 'synthetic identity fraud'?
- Using stolen physical cards at POS terminals
- Combining real and fictitious information to create a new identity (Correct answer)
- Cloning a merchant's payment gateway credentials
- Intercepting NFC signals to copy card data
Correct answer: Combining real and fictitious information to create a new identity
Synthetic identity fraud involves blending real data (like an SSN) with fabricated details to create a fake but plausible identity used to obtain credit.
Question 4: What is the primary purpose of a payment orchestration layer in a merchant's technology stack?
- To encrypt card data at the point of entry
- To route transactions across multiple PSPs and acquirers for optimization (Correct answer)
- To generate fraud scores using ML models
- To manage chargebacks and dispute resolution
Correct answer: To route transactions across multiple PSPs and acquirers for optimization
Payment orchestration platforms sit above PSPs, intelligently routing transactions to optimize for authorization rates, cost, and redundancy across multiple processors.
Question 5: Which financial crime typology is most directly countered by transaction monitoring systems in digital payment platforms?
- Tax evasion
- Money laundering via structuring (smurfing) (Correct answer)
- Insider trading
- Securities fraud
Correct answer: Money laundering via structuring (smurfing)
Transaction monitoring systems are designed to detect structuring (breaking large cash amounts into smaller transactions to evade BSA reporting thresholds).
Question 6: A digital wallet provider stores payment credentials on behalf of users. Under PCI DSS, what is this provider classified as?
- Level 1 merchant
- Service Provider (Correct answer)
- Acquiring Bank
- Payment Facilitator
Correct answer: Service Provider
Entities that store, process, or transmit cardholder data on behalf of others are classified as service providers under PCI DSS and must comply accordingly.
Question 7: What distinguishes a 'push payment' from a 'pull payment' in digital financial services?
- Push payments are initiated by the payer; pull payments are initiated by the payee (Correct answer)
- Push payments require a bank account; pull payments use cards only
- Push payments are always real-time; pull payments are always batch
- Push payments cannot be reversed; pull payments always can
Correct answer: Push payments are initiated by the payer; pull payments are initiated by the payee
In push payments the sender initiates the transfer (e.g., wire transfer, Zelle), while in pull payments the recipient requests funds from the payer's account (e.g., direct debit).
Which technology allows a mobile device to emulate a physical payment card by storing credentials in a secure element or cloud?