CFS Cheat Sheet 2026
The 30 highest-yield CFS facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
150 questions
180 min time limit
75% to pass
- A company requires that journal entries above $10,000 be approved by the CFO. This control is best classified as: → Preventive control
- Multi-factor authentication (MFA) reduces identity theft risk primarily by: → Requiring attackers to compromise multiple independent verification factors
- Which control is most effective at preventing a single employee from executing a billing scheme undetected? → Segregating duties so that no single employee can both add vendors and approve payments
- In a jury trial, the fraud examiner is presenting a chart showing a complex embezzlement scheme. The most effective presentation technique is to: → Build the chart incrementally, explaining each layer before adding the next
- In a lapping scheme, a fraudster covers a misappropriated payment from Customer A by applying a later payment from which source? → Customer B's subsequent payment
- Which regulatory body oversees securities markets in the U.S.? → Securities and Exchange Commission (SEC).
- A fraud examiner is testifying about a Ponzi scheme. The most persuasive way to explain the scheme's mechanics to jurors is to: → Use a simple visual showing money flowing from new investors to pay old investors
- Healthcare fraud committed by a provider billing Medicare for services never rendered is an example of: → Phantom billing
- In digital forensics, 'write blockers' are used to: → Prevent any writes to the evidence drive during acquisition, preserving its integrity
- Which indicator is a classic red flag for a billing scheme involving fictitious vendors? → Vendors with physical addresses matching employee addresses
- A 'lapping' scheme is most likely to be detected by: → Comparing customer account balances to statements and confirming directly with customers
- A company implements mandatory job rotation for employees who handle cash. This control primarily addresses which fraud risk factor? → Opportunity
- Which governance practice helps prevent a single individual from committing and concealing fraud? → Job rotation and mandatory vacations
- Check kiting exploits which banking vulnerability? → The float period between check deposit and fund clearance
- According to ACFE research, what is the most common initial detection method for occupational fraud, including asset misappropriation? → A tip from an employee or other informant
- Which technique is most effective in preventing fraudulent financial reporting? → Implementing strong corporate governance and oversight.
- Under SOX Section 404, management is required to: → Assess and report on the effectiveness of internal controls over financial reporting
- The COSO framework's control environment component most directly supports fraud prevention by: → Establishing the ethical foundation and governance structures of the organization
- What is a key principle of witness interviewing techniques in Certified Fraud Specialist practice? → Applying structured methodologies based on evidence and best practices
- Which concept describes the risk that remains after management has implemented controls to reduce inherent risk? → Residual risk
- Management override of internal controls is considered particularly dangerous because: → Controls cannot detect or prevent actions by those who designed them
- A ghost employee scheme is most effectively prevented by which control? → Periodic physical verification of employees matched to payroll records
- Which fraud risk is heightened when a company has a dominant CEO who overrides controls without challenge? → Management override
- Which quantitative method is used to estimate the expected loss from a fraud risk by combining its likelihood and impact? → Expected value calculation (probability × impact)
- Which analytical technique flags transactions that fall just below an approval threshold repeatedly? → Threshold circumvention detection
- What is the primary purpose of a hotline as an anti-fraud control? → Provide anonymous tips about suspected misconduct
- Continuous monitoring differs from periodic auditing primarily because it: → Detects anomalies in real time as transactions occur
- The term 'spoliation of evidence' in a fraud investigation refers to: → The intentional or negligent destruction, alteration, or concealment of evidence
- When implementing expert testimony & court presentation practices, what should CFS professionals prioritize? → Alignment with professional standards, stakeholder needs, and organizational goals
- What is a key principle of insurance fraud investigation in Certified Fraud Specialist practice? → Applying structured methodologies based on evidence and best practices
Turn these facts into recall:
Was this helpful?