CTP Payment Systems and Technology 4 — Questions and Answers
Question 1: A positive pay service is designed to protect against which specific type of payment fraud?
- ACH unauthorized debits
- Check fraud through altered payee or amount (Correct answer)
- Wire transfer business email compromise
- Card-not-present e-commerce fraud
Correct answer: Check fraud through altered payee or amount
Positive pay matches checks presented for payment against an issued-check file; any discrepancy in payee or amount triggers a pay/no-pay decision.
Question 2: ACH debit blocks and debit filters are bank services that primarily protect against:
- Duplicate wire transfers
- Unauthorized ACH debits initiated by external parties (Correct answer)
- Fraudulent checks drawn on the account
- Excess wire transfer fees
Correct answer: Unauthorized ACH debits initiated by external parties
ACH debit blocks reject all ACH debits from the account, while filters allow only pre-authorized company IDs to debit, preventing unauthorized pulls.
Question 3: Business email compromise (BEC) most commonly targets which payment type in corporate treasury?
- ACH payroll credits
- Outbound wire transfers by tricking employees into changing payment instructions (Correct answer)
- Card payments to vendors
- Check payments under $10,000
Correct answer: Outbound wire transfers by tricking employees into changing payment instructions
BEC fraud typically involves fraudsters impersonating executives or vendors via email to redirect large outbound wire transfers to fraudulent accounts.
Question 4: Under Regulation E, which account type receives the strongest consumer protections for unauthorized electronic fund transfers?
- Corporate checking accounts
- Consumer deposit accounts (Correct answer)
- Money market accounts held by corporations
- Brokerage sweep accounts
Correct answer: Consumer deposit accounts
Regulation E applies exclusively to consumer accounts, providing strict liability limits and dispute rights not available to commercial account holders.
Question 5: The dual-control requirement in payment processing means:
- Two banks must approve every wire transfer
- One person initiates the payment and a different person authorizes it before release (Correct answer)
- All payments must be reviewed by the CFO and treasurer
- Payments must be confirmed via both email and phone
Correct answer: One person initiates the payment and a different person authorizes it before release
Dual control (segregation of duties) requires separate individuals to initiate and approve payments, preventing a single fraudster or error from executing unauthorized transfers.
Question 6: Which payment fraud scheme involves creating fake vendor records in the AP system to divert payments to fraudster-controlled accounts?
- Check kiting
- Vendor master file fraud (Correct answer)
- Positive pay bypass
- ACH return fraud
Correct answer: Vendor master file fraud
Vendor master file fraud exploits weak controls over vendor setup to insert fraudulent bank account details, redirecting legitimate payments to the fraudster.
Question 7: What is the primary treasury risk associated with using paper checks compared to electronic payments?
- Higher Federal Reserve processing fees
- Extended float, physical alteration risk, and longer return/dispute timelines (Correct answer)
- Inability to include remittance information
- Requirement for SWIFT codes
Correct answer: Extended float, physical alteration risk, and longer return/dispute timelines
Paper checks create disbursement float, can be physically altered or forged, and take longer to detect and dispute than electronic payment exceptions.
A positive pay service is designed to protect against which specific type of payment fraud?