Mixed Deck — All ACFE Topics Flashcards
100 cards from real ACFE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All ACFE Topics flashcards as text
Which of the following is a key limitation of relying solely on past fraud losses to assess current fraud risk?
Answer: Past losses reflect detected frauds only and may miss undetected schemes
Historical fraud loss data only captures detected and reported incidents, leaving undetected frauds — which may represent the majority — entirely unmeasured.
A Suspicious Activity Report (SAR) filed under the Bank Secrecy Act must generally be filed within how many days of detecting a suspicious transaction?
Answer: 30 days
Financial institutions must file a SAR within 30 days of initially detecting facts that may constitute a basis for filing, or 60 days if no suspect is identified.
When using data analytics as part of a fraud risk assessment, what is the primary goal?
Answer: To identify anomalies and patterns that may indicate fraud risk exposure
Data analytics in fraud risk assessment is used to surface anomalies, outliers, and unusual patterns that signal areas of elevated fraud risk.
Which element is considered the most cost-effective fraud deterrent in an organization?
Answer: Strong internal controls
Strong internal controls are considered the most cost-effective deterrent because they proactively prevent fraud rather than detect it after the fact.
What is the role of a fraud examiner?
Answer: To detect and investigate fraudulent activity
The primary role of a fraud examiner is to proactively detect, investigate, and resolve instances of fraudulent activity. This involves gathering evidence, interviewing witnesses, analyzing financial data, and preparing comprehensive reports to document findings, ultimately aiming to prevent future fraud and support legal actions.
When conducting a covert investigation, what is the BIGGEST risk of interviewing a suspect prematurely?
Answer: The suspect may destroy evidence or alert co-conspirators
Premature suspect interviews can tip off the subject, causing evidence destruction, flight, or warnings to co-conspirators before the investigation is complete.
Wire fraud under 18 U.S.C. § 1343 differs from mail fraud primarily in that it involves:
Answer: Electronic communications in interstate or foreign commerce
Wire fraud extends the fraud statutes to schemes using wire, radio, or television communications transmitted in interstate or foreign commerce.
A money launderer uses a legitimate restaurant business to commingle illegal cash with daily sales receipts, inflating reported revenues. This primarily exploits which characteristic?
Answer: The cash-intensive nature of restaurant operations
Cash-intensive businesses like restaurants are attractive for commingling because large cash revenues are normal and harder to distinguish from illicit funds.
Which digital forensics concept ensures that a forensic copy is an exact bit-for-bit duplicate of the original storage media?
Answer: Hash value verification
Hash values (MD5, SHA-256) generated before and after copying verify that the forensic image is an exact duplicate and has not been altered.
In a fraud investigation, what is the purpose of an 'exit interview' or 'admission-seeking interview' at the conclusion of an investigation?
Answer: To present evidence to the suspect and obtain an admission or explanation
An admission-seeking interview presents evidence to the suspect in a structured way to elicit a confession, explanation, or denial that can be evaluated.
Which of the following is an example of a preventive control in a fraud prevention framework?
Answer: Requiring dual authorization for wire transfers
Requiring dual authorization prevents unauthorized transfers from occurring at all, making it a preventive control rather than a detective one.
Under the Electronic Communications Privacy Act (ECPA), a 'pen register' captures:
Answer: The dialing, routing, addressing, and signaling information of communications but not content
A pen register records outgoing dialing, routing, addressing, and signaling information but is legally prohibited from capturing the content of any communication.
Which of the following best describes a 'fraud risk scenario' as used in a formal fraud risk assessment?
Answer: A specific, plausible description of how a fraud scheme could be perpetrated in the organization
A fraud risk scenario is a concrete, organization-specific description of how a particular fraud scheme could be carried out given the entity's people, processes, and systems.
A fraudster purchases lottery tickets at face value, then claims to have 'won' the lottery to explain a large cash windfall. This technique is called:
Answer: Layering
Purchasing winning lottery tickets from actual winners to explain illicit funds is a form of layering that creates a legitimate-appearing source of income.
A compliance officer discovers that the CFO is circumventing internal controls. What is the MOST appropriate initial action?
Answer: Escalate to the audit committee or board, bypassing the CFO
When suspected misconduct involves a senior executive, proper escalation goes around that executive to the board or audit committee, which has oversight authority.
Which of the following best describes the concept of 'inherent risk' in a fraud risk assessment?
Answer: The risk of fraud that exists before considering any controls
Inherent risk is the exposure to fraud that exists in the absence of any mitigating controls.
A fraud examiner needs to analyze an employee's hard drive for evidence, including files the employee may have recently deleted. Which data acquisition method is MOST appropriate for this task?
Answer: Creating a bit-stream image of the entire hard drive.
A bit-stream image (or forensic image) is an exact, bit-for-bit copy of an entire storage device, including deleted files, file fragments in slack space, and unallocated clusters. [5, 13, 23] This is the only method that preserves all potential evidence. A logical copy or standard backup only captures active, non-deleted files and would miss crucial artifacts necessary for the investigation. [5, 18]
Which of the following is considered a 'material weakness' under PCAOB standards?
Answer: A significant deficiency where there is a reasonable possibility of a material misstatement not being prevented or detected
A material weakness is a significant deficiency in internal control where there is a reasonable possibility that a material misstatement of the financial statements would not be prevented or detected on a timely basis.
What is the main advantage of a confidential employee hotline compared to open-door reporting policies?
Answer: It encourages reporting by reducing fear of retaliation
Confidential hotlines encourage reporting because employees fear less retaliation when their identity is protected, leading to more tips being submitted.
How can data analytics help detect fraud schemes?
Answer: By identifying irregularities in financial data
Data analytics helps detect fraud schemes by processing and analyzing large volumes of financial data to identify irregularities, anomalies, and unusual patterns. These deviations from expected behavior can serve as red flags, indicating potential fraudulent activities that might otherwise go unnoticed through traditional auditing methods. By highlighting suspicious transactions or trends, data analytics enables targeted investigations and proactive fraud prevention.