Accredited Payments Risk Professional (APRP) — Questions and Answers
Question 1: A payments company's compliance officer discovers that transaction monitoring rules have not been updated in 18 months despite the emergence of new fraud schemes. This is best described as a failure in:
- Control environment maintenance (Correct answer)
- Key Risk Indicator (KRI) tracking
- Customer due diligence
- Model validation
Correct answer: Control environment maintenance
Failure to update controls to address evolving risks represents a breakdown in the control environment, which requires ongoing maintenance and tuning.
Question 2: Multi-factor authentication (MFA) in payment systems requires users to present credentials from:
- Any combination of login attempts across multiple registered devices
- Authentication tokens issued sequentially by the same hardware vendor
- Two or more independent factors drawn from different categories: something you know, something you have, and/or something you are (Correct answer)
- Two or more passwords created independently by the same user
Correct answer: Two or more independent factors drawn from different categories: something you know, something you have, and/or something you are
True MFA requires factors from at least two distinct categories: knowledge (password/PIN), possession (hardware token, mobile device), or inherence (biometrics). Using two passwords is not MFA — both belong to the same category. The independence of the factors is what makes MFA effective.
Question 3: In payments fraud, 'synthetic identity fraud' refers to:
- Cloning a physical payment card using a skimmer
- Using a real person's identity without their knowledge
- Combining real and fictitious information to create a new identity (Correct answer)
- Submitting false merchant credentials to acquire a merchant account
Correct answer: Combining real and fictitious information to create a new identity
Synthetic identity fraud blends real data (like a valid SSN) with fabricated information to create an identity that passes initial verification checks.
Question 4: In the context of chargeback fraud prevention, what does 'order velocity monitoring' refer to?
- Analyzing the average dollar amount of disputed transactions
- Monitoring how quickly merchants respond to dispute notifications
- Measuring the speed at which chargebacks are processed by the issuer
- Tracking the number of orders placed by the same customer or card within a short time period (Correct answer)
Correct answer: Tracking the number of orders placed by the same customer or card within a short time period
Order velocity monitoring detects suspicious patterns where the same card or customer places multiple orders rapidly, a common indicator of fraudulent activity.
Question 5: Which payment rail is most commonly used for large-value, time-critical interbank transfers in the United States?
- PayPal
- RTP (Real-Time Payments)
- Fedwire Funds Service (Correct answer)
- ACH
Correct answer: Fedwire Funds Service
Fedwire is the Federal Reserve's real-time gross settlement system used for large-value, time-critical transfers between financial institutions.
Question 6: What is the impact of regulatory changes on APRP professionals?
- Regulations never change once established
- Regulatory changes require updating practices, procedures, and documentation to maintain compliance (Correct answer)
- Only government employees need to follow regulatory changes
- Regulatory changes only affect large organizations
Correct answer: Regulatory changes require updating practices, procedures, and documentation to maintain compliance
Professionals must monitor and adapt to regulatory changes that affect their practice, ensuring continued compliance and effective service delivery.
Question 7: In a payments environment, what is the primary purpose of network segmentation?
- To increase internet bandwidth
- To simplify network management
- To isolate the cardholder data environment and reduce the scope of PCI DSS compliance (Correct answer)
- To improve application performance
Correct answer: To isolate the cardholder data environment and reduce the scope of PCI DSS compliance
Network segmentation limits the cardholder data environment to a defined zone, shrinking the PCI DSS audit scope and attack surface.
Question 8: A payments risk policy document should PRIMARILY define which of the following?
- Technical specifications for the payment processing platform
- The scope, objectives, roles, and responsibilities for managing payments risk (Correct answer)
- A complete log of all active fraud investigations
- The dollar limits for every individual customer transaction type
Correct answer: The scope, objectives, roles, and responsibilities for managing payments risk
Risk policies establish the 'what and who' — scope, objectives, accountability, and high-level requirements. Specific transaction limits belong in procedures or risk appetite statements; fraud logs are operational records; technical specs belong in system documentation.
Question 9: What is the primary eligibility requirement for sitting for the APRP examination?
- A master's degree in finance
- Relevant work experience in payments or risk management (Correct answer)
- Passing a prerequisite exam first
- Membership in a specific trade association
Correct answer: Relevant work experience in payments or risk management
Candidates must demonstrate relevant professional experience in payments or risk management to be eligible for the APRP exam.
Question 10: Which regulatory requirement obligates US financial institutions to file a Suspicious Activity Report (SAR) when fraud is suspected above a certain threshold?
- Regulation E
- PCI DSS v4.0
- Bank Secrecy Act (BSA) (Correct answer)
- Gramm-Leach-Bliley Act (GLBA)
Correct answer: Bank Secrecy Act (BSA)
The Bank Secrecy Act and its implementing regulations require financial institutions to file SARs when transactions suggest criminal activity, including fraud, above reporting thresholds.
Question 11: A risk manager is calculating the Annualized Loss Expectancy (ALE) for a payment system outage. If the Single Loss Expectancy (SLE) is $500,000 and the outage is expected to occur twice per year, the ALE is:
- $1,000,000 (Correct answer)
- $500,000
- $250,000
- $1,500,000
Correct answer: $1,000,000
ALE = SLE × Annual Rate of Occurrence (ARO); $500,000 × 2 = $1,000,000.
Question 12: What is the significance of the 'Accredited' designation in the APRP credential name?
- Accreditation means the holder must renew annually
- The credential is accredited by the US Department of Education
- The holder is automatically licensed by a federal agency
- The exam is developed and reviewed through a psychometrically sound, industry-validated process (Correct answer)
Correct answer: The exam is developed and reviewed through a psychometrically sound, industry-validated process
The 'Accredited' designation signifies that the APRP exam is built through a rigorous, psychometrically sound, industry-validated development process.
Question 13: Under the Durbin Amendment to the Dodd-Frank Act, interchange fee caps on debit card transactions apply to issuers with assets of at least:
- $1 billion
- $5 billion
- $50 billion
- $10 billion (Correct answer)
Correct answer: $10 billion
The Durbin Amendment's interchange cap applies to debit card issuers with consolidated assets of $10 billion or more.
Question 14: An organization discovers that a former employee's badge still grants access to the payments server room one month after termination. Which process failed?
- Background check procedures
- Physical intrusion detection monitoring
- Security awareness training
- Access revocation as part of the offboarding process (Correct answer)
Correct answer: Access revocation as part of the offboarding process
Timely revocation of physical and logical access during employee offboarding is a fundamental control to prevent unauthorized access by former staff.
Question 15: In payment risk management, what is a 'fat finger' error?
- A fraudulent transaction disguised as a legitimate payment
- A cyberattack that overwhelms a payment gateway with traffic
- A human data entry mistake resulting in an incorrect transaction amount or routing (Correct answer)
- A system bug that duplicates batch settlement files
Correct answer: A human data entry mistake resulting in an incorrect transaction amount or routing
A 'fat finger' error refers to a human keying mistake, such as entering the wrong amount or account number, which can result in significant operational losses in payments.
Question 16: An employee working from home accesses the corporate payment platform. Which control is MOST important to mandate?
- Use of a public Wi-Fi with WEP encryption
- VPN with MFA connecting to the corporate network (Correct answer)
- The employee uses a personal device with antivirus
- Saving cardholder data to a personal cloud drive for backup
Correct answer: VPN with MFA connecting to the corporate network
A VPN with MFA ensures encrypted, authenticated access to payment systems from remote locations.
Question 17: Which review process should be performed on a REGULAR, recurring basis to ensure that terminated employees and role-changed staff cannot access payment systems?
- Vulnerability scanning of all payment servers
- Penetration testing of the payment network perimeter
- Encryption key rotation across all payment databases
- User access recertification (periodic review of access rights) (Correct answer)
Correct answer: User access recertification (periodic review of access rights)
User access recertification (also called access rights review or attestation) is a periodic process in which managers certify that each employee's system access remains appropriate for their current role. This catches orphaned accounts, over-permissioned users, and access rights retained after role changes or termination.
Question 18: The Bank Secrecy Act (BSA) requires financial instructions to:
- Disclose customer information to third parties.
- Report any cash transactions over $10,000. (Correct answer)
- Limit the amount of cash withdrawals per day.
- Perform credit checks on all account holders
Correct answer: Report any cash transactions over $10,000.
The Bank Secrecy Act (BSA) is a key anti-money laundering (AML) statute that requires financial institutions to assist the U.S. government in detecting and preventing illicit financial activities. A central requirement is the reporting of cash transactions exceeding $10,000 to the Financial Crimes Enforcement Network (FinCEN) via a Currency Transaction Report (CTR). This helps track large cash movements that could be linked to criminal enterprises.
Question 19: Under the Basel framework, which approach allows banks to calculate operational risk capital using their own internal loss data models?
- Standardized Approach (SA)
- Basic Indicator Approach (BIA)
- Advanced Measurement Approach (AMA) (Correct answer)
- Internal Ratings-Based (IRB) Approach
Correct answer: Advanced Measurement Approach (AMA)
The Advanced Measurement Approach (AMA) allows qualifying banks to use their own internal models and historical loss data to calculate operational risk capital requirements.
Question 20: Which compliance concept requires a payments company to verify that a third-party processor complies with applicable rules before onboarding them?
- Downstream monitoring
- Correspondent banking review
- Subprocessor indemnification
- Third-party due diligence (Correct answer)
Correct answer: Third-party due diligence
Third-party due diligence requires assessing a vendor's or partner's compliance posture before entering into a business relationship.
Question 21: Which payment rail is governed by SWIFT and primarily used for cross-border interbank fund transfers?
- Fedwire
- RTP
- SWIFT GPI (Correct answer)
- CHIPS
Correct answer: SWIFT GPI
SWIFT GPI (Global Payments Innovation) is SWIFT's enhanced correspondent banking service that adds speed, transparency, and end-to-end tracking to cross-border payments.
Question 22: What is the PRIMARY purpose of a payments risk governance framework within a financial institution?
- To reduce compliance staffing costs by consolidating risk functions
- To eliminate all payment-related losses within the fiscal year
- To maximize transaction volume by streamlining approval processes
- To establish clear accountability, oversight, and decision-making authority for managing payments risk (Correct answer)
Correct answer: To establish clear accountability, oversight, and decision-making authority for managing payments risk
A risk governance framework exists to define who is responsible for identifying, managing, and escalating payments risk — ensuring accountability flows from the board down through management to operational staff. It does not aim to eliminate all loss or reduce headcount.
Question 23: A cardholder files a dispute 95 days after a transaction, claiming the service was not as described. Under Visa's rules, which outcome is MOST likely?
- The issuer cannot file the chargeback because the dispute window has expired (Correct answer)
- The issuer can file under a different reason code to extend the window
- The merchant must automatically accept the chargeback
- Visa allows an extended 180-day window for 'not as described' disputes
Correct answer: The issuer cannot file the chargeback because the dispute window has expired
Visa's standard dispute window is 120 days from the transaction date or expected delivery date, and a filing at 95 days would still be within that window; however, if the 120-day limit had passed, the chargeback would be time-barred.
Question 24: A compliance audit reveals a processor is routing transactions to avoid certain fraud screening rules. This practice is known as:
- Risk-weighted processing
- Selective routing optimization
- Interchange downgrade management
- Transaction laundering (Correct answer)
Correct answer: Transaction laundering
Transaction laundering (also called factoring) involves routing transactions through another merchant's account to circumvent fraud controls and compliance requirements.
Question 25: Which of the following operational risk tools helps quantify the frequency and severity of potential payment loss events using statistical distributions?
- Balanced scorecard
- SWOT analysis
- RACI matrix
- Loss Distribution Approach (LDA) (Correct answer)
Correct answer: Loss Distribution Approach (LDA)
The Loss Distribution Approach (LDA) uses historical loss data fitted to statistical distributions to model the frequency and severity of operational risk events for capital and risk quantification.
Question 26: What is the purpose of a Hardware Security Module (HSM) in a payment processing environment?
- To perform load balancing across payment servers
- To monitor network traffic for intrusions
- To securely generate, store, and manage cryptographic keys (Correct answer)
- To provide physical server cooling
Correct answer: To securely generate, store, and manage cryptographic keys
An HSM is a tamper-resistant physical device that manages cryptographic keys and performs encryption operations securely.
Question 27: Under Nacha's APRP ethics guidelines, what must a credential holder do if they discover a material error in work they previously submitted to a client?
- Promptly disclose and correct the error (Correct answer)
- Delegate correction responsibility to a supervisor
- Ignore minor errors to protect the client relationship
- Wait for the client to notice the error
Correct answer: Promptly disclose and correct the error
APRP ethics standards require prompt disclosure and correction of material errors to maintain professional integrity.
Question 28: A company uses a third-party payment processor. Under the principle of data minimization, what is the BEST approach to handling customer data shared with the processor?
- Allow the processor to decide what data they need
- Encrypt the full customer profile before sharing
- Share only the data fields strictly necessary to complete the transaction (Correct answer)
- Share all available customer data for fraud analytics
Correct answer: Share only the data fields strictly necessary to complete the transaction
Data minimization requires sharing only the minimum necessary data to fulfill the specific processing purpose, reducing exposure in the event of a breach.
Question 29: An APRP professional joins a Nacha working group to help develop updated ACH risk guidelines. Which type of professional development does this activity represent?
- On-the-job training only
- Industry service and volunteerism (Correct answer)
- Vendor-sponsored learning
- Passive education
Correct answer: Industry service and volunteerism
Participating in Nacha working groups constitutes industry service and volunteerism, which is a recognized category of professional development.
Question 30: A merchant receives a chargeback under Visa reason code 13.1 (Merchandise/Services Not Received). Which document would MOST effectively rebut this dispute?
- A screenshot of the product listing page at time of sale
- The merchant's refund policy posted on the website
- A copy of the original sales receipt showing the transaction amount
- Signed delivery confirmation from a major carrier showing delivery to the cardholder's address (Correct answer)
Correct answer: Signed delivery confirmation from a major carrier showing delivery to the cardholder's address
Signed proof of delivery showing the cardholder's address received the goods is the strongest evidence to rebut a 'not received' chargeback.
Question 31: Under NACHA Operating Rules, an Originating Depository Financial Institution (ODFI) that originates ACH debits is required to conduct which type of ongoing monitoring of its originators?
- Annual PCI DSS audits of originator systems
- Risk-based monitoring of originator return rates and transaction patterns (Correct answer)
- Quarterly reviews of originator interchange revenue
- Monthly OFAC sanctions screening of all ACH batches
Correct answer: Risk-based monitoring of originator return rates and transaction patterns
NACHA rules require ODFIs to perform risk-based monitoring of originators, including tracking return rates and identifying unusual patterns that signal potential fraud or rule violations.
Question 32: When evaluating a job offer, an APRP holder should consider which factor most carefully?
- The length of the company's holiday party
- Whether the role provides continued exposure to payments risk challenges and professional growth (Correct answer)
- Proximity to a gym
- The color scheme of the office
Correct answer: Whether the role provides continued exposure to payments risk challenges and professional growth
Career growth for an APRP holder depends on roles that deepen expertise in payments risk management and offer opportunities to apply and expand credentials.
Question 33: Under PCI DSS, what is the requirement for protecting cryptographic keys used to encrypt cardholder data?
- Keys must be stored securely and access restricted to the fewest custodians necessary, with key-management procedures documented (Correct answer)
- Keys should be changed only when a breach occurs
- Keys can be shared across all system administrators for operational efficiency
- Keys may be stored in plaintext if the server is physically secured
Correct answer: Keys must be stored securely and access restricted to the fewest custodians necessary, with key-management procedures documented
PCI DSS Requirement 3 mandates strict key management including secure storage, limited access, and documented procedures for the full key lifecycle.
Question 34: What is the primary purpose of scenario analysis in operational risk assessment for a payments firm?
- To estimate potential losses from severe but plausible events not captured in historical loss data (Correct answer)
- To evaluate compliance with card brand operating rules
- To backtest fraud models against historical transaction data
- To benchmark processing fees against competitor pricing
Correct answer: To estimate potential losses from severe but plausible events not captured in historical loss data
Scenario analysis helps organizations estimate the potential impact of rare, high-severity events (e.g., major cyberattack) for which historical loss data may be insufficient.
Question 35: An APRP holder notices their employer's risk framework is outdated compared to current Nacha rules. What is the most professionally appropriate response?
- Document the gaps, prepare a remediation proposal, and present it to management (Correct answer)
- Resign from the position
- Ignore the discrepancy to avoid conflict
- Immediately report the employer to regulators without internal discussion
Correct answer: Document the gaps, prepare a remediation proposal, and present it to management
Documenting gaps and proposing remediation demonstrates leadership and professional responsibility, advancing both organizational compliance and the individual's career.
Question 36: Which of the following activities is the responsibility of SENIOR MANAGEMENT rather than the board of directors in a payments risk governance structure?
- Approving the organization's overall risk appetite
- Providing independent audit assurance on control effectiveness
- Setting the organization's long-term strategic risk tolerance
- Implementing board-approved payments risk policies and procedures (Correct answer)
Correct answer: Implementing board-approved payments risk policies and procedures
Senior management translates board-approved policies into operational procedures and ensures they are carried out. The board sets and approves risk appetite and strategy; independent audit assurance is the role of internal audit, not management.
Question 37: A payment risk professional recommends step-up authentication only for transactions above a defined risk threshold. This approach is an example of:
- Risk-based authentication (Correct answer)
- Multifactor enrollment
- Static rule enforcement
- Zero-trust security architecture
Correct answer: Risk-based authentication
Risk-based authentication applies additional verification only when a transaction's risk score exceeds a threshold, balancing security and customer friction.
Question 38: What is the primary purpose of a payments risk management policy?
- To identify and mitigate risks associated with payment systems (Correct answer)
- To increase transaction volume
- To ensure compliance with regulatory requirements
- To reduce the cost of payment transactions
Correct answer: To identify and mitigate risks associated with payment systems
A payments risk management policy provides a structured framework for an organization to identify, assess, and control the various risks associated with payment systems. This includes operational, fraud, credit, and compliance risks. Its primary purpose is to safeguard the integrity and security of payment operations, ensuring smooth, secure transactions and minimizing potential financial losses.
Question 39: What is 'change management risk' in the context of payment systems?
- Risk that system changes introduce errors, outages, or vulnerabilities if not properly controlled (Correct answer)
- Risk that customers resist new payment product features
- Risk of exchange rate fluctuations during a system migration
- Risk that regulators reject a new payment license application
Correct answer: Risk that system changes introduce errors, outages, or vulnerabilities if not properly controlled
Change management risk is the possibility that modifications to payment systems or processes introduce new failures, errors, or security vulnerabilities without proper testing and approval.
Question 40: Which concept requires that no single individual can complete a sensitive payment transaction or system change without involvement from at least one other person?
- Separation of duties (Correct answer)
- Least privilege
- Need to know
- Defense in depth
Correct answer: Separation of duties
Separation of duties splits critical tasks between two or more individuals to prevent fraud and errors by any single person.
Question 41: Which type of attack specifically targets the enrollment phase of biometric authentication in mobile payment apps?
- Replay attack using captured biometric templates
- Brute force attack on the biometric PIN fallback
- Man-in-the-middle attack on the biometric comparison server
- Presentation attack using a spoofed fingerprint or face mask (Correct answer)
Correct answer: Presentation attack using a spoofed fingerprint or face mask
Presentation attacks at enrollment inject fake biometric samples (spoofed fingerprints, 3D-printed faces) to register an attacker's biometric as the legitimate user's credential.
Question 42: How does earning the APRP designation benefit an employer organization?
- It eliminates all payments fraud losses
- It guarantees regulatory compliance without further effort
- It replaces the need for internal audit functions
- It demonstrates that staff have a validated competency in payments risk management (Correct answer)
Correct answer: It demonstrates that staff have a validated competency in payments risk management
The APRP demonstrates that staff possess a validated, independently assessed competency in payments risk management, benefiting the organization.
Question 43: Which of the following is an example of a 'preventive' control in a payments fraud management program?
- Generating monthly fraud loss reports for management
- Reviewing declined transaction logs to identify false positives
- Filing chargebacks on unauthorized transactions after the fact
- Real-time velocity checking that blocks transactions exceeding defined thresholds (Correct answer)
Correct answer: Real-time velocity checking that blocks transactions exceeding defined thresholds
Real-time velocity checking prevents fraudulent transactions from completing, making it a preventive control that acts before the harm occurs.
Question 44: How should APRP professionals approach client or stakeholder communication?
- Use clear, professional language appropriate to the audience, confirm understanding, and document key communications (Correct answer)
- Communication skills are unimportant for technical professionals
- Only communicate in writing, never verbally
- Use technical jargon regardless of the audience
Correct answer: Use clear, professional language appropriate to the audience, confirm understanding, and document key communications
Effective communication tailored to the audience's knowledge level is essential for building trust, ensuring understanding, and achieving professional objectives.
Question 45: What does 'settlement risk' refer to in the context of payment systems?
- The risk that chargebacks will exceed a merchant's reserve account
- The risk of regulatory fines for non-compliance with PCI DSS
- The risk that one party will fail to deliver on its obligation after the counterparty has already fulfilled theirs (Correct answer)
- The risk that a payment network will fail to authenticate a transaction
Correct answer: The risk that one party will fail to deliver on its obligation after the counterparty has already fulfilled theirs
Settlement risk, also called Herstatt risk, occurs when one party has already settled but the counterparty defaults before completing its leg of the transaction.
Question 46: What is real-time payments (RTP) and how does it differ from traditional payment processing?
- Only cryptocurrency transactions
- Payments that are initiated, cleared, and settled within seconds, available 24/7/365 (Correct answer)
- Payments processed at the normal batch processing speed
- Payments that require real-time video verification
Correct answer: Payments that are initiated, cleared, and settled within seconds, available 24/7/365
Real-time payments are processed end-to-end within seconds, providing immediate funds availability, unlike traditional ACH or card payments that may take hours or days to settle.
Question 47: How should an APRP holder document their credential when signing professional correspondence?
- Include 'APRP' as a post-nominal designation after their name (Correct answer)
- List it only on business cards
- Never mention professional credentials in correspondence
- Only mention it verbally, never in writing
Correct answer: Include 'APRP' as a post-nominal designation after their name
Using 'APRP' as a post-nominal designation on correspondence communicates professional credentialing and signals expertise to clients and colleagues.
Question 48: Which metric is the PRIMARY indicator used to measure the effectiveness of a fraud prevention program?
- Fraud loss as a percentage of sales volume (Correct answer)
- Number of chargebacks filed per month
- Average transaction approval time
- Total number of transactions declined
Correct answer: Fraud loss as a percentage of sales volume
Fraud loss as a percentage of sales volume (fraud rate) is the standard KPI for measuring fraud prevention effectiveness relative to business scale.
Question 49: A payment organization suffers a data breach exposing cardholder data. Which entity must be notified immediately under card network rules?
- The acquiring bank and card networks (e.g., Visa, Mastercard) (Correct answer)
- The organization's external auditors
- Only the affected cardholders directly
- The Federal Reserve Board exclusively
Correct answer: The acquiring bank and card networks (e.g., Visa, Mastercard)
Card network rules require immediate notification of the acquiring bank and the relevant card networks when a breach involving cardholder data is discovered.
Question 50: Which metric BEST measures the financial impact of chargebacks on a merchant relative to their overall sales volume?
- Chargeback-to-transaction ratio (Correct answer)
- Dispute win rate
- Refund rate
- Average chargeback amount
Correct answer: Chargeback-to-transaction ratio
The chargeback-to-transaction ratio (total chargebacks divided by total transactions) is the primary metric card networks use to monitor merchant chargeback performance.
Question 51: Which of the following is a proactive strategy for reducing chargeback rates related to 'services not as described' disputes?
- Requiring cardholders to sign a waiver before purchasing
- Blocking all international transactions
- Ensuring product descriptions, images, and return policies are accurate and clearly communicated before purchase (Correct answer)
- Implementing velocity limits on card transactions
Correct answer: Ensuring product descriptions, images, and return policies are accurate and clearly communicated before purchase
Clear, accurate product descriptions and transparent return policies reduce consumer confusion and set proper expectations, directly lowering 'not as described' dispute rates.
Question 52: A payments organization uses multi-factor authentication (MFA). Which combination correctly represents three different authentication factors?
- Password, PIN, and security question
- Password, username, and employee ID
- Smart card, fingerprint, and one-time passcode (Correct answer)
- Retina scan, voice print, and face scan
Correct answer: Smart card, fingerprint, and one-time passcode
Smart card (something you have), fingerprint (something you are), and OTP (something you have/know) span three distinct factor categories.
Question 53: What is the role of a 'negative file' or 'deny list' in fraud prevention?
- It contains identifiers associated with past fraud that trigger declines or alerts (Correct answer)
- It stores approved merchant categories for automated clearing
- It lists accounts exempt from velocity checks due to VIP status
- It records failed authentication attempts for regulatory reporting
Correct answer: It contains identifiers associated with past fraud that trigger declines or alerts
A negative file is a database of known fraudulent identifiers (cards, accounts, devices, IPs) used to automatically block or flag matching future transactions.
Question 54: Which type of social engineering attack targets specific high-value individuals within a payments organization, such as the CFO or CTO?
- Smishing
- Pretexting via helpdesk
- Spear phishing (whaling) (Correct answer)
- Vishing
Correct answer: Spear phishing (whaling)
Whaling is a targeted spear phishing attack aimed at senior executives to authorize fraudulent payments or disclose credentials.
Question 55: In a payments organization, which body typically holds ULTIMATE responsibility for approving the enterprise risk appetite statement?
- The internal audit department
- The ACH operations manager
- The Chief Compliance Officer
- The board of directors (Correct answer)
Correct answer: The board of directors
The board of directors bears ultimate fiduciary responsibility for the organization, including approving the overall risk appetite. Management implements board-approved policies; internal audit provides independent assurance; the CCO oversees day-to-day compliance.
Question 56: Which committee membership would most advance an APRP holder's career in payments risk governance?
- Annual picnic planning committee
- Company softball team committee
- Nacha's Risk Management Advisory Group or similar industry working group (Correct answer)
- Office supply ordering committee
Correct answer: Nacha's Risk Management Advisory Group or similar industry working group
Serving on Nacha's Risk Management Advisory Group positions an APRP professional at the forefront of industry standards development and peer networking.
Question 57: Under Visa's dispute resolution framework, what is the term for a merchant's response that challenges a chargeback and provides evidence the original transaction was valid?
- Compliance filing
- Pre-arbitration
- Arbitration
- Representment (Correct answer)
Correct answer: Representment
Representment is the process by which a merchant (through their acquirer) re-presents a transaction to rebut a cardholder's chargeback with supporting documentation.
Question 58: What is the role of a Qualified Security Assessor (QSA) in the PCI DSS compliance process?
- To approve new payment card designs for card networks
- To set PCI DSS standards on behalf of the PCI Security Standards Council
- To process chargebacks on behalf of issuing banks
- To independently assess and validate an organization's compliance with PCI DSS requirements (Correct answer)
Correct answer: To independently assess and validate an organization's compliance with PCI DSS requirements
A QSA is a company certified by the PCI SSC to independently assess an organization's PCI DSS compliance and validate its Report on Compliance (ROC).
Question 59: What does 'interchange optimization' mean for a merchant accepting card payments?
- Ensuring transactions qualify for the lowest possible interchange category through proper data submission (Correct answer)
- Minimizing the number of card networks the merchant accepts
- Switching from card payments to ACH to eliminate interchange entirely
- Negotiating directly with card issuers to reduce published rates
Correct answer: Ensuring transactions qualify for the lowest possible interchange category through proper data submission
Interchange optimization involves submitting complete transaction data (e.g., Level 2 or Level 3 data for B2B cards) to qualify transactions for lower interchange tiers.
Question 60: A merchant's chargeback-to-transaction ratio is 0.8% but their raw chargeback count is 150 per month. Under Visa's VDMP, which condition is relevant?
- Only the count matters; the ratio is irrelevant
- Only the ratio matters; the count is irrelevant
- Neither threshold is met, so no monitoring applies
- Both the ratio threshold AND minimum chargeback count thresholds must be met to trigger monitoring (Correct answer)
Correct answer: Both the ratio threshold AND minimum chargeback count thresholds must be met to trigger monitoring
Visa's VDMP requires BOTH a chargeback ratio above the threshold AND a minimum number of chargebacks (e.g., 100+) to trigger a monitoring program tier.
Question 61: Mastercard's 'Consumer Clarity' program is analogous to which Visa service designed to reduce friendly fraud chargebacks?
- Visa Claims Resolution (VCR)
- Visa Resolve Online (VROL)
- Visa Secure
- Visa Order Insight (Correct answer)
Correct answer: Visa Order Insight
Mastercard's Consumer Clarity and Visa's Order Insight both allow merchants to share transaction details with issuers to resolve cardholder confusion before it escalates to a chargeback.
Question 62: Which of the following describes a 'skimming' attack in the context of payment data security?
- A phishing email campaign targeting payment card customers
- Social engineering of call center agents to obtain cardholder details
- A man-in-the-middle attack intercepting online payment transactions
- The theft of card data by attaching a covert device to a payment terminal or ATM (Correct answer)
Correct answer: The theft of card data by attaching a covert device to a payment terminal or ATM
Skimming involves attaching a covert device to a payment terminal or ATM to capture magnetic stripe data from cards as they are swiped.
Question 63: Which federal agency has primary examination authority over non-bank payment processors for consumer protection compliance?
- CFPB (Correct answer)
- Federal Reserve
- FDIC
- OCC
Correct answer: CFPB
The Consumer Financial Protection Bureau (CFPB) has supervisory authority over large non-bank payment processors for consumer protection laws.
Question 64: What is the importance of professional networking in payment risk management?
- Networking only benefits entry-level professionals
- Only online networking has value
- Networking is a waste of time for established professionals
- Building relationships with peers enables knowledge sharing, professional development, and career advancement (Correct answer)
Correct answer: Building relationships with peers enables knowledge sharing, professional development, and career advancement
Professional networks provide opportunities for knowledge exchange, mentorship, collaboration, and staying informed about industry trends and opportunities.
Question 65: What is the PRIMARY objective of a Know Your Customer (KYC) program in the context of payments risk?
- To obtain customer consent for sharing transaction data with third parties
- To collect demographic data for targeted product marketing campaigns
- To verify customer identity and assess money laundering risk before and throughout the customer relationship (Correct answer)
- To ensure customers understand their chargeback and dispute rights
Correct answer: To verify customer identity and assess money laundering risk before and throughout the customer relationship
KYC programs are AML tools designed to verify who customers are and assess the risk they pose for financial crimes such as money laundering or terrorist financing. This is an ongoing obligation — not a one-time marketing or consent activity.
Question 66: What is the primary purpose of the FFIEC's Authentication Guidance for internet banking environments?
- To require biometric authentication for mobile banking applications
- To mandate multifactor authentication for all transactions regardless of risk
- To establish minimum password complexity requirements for all users
- To provide a risk-based framework for evaluating and implementing appropriate authentication controls (Correct answer)
Correct answer: To provide a risk-based framework for evaluating and implementing appropriate authentication controls
The FFIEC Authentication Guidance establishes a risk-based framework, requiring institutions to assess transaction risk and implement authentication controls commensurate with that risk.
Question 67: A merchant notices an unusual spike in chargebacks originating from transactions made via a Buy Now, Pay Later (BNPL) provider. What is the most likely root cause?
- Friendly fraud by consumers exploiting BNPL's split payment structure (Correct answer)
- Excessive interchange fees triggering consumer disputes
- ACH return rate violations by the BNPL provider
- Incorrect MCC code assignment by the merchant acquirer
Correct answer: Friendly fraud by consumers exploiting BNPL's split payment structure
BNPL's deferred payment model creates incentives for friendly fraud, where consumers dispute charges after receiving goods to avoid installment payments.
Question 68: Under the Gramm-Leach-Bliley Act (GLBA), payment companies that qualify as financial institutions must provide customers with:
- Annual interest rate disclosures
- Monthly account statements
- Privacy notices explaining information sharing practices (Correct answer)
- Quarterly risk assessments
Correct answer: Privacy notices explaining information sharing practices
GLBA requires financial institutions to provide customers with clear privacy notices describing how personal financial information is collected and shared.
Question 69: PCI DSS requires that all default passwords on payment system components be changed. Why is this critical?
- Changing passwords resets admin audit logs
- Default passwords are publicly known and easily exploited by attackers (Correct answer)
- Default passwords are too short for system performance
- Vendors require password changes for warranty compliance
Correct answer: Default passwords are publicly known and easily exploited by attackers
Default credentials are documented in vendor manuals and widely known; leaving them unchanged is one of the most common and easily exploited vulnerabilities.
Question 70: A payments firm's governance committee receives a risk report showing that inherent risk is high but residual risk is low. What does this indicate?
- The firm is exposed to significant losses with no mitigating controls in place
- Risk appetite exceeds the firm's actual risk capacity
- The firm has understated its risk exposure in the report
- Effective controls are successfully reducing the impact of a high-risk environment (Correct answer)
Correct answer: Effective controls are successfully reducing the impact of a high-risk environment
Residual risk equals inherent risk minus the effect of controls; a low residual risk despite high inherent risk indicates that controls are working effectively.
Question 71: During the pre-arbitration phase of a Visa dispute, the issuer rejects the merchant's representment. What is the merchant's NEXT available step?
- Submit a second representment with additional evidence
- File for arbitration with Visa (Correct answer)
- Accept the chargeback and move on
- Escalate directly to law enforcement
Correct answer: File for arbitration with Visa
If pre-arbitration is rejected, the acquiring bank may escalate to formal Visa arbitration for a binding ruling.
Question 72: A merchant enrolled in Visa's Dispute Monitoring Program (VDMP) fails to reduce chargebacks within the remediation period. What is the MOST likely consequence?
- The merchant is automatically transferred to Mastercard's monitoring program
- The issuing bank absorbs all future chargebacks from that merchant
- The merchant's chargeback fees are temporarily waived during remediation
- Visa may impose fines and ultimately disqualify the merchant from accepting Visa cards (Correct answer)
Correct answer: Visa may impose fines and ultimately disqualify the merchant from accepting Visa cards
Merchants who remain non-compliant in Visa's monitoring programs face escalating fines and potential disqualification from accepting Visa payments.
Question 73: Under the EU's Payment Services Directive 2 (PSD2), Strong Customer Authentication (SCA) requires a combination of at least two of which three factors?
- PIN, Token, and Biometric only
- Identity, Velocity, and Location
- Knowledge, Possession, and Inherence (Correct answer)
- Password, SMS OTP, and Device fingerprint only
Correct answer: Knowledge, Possession, and Inherence
PSD2 SCA requires authentication using at least two of three independent factors: something you know (Knowledge), something you have (Possession), and something you are (Inherence).
Question 74: Which of the following best describes the primary audience for the APRP designation?
- Marketing professionals in the payments industry
- Bank tellers and branch staff
- IT cybersecurity professionals only
- Payments professionals seeking demonstrated risk expertise (Correct answer)
Correct answer: Payments professionals seeking demonstrated risk expertise
The APRP designation is designed for payments professionals who want to demonstrate expertise in payments risk management.
Question 75: A subscription merchant wants to reduce 'cardholder does not recognize' chargebacks. Which tactic is MOST effective?
- Using a recognizable billing descriptor that includes the brand name and contact information (Correct answer)
- Requiring cardholders to sign a paper agreement
- Increasing the subscription price to deter fraud
- Sending physical mail confirmations for each billing cycle
Correct answer: Using a recognizable billing descriptor that includes the brand name and contact information
A clear, recognizable billing descriptor directly on the card statement is the most effective way to prevent cardholders from disputing transactions they don't recognize.
Question 76: Which concept describes the practice of using a single transaction to offset obligations between multiple counterparties, reducing gross settlement to a net amount?
- Float management
- Straight-through processing
- Multilateral netting (Correct answer)
- Tokenization
Correct answer: Multilateral netting
Multilateral netting consolidates obligations among multiple parties so only net positions are settled, reducing liquidity needs and credit exposure.
Question 77: A BNPL provider offers instant credit without a hard credit check. Which risk does this practice most directly increase for the payment ecosystem?
- Systemic counterparty credit risk when BNPL providers extend beyond their capital base (Correct answer)
- Reg Z disclosure violations for open-end credit products
- PCI DSS scope expansion for all merchants accepting BNPL
- ACH nacha rule violations for recurring debit authorizations
Correct answer: Systemic counterparty credit risk when BNPL providers extend beyond their capital base
BNPL providers extending credit without robust credit checks build portfolios of potentially high-risk borrowers, and if losses exceed capital, their inability to honor merchant settlements creates systemic risk.
Question 78: In SWIFT messaging, which message type (MT) is used for a general financial institution transfer (customer credit transfer)?
- MT 900
- MT 202
- MT 103 (Correct answer)
- MT 950
Correct answer: MT 103
MT 103 is the SWIFT message type for single customer credit transfers, used to instruct a bank to transfer funds to a beneficiary customer.
Question 79: In payments risk management, 'corporate account takeover' (CATO) is BEST described as:
- An internal fraud scheme in which an employee diverts incoming wires to a personal account
- A regulatory action in which authorities seize control of a non-compliant financial institution
- Criminals stealing business online banking credentials to initiate unauthorized ACH debits or wire transfers (Correct answer)
- A hostile acquisition of a payment processing company by a competitor
Correct answer: Criminals stealing business online banking credentials to initiate unauthorized ACH debits or wire transfers
CATO refers to cybercriminals compromising a business's online banking login credentials — often through malware or phishing — and then using those credentials to initiate unauthorized payments such as ACH batch files or wire transfers. It is a major fraud vector specifically targeting commercial payment accounts.
Question 80: Which of the following is a key component of a risk assessment process for payment systems?
- Reducing staff numbers
- Marketing new payment products
- Increasing the speed transactions
- Identifying potential threats and vulnerabilities (Correct answer)
Correct answer: Identifying potential threats and vulnerabilities
A key component of a risk assessment process for payment systems involves systematically identifying potential threats and vulnerabilities. Threats include external dangers like cyberattacks or fraud schemes, while vulnerabilities are weaknesses within the system itself, such as outdated software or weak controls. This identification is crucial for understanding where the system is susceptible to harm and for developing effective mitigation strategies.
Question 81: An international remittance provider uses cryptocurrency rails to avoid correspondent banking fees. What is the primary OFAC compliance challenge?
- Screening wallet addresses against OFAC's SDN list when blockchain addresses are pseudonymous and change frequently (Correct answer)
- Calculating transaction values in USD when cryptocurrency prices fluctuate between initiation and settlement
- Obtaining a specific license for cryptocurrency use from the Office of Foreign Assets Control
- Reporting cryptocurrency transactions to FinCEN when no CTR threshold exists for digital assets
Correct answer: Screening wallet addresses against OFAC's SDN list when blockchain addresses are pseudonymous and change frequently
OFAC requires screening against its SDN list, but blockchain's pseudonymous wallet addresses can obscure sanctioned parties, and wallet addresses used by sanctioned entities may not be published promptly.
Question 82: Which network rule governs the time frame within which an issuer must respond to an authorization request in card payment systems?
- Floor limit policy
- Authorization response time limit (Correct answer)
- Interchange reimbursement fee schedule
- Chargeback representment window
Correct answer: Authorization response time limit
Network rules specify authorization response time limits to ensure timely approval or decline decisions during card transactions.
Question 83: When a card network rules in favor of the issuer during formal arbitration, what financial consequence does the losing acquirer typically face?
- The acquirer must issue a public statement about the dispute
- The acquirer receives a credit for previously paid chargeback fees
- The acquirer pays the chargeback amount plus arbitration fees charged by the card network (Correct answer)
- Only the original transaction amount is debited
Correct answer: The acquirer pays the chargeback amount plus arbitration fees charged by the card network
When an acquirer loses arbitration, they are liable for the disputed transaction amount plus significant arbitration fees (often $250–$500 per case) imposed by the card network.
Question 84: The Real-Time Payments (RTP) network operated by The Clearing House uses which credit-push model characteristic?
- Participating banks can reverse transactions up to 90 days post-settlement
- Funds can be debited from a receiver's account without prior authorization
- Transactions settle on a next-day basis through the Federal Reserve
- Payments are irrevocable once the receiver's bank confirms receipt (Correct answer)
Correct answer: Payments are irrevocable once the receiver's bank confirms receipt
RTP payments are credit pushes and irrevocable upon confirmation of receipt by the receiving financial institution, meaning payers must ensure accuracy before sending.
Question 85: In EMV chip card transactions, what is 'offline data authentication' (ODA) designed to verify?
- That the chip card is genuine and not a counterfeit (Correct answer)
- That the transaction amount does not exceed the cardholder's credit limit
- That the cardholder's PIN matches the issuer's records
- That the terminal is certified by the card network
Correct answer: That the chip card is genuine and not a counterfeit
Offline data authentication uses cryptographic techniques (SDA, DDA, or CDA) to verify the chip card's authenticity without requiring a connection to the issuer.
Question 86: Which professional organization is most directly associated with the APRP credential for payments risk professionals?
- NACHA (Correct answer)
- AFP
- ISACA
- RIMS
Correct answer: NACHA
NACHA (now Nacha) administers the APRP credential, which is specifically designed for payments risk professionals.
Question 87: Which RTP (Real-Time Payments) network attribute makes fraud recovery fundamentally more difficult than traditional ACH?
- Immediate and irrevocable settlement (Correct answer)
- Higher per-transaction fees
- Mandatory two-factor authentication
- 24/7 processing windows
Correct answer: Immediate and irrevocable settlement
Because RTP funds are credited instantly and settlement is final, there is no recall window like ACH's two-day return period.
Question 88: Under the 'three lines of defense' model, which group provides INDEPENDENT assurance that risk controls are effective?
- Business unit managers (first line)
- Risk management and compliance functions (second line)
- Internal audit (third line) (Correct answer)
- External regulators
Correct answer: Internal audit (third line)
Internal audit is the third line of defense, providing independent, objective assurance over the effectiveness of risk management and controls. The first line owns and manages risks; the second line oversees and provides guidance; internal audit independently validates both.
Question 89: Which of the following best describes 'concentration risk' in payment operations?
- Risk from over-reliance on a single vendor, geography, or technology for critical payment functions (Correct answer)
- Risk from holding too many payment fraud cases in a single queue
- Risk from employee turnover in the payments compliance team
- Risk that a payment message is duplicated during transmission
Correct answer: Risk from over-reliance on a single vendor, geography, or technology for critical payment functions
Concentration risk arises when an organization is overly dependent on a single vendor, region, or technology, making it vulnerable if that single source fails.
Question 90: What is cyber insurance for payment companies?
- A warranty on payment processing hardware
- Insurance for internet service providers
- Only applicable to technology companies, not payment companies
- Insurance coverage protecting against financial losses from cyber attacks, data breaches, and system failures (Correct answer)
Correct answer: Insurance coverage protecting against financial losses from cyber attacks, data breaches, and system failures
Cyber insurance covers financial losses from data breaches (notification costs, legal fees, regulatory fines), business interruption from cyber attacks, and third-party liability for compromised customer data.
Question 91: A risk appetite statement in the context of payments risk management is BEST described as:
- A historical report of all payment losses incurred in the prior fiscal year
- A regulatory filing submitted annually to the Consumer Financial Protection Bureau
- A statement articulating how much risk the organization is willing to accept in pursuit of its business objectives (Correct answer)
- A customer-facing disclosure about payment processing fees and security practices
Correct answer: A statement articulating how much risk the organization is willing to accept in pursuit of its business objectives
A risk appetite statement is a forward-looking governance document that defines the level and types of risk senior leadership and the board are willing to tolerate. It guides strategic and operational decisions and is internal, not a regulatory filing or customer disclosure.
Question 92: What is the MAIN risk of printing cardholder data (such as PANs) on receipts or reports in a payments environment?
- Printed data can be stolen, lost, or improperly disposed of, exposing sensitive account information (Correct answer)
- It slows down transaction processing
- Printers are always connected to the internet
- It increases paper costs
Correct answer: Printed data can be stolen, lost, or improperly disposed of, exposing sensitive account information
Printed cardholder data creates physical copies that can be accessed by unauthorized individuals if not properly secured and destroyed.
Question 93: Which U.S. federal regulation specifically addresses the rights and responsibilities of consumers using credit cards, including billing disputes?
- Regulation E
- Regulation J
- Regulation Z (Correct answer)
- Regulation CC
Correct answer: Regulation Z
Regulation Z (implementing the Truth in Lending Act) governs credit card disclosures, billing error resolution, and consumer rights for credit card transactions.
Question 94: Which risk type is most directly addressed by requiring merchants to implement 3D Secure (3DS) authentication for card-not-present transactions?
- Liquidity risk from delayed settlement cycles
- Operational risk from terminal malfunctions
- Fraud risk from unauthorized use of stolen card credentials in e-commerce (Correct answer)
- Credit risk from cardholder inability to repay balances
Correct answer: Fraud risk from unauthorized use of stolen card credentials in e-commerce
3DS adds an authentication step (e.g., OTP or biometric) in CNP transactions to verify the cardholder is legitimate, directly reducing fraud from stolen card data.
Question 95: What does 'compelling evidence' refer to in the context of a chargeback representment?
- An independent audit of the merchant's sales records
- A sworn affidavit from the cardholder
- Documentation that disproves the cardholder's claim or confirms transaction legitimacy (Correct answer)
- A certified letter from the card network
Correct answer: Documentation that disproves the cardholder's claim or confirms transaction legitimacy
Compelling evidence is documentation (e.g., signed receipts, delivery confirmation, customer correspondence) that the merchant provides to demonstrate the transaction was valid.
Question 96: Which emerging risk does 'ghost broking' represent in embedded insurance products bundled with payment cards?
- Insurers deny claims citing the embedded nature of the coverage as non-binding
- Fraudulent intermediaries sell fake insurance policies funded by cardholder interchange (Correct answer)
- Payment networks assume underwriting liability for card-linked insurance products
- Cardholders double-claim insurance from both the card benefit and a standalone policy
Correct answer: Fraudulent intermediaries sell fake insurance policies funded by cardholder interchange
Ghost broking involves fraudulent intermediaries who collect premiums for insurance policies that are either fake or quickly cancelled after issuance, leaving victims uninsured.
Question 97: Which of the following is a common physical security measure to protect against unauthorized access to a data center?
- Strong encryption algorithms
- Biometric access control (Correct answer)
- Employee training programs
- Regular software updates
Correct answer: Biometric access control
Biometric access control, such as fingerprint or retina scanners, is a robust physical security measure designed to prevent unauthorized individuals from entering restricted areas like data centers. It verifies unique biological characteristics, making it significantly harder to bypass than traditional methods. This directly enhances the physical protection of sensitive facilities and their contents.
Question 98: Which organization publishes the Payment Card Industry Data Security Standard (PCI DSS)?
- PCI Security Standards Council (Correct answer)
- NACHA
- FFIEC
- Federal Reserve
Correct answer: PCI Security Standards Council
The PCI Security Standards Council, founded by the major card brands, publishes and maintains PCI DSS.
Question 99: How does a 'chargeback' differ from a 'refund' in the card payment ecosystem from a risk management perspective?
- A chargeback is initiated by the issuer or cardholder through the network and can result in penalties for the merchant; a refund is initiated by the merchant directly (Correct answer)
- Chargebacks apply only to credit cards; refunds apply only to debit cards
- A refund carries network fees while a chargeback is always free for merchants
- A chargeback returns funds faster than a refund in all circumstances
Correct answer: A chargeback is initiated by the issuer or cardholder through the network and can result in penalties for the merchant; a refund is initiated by the merchant directly
A chargeback bypasses the merchant and is adjudicated through the card network, potentially resulting in fees, fines, or program termination; a refund is a voluntary merchant-initiated credit.
Question 100: The ISO 20022 messaging standard is primarily designed to improve which aspect of payments?
- ATM network routing
- Fraud detection algorithms
- Rich data and interoperability across payment systems (Correct answer)
- Cardholder authentication
Correct answer: Rich data and interoperability across payment systems
ISO 20022 provides a universal financial messaging standard enabling richer data and greater interoperability across domestic and international payment systems.
Question 101: Which metric is calculated by dividing the total number of chargebacks in a month by the total number of transactions processed in that same month?
- Dispute resolution rate
- Fraud-to-sales ratio
- Retrieval request ratio
- Chargeback-to-transaction ratio (Correct answer)
Correct answer: Chargeback-to-transaction ratio
The chargeback-to-transaction ratio (or chargeback rate) is calculated by dividing monthly chargeback count by monthly transaction count and is the primary metric card networks use for monitoring.
Question 102: Under PCI DSS, what is the minimum frequency for running internal vulnerability scans on systems in the cardholder data environment?
- Semi-annually
- Quarterly (Correct answer)
- Annually
- Monthly
Correct answer: Quarterly
PCI DSS Requirement 11 mandates that internal vulnerability scans be performed at least quarterly and after any significant changes to the network.
Question 103: What distinguishes a 'closed-loop' payment system from an 'open-loop' payment system?
- Closed-loop systems require EMV chip technology; open-loop systems do not
- Closed-loop systems are regulated by the Federal Reserve; open-loop systems are not
- Open-loop systems settle in real time; closed-loop systems use batch processing
- Closed-loop systems are usable only within a specific merchant or network; open-loop systems are accepted broadly (Correct answer)
Correct answer: Closed-loop systems are usable only within a specific merchant or network; open-loop systems are accepted broadly
Closed-loop systems (e.g., Starbucks gift cards) are accepted only within a defined network, while open-loop systems (e.g., Visa) are accepted across many merchants.
Question 104: A fraud analyst notices that disputed transactions share the same IP geolocation — a country the cardholder has never visited. This is an example of using which fraud signal?
- Velocity threshold breach
- Negative file match
- Chargeback reason code analysis
- Geolocation anomaly detection (Correct answer)
Correct answer: Geolocation anomaly detection
Geolocation anomaly detection compares the transaction origin's IP location against cardholder behavioral history to flag geographically implausible activity.
Question 105: Which fraud type involves a legitimate business processing fraudulent transactions on behalf of unknown third-party fraudsters?
- Factoring (merchant laundering) (Correct answer)
- Refund abuse
- Bust-out fraud
- Triangulation fraud
Correct answer: Factoring (merchant laundering)
Factoring occurs when a merchant runs transactions for another party through its own merchant account, violating card network rules and enabling fraud or money laundering.
Question 106: A key risk indicator (KRI) differs from a key performance indicator (KPI) in that a KRI:
- Signals an increase in the likelihood of future risk events (Correct answer)
- Measures how efficiently a process operates
- Reports on revenues generated by a business unit
- Counts the total number of transactions processed
Correct answer: Signals an increase in the likelihood of future risk events
KRIs are forward-looking metrics that warn of rising risk levels, while KPIs measure operational or financial performance.
Question 107: In payments compliance, what is a 'de-risking' strategy and why is it controversial?
- Outsourcing compliance functions to reduce internal risk
- Terminating relationships with entire categories of higher-risk customers to avoid compliance burden (Correct answer)
- Encrypting all stored card data to reduce breach risk
- Using risk-scoring models to price transactions dynamically
Correct answer: Terminating relationships with entire categories of higher-risk customers to avoid compliance burden
De-risking involves exiting entire customer segments (e.g., money service businesses) to avoid AML compliance costs, which regulators criticize for excluding legitimate customers from financial services.
Question 108: What is 'representment' in the chargeback process?
- The merchant resubmitting a transaction to recover funds after a chargeback (Correct answer)
- The cardholder re-filing a dispute after it is denied
- The issuing bank requesting additional documentation
- The card network arbitrating between parties
Correct answer: The merchant resubmitting a transaction to recover funds after a chargeback
Representment is the process by which a merchant (through their acquirer) submits compelling evidence to reverse a chargeback and recover the disputed funds.
Question 109: A customer claims they returned merchandise but the merchant disputes receiving it. This scenario BEST describes which chargeback condition?
- Credit not processed (Correct answer)
- Unauthorized transaction
- Not as described
- Merchandise not received
Correct answer: Credit not processed
When a customer has returned goods and a credit has not been issued, the appropriate chargeback reason is 'credit not processed.'
Question 110: A high-risk merchant processes mostly card-not-present transactions and wants to reduce friendly fraud chargebacks. Which tool provides the STRONGEST protection under Visa's rules?
- Manual order review by staff
- Visa Secure (3-D Secure 2.0) with successful cardholder authentication (Correct answer)
- Address Verification Service (AVS) alone
- IP geolocation matching
Correct answer: Visa Secure (3-D Secure 2.0) with successful cardholder authentication
Successful 3-D Secure 2.0 authentication shifts chargeback liability for fraud disputes from the merchant to the issuer, providing the strongest protection available.
Question 111: Which of the following scenarios best demonstrates application of APRP professional development in a real workplace setting?
- Applying outdated risk checklists from five years ago
- Delegating all risk policy updates to outside counsel
- Ignoring rule changes until an audit finding is issued
- Updating an organization's ACH risk policy based on the latest Nacha Operating Rules changes (Correct answer)
Correct answer: Updating an organization's ACH risk policy based on the latest Nacha Operating Rules changes
Updating internal policies based on the latest Nacha Operating Rules changes directly applies APRP knowledge in a practical context.
Question 112: Which term describes the fee levied on a merchant's acquirer (and passed to the merchant) for each chargeback received?
- Chargeback fee (Correct answer)
- Assessment fee
- Dispute resolution fee
- Interchange fee
Correct answer: Chargeback fee
A chargeback fee is charged to the merchant (via the acquirer) each time a chargeback is filed, regardless of the final outcome of the dispute.
Question 113: Which control BEST prevents a single employee from both initiating a payment AND approving that same payment for processing?
- Multi-factor authentication for all payment initiators
- Mandatory password complexity and rotation requirements
- Segregation of duties between payment initiation and payment approval roles (Correct answer)
- Transaction velocity limits on individual user accounts
Correct answer: Segregation of duties between payment initiation and payment approval roles
Segregation of duties (SoD) assigns the initiation and authorization steps of a payment workflow to different individuals, ensuring no single employee can complete a fraudulent transaction without a second party's involvement. MFA and password controls address authentication, not authorization workflow separation.
Question 114: An APRP candidate is preparing a resume. Which section best highlights the credential's relevance to a risk management position?
- Hobbies and interests
- Professional certifications with credential number and issue date (Correct answer)
- References section
- Educational background only
Correct answer: Professional certifications with credential number and issue date
Listing the APRP under professional certifications with the credential number and issuance date provides verifiable proof of expertise to hiring managers.
Question 115: What is the recommended first step a payments risk professional should take when analyzing an unexpected spike in a merchant's chargeback rate?
- Immediately terminate the merchant account
- Categorize chargebacks by reason code to identify the root cause (Correct answer)
- Report the merchant to the card network
- Increase the merchant's reserve requirement without investigation
Correct answer: Categorize chargebacks by reason code to identify the root cause
Categorizing chargebacks by reason code helps identify whether the spike is fraud-related, fulfillment-related, or authorization-related, enabling targeted remediation.
Question 116: A U.S. payments firm processes transactions involving a Cuban national. Which regulatory body enforces the sanctions rules that apply?
- OCC
- FFIEC
- FinCEN
- OFAC (Correct answer)
Correct answer: OFAC
The Office of Foreign Assets Control (OFAC) administers and enforces U.S. economic and trade sanctions, including the Cuba embargo.
Question 117: Which party bears liability for a card-present EMV chip transaction where the merchant has a chip-capable terminal and the issuer has issued a chip card, but fraud still occurs?
- The acquirer
- The issuer (Correct answer)
- The merchant
- The cardholder
Correct answer: The issuer
When both the merchant and issuer have chip capabilities, the issuer bears fraud liability because the chip technology should have prevented the fraud.
Question 118: What documentation best practices should APRP professionals follow?
- Brief notes are always sufficient
- Documentation is only needed for billing purposes
- Documentation can be completed months after the work
- Maintain thorough, accurate, timely records that support findings, decisions, and compliance requirements (Correct answer)
Correct answer: Maintain thorough, accurate, timely records that support findings, decisions, and compliance requirements
Comprehensive documentation provides an audit trail, supports decision-making, facilitates knowledge transfer, and demonstrates compliance with professional standards.
Question 119: A payments processor discovers an unknown USB device plugged into a point-of-sale terminal. What is the FIRST action to take?
- Ignore it if transactions are processing normally
- Remove the device and preserve it as evidence (Correct answer)
- Plug it into an isolated PC to inspect contents
- Format and reuse the device
Correct answer: Remove the device and preserve it as evidence
Removing and preserving the device maintains the chain of custody for forensic investigation without introducing further risk.
Question 120: Under Mastercard's dispute resolution framework, what is the maximum number of days an issuer has to file a chargeback after the transaction processing date for most dispute categories?
- 90 days
- 60 days
- 120 days (Correct answer)
- 180 days
Correct answer: 120 days
Mastercard generally allows issuers 120 days from the transaction processing date to file a chargeback for most dispute reason codes.
Accredited Payments Risk Professional (APRP)
The APRP certification validates expertise in payments risk management across ACH, card, wire, and emerging payment systems. It covers risk identification, controls, governance, information security, and regulatory compliance for payments professionals.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds