APRP Industry Standards Flashcards
7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 APRP Industry Standards flashcards as text
Which PCI DSS requirement specifically mandates that cardholder data must not be stored after authorization?
Answer: Requirement 3
PCI DSS Requirement 3 governs the protection of stored cardholder data, including prohibitions on storing sensitive authentication data after authorization.
Under NACHA Operating Rules, what is the maximum dollar threshold per transaction for Same Day ACH entries?
Answer: $100,000
NACHA set the Same Day ACH per-transaction cap at $100,000, effective March 2020, to support higher-value business payments.
The ISO 20022 messaging standard is primarily designed to improve which aspect of payments?
Answer: Rich data and interoperability across payment systems
ISO 20022 provides a universal financial messaging standard enabling richer data and greater interoperability across domestic and international payment systems.
Which Regulation E provision requires financial institutions to investigate disputes and provisionally credit consumer accounts within a specific timeframe?
Answer: 10 business days
Regulation E requires financial institutions to complete error resolution investigations within 10 business days, or provisionally credit the account while extending the investigation.
What does the FFIEC define as a key element of layered security for online banking?
Answer: Anomaly detection and out-of-band transaction verification
FFIEC guidance identifies anomaly detection coupled with out-of-band verification for high-risk transactions as critical components of effective layered security.
Under the Card Brand Rules, what is the standard chargeback representment window for Visa disputes?
Answer: 45 days
Visa's dispute rules generally allow merchants 45 days to respond to a chargeback with representment documentation.
The EMVCo 3-D Secure (3DS2) protocol introduces which key capability over the original 3DS1?
Answer: Risk-based authentication using rich data from the merchant
3DS2 enables risk-based authentication by passing rich transaction and device data from the merchant to the issuer, allowing frictionless flows for low-risk transactions.