โ† All APRP Flashcard Decks

APRP Quality & Compliance Flashcards

7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 APRP Quality & Compliance flashcards as text
  1. Under PCI DSS, what is the maximum period allowed between required internal vulnerability scans?

    Answer: 90 days

    PCI DSS requires internal vulnerability scans to be performed at least quarterly (every 90 days).

  2. A merchant's chargeback rate exceeds the card network's threshold for two consecutive months. What program does this typically trigger?

    Answer: Chargeback Monitoring Program

    Card networks place merchants whose chargeback rates exceed defined thresholds into a Chargeback Monitoring Program, which imposes fees and remediation requirements.

  3. Which BSA/AML control requires financial institutions to identify and verify the identity of beneficial owners of legal entity customers?

    Answer: Customer Due Diligence (CDD) Rule

    FinCEN's CDD Rule requires covered institutions to collect and verify beneficial ownership information for legal entity customers.

  4. A quality assurance review finds that a payments processor is approving transactions without verifying CVV2 for card-not-present purchases. Which compliance domain is most directly violated?

    Answer: PCI DSS Requirement 3

    PCI DSS Requirement 3 governs the protection of stored cardholder data, including restrictions on storing sensitive authentication data such as CVV2 after authorization.

  5. What does a 'Risk-Based Approach' to AML compliance mean in practice?

    Answer: Allocating more compliance resources to higher-risk customers and transactions

    A risk-based approach concentrates AML resources and enhanced due diligence on customers and transactions assessed as higher risk.

  6. Which metric is the PRIMARY indicator used to measure the effectiveness of a fraud prevention program?

    Answer: Fraud loss as a percentage of sales volume

    Fraud loss as a percentage of sales volume (fraud rate) is the standard KPI for measuring fraud prevention effectiveness relative to business scale.

  7. An issuer notices a pattern where stolen card data is tested with small micro-transactions before large fraudulent purchases. What fraud tactic is this?

    Answer: Card testing (BIN attack)

    Card testing, also known as a BIN attack, involves using small transactions to validate stolen card credentials before committing larger fraud.

APRP Quality & Compliance Flashcards โ€” APRP Study Cards with Answers