APRP Quality & Compliance Flashcards
7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 APRP Quality & Compliance flashcards as text
Under PCI DSS, what is the maximum period allowed between required internal vulnerability scans?
Answer: 90 days
PCI DSS requires internal vulnerability scans to be performed at least quarterly (every 90 days).
A merchant's chargeback rate exceeds the card network's threshold for two consecutive months. What program does this typically trigger?
Answer: Chargeback Monitoring Program
Card networks place merchants whose chargeback rates exceed defined thresholds into a Chargeback Monitoring Program, which imposes fees and remediation requirements.
Which BSA/AML control requires financial institutions to identify and verify the identity of beneficial owners of legal entity customers?
Answer: Customer Due Diligence (CDD) Rule
FinCEN's CDD Rule requires covered institutions to collect and verify beneficial ownership information for legal entity customers.
A quality assurance review finds that a payments processor is approving transactions without verifying CVV2 for card-not-present purchases. Which compliance domain is most directly violated?
Answer: PCI DSS Requirement 3
PCI DSS Requirement 3 governs the protection of stored cardholder data, including restrictions on storing sensitive authentication data such as CVV2 after authorization.
What does a 'Risk-Based Approach' to AML compliance mean in practice?
Answer: Allocating more compliance resources to higher-risk customers and transactions
A risk-based approach concentrates AML resources and enhanced due diligence on customers and transactions assessed as higher risk.
Which metric is the PRIMARY indicator used to measure the effectiveness of a fraud prevention program?
Answer: Fraud loss as a percentage of sales volume
Fraud loss as a percentage of sales volume (fraud rate) is the standard KPI for measuring fraud prevention effectiveness relative to business scale.
An issuer notices a pattern where stolen card data is tested with small micro-transactions before large fraudulent purchases. What fraud tactic is this?
Answer: Card testing (BIN attack)
Card testing, also known as a BIN attack, involves using small transactions to validate stolen card credentials before committing larger fraud.