← All APRP Flashcard Decks

APRP Quality & Compliance Flashcards

7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 APRP Quality & Compliance flashcards as text
  1. Which data element, if compromised, allows fraudsters to clone a physical payment card?

    Answer: Track 1 or Track 2 magnetic stripe data

    Track 1 and Track 2 magnetic stripe data contain all information needed to encode a counterfeit card, making their protection critical under PCI DSS.

  2. An APRP candidate reviews a processor's audit findings and sees 'scope creep' flagged as a deficiency. What does this mean in a PCI DSS context?

    Answer: Systems that touch cardholder data were added without updating the cardholder data environment boundary

    PCI DSS scope creep occurs when new systems enter the cardholder data environment without proper documentation and security controls being applied to them.

  3. What is 'network tokenization' and how does it improve payment security?

    Answer: Substituting a PAN with a token issued by the card network, valid only for a specific merchant or device

    Network tokenization replaces sensitive PANs with network-issued tokens scoped to a specific merchant or device, limiting the value of intercepted payment credentials.

  4. A bank files a Suspicious Activity Report (SAR) on a customer. Under BSA regulations, what is the bank prohibited from doing?

    Answer: Disclosing to the customer that a SAR has been filed

    BSA regulations prohibit 'tipping off' — informing the subject of a SAR that one has been filed, to avoid alerting potential money launderers.

  5. In the context of payments compliance, what does 'regulatory capital' refer to for an acquiring bank?

    Answer: Capital reserves that regulators require banks to hold against risk-weighted assets

    Regulatory capital refers to the minimum capital buffers mandated by bank regulators (such as under Basel III) to absorb losses from risk-weighted exposures.

  6. Which of the following is an example of a 'preventive' control in a payments fraud management program?

    Answer: Real-time velocity checking that blocks transactions exceeding defined thresholds

    Real-time velocity checking prevents fraudulent transactions from completing, making it a preventive control that acts before the harm occurs.

  7. A payments risk professional is asked to evaluate a new fintech partner's compliance posture. Which document would BEST demonstrate the partner's security controls to a third party?

    Answer: A SOC 2 Type II audit report

    A SOC 2 Type II report provides independent third-party validation that a service organization's controls are designed effectively and operated consistently over a period of time.