โ† All APRP Flashcard Decks

Emerging Payment Risks Flashcards

7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Emerging Payment Risks flashcards as text
  1. Which type of attack specifically targets the enrollment phase of biometric authentication in mobile payment apps?

    Answer: Presentation attack using a spoofed fingerprint or face mask

    Presentation attacks at enrollment inject fake biometric samples (spoofed fingerprints, 3D-printed faces) to register an attacker's biometric as the legitimate user's credential.

  2. What distinguishes a 'push payment fraud' from traditional card fraud in terms of recovery options?

    Answer: Push payments have no chargeback mechanism, making recovery largely dependent on voluntary bank cooperation

    Push payments (like Zelle or wire transfers) are authorized by the consumer, so no card network chargeback right exists; recovery depends on receiving bank cooperation or litigation.

  3. In the context of tokenization for digital wallets, what risk does 'token requestor compromise' represent?

    Answer: A compromised token requestor can request and stockpile tokens tied to real PANs for later fraud

    If a token requestor (e.g., a digital wallet provider) is compromised, attackers can generate large numbers of payment tokens linked to real account numbers and use them for fraudulent transactions.

  4. A BNPL provider offers instant credit without a hard credit check. Which risk does this practice most directly increase for the payment ecosystem?

    Answer: Systemic counterparty credit risk when BNPL providers extend beyond their capital base

    BNPL providers extending credit without robust credit checks build portfolios of potentially high-risk borrowers, and if losses exceed capital, their inability to honor merchant settlements creates systemic risk.

  5. Which characteristic of real-time payment systems (e.g., RTP, FedNow) makes fraud prevention fundamentally harder than in batch ACH processing?

    Answer: The irrevocability and speed leave no window for pre-settlement fraud intervention

    Real-time payments settle in seconds and are typically irrevocable, eliminating the hours-long batch window where traditional fraud controls could flag and recall suspicious ACH transactions.

  6. An e-money institution offers a multi-currency digital wallet. Which operational risk is most amplified by real-time FX conversion features?

    Answer: Basis risk from mismatched FX hedge durations during high-volatility periods

    Real-time FX conversion exposes the institution to basis risk when hedges are executed at different times or tenors than the underlying customer transactions during volatile market conditions.

  7. What is 'credential stuffing' and why is it particularly dangerous in the context of stored payment credentials?

    Answer: Using breached username/password pairs to take over accounts containing stored payment methods

    Credential stuffing automates login attempts using username/password pairs from prior breaches, and success gives attackers access to stored payment methods for immediate fraudulent use.