Emerging Payment Risks Flashcards
7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Emerging Payment Risks flashcards as text
Which type of attack specifically targets the enrollment phase of biometric authentication in mobile payment apps?
Answer: Presentation attack using a spoofed fingerprint or face mask
Presentation attacks at enrollment inject fake biometric samples (spoofed fingerprints, 3D-printed faces) to register an attacker's biometric as the legitimate user's credential.
What distinguishes a 'push payment fraud' from traditional card fraud in terms of recovery options?
Answer: Push payments have no chargeback mechanism, making recovery largely dependent on voluntary bank cooperation
Push payments (like Zelle or wire transfers) are authorized by the consumer, so no card network chargeback right exists; recovery depends on receiving bank cooperation or litigation.
In the context of tokenization for digital wallets, what risk does 'token requestor compromise' represent?
Answer: A compromised token requestor can request and stockpile tokens tied to real PANs for later fraud
If a token requestor (e.g., a digital wallet provider) is compromised, attackers can generate large numbers of payment tokens linked to real account numbers and use them for fraudulent transactions.
A BNPL provider offers instant credit without a hard credit check. Which risk does this practice most directly increase for the payment ecosystem?
Answer: Systemic counterparty credit risk when BNPL providers extend beyond their capital base
BNPL providers extending credit without robust credit checks build portfolios of potentially high-risk borrowers, and if losses exceed capital, their inability to honor merchant settlements creates systemic risk.
Which characteristic of real-time payment systems (e.g., RTP, FedNow) makes fraud prevention fundamentally harder than in batch ACH processing?
Answer: The irrevocability and speed leave no window for pre-settlement fraud intervention
Real-time payments settle in seconds and are typically irrevocable, eliminating the hours-long batch window where traditional fraud controls could flag and recall suspicious ACH transactions.
An e-money institution offers a multi-currency digital wallet. Which operational risk is most amplified by real-time FX conversion features?
Answer: Basis risk from mismatched FX hedge durations during high-volatility periods
Real-time FX conversion exposes the institution to basis risk when hedges are executed at different times or tenors than the underlying customer transactions during volatile market conditions.
What is 'credential stuffing' and why is it particularly dangerous in the context of stored payment credentials?
Answer: Using breached username/password pairs to take over accounts containing stored payment methods
Credential stuffing automates login attempts using username/password pairs from prior breaches, and success gives attackers access to stored payment methods for immediate fraudulent use.