← All APRP Flashcard Decks

Fraud Prevention & Detection Flashcards

7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Fraud Prevention & Detection flashcards as text
  1. Which regulatory requirement obligates US financial institutions to file a Suspicious Activity Report (SAR) when fraud is suspected above a certain threshold?

    Answer: Bank Secrecy Act (BSA)

    The Bank Secrecy Act and its implementing regulations require financial institutions to file SARs when transactions suggest criminal activity, including fraud, above reporting thresholds.

  2. A fraud analyst notices that disputed transactions share the same IP geolocation — a country the cardholder has never visited. This is an example of using which fraud signal?

    Answer: Geolocation anomaly detection

    Geolocation anomaly detection compares the transaction origin's IP location against cardholder behavioral history to flag geographically implausible activity.

  3. What distinguishes 'first-party misuse' from 'third-party fraud' in consumer payments?

    Answer: First-party misuse is committed by the account holder; third-party fraud is committed by someone other than the account holder

    First-party misuse means the legitimate account owner abuses the account (e.g., friendly fraud), whereas third-party fraud involves an outside party acting without the account holder's knowledge.

  4. Which data sharing practice helps issuers detect account takeover by alerting them when a cardholder's personal information appears in a known data breach?

    Answer: Dark web monitoring and breach intelligence feeds

    Dark web monitoring services scan criminal marketplaces and breach databases to alert issuers when customer credentials or card data appear, enabling proactive account protection.

  5. A payment risk professional recommends step-up authentication only for transactions above a defined risk threshold. This approach is an example of:

    Answer: Risk-based authentication

    Risk-based authentication applies additional verification only when a transaction's risk score exceeds a threshold, balancing security and customer friction.

  6. In chargeback management, which reason code category is most directly associated with card-not-present fraud on Visa's dispute framework?

    Answer: Fraud (Category 10)

    Visa's Category 10 covers fraud disputes, including 10.4 (card-absent environment), which is the primary CNP fraud chargeback reason code.

  7. Which emerging fraud vector exploits the speed of instant payment rails (e.g., RTP, FedNow) to make fund recovery nearly impossible?

    Answer: Real-time payment fraud through social engineering

    Real-time payment rails settle funds in seconds, and fraudsters exploit this speed through APP scams and account takeover to move money before detection or freezing is possible.