← All CEC Flashcard Decks

Payment Processing & Security Flashcards

7 cards from real CEC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Payment Processing & Security flashcards as text
  1. What does the term 'chargeback ratio' refer to in ecommerce payment processing?

    Answer: The percentage of transactions disputed by cardholders relative to total transactions

    Chargeback ratio is the number of chargebacks divided by total transactions, and card networks penalize merchants who exceed thresholds (typically 1%).

  2. Which tokenization method replaces a customer's stored payment card data with a non-sensitive placeholder?

    Answer: Network tokenization

    Network tokenization, offered by card networks like Visa and Mastercard, replaces the PAN with a network-issued token that is tied to a specific merchant or device.

  3. An ecommerce merchant processes $500,000/month in card-not-present transactions. Which PCI DSS merchant level applies?

    Answer: Level 2

    PCI DSS Level 2 applies to merchants processing 1 million to 6 million card-not-present transactions annually, which equates to roughly $83K–$500K+ per month in volume context.

  4. What is the primary purpose of a payment facilitator (PayFac) model in ecommerce?

    Answer: To allow sub-merchants to accept payments under a master merchant account

    A PayFac sponsors sub-merchants under its own master merchant account, enabling faster onboarding without each business needing its own acquiring bank relationship.

  5. Which fraud prevention technique uses behavioral data like typing speed and mouse movement to verify identity?

    Answer: Behavioral biometrics

    Behavioral biometrics analyzes how users interact with devices—typing cadence, mouse patterns—to passively verify identity without friction.

  6. What does 'interchange-plus' pricing mean for a merchant accepting credit cards?

    Answer: The actual interchange cost plus a fixed processor markup

    Interchange-plus (cost-plus) pricing passes the exact interchange fee set by card networks to the merchant plus a fixed processor markup, offering full transparency.

  7. In the context of ecommerce security, what is a 'man-in-the-browser' attack?

    Answer: Malware that intercepts and modifies browser transactions in real time

    Man-in-the-browser (MitB) attacks use trojans embedded in the browser to intercept and alter transactions after the user has authenticated, bypassing standard SSL protections.