โ† All CEC Flashcard Decks

Payment Processing & Security Flashcards

7 cards from real CEC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Payment Processing & Security flashcards as text
  1. Which EMV technology feature is most effective at preventing counterfeit card fraud at card-present terminals?

    Answer: Dynamic cryptogram generated per transaction

    EMV chips generate a unique cryptogram for each transaction, making it virtually impossible to create a usable counterfeit card even if the data is captured.

  2. What is the role of an acquirer (acquiring bank) in the payment processing chain?

    Answer: Processes transactions on behalf of merchants and settles funds

    The acquiring bank maintains the merchant's account, processes transactions through card networks, and deposits settlement funds into the merchant's account.

  3. A customer's card is declined with response code 'Do Not Honor.' What should an ecommerce merchant do?

    Answer: Prompt the customer to use an alternative payment method

    A 'Do Not Honor' decline is a soft decline from the issuing bank; the merchant should prompt the customer to contact their bank or use a different card.

  4. Which of the following best describes 'strong customer authentication' (SCA) under PSD2 regulations?

    Answer: Verification using at least two of: something you know, have, or are

    SCA under PSD2 requires at least two independent authentication factors from the categories of knowledge, possession, and inherence to verify the customer's identity.

  5. What is 'velocity checking' in the context of ecommerce fraud prevention?

    Answer: Monitoring the frequency of transactions from a single source within a time window

    Velocity checking flags suspicious patterns by counting how many transactions originate from the same card, IP, device, or email within a defined timeframe.

  6. An ecommerce site stores encrypted cardholder data in its database. Under PCI DSS, what additional requirement applies?

    Answer: The encryption keys must be managed separately from the encrypted data

    PCI DSS requires that encryption keys be stored and managed separately from the data they encrypt to prevent a single point of compromise.

  7. What distinguishes a 'soft decline' from a 'hard decline' in payment processing?

    Answer: Soft declines are temporary and retriable; hard declines are permanent rejections

    Soft declines are temporary rejections (e.g., insufficient funds, authentication needed) that may succeed on retry, while hard declines (e.g., stolen card) are permanent.