Payment Processing & Security Flashcards
7 cards from real CEC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Payment Processing & Security flashcards as text
Which payment method type typically has the lowest dispute rate in ecommerce transactions?
Answer: ACH bank transfers
ACH transfers have very low dispute rates because they are bank-to-bank transactions with strict identity verification and limited chargeback rights compared to credit cards.
What is the function of the Card Verification Value 2 (CVV2) in card-not-present transactions?
Answer: It proves the customer physically has the card since it is not stored in the magnetic stripe
CVV2 is not stored on the magnetic stripe or chip, so requiring it in CNP transactions helps confirm the customer has the physical card.
A merchant enables '3D Secure 2.0' for their checkout. Which outcome is most likely for low-risk transactions?
Answer: Low-risk transactions will be frictionlessly authenticated using shared data
3DS 2.0 supports frictionless flow, where rich contextual data is shared with the issuer to authenticate low-risk transactions without presenting a challenge to the user.
What is 'friendly fraud' in the context of ecommerce chargebacks?
Answer: A chargeback filed by a cardholder who legitimately received the goods but claims otherwise
Friendly fraud occurs when a legitimate cardholder deliberately disputes a valid charge—claiming non-receipt or unauthorized use—to obtain a refund while keeping the merchandise.
Which PCI DSS requirement specifically governs the use of firewalls to protect cardholder data?
Answer: Requirement 1: Install and maintain network security controls
PCI DSS Requirement 1 mandates installing and maintaining network security controls, including firewalls, to protect the cardholder data environment.
An ecommerce merchant wants to reduce processing fees for premium rewards cards. Which strategy is most effective?
Answer: Collect additional Level 2 or Level 3 transaction data
Submitting Level 2 (tax amount, customer code) or Level 3 (line-item detail) data qualifies transactions for lower interchange rates, even on premium cards.
What is the primary security risk of using a shared SSL certificate across multiple ecommerce domains?
Answer: A compromise of one domain can expose all domains sharing the certificate
A wildcard or shared SSL certificate means that if the private key is compromised on one domain, all domains using that certificate are exposed.