APRP EOC EXAM PREP QUESTIONS AND ANSWERS
✔✔Business Continuity Strategy - ✔✔Comprehensive strategies to recover, resume
and maintain all critical business functions.
✔✔Risk Mitigation - ✔✔Process of reducing risks through the introduction of specific
controls and risk transfer.
✔✔Transaction Testing - ✔✔A testing activity designed to validate the continuity of
business transactions and the replication of associated date.
✔✔Test Plan - ✔✔A document based on the institutions test scope and objectives and
includes various test methods.
✔✔Business Continuity Test/DisasterRecovery Exercise - ✔✔A test of an institution's
disaster recovery plan or BCP.
✔✔Preventive Controls - ✔✔A mitigating technique designed to prevent an event from
occurring.
✔✔Name the 5 steps in the vendor management lifecycle according to the FFIEC. -
✔✔1.Planning
2.Due Diligence in vendor selection
3.Contract Negotiation
4.Ongoing Monitoring
5.Termination
✔✔Name the FTC'S "4 Ps" for evaluating whether a representation, omission, act or
practice is likely to mislead. - ✔✔1.Prominent-will the consumer notice the information?
2.Presented-is the format easy-to-understand?
3.Placement-is the information located where a consumer would expect to look?
4.Proximity-is the information close to the claim in qualifies?
✔✔Anomalous Activity - ✔✔Activity that is inconsistent with or deviating from what is
usual, normal or expected.
✔✔Unfair, Deceptive or Abusive Acts or Practices(UDAAP) - ✔✔Law to protect
consumers purchasing financial products and services requiring that consumers have
access to information that lets them choose the option they believe is best for their
situation.
✔✔Technical Controls - ✔✔Controls to prevent and detect unauthorized activity.
, ✔✔Procedural Controls - ✔✔Controls that establish policies and procedures that reduce
risk and ensure operating, reporting and compliance objectives are met.
✔✔Administrative Controls - ✔✔Controls that align with board-approved risk appetite
and inform employees of management's expectations.
✔✔Financial Controls - ✔✔Controls to detect and/or prevent errors or
misappropriations.
✔✔At least annually, or more frequently depending on changes in the operating
environment - ✔✔Frequency in with an enterprise-wide business continuity tests should
be conducted.
✔✔At least annually - ✔✔Frequency in with a business continuity plan should be
reviewed by internal or external auditors.
✔✔Exposure Limits - ✔✔A method used to mitigate credit risk, also required by the
ACH Rules.
✔✔Incident Response Plan - ✔✔A plan that defines the action steps, involved
resources and communication strategy upon identification of a threat or potential threat
event, such as a breach in security protocol, power or telecommunication outage,
severe weather or workplace violence.
✔✔Control Self-Assessment (CSA) - ✔✔A technique used to internally assess the
effectiveness of risk management and control processes.
✔✔Risk Assessment - ✔✔Step in the BCP process that evaluates business processes
and BIA assumptions using various threat scenarios.
✔✔Business Impact Analysis - ✔✔Step in the BCP process that identifies the potential
impact of uncontrolled, non-specific events on an institutions business processes.
✔✔Tabletop Exercise/Structured Walk-Through test - ✔✔Testing method ensures
critical personnel from all areas are familiar with the business continuity plan(BCP) and
may be used as an effective training tool.
✔✔Walk-Through Drill/Simulation Test - ✔✔Testing method used to apply a specific
event scenario to the business continuity plan.
✔✔Functional Drill/Parallel Test - ✔✔Testing method involves actual mobilization of
personnel to other sites attempting to establish communications and perform actual
recovery processing as outlined in the business continuity plan.
✔✔Business Continuity Strategy - ✔✔Comprehensive strategies to recover, resume
and maintain all critical business functions.
✔✔Risk Mitigation - ✔✔Process of reducing risks through the introduction of specific
controls and risk transfer.
✔✔Transaction Testing - ✔✔A testing activity designed to validate the continuity of
business transactions and the replication of associated date.
✔✔Test Plan - ✔✔A document based on the institutions test scope and objectives and
includes various test methods.
✔✔Business Continuity Test/DisasterRecovery Exercise - ✔✔A test of an institution's
disaster recovery plan or BCP.
✔✔Preventive Controls - ✔✔A mitigating technique designed to prevent an event from
occurring.
✔✔Name the 5 steps in the vendor management lifecycle according to the FFIEC. -
✔✔1.Planning
2.Due Diligence in vendor selection
3.Contract Negotiation
4.Ongoing Monitoring
5.Termination
✔✔Name the FTC'S "4 Ps" for evaluating whether a representation, omission, act or
practice is likely to mislead. - ✔✔1.Prominent-will the consumer notice the information?
2.Presented-is the format easy-to-understand?
3.Placement-is the information located where a consumer would expect to look?
4.Proximity-is the information close to the claim in qualifies?
✔✔Anomalous Activity - ✔✔Activity that is inconsistent with or deviating from what is
usual, normal or expected.
✔✔Unfair, Deceptive or Abusive Acts or Practices(UDAAP) - ✔✔Law to protect
consumers purchasing financial products and services requiring that consumers have
access to information that lets them choose the option they believe is best for their
situation.
✔✔Technical Controls - ✔✔Controls to prevent and detect unauthorized activity.
, ✔✔Procedural Controls - ✔✔Controls that establish policies and procedures that reduce
risk and ensure operating, reporting and compliance objectives are met.
✔✔Administrative Controls - ✔✔Controls that align with board-approved risk appetite
and inform employees of management's expectations.
✔✔Financial Controls - ✔✔Controls to detect and/or prevent errors or
misappropriations.
✔✔At least annually, or more frequently depending on changes in the operating
environment - ✔✔Frequency in with an enterprise-wide business continuity tests should
be conducted.
✔✔At least annually - ✔✔Frequency in with a business continuity plan should be
reviewed by internal or external auditors.
✔✔Exposure Limits - ✔✔A method used to mitigate credit risk, also required by the
ACH Rules.
✔✔Incident Response Plan - ✔✔A plan that defines the action steps, involved
resources and communication strategy upon identification of a threat or potential threat
event, such as a breach in security protocol, power or telecommunication outage,
severe weather or workplace violence.
✔✔Control Self-Assessment (CSA) - ✔✔A technique used to internally assess the
effectiveness of risk management and control processes.
✔✔Risk Assessment - ✔✔Step in the BCP process that evaluates business processes
and BIA assumptions using various threat scenarios.
✔✔Business Impact Analysis - ✔✔Step in the BCP process that identifies the potential
impact of uncontrolled, non-specific events on an institutions business processes.
✔✔Tabletop Exercise/Structured Walk-Through test - ✔✔Testing method ensures
critical personnel from all areas are familiar with the business continuity plan(BCP) and
may be used as an effective training tool.
✔✔Walk-Through Drill/Simulation Test - ✔✔Testing method used to apply a specific
event scenario to the business continuity plan.
✔✔Functional Drill/Parallel Test - ✔✔Testing method involves actual mobilization of
personnel to other sites attempting to establish communications and perform actual
recovery processing as outlined in the business continuity plan.