APRP COMPREHENSIVE EXAM UPDATED QUESTIONS AND
ANSWERS GRADED A+
✔✔Business Continuity Plan (BCP) - ✔✔A comprehensive written plan to maintain or
resume business in the event of a disruption.
✔✔Encryption - ✔✔A data security technique that encodes information so that data
appears as a meaningless string of letters and symbols during delivery or transmission.
✔✔Test Plan - ✔✔A document based on the institution's test scope and objectives and
includes various test methods.
✔✔RDFI - Receiving Depository Financial Institution - ✔✔A financial instituion that
receives ACH entries from the ACH Operator and posts the entries to the accounts of its
depositors.
✔✔ODFI - Originating Depository Financial Institution - ✔✔A financial institution that
receives payment instructions from Originators and forwards the entries to the ACH
Operator.
✔✔Exposure Limits - ✔✔A method used to mitigate credit risk, required by the ACH
Rules
✔✔Debit Card - ✔✔A payment card issued to a person for purchasing goods and
services thorugh an electronic transfer of funds from a dempand deposit account rather
than using cash, checks or drafts at the point-of-sale.
✔✔Cardholder - ✔✔A person or entity that is issued a credit or debit account that is
accessed using a card.
✔✔API - Application Program Interface - ✔✔A set of specifications, standards or
conventions that enable computer programs to exchange information.
✔✔Business Continuity Test/Disaster Recovery Exercise - ✔✔A test of an institution's
disaster recovery plan or BCP.
✔✔Transaction Testing - ✔✔A testing activity designed to validate the continuity of
business transactions and the replication of associated data.
✔✔Third-Party Service Provider - ✔✔A third-party that processes ACH files and/or
entries on behalf of financial institutions and/or Originators.
✔✔Third Party Sender - ✔✔A third-party that provides ACH services to the Originator,
and, in that capacity, acts as an intermediary between the Originator and ODFI.
, ✔✔DLT - Distributed Ledger Technology - ✔✔A type of database that is consensually
shared and synchronized across nodes in a network spread across multiple sites,
institutions or geographies.
✔✔Clearing House - ✔✔A voluntary association of depository institutions that facilitate
the clearing of checks or electronic items through the direct exchange of funds between
members.
✔✔Vulnerability - ✔✔A weakness in automated system security procedures,
administrative controls, physical layout, internal controls, etc that could be exploited to
gain unauthorized access to information or to disrupt critical processing.
✔✔Risk Tolerance - ✔✔Acceptable level of variation relative to achievement of a
specific objective.
✔✔Physical Access Control - ✔✔Access control that limits access to buildings, rooms
and physical IT assets.
✔✔Logical Access Control - ✔✔Access control that limits connections to computer
networks, system files and data.
✔✔USA PATRIOT Act - ✔✔Act broadened the scope of the Bank Secrecy Act to focus
on terrorist financing.
✔✔Bank Secrecy Act (BSA) - ✔✔Act requires financial institutions to assist U.S.
government agencies to detect and prevent money laundering.
✔✔Gramm-Leach Bliley Act (GLBA) - ✔✔Act, also know as the Financial Services
Modernization Act of 1999, required federal banking agencies to establish information
security standards for financial institutions.
✔✔Anomalous Activity - ✔✔Activity that is inconsistent with or deviating from what is
usual, normal or expected.
✔✔Office of Foreign Assets Control (OFAC) - ✔✔Administers economic sanctions and
embargo programs that require assests and transactions involving the interest of
targeted parties be frozen.
✔✔Risk Appetite - ✔✔Amount of risk, on a broad level, an entity is willing to accept in
pursuit of value.
✔✔Card Issuer - ✔✔An entity that issues a credit or debit card to the Cardholder.
ANSWERS GRADED A+
✔✔Business Continuity Plan (BCP) - ✔✔A comprehensive written plan to maintain or
resume business in the event of a disruption.
✔✔Encryption - ✔✔A data security technique that encodes information so that data
appears as a meaningless string of letters and symbols during delivery or transmission.
✔✔Test Plan - ✔✔A document based on the institution's test scope and objectives and
includes various test methods.
✔✔RDFI - Receiving Depository Financial Institution - ✔✔A financial instituion that
receives ACH entries from the ACH Operator and posts the entries to the accounts of its
depositors.
✔✔ODFI - Originating Depository Financial Institution - ✔✔A financial institution that
receives payment instructions from Originators and forwards the entries to the ACH
Operator.
✔✔Exposure Limits - ✔✔A method used to mitigate credit risk, required by the ACH
Rules
✔✔Debit Card - ✔✔A payment card issued to a person for purchasing goods and
services thorugh an electronic transfer of funds from a dempand deposit account rather
than using cash, checks or drafts at the point-of-sale.
✔✔Cardholder - ✔✔A person or entity that is issued a credit or debit account that is
accessed using a card.
✔✔API - Application Program Interface - ✔✔A set of specifications, standards or
conventions that enable computer programs to exchange information.
✔✔Business Continuity Test/Disaster Recovery Exercise - ✔✔A test of an institution's
disaster recovery plan or BCP.
✔✔Transaction Testing - ✔✔A testing activity designed to validate the continuity of
business transactions and the replication of associated data.
✔✔Third-Party Service Provider - ✔✔A third-party that processes ACH files and/or
entries on behalf of financial institutions and/or Originators.
✔✔Third Party Sender - ✔✔A third-party that provides ACH services to the Originator,
and, in that capacity, acts as an intermediary between the Originator and ODFI.
, ✔✔DLT - Distributed Ledger Technology - ✔✔A type of database that is consensually
shared and synchronized across nodes in a network spread across multiple sites,
institutions or geographies.
✔✔Clearing House - ✔✔A voluntary association of depository institutions that facilitate
the clearing of checks or electronic items through the direct exchange of funds between
members.
✔✔Vulnerability - ✔✔A weakness in automated system security procedures,
administrative controls, physical layout, internal controls, etc that could be exploited to
gain unauthorized access to information or to disrupt critical processing.
✔✔Risk Tolerance - ✔✔Acceptable level of variation relative to achievement of a
specific objective.
✔✔Physical Access Control - ✔✔Access control that limits access to buildings, rooms
and physical IT assets.
✔✔Logical Access Control - ✔✔Access control that limits connections to computer
networks, system files and data.
✔✔USA PATRIOT Act - ✔✔Act broadened the scope of the Bank Secrecy Act to focus
on terrorist financing.
✔✔Bank Secrecy Act (BSA) - ✔✔Act requires financial institutions to assist U.S.
government agencies to detect and prevent money laundering.
✔✔Gramm-Leach Bliley Act (GLBA) - ✔✔Act, also know as the Financial Services
Modernization Act of 1999, required federal banking agencies to establish information
security standards for financial institutions.
✔✔Anomalous Activity - ✔✔Activity that is inconsistent with or deviating from what is
usual, normal or expected.
✔✔Office of Foreign Assets Control (OFAC) - ✔✔Administers economic sanctions and
embargo programs that require assests and transactions involving the interest of
targeted parties be frozen.
✔✔Risk Appetite - ✔✔Amount of risk, on a broad level, an entity is willing to accept in
pursuit of value.
✔✔Card Issuer - ✔✔An entity that issues a credit or debit card to the Cardholder.