APRP FINAL EXAM ACTUAL QUESTIONS AND ANSWERS
GRADED A+
✔✔Risk Avoidance - ✔✔Informed decision to withdraw from or not become involved
with an activity to avoid exposure to unwanted or unacceptable risks.
✔✔Risk Acceptance with treatment - ✔✔Risks that are monitored and reviewed to
ensure they remain within the risk appetite.
✔✔Risk Acceptance without treatment - ✔✔Risk is accepted as tolerable and falls
within the risk appetite.
✔✔credit policy - ✔✔Clear, written guidelines that set the terms and conditions for
supplying services on credit, qualification criteria, procedures for making collections and
steps to be taken in case of customer delinquency.
✔✔Risk Acceptance - ✔✔Informed decision to accept or take a particular risk.
✔✔Business Continuity Plan(BCP) - ✔✔A comprehensive written plan to maintain or
resume business in the event of a disruption.
✔✔Business Impact Analysis (BIA) - ✔✔Process of identifying the potential impact of
uncontrolled, non-specific events on an institution's business process.
✔✔Business Continuity Strategy - ✔✔Comprehensive strategies to recover, resume
and maintain all critical business functions.
✔✔Risk Mitigation - ✔✔Process of reducing risks through the introduction of specific
controls and risk transfer.
✔✔Transaction Testing - ✔✔A testing activity designed to validate the continuity of
business transactions and the replication of associated date.
✔✔Test Plan - ✔✔A document based on the institutions test scope and objectives and
includes various test methods.
✔✔Business Continuity Test/DisasterRecovery Exercise - ✔✔A test of an institution's
disaster recovery plan or BCP.
✔✔Preventive Controls - ✔✔A mitigating technique designed to prevent an event from
occurring.
✔✔Name the 5 steps in the vendor management lifecycle according to the FFIEC. -
✔✔1.Planning
, 2.Due Diligence in vendor selection
3.Contract Negotiation
4.Ongoing Monitoring
5.Termination
✔✔Name the FTC'S "4 Ps" for evaluating whether a representation, omission, act or
practice is likely to mislead. - ✔✔1.Prominent-will the consumer notice the information?
2.Presented-is the format easy-to-understand?
3.Placement-is the information located where a consumer would expect to look?
4.Proximity-is the information close to the claim in qualifies?
✔✔Anomalous Activity - ✔✔Activity that is inconsistent with or deviating from what is
usual, normal or expected.
✔✔Unfair, Deceptive or Abusive Acts or Practices(UDAAP) - ✔✔Law to protect
consumers purchasing financial products and services requiring that consumers have
access to information that lets them choose the option they believe is best for their
situation.
✔✔Technical Controls - ✔✔Controls to prevent and detect unauthorized activity.
✔✔Procedural Controls - ✔✔Controls that establish policies and procedures that reduce
risk and ensure operating, reporting and compliance objectives are met.
✔✔Administrative Controls - ✔✔Controls that align with board-approved risk appetite
and inform employees of management's expectations.
✔✔Financial Controls - ✔✔Controls to detect and/or prevent errors or
misappropriations.
✔✔At least annually, or more frequently depending on changes in the operating
environment - ✔✔Frequency in with an enterprise-wide business continuity tests should
be conducted.
✔✔At least annually - ✔✔Frequency in with a business continuity plan should be
reviewed by internal or external auditors.
✔✔Exposure Limits - ✔✔A method used to mitigate credit risk, also required by the
ACH Rules.
✔✔Incident Response Plan - ✔✔A plan that defines the action steps, involved
resources and communication strategy upon identification of a threat or potential threat
event, such as a breach in security protocol, power or telecommunication outage,
severe weather or workplace violence.
GRADED A+
✔✔Risk Avoidance - ✔✔Informed decision to withdraw from or not become involved
with an activity to avoid exposure to unwanted or unacceptable risks.
✔✔Risk Acceptance with treatment - ✔✔Risks that are monitored and reviewed to
ensure they remain within the risk appetite.
✔✔Risk Acceptance without treatment - ✔✔Risk is accepted as tolerable and falls
within the risk appetite.
✔✔credit policy - ✔✔Clear, written guidelines that set the terms and conditions for
supplying services on credit, qualification criteria, procedures for making collections and
steps to be taken in case of customer delinquency.
✔✔Risk Acceptance - ✔✔Informed decision to accept or take a particular risk.
✔✔Business Continuity Plan(BCP) - ✔✔A comprehensive written plan to maintain or
resume business in the event of a disruption.
✔✔Business Impact Analysis (BIA) - ✔✔Process of identifying the potential impact of
uncontrolled, non-specific events on an institution's business process.
✔✔Business Continuity Strategy - ✔✔Comprehensive strategies to recover, resume
and maintain all critical business functions.
✔✔Risk Mitigation - ✔✔Process of reducing risks through the introduction of specific
controls and risk transfer.
✔✔Transaction Testing - ✔✔A testing activity designed to validate the continuity of
business transactions and the replication of associated date.
✔✔Test Plan - ✔✔A document based on the institutions test scope and objectives and
includes various test methods.
✔✔Business Continuity Test/DisasterRecovery Exercise - ✔✔A test of an institution's
disaster recovery plan or BCP.
✔✔Preventive Controls - ✔✔A mitigating technique designed to prevent an event from
occurring.
✔✔Name the 5 steps in the vendor management lifecycle according to the FFIEC. -
✔✔1.Planning
, 2.Due Diligence in vendor selection
3.Contract Negotiation
4.Ongoing Monitoring
5.Termination
✔✔Name the FTC'S "4 Ps" for evaluating whether a representation, omission, act or
practice is likely to mislead. - ✔✔1.Prominent-will the consumer notice the information?
2.Presented-is the format easy-to-understand?
3.Placement-is the information located where a consumer would expect to look?
4.Proximity-is the information close to the claim in qualifies?
✔✔Anomalous Activity - ✔✔Activity that is inconsistent with or deviating from what is
usual, normal or expected.
✔✔Unfair, Deceptive or Abusive Acts or Practices(UDAAP) - ✔✔Law to protect
consumers purchasing financial products and services requiring that consumers have
access to information that lets them choose the option they believe is best for their
situation.
✔✔Technical Controls - ✔✔Controls to prevent and detect unauthorized activity.
✔✔Procedural Controls - ✔✔Controls that establish policies and procedures that reduce
risk and ensure operating, reporting and compliance objectives are met.
✔✔Administrative Controls - ✔✔Controls that align with board-approved risk appetite
and inform employees of management's expectations.
✔✔Financial Controls - ✔✔Controls to detect and/or prevent errors or
misappropriations.
✔✔At least annually, or more frequently depending on changes in the operating
environment - ✔✔Frequency in with an enterprise-wide business continuity tests should
be conducted.
✔✔At least annually - ✔✔Frequency in with a business continuity plan should be
reviewed by internal or external auditors.
✔✔Exposure Limits - ✔✔A method used to mitigate credit risk, also required by the
ACH Rules.
✔✔Incident Response Plan - ✔✔A plan that defines the action steps, involved
resources and communication strategy upon identification of a threat or potential threat
event, such as a breach in security protocol, power or telecommunication outage,
severe weather or workplace violence.