Skip to content

AFC-CERT Anti-Fraud Controls Certificate Program Practice Questions

Prepare for AFC-CERT with more than an answer.

108 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$417 USD
Level
Certificate (Non-Credential)
Valid for
Lifetime (does not expire)
Domains covered on the exam 3
  1. Internal Controls for Data Security22%
  2. Internal Controls for Fraud Prevention45%
  3. Evaluating and Testing Anti-Fraud Controls33%
  1. 1

    A network architect is designing a secure network for a financial application involving a web server, an application server, and a database server. To minimize the impact of a potential web server compromise, where should the database server be placed?

    Show answer details

    Correct answer: B

    The database contains the most sensitive data and should be placed in the deepest layer of the network (private subnet). The web server (in the DMZ) should talk to the app server, which talks to the database. This tiered architecture ensures that if the public-facing web server is compromised, the attacker still faces an internal firewall to reach the data.

    graph TD Internet((Internet)) --> FW1[External Firewall] FW1 --> DMZ[DMZ: Web Server] DMZ --> FW2[Internal Firewall] FW2 --> App[App Server] App --> DB[(Database: Private Subnet)]
  2. 2

    In an IT environment, allowing a single developer to write code, test it, and deploy it to the production environment violates which internal control principle?

    Show answer details

    Correct answer: D

    Separation of Duties in IT requires distinguishing between development, testing, and production roles. If one person can do all three, they can introduce malicious code (fraud) into production without independent oversight. Developers should generally not have write access to the production environment.

  3. 3

    An organization wants to protect sensitive customer data stored on backup tapes that are transported off-site. Which control provides the BEST protection against data confidentiality loss if the tapes are stolen during transport?

    Show answer details

    Correct answer: D

    Encryption ensures that even if the physical media (tapes) are stolen, the data remains unreadable without the decryption key. While tamper seals indicate if theft occurred, they do not prevent data access. GPS tracking locates the truck but doesn't protect the data itself.

  4. 4

    A multinational corporation is migrating its customer relationship management (CRM) system to a SaaS cloud provider. The Chief Risk Officer is concerned about data security responsibilities. Under the shared responsibility model for SaaS, which of the following security controls remains the primary responsibility of the customer organization?

    Show answer details

    Correct answer: B

    In a SaaS model, the cloud provider manages the infrastructure, physical security, network controls, and application patching. The customer retains responsibility for data classification, identity and access management (IAM), and endpoint device protection. Controlling who accesses the data and how they are authenticated is a critical customer responsibility.

  5. 5

    A financial institution is implementing a Bring Your Own Device (BYOD) policy. To mitigate the risk of corporate data leakage on personal devices without violating employee privacy, which technical control is most appropriate?

    Show answer details

    Correct answer: C

    Containerization (often deployed via MAM) isolates corporate data and applications from personal data on the same device. This allows the organization to control, encrypt, and selectively wipe only the corporate container without accessing or erasing the employee's personal photos, contacts, or applications, balancing security with privacy.

  6. 6

    While auditing logical access controls, an auditor discovers that a senior database administrator (DBA) has the ability to both modify the database schema and delete audit logs. This violation of the principle of least privilege poses a significant risk of:

    Show answer details

    Correct answer: C

    The ability to delete audit logs allows a perpetrator to cover their tracks. If a DBA can manipulate data (schema or content) and also delete the records of those actions (logs), they have the perfect opportunity to commit fraud and conceal it. This is a classic segregation of duties conflict.

Create an account to continue.