Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which of the following is an insurance fraud detection tool used for identifying funds fraudulently sent to fictitious payees by using computer-generated reports to compare payments sent to the same location?
Rationale for Correct Answer:
Address similarity reports are used to identify fraudulent disbursements by flagging payments sent to multiple vendors or payees at the same address. This helps detect fictitious payees or shell companies set up by fraudsters.
Analysis of Incorrect Options:
A . Duplicate payment lists -- Detects duplicate disbursements, not necessarily fictitious payees.
C . Exception reports -- Flag unusual transactions, but not specifically address similarities.
D . Electronic confirmations -- Used to verify balances or transactions, not detect fictitious vendors.
Key Concept: Detection of fraudulent disbursements.
Jonathan, a Certified Fraud Examiner (CFE), is tasked with identifying potential indicators of intrusion into his employer's computer network. Which of the following might indicate that the organization's network has been compromised or accessed without authorization?
Rationale for Correct Answer: Being prompted to install unfamiliar software is a red
Analysis of Incorrect Options:
A -- Standard security measure, not a red flag.
C -- Data from supplier countries is normal if consistent with business operations.
D -- Access denial to files outside a user's role is a normal access control, not an intrusion sign.
Key Concept: Cyberfraud detection -- identifying intrusion indicators.
What type of fraud scheme would MOST LIKELY be revealed by identifying employees with the same government identification numbers?
The correct answer is A. A ghost employee scheme involves adding a fictitious or nonworking person to the payroll so the fraudster can collect wages or salary payments. Data analysis can help detect ghost employees by identifying duplicate, invalid, or suspicious employee information. Multiple employees using the same government or tax identification number is a strong red flag because legitimate employees should generally have unique identifying numbers. Payment tampering involves altering payments after they are initiated, while falsified hours and salary schemes usually involve overstated time worked or unauthorized pay-rate changes for real employees. Fraudulent commission schemes involve manipulating sales or commission records. The ACFE materials specifically identify duplicate government identification numbers as a test for ghost employee schemes.
The amount of cash on hand in a register may be compared to the amount showing in the register tape in order to detect _______.
Rationale for Correct Answer:
Comparing register tape totals to the actual cash on hand is a classic reconciliation test used to detect employee theft. Discrepancies suggest cash has been skimmed or stolen after recording.
Analysis of Incorrect Options:
B . Recorded sales -- Register tapes already show recorded sales; comparison is for theft detection.
C . Internal audits -- A process, not the purpose of the comparison.
D . Occupational frauds -- Too broad a term.
Key Concept:
Cash Reconciliation as a control to detect employee theft.
ACFE Fraud Examiners Manual (2020 International Edition), Cash Receipts --- Detection Methods for Skimming and Larceny.
A fraudster uses the name and picture of another individual to create a social media profile. This scheme can BEST be described as:
The correct answer is D. Traditional identity theft involves using the real identifying information of another person to impersonate that individual. Here, the fraudster uses another person's actual name and picture to create a social media profile, meaning the fraudster is posing directly as a real person rather than creating a hybrid or fictitious identity. Synthetic identity theft combines real and fabricated information to create a new identity, which is not described here. Criminal identity theft involves using another person's identity in a law enforcement or criminal justice context. New account identity theft is not the best ACFE category for this question because the facts emphasize impersonation using real identity information. The ACFE materials distinguish traditional identity theft from synthetic and criminal identity theft.
352 questions covering all exam domains
5 domains from the ACFE CFE-Fraud-Schemes-and-Financial-Crimes exam outline, with approximate weightings. Every sample question above is tagged with the domain it comes from
Examines cash theft, inventory theft, and asset misuse schemes. Study methods used to conceal internal fraud activities and recognize red flags that indicate employee fraud.
Explains bribery, kickbacks, and illegal gratuity schemes including conflicts of interest. Focus on detecting and preventing corruption risks within organizations and procurement-related fraud.
Covers revenue, expense, asset, and liability manipulation schemes. Learn to analyze financial data to identify signs of fraudulent financial reporting practices and disclosures.
Sample question from this domain above: Q4
Covers check fraud, card fraud, and electronic payment schemes including identity theft and account takeover. Develop skills in detecting suspicious financial transaction patterns.
Explains the placement, layering, and integration stages of money laundering and anti-money laundering controls. Focus on identifying suspicious transactions and assessing financial crime risks.
Common questions about the exam itself