Free Questions › CTP › Treasury Technology and Payment Systems
Free CTP Treasury Technology and Payment Systems Practice Questions & Answers
82 exam-style Treasury Technology and Payment Systems questions. Pick your answer, hit Check answer, and see the worked solution — free to start, no signup.
100% free · No login to startQuestion 1
What is the primary purpose of a treasury management system (TMS)?
Select an option first.
Correct answer: A — To centralize and automate treasury activities such as cash positioning, payments, and bank reporting
Explanation: A TMS is a specialized platform designed to centralize and automate core treasury functions including cash positioning, forecasting, payments, bank communications, and debt and investment tracking. It is not an accounting system of record, though it integrates with the ERP or general ledger. Its focus is treasury operations, not sales or inventory management.
Question 2
Straight-through processing (STP) in a treasury environment is best described as:
Select an option first.
Correct answer: B — The end-to-end automated flow of a transaction without manual intervention
Explanation: Straight-through processing refers to the seamless, automated handling of a transaction from initiation through settlement and reconciliation without manual re-keying or intervention. STP reduces errors, lowers costs, and speeds processing. Manual re-keying is precisely what STP is designed to eliminate.
Question 3
Which of the following is typically a core module of a treasury management system?
Select an option first.
Correct answer: C — Cash and liquidity management
Explanation: Cash and liquidity management is a foundational TMS module, supporting cash positioning, forecasting, and bank balance reporting. Other common modules include payments, debt and investments, financial risk management, and bank account management. Payroll, depreciation, and production planning are functions of payroll, accounting, and manufacturing systems, respectively.
Question 4
When an ERP system and a TMS are integrated, what is a key benefit?
Select an option first.
Correct answer: D — Reduced duplicate data entry and improved data consistency across systems
Explanation: Integrating an ERP with a TMS allows shared master data and transaction information to flow between systems, reducing duplicate manual entry and improving data consistency and accuracy. It does not eliminate bank relationships, guarantee investment returns, or remove the need for internal controls, which remain essential.
Question 5
A treasury workstation differs from a full enterprise TMS primarily in that it:
Select an option first.
Correct answer: A — Is generally more limited in scope, focusing on cash management and reporting
Explanation: A treasury workstation typically offers a narrower feature set focused on cash management, positioning, and bank reporting, while a full enterprise TMS provides broader capabilities such as risk management, debt and investments, and multi-entity support. Both connect to banks. Neither is legally mandated for all public companies.
Get the full CTP question bank — free
Drop your email and we'll send you fresh CTP practice questions, fully worked solutions and exam-deadline reminders. No spam — unsubscribe in one click.
Want to save your score and take a full mock exam? Create a free account →
Question 6
Which deployment model allows a company to access its TMS over the internet without hosting the software on its own servers?
Select an option first.
Correct answer: B — Software-as-a-Service (SaaS) / cloud-hosted
Explanation: Software-as-a-Service (SaaS) delivers the TMS through a cloud-hosted, subscription model accessed over the internet, with the vendor managing hosting, maintenance, and upgrades. On-premise installations require the company to host and maintain the software itself. Spreadsheets and mainframe batch systems are not cloud-delivered TMS models.
Question 7
Which U.S. payment system is a real-time gross settlement (RTGS) system operated by the Federal Reserve for large-value, time-critical wire transfers?
Select an option first.
Correct answer: D — Fedwire Funds Service
Explanation: Fedwire Funds Service is the Federal Reserve's real-time gross settlement system, settling large-value wire transfers individually and with finality in real time. ACH is a batch, net settlement system. Check and card networks operate on different, non-RTGS models.
Question 8
CHIPS (Clearing House Interbank Payments System) is best characterized as:
Select an option first.
Correct answer: A — A privately operated large-value payment system that uses netting to settle interbank payments
Explanation: CHIPS is a privately operated (by The Clearing House) large-value payment system that nets payment obligations among participants to conserve liquidity, with final settlement typically at day's end and intraday finality features. It is not a card network, check service, or consumer wallet.
Question 9
The ACH network rules in the United States are administered by:
Select an option first.
Correct answer: B — NACHA
Explanation: NACHA (originally the National Automated Clearing House Association) governs the operating rules for the ACH network. SWIFT is a global messaging cooperative, the SEC regulates securities, and the IRS administers taxes; none set ACH rules.
Question 10
Which statement about the RTP network operated by The Clearing House is correct?
Select an option first.
Correct answer: C — It provides real-time, 24/7/365 clearing and settlement of payments with immediate availability
Explanation: The RTP network provides real-time clearing and settlement with funds availability around the clock, every day of the year. It is a domestic U.S. instant payment rail, not weekly, not exclusively international, and not paper-based.
Question 11
An ACH credit entry is one in which:
Select an option first.
Correct answer: D — The originator pushes funds from its account to the receiver's account
Explanation: In an ACH credit, the originator pushes funds to the receiver, as in direct deposit of payroll or supplier payments. An ACH debit pulls funds from the receiver's account, as in a recurring bill payment. Funds do move, and the originator initiates the entry.
Question 12
Positive pay is a fraud-control service in which:
Select an option first.
Correct answer: A — The company sends the bank a list of issued checks and the bank matches presented checks against it
Explanation: Positive pay requires the company to transmit a file of issued checks (number, amount, and often payee) to the bank, which matches presented items against the list and flags exceptions for review. Unmatched items are not paid without approval. It is a check fraud detection control, not an automatic payment or conversion service.
Question 13
SWIFT is best described as:
Select an option first.
Correct answer: B — A secure global messaging network that financial institutions use to exchange standardized payment and financial messages
Explanation: SWIFT (Society for Worldwide Interbank Financial Telecommunication) operates a secure messaging network enabling banks and corporations to exchange standardized financial messages worldwide. It moves messages, not funds, and does not itself settle payments. It is neither a deposit-taking bank nor a credit bureau.
Question 14
ISO 20022 is:
Select an option first.
Correct answer: C — An international standard for structured, data-rich financial messaging using XML
Explanation: ISO 20022 is a global standard providing a common framework for financial messages, typically expressed in XML, that carry richer, more structured data than legacy formats. It is open and used across many institutions and payment systems. It is not proprietary, a hardware token, or a prohibition on electronic payments.
Question 15
A BIC (Bank Identifier Code) is used to:
Select an option first.
Correct answer: D — Uniquely identify a specific bank or financial institution in cross-border messaging
Explanation: A BIC, also known as a SWIFT code, uniquely identifies a bank or financial institution and is used to route international payments and messages. It does not encrypt messages, denote amounts, or act as a personal password.
Question 16
An IBAN (International Bank Account Number) primarily serves to:
Select an option first.
Correct answer: A — Identify an individual bank account in a standardized international format for cross-border payments
Explanation: An IBAN standardizes the identification of an individual bank account across countries, including a country code, check digits, and the domestic account details, reducing routing errors in cross-border payments. It complements rather than replaces bank identification and does not encrypt data or track physical cash.
Question 17
In SWIFT terminology, MT messages and MX messages differ in that:
Select an option first.
Correct answer: B — MT messages are the legacy FIN format while MX messages use the ISO 20022 XML standard
Explanation: MT (Message Type) refers to the legacy SWIFT FIN message format, while MX refers to the newer ISO 20022 XML-based messages that carry richer structured data. Option A reverses the definitions. The two formats are structurally different, and MX is not limited to domestic checks.
Question 18
A host-to-host bank connection refers to:
Select an option first.
Correct answer: C — A direct, automated system-to-system link between a company's ERP/TMS and its bank for exchanging files
Explanation: Host-to-host connectivity establishes a direct, automated system-to-system channel between a corporate system (ERP or TMS) and the bank, enabling secure exchange of payment and reporting files without manual portal logins. It is not a manual, telephone, or courier process.
Question 19
Business email compromise (BEC) is a fraud scheme in which attackers:
Select an option first.
Correct answer: A — Impersonate an executive or trusted vendor via email to trick staff into sending funds or data
Explanation: BEC involves attackers impersonating a senior executive, vendor, or other trusted party through spoofed or compromised email accounts to deceive employees into transferring funds or divulging sensitive information. It is a social-engineering attack, distinct from physical theft, password guessing, or denial-of-service flooding.
Question 20
Phishing is best defined as:
Select an option first.
Correct answer: B — Fraudulent messages designed to trick recipients into revealing credentials or clicking malicious links
Explanation: Phishing uses deceptive emails, texts, or other messages that appear legitimate to trick recipients into disclosing credentials, sensitive data, or clicking links that install malware. It is an attack technique, not a bank service, encryption method, or settlement enhancement.
Question 21
Ransomware is a type of malware that:
Select an option first.
Correct answer: C — Encrypts or locks a victim's data and demands payment for its release
Explanation: Ransomware encrypts or otherwise locks a victim's systems or data and demands a ransom, often in cryptocurrency, in exchange for a decryption key. It is malicious software, not a performance tool, backup service, or identity-verification mechanism.
Question 22
Multifactor authentication (MFA) strengthens security by requiring:
Select an option first.
Correct answer: D — Two or more independent factors such as something you know, have, or are
Explanation: MFA requires two or more independent authentication factors, typically drawn from something you know (password), something you have (token or phone), and something you are (biometric). Combining factors makes stolen credentials alone insufficient for access. A single password is only one factor.
Question 23
Encryption protects data by:
Select an option first.
Correct answer: A — Converting it into an unreadable form that requires a key to decode
Explanation: Encryption transforms readable data (plaintext) into an unreadable form (ciphertext) using an algorithm and a key, so that only parties with the correct key can decode it. It protects confidentiality in storage and transit. It does not delete, publicize, or inherently slow data beyond minor processing overhead.
Question 24
Tokenization in payment security refers to:
Select an option first.
Correct answer: B — Replacing sensitive data such as an account number with a non-sensitive substitute value
Explanation: Tokenization replaces sensitive data, such as a primary account number, with a non-sensitive surrogate (a token) that has no exploitable value if intercepted, while the real data is stored securely elsewhere. It reduces the scope of sensitive data exposure. It is unrelated to arcade tokens, rounding, or converting data to plaintext.
Question 25
A dual-approval (segregation of duties) control over payments means that:
Select an option first.
Correct answer: C — Initiating and approving a payment are performed by different individuals
Explanation: Segregation of duties through dual approval ensures that the person who initiates a payment is not the same person who approves or releases it, reducing the risk of error and fraud. Allowing one person to do both, or removing approval entirely, defeats the control's purpose.
Question 26
Role-based access control (RBAC) in a treasury system means that:
Select an option first.
Correct answer: D — System permissions are granted according to a user's job role and responsibilities
Explanation: Role-based access control assigns system permissions based on a user's defined job role, ensuring individuals can access only the functions their responsibilities require. This supports least-privilege and segregation-of-duties principles. Granting everyone admin rights or random access would undermine security controls.
Question 27
The principle of least privilege states that users should:
Select an option first.
Correct answer: A — Have the minimum access rights necessary to perform their job
Explanation: Least privilege dictates that each user is granted only the minimum access rights necessary to perform their duties, limiting the potential damage from error, misuse, or compromised credentials. Full access for all, shared logins, and zero access all violate the principle or make work impossible.
Question 28
When treasury applications move to a cloud (SaaS) model, security responsibility is typically:
Select an option first.
Correct answer: B — Shared between the cloud provider and the customer under a shared responsibility model
Explanation: Cloud services operate under a shared responsibility model in which the provider secures the underlying infrastructure and platform while the customer remains responsible for configuration, access management, and data governance. Security is neither entirely offloaded nor eliminated. Responsibility is not left solely to personal devices.
Question 29
A user access review (recertification) is performed to:
Select an option first.
Correct answer: C — Periodically confirm that users' access rights remain appropriate and remove unneeded access
Explanation: Periodic user access reviews verify that each person's system permissions still match their current role and responsibilities, and that access for departed or reassigned employees is removed. This limits privilege creep and orphaned accounts. It does not expand permissions, delete logs, or replace MFA.
Question 30
Payment limits and beneficiary controls configured within a TMS are examples of:
Select an option first.
Correct answer: D — System-embedded fraud and error controls
Explanation: Configurable payment limits, approved beneficiary lists, and threshold-based approval rules are controls embedded in the payment system that help prevent unauthorized, erroneous, or fraudulent payments. They are risk controls, not marketing, tax, or inventory functions.
More free CTP topics
Ten questions in
- The ones you miss are saved as a drill you can repeat
- Your place is kept, on this device and any other
- A streak, if that is the thing that gets you back tomorrow
Every question on this page stays free and open either way.