[Full-Version] 2026 New Preparation Guide of ACAMS CCAS Exam CCAS Practice Exam - 102 Unique Questions NEW QUESTION # 57 To identify and assess the money laundering risks emerging from virtual assets, countries should ensure that virtual asset service providers are: (Select Two.) A. Evaluated for beneficial ownership of virtual asset clients B. Maintaining effective monitoring systems. C. Connected [...]

[Full-Version] 2026 New Preparation Guide of ACAMS CCAS Exam [Q57-Q74]

Share

[Full-Version] 2026 New Preparation Guide of ACAMS CCAS Exam

CCAS Practice Exam - 102 Unique Questions

NEW QUESTION # 57
To identify and assess the money laundering risks emerging from virtual assets, countries should ensure that virtual asset service providers are: (Select Two.)

  • A. Evaluated for beneficial ownership of virtual asset clients
  • B. Maintaining effective monitoring systems.
  • C. Connected with a regulated financial institution.
  • D. Located in a jurisdiction with increased regulatory expectations
  • E. Subjected to AML regulations

Answer: B,E

Explanation:
To effectively mitigate money laundering risks in the virtual asset sector, countries must ensure that Virtual Asset Service Providers (VASPs) are subject to AML regulations (B), which provide the legal framework for risk-based customer due diligence and reporting suspicious activities. Additionally, VASPs must maintain effective monitoring systems (C) that enable the detection and reporting of suspicious transactions.
While connection to regulated financial institutions (A) and beneficial ownership evaluation (E) are important components of AML frameworks, the foundational requirements per FATF and DFSA guidance focus on regulatory oversight and operational controls.
Jurisdictional regulatory expectations (D) influence enforcement but do not replace the need for direct AML regulatory application on VASPs.


NEW QUESTION # 58
Which operational risk mitigation practice by virtual asset service providers (VASPs) is most effective when considering their relationships with other VASPs?

  • A. Gathering sufficient information on the counterpart VASP to determine the quality of the supervision it receives for transactional activities
  • B. Assigning all such relationships as high risk and conducting enhanced due diligence on all of them
  • C. Having no requirement to establish a correspondent relationship and build a risk assessment framework among other cryptoasset exchanges prior to transferring for or on behalf of another person
  • D. Developing cross-border correspondent relationships with cryptoasset exchanges in jurisdictions that have weak or non-existent anti-money laundering (AML) regulation or supervision

Answer: A

Explanation:
Effective risk mitigation requires VASPs to obtain sufficient information about counterpart VASPs to assess the quality of their regulatory supervision and controls. This helps determine the risk of transactions and build a risk-based framework for correspondent relationships.
Having no requirements (A) or engaging with poorly regulated jurisdictions (B) increases risk. Blanket high-risk classification (C) without proper assessment is inefficient.
FATF Recommendation 15 and DFSA guidance emphasize due diligence on counterparties as a critical control.


NEW QUESTION # 59
According to the Financial Crimes Enforcement Network's Guidance 2019-G0001 pertaining to convertible virtual currencies, a money transmitter includes companies that:

  • A. Provide the delivery, communication, or network access services to only support money transmission services.
  • B. Exchange digital tokens.
  • C. Operate a clearance and settlement system or otherwise act as intermediaries solely between Bank Secrecy Act-regulated institutions.
  • D. Act as payment processors to facilitate the purchase of, or payment of a bill for, a good or service through a clearance and settlement system.

Answer: B

Explanation:
The FinCEN 2019 guidance clarifies that money transmitters include entities that exchange digital tokens or convertible virtual currencies as part of their business activities. This includes exchanges and platforms that transfer virtual currencies.
Providing infrastructure services (B), operating clearance systems solely among regulated institutions (C), or acting as payment processors for goods/services (D) without handling value transfer do not fall under the money transmitter definition per this guidance.


NEW QUESTION # 60
Why should firms monitor "dusting" attacks?

  • A. They increase transaction fees.
  • B. They can link anonymous wallets to known identities.
  • C. They slow blockchain performance.
  • D. They inflate token supply.

Answer: B

Explanation:
Dusting involves sending tiny amounts of crypto to many addresses to later analyze transaction patterns, potentially deanonymizing users - a privacy and AML concern.


NEW QUESTION # 61
Which risk category best reflects the risks associated with payment methods (e.g., cash, wires, credit cards, virtual assets)?

  • A. Geographical
  • B. New technologies
  • C. Customers
  • D. Products and services

Answer: D

Explanation:
The risks posed by different payment methods fall under the products and services risk category because payment methods are specific services and products offered by financial institutions or businesses. This category assesses inherent risks linked to how products are designed and used.
Geographical (A) relates to location risks; customers (B) relates to the nature of customers; new technologies (C) covers emerging tools but payment methods are classified under products/services.


NEW QUESTION # 62
What methods do criminals use to avoid clustering of crypto wallet addresses?

  • A. The address receives a large amount of cryptocurrency from another wallet address.
  • B. After receiving a large volume of crypto payments in the wallet, they are left there for a long period of time.
  • C. A small portion of cryptoassets is moved to an exchange, and the rest remain in the wallet.
  • D. The cryptoassets are moved to the exchange after a large number of hops within a short period of time.

Answer: D

Explanation:
Criminals often move cryptoassets through multiple intermediary wallets (many "hops") rapidly to obfuscate the transaction trail and avoid clustering, which blockchain analytics use to link related addresses.
Simply receiving large amounts (A), holding assets (B), or splitting movements (D) are less effective at preventing clustering.


NEW QUESTION # 63
A compliance officer at an exchange who is conducting an annual risk assessment identifies an increased volume of transactions to and from unhosted wallets. Based on Financial Action Task Force guidance, which inherent risk rating would be most appropriate for the compliance officer to assign to such activities?

  • A. Low
  • B. High
  • C. Negligible
  • D. Moderate

Answer: B

Explanation:
The Financial Action Task Force (FATF) guidance on Virtual Assets and Virtual Asset Service Providers (VASPs) explicitly highlights that transactions involving unhosted wallets (wallets not held or controlled by a regulated entity) pose a high inherent risk for money laundering and terrorist financing. This is because unhosted wallets are more difficult to monitor and control, lack identifiable customer information, and are often exploited for illicit activities.
The DFSA AML Module, aligned with FATF recommendations, mandates that Relevant Persons incorporate this risk into their business-wide risk assessments. The increased volume of transactions to and from unhosted wallets should therefore be assigned a high inherent risk rating to trigger enhanced controls such as enhanced due diligence (EDD) and transaction monitoring.
Supporting extracts include:
FATF Guidance on Virtual Assets (October 2021) states: "Unhosted wallets or transactions with them represent a high risk of ML/TF due to limited or no access to identifying information." DFSA AML Module (AML/VER25/05-24) Section 4.1 & 6.1 on Risk-Based Approach: mandates firms to assess and rate risks posed by customers and products, explicitly including virtual assets and unhosted wallets as high risk.
COB Module also requires heightened controls and disclosures when dealing with transactions involving unhosted wallets【AML/VER25/05-24: Sections 4.1, 6.1, COB/VER45/05-24: Sections 6.13, 15.6】.
Thus, option D (High) is the correct risk rating.


NEW QUESTION # 64
How should an investigator use transaction history to determine whether cryptoassets were previously involved in money laundering?

  • A. Assess the identity of the cryptoasset owner.
  • B. Assess other assets held by the cryptoasset owner.
  • C. Assess the cryptoasset addresses' receiving exposure to illicit activity.
  • D. Assess the jurisdiction where the transactions took place.

Answer: C

Explanation:
In the context of AML/CFT frameworks for cryptoassets, the investigation of transaction histories involves blockchain analysis tools to trace the flow of funds to and from crypto addresses. Specifically, it is essential to assess whether the addresses involved have had prior exposure to illicit activities such as known darknet marketplaces, ransomware payments, or sanctioned entities. This form of "address screening" helps identify potentially tainted cryptoassets.
The DFSA AML Module and associated guidance emphasize that transaction monitoring for cryptoassets requires analyzing the provenance of funds, not just ownership. While identifying the owner is part of customer due diligence (CDD), the transactional exposure itself reveals laundering risks embedded in the chain of transfers.
Extract from DFSA AML Module and COB Module on Crypto Business Rules:
"Transaction monitoring systems must include blockchain analysis to detect suspicious activity related to crypto tokens, including tracing transactions against known illicit sources."
"Enhanced due diligence (EDD) is required when a cryptoasset transaction involves addresses or wallets with a history of illicit activity."
"Risk-based approaches must integrate forensic review of transaction histories to assess financial crime risks in crypto asset transfers"【AML/VER25/05-24: Sections 6.3, 7.3, 13.3; COB/VER45/05-24: Sections 6.13, 15】.
Therefore, assessing the receiving exposure of cryptoasset addresses to illicit activity (Option C) is the most direct and effective method to detect laundering.


NEW QUESTION # 65
A compliance officer is conducting a customer risk review. Which statements represent the highest level of customer risk? (Select Two.)

  • A. A customer receiving cryptoassets daily from another virtual asset service provider located in a foreign jurisdiction which are then sent to a private wallet
  • B. A student customer depositing 15,000 USD over a period of a month, using the funds to purchase cryptoassets that are sent to another virtual asset service provider
  • C. A business customer opting to pay suppliers in cryptoassets
  • D. A customer located in a foreign country donating 10,000 USD worth of cryptoassets to a charity for veterans in the US
  • E. A customer who uses a virtual private network (VPN) connection to access the customer's account

Answer: A,B

Explanation:
When determining highest-risk customers under a risk-based approach, firms must consider transaction patterns, jurisdictions, counterparties, and destinations:
B: Large deposits by a student, rapidly converting to crypto and sending to another VASP, suggest potential layering and third-party funding risk.
D: Daily inbound transfers from a foreign VASP to a private (unhosted) wallet indicate consistent high-risk exposure - especially cross-border transactions involving unregulated or weakly regulated jurisdictions.
While VPN use (A) can be a red flag, on its own it is lower risk than significant suspicious fund flows. Paying suppliers in crypto (C) can be legitimate for businesses. A large donation to a charity (E) could be flagged depending on jurisdiction and cause, but is generally less inherently suspicious than B and D unless linked to high-risk entities.
FATF, DFSA, and FSRA AML rules stress that ongoing monitoring should identify these high-frequency, high-value, cross-border crypto flows as priority for Enhanced Due Diligence (EDD) and possible Suspicious Transaction Reports (STRs).


NEW QUESTION # 66
The Financial Action Task Force recommends countries require virtual asset service providers to maintain all records of transactions and customer due diligence measures for a minimum of:

  • A. 7 years
  • B. 6 months
  • C. 2 years
  • D. 5 years

Answer: D

Explanation:
FATF standards specify that Virtual Asset Service Providers (VASPs) must keep records related to transactions and customer due diligence for at least 5 years after the completion of the transaction or end of the business relationship. This retention period facilitates effective AML investigations and regulatory reviews.
DFSA AML Module aligns with this timeframe, reinforcing that comprehensive record retention supports audit trails and compliance verification.


NEW QUESTION # 67
In sanctions screening, a "fuzzy match" occurs when:

  • A. There is no match found.
  • B. A partial or near match to a sanctions list entry occurs.
  • C. Only wallet addresses match exactly.
  • D. The customer is in a low-risk jurisdiction.

Answer: B

Explanation:
Fuzzy matches require further review to confirm whether the match is a true hit or a false positive, ensuring compliance accuracy.


NEW QUESTION # 68
What is the most pertinent item for a cryptoasset money services business to include in a suspicious activity report?

  • A. The names of every owner of the destination wallet address(es) to which the subject sent transactions during the review period
  • B. The aggregate total amount of fiat currency used by the subject to purchase cryptocurrency
  • C. The subject's account onboarding information not otherwise included in the counter-party information section
  • D. All types of cryptocurrencies purchased by the subject, including aggregate total of each and fiat currency equivalent

Answer: D

Explanation:
SARs should include detailed transactional information to support investigations, including all types and aggregate amounts of cryptocurrencies purchased, along with fiat currency equivalents. This information provides a clear picture of the subject's activity and financial scale.
Owner names of destination wallets (B) may not be available; onboarding info (D) is supplementary, and fiat aggregate totals (C) alone are insufficient.
FATF and DFSA guidance recommend comprehensive transactional data inclusion in SARs to facilitate law enforcement.


NEW QUESTION # 69
Which is an accurate description of a Decentralized Autonomous Organization (DAO)?

  • A. DAOs are decentralized blockchain technologies that use traditional contracts instead of smart contracts.
  • B. DAOs are decentralized blockchain organizations that require managerial activity by humans.
  • C. DAOs are organizational structures through which how a protocol will operate is determined by a group of actors.
  • D. DAOs are cryptocurrency funds in which the board of directors submit their votes using blockchain technology.

Answer: C

Explanation:
DAOs are decentralized organizational structures where protocol governance and operational decisions are made collectively by token holders or participants rather than centralized management. This group voting and consensus determine how the protocol functions.
DAOs do not rely on traditional contracts (D) nor necessarily require ongoing human managerial control (A). They are not simply funds with boards voting (C) but represent decentralized governance mechanisms.


NEW QUESTION # 70
Which type of wallet poses the highest AML risk?

  • A. Unhosted wallet
  • B. Exchange hot wallet
  • C. Custodial wallet
  • D. Multi-signature wallet

Answer: A

Explanation:
Unhosted wallets allow direct user control without third-party oversight, making them harder to monitor and more vulnerable to misuse.


NEW QUESTION # 71
A virtual asset service provider (VASP) is using public information on the blockchain to trace a wallet address. Which additional step is necessary to identify the owner or controller of that address?

  • A. Acquire information to connect the wallet address to a natural person.
  • B. Review the wallet address information periodically.
  • C. Obtain further information connecting wallet address to virtual asset transactions.
  • D. Screen the wallet address for any historical transaction activity.

Answer: A

Explanation:
Public blockchain data is pseudonymous, meaning wallet addresses alone do not reveal the owner's identity. To identify the natural person controlling the wallet, the VASP must acquire additional information, typically through customer due diligence (CDD) processes or data obtained from exchanges and counterparties, linking the wallet address to an individual.
Periodic review (A), transaction screening (C), and obtaining transactional data (D) support ongoing monitoring but do not alone establish identity.
AML and FATF guidance emphasize that ownership linkage requires collecting identifying information beyond blockchain data to comply with AML regulations.


NEW QUESTION # 72
Which of the following are functions of cryptoasset mining? (Select Two.)

  • A. Optimizing and improving the functionality of the network
  • B. Ensuring the security of the network
  • C. Generating new cryptoassets
  • D. Validating transactions on the blockchain

Answer: C,D

Explanation:
Mining generates new cryptoassets (A) by rewarding miners for solving complex cryptographic puzzles. It also validates transactions on the blockchain (D) by confirming and recording them in blocks, ensuring the integrity of the ledger.
While mining indirectly contributes to network security, the core security mechanisms involve consensus protocols beyond mining alone (B). Optimizing network functionality (C) is usually a development task rather than a mining function.


NEW QUESTION # 73
Which term describes converting one cryptoasset into another without first converting to fiat?

  • A. Integration
  • B. Structuring
  • C. Layering
  • D. Chain hopping

Answer: D

Explanation:
Chain hopping involves moving between blockchains to make tracing harder, often exploiting regulatory gaps.


NEW QUESTION # 74
......

Latest Questions CCAS Guide to Prepare Free Practice Tests: https://examcollection.guidetorrent.com/CCAS-dumps-questions.html