CACs - Certified Application Counselor Privacy and Security Standards Questions and Answers 1 — Questions and Answers
Question 1: A CAC is assisting a consumer at a busy enrollment event in a public space. The CAC needs to step away from their laptop for a moment to retrieve a form. What is the most important security action the CAC must take before leaving the computer?
- Ask the consumer to watch the laptop.
- Lock the computer screen. (Correct answer)
- Turn the screen brightness all the way down.
- Close the web browser window showing the consumer's application.
Correct answer: Lock the computer screen.
Locking the computer screen is a fundamental security practice that prevents unauthorized access to any information on the computer. This ensures that even in a brief absence, no one can view or interact with sensitive consumer PII. While closing the browser is good, it doesn't protect other information on the computer, and the other options are not secure measures.
Question 2: According to federal standards for protecting consumer Personally Identifiable Information (PII), which of the following is an approved method for destroying paper documents containing sensitive PII?
- Tearing the documents into several pieces before placing them in a trash can.
- Placing the documents in a standard, unlocked office recycling bin.
- Using a cross-cut shredder to render the information unreconstructible. (Correct answer)
- Blacking out the consumer's name and address with a marker before discarding.
Correct answer: Using a cross-cut shredder to render the information unreconstructible.
Federal standards, such as those from NIST, require that PII be rendered unreadable, indecipherable, and unreconstructible. Cross-cut shredding, pulverizing, or incinerating are methods that meet this standard. The other methods are insufficient as they could allow a determined individual to reconstruct the sensitive information.
Question 3: Which of the following is a critical element that must be included in a consumer's written consent form before a CAC can access and use their PII?
- The timeframe during which the consent is valid. (Correct answer)
- The name of the consumer's preferred health insurance plan.
- A clause allowing the CAC to share the PII for marketing purposes.
- The CAC's personal contact information.
Correct answer: The timeframe during which the consent is valid.
A valid consent agreement must specify the period during which the authorization is effective, and it must also allow the consumer to revoke the consent at any time. This ensures the consumer has control over their information. Using PII for marketing is prohibited, and while other details might be on the form, the timeframe of consent is a required component.
Question 4: A CAC receives an email that appears to be from the Health Insurance Marketplace, asking them to click a link and "verify their account credentials immediately" to avoid deactivation. The email uses a generic greeting. What is the most appropriate action for the CAC to take?
- Click the link and enter the credentials as requested to avoid service disruption.
- Reply to the email with the requested information to confirm their identity.
- Forward the email to a colleague to ask if they also received it.
- Do not click the link, and report the email as a potential phishing attempt according to their organization's policy. (Correct answer)
Correct answer: Do not click the link, and report the email as a potential phishing attempt according to their organization's policy.
This scenario describes a common phishing attack, which uses deceptive emails to trick people into divulging sensitive information. Red flags include urgent language, generic greetings, and requests for login credentials. The proper response is to not engage with the email and report it through the correct channels.
Question 5: When assisting consumers, a CAC is responsible for safeguarding their Personally Identifiable Information (PII). Which of the following is the BEST example of PII that must be protected?
- The consumer's opinion on available health plans.
- The consumer's name combined with their Social Security Number. (Correct answer)
- A list of hospitals in the consumer's local area.
- An anonymized statistic about Marketplace enrollment in their state.
Correct answer: The consumer's name combined with their Social Security Number.
Personally Identifiable Information (PII) is any information that can be used to distinguish or trace an individual's identity. A name combined with a Social Security Number is a primary example of sensitive PII that requires the highest level of protection. The other options are either opinions, public information, or anonymized data.
Question 6: Which of the following actions represents a violation of the 'principle of least privilege' regarding access to consumer PII?
- Accessing only the financial section of an application to help a consumer with income questions.
- Using a unique, complex password to log into the Marketplace portal.
- Allowing all CACs at an organization to use a single, shared username and password for the system to make helping consumers faster. (Correct answer)
- Securing paper applications in a locked file cabinet at the end of the day.
Correct answer: Allowing all CACs at an organization to use a single, shared username and password for the system to make helping consumers faster.
The principle of least privilege dictates that a user should only have the minimum access necessary to perform their job functions. Sharing a single login credential violates this by giving multiple users broad, unaudited access and makes it impossible to trace actions back to a specific individual. Individual accounts ensure accountability and limit potential damage if credentials are compromised.
A CAC is assisting a consumer at a busy enrollment event in a public space.
The CAC needs to step away from their laptop for a moment to retrieve a form.
What is the most important security action the CAC must take before leaving the computer?