Capital One Assessment Test Safety and Compliance 2 — Questions and Answers
Question 1: A customer calls claiming their account was charged without authorization. Under Regulation E, how long does the bank have to investigate the claim if the customer has not provided a written statement?
- 5 business days
- 10 business days (Correct answer)
- 45 days
- 90 days
Correct answer: 10 business days
Regulation E gives financial institutions 10 business days to investigate electronic fund transfer errors after receiving oral notice, before provisional credit may be required.
Question 2: Which federal law requires Capital One to implement an information security program to protect customer data?
- Sarbanes-Oxley Act
- Gramm-Leach-Bliley Act (Correct answer)
- Fair Credit Reporting Act
- Electronic Fund Transfer Act
Correct answer: Gramm-Leach-Bliley Act
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to protect the security and confidentiality of nonpublic personal information through a written information security program.
Question 3: An employee notices a coworker accessing customer account records for accounts not related to any active work request. What is the MOST appropriate first action?
- Confront the coworker directly
- Ignore it since it may be a legitimate business need
- Report it to a manager or through the ethics hotline (Correct answer)
- Send an email to the entire team warning about data misuse
Correct answer: Report it to a manager or through the ethics hotline
Unauthorized access to customer accounts is a potential data privacy violation that must be reported to management or through official ethics reporting channels.
Question 4: What does 'need-to-know' mean in the context of information access controls at a financial institution?
- Employees must explain why they need any information they access
- Access to sensitive data is limited to those whose job functions require it (Correct answer)
- Customers must be told why their data is being accessed
- Regulators must approve all data access requests
Correct answer: Access to sensitive data is limited to those whose job functions require it
The need-to-know principle restricts access to sensitive information only to employees whose role specifically requires that access to perform their duties.
Question 5: Under the Bank Secrecy Act (BSA), what is the threshold for filing a Currency Transaction Report (CTR)?
- $5,000 in cash
- $10,000 in cash (Correct answer)
- $25,000 in cash
- $50,000 in cash
Correct answer: $10,000 in cash
Financial institutions must file a CTR for any cash transaction exceeding $10,000 in a single business day, even if conducted in multiple transactions.
Question 6: A customer asks a Capital One associate to hold their mail and send account statements to a friend's address temporarily. What compliance concern does this raise?
- No concern — it is a routine customer service request
- Potential identity theft or elder financial abuse (Correct answer)
- A violation of the CAN-SPAM Act
- A potential Fair Lending violation
Correct answer: Potential identity theft or elder financial abuse
Redirecting account statements to a third party without proper verification may indicate identity theft, account takeover, or financial exploitation of a vulnerable customer.
Question 7: Which regulatory body is Capital One's PRIMARY federal prudential regulator for its bank subsidiary?
- Consumer Financial Protection Bureau (CFPB)
- Federal Deposit Insurance Corporation (FDIC)
- Office of the Comptroller of the Currency (OCC) (Correct answer)
- Securities and Exchange Commission (SEC)
Correct answer: Office of the Comptroller of the Currency (OCC)
Capital One, National Association is chartered as a national bank, making the OCC its primary federal prudential regulator responsible for bank safety and soundness.
A customer calls claiming their account was charged without authorization.
Under Regulation E, how long does the bank have to investigate the claim if the customer has not provided a written statement?