Capital One Assessment Test Safety and Compliance 3 — Questions and Answers
Question 1: A Capital One associate receives a phishing email appearing to be from IT asking them to reset their password via a provided link. What is the BEST response?
- Click the link and reset the password since IT may have detected a breach
- Forward the email to coworkers to warn them
- Report the email to the IT security team and delete it (Correct answer)
- Reply to the email asking for verification of identity
Correct answer: Report the email to the IT security team and delete it
Phishing emails should be reported to the IT security team immediately and deleted without clicking any links, to prevent credential theft and protect company systems.
Question 2: What is 'structuring' in the context of BSA/AML compliance?
- Organizing customer accounts into risk tiers
- Breaking up large cash transactions to avoid the CTR filing requirement (Correct answer)
- Creating complex financial products for high-net-worth clients
- Structuring loan repayment schedules for compliance
Correct answer: Breaking up large cash transactions to avoid the CTR filing requirement
Structuring (also called 'smurfing') is the illegal act of deliberately breaking up large cash transactions into smaller amounts to evade the $10,000 CTR reporting threshold.
Question 3: Under the Equal Credit Opportunity Act (ECOA), which factor is PROHIBITED from being used in a credit decision?
- Credit score
- Debt-to-income ratio
- National origin (Correct answer)
- Length of employment
Correct answer: National origin
ECOA prohibits credit discrimination based on race, color, religion, national origin, sex, marital status, age, or receipt of public assistance.
Question 4: What is the purpose of a Suspicious Activity Report (SAR)?
- To report customer complaints about fraudulent charges
- To notify customers of suspected fraud on their accounts
- To alert FinCEN of transactions that may involve money laundering or other crimes (Correct answer)
- To document internal employee misconduct
Correct answer: To alert FinCEN of transactions that may involve money laundering or other crimes
SARs are confidential reports filed with FinCEN to alert law enforcement of transactions suspected to involve money laundering, fraud, or other financial crimes.
Question 5: A new hire at Capital One is asked by their manager to skip the mandatory compliance training to meet a project deadline. What should the employee do?
- Skip the training since the manager approved it
- Complete the training and inform HR or compliance that the manager requested they skip it (Correct answer)
- Complete the project first and take the training within the next month
- Ask a coworker to certify the training on their behalf
Correct answer: Complete the training and inform HR or compliance that the manager requested they skip it
Mandatory compliance training cannot be waived by a manager; the employee should complete the training and escalate the inappropriate request through proper channels.
Question 6: What does the Community Reinvestment Act (CRA) require of banks like Capital One?
- To offer free checking accounts to low-income customers
- To reinvest a percentage of profits into community development bonds
- To meet the credit needs of the communities they serve, including low- and moderate-income neighborhoods (Correct answer)
- To maintain branches in every county where they have customers
Correct answer: To meet the credit needs of the communities they serve, including low- and moderate-income neighborhoods
The CRA requires banks to help meet the credit needs of all segments of their communities, including low- and moderate-income areas, and are evaluated by regulators on this performance.
Question 7: Which practice BEST demonstrates compliance with the Fair Credit Reporting Act (FCRA) when denying a credit application?
- Verbally explaining to the customer why they were denied
- Sending an adverse action notice with the specific reasons for denial and credit bureau contact information (Correct answer)
- Offering the customer a secured card instead without explanation
- Storing the denial reason internally without notifying the customer
Correct answer: Sending an adverse action notice with the specific reasons for denial and credit bureau contact information
FCRA requires that when credit is denied based on information in a credit report, the applicant must receive an adverse action notice stating the reasons and how to contact the credit reporting agency.
A Capital One associate receives a phishing email appearing to be from IT asking them to reset their password via a provided link.
What is the BEST response?