Capital One Assessment Test Safety and Compliance 4 — Questions and Answers
Question 1: A Capital One employee discovers that a database containing customer PII was accidentally left publicly accessible online for 48 hours. What is the FIRST step under a proper incident response plan?
- Notify all affected customers by email immediately
- Contain the breach by restricting access and escalate to the security and legal teams (Correct answer)
- Determine exactly which records were accessed before taking any action
- Issue a public press release to maintain transparency
Correct answer: Contain the breach by restricting access and escalate to the security and legal teams
Incident response protocol requires first containing the breach to prevent further exposure, then escalating to the appropriate security, legal, and compliance teams for assessment.
Question 2: Under the Truth in Lending Act (TILA) and Regulation Z, what must be clearly disclosed to a credit card applicant?
- The bank's cost of funds
- The Annual Percentage Rate (APR) and all fees (Correct answer)
- The internal credit scoring model used
- The applicant's projected credit limit increase schedule
Correct answer: The Annual Percentage Rate (APR) and all fees
Regulation Z requires clear disclosure of the APR, fees, and other key credit terms before and after account opening so consumers can make informed credit decisions.
Question 3: An associate is working from a coffee shop and needs to access a customer account to resolve an issue. What is the SAFEST approach?
- Use the coffee shop's public Wi-Fi since the systems require a login password
- Access the account only after connecting through the company's VPN on a secured device (Correct answer)
- Wait until returning to the office or a secure location
- Use a personal hotspot if a VPN is not available
Correct answer: Access the account only after connecting through the company's VPN on a secured device
Accessing customer data remotely must always be done through an approved VPN on a company-secured device to encrypt the connection and protect sensitive information.
Question 4: What is the primary purpose of Know Your Customer (KYC) procedures at Capital One?
- To improve customer satisfaction scores
- To verify customer identity and assess the risk of money laundering or terrorist financing (Correct answer)
- To qualify customers for premium rewards products
- To collect marketing data for targeted product offers
Correct answer: To verify customer identity and assess the risk of money laundering or terrorist financing
KYC procedures verify customer identities and assess financial crime risk as required by BSA/AML regulations and the Customer Identification Program (CIP) rules.
Question 5: A Capital One associate is offered a gift card worth $150 by a vendor they work with regularly. According to typical financial institution gift policies, what should the associate do?
- Accept it as a token of the business relationship
- Accept it and report it to their manager
- Decline it and report the offer to compliance (Correct answer)
- Accept it only if it is disclosed on their annual ethics certification
Correct answer: Decline it and report the offer to compliance
Most financial institutions prohibit employees from accepting gifts above a nominal value from vendors or business partners; the offer should be declined and reported to compliance to avoid conflicts of interest.
Question 6: What does the term 'red flag' refer to in the context of Capital One's Identity Theft Prevention Program under FACTA?
- A customer complaint flagged as high priority
- A pattern or practice that indicates possible identity theft (Correct answer)
- An account that has exceeded its credit limit multiple times
- A transaction declined due to suspected fraud
Correct answer: A pattern or practice that indicates possible identity theft
Under FACTA's Red Flags Rule, a red flag is a pattern, practice, or specific activity that indicates the possible existence of identity theft and triggers further review or action.
Question 7: Which action BEST protects against social engineering attacks targeting Capital One employees?
- Using complex passwords on all accounts
- Verifying the identity of anyone requesting sensitive information through a separate, established channel (Correct answer)
- Locking computer screens when stepping away from desks
- Encrypting all outgoing emails
Correct answer: Verifying the identity of anyone requesting sensitive information through a separate, established channel
Social engineering exploits trust; verifying requests for sensitive information through an independent, pre-established communication channel prevents manipulation even when the requester seems credible.
A Capital One employee discovers that a database containing customer PII was accidentally left publicly accessible online for 48 hours.
What is the FIRST step under a proper incident response plan?