โ† All CFP Flashcard Decks

CFP Cybersecurity & Data Privacy in Finance Flashcards

6 cards from real CFP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CFP Cybersecurity & Data Privacy in Finance flashcards as text
  1. What does 'incident response plan' refer to in fintech cybersecurity?

    Answer: A documented procedure for detecting, containing, and recovering from security incidents

    An incident response plan outlines the steps a fintech must follow to detect, contain, eradicate, and recover from cybersecurity events while minimizing damage.

  2. What is 'tokenization' as used in payment security?

    Answer: Replacing sensitive payment data with a non-sensitive substitute (token)

    Tokenization replaces sensitive cardholder data with a unique, randomly generated token that has no exploitable value, reducing breach risk in payment systems.

  3. Which U.S. law requires financial institutions to notify customers and regulators promptly after a data breach?

    Answer: GLBA Safeguards Rule (FTC breach notification)

    The updated FTC Safeguards Rule requires non-bank financial institutions to report breaches affecting 500 or more customers to the FTC as soon as possible.

  4. What is 'social engineering' in the context of fintech cybersecurity threats?

    Answer: Manipulating individuals into divulging confidential information

    Social engineering exploits human psychology rather than technical vulnerabilities, tricking employees or customers into revealing credentials or authorizing fraudulent transactions.

  5. What is the role of a Security Operations Center (SOC) in a fintech company?

    Answer: Monitoring, detecting, and responding to cybersecurity threats in real time

    A SOC provides 24/7 real-time monitoring of a fintech's systems to rapidly detect, analyze, and respond to cybersecurity incidents.

  6. Which approach best describes 'privacy by design' in fintech product development?

    Answer: Embedding data privacy controls into the system architecture from the start

    Privacy by design means proactively integrating privacy and data protection into the design of fintech systems and processes rather than retrofitting them afterward.