← All CFP Flashcard Decks

CFP Cybersecurity & Data Privacy in Finance Flashcards

6 cards from real CFP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CFP Cybersecurity & Data Privacy in Finance flashcards as text
  1. Which U.S. federal law primarily governs the privacy and security of consumer financial data held by financial institutions?

    Answer: Gramm-Leach-Bliley Act (GLBA)

    The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their data-sharing practices and protect sensitive consumer information.

  2. What type of attack involves cybercriminals intercepting communication between a fintech app and its server to steal credentials?

    Answer: Man-in-the-middle (MITM) attack

    A man-in-the-middle attack intercepts data in transit, making it critical for fintechs to use TLS/SSL encryption and certificate pinning.

  3. Which security framework is most widely adopted by U.S. financial institutions to manage cybersecurity risk?

    Answer: NIST Cybersecurity Framework

    The NIST Cybersecurity Framework (CSF) is the most widely adopted standard by U.S. financial institutions for identifying, protecting, detecting, responding to, and recovering from cyber threats.

  4. What does 'data minimization' mean in the context of fintech data privacy?

    Answer: Collecting only the data necessary for the specified purpose

    Data minimization is the principle of collecting and retaining only the personal data strictly necessary for a defined purpose, reducing exposure in case of a breach.

  5. Which payment card data security standard must fintech companies handling card transactions comply with?

    Answer: PCI DSS

    The Payment Card Industry Data Security Standard (PCI DSS) sets requirements for all entities that store, process, or transmit cardholder data.

  6. What is the purpose of multi-factor authentication (MFA) in fintech applications?

    Answer: To verify user identity using two or more independent factors

    MFA adds layers of security by requiring users to verify their identity through multiple independent factors such as a password plus a one-time code.