CFP Technology & Digital Applications 2 — Questions and Answers
Question 1: A CFP practitioner is evaluating robo-advisor platforms for a client. Which feature is MOST important for ensuring the platform meets fiduciary standards?
- Lowest management fee available
- Transparent algorithm disclosure and conflict-of-interest policies (Correct answer)
- Integration with the client's existing brokerage
- Availability of tax-loss harvesting
Correct answer: Transparent algorithm disclosure and conflict-of-interest policies
Fiduciary robo-advisors must disclose how their algorithms work and any conflicts of interest, such as proprietary fund preferences.
Question 2: Which cybersecurity framework is most commonly recommended for financial planning firms seeking to protect client data?
- ISO 9001
- NIST Cybersecurity Framework (Correct answer)
- PCI DSS
- SOC 2 Type I
Correct answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework provides a flexible, risk-based approach widely adopted by financial services firms for data protection.
Question 3: A client wants to use a budgeting app that aggregates all financial accounts. What is the primary data-sharing risk the CFP should explain?
- The app may charge hidden subscription fees
- Aggregators may store login credentials or use screen scraping, creating security vulnerabilities (Correct answer)
- The app cannot sync with employer-sponsored retirement plans
- Budget categories may not align with the financial plan
Correct answer: Aggregators may store login credentials or use screen scraping, creating security vulnerabilities
Many aggregators store user credentials or use screen scraping rather than secure API connections, exposing accounts to unauthorized access.
Question 4: Which regulation primarily governs how registered investment advisers must safeguard client data in electronic form?
- Regulation Best Interest (Reg BI)
- Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (Correct answer)
- Dodd-Frank Act Title VII
- Securities Exchange Act Section 10(b)
Correct answer: Gramm-Leach-Bliley Act (GLBA) Safeguards Rule
The GLBA Safeguards Rule requires financial institutions, including RIAs, to develop written information security programs to protect client nonpublic personal information.
Question 5: A client asks about using cryptocurrency as part of their retirement portfolio. Which statement best reflects current CFP guidance?
- Crypto should replace at least 10% of bond allocations for inflation protection
- CFPs must recommend only SEC-registered crypto assets
- Crypto carries significant volatility, regulatory uncertainty, and custody risks that must be clearly disclosed (Correct answer)
- Cryptocurrency income is always tax-free in a self-directed IRA
Correct answer: Crypto carries significant volatility, regulatory uncertainty, and custody risks that must be clearly disclosed
CFP practitioners must disclose the substantial risks of cryptocurrency—including extreme volatility, evolving regulation, and custody challenges—before recommending it.
Question 6: What is open banking, and how does it affect financial planning clients?
- A system where banks share profits with customers through dividends
- A regulatory framework allowing third-party apps to access client financial data via secure APIs with consent (Correct answer)
- A government program providing free checking accounts
- A method of investing in bank stocks through direct purchase plans
Correct answer: A regulatory framework allowing third-party apps to access client financial data via secure APIs with consent
Open banking uses secure APIs so clients can authorize third-party financial apps to access their account data, enabling better financial planning integrations.
Question 7: A financial planning firm stores client files in a cloud service. Which practice BEST reduces the risk of a data breach?
- Using the cheapest cloud provider to minimize costs
- Enabling multi-factor authentication and encrypting data at rest and in transit (Correct answer)
- Allowing all staff unrestricted access to all client files
- Storing backups on the same cloud server as the primary data
Correct answer: Enabling multi-factor authentication and encrypting data at rest and in transit
MFA combined with encryption of data at rest and in transit provides layered security that significantly reduces breach risk.
A CFP practitioner is evaluating robo-advisor platforms for a client.
Which feature is MOST important for ensuring the platform meets fiduciary standards?