CFS Identity Theft & Prevention 2 — Questions and Answers
Question 1: Which federal law requires financial institutions to implement a written Identity Theft Prevention Program under the 'Red Flags Rule'?
- Gramm-Leach-Bliley Act
- Fair and Accurate Credit Transactions Act (FACTA) (Correct answer)
- Bank Secrecy Act
- Identity Theft Enforcement and Restitution Act
Correct answer: Fair and Accurate Credit Transactions Act (FACTA)
FACTA Section 114 directed the FTC and other agencies to create the Red Flags Rule requiring covered entities to implement identity theft prevention programs.
Question 2: A fraudster obtains a victim's Social Security number and date of birth to open new credit accounts. This is best classified as which type of identity theft?
- Account takeover fraud
- New account fraud (Correct answer)
- Synthetic identity fraud
- Medical identity theft
Correct answer: New account fraud
New account fraud involves using stolen personally identifiable information to open entirely new credit or financial accounts in the victim's name.
Question 3: Synthetic identity fraud is most challenging to detect because:
- It always involves foreign nationals
- The victim's credit score is immediately destroyed
- There is no single real victim who notices unauthorized charges (Correct answer)
- It requires physical documents to be stolen
Correct answer: There is no single real victim who notices unauthorized charges
Synthetic identities blend real and fabricated information, so no single real person receives statements or notices unusual activity, making detection particularly difficult.
Question 4: Which of the following is a 'Red Flag' indicator of potential identity theft under the FTC's Red Flags Rule?
- Customer requests a credit limit increase
- Address discrepancy between application and credit report (Correct answer)
- Customer opens a second checking account
- Application received via mail rather than online
Correct answer: Address discrepancy between application and credit report
An address discrepancy between what a customer provides and what appears on their credit report is explicitly listed as a Red Flag category requiring investigation.
Question 5: A consumer discovers their medical records contain treatments they never received. This is an example of:
- Insurance premium fraud
- Medical identity theft (Correct answer)
- Healthcare billing fraud
- Prescription drug diversion
Correct answer: Medical identity theft
Medical identity theft occurs when someone uses another person's identity to obtain healthcare services, prescriptions, or medical devices, corrupting the victim's medical records.
Question 6: Under the Identity Theft Enforcement and Restitution Act, federal courts may order identity theft offenders to pay restitution that includes:
- Only direct financial losses
- Lost wages and costs to restore credit only
- The value of time spent restoring credit and reputation (Correct answer)
- Punitive damages to deter future crimes
Correct answer: The value of time spent restoring credit and reputation
The Act expanded restitution to include the value of time victims spend remedying the effects of identity theft, recognizing the significant non-monetary burden on victims.
Question 7: Which technique do identity thieves commonly use to harvest credentials by creating fraudulent copies of legitimate websites?
- Skimming
- Pharming
- Phishing (Correct answer)
- Vishing
Correct answer: Phishing
Phishing involves sending fraudulent communications that appear to come from reputable sources, directing victims to fake websites designed to steal login credentials and personal data.
Which federal law requires financial institutions to implement a written Identity Theft Prevention Program under the 'Red Flags Rule'?