CIPA CIPA Digital Identity & Online Security 2 — Questions and Answers
Question 1: What is 'account takeover' (ATO) fraud?
- Opening a new account using stolen identity information
- Gaining unauthorized access to an existing account to commit fraud (Correct answer)
- Cloning a victim's physical credit card
- Submitting false insurance claims
Correct answer: Gaining unauthorized access to an existing account to commit fraud
Account takeover fraud occurs when a criminal gains unauthorized access to a legitimate user's existing account, typically to steal funds or personal data.
Question 2: Which of the following is a recommended best practice for creating strong passwords?
- Using a pet's name followed by a birth year
- Using a mix of uppercase, lowercase, numbers, and symbols of at least 12 characters (Correct answer)
- Storing passwords in a plain text file for easy access
- Using the same password for all financial accounts
Correct answer: Using a mix of uppercase, lowercase, numbers, and symbols of at least 12 characters
Strong passwords combine uppercase and lowercase letters, numbers, and symbols, and should be at least 12 characters long to resist brute-force attacks.
Question 3: What role does a password manager play in identity protection?
- It stores passwords in an unencrypted format for convenience
- It generates and securely stores unique, complex passwords for each account (Correct answer)
- It shares passwords with trusted contacts automatically
- It resets all passwords on a weekly schedule
Correct answer: It generates and securely stores unique, complex passwords for each account
A password manager generates and encrypts unique, complex passwords for each account, reducing the risk from password reuse and weak credentials.
Question 4: A client receives an email appearing to be from their bank asking them to verify their login credentials. This is most likely an example of:
- Vishing
- Spear phishing (Correct answer)
- Smishing
- Pharming
Correct answer: Spear phishing
Spear phishing is a targeted phishing attack that appears to come from a trusted source, such as a bank, to trick the recipient into revealing credentials.
Question 5: Why should clients be cautious about using public Wi-Fi networks for sensitive transactions?
- Public Wi-Fi is slower and less convenient
- Attackers can intercept unencrypted data transmitted over unsecured networks (Correct answer)
- Public networks do not support HTTPS
- Public Wi-Fi prevents access to financial websites
Correct answer: Attackers can intercept unencrypted data transmitted over unsecured networks
On unsecured public Wi-Fi, attackers can use packet sniffing or man-in-the-middle techniques to intercept unencrypted sensitive data such as login credentials.
Question 6: What is the purpose of a Virtual Private Network (VPN) in the context of identity protection?
- To increase internet download speeds
- To encrypt internet traffic and mask the user's IP address (Correct answer)
- To block all outgoing emails
- To scan devices for malware
Correct answer: To encrypt internet traffic and mask the user's IP address
A VPN encrypts the user's internet traffic and conceals their IP address, making it more difficult for attackers or third parties to intercept data or track online activity.
What is 'account takeover' (ATO) fraud?