CIPA CIPA Digital Identity & Online Security 1 — Questions and Answers
Question 1: Which of the following best describes a 'digital footprint' in the context of identity protection?
- The trail of data left by a user's online activities (Correct answer)
- A physical signature stored in a database
- A biometric scan used for authentication
- A government-issued digital ID number
Correct answer: The trail of data left by a user's online activities
A digital footprint is the trail of data—including browsing history, social media activity, and transactions—that a person leaves behind online.
Question 2: What is the primary purpose of multi-factor authentication (MFA) in protecting digital identity?
- To speed up the login process
- To require multiple forms of verification before granting access (Correct answer)
- To eliminate the need for passwords
- To encrypt stored user data
Correct answer: To require multiple forms of verification before granting access
MFA requires users to verify their identity through two or more independent factors, significantly reducing the risk of unauthorized account access.
Question 3: A client reuses the same password across multiple websites. What is the primary identity theft risk this creates?
- Slower login speeds
- Credential stuffing attacks (Correct answer)
- Increased phishing susceptibility
- Weaker encryption
Correct answer: Credential stuffing attacks
Credential stuffing uses stolen username/password pairs from one breach to try to access other accounts where the same credentials are reused.
Question 4: Which type of attack involves an adversary secretly intercepting communications between two parties to steal identity data?
- Phishing
- Man-in-the-middle (MITM) attack (Correct answer)
- SQL injection
- Ransomware
Correct answer: Man-in-the-middle (MITM) attack
A man-in-the-middle attack occurs when an attacker secretly relays and possibly alters communications between two parties who believe they are communicating directly.
Question 5: What does 'end-to-end encryption' mean for protecting digital communications?
- Only the sender's device encrypts the message
- The message is encrypted at the sender's device and can only be decrypted by the intended recipient (Correct answer)
- The server decrypts the message before forwarding it
- Encryption is applied only at the receiving end
Correct answer: The message is encrypted at the sender's device and can only be decrypted by the intended recipient
End-to-end encryption ensures that data is encrypted on the sender's device and can only be decrypted by the intended recipient, preventing interception in transit.
Question 6: Which practice best helps clients minimize exposure of personally identifiable information (PII) on social media?
- Using their full legal name and birthdate in profiles
- Keeping profiles public to build credibility
- Reviewing privacy settings and limiting personal details shared publicly (Correct answer)
- Posting location check-ins to establish routine
Correct answer: Reviewing privacy settings and limiting personal details shared publicly
Regularly reviewing and restricting social media privacy settings limits the amount of PII visible to potential attackers or data harvesters.
Which of the following best describes a 'digital footprint' in the context of identity protection?