CIPA Client Education & Protection Strategies 2 — Questions and Answers
Question 1: A client wants to protect their Social Security number from misuse. Which practice is MOST effective?
- Memorize the SSN and never carry the card
- Store the SSN card in a fireproof home safe only
- Share the SSN only when legally required and verify requestors (Correct answer)
- Change the SSN annually through the Social Security Administration
Correct answer: Share the SSN only when legally required and verify requestors
SSNs cannot be changed routinely, so limiting disclosure to legally required situations and verifying who is asking is the best protective practice.
Question 2: Which of the following best describes a 'credit freeze' compared to a 'fraud alert'?
- A credit freeze lasts 90 days; a fraud alert is permanent
- A credit freeze blocks new credit inquiries; a fraud alert requests extra verification (Correct answer)
- A fraud alert prevents all credit activity; a credit freeze only slows processing
- Both are identical protections offered by the FTC directly
Correct answer: A credit freeze blocks new credit inquiries; a fraud alert requests extra verification
A credit freeze restricts access to the credit file entirely, while a fraud alert asks creditors to take extra steps to verify identity before extending credit.
Question 3: A client receives an email asking them to verify their bank account details via a link. What type of attack is this?
- Vishing
- Smishing
- Phishing (Correct answer)
- Pharming
Correct answer: Phishing
Phishing uses deceptive emails that impersonate legitimate institutions to trick recipients into revealing sensitive information.
Question 4: When educating clients about password security, which strategy provides the strongest protection?
- Using the same strong password across all financial accounts for consistency
- Creating unique, complex passwords for each account and storing them in a password manager (Correct answer)
- Changing all passwords every week regardless of complexity
- Using personal information like birthdays to make passwords memorable
Correct answer: Creating unique, complex passwords for each account and storing them in a password manager
Unique, complex passwords for each account prevent credential stuffing attacks, and a reputable password manager securely stores them.
Question 5: A client asks about the 'dark web.' What is the MOST accurate description to provide?
- A government-monitored network used only by criminals
- An encrypted portion of the internet where stolen data is frequently bought and sold (Correct answer)
- A social media platform accessible only with special software
- The section of the internet not indexed by standard search engines but safe to browse
Correct answer: An encrypted portion of the internet where stolen data is frequently bought and sold
The dark web is an encrypted overlay network often used for illicit activity, including the sale of stolen personally identifiable information.
Question 6: Which federal law gives consumers the right to one free credit report annually from each major bureau?
- The Fair Credit Billing Act (FCBA)
- The Identity Theft Enforcement and Restitution Act
- The Fair and Accurate Credit Transactions Act (FACTA) (Correct answer)
- The Gramm-Leach-Bliley Act (GLBA)
Correct answer: The Fair and Accurate Credit Transactions Act (FACTA)
FACTA amended the FCRA to entitle every consumer to one free credit report per year from each of the three major credit bureaus via AnnualCreditReport.com.
Question 7: A client notices a small, unfamiliar charge of $1.00 on their credit card statement. Why should an advisor flag this as a potential identity theft indicator?
- Small charges are always billing errors that banks auto-reverse
- Thieves often test stolen card numbers with micro-transactions before making larger purchases (Correct answer)
- It indicates the card issuer is charging a new monthly fee
- A $1.00 charge is below the reporting threshold and can be ignored
Correct answer: Thieves often test stolen card numbers with micro-transactions before making larger purchases
Fraudsters frequently run small test charges to confirm a stolen card number is active before escalating to larger fraudulent purchases.
A client wants to protect their Social Security number from misuse.
Which practice is MOST effective?