CIPA Client Education & Protection Strategies 3 — Questions and Answers
Question 1: A client is setting up multi-factor authentication (MFA). Which MFA method is considered MOST secure?
- SMS text message codes sent to a mobile phone
- Security questions based on personal history
- A hardware security key (e.g., FIDO2/YubiKey) (Correct answer)
- An email-based one-time passcode
Correct answer: A hardware security key (e.g., FIDO2/YubiKey)
Hardware security keys are resistant to phishing and SIM-swapping attacks, making them the strongest common MFA option.
Question 2: Which of the following is an example of 'synthetic identity theft'?
- Using a deceased person's exact identity to open credit accounts
- Combining a real SSN with fabricated personal information to create a new identity (Correct answer)
- Stealing a wallet and using all cards immediately
- Hacking into a database to steal thousands of complete identity records
Correct answer: Combining a real SSN with fabricated personal information to create a new identity
Synthetic identity fraud merges real elements (often a legitimate SSN) with fictional details to build a new credit identity that is harder to detect.
Question 3: A client's child has never applied for credit but receives a debt collection notice. This is MOST likely an example of:
- A clerical error by the credit bureau
- Child identity theft using the minor's SSN (Correct answer)
- An identity mix-up with a parent sharing the same name
- Normal activity because minors can have authorized user accounts
Correct answer: Child identity theft using the minor's SSN
Children's SSNs are prime targets for identity thieves because they are clean records that may go undetected for years.
Question 4: When advising clients on safe disposal of sensitive documents, which method is recommended?
- Tearing documents into four pieces before recycling
- Placing documents in a sealed bag before trash disposal
- Cross-cut shredding all documents containing personal information (Correct answer)
- Burning documents only when recycling is unavailable
Correct answer: Cross-cut shredding all documents containing personal information
Cross-cut (confetti) shredding renders documents unreadable and is the recommended method for destroying sensitive personal information.
Question 5: A CIPA advisor is working with an elderly client concerned about phone scams. Which tactic is MOST commonly used in phone-based identity fraud targeting seniors?
- Offering legitimate government grants requiring SSN verification
- Impersonating IRS or Medicare officials to demand immediate payment or information (Correct answer)
- Sending physical letters with fake prize notifications
- Installing malware through apps recommended by the caller
Correct answer: Impersonating IRS or Medicare officials to demand immediate payment or information
Government impersonation scams — particularly IRS and Medicare fraud — are among the most prevalent phone-based schemes targeting older adults.
Question 6: Which statement about placing a security freeze is CORRECT under current U.S. federal law?
- Consumers must pay a fee each time they place or lift a freeze
- Security freezes are free for all consumers and can be placed or lifted at no charge (Correct answer)
- Only victims of identity theft are eligible to place a security freeze
- A security freeze automatically expires after one year
Correct answer: Security freezes are free for all consumers and can be placed or lifted at no charge
The Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018 made security freezes free for all U.S. consumers.
Question 7: What is the primary purpose of educating clients about 'account takeover' (ATO) fraud?
- To help clients understand corporate merger regulations
- To ensure clients recognize when criminals gain control of existing legitimate accounts (Correct answer)
- To explain how banks legally transfer accounts between customers
- To describe how creditors reassign delinquent accounts to collectors
Correct answer: To ensure clients recognize when criminals gain control of existing legitimate accounts
Account takeover fraud occurs when a criminal gains unauthorized access to and control of a victim's existing financial or online accounts.
A client is setting up multi-factor authentication (MFA).
Which MFA method is considered MOST secure?