CIPA Client Education & Protection Strategies 4 — Questions and Answers
Question 1: A client asks what to do FIRST after discovering they are a victim of identity theft. What should an advisor recommend?
- File a police report immediately at the local precinct
- Place a fraud alert with one major credit bureau, which notifies the others (Correct answer)
- Cancel all existing bank accounts and open new ones
- Post a public notice on social media to warn others
Correct answer: Place a fraud alert with one major credit bureau, which notifies the others
Placing an initial fraud alert with any one of the three major bureaus (Equifax, Experian, TransUnion) triggers that bureau to notify the other two, providing immediate protection.
Question 2: Which of the following correctly describes an 'extended fraud alert'?
- It lasts 90 days and is available to any consumer who requests it
- It lasts 7 years and is available only to confirmed identity theft victims (Correct answer)
- It lasts 1 year and requires annual renewal
- It lasts indefinitely and replaces the need for a credit freeze
Correct answer: It lasts 7 years and is available only to confirmed identity theft victims
An extended fraud alert lasts seven years and requires consumers to provide documentation confirming they are identity theft victims.
Question 3: A client uses public Wi-Fi at a coffee shop to access their bank account. Which risk should an advisor emphasize?
- The bank's server may reject the login due to geolocation mismatch
- Attackers can intercept unencrypted data via a man-in-the-middle attack (Correct answer)
- Public Wi-Fi automatically encrypts all banking traffic by default
- The risk is minimal if the client logs out immediately after use
Correct answer: Attackers can intercept unencrypted data via a man-in-the-middle attack
Public Wi-Fi networks are vulnerable to man-in-the-middle attacks where attackers intercept and capture sensitive data transmitted on the network.
Question 4: Under the Fair Credit Reporting Act (FCRA), how long can most negative information remain on a consumer's credit report?
- 3 years
- 5 years
- 7 years (Correct answer)
- 10 years
Correct answer: 7 years
Most negative items such as late payments, collections, and charge-offs can remain on a credit report for up to seven years under the FCRA.
Question 5: A client wants to monitor their credit proactively. Which combination provides the MOST comprehensive protection?
- Checking one credit report every three years and using basic antivirus software
- Enrolling in credit monitoring, reviewing all three bureau reports annually, and using identity theft insurance (Correct answer)
- Relying solely on bank fraud alerts and avoiding online banking
- Checking only their highest-limit card statements monthly
Correct answer: Enrolling in credit monitoring, reviewing all three bureau reports annually, and using identity theft insurance
Combining multi-bureau credit monitoring, regular report reviews, and identity theft insurance creates layered, proactive protection across multiple vectors.
Question 6: Which agency should a client contact to report identity theft and create an official recovery plan?
- The Consumer Financial Protection Bureau (CFPB)
- IdentityTheft.gov operated by the Federal Trade Commission (FTC) (Correct answer)
- The Social Security Administration (SSA) fraud hotline
- The Department of Justice (DOJ) cybercrime division
Correct answer: IdentityTheft.gov operated by the Federal Trade Commission (FTC)
IdentityTheft.gov, managed by the FTC, is the official U.S. government resource for reporting identity theft and generating a personalized recovery plan.
Question 7: A client's medical insurance claim is denied because records show a procedure they never had. This MOST likely indicates:
- A billing error by the insurance company's coding department
- Medical identity theft where someone used their insurance to receive care (Correct answer)
- A duplicate claim submission by the healthcare provider
- A coverage lapse that caused prior claims to be applied incorrectly
Correct answer: Medical identity theft where someone used their insurance to receive care
Medical identity theft occurs when someone uses another person's health insurance information to receive medical care, leaving false records in the victim's file.
A client asks what to do FIRST after discovering they are a victim of identity theft.
What should an advisor recommend?