CIPA Client Education & Protection Strategies 5 — Questions and Answers
Question 1: Which type of identity theft involves a criminal using a victim's identity specifically to evade law enforcement or criminal charges?
- Financial identity theft
- Medical identity theft
- Criminal identity theft (Correct answer)
- Synthetic identity theft
Correct answer: Criminal identity theft
Criminal identity theft occurs when someone provides another person's identifying information to police during arrest or investigation, creating a false criminal record for the victim.
Question 2: A client asks about 'SIM swapping.' What should an advisor explain?
- A technique to upgrade to a newer SIM card for better coverage
- A fraud where attackers convince a carrier to transfer a victim's number to a criminal's SIM (Correct answer)
- A method banks use to verify identity through mobile carriers
- A legitimate service to keep the same number when switching phones
Correct answer: A fraud where attackers convince a carrier to transfer a victim's number to a criminal's SIM
SIM swapping is a social engineering attack where fraudsters impersonate a victim to a mobile carrier, redirecting calls and texts — including MFA codes — to the attacker's device.
Question 3: When advising clients on social media privacy, which practice MOST reduces identity theft risk?
- Using a nickname on all platforms so real identity is hidden
- Setting profiles to private and avoiding posting personal details like full birthdate or address (Correct answer)
- Only using social media platforms headquartered in the United States
- Accepting only verified users as connections or followers
Correct answer: Setting profiles to private and avoiding posting personal details like full birthdate or address
Private settings and limiting disclosure of identifying details minimize the personal information available for social engineering or identity reconstruction by bad actors.
Question 4: A CIPA professional helps a client understand 'pretexting.' Which scenario BEST illustrates this tactic?
- A hacker exploiting a software vulnerability to access a database
- A criminal calling a bank while posing as the account holder to extract account details (Correct answer)
- An attacker sending mass phishing emails to thousands of recipients
- Malware installed through a malicious email attachment
Correct answer: A criminal calling a bank while posing as the account holder to extract account details
Pretexting is a social engineering technique where an attacker fabricates a scenario (pretext) to manipulate another person into divulging confidential information.
Question 5: Which of the following is the BEST advice for a client who has received a data breach notification from a company?
- Wait for the company to resolve the issue before taking any personal action
- Change passwords for the breached account and any accounts sharing that password, and monitor credit (Correct answer)
- File a lawsuit immediately against the breached company
- Ignore it if no fraudulent charges appear within 30 days
Correct answer: Change passwords for the breached account and any accounts sharing that password, and monitor credit
Immediately changing credentials and monitoring credit after a breach reduces the window during which stolen data can be exploited.
Question 6: A client asks why tax-related identity theft is particularly damaging. What is the MOST accurate explanation?
- It causes the victim to owe additional taxes to the IRS immediately
- Thieves use the victim's SSN to file a fraudulent return and claim a refund before the victim files (Correct answer)
- The IRS shares tax data with credit bureaus, damaging the victim's credit score
- Tax theft results in automatic criminal charges against the victim
Correct answer: Thieves use the victim's SSN to file a fraudulent return and claim a refund before the victim files
Tax identity thieves file fraudulent returns early in the tax season using stolen SSNs to collect refunds, causing the legitimate taxpayer's return to be rejected when they file.
Question 7: Which of the following client behaviors represents the HIGHEST risk for identity theft?
- Using a VPN when accessing financial accounts on mobile data
- Receiving paper bank statements mailed to a secure P.O. box
- Clicking links in unsolicited emails to 'verify' account information (Correct answer)
- Reviewing credit reports quarterly via AnnualCreditReport.com
Correct answer: Clicking links in unsolicited emails to 'verify' account information
Clicking links in unsolicited emails is the hallmark of phishing susceptibility, the leading method through which identities and credentials are stolen.
Which type of identity theft involves a criminal using a victim's identity specifically to evade law enforcement or criminal charges?