CIPA Identity Theft Risk Assessment & Prevention 2 — Questions and Answers
Question 1: Which factor is considered the HIGHEST risk indicator when assessing an individual's vulnerability to medical identity theft?
- Using public Wi-Fi occasionally
- Sharing insurance cards with family members
- Having multiple healthcare providers with uncoordinated records (Correct answer)
- Receiving paper Explanation of Benefits statements
Correct answer: Having multiple healthcare providers with uncoordinated records
Multiple uncoordinated providers create fragmented records that are harder to monitor for fraudulent entries, increasing medical identity theft risk.
Question 2: A CIPA advisor is conducting a household risk assessment. Which discovery would MOST warrant immediate escalation?
- An unlocked filing cabinet containing tax returns
- A client who never checks their credit report
- Mail piling up at an unoccupied vacation home for two weeks (Correct answer)
- Using the same password for multiple streaming services
Correct answer: Mail piling up at an unoccupied vacation home for two weeks
Accumulated mail at an unoccupied property is a high-priority physical risk because stolen pre-approved offers and financial statements enable new account fraud.
Question 3: When evaluating synthetic identity theft risk for a minor child, which scenario presents the GREATEST concern?
- The child has a savings account opened by parents
- The child's SSN has never been used for any credit (Correct answer)
- The parents claim the child as a dependent on taxes
- The child uses a shared family tablet for schoolwork
Correct answer: The child's SSN has never been used for any credit
A pristine, unused SSN belonging to a minor is highly attractive to fraudsters who can build synthetic identities on it undetected for years.
Question 4: Which prevention strategy BEST addresses the risk of account takeover through SIM swapping?
- Enabling two-factor authentication via SMS
- Setting a port freeze or SIM lock with your mobile carrier (Correct answer)
- Using a unique email address for financial accounts
- Enrolling in credit monitoring services
Correct answer: Setting a port freeze or SIM lock with your mobile carrier
A carrier-level SIM lock or port freeze requires additional in-person verification before a number can be transferred, directly blocking SIM swap attacks.
Question 5: In a risk assessment for a recently divorced client, which asset deserves IMMEDIATE identity theft protection attention?
- Joint bank accounts that have been closed
- Joint credit accounts that have not yet been separated (Correct answer)
- A shared streaming service subscription
- Previously filed joint tax returns
Correct answer: Joint credit accounts that have not yet been separated
Open joint credit accounts give an ex-spouse the ability to run up debt or open new accounts, making them a critical immediate risk post-divorce.
Question 6: Which method of document destruction is recommended for disposing of pre-approved credit card offers?
- Tearing the document in half before discarding
- Placing in a locked recycling bin
- Cross-cut or micro-cut shredding (Correct answer)
- Soaking in water before disposal
Correct answer: Cross-cut or micro-cut shredding
Cross-cut or micro-cut shredding renders documents unreadable and unrecoverable, unlike simple tearing or other methods that can be reassembled.
Question 7: A client reports they recently responded to an email from their bank requesting account verification. What identity theft risk has MOST likely occurred?
- Shoulder surfing
- Dumpster diving
- Phishing credential compromise (Correct answer)
- Social engineering via vishing
Correct answer: Phishing credential compromise
Responding to fraudulent bank emails is a classic phishing attack that likely resulted in credential compromise of the client's online banking login.
Which factor is considered the HIGHEST risk indicator when assessing an individual's vulnerability to medical identity theft?