CIPA Identity Theft Risk Assessment & Prevention 3 — Questions and Answers
Question 1: Which type of identity theft is MOST difficult to detect because it does not directly affect the victim's existing credit accounts?
- Account takeover fraud
- Synthetic identity fraud (Correct answer)
- Tax identity theft
- Medical identity theft
Correct answer: Synthetic identity fraud
Synthetic identity fraud blends real and fabricated information to create a new identity, so victims may never see it on their own credit reports.
Question 2: When performing a digital footprint risk assessment, which finding represents the HIGHEST exposure risk?
- A LinkedIn profile listing current employer
- Mother's maiden name listed on a public genealogy website (Correct answer)
- A public Instagram account showing vacation photos
- An old Yelp review with the client's first name
Correct answer: Mother's maiden name listed on a public genealogy website
Mother's maiden name is a common security verification question, and its public availability dramatically lowers barriers to account takeover.
Question 3: A CIPA advisor recommends placing a security freeze versus a fraud alert. When is a security freeze PREFERRED?
- When the client suspects their mail has been stolen
- When the client needs to apply for new credit within 30 days
- When confirmed identity theft has occurred and no new credit is needed (Correct answer)
- When a client wants to monitor activity without restricting applications
Correct answer: When confirmed identity theft has occurred and no new credit is needed
A security freeze provides stronger protection by blocking new credit inquiries entirely, making it the preferred tool when no new credit is anticipated after confirmed theft.
Question 4: Which behavior MOST increases an employee's risk of workplace identity theft?
- Using a company-issued laptop for personal banking
- Leaving personnel files in an unlocked desk drawer
- Sharing login credentials with a trusted supervisor (Correct answer)
- Receiving personal mail at a work address
Correct answer: Sharing login credentials with a trusted supervisor
Sharing login credentials violates security protocols and creates liability, as the other party gains access to systems containing sensitive personal data.
Question 5: Which IRS program is specifically designed to reduce tax identity theft risk for individuals with prior victimization?
- The IRS Direct File program
- The IRS Identity Protection PIN (IP PIN) program (Correct answer)
- The IRS Online Account self-service portal
- The IRS Taxpayer Advocate Service
Correct answer: The IRS Identity Protection PIN (IP PIN) program
The IRS IP PIN is a six-digit number that prevents fraudulent tax returns from being filed using a victim's SSN by requiring it to process their legitimate return.
Question 6: When assessing risk for elderly clients, which vulnerability is MOST unique to their demographic?
- Susceptibility to phishing emails
- Higher likelihood of being targeted by trusted family or caregivers (Correct answer)
- Lack of awareness about credit monitoring
- Tendency to use weak passwords
Correct answer: Higher likelihood of being targeted by trusted family or caregivers
Elder financial abuse and identity theft by known individuals — including family members and caregivers — is a statistically distinct and underreported risk for seniors.
Question 7: A client discovers a collection account on their credit report for a debt they do not recognize. What is the FIRST recommended action?
- Pay the collection to protect their credit score
- File a police report immediately
- Request their full credit reports from all three bureaus and dispute the account (Correct answer)
- Contact the collection agency to negotiate a settlement
Correct answer: Request their full credit reports from all three bureaus and dispute the account
Pulling all three bureau reports first establishes the full scope of the problem before taking any action, as additional fraudulent accounts may exist.
Which type of identity theft is MOST difficult to detect because it does not directly affect the victim's existing credit accounts?