CIPA Identity Theft Risk Assessment & Prevention 4 — Questions and Answers
Question 1: Which risk factor is MOST associated with new account fraud following a large-scale data breach?
- The victim's age
- The type of data exposed, specifically SSN plus date of birth (Correct answer)
- Whether the victim uses credit or debit cards
- The geographic location of the victim
Correct answer: The type of data exposed, specifically SSN plus date of birth
SSN combined with date of birth provides the core identity elements needed to open new credit accounts, making this combination the most dangerous breach exposure.
Question 2: Under the Fair Credit Reporting Act (FCRA), how long does a credit bureau have to investigate a consumer's dispute of a fraudulent account?
- 15 business days
- 30 days (or 45 if additional information is submitted) (Correct answer)
- 60 days from receipt of the dispute
- 90 days if the account is more than two years old
Correct answer: 30 days (or 45 if additional information is submitted)
The FCRA mandates a 30-day investigation window, extendable to 45 days if the consumer provides additional relevant information during the dispute process.
Question 3: Which preventive measure MOST effectively reduces risk from mail theft of financial documents?
- Switching all statements to paperless delivery and using a USPS-informed delivery account (Correct answer)
- Installing a mailbox with a combination lock
- Using a P.O. box for all correspondence
- Collecting mail within 24 hours of anticipated delivery
Correct answer: Switching all statements to paperless delivery and using a USPS-informed delivery account
Paperless delivery eliminates the physical document entirely, and USPS Informed Delivery provides digital previews so the client knows what should arrive — a dual-layer solution.
Question 4: A client is a gig economy worker who frequently uses public Wi-Fi. Which tool MOST directly mitigates their network-based identity theft risk?
- Antivirus software with real-time scanning
- A virtual private network (VPN) with encryption (Correct answer)
- Two-factor authentication on all accounts
- A password manager with strong unique passwords
Correct answer: A virtual private network (VPN) with encryption
A VPN encrypts all internet traffic, preventing man-in-the-middle attacks on public Wi-Fi that could capture login credentials and personal data.
Question 5: When assessing business identity theft risk for a small business owner, which exposure is MOST commonly overlooked?
- Employee access to QuickBooks
- The business's EIN being publicly listed in state registration records (Correct answer)
- Using a personal credit card for business expenses
- The owner's personal SSN used during business formation
Correct answer: The business's EIN being publicly listed in state registration records
State business registrations are often public records that expose the EIN, which criminals use to open fraudulent credit lines in the business's name.
Question 6: Which element of a comprehensive identity theft risk assessment specifically evaluates digital account hygiene?
- Reviewing physical mail storage practices
- Auditing password strength, reuse, and multi-factor authentication enrollment (Correct answer)
- Checking the number of credit accounts open
- Assessing the client's awareness of phishing tactics
Correct answer: Auditing password strength, reuse, and multi-factor authentication enrollment
Digital account hygiene evaluation directly measures password security and MFA adoption — the two primary defenses against unauthorized account access.
Question 7: A client placed a fraud alert on their credit file. Which statement MOST accurately describes how this affects new credit applications?
- All new credit applications are automatically denied for 90 days
- Creditors must take reasonable steps to verify the applicant's identity before extending credit (Correct answer)
- The client must manually approve each credit inquiry in real time
- Only hard inquiries from lenders are blocked; soft pulls are unaffected
Correct answer: Creditors must take reasonable steps to verify the applicant's identity before extending credit
A fraud alert requires creditors to take reasonable identity verification steps before opening new accounts, but does not automatically deny applications.
Which risk factor is MOST associated with new account fraud following a large-scale data breach?