CIPA Identity Theft Risk Assessment & Prevention 5 — Questions and Answers
Question 1: Which scenario BEST illustrates child identity theft going undetected for an extended period?
- A parent notices unfamiliar charges on a joint checking account
- A child is denied a student loan at age 18 due to a damaged credit history they never created (Correct answer)
- A child's school reports an unauthorized individual claiming to be the parent
- A parent receives a pre-approved credit offer addressed to their child
Correct answer: A child is denied a student loan at age 18 due to a damaged credit history they never created
Child identity theft is often discovered only when the child reaches adulthood and applies for credit, revealing years of fraudulent accounts built on their SSN.
Question 2: When a CIPA advisor reviews a client's risk from dark web exposure, what is the MOST actionable first step?
- Immediately close all existing bank accounts
- Run a dark web scan and change passwords for any accounts with exposed credentials (Correct answer)
- Freeze credit at all three bureaus and wait for alerts
- File a report with the FBI's Internet Crime Complaint Center (IC3)
Correct answer: Run a dark web scan and change passwords for any accounts with exposed credentials
Identifying which specific credentials were exposed and immediately rotating those passwords prevents criminals from exploiting the leaked data.
Question 3: Which risk mitigation strategy is MOST effective for preventing account takeover on financial institution accounts?
- Enrolling in paperless statements
- Using an authenticator app for multi-factor authentication instead of SMS (Correct answer)
- Setting up low-balance alerts via email
- Changing passwords every 90 days
Correct answer: Using an authenticator app for multi-factor authentication instead of SMS
Authenticator app-based MFA is resistant to SIM swapping and SMS interception, making it significantly stronger than SMS-based two-factor authentication.
Question 4: A CIPA candidate is reviewing a client's EOB (Explanation of Benefits) statement for signs of medical identity theft. Which finding is a RED FLAG?
- A claim from a physician the client saw six months ago
- Claims for services at a provider in a city where the client has never received treatment (Correct answer)
- A copay amount that differs from what the client remembers paying
- An EOB arriving by mail instead of electronically
Correct answer: Claims for services at a provider in a city where the client has never received treatment
Services billed from an unknown geographic location are a clear indicator that someone else used the client's insurance information to receive care.
Question 5: Which federal law grants consumers the right to obtain one free credit report from each major bureau annually and dispute inaccurate information?
- The Gramm-Leach-Bliley Act (GLBA)
- The Fair and Accurate Credit Transactions Act (FACTA) (Correct answer)
- The Electronic Communications Privacy Act (ECPA)
- The Identity Theft Enforcement and Restitution Act
Correct answer: The Fair and Accurate Credit Transactions Act (FACTA)
FACTA, an amendment to the FCRA, established the free annual credit report right and added provisions specifically addressing identity theft protection and dispute processes.
Question 6: A client who owns rental properties asks about risks specific to their situation. Which identity theft risk is MOST elevated for landlords?
- Tenants using the landlord's name on utility applications
- Tenants accessing the landlord's home network
- The landlord's address appearing in public property records linked to multiple people (Correct answer)
- Tenants filing complaints with local housing authorities
Correct answer: The landlord's address appearing in public property records linked to multiple people
Public property records tie a landlord's identity to multiple addresses and individuals, making it easier for criminals to build social engineering scripts using that relationship map.
Question 7: In assessing a client's overall identity theft risk level, which combination of factors results in the HIGHEST composite risk score?
- Recent data breach exposure + active social media presence + paperless billing enrolled
- Confirmed SSN exposure on dark web + no credit freeze + reused passwords across financial sites (Correct answer)
- Multiple credit cards + frequent travel + shared household Wi-Fi
- Recent job change + new address + no fraud alert on file
Correct answer: Confirmed SSN exposure on dark web + no credit freeze + reused passwords across financial sites
Dark web SSN exposure combined with no credit freeze and reused passwords creates simultaneous vulnerability to new account fraud and account takeover — the highest-risk combination.
Which scenario BEST illustrates child identity theft going undetected for an extended period?