Independent exam preparation · Original questions, every answer explained Reviews
Finance Exam Pro

Account Takeover

Appears in our practice questions for: Series 24

A form of identity theft in which a fraudster gains unauthorized control of a customer's existing account, often to redirect disbursements. A firm's identity theft prevention program must include red flags designed to detect account takeover attempts.

Practice questions using Account Takeover

Original questions written against the published FINRA and NASAA exam content outlines — not actual exam questions. Every choice is explained.

A firm's written identity-theft prevention program lists categories of red flags but has never been reviewed or updated since it was first adopted years ago, even as new types of account takeover schemes have become common industry-wide. What must the principal ensure?

  1. A.Nothing, as long as the program was approved by the board of directors when adoptedWrong. Initial board approval does not substitute for the ongoing obligation to update the program as risks evolve.
  2. B.Nothing, because identity-theft red flags programs are only required to be updated every ten yearsWrong. This invents a specific ten-year cycle that has no basis in the ongoing-currency obligation.
  3. C.Nothing, since the program was compliant when it was first adoptedWrong. Initial adoption alone does not satisfy the ongoing obligation to keep the program current against evolving risks.
  4. D.Ensure the program is periodically reviewed and updated to address new and evolving identity-theft risksCorrect. An identity-theft prevention program must be kept current through periodic review and updating, not left static after initial adoption.

Why: An identity-theft prevention program under Regulation S-ID should be periodically reviewed and updated to address changes in the types of risks the firm faces. The principal must ensure the program is actually kept current, not treat initial adoption as satisfying an ongoing obligation.

A customer calls in and requests a large wire transfer to a new, unfamiliar recipient account, using language and phrasing the representative finds subtly inconsistent with how this customer normally communicates. What should the principal expect the firm's identity-theft red flags program to require?

  1. A.To recognize the unusual pattern as a potential red flag and verify the customer's identity and request through additional means before processingCorrect. A red flags program should prompt additional verification when unusual patterns suggest possible identity theft, rather than proceeding on account familiarity alone.
  2. B.To process the wire immediately and address any concerns only if the customer later disputes the transactionWrong. Waiting for a dispute after the fact defeats the preventive purpose of an identity-theft red flags program.
  3. C.To decline all wire transfer requests permanently for that customer's accountWrong. This overreacts; the appropriate response is additional verification of this specific unusual request, not a permanent blanket restriction.
  4. D.To process the request as usual, since it came from the customer's known account and phone numberWrong. This is the exact trap the question describes -- known account details do not rule out identity theft or account takeover.

Why: A red flags program under Regulation S-ID should call for the representative to recognize unusual account activity and communication patterns as potential signs of identity theft or account takeover, and to verify the customer's identity and the legitimacy of the request through additional means before processing it, rather than executing an unusual request simply because it came through the customer's known account.

Related terms

Finance Exam Pro is not affiliated with FINRA, NASAA, or any exam sponsor. Practice questions are original and are not actual exam questions. Rules change — confirm current requirements with the relevant regulator.