Which control helps prevent EFT fraud by verifying addresses and identity?

Prepare for the Coach CFE Exam. Study using flashcards and multiple-choice questions, each with hints and explanations. Get ready for your assessment!

Multiple Choice

Which control helps prevent EFT fraud by verifying addresses and identity?

Explanation:
Verifying identity when a request to change an address is made is a key security control to stop EFT fraud. Address changes are high-risk because they can redirect funds or communications, so confirming who is making the request through an independent channel helps ensure the person is the legitimate account holder. This approach uses out-of-band verification—calling the customer on a known number or sending a confirmation via mail—before updating sensitive information. It creates a reliable check that the requester truly is authorized, reducing the chance that a fraudster with stolen credentials can hijack an account or divert funds. Sending PINs with usernames by mail or through any insecure channel is risky because mail can be intercepted, exposing access credentials. Disregarding address verification for existing customers misses a critical control point; even established customers can be targets of social engineering. Sharing passwords with customers is improper practice—passwords should never be exchanged or transmitted insecurely; secure password resets and authentication processes should be used instead. In short, confirming changes through a trusted, independent channel is the most effective way to protect accounts during address-change requests.

Verifying identity when a request to change an address is made is a key security control to stop EFT fraud. Address changes are high-risk because they can redirect funds or communications, so confirming who is making the request through an independent channel helps ensure the person is the legitimate account holder.

This approach uses out-of-band verification—calling the customer on a known number or sending a confirmation via mail—before updating sensitive information. It creates a reliable check that the requester truly is authorized, reducing the chance that a fraudster with stolen credentials can hijack an account or divert funds.

Sending PINs with usernames by mail or through any insecure channel is risky because mail can be intercepted, exposing access credentials. Disregarding address verification for existing customers misses a critical control point; even established customers can be targets of social engineering. Sharing passwords with customers is improper practice—passwords should never be exchanged or transmitted insecurely; secure password resets and authentication processes should be used instead.

In short, confirming changes through a trusted, independent channel is the most effective way to protect accounts during address-change requests.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy