โ† All CAC Flashcard Decks

Compliance and Regulatory Standards Flashcards

7 cards from real CAC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance and Regulatory Standards flashcards as text
  1. Under the Fair Debt Collection Practices Act, a third-party collector generally may not contact a consumer at which time without consent?

    Answer: 9:30 p.m.

    Communications before 8 a.m. or after 9 p.m. at the consumer's location are presumed inconvenient.

  2. Regulation F (the FDCPA rule) presumes a debt collector violates the law if it calls about a specific debt how often?

    Answer: More than 7 times within 7 days

    Regulation F sets a call-frequency presumption of more than seven calls within seven consecutive days.

  3. The Servicemembers Civil Relief Act caps interest on obligations taken out before active duty at what rate?

    Answer: 6%

    The SCRA limits interest on pre-service debts to 6% during military service, as long as the servicemember gives proper notice.

  4. Under the SCRA, which is generally required before repossessing a servicemember's vehicle financed before entering active duty?

    Answer: A court order

    The SCRA prohibits repossessing property purchased before service without a court order if a deposit or installment was paid before entering service.

  5. Under the Gramm-Leach-Bliley Act, when must a financial institution give a customer an initial privacy notice?

    Answer: No later than when the customer relationship begins

    GLBA's Privacy Rule requires an initial privacy notice by the time the customer relationship is established.

  6. The FTC Safeguards Rule, as amended, requires covered auto finance companies to do which of these?

    Answer: Designate a qualified individual to oversee the information security program

    The amended Safeguards Rule requires a designated qualified individual, risk assessments, MFA, encryption, and other controls.

  7. Under the FTC's Safeguards Rule amendment that took effect in 2024, covered institutions must notify the FTC of a security event involving unencrypted data of at least how many consumers?

    Answer: 500

    Notification is required within 30 days after discovering an event affecting 500 or more consumers.