CORRECT ANSWERS UPDATED 2025
Church Plan - Correct Answersa plan established and maintained for its EEs, or by
a convention or association, is exempt form tax under IRC sec 501
SAR - Correct Answersthis document is the summary of certain info contained in a
plans 5500 report
Fidelity Bond - Correct AnswersThis must be purchased to cover every person who
handles plan funds
1095-C - Correct AnswersThis form is used by Large self insured ERs to report whether
they offer group health ins to any employees, including PT employees.
QSEHRA - Correct AnswersA small ER that does not offer group medical coverage may
offer these.
Age 55 - Correct AnswersExtra catch-up contributions can be made to an HSA by
individuals of this age, or older, until they are eligible to enroll in Medicare
Roth IRA - Correct AnswersRetirement plan contributions that are not deductible from
EE income
Every 5 years - Correct AnswersDistribution period for SPDs with material reductions
and changes
210th day - Correct AnswersThe time frame for distribution of a SPD by the close of the
relevant plan year
90 Days - Correct Answerstime frame for distribution of SPD for new plan ppts
120 Days - Correct Answerstimeline for distribution of plans that become subject to
ERISA
Good Internal Controls - Correct AnswersBest way to reduce/eliminate errors in benefit
plan operations
PII - Correct AnswersInfo that can be used to trace/distinguish a person's identity
404(a) - Correct AnswersSection of ERISA that requires a fiduciary to discharge their
duties
Office of Mgmt and budget (OMB) - Correct AnswersThis office has set definitions for
PII
, Federal Trade Commission (FTC) - Correct AnswersThis agency requires personal data
in benefit plans be protected
A form of data breach identified in Retirement plans - Correct AnswersFailure to install
security system updates
using the same PW for multiple clients
Gramm-Leach-Bliley Act - Correct AnswersLaw that controls the way private info of
individuals is treated
Due Diligence - Correct AnswersCare taken by a reasonable person to avoid harm to
others or their property
Fiduciary Act - Correct AnswersRemoving or retaining a service provider
DOL - Correct AnswersThis agency issued 3 pieces of sub-regulatory guidance
addressing the cybersecurity practices of retirement plan sponsors, their service
providers and plan ppts
GMR Case - Correct AnswersInvolved inadvertent exposure of personal medical
information
Data Breach of Medical Plan - Correct AnswersLost documents with PHI
rx disposals in a trash can
Personal Info - Correct Answersan individuals name in combination with other data
National Institute of standards and technology (NIST) - Correct AnswersThis org.
developed the cybersecurity framework
4/10 audits had unacceptable major deficiencies - Correct Answersresults of the 2014
DOL audit quality study
EE Benefits Security Administration (EBSA) - Correct Answerspart of the DOL,
oversees the quality of benefit plan audits by CPAs
Significant Weakness - Correct AnswersDeficiency in an internal control that is less
severe than a material weakness
Plan Management - Correct AnswersEntity responsible for understanding the objective
of the plan audit
HR, BOD, Legal - Correct AnswersDepts. where fraud occurrences are low