CFCS CFCS Cybercrime & Digital Forensics 2 — Questions and Answers
Question 1: Which federal law specifically criminalizes unauthorized access to computers and is frequently used to prosecute cybercrime in the US?
- Bank Secrecy Act
- Computer Fraud and Abuse Act (CFAA) (Correct answer)
- Electronic Communications Privacy Act
- Identity Theft Enforcement and Restitution Act
Correct answer: Computer Fraud and Abuse Act (CFAA)
The Computer Fraud and Abuse Act (CFAA) is the primary US federal statute governing computer-related crimes including unauthorized access and fraud.
Question 2: What is 'dark web' marketplace activity most commonly associated with in financial crime investigations?
- Stock manipulation
- Sale of stolen financial data, drugs, and money laundering services (Correct answer)
- Corporate espionage
- Real estate fraud
Correct answer: Sale of stolen financial data, drugs, and money laundering services
Dark web marketplaces primarily facilitate the sale of stolen financial credentials, personally identifiable information, narcotics, and money laundering services.
Question 3: In digital forensics, what is a 'chain of custody' and why is it critical in financial crime cases?
- A list of cryptocurrency wallet addresses
- A documented record ensuring digital evidence integrity and admissibility in court (Correct answer)
- A regulatory reporting chain for cyber incidents
- A network diagram of criminal actors
Correct answer: A documented record ensuring digital evidence integrity and admissibility in court
Chain of custody documents every person who handled digital evidence and all actions taken, ensuring its integrity and legal admissibility in criminal proceedings.
Question 4: Which financial crime technique involves criminals creating fraudulent online storefronts to collect payments for goods never delivered?
- Account takeover fraud
- E-commerce fraud / ghost merchant scheme (Correct answer)
- Card-not-present fraud
- Triangulation fraud
Correct answer: E-commerce fraud / ghost merchant scheme
Ghost merchant schemes involve setting up fake online stores that collect payments but never fulfill orders, generating illicit revenue through consumer fraud.
Question 5: What does a financial institution's SIEM system primarily do in the context of cybercrime detection?
- Processes customer loan applications
- Collects and correlates security event data to detect anomalous activity in real time (Correct answer)
- Manages regulatory exam schedules
- Handles SWIFT messaging encryption
Correct answer: Collects and correlates security event data to detect anomalous activity in real time
A Security Information and Event Management (SIEM) system aggregates logs from across an organization's IT infrastructure and uses correlation rules to detect suspicious patterns indicative of cyber threats.
Question 6: Which emerging financial crime method involves criminals using AI-generated audio or video to impersonate executives and authorize fraudulent transfers?
- Vishing
- Deepfake fraud (Correct answer)
- Spear phishing
- Man-in-the-middle attack
Correct answer: Deepfake fraud
Deepfake fraud uses AI-synthesized voice or video of executives to trick employees into initiating unauthorized wire transfers or disclosing sensitive information.
Which federal law specifically criminalizes unauthorized access to computers and is frequently used to prosecute cybercrime in the US?