CFE Legal Frameworks & Regulatory Standards 3 โ Questions and Answers
Question 1: Under the Federal Rules of Evidence Rule 702, a forensic expert witness must demonstrate that their testimony is based on:
- Personal observation only
- Sufficient facts or data and reliable principles and methods (Correct answer)
- Peer-reviewed publications exclusively
- The judge's prior approval of methodology
Correct answer: Sufficient facts or data and reliable principles and methods
FRE 702 requires expert testimony to rest on sufficient facts or data, reliable principles/methods, and reliable application of those methods to the facts.
Question 2: Which doctrine holds that evidence derived from an illegal search is inadmissible in court?
- Fruit of the poisonous tree (Correct answer)
- Chain of custody doctrine
- Best evidence rule
- Collateral estoppel
Correct answer: Fruit of the poisonous tree
The 'fruit of the poisonous tree' doctrine excludes evidence obtained as a result of an unlawful search or seizure under the Fourth Amendment.
Question 3: The Health Insurance Portability and Accountability Act (HIPAA) Security Rule requires covered entities to implement which category of safeguards for electronic PHI?
- Physical, administrative, and technical safeguards only (Correct answer)
- Physical, administrative, technical, and organizational safeguards
- Technical and administrative safeguards only
- Physical and technical safeguards only
Correct answer: Physical, administrative, and technical safeguards only
HIPAA Security Rule mandates physical, administrative, and technical safeguards to protect electronic protected health information (ePHI).
Question 4: A forensic examiner is asked to testify about findings in a state court case. Which standard for expert testimony most commonly applies in state courts that have NOT adopted the Daubert standard?
- Frye general acceptance standard (Correct answer)
- Federal Rules of Evidence 702
- Kumho Tire standard
- Joiner standard
Correct answer: Frye general acceptance standard
The Frye standard, requiring scientific evidence to be 'generally accepted' in the relevant scientific community, is still used by some states that have not adopted Daubert.
Question 5: Under 18 U.S.C. ยง 1030 (Computer Fraud and Abuse Act), accessing a protected computer without authorization to obtain information carries criminal liability. What makes a computer 'protected' under this statute?
- It must store classified government data
- It is used in or affects interstate or foreign commerce or communication (Correct answer)
- It must have encryption software installed
- It belongs to a financial institution only
Correct answer: It is used in or affects interstate or foreign commerce or communication
Under the CFAA, a 'protected computer' is one used in or affecting interstate or foreign commerce or communication, which broadly covers virtually all internet-connected systems.
Question 6: Which legal privilege most commonly protects communications between a forensic examiner hired by defense counsel and that counsel?
- Attorney-client privilege
- Work product doctrine (Correct answer)
- Doctor-patient privilege
- Spousal privilege
Correct answer: Work product doctrine
The work product doctrine protects materials prepared by or for an attorney in anticipation of litigation, including forensic reports commissioned by defense counsel.
Question 7: The Sarbanes-Oxley Act Section 802 imposes criminal penalties for altering or destroying records with intent to obstruct a federal investigation. The maximum prison term for this offense is:
- 5 years
- 10 years
- 20 years (Correct answer)
- 25 years
Correct answer: 20 years
SOX Section 802 provides for up to 20 years imprisonment for knowingly altering, destroying, or falsifying records in a federal investigation or bankruptcy proceeding.
Under the Federal Rules of Evidence Rule 702, a forensic expert witness must demonstrate that their testimony is based on: