CFE Visual Facilitation Techniques 2 — Questions and Answers
Question 1: When constructing a link analysis chart for a fraud investigation, what is the PRIMARY purpose of node clustering?
- To reduce file size of the diagram
- To group related entities and reveal hidden organizational structures (Correct answer)
- To color-code transactions by dollar amount
- To alphabetize entity names for easy reference
Correct answer: To group related entities and reveal hidden organizational structures
Node clustering groups related entities together to expose hidden hierarchies, shell company networks, and conspiratorial relationships that may not be apparent in raw data.
Question 2: A forensic examiner is presenting a complex embezzlement scheme to a jury. Which visual aid is MOST effective for showing the chronological flow of fraudulent transactions?
- Pie chart showing transaction categories
- Scatter plot of transaction amounts
- Timeline diagram with annotated milestones (Correct answer)
- Heat map of transaction frequency by hour
Correct answer: Timeline diagram with annotated milestones
A timeline diagram with annotated milestones clearly communicates the sequence of events, making it easier for jurors to follow the progression of the fraud scheme.
Question 3: In visual facilitation, what does an 'affinity diagram' primarily help investigators accomplish?
- Track money movement between accounts
- Organize large amounts of qualitative data into meaningful categories (Correct answer)
- Plot geographic locations of witnesses
- Compare suspect profiles side by side
Correct answer: Organize large amounts of qualitative data into meaningful categories
An affinity diagram groups large volumes of qualitative information (observations, ideas, facts) into natural clusters to reveal patterns and themes during investigation.
Question 4: When creating a process flow diagram to depict internal control weaknesses, which element is MOST critical to include for forensic purposes?
- Color-coded department logos
- Decision points where controls were bypassed or overridden (Correct answer)
- Employee photos at each process step
- Software version numbers for each system
Correct answer: Decision points where controls were bypassed or overridden
Decision points where controls were bypassed or overridden are the critical vulnerabilities that show exactly how fraud was enabled within a process.
Question 5: Which visualization technique is BEST suited for identifying an individual who serves as a central connection point between multiple fraud participants?
- Bar chart of individual transaction totals
- Network analysis diagram showing centrality metrics (Correct answer)
- Waterfall chart of cumulative losses
- Gantt chart of investigation milestones
Correct answer: Network analysis diagram showing centrality metrics
Network analysis diagrams with centrality metrics identify 'hub' nodes — individuals with the most connections — revealing key orchestrators of a fraud scheme.
Question 6: A forensic accountant uses a Sankey diagram during a fraud investigation. What type of information does this diagram BEST convey?
- The hierarchy of suspects by seniority
- The volume and direction of fund flows between entities (Correct answer)
- The timeline of document tampering events
- The geographic spread of fraudulent activity
Correct answer: The volume and direction of fund flows between entities
Sankey diagrams are specifically designed to show the magnitude and direction of flows — making them ideal for visualizing how funds move through accounts and entities.
Question 7: During a facilitated fraud brainstorming session, an examiner uses sticky notes on a wall to map out potential fraud schemes. This technique is an example of:
- Digital forensics documentation
- Affinity mapping for hypothesis generation (Correct answer)
- Formal audit trail creation
- Evidence chain-of-custody recording
Correct answer: Affinity mapping for hypothesis generation
Using sticky notes to externalize and spatially organize ideas is a classic affinity mapping technique that helps teams collaboratively generate and categorize fraud hypotheses.
When constructing a link analysis chart for a fraud investigation, what is the PRIMARY purpose of node clustering?