CFPT Technology and Communications 5 — Questions and Answers
Question 1: What is 'spear phishing' and how does it differ from general phishing attacks?
- Spear phishing targets random users while phishing targets specific individuals
- Spear phishing is a targeted attack customized for a specific individual or organization (Correct answer)
- Spear phishing only occurs via text message while phishing is email-based
- They are identical — 'spear phishing' is simply an older term for the same attack
Correct answer: Spear phishing is a targeted attack customized for a specific individual or organization
Spear phishing uses personalized details about the target to craft convincing deceptive messages, making it more dangerous than generic phishing campaigns.
Question 2: What is the purpose of a 'records retention schedule' in the context of consular records management?
- To determine which staff members may access specific records
- To specify how long different categories of records must be kept and when they should be destroyed (Correct answer)
- To schedule regular backups of electronic consular databases
- To rank records by their classification level
Correct answer: To specify how long different categories of records must be kept and when they should be destroyed
A records retention schedule defines mandatory timeframes for keeping official records and the proper disposition method (e.g., destruction or permanent archive) when those periods expire.
Question 3: Which of the following best describes the concept of 'chain of custody' as it applies to digital evidence in a consular fraud investigation?
- The hierarchy of officers who review a fraud case
- The documented, unbroken record of who handled digital evidence and how it was preserved (Correct answer)
- The sequential steps in processing a visa application
- The encrypted pathway data travels between consular posts
Correct answer: The documented, unbroken record of who handled digital evidence and how it was preserved
Chain of custody documents every person who handled digital evidence and every action taken, ensuring its integrity and admissibility in legal proceedings.
Question 4: A foreign national applies for a nonimmigrant visa and claims their prior visa was lost. What technology-based system would a consular officer use to verify the claim?
- The applicant's personal email records
- The Consular Consolidated Database (CCD) to check prior visa issuance records (Correct answer)
- Interpol's public database
- The applicant's home country immigration records directly
Correct answer: The Consular Consolidated Database (CCD) to check prior visa issuance records
The CCD contains records of all U.S. visa applications and issuances, allowing officers to verify whether a visa was previously issued regardless of applicant claims.
Question 5: What is 'multifactor authentication using a PIV card' as used by State Department employees?
- A paper-based identity verification process requiring two supervisors
- Authentication using a Personal Identity Verification smart card combined with a PIN (Correct answer)
- A biometric scan combined with a physical key
- A dual-password system for classified systems
Correct answer: Authentication using a Personal Identity Verification smart card combined with a PIN
A PIV (Personal Identity Verification) card is a federal smart card that, combined with a PIN, provides strong two-factor authentication for accessing government systems.
Question 6: Under what circumstances may a consular officer share visa applicant biometric data with a foreign government?
- Whenever the foreign government formally requests it
- Only pursuant to a bilateral data-sharing agreement or treaty that authorizes such sharing (Correct answer)
- When the applicant provides verbal consent at the interview
- Biometric data may never be shared under any circumstances
Correct answer: Only pursuant to a bilateral data-sharing agreement or treaty that authorizes such sharing
Sharing biometric data with foreign governments requires a legal framework such as a bilateral agreement — ad hoc sharing without such authority is prohibited.
Question 7: What is the significance of the 'Classification by Compilation' principle in diplomatic communications?
- Cables must be classified based on the most sensitive individual paragraph
- Combining multiple unclassified pieces of information can create a classified document requiring higher protection (Correct answer)
- Officers must classify documents based on the total number of pages
- All compilations of data must be stored at the SECRET level
Correct answer: Combining multiple unclassified pieces of information can create a classified document requiring higher protection
Classification by compilation means that aggregating individually unclassified pieces of information can create a document revealing sensitive patterns or details that warrant classification.
What is 'spear phishing' and how does it differ from general phishing attacks?