CJIS CJIS Configuration Management & System Protection 2 β Questions and Answers
Question 1: Under CJIS Security Policy, which principle guides limiting the software installed on CJIS-connected systems to only what is necessary?
- Separation of duties
- Least functionality (Correct answer)
- Defense in depth
- Mandatory access control
Correct answer: Least functionality
The principle of least functionality requires that systems be configured to provide only essential capabilities, reducing the attack surface on CJIS-connected systems.
Question 2: How frequently does the CJIS Security Policy require agencies to perform vulnerability scans on systems processing CJIS data?
- Annually
- Every two years
- Periodically as defined by the agency's risk assessment (Correct answer)
- Only after a security incident
Correct answer: Periodically as defined by the agency's risk assessment
CJIS policy requires periodic vulnerability scanning with frequency informed by the agency's risk assessment and any significant system changes.
Question 3: What is a 'security impact analysis' in the context of CJIS configuration management?
- An annual financial audit of security program costs
- An assessment of the security effects of proposed changes before they are implemented (Correct answer)
- A post-incident review of damage caused by a breach
- A vendor evaluation of new security software products
Correct answer: An assessment of the security effects of proposed changes before they are implemented
A security impact analysis evaluates how a proposed change could affect the security posture of a CJIS system before the change is approved and deployed.
Question 4: Which of the following is an example of a configuration management control required for CJIS-connected systems?
- Allowing users to install personal applications
- Disabling unused ports, protocols, and services (Correct answer)
- Granting all users local administrator rights
- Auto-approving all vendor-pushed firmware updates
Correct answer: Disabling unused ports, protocols, and services
Disabling unused ports, protocols, and services reduces the attack surface of CJIS-connected systems, which is a key configuration management control.
Question 5: Under CJIS policy, patch management requires that critical security patches be applied within what general timeframe?
- Within 24 hours of release
- As quickly as practical, but no more than within the agency's defined patching window (Correct answer)
- Only during scheduled annual maintenance windows
- After a full year of vendor testing
Correct answer: As quickly as practical, but no more than within the agency's defined patching window
CJIS policy requires timely patching consistent with the agency's risk-based patching schedule, ensuring critical vulnerabilities are addressed without undue delay.
Question 6: What role does the Agency Coordinator (AC) play in CJIS configuration management?
- Developing software patches for CJIS applications
- Serving as the point of contact responsible for agency compliance with CJIS policies (Correct answer)
- Managing the FBI's national CJIS database
- Conducting criminal history record checks on agency personnel
Correct answer: Serving as the point of contact responsible for agency compliance with CJIS policies
The Agency Coordinator is the designated point of contact who ensures the agency adheres to CJIS Security Policy requirements, including configuration management.
Under CJIS Security Policy, which principle guides limiting the software installed on CJIS-connected systems to only what is necessary?