CJIS CJIS Configuration Management & System Protection 1 — Questions and Answers
Question 1: Under the CJIS Security Policy, which document must be maintained to record the approved baseline configuration of a system accessing CJIS data?
- System Risk Register
- System Security Plan (SSP)
- Configuration Management Plan (CMP) (Correct answer)
- Security Assessment Report (SAR)
Correct answer: Configuration Management Plan (CMP)
A Configuration Management Plan documents the approved baseline configuration and procedures for managing changes to systems that access CJIS data.
Question 2: What is the primary purpose of establishing a configuration baseline for systems that access CJIS data?
- To reduce software licensing costs
- To provide a known secure starting point for detecting unauthorized changes (Correct answer)
- To document user access permissions
- To satisfy state government budget reporting requirements
Correct answer: To provide a known secure starting point for detecting unauthorized changes
A configuration baseline establishes a known secure state so that unauthorized or risky changes can be detected and remediated quickly.
Question 3: Which CJIS Security Policy requirement mandates that agencies identify and document hardware and software components of systems that store, process, or transmit CJIS data?
- Identification and Authentication policy
- Configuration Management and Change Control (Correct answer)
- Audit and Accountability policy
- Physical Protection policy
Correct answer: Configuration Management and Change Control
The Configuration Management and Change Control requirement mandates that agencies maintain an inventory of hardware and software components handling CJIS data.
Question 4: Before deploying a change to a system that accesses CJIS data, what step is required under CJIS configuration management policy?
- Notifying all end users via email
- Testing the change in an isolated environment and documenting approval (Correct answer)
- Receiving written consent from the record subject
- Submitting a change request to the FBI CJIS Division
Correct answer: Testing the change in an isolated environment and documenting approval
CJIS policy requires that changes be tested and formally approved before deployment to prevent unauthorized or untested modifications from affecting system security.
Question 5: Under CJIS policy, what should agencies do with software that is no longer supported by its vendor (end-of-life)?
- Continue using it with additional network monitoring
- Remove or replace it to eliminate unpatched vulnerabilities (Correct answer)
- Obtain a waiver from the state CJIS Systems Officer
- Isolate it on a dedicated VLAN and continue operations
Correct answer: Remove or replace it to eliminate unpatched vulnerabilities
End-of-life software must be removed or replaced because it no longer receives security patches, creating exploitable vulnerabilities in CJIS environments.
Question 6: What is the recommended practice for managing default passwords on systems or devices that access CJIS data?
- Document and archive default passwords in a secure vault
- Change all default passwords immediately upon deployment (Correct answer)
- Disable password authentication and use biometrics only
- Retain default passwords for vendor-support purposes
Correct answer: Change all default passwords immediately upon deployment
CJIS policy requires that default passwords be changed immediately upon deployment to prevent exploitation using publicly known vendor credentials.
Under the CJIS Security Policy, which document must be maintained to record the approved baseline configuration of a system accessing CJIS data?