CJIS Cheat Sheet 2026

The 30 highest-yield CJIS facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

50 questions
60 min time limit
80% to pass
  1. Which scenario violates CJIS record management policy? Using CHRI results to deny employment without legal authorization
  2. A fingerprint-based background check using CHRI is considered more reliable than a name-based check because: It uniquely identifies an individual regardless of name variations
  3. Which of the following best describes a key competency required for disaster recovery & business continuity in CJIS practice? Strong analytical skills combined with effective communication and ethical judgment
  4. A forensic examiner is asked to testify about findings from a disk image. What must be established first to make the evidence admissible? Foundation for authenticity, including chain of custody and hash verification
  5. Under CJIS policy, who bears ultimate responsibility for ensuring compliance within a criminal justice agency? The Agency Head (Chief or Director)
  6. Which agency is responsible for maintaining the national repository of criminal history records used in CJIS background investigations? FBI CJIS Division
  7. What is a key component of incident documentation? Detailed records
  8. What is the role of audit trails in data management? Track changes and access
  9. An agency discovers that a former employee still has active credentials in a CJIS system two weeks after termination. Which policy has been violated? Account Management Policy
  10. Which legal doctrine allows law enforcement to seize digital evidence not specified in a warrant if it is in plain view during lawful execution of the warrant? Plain view doctrine
  11. What minimum password length does CJIS Security Policy require for accounts accessing CJI? 8 characters
  12. Which CJIS policy requirement applies when criminal justice data is transmitted over a public network? Data must be encrypted using FIPS 140-2 validated encryption
  13. What does FIPS 140-2 or FIPS 140-3 validation indicate about an encryption product used with CJI? The cryptographic module meets federal security standards tested by NIST
  14. Which CJIS policy area governs the requirements for transmitting CJI over public networks? Encryption and Data-in-Transit
  15. Under CJIS Security Policy, what is required before a mobile device can access CJI via a cellular network? The device must use a VPN or equivalent encryption tunnel
  16. Which of the following is NOT a required component of a CJIS-compliant incident response plan? A list of all approved vendors for law enforcement equipment purchases
  17. Which CJIS requirement governs how long physical access control records (e.g., badge swipe logs) must be retained? At least 1 year
  18. What is system auditing used for? Review activity
  19. An agency's IT vendor remotely accesses a server that stores CJI. Under CJIS policy, this vendor must: Be supervised by agency staff and comply with the CJIS Security Addendum
  20. What action must an agency take when an individual named in an NCIC protection order record reports that the order has been lifted by the court? Verify the court order modification before clearing the record
  21. A vendor provides a network appliance that will sit inside the CJIS-connected network. What must the agency verify about the appliance? Its cryptographic modules must be FIPS 140-2 validated if used for encryption
  22. How often must CJIS security training be completed? Annually
  23. When a CJIS agency relocates its server room, what physical security action must be taken before CJI systems are moved? Ensure the new location meets CJIS physical security standards before relocation
  24. What is the first step in incident response? Identify and report
  25. What is the purpose of data management? Organize and maintain data
  26. Under CJIS policy, what action must be taken if a mobile device containing CJI is lost or stolen? Immediately report the incident to the CSA and initiate remote wipe if possible
  27. How does CJIS policy address the use of personally owned devices (BYOD) for accessing CJI? BYOD must meet the same security controls as agency-owned devices
  28. What is the maximum time an agency has to enter a wanted person record into NCIC after issuance of a warrant? 24 hours
  29. When a CJIS-authorized user's employment is terminated, within what timeframe must their access be revoked? Immediately upon separation
  30. What does 'spoliation' of digital evidence refer to? Destruction or alteration of evidence that may be relevant to litigation
Turn these facts into recall:
Was this helpful?