CJIS Security Policy Certification — Questions and Answers
Question 1: Multi-factor authentication (MFA) under CJIS policy requires which combination of factors?
- Biometrics and smart card only
- Two passwords of different complexity
- Something you know plus something you have or are (Correct answer)
- Username, password, and security question
Correct answer: Something you know plus something you have or are
CJIS MFA requires at least two distinct factor types: knowledge (password/PIN), possession (token/smart card), or inherence (biometric).
Question 2: Which of the following best describes a key competency required for network security & authentication in CJIS practice?
- Reliance on a single methodology for all situations
- The ability to work independently without any oversight
- Memorization of all relevant regulations without understanding context
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
CJIS professionals working in network security & authentication need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 3: What is the purpose of a Configuration Management Board (CMB) or similar body in a CJIS-compliant agency?
- To issue CJIS user credentials
- To review and approve changes to CJIS-connected systems before implementation (Correct answer)
- To manage the agency's physical security perimeter
- To conduct criminal background checks on IT staff
Correct answer: To review and approve changes to CJIS-connected systems before implementation
A CMB provides formal oversight of proposed changes to CJIS systems, ensuring changes are reviewed for security impact before they are implemented.
Question 4: Which CJIS Security Policy section governs audit and accountability requirements for criminal justice systems?
- Policy Area 8
- Policy Area 3
- Policy Area 10
- Policy Area 5 (Correct answer)
Correct answer: Policy Area 5
Policy Area 5 of the CJIS Security Policy covers audit and accountability requirements including logging, retention, and review.
Question 5: How often must agencies with CJI access conduct recurring background checks on their personnel under CJIS Security Policy?
- Every 5 years (Correct answer)
- Every 6 months
- Only at initial hire; no recurring checks required
- Every year
Correct answer: Every 5 years
CJIS Security Policy requires agencies to conduct recurring background checks at least every five years for personnel with CJI access.
Question 6: Which scenario represents a CJIS policy violation in interagency data sharing?
- An agency uses a VPN to transmit CJI to a partner agency
- A dispatcher shares wanted person data over an encrypted CAD system
- A detective verbally requests a record check from a neighboring jurisdiction
- An officer emails unencrypted arrest records to a prosecutor's office over public internet (Correct answer)
Correct answer: An officer emails unencrypted arrest records to a prosecutor's office over public internet
Transmitting unencrypted CJI over public networks violates CJIS encryption requirements, regardless of recipient agency.
Question 7: Who is responsible for ensuring that CJIS security awareness training records are maintained for auditing purposes?
- The state training academy
- The FBI CJIS Division exclusively
- Individual employees only
- The Agency Head or their designee (Correct answer)
Correct answer: The Agency Head or their designee
The Agency Head or their designated security officer is responsible for maintaining training records to demonstrate compliance during CJIS audits.
Question 8: Why limit access to sensitive records?
- Increase sharing
- Prevent unauthorized access (Correct answer)
- Speed access
- Ignore records
Correct answer: Prevent unauthorized access
To prevent unauthorized disclosure or tampering.
Question 9: Which network security control does CJIS policy require to monitor and control traffic between network segments in a CJI environment?
- Network Address Translation (NAT) only
- Simple Network Management Protocol (SNMP) traps
- Intrusion Detection System (IDS) only
- Boundary protection devices such as firewalls and routers with ACLs (Correct answer)
Correct answer: Boundary protection devices such as firewalls and routers with ACLs
CJIS requires boundary protection devices (firewalls, routers with ACLs) to monitor and control inter-segment traffic in CJI environments.
Question 10: When a CJIS-authorized user's employment is terminated, within what timeframe must their access be revoked?
- Within 30 days
- Within 24 hours
- Within 7 days
- Immediately upon separation (Correct answer)
Correct answer: Immediately upon separation
CJIS policy requires that access to CJI systems be terminated immediately when an employee leaves, is transferred, or changes roles eliminating the need for access.
Question 11: When a CJIS agency undergoes a triennial compliance audit, what training-related documentation must be available?
- Instructor certifications from state academies only
- Future training schedules and planned content
- Only the training curriculum outline
- Completed training records for all personnel with CJI access (Correct answer)
Correct answer: Completed training records for all personnel with CJI access
During audits, agencies must produce completed training records demonstrating that all CJI-authorized personnel have satisfied awareness training requirements.
Question 12: During a post-incident review of a CJIS breach, investigators find that audit logs were overwritten before analysis. What CJIS requirement was violated?
- Physical security standards
- Encryption-at-rest standards
- Multi-factor authentication policy
- Audit log retention requirements (Correct answer)
Correct answer: Audit log retention requirements
CJIS Security Policy requires audit logs to be retained for a minimum period so they are available for post-incident forensic analysis.
Question 13: Which of the following is a key learning objective of CJIS media protection training?
- How to post department news on social media platforms
- Managing public records requests through media outlets
- Broadcasting agency activity on local news channels
- Proper sanitization or destruction of media containing CJI before disposal (Correct answer)
Correct answer: Proper sanitization or destruction of media containing CJI before disposal
CJIS media protection training teaches personnel to sanitize or destroy storage media containing CJI before disposal to prevent unauthorized data recovery.
Question 14: Which of the following scenarios would trigger a mandatory report to the FBI CJIS Division under CJIS Security Policy?
- A help desk ticket for a forgotten password
- Discovery that CJI was accessed or exfiltrated by an unauthorized party (Correct answer)
- Routine maintenance causing a 10-minute NCIC outage
- A staff member printing CJI for an authorized investigation
Correct answer: Discovery that CJI was accessed or exfiltrated by an unauthorized party
Unauthorized access to or exfiltration of CJI is a confirmed security incident that triggers mandatory reporting to the FBI CJIS Division.
Question 15: What is the first step in incident response?
- Delay response
- Ignore incident
- Delete evidence
- Identify and report (Correct answer)
Correct answer: Identify and report
The first and most critical step in incident response is to identify that an incident has occurred and promptly report it through established channels. This immediate recognition and notification enable a rapid and appropriate response, preventing further damage and initiating the necessary steps to contain and resolve the situation.
Question 16: What is the primary purpose of a forensic image taken during a CJIS incident investigation?
- To preserve evidence in a forensically sound manner that supports legal or administrative proceedings (Correct answer)
- To create a working backup for disaster recovery
- To comply with FISMA annual reporting requirements
- To speed up system restoration by having a ready snapshot
Correct answer: To preserve evidence in a forensically sound manner that supports legal or administrative proceedings
Forensic imaging preserves evidence in an unaltered, legally defensible state to support potential criminal prosecution or administrative action.
Question 17: Which CJIS policy section governs the use of personally identifiable information (PII) within criminal justice databases?
- Policy Area 13 — Mobile Devices
- Policy Area 3 — Incident Response
- Policy Area 5 — Access Control (Correct answer)
- Policy Area 6 — Identification and Authentication
Correct answer: Policy Area 5 — Access Control
Policy Area 5 addresses access control, which governs who may access PII and CJI stored in criminal justice systems.
Question 18: A county sheriff's office wants to share criminal history data with a child protective services agency. Under CJIS policy, what must be established first?
- Mutual law enforcement officer certifications
- A joint data warehouse
- A shared IT infrastructure agreement
- Legislative authority permitting the sharing with that non-criminal justice agency (Correct answer)
Correct answer: Legislative authority permitting the sharing with that non-criminal justice agency
Sharing CJI with non-criminal justice agencies like child protective services requires specific legislative or regulatory authority authorizing that disclosure.
Question 19: Which of the following topics is NOT explicitly required in CJIS security awareness training content?
- Social media marketing strategies (Correct answer)
- Incident response procedures
- Proper handling and protection of CJI
- Threats and vulnerabilities to CJI
Correct answer: Social media marketing strategies
Social media marketing strategies have no relevance to CJIS security awareness training, which focuses on CJI protection, threats, incident response, and acceptable use.
Question 20: A cloud-based interagency data sharing platform stores CJI across servers in multiple states. Which CJIS requirement applies to this architecture?
- Only on-premises storage is permitted under CJIS for interagency platforms
- The platform must ensure all CJI is stored and transmitted using FIPS 140-2 validated encryption regardless of server location (Correct answer)
- CJI must only be stored on servers within the originating state's borders
- The platform must receive case-by-case FBI approval for each stored record
Correct answer: The platform must ensure all CJI is stored and transmitted using FIPS 140-2 validated encryption regardless of server location
Cloud platforms handling CJI must apply FIPS 140-2 validated encryption for data at rest and in transit; geographic server location does not exempt the platform from encryption requirements.
Question 21: What is the primary purpose of the CJIS Security Addendum that personnel must acknowledge?
- To register personal devices for remote access
- To authorize billing for system access
- To certify agreement to safeguard CJI and comply with CJIS policy (Correct answer)
- To request elevated system privileges
Correct answer: To certify agreement to safeguard CJI and comply with CJIS policy
The CJIS Security Addendum is a binding agreement where personnel certify they understand and will comply with CJIS security requirements for protecting CJI.
Question 22: A law enforcement agency contracts with a private company to manage its records management system containing CJI. What training requirement applies to the contractor's employees?
- Training is the contractor's sole responsibility without agency oversight
- The same CJIS security awareness training as agency personnel (Correct answer)
- No training required since they are not sworn officers
- Training only if they are on-site at the agency
Correct answer: The same CJIS security awareness training as agency personnel
Contractor employees with access to CJI must meet the same security awareness training requirements as direct agency employees under CJIS policy.
Question 23: During a CJIS audit, the auditor requests evidence of incident response plan testing. What is the MINIMUM requirement?
- Testing is only required after an actual incident
- Testing is optional if the plan is documented
- The plan must be tested monthly with full simulations
- The plan must be tested at least annually or after significant changes (Correct answer)
Correct answer: The plan must be tested at least annually or after significant changes
CJIS Security Policy requires incident response plans to be tested at least annually or after significant organizational or environmental changes.
Question 24: Which action is MOST critical during the containment phase of a CJIS-related security incident?
- Isolating affected systems to prevent further unauthorized access to CJI (Correct answer)
- Deleting compromised user accounts permanently
- Restoring systems from backup before investigation
- Immediately notifying all end users of the breach
Correct answer: Isolating affected systems to prevent further unauthorized access to CJI
Isolating affected systems prevents further unauthorized access to Criminal Justice Information during the containment phase.
Question 25: Which type of agency is NOT authorized to directly query the National Crime Information Center (NCIC)?
- Municipal police departments
- State police agencies
- Private security firms (Correct answer)
- Federal law enforcement agencies
Correct answer: Private security firms
Private security firms do not have direct NCIC query access as they are not criminal justice agencies under CJIS definitions.
Question 26: An officer receives a phishing email appearing to come from the state CJIS division requesting login credentials. What is the correct response trained under CJIS awareness programs?
- Forward the email to all colleagues to warn them
- Report the email to the agency's IT security team and do not respond (Correct answer)
- Click the link to verify its authenticity
- Reply with credentials since the request appears official
Correct answer: Report the email to the agency's IT security team and do not respond
CJIS security awareness training instructs personnel to report suspected phishing attempts to IT security and never provide credentials in response to unsolicited requests.
Question 27: Which of the following is a required element of a CHRI dissemination agreement between a criminal justice agency and a noncriminal justice agency?
- Fingerprint cards for all authorized personnel
- A list of all employees who will view the CHRI
- The noncriminal justice agency's IT security architecture diagram
- Limitations on the use and re-dissemination of CHRI (Correct answer)
Correct answer: Limitations on the use and re-dissemination of CHRI
Dissemination agreements must include explicit limitations on CHRI use and re-dissemination to ensure the noncriminal justice agency handles the data lawfully.
Question 28: What does CJIS Policy require regarding background investigations for cloud provider personnel with the ability to access CJI?
- State-level background checks are sufficient for cloud personnel
- Only senior cloud engineers require criminal history checks
- Background investigations are optional if the provider is FedRAMP authorized
- They must pass an FBI fingerprint-based background check (Correct answer)
Correct answer: They must pass an FBI fingerprint-based background check
CJIS Policy requires that cloud provider employees with unescorted logical or physical access to CJI undergo an FBI fingerprint-based background investigation.
Question 29: A local police department stores backup CJI media in a locked filing cabinet outside the secure area. What CJIS requirement does this violate?
- User training requirements
- Physical protection of media in transit or at rest (Correct answer)
- Encryption standards
- Audit log retention
Correct answer: Physical protection of media in transit or at rest
CJIS requires CJI media to be physically protected whether in transit or at rest, including secure storage within authorized areas.
Question 30: A cloud storage account is identified as holding potential evidence. Under the Electronic Communications Privacy Act (ECPA), investigators typically need:
- Only verbal permission from the suspect
- An administrative subpoena for all content
- Nothing — cloud data has no expectation of privacy
- A search warrant or valid legal process served to the provider (Correct answer)
Correct answer: A search warrant or valid legal process served to the provider
ECPA requires law enforcement to obtain a search warrant or appropriate legal process before compelling cloud providers to disclose stored content.
Question 31: Which of the following BEST describes the role of the CJIS Systems Agency Information Security Officer (CJIS ISO) during an incident?
- Approving new system purchases during the incident
- Notifying the media of the breach
- Serving as the primary contact and coordinator for security incidents affecting CJI at the agency level (Correct answer)
- Performing all forensic analysis independently
Correct answer: Serving as the primary contact and coordinator for security incidents affecting CJI at the agency level
The CJIS ISO serves as the primary security point of contact and coordinator for incidents affecting CJI within the agency.
Question 32: Under CJIS policy, what is the recommended approach to password management that training should emphasize?
- Reuse passwords across multiple systems for ease of recall
- Share passwords with supervisors for emergency access
- Use complex unique passwords and never share them (Correct answer)
- Write passwords on sticky notes kept in a locked desk
Correct answer: Use complex unique passwords and never share them
CJIS training emphasizes using complex, unique passwords for each system and never sharing credentials with anyone, including supervisors.
Question 33: What is multi-factor authentication?
- No authentication
- Single password
- Two or more verifications (Correct answer)
- Anonymous access
Correct answer: Two or more verifications
Security requiring two or more verification methods.
Question 34: Why is encryption important in CJIS communications?
- Protects data security (Correct answer)
- Confuses users.
- Increases data size.
- Delays data transmission.
Correct answer: Protects data security
Encryption protects data from being intercepted or tampered with during transmission.
Question 35: A supervisor notices that a fellow officer is sharing CJI query results with non-law-enforcement family members. What is the correct action per CJIS training?
- Counsel the officer privately without formal reporting
- Ignore it if no formal complaint has been filed
- Report the incident through the agency's established security incident process (Correct answer)
- Allow it if the information seems harmless
Correct answer: Report the incident through the agency's established security incident process
CJIS training requires personnel to report security incidents and policy violations through official channels — unauthorized CJI dissemination is a serious violation.
Question 36: Under CJIS policy, secondary dissemination of CHRI to a third party by a noncriminal justice agency is:
- Required when the third party is conducting a federal audit
- Permitted if the third party is a government entity
- Allowed with written consent of the record subject
- Generally prohibited without specific authorization (Correct answer)
Correct answer: Generally prohibited without specific authorization
Secondary dissemination of CHRI by noncriminal justice agencies is generally prohibited unless specifically authorized, to prevent unauthorized spread of sensitive records.
Question 37: A state agency discovers that a local department it shares CJI with has suffered a data breach. What must the state agency do immediately?
- Issue a public press release about the breach
- Notify the FBI CJIS Division within the required timeframe (Correct answer)
- Suspend all data sharing with all agencies
- Conduct an independent forensic audit
Correct answer: Notify the FBI CJIS Division within the required timeframe
CJIS policy requires prompt notification to the FBI CJIS Division when a breach involving CJI is discovered, within mandated reporting timeframes.
Question 38: When CJI media must be transported from one agency location to another, what is the primary CJIS requirement?
- The media must be physically escorted by at least two sworn law enforcement officers
- Transport must only occur via U.S. Postal Service Certified Mail
- The media must be protected from unauthorized access throughout transport using encryption or physical controls (Correct answer)
- Transport must be approved in writing by the FBI's CJIS Division before departure
Correct answer: The media must be protected from unauthorized access throughout transport using encryption or physical controls
CJIS requires that CJI media be protected from unauthorized access during transport, typically through encryption, locked containers, or other controls ensuring confidentiality and integrity.
Question 39: Which CJIS control governs how agencies must handle and destroy physical media (hard drives, USB drives) that contain CJI?
- System Integrity
- Incident Response
- Media Protection (Correct answer)
- Physical Protection
Correct answer: Media Protection
The Media Protection policy area requires agencies to sanitize or destroy physical media containing CJI using NIST SP 800-88 guidelines before disposal.
Question 40: Which CJIS control addresses the risk of a mobile device being lost or stolen with CJI in an offline cache?
- Prohibiting any offline access to CJI on mobile devices
- Requiring officers to submit devices for nightly inspection
- Full-device encryption combined with remote wipe capability (Correct answer)
- Requiring devices to connect to agency Wi-Fi at least once per shift
Correct answer: Full-device encryption combined with remote wipe capability
Full-device encryption ensures cached CJI is unreadable if the device is lost, while remote wipe allows the agency to destroy data on a stolen device.
Question 41: How does CJIS policy define 'Personally Identifiable Information' (PII) in the context of awareness training?
- Classified government intelligence data
- Only Social Security numbers and dates of birth
- Information that alone or combined can identify a specific individual (Correct answer)
- Law enforcement officer identification numbers only
Correct answer: Information that alone or combined can identify a specific individual
CJIS training defines PII broadly as any information that alone or in combination can be used to identify a specific individual, requiring careful handling protections.
Question 42: Which entity is primarily responsible for coordinating incident response when CJI stored by a local agency is compromised?
- The Compact Council
- The Department of Homeland Security exclusively
- The local agency's IT department alone
- The local agency's CSO in coordination with the SIB and FBI CJIS Division (Correct answer)
Correct answer: The local agency's CSO in coordination with the SIB and FBI CJIS Division
The local agency's CJIS Systems Officer coordinates with the State Identification Bureau and FBI CJIS Division during a CJI compromise.
Question 43: What is the most effective way to measure success in mobile device & cloud security within CJIS professional practice?
- Rely solely on supervisor opinion
- Compare only with industry averages without considering context
- Count only the number of activities completed
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 44: A vendor provides a network appliance that will sit inside the CJIS-connected network. What must the agency verify about the appliance?
- Its cryptographic modules must be FIPS 140-2 validated if used for encryption (Correct answer)
- It must run an open-source operating system
- It must have received an FCC radio certification
- It must be manufactured in the United States
Correct answer: Its cryptographic modules must be FIPS 140-2 validated if used for encryption
Any appliance performing encryption in a CJIS environment must use FIPS 140-2 validated cryptographic modules.
Question 45: What is system auditing used for?
- Review activity (Correct answer)
- Speed systems
- Hide activity
- Ignore logs
Correct answer: Review activity
System auditing is primarily used to review and verify activity within a system, including user actions, access attempts, and system events. By systematically examining these records, auditors can detect unauthorized access, policy violations, and suspicious behavior, ensuring the integrity and security of the system.
Question 46: A CJIS audit log must capture which of the following elements at minimum?
- User ID, physical location, and supervisor name
- Application name and transaction amount
- User ID, date/time, type of event, and success or failure of event (Correct answer)
- Date/time and IP address only
Correct answer: User ID, date/time, type of event, and success or failure of event
CJIS audit logs must at minimum capture user ID, date/time stamp, type of event, and whether the event succeeded or failed.
Question 47: A prosecutor's office requests direct access to a law enforcement database containing CJI. How is this access classified under CJIS?
- Restricted access available only through court order
- Criminal justice agency access, since prosecution is a criminal justice function (Correct answer)
- Civilian access requiring highest-level clearance
- Noncriminal justice agency access requiring additional controls
Correct answer: Criminal justice agency access, since prosecution is a criminal justice function
Prosecution is defined as a criminal justice function, so prosecutors' offices qualify as criminal justice agencies with appropriate access under CJIS.
Question 48: Which session timeout policy is required by CJIS for unattended workstations accessing CJI?
- 60 minutes of inactivity
- 10 minutes of inactivity
- 30 minutes of inactivity
- 15 minutes of inactivity (Correct answer)
Correct answer: 15 minutes of inactivity
CJIS Security Policy mandates a session lock after no more than 15 minutes of inactivity on systems that access CJI.
Question 49: When a CJIS professional encounters an unfamiliar challenge in disaster recovery & business continuity, what is the recommended first course of action?
- Postpone addressing the issue indefinitely
- Proceed based on personal intuition alone
- Research applicable standards, consult with subject matter experts, and document the approach (Correct answer)
- Apply the solution used for the most recent similar problem without adaptation
Correct answer: Research applicable standards, consult with subject matter experts, and document the approach
Professional practice requires a methodical approach to unfamiliar challenges: research the applicable standards, consult experts when needed, and document the reasoning for the chosen approach.
Question 50: Under CJIS policy, who must be notified when a significant disaster affects criminal justice information systems?
- The Department of Homeland Security exclusively
- The FBI CJIS Division and the State Identification Bureau (Correct answer)
- Only the agency's legal counsel
- Only the local IT department
Correct answer: The FBI CJIS Division and the State Identification Bureau
CJIS policy requires notification to the FBI CJIS Division and the appropriate State Identification Bureau when systems are compromised or experience significant outages.
Question 51: An agency enters a stolen firearm record into NCIC. Which data element is mandatory for the entry to be valid?
- The color and finish of the firearm
- The serial number of the firearm (Correct answer)
- The estimated value of the firearm
- The registered owner's date of birth
Correct answer: The serial number of the firearm
A valid NCIC stolen gun record requires the firearm's serial number as the primary identifier for matching purposes.
CJIS Security Policy Certification
The CJIS Security Policy Certification ensures individuals understand and can apply the FBI's Criminal Justice Information Services (CJIS) Security Policy to protect sensitive criminal justice information.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds