CJIS Security Policy Certification — Questions and Answers
Question 1: Which of the following best describes a key competency required for disaster recovery & business continuity in CJIS practice?
- Reliance on a single methodology for all situations
- The ability to work independently without any oversight
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
- Memorization of all relevant regulations without understanding context
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
CJIS professionals working in disaster recovery & business continuity need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 2: How often must passwords be changed for accounts with access to Criminal Justice Information under CJIS policy?
- Every 6 months
- Every 90 days (Correct answer)
- Every 12 months
- Every 30 days
Correct answer: Every 90 days
CJIS Security Policy requires passwords for CJI accounts to be changed at minimum every 90 days.
Question 3: A seized smartphone is placed in a Faraday bag during transport. What is the PRIMARY purpose of this action?
- To maintain chain of custody paperwork
- To prevent remote wiping or data modification via wireless signals (Correct answer)
- To preserve battery life during storage
- To prevent physical damage to the screen
Correct answer: To prevent remote wiping or data modification via wireless signals
A Faraday bag blocks wireless signals, preventing remote wiping, lock activation, or data changes via cellular, Wi-Fi, or Bluetooth.
Question 4: Under CJIS, how often must user accounts be reviewed to ensure access remains appropriate?
- Every 3 years
- Every 30 days
- Annually (Correct answer)
- Every 6 months
Correct answer: Annually
CJIS Security Policy requires agencies to review user accounts at least annually to validate ongoing access need.
Question 5: Which CJIS requirement applies when an agency uses a wireless LAN to transmit criminal justice information?
- Only guest networks may carry CJI if segmented
- Wireless transmissions must use FIPS 140-2 validated encryption (Correct answer)
- WEP encryption is sufficient if combined with a VPN
- Wireless networks are prohibited for CJI transmission
Correct answer: Wireless transmissions must use FIPS 140-2 validated encryption
CJIS requires FIPS 140-2 validated cryptographic modules for wireless CJI transmissions.
Question 6: Under CJIS Security Policy, what is the significance of maintaining an up-to-date system inventory for configuration management purposes?
- It satisfies federal tax reporting requirements for IT assets
- It enables accurate identification of all components subject to CJIS security controls (Correct answer)
- It automates patch deployment across the network
- It allows the FBI to remotely monitor agency systems
Correct answer: It enables accurate identification of all components subject to CJIS security controls
An accurate system inventory ensures every hardware and software component that handles CJIS data is identified and subjected to the required security controls.
Question 7: How should CJIS professionals handle confidential information related to training & awareness programs?
- Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations (Correct answer)
- Delete all records after project completion
- Store information without any security measures
- Share freely with all colleagues for transparency
Correct answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Question 8: What is the role of a 'write blocker' in the digital evidence acquisition process?
- It compresses data during imaging to save storage space
- It prevents any write commands from reaching the source media during acquisition (Correct answer)
- It encrypts the forensic image as it is created
- It verifies hash values after imaging is complete
Correct answer: It prevents any write commands from reaching the source media during acquisition
A write blocker intercepts all write commands directed at the source media, ensuring the original evidence remains unmodified during imaging.
Question 9: What should CJIS security awareness training communicate about encryption requirements for CJI in transit?
- Encryption is only required for interstate transmissions
- Encryption is optional for local area network transmissions
- All CJI transmitted over open networks must be encrypted using FIPS 140-2 validated cryptography (Correct answer)
- Agency discretion determines whether encryption is needed
Correct answer: All CJI transmitted over open networks must be encrypted using FIPS 140-2 validated cryptography
CJIS policy mandates FIPS 140-2 validated encryption for all CJI transmitted over open or public networks with no exceptions based on distance or jurisdiction.
Question 10: During a CJIS audit, the auditor requests evidence of incident response plan testing. What is the MINIMUM requirement?
- The plan must be tested at least annually or after significant changes (Correct answer)
- Testing is optional if the plan is documented
- The plan must be tested monthly with full simulations
- Testing is only required after an actual incident
Correct answer: The plan must be tested at least annually or after significant changes
CJIS Security Policy requires incident response plans to be tested at least annually or after significant organizational or environmental changes.
Question 11: A cloud provider storing CJI experiences a data breach. Under CJIS Security Policy, the criminal justice agency must:
- Transfer all CJI to on-premises storage before filing any report
- Notify the FBI CJIS Division and affected individuals per policy timelines (Correct answer)
- Conduct an internal audit before notifying any external parties
- Allow the cloud provider to manage breach notification independently
Correct answer: Notify the FBI CJIS Division and affected individuals per policy timelines
CJIS Policy requires agencies to report security incidents involving CJI to the FBI CJIS Division and comply with applicable breach notification requirements.
Question 12: Who should be notified in a major security incident?
- Notify authorities (Correct answer)
- Ignore notification
- Avoid communication
- Tell media first
Correct answer: Notify authorities
In a major security incident, especially one involving sensitive criminal justice information, notifying authorities is often a legal and ethical requirement. This ensures proper investigation, compliance with reporting mandates, and allows for potential assistance from law enforcement or regulatory bodies in mitigating the incident and protecting affected parties.
Question 13: Under CJIS Security Policy, which personnel are required to undergo a fingerprint-based background check before being granted unescorted access to a Criminal Justice Information (CJI) area?
- Only employees hired after January 2015
- Only employees who handle federal records
- All personnel, including contractors and vendors, with unescorted physical access to CJI (Correct answer)
- Only sworn law enforcement officers
Correct answer: All personnel, including contractors and vendors, with unescorted physical access to CJI
CJIS policy requires fingerprint-based background checks for all personnel — employees, contractors, and vendors — who have unescorted physical or logical access to CJI.
Question 14: Which scenario best describes a 'need-to-know' violation that CJIS training should address?
- A dispatcher verifying a driver's license status during a traffic stop
- An officer running a plate check on a stolen vehicle
- A detective querying NCIC for a suspect in an active investigation
- An officer looking up a neighbor's criminal history out of personal curiosity (Correct answer)
Correct answer: An officer looking up a neighbor's criminal history out of personal curiosity
Querying CJI for personal curiosity rather than an official law enforcement purpose violates the 'need-to-know' principle central to CJIS policy.
Question 15: An investigator finds a file with a .jpg extension but forensic analysis shows the file header signature is that of a .zip file. This is an example of:
- Anti-forensic file masking or extension spoofing (Correct answer)
- Normal NTFS behavior
- Corrupt file structure
- File compression
Correct answer: Anti-forensic file masking or extension spoofing
Changing a file's extension to disguise its true type is an anti-forensic technique called file masking or extension spoofing.
Question 16: How can incident response be improved?
- Regular drills and updates (Correct answer)
- Delay training
- No drills
- Ignore updates
Correct answer: Regular drills and updates
Incident response capabilities are significantly improved through regular drills and exercises, which allow teams to practice their roles and identify weaknesses in the plan. Continuous updates to the plan, based on lessons learned from drills and evolving threats, ensure its ongoing effectiveness and relevance in a dynamic threat landscape.
Question 17: Which scenario correctly triggers the requirement for a new background check under CJIS standards for an existing employee?
- The employee receives a merit raise without a change in duties
- The employee's position changes to include new unescorted access to CJI they previously did not have (Correct answer)
- The employee transfers to a different desk within the same CJI-authorized unit
- The employee takes a two-week vacation and returns to the same role
Correct answer: The employee's position changes to include new unescorted access to CJI they previously did not have
A new or expanded access grant that was not covered by the original background check triggers the requirement for an updated fingerprint-based background investigation.
Question 18: What role does continuous improvement play in digital evidence management for CJIS certified professionals?
- It is optional and only necessary during certification renewal
- It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation (Correct answer)
- It focuses exclusively on cost reduction
- It applies only to new professionals in their first year
Correct answer: It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation
Continuous improvement is fundamental to professional practice in digital evidence management, involving regular evaluation, feedback integration, and process enhancement to maintain high standards.
Question 19: When CJI media must be transported from one agency location to another, what is the primary CJIS requirement?
- Transport must only occur via U.S. Postal Service Certified Mail
- The media must be protected from unauthorized access throughout transport using encryption or physical controls (Correct answer)
- The media must be physically escorted by at least two sworn law enforcement officers
- Transport must be approved in writing by the FBI's CJIS Division before departure
Correct answer: The media must be protected from unauthorized access throughout transport using encryption or physical controls
CJIS requires that CJI media be protected from unauthorized access during transport, typically through encryption, locked containers, or other controls ensuring confidentiality and integrity.
Question 20: What encryption standard must removable media meet when used to transport CJI outside of a physically secure location, per the CJIS Security Policy?
- Triple DES (3DES) encryption with a 112-bit key
- AES-128 encryption validated under FIPS 140-2
- RSA-2048 public key encryption for file-level protection
- FIPS 140-2 or FIPS 140-3 validated encryption using AES-256 (Correct answer)
Correct answer: FIPS 140-2 or FIPS 140-3 validated encryption using AES-256
The CJIS Security Policy requires CJI transported on removable media to be encrypted using FIPS 140-2 (or 140-3) validated modules with AES-256 to ensure data confidentiality.
Question 21: A CJIS agency policy requires all forensic workstations to be audited. Which log type is MOST critical for detecting unauthorized access to digital evidence files?
- Hardware diagnostic reports
- System access and audit logs showing user account activity (Correct answer)
- Network bandwidth usage logs
- Application crash logs
Correct answer: System access and audit logs showing user account activity
Access and audit logs record which user accounts accessed which files and when, providing the critical trail needed to detect unauthorized evidence access.
Question 22: What role does continuous improvement play in training & awareness programs for CJIS certified professionals?
- It applies only to new professionals in their first year
- It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation (Correct answer)
- It is optional and only necessary during certification renewal
- It focuses exclusively on cost reduction
Correct answer: It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation
Continuous improvement is fundamental to professional practice in training & awareness programs, involving regular evaluation, feedback integration, and process enhancement to maintain high standards.
Question 23: What action must an agency take when a CHRI subject's criminal case results in acquittal or dismissal?
- Transfer the record to civil court files
- Update the disposition in the record to reflect the outcome (Correct answer)
- Retain the record unchanged for seven years
- Delete only the fingerprint records
Correct answer: Update the disposition in the record to reflect the outcome
Agencies must update criminal history records with final dispositions, including acquittals and dismissals, to ensure CHRI accuracy.
Question 24: How frequently does the CJIS Security Policy require agencies to perform vulnerability scans on systems processing CJIS data?
- Annually
- Periodically as defined by the agency's risk assessment (Correct answer)
- Every two years
- Only after a security incident
Correct answer: Periodically as defined by the agency's risk assessment
CJIS policy requires periodic vulnerability scanning with frequency informed by the agency's risk assessment and any significant system changes.
Question 25: An agency discovers a duplicate record in NCIC for the same wanted person. What is the correct action?
- Leave both records active to ensure the hit is returned
- Flag both records for supervisory review without making changes
- Cancel the older record and consolidate information into one active record (Correct answer)
- Contact the FBI CJIS Division to merge the records automatically
Correct answer: Cancel the older record and consolidate information into one active record
Duplicate records must be resolved by canceling the redundant entry to prevent data integrity issues and false multiple-hit returns.
Question 26: In the context of CJIS certification, what is the most important consideration when implementing training & awareness programs?
- Completing implementation as quickly as possible regardless of quality
- Minimizing documentation to save time
- Delegating all responsibilities to junior staff
- Ensuring alignment with established standards, stakeholder needs, and best practices (Correct answer)
Correct answer: Ensuring alignment with established standards, stakeholder needs, and best practices
When implementing training & awareness programs, CJIS professionals must ensure alignment with industry standards and stakeholder needs. Hasty implementation without proper planning often leads to compliance issues and suboptimal outcomes.
Question 27: What is the CJIS requirement for workstations located in publicly accessible areas that display CJI?
- No special requirements if the area has security cameras
- Workstations are prohibited in all publicly accessible areas
- Privacy screens and positioning to prevent unauthorized viewing are required (Correct answer)
- A second officer must always be present when CJI is displayed
Correct answer: Privacy screens and positioning to prevent unauthorized viewing are required
CJIS requires workstations in public areas to use privacy screens or positioning that prevents CJI from being viewed by unauthorized individuals.
Question 28: A state criminal justice agency stores CJI on backup tapes kept at an offsite storage facility. What CJIS requirement applies to the offsite facility?
- The tapes must be transported to the offsite facility daily by sworn law enforcement officers
- The offsite facility must be operated by a government entity and cannot be a private company
- The offsite facility must meet CJIS physical security requirements and personnel at the facility must be subject to appropriate security measures (Correct answer)
- Backup tapes containing CJI cannot be stored offsite under any CJIS policy provision
Correct answer: The offsite facility must meet CJIS physical security requirements and personnel at the facility must be subject to appropriate security measures
CJIS requires that any location where CJI media is stored, including offsite backup facilities, meet applicable physical and personnel security requirements to prevent unauthorized access.
Question 29: Why is root cause analysis important?
- Find root cause (Correct answer)
- Ignore causes
- Blame users
- Delay fixes
Correct answer: Find root cause
Root cause analysis is crucial because it goes beyond addressing the symptoms of an incident to identify its fundamental underlying cause. By understanding why an incident truly happened, organizations can implement effective preventative measures to avoid similar occurrences in the future, significantly strengthening their overall security posture.
Question 30: Under CJIS Security Policy, what is the MAXIMUM time frame within which a security incident must be reported to the FBI CJIS Division after discovery?
- 72 hours (Correct answer)
- 24 hours
- 7 days
- 48 hours
Correct answer: 72 hours
CJIS Security Policy requires that confirmed security incidents be reported to the FBI CJIS Division within 72 hours of discovery.
Question 31: Under CJIS policy, which condition allows a non-criminal justice agency to receive the results of a criminal history check?
- When the requesting agency pays applicable fees to the FBI
- When a federal judge issues a discovery order
- When the subject of the check provides written consent only
- When authorized by federal statute, executive order, or state statute for a specific noncriminal justice purpose (Correct answer)
Correct answer: When authorized by federal statute, executive order, or state statute for a specific noncriminal justice purpose
Noncriminal justice agencies may receive criminal history results only when a specific federal statute, executive order, or state law explicitly authorizes that particular use.
Question 32: Which of the following is a key learning objective of CJIS media protection training?
- Broadcasting agency activity on local news channels
- Managing public records requests through media outlets
- How to post department news on social media platforms
- Proper sanitization or destruction of media containing CJI before disposal (Correct answer)
Correct answer: Proper sanitization or destruction of media containing CJI before disposal
CJIS media protection training teaches personnel to sanitize or destroy storage media containing CJI before disposal to prevent unauthorized data recovery.
Question 33: Under CJIS Security Policy, which of the following actions is REQUIRED after an incident involving CJI exposure is resolved?
- Suspension of CJIS services for 30 days
- Automatic revocation of all user accounts agency-wide
- Immediate decommissioning of all affected hardware
- Completion of a post-incident report documenting cause, impact, and corrective actions (Correct answer)
Correct answer: Completion of a post-incident report documenting cause, impact, and corrective actions
CJIS requires a post-incident report that documents the root cause, scope of CJI exposure, and corrective actions taken to prevent recurrence.
Question 34: What is the most effective way to measure success in physical security requirements within CJIS professional practice?
- Compare only with industry averages without considering context
- Rely solely on supervisor opinion
- Count only the number of activities completed
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 35: Which network security control does CJIS policy require to monitor and control traffic between network segments in a CJI environment?
- Intrusion Detection System (IDS) only
- Network Address Translation (NAT) only
- Simple Network Management Protocol (SNMP) traps
- Boundary protection devices such as firewalls and routers with ACLs (Correct answer)
Correct answer: Boundary protection devices such as firewalls and routers with ACLs
CJIS requires boundary protection devices (firewalls, routers with ACLs) to monitor and control inter-segment traffic in CJI environments.
Question 36: A criminal justice agency discovers that an unauthorized individual accessed the NCIC system. Which is the FIRST step in the incident response process?
- Lessons-learned meeting
- Recovery of affected systems
- Documentation and identification of the incident (Correct answer)
- Eradication of the threat
Correct answer: Documentation and identification of the incident
Identification and documentation is the first step in incident response, establishing that an incident occurred before any other action.
Question 37: How should CJIS professionals handle confidential information related to network security & authentication?
- Delete all records after project completion
- Share freely with all colleagues for transparency
- Store information without any security measures
- Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations (Correct answer)
Correct answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Question 38: Which scenario represents a violation of CJIS Business Continuity requirements during a system outage?
- Coordinating with the State CSO for manual query support
- Documenting all manual transactions performed during the outage
- Allowing unauthenticated access to NCIC to maintain operational tempo (Correct answer)
- Activating the documented contingency plan within the required timeframe
Correct answer: Allowing unauthenticated access to NCIC to maintain operational tempo
Allowing unauthenticated access to CJIS systems under any circumstances, including outages, violates mandatory authentication requirements.
Question 39: Which of the following scenarios would trigger a mandatory report to the FBI CJIS Division under CJIS Security Policy?
- A staff member printing CJI for an authorized investigation
- Routine maintenance causing a 10-minute NCIC outage
- A help desk ticket for a forgotten password
- Discovery that CJI was accessed or exfiltrated by an unauthorized party (Correct answer)
Correct answer: Discovery that CJI was accessed or exfiltrated by an unauthorized party
Unauthorized access to or exfiltration of CJI is a confirmed security incident that triggers mandatory reporting to the FBI CJIS Division.
Question 40: Which of the following best describes the CJIS Security Addendum that cloud providers must sign?
- A background check authorization form for cloud provider employees
- A service-level agreement defining uptime requirements for CJI systems
- A technical specification document listing required firewall rules
- A legally binding agreement committing the provider to CJIS Policy compliance (Correct answer)
Correct answer: A legally binding agreement committing the provider to CJIS Policy compliance
The CJIS Security Addendum is a legally binding document that obligates cloud providers and their personnel to comply with CJIS Security Policy requirements.
Question 41: What is the most effective way to measure success in background investigation standards within CJIS professional practice?
- Compare only with industry averages without considering context
- Count only the number of activities completed
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
- Rely solely on supervisor opinion
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 42: Which of the following best describes a key competency required for physical security requirements in CJIS practice?
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
- Memorization of all relevant regulations without understanding context
- The ability to work independently without any oversight
- Reliance on a single methodology for all situations
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
CJIS professionals working in physical security requirements need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 43: Under CJIS policy, what is the recommended approach to password management that training should emphasize?
- Use complex unique passwords and never share them (Correct answer)
- Reuse passwords across multiple systems for ease of recall
- Share passwords with supervisors for emergency access
- Write passwords on sticky notes kept in a locked desk
Correct answer: Use complex unique passwords and never share them
CJIS training emphasizes using complex, unique passwords for each system and never sharing credentials with anyone, including supervisors.
Question 44: Under the CJIS Security Policy, which of the following individuals is NOT automatically required to undergo a fingerprint-based background check?
- A new records clerk who processes criminal history requests
- A contractor with logical (remote) access to a CJI database
- An IT administrator with physical access to servers storing CJI
- A vendor employee escorted at all times in a CJI area by authorized personnel (Correct answer)
Correct answer: A vendor employee escorted at all times in a CJI area by authorized personnel
Personnel who are escorted by authorized staff at all times while in CJI areas are exempt from the fingerprint-based background check requirement under CJIS policy.
Question 45: An agency's incident response plan assigns audit log review to a single individual with no backup. Which CJIS principle does this violate?
- Separation of duties and continuity of operations (Correct answer)
- Least privilege
- Need-to-know access control
- Physical security tiering
Correct answer: Separation of duties and continuity of operations
Having no backup for a critical function violates separation of duties and continuity of operations requirements, leaving a single point of failure.
Question 46: A detective uses a mobile hotspot on a personal tablet to access a statewide criminal database. Which CJIS control is the MOST critical to verify is in place?
- A signed acceptable use policy specific to hotspot usage
- Network monitoring of the cellular carrier's backbone
- End-to-end encryption protecting CJI in transit over the hotspot (Correct answer)
- Physical access controls on the hotspot device itself
Correct answer: End-to-end encryption protecting CJI in transit over the hotspot
CJI transmitted over a personal hotspot traverses an untrusted public network, making FIPS-compliant encryption in transit the most critical control.
Question 47: Which action is MOST critical during the containment phase of a CJIS-related security incident?
- Deleting compromised user accounts permanently
- Restoring systems from backup before investigation
- Isolating affected systems to prevent further unauthorized access to CJI (Correct answer)
- Immediately notifying all end users of the breach
Correct answer: Isolating affected systems to prevent further unauthorized access to CJI
Isolating affected systems prevents further unauthorized access to Criminal Justice Information during the containment phase.
Question 48: Which of the following best describes a 'rap sheet' in the context of CJIS?
- A report of sex offender registry entries
- A consolidated criminal history record for an individual (Correct answer)
- A real-time wanted persons alert
- A summary of civil court judgments
Correct answer: A consolidated criminal history record for an individual
A rap sheet is a consolidated criminal history record that compiles an individual's arrest, charge, and disposition information from multiple jurisdictions.
Question 49: What role does continuous improvement play in network security & authentication for CJIS certified professionals?
- It applies only to new professionals in their first year
- It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation (Correct answer)
- It focuses exclusively on cost reduction
- It is optional and only necessary during certification renewal
Correct answer: It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation
Continuous improvement is fundamental to professional practice in network security & authentication, involving regular evaluation, feedback integration, and process enhancement to maintain high standards.
Question 50: When a CJIS professional encounters an unfamiliar challenge in disaster recovery & business continuity, what is the recommended first course of action?
- Proceed based on personal intuition alone
- Postpone addressing the issue indefinitely
- Research applicable standards, consult with subject matter experts, and document the approach (Correct answer)
- Apply the solution used for the most recent similar problem without adaptation
Correct answer: Research applicable standards, consult with subject matter experts, and document the approach
Professional practice requires a methodical approach to unfamiliar challenges: research the applicable standards, consult experts when needed, and document the reasoning for the chosen approach.
Question 51: A CJIS awareness training program should train personnel to recognize which type of physical security threat?
- Break room cleanliness standards
- Tailgating into secured areas containing CJI terminals (Correct answer)
- Ergonomic workstation adjustments
- Fire escape route planning
Correct answer: Tailgating into secured areas containing CJI terminals
Tailgating — following authorized personnel into secured areas without proper authentication — is a physical security threat that CJIS training must address.
CJIS Security Policy Certification
The CJIS Security Policy Certification ensures individuals understand and can apply the FBI's Criminal Justice Information Services (CJIS) Security Policy to protect sensitive criminal justice information.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds