CJIS Data Management & Record Keeping 3 — Questions and Answers
Question 1: Which CJIS policy section governs the use of personally identifiable information (PII) within criminal justice databases?
- Policy Area 3 — Incident Response
- Policy Area 5 — Access Control (Correct answer)
- Policy Area 6 — Identification and Authentication
- Policy Area 13 — Mobile Devices
Correct answer: Policy Area 5 — Access Control
Policy Area 5 addresses access control, which governs who may access PII and CJI stored in criminal justice systems.
Question 2: When an NCIC record reaches its expiration date without renewal, what happens automatically?
- The record is archived to a read-only database
- The record is purged from the active NCIC file (Correct answer)
- The record is flagged for supervisory review
- The record is transferred to state repositories
Correct answer: The record is purged from the active NCIC file
NCIC automatically purges records that are not renewed before their expiration date to maintain data accuracy.
Question 3: What is the purpose of the NCIC Validation Program?
- To verify the identity of all NCIC terminal operators
- To ensure entered records are accurate, complete, and still valid (Correct answer)
- To test network connectivity between state systems and the FBI
- To audit access logs for unauthorized queries
Correct answer: To ensure entered records are accurate, complete, and still valid
The NCIC Validation Program requires agencies to periodically review their records to confirm they remain accurate and legally supportable.
Question 4: Under CJIS policy, which of the following is a required element when logging access to criminal justice information?
- The physical location of the terminal
- The user identity, date, time, and type of action performed (Correct answer)
- The supervisor who authorized the access
- The encryption algorithm used during transmission
Correct answer: The user identity, date, time, and type of action performed
Audit logs must capture user identity, timestamps, and the nature of the action to support accountability and forensic review.
Question 5: A criminal justice agency wants to share CHRI with a non-criminal justice government agency for background check purposes. What is required?
- A CJIS Security Addendum signed by the receiving agency (Correct answer)
- An MOU between the two agencies and FBI approval
- Only verbal authorization from the agency head
- Completion of CJIS online training by the receiving agency's staff
Correct answer: A CJIS Security Addendum signed by the receiving agency
Non-criminal justice agencies that access CHRI must sign the CJIS Security Addendum, committing to CJIS security requirements.
Question 6: Which scenario best describes improper record management under CJIS policy?
- Purging a stolen vehicle record after the vehicle is recovered
- Retaining an expunged criminal record in a local database (Correct answer)
- Renewing a missing person record before its expiration
- Logging a query result when no match is found
Correct answer: Retaining an expunged criminal record in a local database
Retaining expunged records violates CJIS policy, which requires timely removal of records ordered sealed or expunged by a court.
Question 7: What is the role of the State Identification Bureau (SIB) in CJIS data management?
- It operates the national NCIC database on behalf of the FBI
- It serves as the state-level custodian for criminal history records and interfaces with III (Correct answer)
- It audits all local agencies for CJIS compliance annually
- It issues encryption certificates for state criminal justice terminals
Correct answer: It serves as the state-level custodian for criminal history records and interfaces with III
The SIB manages state-level criminal history records and acts as the state's interface with the FBI's Interstate Identification Index.
Which CJIS policy section governs the use of personally identifiable information (PII) within criminal justice databases?