CJIS Incident Response & System Auditing 2 — Questions and Answers
Question 1: Under CJIS Security Policy, what is the MAXIMUM time frame within which a security incident must be reported to the FBI CJIS Division after discovery?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
CJIS Security Policy requires that confirmed security incidents be reported to the FBI CJIS Division within 72 hours of discovery.
Question 2: Which action is MOST critical during the containment phase of a CJIS-related security incident?
- Deleting compromised user accounts permanently
- Isolating affected systems to prevent further unauthorized access to CJI (Correct answer)
- Immediately notifying all end users of the breach
- Restoring systems from backup before investigation
Correct answer: Isolating affected systems to prevent further unauthorized access to CJI
Isolating affected systems prevents further unauthorized access to Criminal Justice Information during the containment phase.
Question 3: A CJIS audit log must capture which of the following elements at minimum?
- User ID, date/time, type of event, and success or failure of event (Correct answer)
- User ID, physical location, and supervisor name
- Date/time and IP address only
- Application name and transaction amount
Correct answer: User ID, date/time, type of event, and success or failure of event
CJIS audit logs must at minimum capture user ID, date/time stamp, type of event, and whether the event succeeded or failed.
Question 4: During a post-incident review of a CJIS breach, investigators find that audit logs were overwritten before analysis. What CJIS requirement was violated?
- Encryption-at-rest standards
- Audit log retention requirements (Correct answer)
- Multi-factor authentication policy
- Physical security standards
Correct answer: Audit log retention requirements
CJIS Security Policy requires audit logs to be retained for a minimum period so they are available for post-incident forensic analysis.
Question 5: Which entity is primarily responsible for coordinating incident response when CJI stored by a local agency is compromised?
- The local agency's IT department alone
- The Compact Council
- The local agency's CSO in coordination with the SIB and FBI CJIS Division (Correct answer)
- The Department of Homeland Security exclusively
Correct answer: The local agency's CSO in coordination with the SIB and FBI CJIS Division
The local agency's CJIS Systems Officer coordinates with the State Identification Bureau and FBI CJIS Division during a CJI compromise.
Question 6: What is the purpose of an audit trail in the context of CJIS compliance?
- To track employee salaries and overtime
- To provide a chronological record that allows reconstruction and examination of events (Correct answer)
- To replace the need for access control lists
- To automatically remediate unauthorized access attempts
Correct answer: To provide a chronological record that allows reconstruction and examination of events
An audit trail creates a chronological record enabling reconstruction of events to detect unauthorized activity or policy violations.
Question 7: A criminal justice agency discovers that an unauthorized individual accessed the NCIC system. Which is the FIRST step in the incident response process?
- Eradication of the threat
- Documentation and identification of the incident (Correct answer)
- Recovery of affected systems
- Lessons-learned meeting
Correct answer: Documentation and identification of the incident
Identification and documentation is the first step in incident response, establishing that an incident occurred before any other action.
Under CJIS Security Policy, what is the MAXIMUM time frame within which a security incident must be reported to the FBI CJIS Division after discovery?