CJIS Incident Response & System Auditing 3 — Questions and Answers
Question 1: Under CJIS Security Policy, audit logs must be retained for a minimum of how long?
- 30 days
- 6 months
- 1 year (Correct answer)
- 3 years
Correct answer: 1 year
CJIS Security Policy mandates that audit logs be retained for a minimum of one year to support investigations and reviews.
Question 2: Which of the following BEST describes the role of the CJIS Systems Agency Information Security Officer (CJIS ISO) during an incident?
- Performing all forensic analysis independently
- Serving as the primary contact and coordinator for security incidents affecting CJI at the agency level (Correct answer)
- Approving new system purchases during the incident
- Notifying the media of the breach
Correct answer: Serving as the primary contact and coordinator for security incidents affecting CJI at the agency level
The CJIS ISO serves as the primary security point of contact and coordinator for incidents affecting CJI within the agency.
Question 3: An agency detects repeated failed login attempts on the CJIS terminal at 3 AM. Under incident response procedures, this FIRST qualifies as:
- A confirmed data breach requiring immediate shutdown
- A security event requiring evaluation to determine if it is an incident (Correct answer)
- A routine maintenance window activity
- An authorized penetration test
Correct answer: A security event requiring evaluation to determine if it is an incident
Repeated failed logins are a security event; further evaluation is required to determine whether it constitutes a reportable incident.
Question 4: Which phase of incident response focuses on removing the root cause of the compromise from affected CJIS systems?
- Containment
- Identification
- Eradication (Correct answer)
- Recovery
Correct answer: Eradication
The eradication phase involves removing malware, closing vulnerabilities, or eliminating any other root cause of the incident.
Question 5: A CJIS-compliant audit system must protect audit logs from which of the following?
- Being accessed by authorized auditors
- Unauthorized modification, deletion, or access (Correct answer)
- Automatic encryption during transmission only
- Being exported to CSV format
Correct answer: Unauthorized modification, deletion, or access
CJIS requires that audit logs be protected from unauthorized modification, deletion, or access to preserve their integrity as evidence.
Question 6: During a CJIS audit, the auditor requests evidence of incident response plan testing. What is the MINIMUM requirement?
- The plan must be tested monthly with full simulations
- The plan must be tested at least annually or after significant changes (Correct answer)
- Testing is optional if the plan is documented
- Testing is only required after an actual incident
Correct answer: The plan must be tested at least annually or after significant changes
CJIS Security Policy requires incident response plans to be tested at least annually or after significant organizational or environmental changes.
Question 7: Which of the following is NOT a required component of a CJIS-compliant incident response plan?
- Procedures for reporting incidents to the FBI CJIS Division
- Roles and responsibilities for incident response team members
- A list of all approved vendors for law enforcement equipment purchases (Correct answer)
- Criteria for determining the severity of a security incident
Correct answer: A list of all approved vendors for law enforcement equipment purchases
Vendor purchasing lists are not a component of an incident response plan; the plan focuses on detection, reporting, roles, and severity criteria.
Under CJIS Security Policy, audit logs must be retained for a minimum of how long?