CJIS Information Security & Access Control 2 — Questions and Answers
Question 1: Under CJIS policy, what is the minimum encryption standard required for data-in-transit over public networks?
- DES 56-bit
- AES 128-bit
- Advanced Encryption Standard (AES) 256-bit (Correct answer)
- 3DES 112-bit
Correct answer: Advanced Encryption Standard (AES) 256-bit
CJIS Security Policy requires AES 256-bit encryption for CJI transmitted over public networks.
Question 2: Which type of access control model assigns permissions based on an individual's job function within the organization?
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
- Role-Based Access Control (RBAC) (Correct answer)
- Attribute-Based Access Control (ABAC)
Correct answer: Role-Based Access Control (RBAC)
RBAC grants access rights based on predefined roles corresponding to job functions, which CJIS recommends as the baseline model.
Question 3: A law enforcement officer attempts to log into the RMS after five failed password attempts. What should the system do according to CJIS policy?
- Prompt for a security question
- Lock the account and require administrator reset (Correct answer)
- Allow three more attempts before locking
- Send a one-time password via SMS
Correct answer: Lock the account and require administrator reset
CJIS policy requires accounts to be locked after no more than five consecutive failed login attempts, requiring administrator intervention to unlock.
Question 4: What does the principle of 'need to know' mean in the context of CJIS information access?
- All officers need to know all available CJI
- Access is granted only when required for official law enforcement duties (Correct answer)
- Supervisors must know all data accessed by their subordinates
- Every agency must know what data other agencies hold
Correct answer: Access is granted only when required for official law enforcement duties
'Need to know' limits CJI access to individuals who require it to perform their official, authorized duties.
Question 5: Which CJIS security area governs the physical protection of locations where CJI is processed or stored?
- Personnel Security
- Physical Protection (Correct answer)
- Media Protection
- Incident Response
Correct answer: Physical Protection
The Physical Protection policy area establishes controls for securing facilities and equipment that process or store CJI.
Question 6: Under CJIS, how often must user accounts be reviewed to ensure access remains appropriate?
- Every 30 days
- Every 6 months
- Annually (Correct answer)
- Every 3 years
Correct answer: Annually
CJIS Security Policy requires agencies to review user accounts at least annually to validate ongoing access need.
Question 7: A contractor working on a city's CAD system will have unescorted access to areas where CJI is stored. What is required before access is granted?
- A signed NDA only
- An FBI-approved fingerprint-based background check (Correct answer)
- A local criminal history check only
- Completion of a cybersecurity training course
Correct answer: An FBI-approved fingerprint-based background check
CJIS mandates an FBI-approved fingerprint-based background check for any personnel with unescorted physical or logical access to CJI.
Under CJIS policy, what is the minimum encryption standard required for data-in-transit over public networks?