CJIS Information Security & Access Control 3 — Questions and Answers
Question 1: Which CJIS policy area specifically addresses requirements for logging and auditing access to CJI systems?
- Audit and Accountability (Correct answer)
- Configuration Management
- System and Communications Protection
- Awareness and Training
Correct answer: Audit and Accountability
The Audit and Accountability policy area requires agencies to create, protect, and retain audit logs of CJI access for review and investigation.
Question 2: When a CJIS-authorized user's employment is terminated, within what timeframe must their access be revoked?
- Within 24 hours
- Within 7 days
- Immediately upon separation (Correct answer)
- Within 30 days
Correct answer: Immediately upon separation
CJIS policy requires that access to CJI systems be terminated immediately when an employee leaves, is transferred, or changes roles eliminating the need for access.
Question 3: What is the purpose of a CJIS Security Addendum?
- To define the FBI's internal network architecture
- To contractually bind private entities to CJIS security requirements (Correct answer)
- To document audit log retention schedules
- To specify encryption algorithms for NCIC queries
Correct answer: To contractually bind private entities to CJIS security requirements
The CJIS Security Addendum is a required contractual agreement that holds private sector companies to the same security standards as criminal justice agencies when handling CJI.
Question 4: Multi-factor authentication (MFA) under CJIS policy requires which combination of factors?
- Two passwords of different complexity
- Something you know plus something you have or are (Correct answer)
- Biometrics and smart card only
- Username, password, and security question
Correct answer: Something you know plus something you have or are
CJIS MFA requires at least two distinct factor types: knowledge (password/PIN), possession (token/smart card), or inherence (biometric).
Question 5: An agency discovers that a mobile device containing CJI has been lost. What is the FIRST action required under CJIS incident response procedures?
- File a police report
- Notify the FBI immediately
- Remotely wipe the device and report the incident to the CSO (Correct answer)
- Wait 72 hours to determine if the device is recovered before reporting
Correct answer: Remotely wipe the device and report the incident to the CSO
CJIS requires immediate remote wipe of the lost device and prompt notification to the agency's CJIS Systems Officer (CSO) as the first response steps.
Question 6: Which session timeout policy is required by CJIS for unattended workstations accessing CJI?
- 30 minutes of inactivity
- 15 minutes of inactivity (Correct answer)
- 10 minutes of inactivity
- 60 minutes of inactivity
Correct answer: 15 minutes of inactivity
CJIS Security Policy mandates a session lock after no more than 15 minutes of inactivity on systems that access CJI.
Question 7: Which of the following best describes 'least privilege' as applied under CJIS security requirements?
- Users receive maximum access to ensure no operational delays
- Users are granted only the minimum access rights needed to perform their duties (Correct answer)
- Administrators share a single high-privilege account for efficiency
- Access rights are inherited automatically from a supervisor's permissions
Correct answer: Users are granted only the minimum access rights needed to perform their duties
Least privilege restricts user access rights to the minimum necessary for legitimate job functions, reducing the risk of unauthorized CJI disclosure.
Which CJIS policy area specifically addresses requirements for logging and auditing access to CJI systems?