CJIS Network Security & Authentication 2 — Questions and Answers
Question 1: Under CJIS Security Policy, what is the minimum encryption standard required for data in transit over a network?
- DES with 56-bit keys
- AES with 128-bit keys (Correct answer)
- RC4 with 128-bit keys
- 3DES with 112-bit keys
Correct answer: AES with 128-bit keys
CJIS requires AES 128-bit (or higher) encryption for protecting CJI data transmitted across networks.
Question 2: Which CJIS requirement applies when an agency uses a wireless LAN to transmit criminal justice information?
- WEP encryption is sufficient if combined with a VPN
- Wireless transmissions must use FIPS 140-2 validated encryption (Correct answer)
- Wireless networks are prohibited for CJI transmission
- Only guest networks may carry CJI if segmented
Correct answer: Wireless transmissions must use FIPS 140-2 validated encryption
CJIS requires FIPS 140-2 validated cryptographic modules for wireless CJI transmissions.
Question 3: A firewall protecting a CJIS-connected network should be configured to follow which principle?
- Default-allow with logging of denied traffic
- Default-deny with explicit permit rules for authorized traffic (Correct answer)
- Stateless packet filtering only
- Allow all internal traffic, block only inbound external traffic
Correct answer: Default-deny with explicit permit rules for authorized traffic
CJIS policy requires a default-deny posture where only explicitly authorized traffic is permitted through firewalls.
Question 4: How often must passwords be changed for accounts with access to Criminal Justice Information under CJIS policy?
- Every 6 months
- Every 90 days (Correct answer)
- Every 12 months
- Every 30 days
Correct answer: Every 90 days
CJIS Security Policy requires passwords for CJI accounts to be changed at minimum every 90 days.
Question 5: What does CJIS policy require regarding session timeouts for systems accessing CJI?
- Sessions must time out after no more than 30 minutes of inactivity (Correct answer)
- Sessions must time out after no more than 10 minutes of inactivity
- Session timeouts are optional if the workstation is physically secured
- Sessions must time out after no more than 60 minutes of inactivity
Correct answer: Sessions must time out after no more than 30 minutes of inactivity
CJIS requires workstation sessions to lock or log off automatically after a maximum of 30 minutes of inactivity.
Question 6: Under CJIS policy, which authentication mechanism satisfies Advanced Authentication (AA) requirements?
- A complex password of 10+ characters alone
- Username and PIN without any second factor
- A smart card combined with a PIN (Correct answer)
- Security questions answered at login
Correct answer: A smart card combined with a PIN
Advanced Authentication under CJIS requires two or more factors; a smart card (possession) plus PIN (knowledge) satisfies this requirement.
Question 7: When is Advanced Authentication (AA) required under CJIS Security Policy?
- Only when accessing NCIC directly
- Whenever CJI is accessed from outside a physically secure location or over a non-secure network (Correct answer)
- Only for administrators with elevated privileges
- Only when using mobile devices
Correct answer: Whenever CJI is accessed from outside a physically secure location or over a non-secure network
CJIS mandates Advanced Authentication whenever CJI is accessed from outside a physically secure location or traverses a network that is not controlled end-to-end.
Under CJIS Security Policy, what is the minimum encryption standard required for data in transit over a network?