CJIS Network Security & Authentication 3 — Questions and Answers
Question 1: Which port is commonly used for HTTPS traffic, which CJIS recommends for secure web-based CJI access?
- Port 80
- Port 443 (Correct answer)
- Port 8080
- Port 21
Correct answer: Port 443
HTTPS operates on port 443 and uses TLS encryption, meeting CJIS requirements for secure web-based data transmission.
Question 2: A CJIS-connected agency wants to allow remote officers to access CJI from the field. What is required?
- A dedicated leased line for each officer
- A VPN with FIPS 140-2 validated encryption and Advanced Authentication (Correct answer)
- Any commercially available VPN product
- Remote access is prohibited under CJIS policy
Correct answer: A VPN with FIPS 140-2 validated encryption and Advanced Authentication
Remote access to CJI must use a FIPS 140-2 validated VPN and Advanced Authentication to satisfy CJIS requirements.
Question 3: Under CJIS policy, what must happen if a user account has been inactive for 90 days?
- The account password must be reset by the user
- The account must be disabled (Correct answer)
- The account must be deleted immediately
- The account must be reviewed but no action is required
Correct answer: The account must be disabled
CJIS requires that user accounts inactive for 90 days be disabled to reduce unauthorized access risk.
Question 4: Which network security control does CJIS policy require to monitor and control traffic between network segments in a CJI environment?
- Network Address Translation (NAT) only
- Intrusion Detection System (IDS) only
- Boundary protection devices such as firewalls and routers with ACLs (Correct answer)
- Simple Network Management Protocol (SNMP) traps
Correct answer: Boundary protection devices such as firewalls and routers with ACLs
CJIS requires boundary protection devices (firewalls, routers with ACLs) to monitor and control inter-segment traffic in CJI environments.
Question 5: What minimum password length does CJIS Security Policy require for accounts accessing CJI?
- 6 characters
- 8 characters (Correct answer)
- 10 characters
- 12 characters
Correct answer: 8 characters
CJIS requires a minimum password length of 8 characters for accounts that access Criminal Justice Information.
Question 6: A law enforcement agency uses cloud services to store CJI. Which CJIS requirement must the cloud provider meet?
- ISO 27001 certification alone is sufficient
- The provider must sign a CJIS Security Addendum (Correct answer)
- The provider must be a US government agency
- Cloud storage of CJI is prohibited without exception
Correct answer: The provider must sign a CJIS Security Addendum
Any third-party or cloud provider handling CJI must execute a CJIS Security Addendum agreeing to comply with CJIS policy.
Question 7: What does the CJIS policy state about the use of peer-to-peer (P2P) file-sharing applications on systems with access to CJI?
- P2P is allowed if encrypted
- P2P is allowed only for administrative file transfers
- P2P applications are prohibited on systems used to access CJI (Correct answer)
- P2P is allowed if approved by a local IT administrator
Correct answer: P2P applications are prohibited on systems used to access CJI
CJIS prohibits peer-to-peer file-sharing applications on any system used to access Criminal Justice Information due to security risks.
Which port is commonly used for HTTPS traffic, which CJIS recommends for secure web-based CJI access?