CSI® Certified Security Investigator — Questions and Answers
Question 1: Why is documentation crucial in the handling of digital evidence?
- To ensure the evidence is legally admissible (Correct answer)
- To ensure the evidence is hidden from the public
- To reduce the number of staff involved
- To track the financial value of the evidence
Correct answer: To ensure the evidence is legally admissible
Thorough documentation is paramount in handling digital evidence, as it creates a detailed record of every step taken during the collection, preservation, analysis, and storage process. This includes timestamps, personnel involved, methods used, and any observations. This comprehensive record is essential for establishing the evidence's authenticity and integrity, making it legally admissible and defensible in court.
Question 2: Which of the following describes a phishing attack?
- Exploiting a buffer overflow vulnerability in a web application
- Sending deceptive messages that appear legitimate to trick users into revealing credentials (Correct answer)
- Encrypting an organization's data and demanding a ransom
- Scanning a network to map open ports and running services
Correct answer: Sending deceptive messages that appear legitimate to trick users into revealing credentials
Phishing uses deceptive emails or messages that mimic trusted entities to trick recipients into providing credentials or clicking malicious links.
Question 3: What is a 'cognitive load' indicator during an interview, and why is it significant?
- The subject's ability to recall facts quickly without effort
- A measure of the interviewer's workload during complex cases
- Signs of mental effort that may indicate fabrication of a story (Correct answer)
- The number of follow-up questions needed to clarify a statement
Correct answer: Signs of mental effort that may indicate fabrication of a story
Increased cognitive load — shown by pauses, slower speech, or requests for repetition — can indicate a subject is constructing rather than recalling a story.
Question 4: What is 'transient evidence' in the context of physical security investigations?
- Background information about a suspect's past behavior
- Secondary documentation created after the incident
- Evidence discovered during unrelated investigations
- Evidence that is temporary in nature and must be collected immediately (Correct answer)
Correct answer: Evidence that is temporary in nature and must be collected immediately
Transient evidence, such as odors, temperature, or melting materials, exists only briefly and must be documented or collected before it disappears.
Question 5: When documenting activities related to physical security surveys, which practice is considered essential for CSI certification holders?
- Completing documentation only when requested by auditors or supervisors
- Keeping documentation in personal notes that are not accessible to other team members
- Recording only outcomes while omitting the methods and processes used
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in physical security surveys. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 6: Which quality assurance method is most commonly applied in physical security surveys to verify that CSI professional standards are being met?
- Structured audits, peer reviews, and performance metrics aligned with industry benchmarks (Correct answer)
- Relying on client satisfaction surveys as the sole measure of quality
- Annual reviews conducted exclusively by non-technical management
- Informal self-assessment without external validation
Correct answer: Structured audits, peer reviews, and performance metrics aligned with industry benchmarks
Structured audits, peer reviews, and performance metrics aligned with industry benchmarks are the most effective quality assurance methods in physical security surveys, providing objective, measurable evidence that CSI standards are consistently met.
Question 7: When transferring evidence to another investigator or storage facility, what document must accompany it?
- A sworn affidavit from the original collector only
- An evidence transfer log signed by both the releasing and receiving parties (Correct answer)
- A property receipt signed by the facility manager alone
- A duplicate copy of the original incident report
Correct answer: An evidence transfer log signed by both the releasing and receiving parties
A transfer log with signatures from both parties creates a documented, unbroken chain of custody during handoffs.
Question 8: In digital evidence documentation, a 'hash value' is used to:
- Index digital files for rapid database retrieval
- Encrypt files so only authorized personnel can access them
- Verify that electronic evidence has not been altered since collection (Correct answer)
- Establish ownership of digital property in court
Correct answer: Verify that electronic evidence has not been altered since collection
A hash value is a mathematical fingerprint that confirms digital evidence integrity by detecting any post-collection modifications.
Question 9: When developing an Emergency Action Plan for a multi-tenant building, the security investigator should FIRST:
- Publish the plan on the company intranet
- Install new fire suppression systems
- Conduct a tabletop exercise with senior leadership
- Coordinate with building management and other tenants to avoid conflicting procedures (Correct answer)
Correct answer: Coordinate with building management and other tenants to avoid conflicting procedures
Coordination with building management and co-tenants is essential first to ensure evacuation routes, assembly points, and alarm systems are compatible and non-conflicting.
Question 10: When conducting a forensic investigation, what is the PRIMARY reason an investigator should use a write blocker when accessing a suspect drive?
- To decrypt encrypted partitions automatically
- To compress the forensic image for storage
- To prevent accidental modification of the original evidence (Correct answer)
- To speed up the data acquisition process
Correct answer: To prevent accidental modification of the original evidence
A write blocker prevents any writes to the original drive, preserving the integrity of the evidence and ensuring admissibility in court.
Question 11: How does encryption impact the handling of digital evidence?
- It prevents data from being accessed during investigations
- It helps secure sensitive data but can complicate analysis (Correct answer)
- It makes digital evidence easier to handle
- It is irrelevant for forensic investigations
Correct answer: It helps secure sensitive data but can complicate analysis
Encryption is vital for protecting sensitive digital evidence from unauthorized access, thereby maintaining data confidentiality and integrity. However, during a forensic investigation, encrypted data presents a significant challenge as investigators must obtain the correct decryption keys or methods to access and analyze the content. Without proper decryption, the evidence remains inaccessible, potentially hindering the investigation.
Question 12: Which term describes the practice of an investigator joining an organization or group under a false identity to gather evidence from within?
- Overt penetration
- Parallel construction
- Embedded surveillance
- Undercover infiltration (Correct answer)
Correct answer: Undercover infiltration
Undercover infiltration involves an investigator assuming a false identity to gain membership in an organization and gather evidence covertly from the inside.
Question 13: Which of the following BEST describes the difference between a threat and a hazard in security assessment?
- There is no meaningful difference; the terms are interchangeable
- A hazard is always intentional while a threat can be accidental
- A threat involves intent or agency, while a hazard is typically unintentional or natural (Correct answer)
- A threat is physical and a hazard is administrative
Correct answer: A threat involves intent or agency, while a hazard is typically unintentional or natural
In security assessment, a threat implies human intent or agency, whereas a hazard typically refers to unintentional dangers such as natural events or accidents.
Question 14: When documenting activities related to emergency action planning, which practice is considered essential for CSI certification holders?
- Completing documentation only when requested by auditors or supervisors
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Keeping documentation in personal notes that are not accessible to other team members
- Recording only outcomes while omitting the methods and processes used
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in emergency action planning. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 15: During a vulnerability assessment, a security investigator discovers an unlocked server room. This finding represents:
- An exploit
- A vulnerability (Correct answer)
- A risk
- A threat
Correct answer: A vulnerability
An unlocked server room is a vulnerability — a weakness that could be exploited by a threat actor.
Question 16: Which type of transmission is most susceptible to interception when used in a wireless surveillance system?
- Unencrypted 2.4 GHz RF (Correct answer)
- Fiber optic
- Coaxial cable
- Twisted pair with encryption
Correct answer: Unencrypted 2.4 GHz RF
Unencrypted 2.4 GHz RF transmissions can be intercepted with readily available equipment, making them the least secure transmission method listed.
Question 17: Under OSHA's Emergency Action Plan standard (29 CFR 1910.38), which of the following elements is REQUIRED?
- Procedures for reporting fires and other emergencies (Correct answer)
- Monthly fire drill schedules
- A list of all hazardous materials on-site
- A budget for emergency supplies
Correct answer: Procedures for reporting fires and other emergencies
OSHA 29 CFR 1910.38 mandates procedures for reporting fires and other emergencies as a core required element of every Emergency Action Plan.
Question 18: Which of the following best describes social engineering in the context of information security?
- Using technical exploits to compromise network infrastructure
- Installing malware through compromised software updates
- Manipulating people psychologically to divulge confidential information (Correct answer)
- Intercepting unencrypted network traffic to steal credentials
Correct answer: Manipulating people psychologically to divulge confidential information
Social engineering exploits human psychology rather than technical vulnerabilities to trick individuals into revealing sensitive information or taking harmful actions.
Question 19: An investigator is conducting mobile surveillance and loses sight of the subject's vehicle. What is the BEST next action?
- Radio other team members with the last known direction and attempt to reacquire at predictable locations (Correct answer)
- Terminate surveillance and notify the client of the loss
- Return to the subject's residence and wait for their return
- Speed up and try to locate the subject immediately
Correct answer: Radio other team members with the last known direction and attempt to reacquire at predictable locations
Coordinating with team members to cover likely routes or destinations while avoiding high-speed driving is the safest and most tactically sound response to losing a subject.
Question 20: Which of the following practices undermines the integrity of a security incident report?
- Attaching supporting documents as exhibits
- Using numbered paragraphs for each new topic
- Including a table of contents for lengthy reports
- Backdating entries to reflect an earlier time than actual completion (Correct answer)
Correct answer: Backdating entries to reflect an earlier time than actual completion
Backdating is a form of falsification that can constitute fraud and destroys the document's legal credibility.
Question 21: Which risk treatment strategy involves purchasing insurance to cover potential losses from a security incident?
- Risk mitigation
- Risk acceptance
- Risk transfer (Correct answer)
- Risk avoidance
Correct answer: Risk transfer
Risk transfer shifts the financial burden of a potential loss to another party, most commonly through insurance.
Question 22: A surveyor finds that emergency exit doors are propped open by staff for convenience. This is BEST classified as:
- A minor administrative issue
- A physical security vulnerability requiring immediate correction (Correct answer)
- A fire code violation only
- An acceptable operational variance
Correct answer: A physical security vulnerability requiring immediate correction
Propped emergency exits create unauthorized access points and represent an immediate physical security vulnerability that must be corrected.
Question 23: When an investigator discovers new evidence after submitting a preliminary report, the correct action is to:
- Verbally inform the client without updating written records
- Discard the preliminary report and start fresh
- Amend the original report by overwriting the existing content
- Issue a supplemental report documenting the new findings (Correct answer)
Correct answer: Issue a supplemental report documenting the new findings
A supplemental report preserves the integrity of the original report while formally documenting newly discovered evidence.
Question 24: Why is it important for investigative reports to be time-stamped?
- To shorten the report
- To make the report appear official
- To establish an accurate timeline of events (Correct answer)
- To reduce the need for documentation
Correct answer: To establish an accurate timeline of events
Time-stamping investigative reports and individual pieces of evidence is crucial for establishing an accurate and indisputable timeline of events. This chronological record helps to reconstruct the sequence of incidents, demonstrate the order in which evidence was collected, and verify the integrity of data over time. An accurate timeline is vital for corroborating facts and presenting a coherent narrative, especially in legal contexts.
Question 25: A post-incident review process is part of which phase of security policy implementation?
- Policy training and awareness
- Regulatory compliance filing
- Continuous improvement and lessons learned (Correct answer)
- Initial policy drafting
Correct answer: Continuous improvement and lessons learned
Post-incident reviews identify what worked and what failed, feeding lessons learned back into policy updates as part of continuous improvement.
Question 26: Which standard is considered the primary benchmark for private sector business continuity and emergency management planning in the United States?
- ISO 9001
- NFPA 1600 (Correct answer)
- OSHA 1910.119
- ANSI/ASIS ORM.1
Correct answer: NFPA 1600
NFPA 1600 is the widely adopted standard for disaster/emergency management and business continuity programs in the private sector in the U.S.
Question 27: What role does 'active listening' play in an investigative interview?
- It speeds up the interview by reducing unnecessary questions
- It replaces the need for written documentation
- It helps the investigator detect inconsistencies and gather complete information (Correct answer)
- It demonstrates that the investigator already knows the facts
Correct answer: It helps the investigator detect inconsistencies and gather complete information
Active listening involves full attention, follow-up clarifications, and noting contradictions to build a comprehensive picture of events.
Question 28: When collecting physical evidence at a security incident scene, what should an investigator do first?
- Document and photograph the scene before touching anything (Correct answer)
- Contact law enforcement to take over the scene
- Package all visible evidence immediately to prevent loss
- Interview nearby witnesses before any evidence is collected
Correct answer: Document and photograph the scene before touching anything
Documenting and photographing the scene before collection preserves the original state of evidence and its spatial relationships.
Question 29: Which of the following is an example of two-factor authentication (2FA)?
- Answering two security questions during login
- Using the same password on two separate login screens
- Using a long, complex password with mixed characters
- Entering a password and then a one-time code sent to a mobile phone (Correct answer)
Correct answer: Entering a password and then a one-time code sent to a mobile phone
Two-factor authentication combines something you know (password) with something you have (OTP sent to phone), adding a second verification layer.
Question 30: Which of the following is a fundamental principle of emergency action planning as it applies to Certified Security Investigator?
- Avoiding documentation to streamline workflow efficiency
- Relying solely on personal experience without reference to guidelines
- Systematic evaluation and adherence to established industry standards (Correct answer)
- Prioritizing speed of completion over accuracy and compliance
Correct answer: Systematic evaluation and adherence to established industry standards
A fundamental principle of emergency action planning in Certified Security Investigator is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.
Question 31: In threat assessment, the term 'target hardening' refers to:
- Eliminating all identified vulnerabilities simultaneously
- Training staff to respond aggressively to threats
- Conducting background checks on all personnel
- Increasing the difficulty for a threat actor to successfully attack an asset (Correct answer)
Correct answer: Increasing the difficulty for a threat actor to successfully attack an asset
Target hardening involves implementing measures that make it more difficult, costly, or risky for a threat actor to successfully attack or exploit an asset.
Question 32: In digital forensics, what does the term 'anti-forensics' refer to?
- The process of verifying forensic tool accuracy
- Techniques used by investigators to detect hidden evidence
- Legal defenses challenging the admissibility of digital evidence
- Methods suspects use to destroy, hide, or obfuscate digital evidence (Correct answer)
Correct answer: Methods suspects use to destroy, hide, or obfuscate digital evidence
Anti-forensics encompasses techniques like data wiping, encryption, timestomping, and steganography used to hinder forensic investigations.
Question 33: Which of the following best describes a 'fixed surveillance' (also called a 'stationary' or 'plant') observation post?
- A moving vehicle that follows a subject at a constant speed
- A stationary position from which an investigator monitors a specific location or subject (Correct answer)
- An undercover operative embedded within an organization
- A remote camera system that automatically tracks movement
Correct answer: A stationary position from which an investigator monitors a specific location or subject
A fixed surveillance post is a stationary location — such as a parked vehicle, building, or natural feature — from which an investigator observes a specific area or subject.
Question 34: How does thorough documentation of evidence contribute to investigative reporting?
- It provides a foundation for further legal action (Correct answer)
- It focuses solely on the report's length
- It limits the amount of evidence available
- It makes the investigation less organized
Correct answer: It provides a foundation for further legal action
Thorough documentation of evidence is fundamental because it creates a robust, verifiable record that can withstand scrutiny in legal proceedings. This detailed record establishes the chain of custody, authenticity, and relevance of each piece of evidence, forming a solid foundation for prosecution, defense, or other legal actions. Without comprehensive documentation, evidence may be deemed inadmissible or unreliable, jeopardizing the case.
Question 35: A 'mutual aid agreement' between organizations or jurisdictions primarily establishes:
- Pre-arranged commitments to share resources and provide assistance during emergencies (Correct answer)
- A shared emergency operations center location
- Legal liability waivers for all responding personnel
- Mandatory response time standards for partner organizations
Correct answer: Pre-arranged commitments to share resources and provide assistance during emergencies
Mutual aid agreements formalize the terms under which organizations agree to share personnel, equipment, and resources during emergencies that exceed one party's capacity.
Question 36: During post-incident analysis, the security investigator identifies that the emergency notification system failed to reach employees on the loading dock. The BEST corrective action is to:
- Discipline the supervisor responsible for the loading dock area
- Require all loading dock employees to carry personal radios at their own expense
- Add a secondary notification method (e.g., strobe lights or PA system) tailored to the loading dock environment (Correct answer)
- Remove the loading dock from the facility's emergency plan scope
Correct answer: Add a secondary notification method (e.g., strobe lights or PA system) tailored to the loading dock environment
Addressing notification gaps with environment-appropriate redundant methods—such as strobes in high-noise areas—ensures all personnel receive emergency alerts regardless of location.
Question 37: When a security policy conflicts with an employee's job function, the proper course of action is to:
- Ignore the policy if the job requires it
- Seek a formal policy exception or waiver through appropriate channels (Correct answer)
- Resign from the conflicting duty
- Modify the policy without approval
Correct answer: Seek a formal policy exception or waiver through appropriate channels
Formal exception processes allow legitimate operational needs to be accommodated while maintaining documented governance oversight.
Question 38: A subject makes a spontaneous, incriminating statement to an investigator during an overt interview. How should the investigator handle this?
- Document the statement verbatim as soon as possible after the interview (Correct answer)
- Terminate the interview to avoid violating the subject's rights
- Disregard the statement unless it is corroborated by physical evidence
- Immediately stop and inform the subject of their Miranda rights
Correct answer: Document the statement verbatim as soon as possible after the interview
Investigators should document spontaneous statements verbatim immediately after the interview to preserve the exact words as accurately as possible for evidentiary purposes.
Question 39: What is the primary objective of cybersecurity in investigative work?
- To store evidence safely in physical locations
- To monitor employee activities
- To ensure evidence is preserved and protected from cyber threats (Correct answer)
- To focus only on physical evidence
Correct answer: To ensure evidence is preserved and protected from cyber threats
In investigative work, digital evidence is often critical for solving cases. Cybersecurity's primary objective in this context is to safeguard this evidence from unauthorized access, alteration, or destruction by cyber threats, such as hacking or malware. Maintaining the integrity and confidentiality of digital evidence is paramount to its admissibility and credibility in legal proceedings.
Question 40: During a mass evacuation drill, the security investigator notices that employees with mobility impairments have no designated rescue assistance procedure. The BEST immediate action is to:
- Report the finding only to senior management after the drill
- Post signs directing mobility-impaired employees to wait near elevators
- Document the gap and establish a Personal Emergency Evacuation Plan (PEEP) for each affected individual (Correct answer)
- Evacuate all mobility-impaired employees immediately using the nearest stairwell
Correct answer: Document the gap and establish a Personal Emergency Evacuation Plan (PEEP) for each affected individual
Establishing individual PEEPs ensures that employees with mobility impairments have a documented, rehearsed plan tailored to their specific needs and the building layout.
Question 41: Why is chain of custody important in handling digital evidence?
- It maintains the integrity of the evidence for legal purposes (Correct answer)
- It is irrelevant once the evidence is secured
- It is not required for digital evidence
- It only applies to physical evidence
Correct answer: It maintains the integrity of the evidence for legal purposes
Chain of custody is a meticulously documented process that tracks the handling, storage, and transfer of evidence from the moment it is collected until it is presented in court. For digital evidence, this unbroken record proves that the evidence has not been tampered with or altered, ensuring its authenticity and reliability. Without a proper chain of custody, digital evidence can be challenged and deemed inadmissible in legal proceedings.
Question 42: In emergency planning, a 'hazard vulnerability analysis' (HVA) is used to:
- Map evacuation routes from the facility to external assembly areas
- Assess employee readiness through written competency tests
- Determine insurance coverage requirements for natural disasters
- Identify and prioritize hazards based on likelihood and potential impact (Correct answer)
Correct answer: Identify and prioritize hazards based on likelihood and potential impact
An HVA systematically identifies potential hazards, estimates their probability of occurrence, and evaluates the potential impact to prioritize planning resources.
Question 43: What is the primary function of investigative reporting in a legal context?
- To provide opinions on the case
- To present objective, factual information for legal use (Correct answer)
- To summarize the investigation in a narrative form
- To make assumptions about the outcome
Correct answer: To present objective, factual information for legal use
In a legal context, the primary function of investigative reporting is to present objective, factual, and verifiable information that can be used as evidence in court or other legal proceedings. The report serves as a formal record of the investigation's findings, meticulously detailing evidence, methodologies, and conclusions without bias or speculation. This factual basis is essential for informing legal decisions and ensuring due process.
Question 44: When multiple witnesses are available, what is the best practice for conducting interviews in a security investigation?
- Conduct a group debrief before any individual interviews
- Interview witnesses together to save time and align their stories
- Allow witnesses to review each other's written statements first
- Interview each witness separately to prevent cross-contamination of accounts (Correct answer)
Correct answer: Interview each witness separately to prevent cross-contamination of accounts
Separate interviews prevent witnesses from influencing each other's recollections and preserve the independence of their accounts.
Question 45: Which volatile data source should a CSI investigator capture FIRST on a live Windows system before powering it down?
- Browser bookmarks
- Running processes and active network connections (Correct answer)
- Recycle Bin contents
- Installed software registry keys
Correct answer: Running processes and active network connections
Running processes and network connections exist only in RAM and disappear when the system is shut down, making them the highest-priority volatile artifact.
Question 46: In loss prevention terminology, what does 'shrinkage' refer to?
- Reduction in store size due to remodeling
- Decrease in customer foot traffic
- Reduction in employee headcount
- Inventory loss from theft, fraud, administrative error, or vendor fraud (Correct answer)
Correct answer: Inventory loss from theft, fraud, administrative error, or vendor fraud
Shrinkage is the difference between recorded inventory and actual inventory, caused by shoplifting, employee theft, vendor fraud, and administrative errors.
Question 47: A suspect deleted files and then used a disk-wiping tool on a Windows NTFS volume. Which forensic artifact might still reveal what files existed before deletion?
- The $MFT (Master File Table) and $LogFile journal remnants (Correct answer)
- Event log entries in Security.evtx
- The Windows registry CurrentControlSet
- The pagefile.sys swap file
Correct answer: The $MFT (Master File Table) and $LogFile journal remnants
Even after wiping, MFT entry remnants and journal records can reveal file names, metadata, and timestamps of previously existing files.
Question 48: Which element distinguishes a professional investigative report from an informal memorandum?
- Use of legal terminology throughout the document
- Formal structure including case identifiers, methodology, findings, and conclusions with citations (Correct answer)
- Submission in PDF format rather than printed paper
- Length — reports must exceed 10 pages to be considered professional
Correct answer: Formal structure including case identifiers, methodology, findings, and conclusions with citations
Professional investigative reports follow a formal structure with standardized sections that ensure completeness, objectivity, and legal defensibility.
Question 49: Which concept describes the practice of reducing a system's attack surface by disabling unnecessary services and features?
- Incident response
- Risk transfer
- Defense in depth
- Hardening (Correct answer)
Correct answer: Hardening
Hardening involves removing or disabling non-essential services, accounts, and features to reduce the number of exploitable entry points.
Question 50: A CSI uses a drone to conduct aerial surveillance of a subject's fenced private property. Which concern is MOST legally significant?
- Potential violation of the subject's reasonable expectation of privacy over their curtilage (Correct answer)
- FAA registration of the drone before conducting surveillance
- Whether the drone footage is admissible as photographic evidence in civil court
- The cost of the drone operation and whether it is billable to the client
Correct answer: Potential violation of the subject's reasonable expectation of privacy over their curtilage
Courts have extended Fourth Amendment-like privacy expectations to the curtilage (the area immediately surrounding a home), and aerial surveillance of enclosed private property may violate these expectations regardless of drone registration.
Question 51: During an insider threat investigation, an employee is suspected of exfiltrating IP via personal cloud storage. Which log source would BEST confirm this activity?
- Active Directory Group Policy change logs
- Endpoint DLP (Data Loss Prevention) and proxy/web gateway logs (Correct answer)
- Antivirus quarantine event logs
- Physical access badge entry/exit logs
Correct answer: Endpoint DLP (Data Loss Prevention) and proxy/web gateway logs
DLP tools flag sensitive data transfers and proxy logs capture outbound HTTPS traffic to cloud storage domains, providing direct evidence of exfiltration.
Question 52: What is the primary ethical obligation of a CSI professional when a conflict of interest arises during emergency action planning activities?
- Proceed while favoring the outcome that benefits the professional personally
- Resolve the conflict privately without informing stakeholders
- Disclose the conflict to all relevant parties and recuse from the decision if necessary (Correct answer)
- Ignore the conflict if it does not directly affect the current task
Correct answer: Disclose the conflict to all relevant parties and recuse from the decision if necessary
The primary ethical obligation when a conflict of interest arises in emergency action planning is to disclose it to all relevant parties and, if necessary, recuse from the decision. This maintains professional integrity and stakeholder trust.
Question 53: Under the Electronic Communications Privacy Act (ECPA), what is generally required before law enforcement can access stored electronic communications held by a third-party provider?
- Only a written request to the provider
- A valid subpoena, court order, or search warrant depending on content age and type (Correct answer)
- A simple administrative request signed by an agency supervisor
- No legal process if the data is over 180 days old
Correct answer: A valid subpoena, court order, or search warrant depending on content age and type
ECPA establishes a tiered framework requiring subpoenas, court orders, or warrants based on the type and age of stored communications.
Question 54: Which of the following is a PRIMARY goal of a threat vulnerability assessment?
- Document incident response procedures
- Identify suspects in a crime
- Train security personnel on new policies
- Determine which assets face the greatest exposure (Correct answer)
Correct answer: Determine which assets face the greatest exposure
A threat vulnerability assessment aims to identify which assets are most exposed to identified threats.
Question 55: What is the purpose of a 'red team' exercise in threat identification?
- Audit financial records for fraud
- Conduct background checks on employees
- Simulate adversarial attacks to identify exploitable vulnerabilities (Correct answer)
- Train new security investigators
Correct answer: Simulate adversarial attacks to identify exploitable vulnerabilities
A red team simulates real-world adversary tactics to uncover vulnerabilities before actual attackers can exploit them.
Question 56: A surveillance system's 'field of view' is widened by using a lens with a:
- Narrower iris setting
- Shorter focal length (Correct answer)
- Higher aperture number (smaller opening)
- Longer focal length
Correct answer: Shorter focal length
Shorter focal length lenses capture a wider angle of view, while longer focal lengths narrow the view and magnify distant subjects.
Question 57: A 'threat agent' in security risk terminology refers to:
- A monitoring software system
- A government law enforcement officer
- An automated security control
- The entity capable of exploiting a vulnerability (Correct answer)
Correct answer: The entity capable of exploiting a vulnerability
A threat agent is any person, group, or force with the capability and intent to exploit a vulnerability.
Question 58: In the context of emergency action planning, what role does continuous professional development play for CSI practitioners?
- It is required only during the first year of certification
- It serves primarily as a networking opportunity with no practical benefit
- It is optional and only needed for career advancement
- It ensures practitioners remain current with evolving standards, technologies, and best practices (Correct answer)
Correct answer: It ensures practitioners remain current with evolving standards, technologies, and best practices
Continuous professional development is essential in emergency action planning because it ensures CSI practitioners remain current with evolving standards, technologies, and best practices, maintaining competency throughout their careers.
Question 59: An employee claims they were unaware of a security policy they violated. The strongest organizational defense is to demonstrate:
- That other employees know about the policy
- That the policy was posted on an internal website accessible to all
- Signed acknowledgment records showing the employee received, read, and understood the policy (Correct answer)
- That the policy was emailed to all staff at some point in the past
Correct answer: Signed acknowledgment records showing the employee received, read, and understood the policy
Signed acknowledgment records provide documented proof that an individual was informed of and understood a specific policy, making the 'unawareness' defense untenable.
Question 60: Why is objectivity crucial in investigative reporting?
- It focuses on narrative storytelling
- It makes the report more entertaining
- It helps maintain the integrity of the investigation (Correct answer)
- It adds personal opinions to the report
Correct answer: It helps maintain the integrity of the investigation
Objectivity is paramount in investigative reporting because it ensures that the findings are based solely on verifiable facts and evidence, free from personal biases, opinions, or emotional influences. Maintaining objectivity upholds the integrity and credibility of the entire investigation and its report. This allows the report to be trusted as an accurate and impartial account, which is essential, especially in legal contexts.
Question 61: When collecting witness statements as evidence, a security investigator should ensure the statement is:
- Rewritten by the investigator in more professional language
- Submitted only in oral form to preserve natural expression
- Signed and dated by the witness and the collecting investigator (Correct answer)
- Kept confidential and not shared with any other party
Correct answer: Signed and dated by the witness and the collecting investigator
A signed and dated witness statement provides authentication and creates a verifiable record that the witness provided the account at a specific time.
Question 62: In security investigations, the PEACE model acronym stands for Preparation, Engage and Explain, Account, Closure, and what?
- Execution
- Evidence
- Examination
- Evaluation (Correct answer)
Correct answer: Evaluation
PEACE stands for Preparation, Engage and Explain, Account, Closure, and Evaluation — a non-coercive interview framework.
Question 63: The legal standard governing a private security officer's use of force is best described as:
- Minimum force only — no force above verbal commands is ever lawful
- Objectively reasonable force under the circumstances known to the officer at the time (Correct answer)
- Identical to the Graham v. Connor objective reasonableness standard applied to police
- Any force necessary to protect employer property regardless of threat level
Correct answer: Objectively reasonable force under the circumstances known to the officer at the time
Security officers must use only the level of force that is objectively reasonable given the circumstances; excessive force creates both civil and criminal liability.
Question 64: Which communication method is generally considered MOST reliable when normal telecommunications infrastructure fails during a major disaster?
- Social media platforms
- Cellular telephone networks
- Corporate email systems
- Amateur (ham) radio (Correct answer)
Correct answer: Amateur (ham) radio
Amateur (ham) radio operates independently of commercial infrastructure and is widely used as a backup emergency communication system when cellular and internet networks are down.
Question 65: A 'crisis communications plan' should specifically include which element to be effective during an emergency?
- Step-by-step instructions for activating all alarm systems
- Detailed technical specifications of all security systems
- Pre-approved message templates and designated spokesperson protocols (Correct answer)
- A complete employee roster with personal contact information
Correct answer: Pre-approved message templates and designated spokesperson protocols
Effective crisis communications plans include pre-drafted message templates for likely scenarios and clear protocols designating who speaks on behalf of the organization.
Question 66: Which of the following best describes 'exception-based reporting' (EBR) in loss prevention?
- Software that flags POS transactions deviating from expected patterns (Correct answer)
- A method for documenting employee disciplinary actions
- Filing incident reports for all security events
- A system for tracking customer complaints
Correct answer: Software that flags POS transactions deviating from expected patterns
Exception-based reporting uses software to analyze POS data and flag transactions that deviate from normal patterns, helping identify potential fraud or theft.
Question 67: Which type of evidence is considered 'best evidence' in a security investigation?
- A sworn statement from the most credible witness
- A surveillance video recording of the incident
- The original document or item, rather than a copy (Correct answer)
- A forensic report prepared by a certified expert
Correct answer: The original document or item, rather than a copy
The best evidence rule requires that the original document or item be presented rather than a duplicate, unless the original is unavailable.
Question 68: An investigator finds that a suspect communicated using an end-to-end encrypted messaging app with disappearing messages enabled. What is the BEST investigative approach to recover this content?
- Subpoena the app's server logs for message content
- Request decryption keys from the app developer under CALEA
- Use network traffic interception to capture the plaintext
- Perform a live device extraction before messages expire, or seek backup data from cloud storage (Correct answer)
Correct answer: Perform a live device extraction before messages expire, or seek backup data from cloud storage
With true E2E encryption, server-side content is inaccessible; extracting the unlocked device or finding unencrypted cloud backups are the primary recovery paths.
Question 69: What is the role of incident reporting in security management?
- It focuses on assigning blame to individuals
- It helps document incidents for future analysis and policy improvement (Correct answer)
- It helps reduce the number of staff involved in incidents
- It reduces the effectiveness of security systems
Correct answer: It helps document incidents for future analysis and policy improvement
Incident reporting is a vital part of security management as it provides a formal record of all security events, from minor policy violations to major breaches. This documentation is essential for post-incident analysis, allowing organizations to understand the root causes, assess the effectiveness of existing controls, and identify areas for policy improvement. It fosters a continuous learning cycle, strengthening the overall security posture.
Question 70: Which of the following is a key legal concern when interrogating employees suspected of workplace theft?
- Conducting the interrogation without any witnesses present
- Avoiding coercive tactics that could constitute false imprisonment (Correct answer)
- Withholding legal counsel information from the subject
- Ensuring the interrogation lasts at least two hours
Correct answer: Avoiding coercive tactics that could constitute false imprisonment
Security investigators must avoid coercive or threatening tactics that could expose the employer to civil liability for false imprisonment.
Question 71: What is 'statement analysis' used for in a security interview?
- Verifying witness identity
- Recording interview duration
- Detecting deception through language patterns (Correct answer)
- Transcribing spoken words verbatim
Correct answer: Detecting deception through language patterns
Statement analysis examines word choice, structure, and omissions in a subject's account to identify potential deception.
Question 72: When documenting activities related to threat & vulnerability assessment, which practice is considered essential for CSI certification holders?
- Keeping documentation in personal notes that are not accessible to other team members
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Completing documentation only when requested by auditors or supervisors
- Recording only outcomes while omitting the methods and processes used
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in threat & vulnerability assessment. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 73: During a risk assessment, which step comes IMMEDIATELY after identifying threats and vulnerabilities?
- Analyzing and evaluating the risk (Correct answer)
- Implementing countermeasures
- Drafting the security policy
- Conducting employee interviews
Correct answer: Analyzing and evaluating the risk
After identifying threats and vulnerabilities, the next step is to analyze and evaluate the risk to determine its likelihood and potential impact.
Question 74: When documenting activities related to covert & overt investigation methods, which practice is considered essential for CSI certification holders?
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Keeping documentation in personal notes that are not accessible to other team members
- Recording only outcomes while omitting the methods and processes used
- Completing documentation only when requested by auditors or supervisors
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in covert & overt investigation methods. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 75: When a report references a prior incident involving the same subject, the investigator should:
- Omit prior incidents to avoid prejudicing the reader
- Summarize the prior incident in full detail within the current report
- Cite the prior case number and date rather than reprinting the full prior report (Correct answer)
- Include only incidents resulting in conviction or formal charges
Correct answer: Cite the prior case number and date rather than reprinting the full prior report
Citing case numbers and dates keeps the current report concise while allowing readers to retrieve prior records through official channels.
Question 76: What should investigators do to preserve digital evidence in a computer system?
- Access the system remotely
- Alter the system to recover data
- Perform a quick scan of the system
- Create a forensic copy of the storage device (Correct answer)
Correct answer: Create a forensic copy of the storage device
To preserve digital evidence on a computer system, investigators must create an exact, bit-for-bit forensic image (or copy) of the original storage device (e.g., hard drive, USB). This process ensures that the original evidence remains untouched and pristine, while all analysis is performed on the copy. This method prevents any alteration of the original data, maintaining its integrity and legal admissibility.
Question 77: A 'tabletop exercise' is most useful for:
- Measuring emergency response times for benchmarking
- Testing physical evacuation routes under realistic conditions
- Identifying gaps in plans through facilitated discussion without deploying resources (Correct answer)
- Training first responders in hands-on emergency techniques
Correct answer: Identifying gaps in plans through facilitated discussion without deploying resources
Tabletop exercises gather key stakeholders to walk through scenarios verbally, exposing plan gaps, coordination issues, and decision-making weaknesses without operational disruption.
Question 78: A CSI investigator is asked to examine cloud-stored evidence. Which legal instrument is typically required to compel a US-based cloud provider to disclose customer data?
- An executive order from a federal agency
- An informal written request from a corporate HR department
- A subpoena, court order, or search warrant under the Stored Communications Act (Correct answer)
- A civil lawsuit filing
Correct answer: A subpoena, court order, or search warrant under the Stored Communications Act
The Stored Communications Act (part of ECPA) governs law enforcement access to cloud-stored data and requires the appropriate legal process.
Question 79: When evaluating a facility's key control program during a survey, which finding represents the MOST serious vulnerability?
- Master keys are issued to all supervisors
- Keys are labeled with room numbers for convenience (Correct answer)
- Key inventory is conducted annually
- Some keys are over 10 years old
Correct answer: Keys are labeled with room numbers for convenience
Labeling keys with room numbers enables a lost or stolen key to be used immediately against the targeted lock, creating a critical vulnerability.
Question 80: In a security investigation interview, the 'funnel technique' refers to:
- Starting with broad open-ended questions and narrowing to specific details (Correct answer)
- Beginning with accusations and gradually reducing their severity
- Using multiple interviewers to cover different topics simultaneously
- Restricting the subject's movements to a small interview room
Correct answer: Starting with broad open-ended questions and narrowing to specific details
The funnel technique moves from open narrative questions to specific probes, reducing the risk of contaminating the subject's account.
Question 81: What is the purpose of conducting a 'memory dump' (RAM capture) during a live forensic investigation?
- To verify the integrity of installed operating system files
- To create a backup copy of the hard drive before shutdown
- To analyze the Windows event logs stored in system memory
- To capture running processes, encryption keys, passwords, and network connections that exist only in volatile memory (Correct answer)
Correct answer: To capture running processes, encryption keys, passwords, and network connections that exist only in volatile memory
RAM captures volatile artifacts like running processes, decrypted data, active connections, and credentials that are lost when the system powers off.
Question 82: The term 'point of distribution' (POD) in emergency management refers to:
- A location where incident commanders receive briefings
- A facility's main entry point used during controlled evacuations
- A communication relay station for field responders
- A pre-designated site where emergency supplies or services are dispensed to the public (Correct answer)
Correct answer: A pre-designated site where emergency supplies or services are dispensed to the public
A POD is a pre-planned location where commodities such as water, food, or medications are distributed to affected community members following a disaster.
Question 83: The legal doctrine of 'respondeat superior' holds that:
- Supervisors are criminally responsible for subordinates' acts
- An employer is liable for tortious acts of employees committed within the scope of employment (Correct answer)
- An employee cannot be personally sued for on-duty negligence
- Security contractors are always considered employees, not independent contractors
Correct answer: An employer is liable for tortious acts of employees committed within the scope of employment
Respondeat superior ('let the master answer') makes employers vicariously liable for employees' negligent acts performed within the scope of their duties.
Question 84: What is the significance of using tamper-evident seals on evidence containers?
- They prevent the evidence from degrading due to environmental exposure
- They provide visible proof if unauthorized access to the evidence has occurred (Correct answer)
- They legally certify the evidence was collected by a licensed investigator
- They indicate the evidence has been approved for court submission
Correct answer: They provide visible proof if unauthorized access to the evidence has occurred
Tamper-evident seals show any attempt to open or access the container, supporting the integrity of the chain of custody.
Question 85: A 'shelter-in-place' directive is MOST appropriate when:
- A hazardous material release occurs outdoors near the facility (Correct answer)
- A power outage affects only part of the building
- A fire is detected inside the building
- An active shooter is moving toward the building from inside
Correct answer: A hazardous material release occurs outdoors near the facility
Shelter-in-place is most appropriate for outdoor hazardous material releases where remaining indoors with sealed ventilation reduces exposure risk.
Question 86: A security investigator conducting a 'gap analysis' of an existing Emergency Action Plan is primarily seeking to identify:
- The cost differential between current and best-practice security systems
- Personnel who have not completed emergency training certifications
- Discrepancies between current capabilities and required or desired preparedness standards (Correct answer)
- Differences in emergency procedures between day and night shift employees
Correct answer: Discrepancies between current capabilities and required or desired preparedness standards
A gap analysis compares the organization's current state against required standards or best practices to identify deficiencies that need to be addressed in the plan.
Question 87: When a suspect's smartphone is seized, what is the FIRST step an investigator should take to preserve its digital evidence?
- Remove the SIM card and battery
- Attempt to unlock it using common PIN guesses
- Immediately connect it to a forensic workstation
- Place it in airplane mode or a Faraday bag to prevent remote wiping (Correct answer)
Correct answer: Place it in airplane mode or a Faraday bag to prevent remote wiping
Isolating the device from networks prevents remote wipe commands and preserves the current state of all data.
Question 88: A CSI professional encounters an unfamiliar situation while performing emergency action planning duties. What is the most appropriate first action?
- Skip the task entirely and move to the next assignment
- Proceed based on general assumptions to avoid delays
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Apply a solution from an unrelated field without verification
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in emergency action planning, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 89: What is 'skip tracing' and which combination of resources is most effective for locating a missing subject?
- Locating a person who has 'skipped' or fled; combining public records, database searches, and social media (Correct answer)
- Identifying surveillance gaps in a route; uses mapping software and GPS tracking
- Retrieving abandoned surveillance equipment; requires a court order for private property
- A technique for following a subject on foot; best done in pairs with radio communication
Correct answer: Locating a person who has 'skipped' or fled; combining public records, database searches, and social media
Skip tracing is the process of locating a person who is avoiding contact or has disappeared, and combining public records, licensed database searches, and social media yields the most comprehensive results.
Question 90: In the context of covert & overt investigation methods, what role does continuous professional development play for CSI practitioners?
- It serves primarily as a networking opportunity with no practical benefit
- It is optional and only needed for career advancement
- It is required only during the first year of certification
- It ensures practitioners remain current with evolving standards, technologies, and best practices (Correct answer)
Correct answer: It ensures practitioners remain current with evolving standards, technologies, and best practices
Continuous professional development is essential in covert & overt investigation methods because it ensures CSI practitioners remain current with evolving standards, technologies, and best practices, maintaining competency throughout their careers.
Question 91: Which of the following best describes 'locard's exchange principle' and its relevance to evidence collection?
- Evidence must be exchanged between jurisdictions when multiple agencies are involved
- Every contact leaves a trace, meaning physical evidence is often transferred between a subject and a scene (Correct answer)
- Investigators must exchange findings with defense counsel before proceedings
- Physical contact with evidence must be minimized to prevent trace loss
Correct answer: Every contact leaves a trace, meaning physical evidence is often transferred between a subject and a scene
Locard's Exchange Principle holds that any physical interaction leaves microscopic evidence behind, forming the scientific basis for trace evidence collection.
Question 92: A 'rally point' in an active shooter emergency plan is BEST defined as:
- A medical triage area adjacent to the affected building
- A room designated for armed security personnel to stage a counterassault
- A pre-designated secure location where survivors reconvene after evacuating a threat (Correct answer)
- The command post where law enforcement coordinates their response
Correct answer: A pre-designated secure location where survivors reconvene after evacuating a threat
A rally point is a pre-identified, secure location away from danger where evacuees gather to be accounted for and to receive further instructions.
Question 93: A CSI is asked to assess the risk posed by disgruntled former employees. Which control MOST directly addresses this threat?
- Requiring employees to sign non-disclosure agreements
- Immediately revoking all access credentials upon separation (Correct answer)
- Installing security cameras in all hallways
- Increasing perimeter lighting
Correct answer: Immediately revoking all access credentials upon separation
Immediately terminating access credentials upon employee separation is the most direct control against unauthorized access by former employees.
Question 94: When surveying access control systems, what does 'two-factor authentication' require?
- Two security guards verifying identity
- A PIN entered twice for confirmation
- Two separate passwords entered in sequence
- Something you know AND something you have or are (Correct answer)
Correct answer: Something you know AND something you have or are
Two-factor authentication combines two distinct credential categories—knowledge, possession, or biometric—to verify identity.
Question 95: A forensic analyst is examining Windows event logs and finds Event ID 4624 followed by 4672 for the same logon session. What does this combination indicate?
- A service account started without user interaction
- A successful logon where the account was also assigned special/elevated privileges (Correct answer)
- A failed logon attempt followed by account lockout
- A remote desktop session that was forcefully terminated
Correct answer: A successful logon where the account was also assigned special/elevated privileges
Event ID 4624 is a successful logon; Event ID 4672 indicates special privileges (often administrative) were assigned to that session.
Question 96: Which of the following BEST describes 'consequence management' in the context of emergency planning?
- Prosecuting individuals responsible for causing an emergency
- Addressing the effects of an emergency to protect public health, safety, and the environment (Correct answer)
- Managing media relations after a high-profile security incident
- Preventing an emergency from occurring through proactive security measures
Correct answer: Addressing the effects of an emergency to protect public health, safety, and the environment
Consequence management focuses on mitigating the effects of an incident on people, property, and the environment after it has occurred.
Question 97: In the context of physical security surveys, what role does continuous professional development play for CSI practitioners?
- It is required only during the first year of certification
- It ensures practitioners remain current with evolving standards, technologies, and best practices (Correct answer)
- It serves primarily as a networking opportunity with no practical benefit
- It is optional and only needed for career advancement
Correct answer: It ensures practitioners remain current with evolving standards, technologies, and best practices
Continuous professional development is essential in physical security surveys because it ensures CSI practitioners remain current with evolving standards, technologies, and best practices, maintaining competency throughout their careers.
Question 98: What is the concept of Crime Prevention Through Environmental Design (CPTED) as applied to asset protection?
- Using physical design of the environment to reduce opportunities for crime and increase natural surveillance (Correct answer)
- Developing criminal profiles based on past incident reports
- Deploying undercover investigators in high-theft environments
- Installing panic buttons throughout a facility for emergency alerts
Correct answer: Using physical design of the environment to reduce opportunities for crime and increase natural surveillance
CPTED uses environmental design strategies such as natural surveillance, access control, and territorial reinforcement to reduce criminal opportunity and increase the risk of detection.
Question 99: Why is it essential to use write-blockers when handling digital evidence?
- To allow faster data access
- To allow investigators to edit files on the device
- To remove unnecessary files from the device
- To prevent altering the evidence during analysis (Correct answer)
Correct answer: To prevent altering the evidence during analysis
Write-blockers are crucial hardware or software tools used in digital forensics to prevent any modifications to the original digital evidence. By physically or logically blocking write commands, they ensure that the forensic analysis process does not inadvertently alter timestamps, metadata, or file contents on the source drive. This preservation of integrity is paramount for maintaining the admissibility and reliability of evidence in legal proceedings.
Question 100: Which document within an emergency plan specifies the order in which a facility will restore functions after an incident?
- Business Impact Analysis
- Incident Action Plan
- Hazard Vulnerability Analysis
- Recovery Priorities List (Correct answer)
Correct answer: Recovery Priorities List
A Recovery Priorities List (or restoration priority document) ranks critical functions and systems in the order they must be restored post-incident.
Question 101: What is 'spoliation of evidence,' and what are its consequences in a security investigation?
- The accidental duplication of evidence records in multiple systems
- The gradual degradation of biological evidence over time in storage
- The process of transferring evidence to an external forensic lab
- The intentional or negligent destruction of evidence, which can result in legal sanctions and adverse inferences (Correct answer)
Correct answer: The intentional or negligent destruction of evidence, which can result in legal sanctions and adverse inferences
Spoliation occurs when evidence is destroyed, altered, or concealed, and courts may draw adverse inferences or impose sanctions against the responsible party.
Question 102: During a physical security survey, which lighting type is BEST for illuminating building perimeters without creating glare for security personnel?
- Mercury vapor lamps
- High-pressure sodium lamps (Correct answer)
- Incandescent floodlights
- Strobe lighting
Correct answer: High-pressure sodium lamps
High-pressure sodium lamps provide broad, even illumination with low glare, making them ideal for perimeter security lighting.
Question 103: Which type of motion detection is more reliable in outdoor environments with moving vegetation and lighting changes?
- Pixel-based motion detection
- Frame differencing algorithms
- Infrared beam interruption only
- Video analytics with object classification (Correct answer)
Correct answer: Video analytics with object classification
Video analytics with object classification can distinguish between humans, vehicles, and environmental movement (wind, shadows), significantly reducing false alarms outdoors.
Question 104: What is the primary purpose of maintaining a 'chain of custody' for evidence in a security investigation?
- To ensure evidence is stored in a locked room at all times
- To limit the number of investigators who can access physical evidence
- To create a backup copy of all evidence collected on scene
- To document every person who handled the evidence from collection to presentation (Correct answer)
Correct answer: To document every person who handled the evidence from collection to presentation
Chain of custody documentation proves that evidence has not been tampered with, altered, or contaminated between collection and use in proceedings.
Question 105: A forensic image of a suspect hard drive differs in hash value from the original drive after acquisition. What does this MOST likely indicate?
- The evidence may have been altered or the acquisition process was flawed (Correct answer)
- The investigator used SHA-256 instead of MD5
- The forensic software used lossless compression
- The drive uses a proprietary file system
Correct answer: The evidence may have been altered or the acquisition process was flawed
A hash mismatch means the image does not exactly match the source, indicating possible evidence tampering or an acquisition error.
Question 106: Which term describes the pre-designated individual responsible for accounting for all personnel after an evacuation?
- Floor Warden (Correct answer)
- Incident Commander
- Emergency Coordinator
- Assembly Point Monitor
Correct answer: Floor Warden
A Floor Warden (also called an area warden) is responsible for sweeping their zone, directing occupants out, and accounting for personnel at the assembly point.
Question 107: When an emergency action plan includes a 'lockdown' procedure, employees should be trained to:
- Congregate in the lobby for headcount before lockdown is verified
- Evacuate immediately using the nearest exit when a lockdown is announced
- Call 911 only after the lockdown has been confirmed by management
- Secure doors, turn off lights, stay away from windows, and silence mobile devices (Correct answer)
Correct answer: Secure doors, turn off lights, stay away from windows, and silence mobile devices
Lockdown procedures require employees to secure their space, reduce visibility, silence noise sources, and remain in place until an all-clear is issued by authorities.
Question 108: When should an Emergency Action Plan be reviewed and updated?
- Whenever federal regulations require a new OSHA inspection
- Every five years regardless of facility changes
- When the plan is changed, facility layout changes, or when a drill reveals deficiencies (Correct answer)
- Only after a major emergency has occurred
Correct answer: When the plan is changed, facility layout changes, or when a drill reveals deficiencies
OSHA requires EAP review whenever the plan itself changes, when occupancy or layout changes, or when post-drill/exercise review reveals inadequacies.
Question 109: In the Reid Technique, the 'Behavior Analysis Interview (BAI)' is used to:
- Document witness statements for legal proceedings
- Identify behavioral cues that distinguish truthful from deceptive subjects (Correct answer)
- Establish the timeline of an incident
- Train investigators in interview room setup
Correct answer: Identify behavioral cues that distinguish truthful from deceptive subjects
The BAI uses structured questions and observation of behavioral responses to assess the likelihood of deception before a formal interrogation.
Question 110: Which of the following best describes a 'Man-in-the-Middle' (MitM) attack in the context of a digital investigation?
- Deploying ransomware that encrypts all network shares simultaneously
- An attacker who physically intercepts mail between two parties
- An adversary who secretly intercepts and potentially alters communications between two parties (Correct answer)
- Social engineering an employee to reveal their credentials
Correct answer: An adversary who secretly intercepts and potentially alters communications between two parties
In a MitM attack, the adversary positions themselves between two communicating parties to intercept, read, or modify data in transit.
Question 111: In a physical security survey, 'layers of protection' refers to:
- Stacked filing systems for security documentation
- Multiple coats of security paint on doors
- Redundant alarm system wiring
- A defense-in-depth strategy using multiple barriers and controls (Correct answer)
Correct answer: A defense-in-depth strategy using multiple barriers and controls
Defense-in-depth layers multiple physical and procedural controls so that defeating one layer does not compromise the entire security system.
Question 112: What type of threat involves a malicious insider gradually increasing their access privileges over time without authorization?
- Social engineering
- Lateral movement
- Privilege escalation (Correct answer)
- Phishing
Correct answer: Privilege escalation
Privilege escalation involves an insider or attacker gaining higher-level access rights than they are authorized to have.
Question 113: What distinguishes an 'admission' from a 'confession' in the context of investigative interviews?
- An admission is documented in writing while a confession is recorded on audio or video
- An admission is made under oath while a confession is made voluntarily
- An admission acknowledges specific facts while a confession is a complete acknowledgment of guilt (Correct answer)
- An admission applies to civil cases and a confession applies only to criminal matters
Correct answer: An admission acknowledges specific facts while a confession is a complete acknowledgment of guilt
An admission is a statement acknowledging specific incriminating facts, while a confession is a complete acknowledgment of guilt for the act under investigation.
Question 114: Which section of a formal incident report typically contains the investigator's conclusions and recommendations?
- Chain of Custody Log
- Synopsis
- Body/Narrative
- Summary and Recommendations (Correct answer)
Correct answer: Summary and Recommendations
The Summary and Recommendations section is where investigators present their analytical conclusions and proposed next steps.
Question 115: What legal doctrine must private investigators be aware of when gathering electronic evidence that could affect its admissibility?
- The hearsay exclusion rule
- The fruit of the poisonous tree doctrine
- The best evidence rule
- The chain of custody doctrine (Correct answer)
Correct answer: The chain of custody doctrine
Chain of custody requires that evidence be properly collected, documented, and tracked through every transfer to ensure it has not been tampered with or altered, which is critical for admissibility.
Question 116: Under Title III of the Omnibus Crime Control and Safe Streets Act, intercepting a wire communication without authorization is a:
- State misdemeanor
- Civil infraction only
- Regulatory violation handled by the FCC
- Federal criminal offense (Correct answer)
Correct answer: Federal criminal offense
Title III makes the unauthorized interception of wire, oral, or electronic communications a federal felony punishable by fines and imprisonment.
Question 117: What is 'counter-surveillance' in the context of a covert investigation?
- A court-ordered review of surveillance footage
- Installing cameras to monitor the client's property
- Techniques used to detect whether the investigator is being watched or followed (Correct answer)
- Monitoring a second subject while the primary surveillance continues
Correct answer: Techniques used to detect whether the investigator is being watched or followed
Counter-surveillance involves actions taken by an investigator to detect if they themselves are being monitored, followed, or compromised by the subject or their associates.
Question 118: The National Incident Management System (NIMS) was designed primarily to:
- Replace local emergency response plans with federal standards
- Establish liability protections for emergency volunteers
- Mandate specific equipment for all first responders
- Provide a consistent nationwide framework for government and private sector emergency management (Correct answer)
Correct answer: Provide a consistent nationwide framework for government and private sector emergency management
NIMS provides a scalable, flexible framework enabling all levels of government, NGOs, and the private sector to work together effectively during incidents of any size.
Question 119: Under the Electronic Communications Privacy Act (ECPA), a 'trap and trace' device captures:
- GPS location of the communicating parties
- All content of electronic messages
- Incoming identifying information such as caller ID data (Correct answer)
- Encrypted communications before decryption
Correct answer: Incoming identifying information such as caller ID data
A trap and trace device records incoming identifying information (such as the originating phone number) rather than the content of communications.
Question 120: Which document is the surveyor's PRIMARY reference for establishing minimum physical security standards at a federal contractor facility?
- ASIS Physical Security Standard
- NISPOM (National Industrial Security Program Operating Manual) (Correct answer)
- ISO 27001
- Local building code
Correct answer: NISPOM (National Industrial Security Program Operating Manual)
The NISPOM establishes mandatory physical security standards for facilities handling classified information under federal contracts.
Question 121: In covert investigations, 'pretext' most accurately refers to:
- A legal doctrine permitting searches without warrants in emergencies
- Written authorization from a supervising attorney before starting an investigation
- A fabricated or assumed identity or scenario used to elicit information (Correct answer)
- Background research conducted before initiating contact with a subject
Correct answer: A fabricated or assumed identity or scenario used to elicit information
Pretext involves assuming a false identity or creating a fictitious scenario to obtain information or access that would otherwise be denied.
Question 122: Which quality assurance method is most commonly applied in emergency action planning to verify that CSI professional standards are being met?
- Annual reviews conducted exclusively by non-technical management
- Structured audits, peer reviews, and performance metrics aligned with industry benchmarks (Correct answer)
- Relying on client satisfaction surveys as the sole measure of quality
- Informal self-assessment without external validation
Correct answer: Structured audits, peer reviews, and performance metrics aligned with industry benchmarks
Structured audits, peer reviews, and performance metrics aligned with industry benchmarks are the most effective quality assurance methods in emergency action planning, providing objective, measurable evidence that CSI standards are consistently met.
Question 123: Which principle states that during an incident, responders should request resources through their immediate supervisor rather than going around the chain of command?
- Unity of command (Correct answer)
- Unified command
- Span of control
- Modular organization
Correct answer: Unity of command
Unity of command means every individual reports to only one supervisor, ensuring clear accountability and preventing conflicting instructions during incident response.
Question 124: The Incident Command System (ICS) uses a 'span of control' that is ideally kept within what ratio?
- 1 supervisor to 3–7 personnel (Correct answer)
- 1 supervisor to 8–12 personnel
- 1 supervisor to 2–3 personnel
- 1 supervisor to 15–20 personnel
Correct answer: 1 supervisor to 3–7 personnel
ICS recommends a span of control between 1:3 and 1:7, with 1:5 considered optimal, to maintain effective supervision without overwhelming any single supervisor.
Question 125: Which of the following best describes the 'Reid Technique' and its primary criticism in modern investigative practice?
- A digital forensics framework; criticized for not addressing encrypted evidence
- A document examination method; criticized for high equipment costs
- A behavioral-based interrogation method; criticized for potentially producing false confessions (Correct answer)
- A surveillance team coordination protocol; criticized for requiring large investigative budgets
Correct answer: A behavioral-based interrogation method; criticized for potentially producing false confessions
The Reid Technique uses behavioral analysis and psychological pressure to elicit confessions, but research has shown it can produce false confessions, particularly from vulnerable populations.
Question 126: Which phase of the emergency management cycle focuses on reducing the impact of future disasters through structural and non-structural measures?
- Response
- Recovery
- Preparedness
- Mitigation (Correct answer)
Correct answer: Mitigation
Mitigation involves actions taken before a disaster to reduce or eliminate long-term risk, such as reinforcing structures or relocating assets out of flood zones.
Question 127: Which factor is MOST critical when selecting an alternate emergency operations center (EOC)?
- Proximity to the primary EOC for quick staff transfers
- Availability of the location when the primary EOC is unavailable (Correct answer)
- Presence of a cafeteria for extended operations
- High public visibility to reassure community members
Correct answer: Availability of the location when the primary EOC is unavailable
The alternate EOC must be reliably available precisely when the primary site is compromised, making availability the paramount selection criterion.
Question 128: When conducting a witness interview, a security investigator should primarily:
- Suggest likely answers to speed up the process
- Listen actively and avoid interrupting the witness narrative (Correct answer)
- Conduct the interview in a group setting for efficiency
- Record only information that supports the initial theory
Correct answer: Listen actively and avoid interrupting the witness narrative
Active listening without interruption ensures witnesses provide complete, uncontaminated accounts.
Question 129: Which method is used to preserve digital evidence found on a computer without altering the original data?
- Printing all documents found on the device
- Creating a forensic bit-for-bit image of the storage media (Correct answer)
- Rebooting the computer and capturing startup logs
- Copying files to a USB drive for analysis
Correct answer: Creating a forensic bit-for-bit image of the storage media
A forensic image duplicates every bit of the storage media, preserving all data including deleted files and metadata without modifying the original.
Question 130: When documenting activities related to security law & liability, which practice is considered essential for CSI certification holders?
- Keeping documentation in personal notes that are not accessible to other team members
- Recording only outcomes while omitting the methods and processes used
- Completing documentation only when requested by auditors or supervisors
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in security law & liability. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 131: A security investigator is reviewing access logs and discovers an authorized user downloaded 50,000 customer records in one session. This is BEST described as:
- An external attack that bypassed authentication
- A potential data exfiltration event requiring investigation (Correct answer)
- Normal business activity if the user has data access rights
- A policy violation requiring no further action
Correct answer: A potential data exfiltration event requiring investigation
An unusually large download of sensitive records by an authorized user is an anomaly that warrants investigation as a potential data exfiltration or insider threat incident.
Question 132: Which element should be included in the header of every incident report page?
- Case number, date, and investigator name (Correct answer)
- Full transcripts of all interviews
- Analysis of physical evidence
- Suspect's complete criminal history
Correct answer: Case number, date, and investigator name
Headers with case number, date, and investigator name ensure each page can be identified and attributed if separated.
Question 133: Which chain of custody principle ensures that digital evidence collected at a scene can be traced from collection through court presentation?
- Separation of duties
- Non-repudiation
- Data minimization
- Continuity of evidence documentation (Correct answer)
Correct answer: Continuity of evidence documentation
Continuity of evidence documentation (chain of custody) records every person who handled evidence and all transfers, ensuring traceability.
Question 134: In CCTV surveillance, what does 'dwell time' refer to?
- The lifespan of a recording medium
- The time a camera takes to refocus
- The time a PTZ camera remains on a preset position before cycling (Correct answer)
- The delay between recording and playback
Correct answer: The time a PTZ camera remains on a preset position before cycling
Dwell time is the duration a pan-tilt-zoom camera pauses at each preset position during an auto-patrol sequence before moving to the next.
Question 135: Under the federal Electronic Communications Privacy Act (ECPA), employer monitoring of employee electronic communications at work is generally:
- Prohibited regardless of consent or notice
- Permissible when employees have been notified and have consented via policy (Correct answer)
- Limited to monitoring emails but not instant messages
- Permissible only with a court order
Correct answer: Permissible when employees have been notified and have consented via policy
ECPA's 'consent exception' and 'ordinary course of business' exception allow employer monitoring when employees have been given clear notice and consent through acceptable-use policies.
Question 136: A security officer working at a shopping mall fails to respond to a report of a wet floor, and a patron slips and is injured. The mall is most likely liable under which legal theory?
- Premises liability / negligence (Correct answer)
- Respondeat superior for intentional torts
- Vicarious criminal liability
- Strict liability
Correct answer: Premises liability / negligence
Premises liability holds property owners and their agents responsible for negligently maintaining safe conditions for invitees.
Question 137: A 'continuity of operations plan' (COOP) primarily addresses which concern?
- How essential functions will continue during and after a disruption (Correct answer)
- How to restore IT systems after a cyberattack
- How to extinguish industrial fires
- How to communicate with media during a crisis
Correct answer: How essential functions will continue during and after a disruption
A COOP defines how an organization sustains its essential functions and critical operations during and following an emergency or major disruption.
Question 138: According to FEMA's 'Whole Community' approach to emergency management, which group is considered a key partner in preparedness planning?
- State and local government entities exclusively
- Certified security professionals and law enforcement only
- Federal agencies only
- Private sector, NGOs, faith-based organizations, and the public (Correct answer)
Correct answer: Private sector, NGOs, faith-based organizations, and the public
FEMA's Whole Community approach recognizes that effective emergency management requires engagement with the full range of community stakeholders including private sector, nonprofits, and the public.
Question 139: A digital video recorder (DVR) uses H.264 compression. Compared to older MPEG-2, what is the main advantage?
- Smaller file sizes at equivalent image quality (Correct answer)
- Compatibility with analog cameras only
- Higher frame rates only
- Faster playback speeds
Correct answer: Smaller file sizes at equivalent image quality
H.264 achieves significantly smaller file sizes than MPEG-2 at the same image quality level, allowing longer storage retention or less storage space.
Question 140: What is a 'bait vehicle' or 'bait property' operation, and what legal safeguard is essential before conducting one?
- A planted informant device inside a subject's property; requires a wiretap order
- A decoy target placed to lure a subject into a controlled location; requires police cooperation
- A fake vehicle used to replace the surveillance vehicle if it is compromised; requires client authorization
- Property intentionally left accessible to attract a theft suspect; requires careful documentation to avoid entrapment claims (Correct answer)
Correct answer: Property intentionally left accessible to attract a theft suspect; requires careful documentation to avoid entrapment claims
Bait operations use attractive targets to draw out theft or fraud suspects, but investigators must carefully document that the subject was predisposed to commit the act to avoid entrapment defenses.
Question 141: Why is it important to regularly update security policies?
- It keeps the policies aligned with outdated practices
- It focuses on minimizing employee responsibility
- It allows for more lenient enforcement of procedures
- It reduces the number of incidents and response time (Correct answer)
Correct answer: It reduces the number of incidents and response time
Regularly updating security policies is crucial because the threat landscape, technologies, and organizational needs are constantly evolving. Outdated policies can leave an organization vulnerable to new threats or fail to address current operational realities. Keeping policies current ensures they remain effective in mitigating risks, which in turn helps reduce the frequency of security incidents and improves the efficiency of incident response.
Question 142: When documenting an interview, which practice best preserves evidential integrity?
- Summarizing the interview from memory at the end of the workday
- Paraphrasing responses to make the report easier to read
- Recording verbatim statements and noting any spontaneous admissions immediately (Correct answer)
- Omitting emotional outbursts as irrelevant to the investigation
Correct answer: Recording verbatim statements and noting any spontaneous admissions immediately
Verbatim documentation of key statements and real-time notes ensure accuracy and admissibility in subsequent proceedings.
Question 143: Which factor most commonly causes security policies to fail in practice?
- Security policies conflict with international standards
- Policies are too detailed and technical for general staff
- Lack of visible management support and consistent enforcement (Correct answer)
- Policies are written in English rather than employees' native languages
Correct answer: Lack of visible management support and consistent enforcement
When management does not visibly enforce policies or models non-compliance, employees perceive the policies as optional, leading to widespread non-adherence.
Question 144: When documenting witness statements in an incident report, the investigator should:
- Record statements verbatim and attribute them to the source (Correct answer)
- Combine multiple witness accounts into a single narrative
- Omit statements that contradict the physical evidence
- Paraphrase all statements to improve clarity
Correct answer: Record statements verbatim and attribute them to the source
Verbatim recording with proper attribution preserves the integrity of witness testimony and supports evidentiary value.
Question 145: Why is monitoring and reviewing risks essential in security management?
- It focuses on managing employee behavior only
- It helps identify new risks and assess the effectiveness of mitigation strategies (Correct answer)
- It reduces the frequency of audits
- It allows for increased spending on security infrastructure
Correct answer: It helps identify new risks and assess the effectiveness of mitigation strategies
The security landscape is constantly evolving, with new threats and vulnerabilities emerging regularly. Continuous monitoring and periodic review of risks are essential to identify these changes, assess if existing mitigation strategies are still effective, and adapt them as needed. This iterative process ensures that the security program remains relevant, robust, and capable of protecting assets against current and future threats.
Question 146: Which of the following is the BEST indicator of a well-maintained physical security program during a survey?
- Current, tested procedures with documented maintenance records (Correct answer)
- Multiple warning signs posted around the facility
- Presence of expensive security equipment
- Large number of security personnel on duty
Correct answer: Current, tested procedures with documented maintenance records
Documented, tested procedures and maintenance records demonstrate that the security program is actively managed and operationally effective.
Question 147: The 'chain of succession' documented in an emergency plan is intended to:
- Ensure that leadership authority transfers to designated alternates when primary leaders are unavailable (Correct answer)
- Define the sequence in which critical business functions are restored
- Establish the order for employee evacuation by seniority
- Identify the order in which contractors are notified during an emergency
Correct answer: Ensure that leadership authority transfers to designated alternates when primary leaders are unavailable
Chain of succession identifies pre-designated alternates in rank order to assume authority and decision-making if primary leaders are incapacitated or unavailable during an emergency.
Question 148: What is a digital forensics tool used for?
- To modify digital files for investigation
- To delete data for privacy reasons
- To recover and analyze data from digital devices (Correct answer)
- To monitor network activity only
Correct answer: To recover and analyze data from digital devices
Digital forensics tools are specialized software and hardware designed to extract, preserve, and analyze data from various digital sources like computers, mobile phones, and storage media. Their primary purpose is to recover potential evidence without altering the original data, ensuring its integrity for legal or investigative purposes. This process involves techniques to uncover hidden, deleted, or encrypted information.
Question 149: The 'all-hazards' approach to emergency planning is best described as:
- Prioritizing natural disasters over man-made threats
- Developing core response capabilities applicable across multiple types of emergencies (Correct answer)
- Planning separately for each specific type of hazard
- Conducting annual hazard surveys for OSHA compliance
Correct answer: Developing core response capabilities applicable across multiple types of emergencies
The all-hazards approach builds common core capabilities—communications, evacuation, command—that apply regardless of the specific emergency type.
Question 150: In a report, the phrase 'unknown suspect' should be replaced with a detailed description when:
- Management requests a more formal document
- The investigator suspects a known offender
- The incident results in significant financial loss
- A witness or camera footage provides identifiable physical details (Correct answer)
Correct answer: A witness or camera footage provides identifiable physical details
When physical details are available from witnesses or surveillance, they must be recorded to aid identification.
Question 151: In a formal policy hierarchy, which document typically provides the highest-level strategic direction?
- Work Instruction
- Security Policy (Correct answer)
- Technical Guideline
- Standard Operating Procedure
Correct answer: Security Policy
Security policies sit at the top of the hierarchy, establishing overarching principles that standards, procedures, and guidelines must support.
CSI® Certified Security Investigator
The CSI® certification validates specialist competence in corporate security investigations, covering the full lifecycle from case management and evidence gathering through interview methodology and investigation reporting. It is awarded by CorpSecurity International.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds