Mixed Deck — All CSI Topics Flashcards
100 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CSI Topics flashcards as text
What does the term 'attack surface' refer to in information security?
Answer: The sum of all points where an unauthorized user can try to enter or extract data
The attack surface encompasses all the different points where an attacker could try to enter, extract data from, or disrupt a system or network.
What is a 'cognitive load' indicator during an interview, and why is it significant?
Answer: Signs of mental effort that may indicate fabrication of a story
Increased cognitive load — shown by pauses, slower speech, or requests for repetition — can indicate a subject is constructing rather than recalling a story.
A CSI investigator preparing a report for litigation should write in:
Answer: Third person to maintain professional objectivity
Third-person writing in investigative reports maintains professional neutrality and objectivity required for legal proceedings.
A forensic image of a suspect hard drive differs in hash value from the original drive after acquisition. What does this MOST likely indicate?
Answer: The evidence may have been altered or the acquisition process was flawed
A hash mismatch means the image does not exactly match the source, indicating possible evidence tampering or an acquisition error.
When a security investigator must correct an error in a written report, the proper procedure is to:
Answer: Draw a single line through the error, initial it, and make the correction
Drawing a single line, initialing, and correcting preserves the original entry while showing the authorized change.
What is 'statement analysis' used for in a security interview?
Answer: Detecting deception through language patterns
Statement analysis examines word choice, structure, and omissions in a subject's account to identify potential deception.
A CSI professional encounters an unfamiliar situation while performing threat & vulnerability assessment duties. What is the most appropriate first action?
Answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in threat & vulnerability assessment, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Which policy governs how an organization responds when a security breach is discovered?
Answer: Incident Response Policy
An Incident Response Policy defines roles, procedures, and timelines for detecting, containing, and recovering from security incidents.
Which hashing algorithm is currently recommended by NIST for forensic evidence verification due to its collision resistance?
Answer: SHA-256
SHA-256 is NIST-recommended for integrity verification because MD5 and SHA-1 have known collision vulnerabilities.
What distinguishes an 'admission' from a 'confession' in the context of investigative interviews?
Answer: An admission acknowledges specific facts while a confession is a complete acknowledgment of guilt
An admission is a statement acknowledging specific incriminating facts, while a confession is a complete acknowledgment of guilt for the act under investigation.
What is 'OSINT' as it relates to surveillance investigations?
Answer: Open Source Intelligence gathered from publicly available information
OSINT (Open Source Intelligence) involves collecting and analyzing information from publicly available sources such as social media, public records, and websites.
Why is monitoring and reviewing risks essential in security management?
Answer: It helps identify new risks and assess the effectiveness of mitigation strategies
The security landscape is constantly evolving, with new threats and vulnerabilities emerging regularly. Continuous monitoring and periodic review of risks are essential to identify these changes, assess if existing mitigation strategies are still effective, and adapt them as needed. This iterative process ensures that the security program remains relevant, robust, and capable of protecting assets against current and future threats.
Which of the following is a key legal concern when interrogating employees suspected of workplace theft?
Answer: Avoiding coercive tactics that could constitute false imprisonment
Security investigators must avoid coercive or threatening tactics that could expose the employer to civil liability for false imprisonment.
What is the first step in risk management for security professionals?
Answer: Identifying potential threats and vulnerabilities
The first and most fundamental step in any risk management process is to thoroughly identify what could go wrong. This involves recognizing potential threats (e.g., cyberattacks, natural disasters, insider threats) and understanding the vulnerabilities within a system or organization that these threats could exploit. Without a clear understanding of these elements, effective risk assessment and mitigation cannot occur.
Which factor is MOST critical when selecting an alternate emergency operations center (EOC)?
Answer: Availability of the location when the primary EOC is unavailable
The alternate EOC must be reliably available precisely when the primary site is compromised, making availability the paramount selection criterion.
During an investigation, an analyst finds that an attacker used SQL injection. Which security principle was most directly violated?
Answer: Input validation and secure coding practices
SQL injection exploits failures in input validation and secure coding, where user-supplied data is incorrectly trusted and passed to a database interpreter.
In most U.S. jurisdictions, 'punitive damages' in a civil lawsuit against a security company are available when:
Answer: The defendant's conduct was willful, wanton, or maliciously reckless
Punitive (exemplary) damages are reserved for egregious misconduct that goes beyond ordinary negligence, such as willful or malicious behavior.
A CSI professional encounters an unfamiliar situation while performing covert & overt investigation methods duties. What is the most appropriate first action?
Answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in covert & overt investigation methods, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
What should investigators do if they encounter digital evidence stored on a password-protected device?
Answer: Request proper authorization and use legal tools to access the device
When encountering a password-protected device, investigators must adhere to strict legal and ethical guidelines to ensure the admissibility of evidence. This involves obtaining proper legal authorization, such as a search warrant or court order, before attempting to access the device. Using authorized forensic tools and methods ensures that any attempts to bypass security are legally sound and forensically sound, preserving the chain of custody and data integrity.
A CSI professional encounters an unfamiliar situation while performing emergency action planning duties. What is the most appropriate first action?
Answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in emergency action planning, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.