CSL Cybercrime & Legal Frameworks 3 β Questions and Answers
Question 1: The CAN-SPAM Act of 2003 applies to commercial email messages. Which of the following is NOT a requirement imposed on senders under CAN-SPAM?
- Include a functioning opt-out mechanism
- Honor opt-out requests within 10 business days
- Obtain prior affirmative consent before sending any commercial email (Correct answer)
- Include a valid physical postal address
Correct answer: Obtain prior affirmative consent before sending any commercial email
CAN-SPAM is an opt-out law, not opt-in; it does not require prior consent before sending commercial email, distinguishing it from the EU's GDPR email rules.
Question 2: A ransomware group encrypts hospital systems and demands Bitcoin payment. Under the CFAA, which provision most directly covers the act of knowingly causing damage to a protected computer used in interstate commerce?
- 18 U.S.C. Β§ 1030(a)(2) β unauthorized access to obtain information
- 18 U.S.C. Β§ 1030(a)(5) β intentional damage to a protected computer (Correct answer)
- 18 U.S.C. Β§ 1030(a)(4) β fraud and obtaining value
- 18 U.S.C. Β§ 1030(a)(7) β extortionate threats
Correct answer: 18 U.S.C. Β§ 1030(a)(5) β intentional damage to a protected computer
Section 1030(a)(5) criminalizes intentionally causing damage to a protected computer, making it the primary provision for ransomware and destructive malware attacks.
Question 3: Which U.S. agency leads cybercrime investigations under Title 18 (federal criminal statutes) and operates the Internet Crime Complaint Center (IC3)?
- Cybersecurity and Infrastructure Security Agency (CISA)
- Federal Bureau of Investigation (FBI) (Correct answer)
- Secret Service Electronic Crimes Task Forces
- National Security Agency (NSA)
Correct answer: Federal Bureau of Investigation (FBI)
The FBI has primary jurisdiction over federal cybercrime investigations and operates IC3, which receives and refers cybercrime complaints nationwide.
Question 4: Under the Defend Trade Secrets Act (DTSA) of 2016, a company can seek a civil ex parte seizure order in a cybertheft case. What must the plaintiff demonstrate to obtain this extraordinary remedy?
- That the defendant is a foreign national operating outside the U.S.
- That notice would cause the defendant to destroy or dissipate the stolen trade secrets (Correct answer)
- That the trade secret involves classified government information
- That criminal prosecution has already been initiated
Correct answer: That notice would cause the defendant to destroy or dissipate the stolen trade secrets
An ex parte seizure under DTSA requires showing that advance notice would enable the defendant to destroy, move, hide, or make the trade secrets otherwise inaccessible.
Question 5: The Wire Fraud statute (18 U.S.C. Β§ 1343) is frequently used in cybercrime prosecutions. What element distinguishes wire fraud from mail fraud?
- Wire fraud requires proof of actual financial loss; mail fraud does not
- Wire fraud involves use of electronic wire communications in interstate commerce (Correct answer)
- Wire fraud only applies to bank-related schemes
- Wire fraud requires a minimum loss amount of $5,000
Correct answer: Wire fraud involves use of electronic wire communications in interstate commerce
Wire fraud requires the use of wire, radio, or television communications in interstate or foreign commerce as part of a scheme to defraud, while mail fraud uses the postal system.
Question 6: Under the USA PATRIOT Act, which provision expanded the government's ability to conduct 'roving' wiretaps on suspected terrorists or foreign intelligence targets?
- Section 215 β business records
- Section 206 β roving wiretap authority (Correct answer)
- Section 218 β FISA probable cause standard
- Section 505 β national security letters
Correct answer: Section 206 β roving wiretap authority
Section 206 of the PATRIOT Act authorized roving wiretaps under FISA, allowing surveillance to follow a target across multiple devices without identifying each device in advance.
Question 7: A cybercriminal in Country A hacks servers in Country B to steal data from victims in Country C. Which legal principle best supports Country C asserting criminal jurisdiction?
- Territorial principle
- Passive personality principle
- Effects doctrine (Correct answer)
- Flag state jurisdiction
Correct answer: Effects doctrine
The effects doctrine allows Country C to assert jurisdiction because the harmful effects of the cybercrime were felt by its nationals or within its territory.
The CAN-SPAM Act of 2003 applies to commercial email messages.
Which of the following is NOT a requirement imposed on senders under CAN-SPAM?