CSX Criminal Investigation Procedures 2 โ Questions and Answers
Question 1: Under the Fourth Amendment, law enforcement generally requires a search warrant to access stored electronic communications that are older than how many days, per the Electronic Communications Privacy Act (ECPA)?
- 30 days
- 90 days
- 180 days (Correct answer)
- 365 days
Correct answer: 180 days
ECPA's original threshold treats stored communications older than 180 days as abandoned, historically allowing access with a subpoena rather than a warrant, though courts increasingly require warrants regardless.
Question 2: What is the primary legal authority under US federal law that criminalizes unauthorized access to computer systems?
- Electronic Communications Privacy Act
- Computer Fraud and Abuse Act (Correct answer)
- Cybersecurity Information Sharing Act
- Digital Millennium Copyright Act
Correct answer: Computer Fraud and Abuse Act
The Computer Fraud and Abuse Act (CFAA), 18 U.S.C. ยง 1030, is the primary federal statute criminalizing unauthorized computer access and related offenses.
Question 3: During a cybercrime investigation, an investigator discovers logs showing an attacker pivoted through systems in three different countries. Which organization is best positioned to coordinate this multi-jurisdictional investigation?
- FBI Cyber Division
- INTERPOL Cybercrime Directorate (Correct answer)
- CISA
- NSA
Correct answer: INTERPOL Cybercrime Directorate
INTERPOL's Cybercrime Directorate facilitates cross-border coordination among member nations' law enforcement agencies for international cybercrime investigations.
Question 4: A forensic examiner receives a hard drive from law enforcement. What should be the FIRST step before any analysis?
- Install forensic software on the drive
- Create a bit-for-bit forensic image (Correct answer)
- Run antivirus scans
- Index all files for keyword searching
Correct answer: Create a bit-for-bit forensic image
Creating a bit-for-bit forensic image preserves the original evidence and ensures the original drive is not modified during analysis.
Question 5: Which legal doctrine allows evidence obtained during an unlawful search to be excluded from trial?
- Fruit of the poisonous tree (Correct answer)
- Chain of custody
- Best evidence rule
- Hearsay exception
Correct answer: Fruit of the poisonous tree
The 'fruit of the poisonous tree' doctrine holds that evidence derived from an illegal search or seizure is inadmissible because it is tainted by the initial constitutional violation.
Question 6: When a company experiences a data breach, which federal agency should typically be notified if the breach involves critical infrastructure?
- FTC
- CISA (Correct answer)
- SEC
- FCC
Correct answer: CISA
CISA (Cybersecurity and Infrastructure Security Agency) is the lead federal agency for coordinating cybersecurity efforts affecting critical infrastructure.
Question 7: An investigator wants to obtain subscriber information from an ISP without a full search warrant. Which legal instrument is most appropriate?
- Grand jury subpoena (Correct answer)
- Title III wiretap order
- Section 215 order
- Pen register order
Correct answer: Grand jury subpoena
A grand jury subpoena (or administrative subpoena in some contexts) can compel ISPs to produce basic subscriber records such as name, address, and account information without a full search warrant.
Under the Fourth Amendment, law enforcement generally requires a search warrant to access stored electronic communications that are older than how many days, per the Electronic Communications Privacy Act (ECPA)?