CSX Legal Framework & Constitutional Law 3 — Questions and Answers
Question 1: Under the Computer Fraud and Abuse Act (CFAA), what is the threshold amount of damage or loss that elevates a violation to a federal felony?
- $500 in a one-year period
- $1,000 in a one-year period
- $5,000 in a one-year period (Correct answer)
- $10,000 in a one-year period
Correct answer: $5,000 in a one-year period
The CFAA requires aggregated damage or loss of at least $5,000 during a one-year period for many felony provisions to apply.
Question 2: A security researcher accesses a company's publicly available web server to demonstrate a vulnerability without authorization. Under the CFAA, which element is most contested in this scenario?
- Whether the server qualifies as a 'protected computer'
- Whether the researcher acted 'without authorization' or exceeded authorized access (Correct answer)
- Whether the damage threshold was met
- Whether federal jurisdiction applies
Correct answer: Whether the researcher acted 'without authorization' or exceeded authorized access
The 'without authorization' or 'exceeds authorized access' element is the most contentious CFAA issue for security researchers accessing systems without explicit permission.
Question 3: Which CFAA provision specifically criminalizes trafficking in passwords or similar information used to access protected computers?
- 18 U.S.C. § 1030(a)(2)
- 18 U.S.C. § 1030(a)(4)
- 18 U.S.C. § 1030(a)(6) (Correct answer)
- 18 U.S.C. § 1030(a)(7)
Correct answer: 18 U.S.C. § 1030(a)(6)
Section 1030(a)(6) of the CFAA prohibits knowingly trafficking in passwords or similar information through which a protected computer may be accessed without authorization.
Question 4: In Van Buren v. United States (2021), how did the Supreme Court interpret 'exceeds authorized access' under the CFAA?
- It includes any use of a computer that violates an employer's acceptable use policy
- It is limited to accessing areas of a computer that are off-limits, not misusing access to permissible areas (Correct answer)
- It covers any access that results in financial harm to the owner
- It applies whenever a user circumvents technical access controls
Correct answer: It is limited to accessing areas of a computer that are off-limits, not misusing access to permissible areas
Van Buren narrowed 'exceeds authorized access' to mean accessing parts of a system one is not permitted to access, not misusing access to areas one is already allowed to view.
Question 5: Which statute, alongside the CFAA, primarily governs criminal wiretapping and interception of electronic communications in the United States?
- Electronic Communications Privacy Act (ECPA) – Title I (Wiretap Act) (Correct answer)
- Health Insurance Portability and Accountability Act (HIPAA)
- Gramm-Leach-Bliley Act (GLBA)
- Children's Online Privacy Protection Act (COPPA)
Correct answer: Electronic Communications Privacy Act (ECPA) – Title I (Wiretap Act)
Title I of ECPA, known as the Wiretap Act (18 U.S.C. § 2511), prohibits intentional interception of wire, oral, or electronic communications.
Question 6: A disgruntled employee uses their legitimate work credentials to copy confidential files before resigning. Under the CFAA, the most likely applicable provision is:
- Unauthorized access to obtain national security information
- Intentional access without authorization to obtain financial information
- Intentionally exceeding authorized access to obtain information from a protected computer (Correct answer)
- Knowingly causing damage to a protected computer
Correct answer: Intentionally exceeding authorized access to obtain information from a protected computer
Using valid credentials beyond their permitted scope to obtain confidential data typically falls under exceeding authorized access under 18 U.S.C. § 1030(a)(2).
Question 7: Which federal law primarily governs the interception and disclosure of communications by a provider of electronic communication services to the public?
- Stored Communications Act (SCA) (Correct answer)
- Wiretap Act
- Pen Register Act
- Communications Assistance for Law Enforcement Act (CALEA)
Correct answer: Stored Communications Act (SCA)
The Stored Communications Act restricts ISPs and cloud providers from voluntarily disclosing stored user communications and content to third parties including law enforcement without proper legal process.
Under the Computer Fraud and Abuse Act (CFAA), what is the threshold amount of damage or loss that elevates a violation to a federal felony?