← All FBI Flashcard Decks

FBI Cybercrime and Digital Forensics Flashcards

6 cards from real FBI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 FBI Cybercrime and Digital Forensics flashcards as text
  1. What FBI unit specializes in deploying to major intrusion incidents to assist victims and collect evidence?

    Answer: Cyber Action Teams (CAT)

    The FBI's Cyber Action Teams (CATs) are rapid-response units that deploy globally to assist victims of significant cyber intrusions, collect forensic evidence, and support attribution efforts.

  2. Which of the following is NOT a category of cybercrime the FBI investigates under its cyber program?

    Answer: Shoplifting using counterfeit loyalty reward points

    Physical retail shoplifting with counterfeit loyalty points is not a cyber program matter; BEC, ransomware on critical infrastructure, and online CSAM are all core FBI cyber mission areas.

  3. What is a 'botnet' and why is it significant to FBI cybercrime investigations?

    Answer: A network of compromised computers controlled remotely by criminals to conduct attacks, spam, or fraud at scale

    A botnet is a network of malware-infected computers (bots) controlled by a criminal operator (botmaster) used to conduct DDoS attacks, send spam, steal credentials, or distribute ransomware.

  4. What is the FBI's legal mechanism for obtaining real-time interception of electronic communications in a cyber investigation?

    Answer: A Title III wiretap order from a federal judge

    Real-time interception of electronic communications — including internet traffic — requires a Title III order (electronic surveillance warrant) issued by a federal judge upon showing of probable cause.

  5. What does 'attribution' mean in the context of FBI cyber investigations?

    Answer: Identifying the specific individual, group, or nation-state responsible for a cyber intrusion

    Attribution in cyber investigations is the technical and analytical process of identifying who is responsible for an intrusion — whether a criminal, hacktivist group, or nation-state actor.

  6. Under the FBI's cyber program, what is 'critical infrastructure' as defined by Presidential Policy Directive 21 (PPD-21)?

    Answer: Systems and assets so vital to the U.S. that their incapacitation would have a debilitating effect on national security, public health, or the economy

    PPD-21 defines critical infrastructure as 16 sectors (energy, water, finance, healthcare, etc.) whose disruption would severely impact national security, public health, safety, or the economy.