FBI Cybercrime and Digital Forensics Flashcards
6 cards from real FBI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 FBI Cybercrime and Digital Forensics flashcards as text
What FBI division is primarily responsible for investigating cyber intrusions and cybercrime?
Answer: Cyber Division
The FBI's Cyber Division leads the Bureau's investigations into computer intrusions, ransomware, online fraud, and other cyber threats to U.S. systems and critical infrastructure.
What is the Computer Fraud and Abuse Act (CFAA) and why is it relevant to FBI cyber investigations?
Answer: The primary federal statute criminalizing unauthorized access to computers and computer-facilitated fraud
The CFAA (18 U.S.C. § 1030) is the primary federal law the FBI uses to prosecute unauthorized access to computer systems, data theft, and computer-facilitated crimes.
What type of cyber threat involves criminals encrypting a victim's data and demanding payment for the decryption key?
Answer: Ransomware attack
Ransomware is a type of malware that encrypts victim files and demands a ransom — typically in cryptocurrency — in exchange for the decryption key to restore access.
What is 'digital forensics' in the context of FBI investigations?
Answer: The collection, preservation, analysis, and presentation of digital evidence in a legally sound manner
Digital forensics involves the scientific examination of digital devices and data — following strict protocols to preserve evidence integrity — to support criminal or civil investigations.
What is a 'preservation letter' in FBI cyber investigations?
Answer: A formal request to an internet service provider to preserve electronic records pending a legal process
Under 18 U.S.C. § 2703(f), the FBI can request that internet service providers preserve stored electronic records for 90 days (renewable) while formal legal process is obtained.
What does the acronym 'IOC' stand for in FBI cyber threat intelligence?
Answer: Indicator of Compromise
An Indicator of Compromise (IOC) is a piece of forensic data — such as a malicious IP address, file hash, or domain — that indicates a computer system may have been breached.