LEIN Data Security & Privacy Protocols 5 — Questions and Answers
Question 1: Which of the following is the correct procedure when a LEIN operator suspects they are responding to a 'social engineering' attempt to obtain LEIN data over the phone?
- Provide general information only to avoid being impolite to a potential colleague
- Refuse to provide any LEIN data and report the incident to the TAC (Correct answer)
- Request the caller's badge number and provide the data if they supply one
- Transfer the call to a supervisor who can verify the request independently
Correct answer: Refuse to provide any LEIN data and report the incident to the TAC
Operators must refuse to release LEIN data based on unverified phone requests and report suspected social engineering attempts to the TAC.
Question 2: Under LEIN security protocols, mobile devices used to access LEIN data must:
- Be personal devices owned by the officer to ensure accountability
- Meet FBI CJIS Security Policy requirements including encryption and remote-wipe capability (Correct answer)
- Only access LEIN through unsecured Wi-Fi when in the field
- Be approved by the county IT department with no federal standards required
Correct answer: Meet FBI CJIS Security Policy requirements including encryption and remote-wipe capability
Mobile devices accessing LEIN must comply with FBI CJIS Security Policy, which mandates encryption, remote wipe, and other security controls.
Question 3: A subject challenges the accuracy of a criminal history record obtained through LEIN. Under applicable law and policy, the subject's challenge should be directed to:
- The LEIN terminal operator who last accessed the record
- The agency that originally entered the record and/or the state repository maintaining it (Correct answer)
- The FBI directly, bypassing all state systems
- The court that processed the underlying case, with no agency notification required
Correct answer: The agency that originally entered the record and/or the state repository maintaining it
Challenges to CHRI accuracy are directed to the originating agency or state repository, which are responsible for the accuracy of their entries.
Question 4: When conducting a LEIN query during a traffic stop, an officer's in-car terminal displays a 'system unavailable' message. The correct protocol is to:
- Detain the subject until the system is restored, regardless of time
- Contact dispatch to run the query through an alternate terminal and proceed based on the result (Correct answer)
- Release the subject immediately since no query can be completed
- Manually search law enforcement databases on a personal device
Correct answer: Contact dispatch to run the query through an alternate terminal and proceed based on the result
When a terminal is unavailable, dispatch can run the query through an alternate terminal, ensuring the officer still has access to necessary information.
Question 5: Under LEIN and CJIS policies, which of the following individuals is NOT required to complete LEIN security awareness training?
- A records clerk who enters data into LEIN
- A jail administrator who supervises staff with LEIN access
- A contracted IT vendor who maintains the LEIN terminal hardware but has no system access (Correct answer)
- A dispatcher who queries LEIN on behalf of field officers
Correct answer: A contracted IT vendor who maintains the LEIN terminal hardware but has no system access
Contracted personnel who maintain hardware but have no logical or physical access to CJI are not required to complete CJIS security awareness training.
Question 6: The LEIN 'hit confirmation' requirement before taking enforcement action on a stolen property hit is designed primarily to:
- Give the suspect time to voluntarily surrender the property
- Prevent wrongful enforcement actions based on records that may be outdated or entered in error (Correct answer)
- Allow the entering agency to collect the property before the field officer takes action
- Satisfy a court requirement that all LEIN queries be reviewed by a judge
Correct answer: Prevent wrongful enforcement actions based on records that may be outdated or entered in error
Hit confirmation protects individuals from wrongful detention or arrest by ensuring the record is still active and valid before enforcement action is taken.
Question 7: An agency wants to provide LEIN query access to a neighboring municipality's officers on a temporary basis during a joint task force operation. This requires:
- Verbal authorization from the hosting agency's chief only
- A formal written agreement and individual user account provisioning per LEIN policy (Correct answer)
- No special action if both agencies are within the same county
- FBI CJIS approval for any inter-agency data sharing
Correct answer: A formal written agreement and individual user account provisioning per LEIN policy
Temporary access for outside personnel requires a formal written agreement and individual account creation to maintain audit accountability.
Which of the following is the correct procedure when a LEIN operator suspects they are responding to a 'social engineering' attempt to obtain LEIN data over the phone?