PI PI Digital Investigation and OSINT 2 — Questions and Answers
Question 1: When conducting a reverse image search during an investigation, a PI is attempting to:
- Enhance a blurry photograph
- Find other locations where the same image appears online (Correct answer)
- Convert images to digital text
- Identify counterfeit documents
Correct answer: Find other locations where the same image appears online
A reverse image search allows a PI to find other websites or profiles where the same image has been used, which can expose fake identities or reveal additional information about a subject.
Question 2: Which tool category is most commonly used by PIs to aggregate publicly available data about an individual from multiple sources?
- Dark web scrapers
- People-search aggregator sites (Correct answer)
- Keylogger software
- Packet sniffer programs
Correct answer: People-search aggregator sites
People-search aggregator sites compile publicly available records such as addresses, phone numbers, and relatives, making them a common and legal OSINT resource for PIs.
Question 3: A PI discovers that a subject uses the same username across multiple platforms. This technique of linking accounts is called:
- Account hijacking
- Username correlation (Correct answer)
- Social engineering
- Phishing
Correct answer: Username correlation
Username correlation is a passive OSINT technique where a PI identifies that the same username appears across multiple platforms, allowing them to build a more complete profile of the subject.
Question 4: Under the Computer Fraud and Abuse Act (CFAA), a PI could face criminal liability for:
- Reviewing publicly available websites
- Accessing a protected computer without authorization (Correct answer)
- Using a search engine to research a subject
- Reviewing public social media profiles
Correct answer: Accessing a protected computer without authorization
The CFAA criminalizes unauthorized access to protected computers, meaning PIs who access accounts or systems without authorization—even if passwords are guessed—can face federal charges.
Question 5: What is 'geo-fencing' data and how might it legally appear in a PI investigation?
- A method of blocking a subject from using GPS devices
- Location data tied to a specific geographic area that may be included in discovery materials (Correct answer)
- Software used to track vehicles without physical devices
- A court-ordered restriction on a subject's movements
Correct answer: Location data tied to a specific geographic area that may be included in discovery materials
Geo-fencing data links digital activity to a specific geographic area; a PI may encounter it through legally obtained court records, civil litigation discovery, or public data sources.
Question 6: Which of the following best describes 'pretexting' and its legality under federal law?
- A legal technique involving reviewing pretext ads
- Fabricating a false identity or scenario to obtain private information, which is illegal under the GLBA for financial records (Correct answer)
- Using indirect questions to elicit information, which is always legal
- Researching a subject's background using public records
Correct answer: Fabricating a false identity or scenario to obtain private information, which is illegal under the GLBA for financial records
Pretexting involves using false pretenses to obtain private information; the Gramm-Leach-Bliley Act specifically prohibits pretexting to obtain financial records, and broader pretexting can violate other laws.
When conducting a reverse image search during an investigation, a PI is attempting to: