PILB Digital Forensics and Cyber Investigations 2 — Questions and Answers
Question 1: Open Source Intelligence (OSINT) in a cyber investigation refers to:
- Collecting information from publicly accessible sources such as social media, websites, and public records (Correct answer)
- Hacking into private databases to gather intelligence
- Purchasing data from the dark web
- Intercepting private communications without consent
Correct answer: Collecting information from publicly accessible sources such as social media, websites, and public records
OSINT involves gathering information from legally accessible public sources, making it a foundational and lawful investigative technique.
Question 2: A Nevada PI is asked to intercept text messages on a subject's phone. Under the Electronic Communications Privacy Act (ECPA), this is:
- Illegal without consent from at least one party to the communication or a court order (Correct answer)
- Legal if the client is the subject's employer
- Legal if the PI obtains PILB approval
- Legal if conducted for a civil litigation matter
Correct answer: Illegal without consent from at least one party to the communication or a court order
The ECPA prohibits intercepting electronic communications without consent or a lawful court order, regardless of the requester's identity.
Question 3: Which Nevada law governs recording of private conversations and sets a one-party consent standard?
- NRS 200.620 — Nevada is a one-party consent state for recording private conversations (Correct answer)
- NRS 648 — requires all parties to consent before any recording
- Nevada follows federal two-party consent rules exclusively
- There is no Nevada law on recording conversations
Correct answer: NRS 200.620 — Nevada is a one-party consent state for recording private conversations
Under NRS 200.620, Nevada allows recording of a private conversation with the consent of at least one party, meaning a PI who is party to the call may record it.
Question 4: A PI discovers during a cyber investigation that a subject is operating a phishing scheme targeting Nevada residents. The PI should:
- Document findings, inform the client, and recommend reporting to law enforcement or the Nevada AG (Correct answer)
- Disable the phishing site by hacking it
- Alert the victims directly and advise them on legal action
- Post the findings publicly online to warn others
Correct answer: Document findings, inform the client, and recommend reporting to law enforcement or the Nevada AG
A PI's role is to document and report findings to the client who can then engage proper authorities; taking unilateral action would be both legally and ethically improper.
Question 5: When preserving a webpage as digital evidence, the most forensically sound method is:
- Using a web archiving tool that captures the full HTML, metadata, and timestamp (Correct answer)
- Taking a regular screenshot with no metadata capture
- Printing the page to PDF without recording the URL
- Emailing the link to the client as documentation
Correct answer: Using a web archiving tool that captures the full HTML, metadata, and timestamp
Forensic web archiving tools capture the full page content along with URL, timestamp, and technical metadata required for evidentiary purposes.
Question 6: A PI conducting a background investigation finds a subject's prior criminal conviction record. Under the FCRA, this information may be reported to a client for employment screening for how long after the conviction?
- There is no time limit on reporting criminal convictions under the FCRA (Correct answer)
- Only convictions within the last 7 years
- Only convictions within the last 3 years
- Convictions may never be reported to employers
Correct answer: There is no time limit on reporting criminal convictions under the FCRA
Unlike some other adverse information, the FCRA's 7-year limit does not apply to criminal convictions, which may be reported indefinitely.
Open Source Intelligence (OSINT) in a cyber investigation refers to: