SSP Legal & Ethical Compliance 4 — Questions and Answers
Question 1: When conducting a pre-employment background investigation, failure to obtain written authorization from the applicant violates which federal law?
- Americans with Disabilities Act
- Fair Credit Reporting Act (FCRA) (Correct answer)
- National Labor Relations Act
- Employee Polygraph Protection Act
Correct answer: Fair Credit Reporting Act (FCRA)
The FCRA requires written disclosure and authorization before obtaining consumer reports (including background checks) for employment purposes.
Question 2: A security officer uses physical force to detain a shoplifter beyond what was necessary after the threat was neutralized. This may constitute:
- Justifiable use of force under merchant privilege
- Excessive force, potentially exposing the officer to civil and criminal liability (Correct answer)
- Standard procedure under security protocols
- A protected action under sovereign immunity
Correct answer: Excessive force, potentially exposing the officer to civil and criminal liability
Force used beyond what is necessary to control a situation constitutes excessive force, which can result in civil liability and criminal charges.
Question 3: Which ethical framework focuses on the outcome of actions, judging them as right if they produce the greatest good for the greatest number?
- Deontological ethics
- Virtue ethics
- Utilitarian ethics (Correct answer)
- Rights-based ethics
Correct answer: Utilitarian ethics
Utilitarian ethics evaluates the morality of actions based on their consequences, seeking to maximize overall benefit.
Question 4: Under the Computer Fraud and Abuse Act (CFAA), unauthorized access to a computer system used in interstate commerce is:
- A civil matter only, handled by state courts
- A federal crime subject to criminal prosecution (Correct answer)
- Only actionable if financial loss exceeds $10,000
- Protected activity if the accessor is a licensed security professional
Correct answer: A federal crime subject to criminal prosecution
The CFAA makes unauthorized access to protected computers a federal criminal offense, regardless of the amount of financial loss in many cases.
Question 5: A security professional overhears a conversation suggesting an imminent threat of workplace violence. Their primary obligation is to:
- Keep it confidential as it was an overheard conversation
- Immediately report the threat to appropriate authorities (Correct answer)
- Confront the individual directly to assess the threat personally
- Document the incident and review it at the next weekly meeting
Correct answer: Immediately report the threat to appropriate authorities
Imminent threats of violence must be immediately reported to appropriate authorities to fulfill the duty to warn and prevent harm.
Question 6: The principle of 'proportionality' in use-of-force policy requires that:
- Force must always match exactly what was used against the officer
- The level of force used must be appropriate to the level of threat faced (Correct answer)
- Equal force must be applied to all individuals regardless of context
- Force may be escalated preemptively to deter resistance
Correct answer: The level of force used must be appropriate to the level of threat faced
Proportionality requires that the force applied be commensurate with the threat posed, neither insufficient nor excessive.
Question 7: Which provision of HIPAA directly applies when security personnel access medical information during a workplace incident investigation?
- HIPAA Transactions Rule
- HIPAA Privacy Rule (Correct answer)
- HIPAA Enforcement Rule
- HIPAA Breach Notification Rule
Correct answer: HIPAA Privacy Rule
The HIPAA Privacy Rule governs who may access protected health information and under what circumstances, directly impacting security investigations.
When conducting a pre-employment background investigation, failure to obtain written authorization from the applicant violates which federal law?