Treasury Enforcement Agent Exam Technology & Digital Applications 4 — Questions and Answers
Question 1: An agent reviewing wire transfer records notices transactions routed through multiple correspondent banks across different countries. This technique is known as:
- Layering in a money laundering scheme (Correct answer)
- Currency arbitrage for profit
- Legitimate trade finance structuring
- Hawala informal transfer
Correct answer: Layering in a money laundering scheme
Layering is the second stage of money laundering, where funds are moved through complex transactions to distance them from their illegal origin.
Question 2: What does OSINT stand for, and how is it used by Treasury Enforcement Agents?
- Operational Security Intelligence Network Training
- Open Source Intelligence—gathering information from publicly available sources for investigative leads (Correct answer)
- Official Secret Information Network Tracking
- Online Surveillance and Interception Technology
Correct answer: Open Source Intelligence—gathering information from publicly available sources for investigative leads
OSINT involves collecting investigative information from public sources such as social media, court records, and news to build cases without legal process.
Question 3: A suspect uses encrypted messaging applications to coordinate financial crimes. Under what legal authority can agents potentially access message content?
- Agents can always access encrypted messages with badge authority
- A Title III wiretap order issued by a federal judge for real-time intercepts, or a warrant for stored content (Correct answer)
- A grand jury subpoena to the messaging app is always sufficient
- Encryption legally prohibits any government access under the Fourth Amendment
Correct answer: A Title III wiretap order issued by a federal judge for real-time intercepts, or a warrant for stored content
Title III authorizes real-time interception with court approval, while stored message content requires a warrant; both require judicial oversight.
Question 4: Which of the following best describes a 'hash value' in digital forensics?
- A password used to encrypt a forensic image
- A unique numerical fingerprint generated from digital data used to verify file integrity (Correct answer)
- The file size of a piece of digital evidence
- A timestamp embedded in a document's properties
Correct answer: A unique numerical fingerprint generated from digital data used to verify file integrity
A cryptographic hash (e.g., MD5 or SHA-256) produces a unique value for a file; any alteration changes the hash, proving the evidence was not tampered with.
Question 5: When a Treasury agent wants to track the financial activity of a known criminal organization, which automated system links financial reports filed under the Bank Secrecy Act?
- Interpol's I-24/7 gateway
- FinCEN's FINCEN 314(b) information sharing program and analytical databases (Correct answer)
- The FBI's Sentinel case management system
- IRS e-Services tax transcript portal
Correct answer: FinCEN's FINCEN 314(b) information sharing program and analytical databases
FinCEN's databases aggregate BSA filings and allow investigators to identify financial networks linked to criminal organizations.
Question 6: An agent discovers that a suspect has deleted financial records from a computer. What forensic reality is most relevant to recovering this evidence?
- Deleted files are permanently unrecoverable once removed from the recycle bin
- Deleted files often remain on the drive until overwritten and can frequently be recovered with forensic tools (Correct answer)
- Formatting a hard drive completely destroys all data beyond recovery
- Only files deleted within 24 hours can be recovered forensically
Correct answer: Deleted files often remain on the drive until overwritten and can frequently be recovered with forensic tools
Deletion typically removes only the file pointer; the actual data remains on the storage medium until new data overwrites it, enabling forensic recovery.
Question 7: What is 'spear phishing' and why is it a particular concern in attacks targeting financial institutions or government agencies?
- A generic mass-email attack sent to millions of random recipients
- A targeted phishing attack using personalized details about the victim to increase credibility and success rates (Correct answer)
- A phishing attack that uses voice calls rather than email
- A cyberattack that exploits vulnerabilities in financial transaction protocols
Correct answer: A targeted phishing attack using personalized details about the victim to increase credibility and success rates
Spear phishing uses victim-specific information to craft convincing deceptive messages, making it far more effective against high-value targets than generic phishing.
An agent reviewing wire transfer records notices transactions routed through multiple correspondent banks across different countries.
This technique is known as: