2025-2026 Exam 50 Questions with 100% Verified
Correct Answers Guaranteed A+
A commonly used type of social engineering is: - CORRECT ANSWER: All of these are
correct
A security incident is a violation of the CJIS Security Policy that threatens the
confidentiality, integrity, or availability of CJI. - CORRECT ANSWER: True
Access to and use of CJI and CHRI is for: - CORRECT ANSWER: Criminal justice
purposes and authorized noncriminal justice functions only
Access to controlled areas containing systems/components that access CJI should be: -
CORRECT ANSWER: limited to only those personnel authorized by the agency to
access or view CJI
After the initial training, how often must Security and Privacy Training be completed? -
CORRECT ANSWER: Every year
All training records must be kept current and be maintained for a minimum of three
years. - CORRECT ANSWER: True
An authentication factor is: - CORRECT ANSWER: All of these are correct
An example of a possible threat to security and privacy is a user accidentally erasing a
critical file while "playing" on the computer. - CORRECT ANSWER: True
Any incidents or unusual activity should be reported to your agency contact, LASO, or
Information Security Officer immediately. - CORRECT ANSWER: True
, Authorized criminal justice purposes for the use of CJI include: - CORRECT ANSWER:
All of these are correct
CJI can include which of the following types of data? - CORRECT ANSWER: All of
these are correct
Encryption is: - CORRECT ANSWER: The process of converting information or data into
a code to prevent unauthorized access
For personnel with access to CJI, screening requirements must include _______ and
_______ record checks. - CORRECT ANSWER: State of residency; National fingerprint-
based
If electronic media cannot be physically destroyed, it must be _______ to prevent
unauthorized access to previously stored data. - CORRECT ANSWER: Overwritten at
least three times
Information system devices should be positioned so that anyone can view them. -
CORRECT ANSWER: false
Multi-factor authentication requires the use of: - CORRECT ANSWER: Two or more
different factors to achieve authentication
Remote access may be permitted for privileged functions: - CORRECT ANSWER: Only
for compelling operational needs
Security and Privacy Literacy Training must be taken at the following time(s) -
CORRECT ANSWER: All of these are correct
Security incidents are always very obvious. - CORRECT ANSWER: false