CJIS SECURITY STUDY EXAMS GUIDE QUESTIONS
AND ANSWERS SURE A+
✔✔Access control - ✔✔The planning and implementation of mechanisms to restrict the
access, modification, and transmission of CJIS information.
✔✔Access Control Lists (ACLs) - ✔✔Registers of users and their permissions to access
specific system resources.
✔✔Resource Restrictions - ✔✔Prohibiting users from requesting information or
resources for which they do not have access.
✔✔Least privilege - ✔✔Granting individuals only the minimum access privileges
required to perform their official duties.
✔✔Separation of duties - ✔✔The division of roles and responsibilities to prevent
conflicts of interest and ensure accountability within an organization.
✔✔Screening Requirements - ✔✔The mandatory checks and procedures for vetting
individuals before granting them access to CJI.
✔✔National fingerprint-based records checks - ✔✔Background checks using fingerprint
records at the national level to assess an individual's criminal history.
, ✔✔Individual background re-investigations - ✔✔Periodic re-evaluations of an
individual's background and qualifications, typically conducted every five years.
✔✔Insider threat - ✔✔The risk posed to an organization's security by individuals within
the organization, such as employees or contractors, who have access to sensitive
information.
✔✔Access, Use, & Dissemination Penalties - ✔✔The consequences for unauthorized
requests, release, or discussion of CJI, including criminal prosecution and termination of
employment.
✔✔Personnel Sanctions - ✔✔Formal disciplinary measures for personnel failing to
comply with information security policies and procedures.
✔✔CJIS Security Addendum - ✔✔The CJIS Security Addendum is an additional
agreement to the contract between a criminal justice agency and a private contractor,
outlining security provisions and requirements for accessing CJI.
✔✔Access Control for Transmission Medium - ✔✔This refers to controlling physical
access to information system distribution and transmission lines within a physically
secure location, ensuring the security of CJI during transmission.
✔✔Visitor Control - ✔✔Visitor control involves authenticating visitors before granting
escorted access to physically secure locations, and monitoring their activity within these
areas.
✔✔Controlled Area - ✔✔A designated area, room, or storage container for accessing or
storing CJI, with specific security measures to prevent unauthorized access.
✔✔System Use Notification - ✔✔An approved message displayed by the information
system before granting access, informing users of usage and monitoring rules for the
system.
✔✔Session Lock - ✔✔An automatic lock, such as a screensaver with a password,
initiated after a period of inactivity to prevent unauthorized access to the system.
✔✔Identification - ✔✔Identification is a unique representation of an identity within an
information system, such as a User ID, ORI, or device identifier.
✔✔Authentication - ✔✔Authentication refers to processes to verify the identity of a user,
process, or device before allowing access to a system's resources, following FBI CJIS
Security Policy requirements.
AND ANSWERS SURE A+
✔✔Access control - ✔✔The planning and implementation of mechanisms to restrict the
access, modification, and transmission of CJIS information.
✔✔Access Control Lists (ACLs) - ✔✔Registers of users and their permissions to access
specific system resources.
✔✔Resource Restrictions - ✔✔Prohibiting users from requesting information or
resources for which they do not have access.
✔✔Least privilege - ✔✔Granting individuals only the minimum access privileges
required to perform their official duties.
✔✔Separation of duties - ✔✔The division of roles and responsibilities to prevent
conflicts of interest and ensure accountability within an organization.
✔✔Screening Requirements - ✔✔The mandatory checks and procedures for vetting
individuals before granting them access to CJI.
✔✔National fingerprint-based records checks - ✔✔Background checks using fingerprint
records at the national level to assess an individual's criminal history.
, ✔✔Individual background re-investigations - ✔✔Periodic re-evaluations of an
individual's background and qualifications, typically conducted every five years.
✔✔Insider threat - ✔✔The risk posed to an organization's security by individuals within
the organization, such as employees or contractors, who have access to sensitive
information.
✔✔Access, Use, & Dissemination Penalties - ✔✔The consequences for unauthorized
requests, release, or discussion of CJI, including criminal prosecution and termination of
employment.
✔✔Personnel Sanctions - ✔✔Formal disciplinary measures for personnel failing to
comply with information security policies and procedures.
✔✔CJIS Security Addendum - ✔✔The CJIS Security Addendum is an additional
agreement to the contract between a criminal justice agency and a private contractor,
outlining security provisions and requirements for accessing CJI.
✔✔Access Control for Transmission Medium - ✔✔This refers to controlling physical
access to information system distribution and transmission lines within a physically
secure location, ensuring the security of CJI during transmission.
✔✔Visitor Control - ✔✔Visitor control involves authenticating visitors before granting
escorted access to physically secure locations, and monitoring their activity within these
areas.
✔✔Controlled Area - ✔✔A designated area, room, or storage container for accessing or
storing CJI, with specific security measures to prevent unauthorized access.
✔✔System Use Notification - ✔✔An approved message displayed by the information
system before granting access, informing users of usage and monitoring rules for the
system.
✔✔Session Lock - ✔✔An automatic lock, such as a screensaver with a password,
initiated after a period of inactivity to prevent unauthorized access to the system.
✔✔Identification - ✔✔Identification is a unique representation of an identity within an
information system, such as a User ID, ORI, or device identifier.
✔✔Authentication - ✔✔Authentication refers to processes to verify the identity of a user,
process, or device before allowing access to a system's resources, following FBI CJIS
Security Policy requirements.