ACTUAL EXAM 2026/2027 | CJIS
Security Policy & Operating Manuals |
Comprehensive Practice Test | Verified
Q&A | Pass Guaranteed - A+ Graded
SECTION 1: FCIC/NCIC SYSTEM OVERVIEW &
ADMINISTRATION (Questions 1-20)
Q1: Which federal agency serves as the national administrator for the National Crime
Information Center (NCIC)?
A. Florida Department of Law Enforcement (FDLE)
B. Federal Bureau of Investigation (FBI) [CORRECT]
C. Department of Homeland Security (DHS)
D. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF)
Correct Answer: B
Rationale: The FBI's Criminal Justice Information Services (CJIS) Division in Clarksburg, West
Virginia, serves as the national administrator for NCIC. FDLE administers FCIC at the state
level. This hierarchical structure ensures national standardization while allowing state-level
customization per NCIC 2000 Operating Manual, Introduction Section.
Q2: What is the primary distinction between FCIC and NCIC regarding jurisdictional scope?
A. FCIC contains only Florida records; NCIC contains only federal records
B. FCIC contains Florida and some neighboring state records; NCIC contains national records
C. FCIC contains Florida-specific records; NCIC contains records from all 50 states,
territories, and federal agencies [CORRECT]
,D. FCIC is for criminal records only; NCIC is for civil records only
Correct Answer: C
Rationale: FCIC (Florida Crime Information Center) maintains statewide Florida criminal
justice information, while NCIC maintains nationwide data accessible to all participating
criminal justice agencies. FCIC serves as Florida's interface with NCIC, per FDLE FCIC User
Agreement, Section 1.2.
Q3: Under CJIS Security Policy, what is the minimum background investigation requirement
for terminal operators with access to FCIC/NCIC?
A. Local police background check only
B. FDLE Level 1 background screening
C. FBI fingerprint-based criminal history check (CHRI access) and state repository check
[CORRECT]
D. Self-certification by employing agency
Correct Answer: C
Rationale: CJIS Security Policy Version 5.9.2, Section 4.1 requires fingerprint-based criminal
history record information (CHRI) checks for all personnel with access to CJI (Criminal
Justice Information). This includes national FBI checks and state repository checks.
Rap-back services must be implemented for ongoing monitoring.
Q4: What constitutes a "criminal justice agency" for FCIC/NCIC access purposes?
A. Any government agency with law enforcement personnel
B. Courts, law enforcement agencies, and corrections agencies with primary criminal justice
mission [CORRECT]
C. Private security companies with state licenses
D. All state and local government agencies
Correct Answer: B
Rationale: Per CJIS Security Policy Section 1.3, a criminal justice agency is defined as a
court, law enforcement agency, or corrections agency with a primary mission of criminal
,justice administration. Private entities, even with licensing, do not qualify for direct access
without specific statutory authority.
Q5: What is the "terminal agency coordinator" (TAC) responsible for?
A. Only technical troubleshooting of terminals
B. Agency-level administration, user certification, security compliance, and liaison with CJIS
systems [CORRECT]
C. Making arrests based on NCIC hits
D. Writing state legislation on information systems
Correct Answer: B
Rationale: The TAC serves as the agency's primary point of contact for CJIS matters,
overseeing user certification, security policy compliance, audit responses, and personnel
security per CJIS Security Policy Section 5.1.4. TACs are critical to maintaining agency
compliance.
Q6: Which of the following agencies would NOT qualify for direct FCIC/NCIC access under
standard CJIS policies?
A. Municipal police department
B. State attorney's office
C. Licensed private investigative agency without criminal justice statutory authority
[CORRECT]
D. County sheriff's office
Correct Answer: C
Rationale: Private entities, including licensed private investigators, lack criminal justice
agency status under CJIS Security Policy Section 1.3. They may receive information
secondarily through criminal justice agencies but cannot access FCIC/NCIC directly without
specific federal statutory authorization (e.g., certain airport security or nuclear facility
personnel).
Q7: What is the "need-to-know" standard as applied to FCIC/NCIC information?
, A. Information can be shared with any law enforcement officer
B. Information can only be accessed when necessary for the performance of official criminal
justice duties [CORRECT]
C. Information can be shared with the media if it helps solve crimes
D. Information is available to all government employees
Correct Answer: B
Rationale: The need-to-know standard, per CJIS Security Policy Section 4.2, restricts access
to CJI to that which is necessary for the performance of official criminal justice duties. This
is a fundamental security principle limiting access to authorized personnel performing
specific functions.
Q8: What sanction may CJIS impose for serious FCIC/NCIC system misuse?
A. Verbal warning only
B. Fines up to $10,000
C. Withdrawal of access privileges for individual users or entire agencies [CORRECT]
D. Mandatory retirement of the TAC
Correct Answer: C
Rationale: Per CJIS Security Policy Section 5.10, sanctions for non-compliance range from
technical assistance and corrective action plans to withdrawal of access privileges for
individual users or entire agencies. This is the most severe administrative sanction available
to CJIS.
Q9: How long must audit logs of FCIC/NCIC transactions be retained?
A. 30 days
B. 90 days
C. Minimum one year; some states require longer [CORRECT]
D. Permanently
Correct Answer: C