LEVEL 2 CJIS SECURITY TEST FINAL STUDY
PAPER 2026 COMPLETE QUESTIONS AND
ANSWERS
◉ Which of the following contains CHRI and is considered to be a
restricted file? Answer: National Sex Offender Registry Files
◉ Information system devices should be positioned so that anyone
can view them. Answer: false
◉ Which of the following individual user responsibilities is correct?
Answer: Users should face computer monitors away from outside
windows, doors, or hallways
◉ Security and Privacy Literacy Training must be taken at the
following time(s) Answer: All of these are correct
◉ Security incidents are always very obvious. Answer: false
◉ Multi-factor authentication requires the use of: Answer: Two or
more different factors to achieve authentication
,◉ Remote access may be permitted for privileged functions: Answer:
Only for compelling operational needs
◉ Access to controlled areas containing systems/components that
access CJI should be: Answer: limited to only those personnel
authorized by the agency to access or view CJI
◉ Unauthorized requests, receipt, release, interception,
dissemination, or discussion of CJI is serious and may result in:
Answer: All of these are correct
◉ The perimeter of the area requiring physical security should be
prominently posted. Answer: True
◉ If electronic media cannot be physically destroyed, it must be
_______ to prevent unauthorized access to previously stored data.
Answer: Overwritten at least three times
◉ The security principle of _______ is where individuals are granted
only the most restrictive set of access privileges required to perform
their official duties. Answer: Least privilege
◉ All training records must be kept current and be maintained for a
minimum of three years. Answer: True
, ◉ After the initial training, how often must Security and Privacy
Training be completed? Answer: Every year
◉ An example of a possible threat to security and privacy is a user
accidentally erasing a critical file while "playing" on the computer.
Answer: True
◉ Any incidents or unusual activity should be reported to your
agency contact, LASO, or Information Security Officer immediately.
Answer: True
◉ The FBI authorized originating agency identifier (ORI) must be
used in each transaction on CJIS systems. Answer: True
◉ Authorized criminal justice purposes for the use of CJI include:
Answer: All of these are correct
◉ A security incident is a violation of the CJIS Security Policy that
threatens the confidentiality, integrity, or availability of CJI. Answer:
True
◉ A commonly used type of social engineering is: Answer: All of
these are correct
PAPER 2026 COMPLETE QUESTIONS AND
ANSWERS
◉ Which of the following contains CHRI and is considered to be a
restricted file? Answer: National Sex Offender Registry Files
◉ Information system devices should be positioned so that anyone
can view them. Answer: false
◉ Which of the following individual user responsibilities is correct?
Answer: Users should face computer monitors away from outside
windows, doors, or hallways
◉ Security and Privacy Literacy Training must be taken at the
following time(s) Answer: All of these are correct
◉ Security incidents are always very obvious. Answer: false
◉ Multi-factor authentication requires the use of: Answer: Two or
more different factors to achieve authentication
,◉ Remote access may be permitted for privileged functions: Answer:
Only for compelling operational needs
◉ Access to controlled areas containing systems/components that
access CJI should be: Answer: limited to only those personnel
authorized by the agency to access or view CJI
◉ Unauthorized requests, receipt, release, interception,
dissemination, or discussion of CJI is serious and may result in:
Answer: All of these are correct
◉ The perimeter of the area requiring physical security should be
prominently posted. Answer: True
◉ If electronic media cannot be physically destroyed, it must be
_______ to prevent unauthorized access to previously stored data.
Answer: Overwritten at least three times
◉ The security principle of _______ is where individuals are granted
only the most restrictive set of access privileges required to perform
their official duties. Answer: Least privilege
◉ All training records must be kept current and be maintained for a
minimum of three years. Answer: True
, ◉ After the initial training, how often must Security and Privacy
Training be completed? Answer: Every year
◉ An example of a possible threat to security and privacy is a user
accidentally erasing a critical file while "playing" on the computer.
Answer: True
◉ Any incidents or unusual activity should be reported to your
agency contact, LASO, or Information Security Officer immediately.
Answer: True
◉ The FBI authorized originating agency identifier (ORI) must be
used in each transaction on CJIS systems. Answer: True
◉ Authorized criminal justice purposes for the use of CJI include:
Answer: All of these are correct
◉ A security incident is a violation of the CJIS Security Policy that
threatens the confidentiality, integrity, or availability of CJI. Answer:
True
◉ A commonly used type of social engineering is: Answer: All of
these are correct