2026 CJIS SECURITY 2
EXAM RESOURCE UPDATED
380 QUESTIONS BANK
WITH CORRECT ANSWERS
(EXAM-STYLE QUESTIONS & REVIEW)
What You'll Get:
• 380 questions
• quick review
• Printable, easy-to-study PDF
• Actual questions and correct answers
,Question 1.
Criminal Justice Information (CJI).
Correct Answer: Information related to criminal justice that must be secured
and protected
Question 2.
FBI CJIS Security Policy.
Correct Answer: Policy requiring completion of security and privacy training
before system access and annually thereafter
Question 3.
Literacy Training and Awareness.
Correct Answer: Understanding threats, vulnerabilities, and risks associated
with security and privacy
Question 4.
Access Control.
Correct Answer: Measures to restrict access to authorized personnel only
Question 5.
Physical Security.
Correct Answer: Measures to protect physical locations processing or storing CJI
Question 6.
System Security.
Correct Answer: Measures to protect information systems processing or storing
CJI
Question 7.
Incident Response.
Correct Answer: Procedures for responding to suspected security incidents
,Question 8.
Insider Threat.
Correct Answer: Security risk from personnel with access to sensitive
information
Question 9.
Social Engineering.
Correct Answer: Tricking individuals into revealing information or taking actions
to attack systems or networks
Question 10.
Phishing.
Correct Answer: Digital form of social engineering using authentic-looking
emails to trick users
Question 11.
Spear Phishing.
Correct Answer: Type of phishing targeting specific users or groups based on
their position
Question 12.
Pretexting and Impersonation.
Correct Answer: Creating a fictional backstory to manipulate someone into
providing private information
Question 13.
Baiting.
Correct Answer: Using a false promise to lure users into a trap, including
enticing ads leading to malicious sites
Question 14.
Tailgating.
Correct Answer: Unauthorized person manipulating their way into a restricted
area
, Question 15.
Shoulder Surfing.
Correct Answer: Unauthorized person standing near a user to obtain their
password or other data
Question 16.
Vulnerability.
Correct Answer: Any weakness in security procedures, technical controls, or
other controls that could be exploited by a security threat
Question 17.
Security Alerts and Advisories.
Correct Answer: Regular communication of system security alerts/advisories
and appropriate actions in response
Question 18.
CJIS Systems Agency (CSA).
Correct Answer: Agency responsible for establishing and administering an
information security program
Question 19.
CJIS Systems Officer (CSO).
Correct Answer: Individual responsible for administering the CJIS network within
the CSA
Question 20.
Information Security Officer (ISO).
Correct Answer: Security point-of- contact to the FBI CJIS Division responsible
for implementing security-related controls
Question 21.
Criminal Justice Agency (CJA).
Correct Answer: Governmental agency administering criminal justice pursuant
to a statute or executive order
EXAM RESOURCE UPDATED
380 QUESTIONS BANK
WITH CORRECT ANSWERS
(EXAM-STYLE QUESTIONS & REVIEW)
What You'll Get:
• 380 questions
• quick review
• Printable, easy-to-study PDF
• Actual questions and correct answers
,Question 1.
Criminal Justice Information (CJI).
Correct Answer: Information related to criminal justice that must be secured
and protected
Question 2.
FBI CJIS Security Policy.
Correct Answer: Policy requiring completion of security and privacy training
before system access and annually thereafter
Question 3.
Literacy Training and Awareness.
Correct Answer: Understanding threats, vulnerabilities, and risks associated
with security and privacy
Question 4.
Access Control.
Correct Answer: Measures to restrict access to authorized personnel only
Question 5.
Physical Security.
Correct Answer: Measures to protect physical locations processing or storing CJI
Question 6.
System Security.
Correct Answer: Measures to protect information systems processing or storing
CJI
Question 7.
Incident Response.
Correct Answer: Procedures for responding to suspected security incidents
,Question 8.
Insider Threat.
Correct Answer: Security risk from personnel with access to sensitive
information
Question 9.
Social Engineering.
Correct Answer: Tricking individuals into revealing information or taking actions
to attack systems or networks
Question 10.
Phishing.
Correct Answer: Digital form of social engineering using authentic-looking
emails to trick users
Question 11.
Spear Phishing.
Correct Answer: Type of phishing targeting specific users or groups based on
their position
Question 12.
Pretexting and Impersonation.
Correct Answer: Creating a fictional backstory to manipulate someone into
providing private information
Question 13.
Baiting.
Correct Answer: Using a false promise to lure users into a trap, including
enticing ads leading to malicious sites
Question 14.
Tailgating.
Correct Answer: Unauthorized person manipulating their way into a restricted
area
, Question 15.
Shoulder Surfing.
Correct Answer: Unauthorized person standing near a user to obtain their
password or other data
Question 16.
Vulnerability.
Correct Answer: Any weakness in security procedures, technical controls, or
other controls that could be exploited by a security threat
Question 17.
Security Alerts and Advisories.
Correct Answer: Regular communication of system security alerts/advisories
and appropriate actions in response
Question 18.
CJIS Systems Agency (CSA).
Correct Answer: Agency responsible for establishing and administering an
information security program
Question 19.
CJIS Systems Officer (CSO).
Correct Answer: Individual responsible for administering the CJIS network within
the CSA
Question 20.
Information Security Officer (ISO).
Correct Answer: Security point-of- contact to the FBI CJIS Division responsible
for implementing security-related controls
Question 21.
Criminal Justice Agency (CJA).
Correct Answer: Governmental agency administering criminal justice pursuant
to a statute or executive order