CFS Investigation Techniques & Ethics 3 — Questions and Answers
Question 1: An investigator uses social engineering to gain access to a suspect's computer files without authorization. This action is best described as:
- A legitimate covert investigation technique
- Ethically permissible if fraud is suspected
- An illegal and unethical method that violates privacy laws (Correct answer)
- Acceptable only with verbal management approval
Correct answer: An illegal and unethical method that violates privacy laws
Unauthorized access to computer files via social engineering violates computer fraud laws (e.g., CFAA) and professional ethics regardless of suspected wrongdoing.
Question 2: During a fraud examination, the investigator identifies multiple red flags but no direct evidence of fraud. The report should:
- Conclude fraud occurred based on the red flags
- Document the red flags and recommend further investigation (Correct answer)
- Dismiss the red flags as inconclusive and close the case
- Report the suspect to law enforcement immediately
Correct answer: Document the red flags and recommend further investigation
Red flags indicate risk but not proof; investigators should document findings and recommend additional steps rather than drawing unsupported conclusions.
Question 3: What is the primary purpose of conducting a background check on a fraud suspect during an investigation?
- To build a personal profile for social media monitoring
- To identify prior incidents, patterns, or undisclosed affiliations relevant to the case (Correct answer)
- To obtain character references for use in court
- To verify the suspect's employment history for HR purposes
Correct answer: To identify prior incidents, patterns, or undisclosed affiliations relevant to the case
Background checks help investigators identify prior fraud incidents, criminal history, conflicts of interest, or hidden business relationships relevant to the case.
Question 4: In fraud investigations, 'corroborating evidence' refers to:
- Evidence that directly proves the fraud occurred
- Additional evidence that supports or confirms other evidence already gathered (Correct answer)
- Testimony obtained from a co-conspirator
- Documents seized under a search warrant
Correct answer: Additional evidence that supports or confirms other evidence already gathered
Corroborating evidence independently supports or strengthens other evidence, increasing the overall reliability of the investigative findings.
Question 5: A fraud investigator is subpoenaed to testify about a confidential client investigation. The investigator's primary duty is to:
- Refuse to testify to protect client confidentiality
- Testify truthfully while asserting applicable privilege through legal counsel (Correct answer)
- Provide only information the client has pre-approved
- Decline testimony until the investigation is formally closed
Correct answer: Testify truthfully while asserting applicable privilege through legal counsel
When subpoenaed, investigators must testify truthfully; any applicable privilege (such as attorney-client) should be asserted by legal counsel, not through refusal to appear.
Question 6: Which of the following is an example of a 'predication' in a fraud investigation?
- A conclusion reached at the end of the investigation
- The factual basis or reasonable grounds that justify initiating a fraud examination (Correct answer)
- The financial impact calculation of identified fraud
- The formal accusation submitted to law enforcement
Correct answer: The factual basis or reasonable grounds that justify initiating a fraud examination
Predication is the totality of circumstances that would lead a reasonable, professionally trained person to believe fraud may have occurred, justifying an investigation.
Question 7: When conducting a fraud investigation involving digital evidence, hash values are used to:
- Encrypt sensitive documents before storage
- Verify that digital files have not been altered since collection (Correct answer)
- Compress large data sets for easier analysis
- Authenticate the identity of the investigator accessing files
Correct answer: Verify that digital files have not been altered since collection
Hash values (e.g., MD5, SHA-256) create a unique fingerprint of digital files, allowing investigators to prove files were not modified after collection.
An investigator uses social engineering to gain access to a suspect's computer files without authorization.
This action is best described as: