FBI FBI Cybercrime and Digital Forensics 1 — Questions and Answers
Question 1: What FBI division is primarily responsible for investigating cyber intrusions and cybercrime?
- Criminal Investigative Division
- Cyber Division (Correct answer)
- Counterterrorism Division
- Counterintelligence Division
Correct answer: Cyber Division
The FBI's Cyber Division leads the Bureau's investigations into computer intrusions, ransomware, online fraud, and other cyber threats to U.S. systems and critical infrastructure.
Question 2: What is the Computer Fraud and Abuse Act (CFAA) and why is it relevant to FBI cyber investigations?
- A policy governing FBI computer usage in field offices
- The primary federal statute criminalizing unauthorized access to computers and computer-facilitated fraud (Correct answer)
- A data sharing agreement between the FBI and NSA
- A classification framework for cyber threat intelligence
Correct answer: The primary federal statute criminalizing unauthorized access to computers and computer-facilitated fraud
The CFAA (18 U.S.C. § 1030) is the primary federal law the FBI uses to prosecute unauthorized access to computer systems, data theft, and computer-facilitated crimes.
Question 3: What type of cyber threat involves criminals encrypting a victim's data and demanding payment for the decryption key?
- Phishing attack
- Ransomware attack (Correct answer)
- Man-in-the-middle attack
- SQL injection attack
Correct answer: Ransomware attack
Ransomware is a type of malware that encrypts victim files and demands a ransom — typically in cryptocurrency — in exchange for the decryption key to restore access.
Question 4: What is 'digital forensics' in the context of FBI investigations?
- Analyzing social media for investigative leads
- The collection, preservation, analysis, and presentation of digital evidence in a legally sound manner (Correct answer)
- Remote network monitoring of suspects
- The creation of digital evidence databases for court use
Correct answer: The collection, preservation, analysis, and presentation of digital evidence in a legally sound manner
Digital forensics involves the scientific examination of digital devices and data — following strict protocols to preserve evidence integrity — to support criminal or civil investigations.
Question 5: What is a 'preservation letter' in FBI cyber investigations?
- A classification document for cyber intelligence
- A formal request to an internet service provider to preserve electronic records pending a legal process (Correct answer)
- A court order to freeze a suspect's cryptocurrency wallet
- A memo documenting the chain of custody for seized digital devices
Correct answer: A formal request to an internet service provider to preserve electronic records pending a legal process
Under 18 U.S.C. § 2703(f), the FBI can request that internet service providers preserve stored electronic records for 90 days (renewable) while formal legal process is obtained.
Question 6: What does the acronym 'IOC' stand for in FBI cyber threat intelligence?
- International Operations Center
- Indicator of Compromise (Correct answer)
- Internet Operations Codebase
- Intrusion Oversight Committee
Correct answer: Indicator of Compromise
An Indicator of Compromise (IOC) is a piece of forensic data — such as a malicious IP address, file hash, or domain — that indicates a computer system may have been breached.
What FBI division is primarily responsible for investigating cyber intrusions and cybercrime?