NCIC NCIC Cybersecurity & Digital Intelligence 1 — Questions and Answers
Question 1: What is open-source intelligence (OSINT) in the context of digital criminal investigations?
- Intelligence collected from classified government databases
- Information gathered from publicly available sources such as websites, social media, and public records (Correct answer)
- Intelligence gathered exclusively from confidential informants
- Data obtained through court-authorized wiretaps
Correct answer: Information gathered from publicly available sources such as websites, social media, and public records
OSINT refers to intelligence collected from publicly available sources including websites, social media platforms, news outlets, and public government records.
Question 2: What does 'metadata' refer to in the context of digital intelligence collection?
- The visible text content of a digital file
- Data that describes other data, such as creation date, author, geolocation, and device information (Correct answer)
- A type of malware used in cyberattacks against law enforcement
- An encrypted criminal records database
Correct answer: Data that describes other data, such as creation date, author, geolocation, and device information
Metadata is information about data, including creation timestamps, geolocation coordinates, device identifiers, and authorship details embedded in digital files.
Question 3: What is the 'dark web' as it relates to criminal intelligence analysis?
- Unlit sections of the internet during network outages
- Encrypted network layers not indexed by standard search engines, often used for illicit activities (Correct answer)
- Classified law enforcement intelligence databases
- Hacker forums accessible through standard web browsers
Correct answer: Encrypted network layers not indexed by standard search engines, often used for illicit activities
The dark web consists of encrypted, non-indexed network content accessible only through specialized tools like Tor, and is often associated with illicit marketplaces and communications.
Question 4: Which federal law primarily governs law enforcement access to electronic communications and stored digital data?
- The Freedom of Information Act (FOIA)
- The Electronic Communications Privacy Act (ECPA) (Correct answer)
- The Computer Fraud and Abuse Act (CFAA)
- The Homeland Security Act
Correct answer: The Electronic Communications Privacy Act (ECPA)
The Electronic Communications Privacy Act (ECPA) establishes the legal standards for law enforcement access to electronic communications and stored electronic data.
Question 5: What is a 'digital footprint' in the context of criminal investigations?
- Physical evidence of a computer device found at a crime scene
- The trail of data left by an individual's online activities across digital platforms (Correct answer)
- A suspect's fingerprint recovered from a digital device
- A law enforcement database record identifier
Correct answer: The trail of data left by an individual's online activities across digital platforms
A digital footprint is the collection of data traces left by an individual's online activities, including browsing history, social media posts, and transaction records.
Question 6: What is the primary challenge that end-to-end encryption presents for criminal intelligence collection?
- It makes digital evidence easier to process in the field
- It prevents unauthorized parties, including law enforcement, from accessing the content of intercepted communications (Correct answer)
- It automatically flags criminal communications for analyst review
- It ensures that digital evidence is automatically admissible in court
Correct answer: It prevents unauthorized parties, including law enforcement, from accessing the content of intercepted communications
End-to-end encryption ensures only communicating parties can access message content, creating a 'going dark' challenge for law enforcement attempting lawful interception.
What is open-source intelligence (OSINT) in the context of digital criminal investigations?