← All ACE Flashcard Decks

Industry Regulations & Compliance Flashcards

7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Industry Regulations & Compliance flashcards as text
  1. Which provision of the USA PATRIOT Act most directly expanded law enforcement's ability to conduct surveillance and obtain records relevant to digital forensic investigations?

    Answer: Section 215 — business records and tangible things

    Section 215 of the PATRIOT Act authorized the FBI to compel production of 'any tangible thing' including business records relevant to foreign intelligence or terrorism investigations.

  2. When an ACE-certified examiner testifies as an expert witness, Federal Rule of Evidence 702 requires that expert testimony be based on sufficient facts and that the methodology be:

    Answer: The product of reliable principles reliably applied to the facts

    FRE 702 (codifying Daubert) requires expert testimony to be based on sufficient facts, reliable methodology, and reliable application of that methodology to the case facts.

  3. Under ISO/IEC 27037:2012, what is the correct sequence of actions when handling digital evidence at a scene?

    Answer: Identify, collect, acquire, preserve

    ISO/IEC 27037 specifies that digital evidence handling follows the sequence: identify, collect, acquire (create forensic image), and preserve the integrity of evidence.

  4. Which U.S. regulation requires financial institutions to file a Suspicious Activity Report (SAR) within 30 days of detecting a transaction that may involve money laundering, and is relevant when forensic findings reveal illicit financial flows?

    Answer: Bank Secrecy Act (BSA) / FinCEN regulations

    The Bank Secrecy Act, enforced through FinCEN regulations, requires financial institutions to file SARs within 30 days of detecting suspicious transactions that may involve money laundering or other crimes.

  5. A forensic examiner in a state with mandatory data breach notification laws discovers a breach involving Social Security numbers. In most U.S. states, the notification obligation is typically triggered when:

    Answer: Unauthorized acquisition of unencrypted personal information is reasonably believed to have occurred

    Most state breach notification laws trigger the notification duty when there is reasonable belief that unencrypted personal information was acquired without authorization, regardless of the number of individuals affected.

  6. Under the Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, what must a defense contractor do within 72 hours of discovering a cyber incident affecting covered defense information (CDI)?

    Answer: Report the incident to the DoD via the DIBNet portal

    DFARS 252.204-7012 requires defense contractors to report cyber incidents affecting CDI to the DoD within 72 hours through the DIBNet portal at dibnet.dod.mil.

  7. When a forensic investigation reveals evidence of a crime during a civil case (e.g., child exploitation material found during a corporate HR investigation), what is the examiner's primary legal and ethical obligation?

    Answer: Immediately stop the examination and report to law enforcement per mandatory reporting laws

    Discovery of child exploitation material (CSAM) triggers mandatory reporting obligations under 18 U.S.C. § 2258A, requiring immediate reporting to NCMEC regardless of the civil case context.