CSI® Certified Security Investigator — Questions and Answers
Question 1: When documenting an interview, which practice best preserves evidential integrity?
- Omitting emotional outbursts as irrelevant to the investigation
- Recording verbatim statements and noting any spontaneous admissions immediately (Correct answer)
- Paraphrasing responses to make the report easier to read
- Summarizing the interview from memory at the end of the workday
Correct answer: Recording verbatim statements and noting any spontaneous admissions immediately
Verbatim documentation of key statements and real-time notes ensure accuracy and admissibility in subsequent proceedings.
Question 2: When packaging physical evidence, why should each item be placed in a separate container?
- To comply with fire safety regulations for evidence storage
- To prevent cross-contamination between evidence items (Correct answer)
- To reduce the total weight of the evidence package
- To make evidence easier to photograph at the lab
Correct answer: To prevent cross-contamination between evidence items
Separate packaging prevents trace materials from one item contaminating another, which could compromise forensic analysis.
Question 3: During an overt investigation, a CSI is interviewing a potentially hostile witness. Which technique is most appropriate?
- Conduct the interview in a police station to create authority
- Record the interview secretly to capture authentic responses
- Use the cognitive interview technique to enhance recall without coercion (Correct answer)
- Threaten legal consequences if the witness refuses to cooperate
Correct answer: Use the cognitive interview technique to enhance recall without coercion
The cognitive interview technique uses memory-enhancing strategies (mental reinstatement, context recall) that are ethical, non-coercive, and effective with resistant witnesses.
Question 4: In digital forensics, what does the term 'anti-forensics' refer to?
- Techniques used by investigators to detect hidden evidence
- Legal defenses challenging the admissibility of digital evidence
- Methods suspects use to destroy, hide, or obfuscate digital evidence (Correct answer)
- The process of verifying forensic tool accuracy
Correct answer: Methods suspects use to destroy, hide, or obfuscate digital evidence
Anti-forensics encompasses techniques like data wiping, encryption, timestomping, and steganography used to hinder forensic investigations.
Question 5: What is the purpose of conducting a 'memory dump' (RAM capture) during a live forensic investigation?
- To create a backup copy of the hard drive before shutdown
- To analyze the Windows event logs stored in system memory
- To verify the integrity of installed operating system files
- To capture running processes, encryption keys, passwords, and network connections that exist only in volatile memory (Correct answer)
Correct answer: To capture running processes, encryption keys, passwords, and network connections that exist only in volatile memory
RAM captures volatile artifacts like running processes, decrypted data, active connections, and credentials that are lost when the system powers off.
Question 6: Why is regular risk assessment crucial for security teams?
- It is needed only during audits
- It helps to adapt and improve risk management strategies (Correct answer)
- It focuses only on financial performance
- It reduces the need for security training
Correct answer: It helps to adapt and improve risk management strategies
The threat landscape is dynamic, and an organization's vulnerabilities can change over time due to new technologies, business processes, or external factors. Regular risk assessments provide security teams with up-to-date information on their risk profile, allowing them to evaluate the effectiveness of current strategies and make necessary adjustments. This continuous feedback loop ensures that risk management remains agile and responsive to evolving challenges.
Question 7: When conducting a covert surveillance operation, what is the PRIMARY purpose of establishing a 'cover story' or legend?
- To provide the investigator with a plausible explanation for their presence if questioned (Correct answer)
- To satisfy legal requirements for undercover operations
- To deceive the subject into revealing information voluntarily
- To document the investigator's identity for court records
Correct answer: To provide the investigator with a plausible explanation for their presence if questioned
A cover story or legend gives the investigator a credible explanation for their presence or identity if they are unexpectedly confronted or questioned.
Question 8: Which of the following best describes 'locard's exchange principle' and its relevance to evidence collection?
- Evidence must be exchanged between jurisdictions when multiple agencies are involved
- Investigators must exchange findings with defense counsel before proceedings
- Every contact leaves a trace, meaning physical evidence is often transferred between a subject and a scene (Correct answer)
- Physical contact with evidence must be minimized to prevent trace loss
Correct answer: Every contact leaves a trace, meaning physical evidence is often transferred between a subject and a scene
Locard's Exchange Principle holds that any physical interaction leaves microscopic evidence behind, forming the scientific basis for trace evidence collection.
Question 9: When an emergency action plan includes a 'lockdown' procedure, employees should be trained to:
- Evacuate immediately using the nearest exit when a lockdown is announced
- Congregate in the lobby for headcount before lockdown is verified
- Call 911 only after the lockdown has been confirmed by management
- Secure doors, turn off lights, stay away from windows, and silence mobile devices (Correct answer)
Correct answer: Secure doors, turn off lights, stay away from windows, and silence mobile devices
Lockdown procedures require employees to secure their space, reduce visibility, silence noise sources, and remain in place until an all-clear is issued by authorities.
Question 10: A CSI professional encounters an unfamiliar situation while performing covert & overt investigation methods duties. What is the most appropriate first action?
- Proceed based on general assumptions to avoid delays
- Apply a solution from an unrelated field without verification
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Skip the task entirely and move to the next assignment
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in covert & overt investigation methods, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 11: When documenting a scene sketch, which information is mandatory to include?
- Names and addresses of all potential suspects
- Weather conditions at the time of the incident
- Scale or legend, north arrow, date, and case number (Correct answer)
- Investigator's personal opinion of what occurred
Correct answer: Scale or legend, north arrow, date, and case number
Scale, legend, north arrow, date, and case number are required elements that make a scene sketch legally valid and reproducible.
Question 12: Which of the following network logs would be MOST useful for identifying unauthorized lateral movement within a corporate network?
- Internal firewall and router flow logs (Correct answer)
- DHCP lease logs
- Public DNS query logs
- Email gateway spam filter logs
Correct answer: Internal firewall and router flow logs
Internal firewall and router flow logs capture traffic between internal segments, making lateral movement patterns visible.
Question 13: A CSI professional encounters an unfamiliar situation while performing electronic surveillance systems duties. What is the most appropriate first action?
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Proceed based on general assumptions to avoid delays
- Apply a solution from an unrelated field without verification
- Skip the task entirely and move to the next assignment
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in electronic surveillance systems, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 14: The 'all-hazards' approach to emergency planning is best described as:
- Conducting annual hazard surveys for OSHA compliance
- Developing core response capabilities applicable across multiple types of emergencies (Correct answer)
- Planning separately for each specific type of hazard
- Prioritizing natural disasters over man-made threats
Correct answer: Developing core response capabilities applicable across multiple types of emergencies
The all-hazards approach builds common core capabilities—communications, evacuation, command—that apply regardless of the specific emergency type.
Question 15: Which best describes a 'mandatory vacation' policy as a security control?
- It allows auditing of an employee's activities during their absence to detect fraud (Correct answer)
- It improves employee wellness and reduces turnover
- It complies with labor law requirements for paid time off
- It ensures workload is evenly distributed among the team
Correct answer: It allows auditing of an employee's activities during their absence to detect fraud
Mandatory vacation forces employees away from their duties temporarily, creating an opportunity to audit their work and detect concealed fraud or policy violations.
Question 16: Which cyber attack technique involves an adversary sending crafted packets to determine which ports are open on a target system before an intrusion?
- Credential stuffing
- SQL injection probing
- ARP poisoning
- Port scanning/reconnaissance (Correct answer)
Correct answer: Port scanning/reconnaissance
Port scanning identifies open ports and services on a target, giving attackers a map of potential entry points before launching an intrusion.
Question 17: The term 'point of distribution' (POD) in emergency management refers to:
- A facility's main entry point used during controlled evacuations
- A communication relay station for field responders
- A location where incident commanders receive briefings
- A pre-designated site where emergency supplies or services are dispensed to the public (Correct answer)
Correct answer: A pre-designated site where emergency supplies or services are dispensed to the public
A POD is a pre-planned location where commodities such as water, food, or medications are distributed to affected community members following a disaster.
Question 18: When a suspect's smartphone is seized, what is the FIRST step an investigator should take to preserve its digital evidence?
- Place it in airplane mode or a Faraday bag to prevent remote wiping (Correct answer)
- Immediately connect it to a forensic workstation
- Remove the SIM card and battery
- Attempt to unlock it using common PIN guesses
Correct answer: Place it in airplane mode or a Faraday bag to prevent remote wiping
Isolating the device from networks prevents remote wipe commands and preserves the current state of all data.
Question 19: What is the primary legal concern when conducting covert video surveillance in a workplace?
- Camera resolution requirements
- Federal licensing for recording equipment
- Employee expectation of privacy in certain areas (Correct answer)
- Mandatory union notification periods
Correct answer: Employee expectation of privacy in certain areas
Employees retain an expectation of privacy in areas such as restrooms and locker rooms, and covert surveillance in these areas is illegal regardless of employer authorization.
Question 20: When conducting a witness interview, a security investigator should primarily:
- Record only information that supports the initial theory
- Suggest likely answers to speed up the process
- Conduct the interview in a group setting for efficiency
- Listen actively and avoid interrupting the witness narrative (Correct answer)
Correct answer: Listen actively and avoid interrupting the witness narrative
Active listening without interruption ensures witnesses provide complete, uncontaminated accounts.
Question 21: Which of the following best describes a 'Man-in-the-Middle' (MitM) attack in the context of a digital investigation?
- Social engineering an employee to reveal their credentials
- Deploying ransomware that encrypts all network shares simultaneously
- An attacker who physically intercepts mail between two parties
- An adversary who secretly intercepts and potentially alters communications between two parties (Correct answer)
Correct answer: An adversary who secretly intercepts and potentially alters communications between two parties
In a MitM attack, the adversary positions themselves between two communicating parties to intercept, read, or modify data in transit.
Question 22: When documenting findings from a vulnerability assessment, why is it important to establish a clear chain of custody for the assessment data?
- To ensure the integrity and admissibility of findings if legal action arises (Correct answer)
- To meet IRS reporting requirements for security expenditures
- To speed up the process of implementing countermeasures
- To allow marketing teams access to facility security data
Correct answer: To ensure the integrity and admissibility of findings if legal action arises
Maintaining chain of custody for assessment data protects its integrity and ensures findings remain admissible as evidence if the matter proceeds to legal or regulatory action.
Question 23: During a corporate data breach investigation, investigators identify exfiltration via DNS tunneling. What characteristic best identifies DNS tunneling activity in log analysis?
- Abnormally long or high-frequency DNS queries to a single external domain (Correct answer)
- Multiple failed authentication attempts on the VPN gateway
- Large ICMP packet sizes from internal workstations
- Unusually large number of HTTPS GET requests to known CDNs
Correct answer: Abnormally long or high-frequency DNS queries to a single external domain
DNS tunneling encodes data inside DNS queries, resulting in unusually long subdomains or an abnormally high volume of queries to one domain.
Question 24: Which threat category encompasses acts of nature such as floods, earthquakes, and hurricanes?
- Accidental threats
- Adversarial threats
- Structural threats
- Environmental threats (Correct answer)
Correct answer: Environmental threats
Environmental threats include natural disasters and acts of nature that can impact organizational security.
Question 25: A security investigator is performing an assessment at a financial institution. Which tool is MOST useful for systematically identifying and prioritizing asset vulnerabilities?
- Gantt chart
- Flow diagram
- Risk matrix (Correct answer)
- SWOT analysis
Correct answer: Risk matrix
A risk matrix allows investigators to systematically assess and prioritize vulnerabilities by plotting the likelihood of a threat against its potential impact.
Question 26: Under OSHA's Emergency Action Plan standard (29 CFR 1910.38), which of the following elements is REQUIRED?
- A list of all hazardous materials on-site
- Procedures for reporting fires and other emergencies (Correct answer)
- Monthly fire drill schedules
- A budget for emergency supplies
Correct answer: Procedures for reporting fires and other emergencies
OSHA 29 CFR 1910.38 mandates procedures for reporting fires and other emergencies as a core required element of every Emergency Action Plan.
Question 27: A CSI professional encounters an unfamiliar situation while performing incident report writing duties. What is the most appropriate first action?
- Apply a solution from an unrelated field without verification
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Skip the task entirely and move to the next assignment
- Proceed based on general assumptions to avoid delays
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in incident report writing, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 28: Why is chain of custody important in handling digital evidence?
- It only applies to physical evidence
- It is not required for digital evidence
- It maintains the integrity of the evidence for legal purposes (Correct answer)
- It is irrelevant once the evidence is secured
Correct answer: It maintains the integrity of the evidence for legal purposes
Chain of custody is a meticulously documented process that tracks the handling, storage, and transfer of evidence from the moment it is collected until it is presented in court. For digital evidence, this unbroken record proves that the evidence has not been tampered with or altered, ensuring its authenticity and reliability. Without a proper chain of custody, digital evidence can be challenged and deemed inadmissible in legal proceedings.
Question 29: What is the purpose of a hash function in information security?
- To compress files for efficient storage and transmission
- To encrypt data so it can be decrypted later with a key
- To generate random encryption keys for symmetric algorithms
- To produce a fixed-size digest that verifies data integrity (Correct answer)
Correct answer: To produce a fixed-size digest that verifies data integrity
Hash functions produce a fixed-length output (digest) from input data; any change to the input produces a different hash, verifying integrity.
Question 30: How does encryption impact the handling of digital evidence?
- It is irrelevant for forensic investigations
- It helps secure sensitive data but can complicate analysis (Correct answer)
- It prevents data from being accessed during investigations
- It makes digital evidence easier to handle
Correct answer: It helps secure sensitive data but can complicate analysis
Encryption is vital for protecting sensitive digital evidence from unauthorized access, thereby maintaining data confidentiality and integrity. However, during a forensic investigation, encrypted data presents a significant challenge as investigators must obtain the correct decryption keys or methods to access and analyze the content. Without proper decryption, the evidence remains inaccessible, potentially hindering the investigation.
Question 31: Which analytical method is used in loss prevention to categorize inventory by value to prioritize security resources?
- Gap analysis
- SWOT analysis
- Root cause analysis
- ABC analysis (Correct answer)
Correct answer: ABC analysis
ABC analysis categorizes inventory into A (high-value, low-quantity), B (moderate value/quantity), and C (low-value, high-quantity) tiers, helping direct security resources toward the most valuable items.
Question 32: A security officer working at a shopping mall fails to respond to a report of a wet floor, and a patron slips and is injured. The mall is most likely liable under which legal theory?
- Strict liability
- Respondeat superior for intentional torts
- Premises liability / negligence (Correct answer)
- Vicarious criminal liability
Correct answer: Premises liability / negligence
Premises liability holds property owners and their agents responsible for negligently maintaining safe conditions for invitees.
Question 33: According to FEMA's 'Whole Community' approach to emergency management, which group is considered a key partner in preparedness planning?
- Federal agencies only
- Certified security professionals and law enforcement only
- Private sector, NGOs, faith-based organizations, and the public (Correct answer)
- State and local government entities exclusively
Correct answer: Private sector, NGOs, faith-based organizations, and the public
FEMA's Whole Community approach recognizes that effective emergency management requires engagement with the full range of community stakeholders including private sector, nonprofits, and the public.
Question 34: A pen register is a device that records:
- Email content and attachments
- The numbers dialed from a telephone (Correct answer)
- GPS coordinates of a mobile device
- The content of telephone calls
Correct answer: The numbers dialed from a telephone
A pen register captures outgoing phone numbers dialed from a target telephone without recording the content of the calls themselves.
Question 35: When documenting activities related to emergency action planning, which practice is considered essential for CSI certification holders?
- Recording only outcomes while omitting the methods and processes used
- Keeping documentation in personal notes that are not accessible to other team members
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Completing documentation only when requested by auditors or supervisors
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in emergency action planning. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 36: An employee claims they were unaware of a security policy they violated. The strongest organizational defense is to demonstrate:
- That the policy was emailed to all staff at some point in the past
- That the policy was posted on an internal website accessible to all
- That other employees know about the policy
- Signed acknowledgment records showing the employee received, read, and understood the policy (Correct answer)
Correct answer: Signed acknowledgment records showing the employee received, read, and understood the policy
Signed acknowledgment records provide documented proof that an individual was informed of and understood a specific policy, making the 'unawareness' defense untenable.
Question 37: What is a 'cognitive load' indicator during an interview, and why is it significant?
- The number of follow-up questions needed to clarify a statement
- The subject's ability to recall facts quickly without effort
- A measure of the interviewer's workload during complex cases
- Signs of mental effort that may indicate fabrication of a story (Correct answer)
Correct answer: Signs of mental effort that may indicate fabrication of a story
Increased cognitive load — shown by pauses, slower speech, or requests for repetition — can indicate a subject is constructing rather than recalling a story.
Question 38: Which method is used to preserve digital evidence found on a computer without altering the original data?
- Copying files to a USB drive for analysis
- Rebooting the computer and capturing startup logs
- Printing all documents found on the device
- Creating a forensic bit-for-bit image of the storage media (Correct answer)
Correct answer: Creating a forensic bit-for-bit image of the storage media
A forensic image duplicates every bit of the storage media, preserving all data including deleted files and metadata without modifying the original.
Question 39: An investigator notices a surveillance camera with a very narrow field of view but extreme detail at long range. This is most likely equipped with a:
- Wide-angle lens
- Varifocal lens
- Fisheye lens
- Telephoto lens (Correct answer)
Correct answer: Telephoto lens
Telephoto lenses have long focal lengths that magnify distant subjects while narrowing the field of view, ideal for long-range detail capture.
Question 40: When developing an Emergency Action Plan for a multi-tenant building, the security investigator should FIRST:
- Conduct a tabletop exercise with senior leadership
- Install new fire suppression systems
- Coordinate with building management and other tenants to avoid conflicting procedures (Correct answer)
- Publish the plan on the company intranet
Correct answer: Coordinate with building management and other tenants to avoid conflicting procedures
Coordination with building management and co-tenants is essential first to ensure evacuation routes, assembly points, and alarm systems are compatible and non-conflicting.
Question 41: What is the primary ethical obligation of a CSI professional when a conflict of interest arises during emergency action planning activities?
- Resolve the conflict privately without informing stakeholders
- Disclose the conflict to all relevant parties and recuse from the decision if necessary (Correct answer)
- Ignore the conflict if it does not directly affect the current task
- Proceed while favoring the outcome that benefits the professional personally
Correct answer: Disclose the conflict to all relevant parties and recuse from the decision if necessary
The primary ethical obligation when a conflict of interest arises in emergency action planning is to disclose it to all relevant parties and, if necessary, recuse from the decision. This maintains professional integrity and stakeholder trust.
Question 42: A security investigator is performing a risk assessment for a retail chain. Which asset would typically be assigned the HIGHEST value?
- Customer payment card data (Correct answer)
- Office furniture
- Parking lot signage
- Employee break room equipment
Correct answer: Customer payment card data
Customer payment card data carries the highest value due to regulatory requirements, financial exposure, and reputational damage if compromised.
Question 43: When transferring evidence to another investigator or storage facility, what document must accompany it?
- A duplicate copy of the original incident report
- A sworn affidavit from the original collector only
- An evidence transfer log signed by both the releasing and receiving parties (Correct answer)
- A property receipt signed by the facility manager alone
Correct answer: An evidence transfer log signed by both the releasing and receiving parties
A transfer log with signatures from both parties creates a documented, unbroken chain of custody during handoffs.
Question 44: What should investigators do to preserve digital evidence in a computer system?
- Perform a quick scan of the system
- Alter the system to recover data
- Access the system remotely
- Create a forensic copy of the storage device (Correct answer)
Correct answer: Create a forensic copy of the storage device
To preserve digital evidence on a computer system, investigators must create an exact, bit-for-bit forensic image (or copy) of the original storage device (e.g., hard drive, USB). This process ensures that the original evidence remains untouched and pristine, while all analysis is performed on the copy. This method prevents any alteration of the original data, maintaining its integrity and legal admissibility.
Question 45: An investigator is conducting mobile surveillance and loses sight of the subject's vehicle. What is the BEST next action?
- Speed up and try to locate the subject immediately
- Return to the subject's residence and wait for their return
- Terminate surveillance and notify the client of the loss
- Radio other team members with the last known direction and attempt to reacquire at predictable locations (Correct answer)
Correct answer: Radio other team members with the last known direction and attempt to reacquire at predictable locations
Coordinating with team members to cover likely routes or destinations while avoiding high-speed driving is the safest and most tactically sound response to losing a subject.
Question 46: In video surveillance, 'looping' recordings refers to:
- Streaming footage to multiple monitors simultaneously
- Playing back footage in a continuous loop
- Duplicating footage to a secondary drive
- Overwriting the oldest footage when storage is full (Correct answer)
Correct answer: Overwriting the oldest footage when storage is full
Looping (or loop recording) automatically overwrites the oldest stored footage when storage capacity is reached, ensuring continuous recording.
Question 47: What is 'skip tracing' and which combination of resources is most effective for locating a missing subject?
- A technique for following a subject on foot; best done in pairs with radio communication
- Identifying surveillance gaps in a route; uses mapping software and GPS tracking
- Locating a person who has 'skipped' or fled; combining public records, database searches, and social media (Correct answer)
- Retrieving abandoned surveillance equipment; requires a court order for private property
Correct answer: Locating a person who has 'skipped' or fled; combining public records, database searches, and social media
Skip tracing is the process of locating a person who is avoiding contact or has disappeared, and combining public records, licensed database searches, and social media yields the most comprehensive results.
Question 48: Which of the following is a fundamental principle of covert & overt investigation methods as it applies to Certified Security Investigator?
- Prioritizing speed of completion over accuracy and compliance
- Relying solely on personal experience without reference to guidelines
- Systematic evaluation and adherence to established industry standards (Correct answer)
- Avoiding documentation to streamline workflow efficiency
Correct answer: Systematic evaluation and adherence to established industry standards
A fundamental principle of covert & overt investigation methods in Certified Security Investigator is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.
Question 49: What is the significance of 'threat convergence' in a vulnerability assessment?
- It describes when multiple security teams work together to counter one threat
- It refers to the point when a threat transitions from potential to active
- It describes the process of consolidating threat intelligence from multiple agencies
- It occurs when several separate threat factors combine to create a more serious risk (Correct answer)
Correct answer: It occurs when several separate threat factors combine to create a more serious risk
Threat convergence occurs when multiple independent threat factors—such as intent, opportunity, and reduced security posture—combine simultaneously to create a significantly elevated risk.
Question 50: Why are security policies essential for an organization?
- They focus on financial auditing only
- They provide a framework for managing security risks (Correct answer)
- They focus solely on employee behavior
- They reduce the need for physical security measures
Correct answer: They provide a framework for managing security risks
Security policies are essential because they establish a comprehensive framework that guides an organization's approach to managing and mitigating security risks. These policies define acceptable behavior, outline responsibilities, and set standards for protecting assets, data, and systems. By providing clear guidelines, they help ensure a consistent and proactive stance against potential threats.
Question 51: Which of the following is a PRIMARY goal of a threat vulnerability assessment?
- Identify suspects in a crime
- Determine which assets face the greatest exposure (Correct answer)
- Train security personnel on new policies
- Document incident response procedures
Correct answer: Determine which assets face the greatest exposure
A threat vulnerability assessment aims to identify which assets are most exposed to identified threats.
Question 52: A subject makes a spontaneous, incriminating statement to an investigator during an overt interview. How should the investigator handle this?
- Immediately stop and inform the subject of their Miranda rights
- Terminate the interview to avoid violating the subject's rights
- Document the statement verbatim as soon as possible after the interview (Correct answer)
- Disregard the statement unless it is corroborated by physical evidence
Correct answer: Document the statement verbatim as soon as possible after the interview
Investigators should document spontaneous statements verbatim immediately after the interview to preserve the exact words as accurately as possible for evidentiary purposes.
Question 53: What is the primary function of a firewall in a network security architecture?
- To authenticate users attempting to access network resources
- To monitor and control incoming and outgoing network traffic based on rules (Correct answer)
- To detect and remove malware from endpoint devices
- To encrypt all data transmitted between internal network segments
Correct answer: To monitor and control incoming and outgoing network traffic based on rules
A firewall enforces a set of rules that permit or deny network traffic, acting as a barrier between trusted internal networks and untrusted external networks.
Question 54: Which type of fraud involves an employee manipulating register transactions, such as issuing false refunds to accounts they control?
- Vendor kickback
- Price switching
- Refund fraud or refund scheme (Correct answer)
- Cargo diversion
Correct answer: Refund fraud or refund scheme
Employee refund fraud or a refund scheme involves manipulating POS transactions to generate refunds to accounts controlled by the employee without a legitimate customer return.
Question 55: What is the purpose of conducting a 'red team' exercise during a security vulnerability assessment?
- To audit financial records for fraud indicators
- To train security staff in first aid response
- To simulate adversarial attacks and test actual defenses (Correct answer)
- To review policy documentation for compliance
Correct answer: To simulate adversarial attacks and test actual defenses
A red team exercise simulates real-world adversarial attacks to test how effectively existing security measures can detect and resist threats.
Question 56: What is 'timestomping' and why is it significant in a digital forensic investigation?
- Recording the exact time evidence was collected in the chain of custody log
- Deliberately altering file system timestamps to mislead investigators about when files were created or modified (Correct answer)
- Adding time-based digital signatures to forensic images
- Synchronizing system clocks across multiple forensic workstations
Correct answer: Deliberately altering file system timestamps to mislead investigators about when files were created or modified
Timestomping changes MACB (Modified, Accessed, Changed, Born) timestamps to conceal when malicious files were placed on a system.
Question 57: The term 'narrative' in an investigative report refers to:
- A fictional reconstruction of events for presentation purposes
- The chronological, factual account of the investigative activities and findings (Correct answer)
- A summary of the client's desired outcome from the investigation
- Legal arguments prepared for court presentation
Correct answer: The chronological, factual account of the investigative activities and findings
The narrative is the factual, chronological account of what the investigator did, observed, and found during the investigation.
Question 58: In the context of investigative reporting, 'due diligence' documentation typically includes:
- Media reports about the subject gathered from public sources only
- Only criminal background check results
- The client's internal risk assessment conclusions
- Comprehensive records of all investigative steps taken and sources consulted (Correct answer)
Correct answer: Comprehensive records of all investigative steps taken and sources consulted
Due diligence documentation must show the full scope of investigative steps, sources, and methodology to demonstrate thoroughness and professional standard of care.
Question 59: Which quality assurance method is most commonly applied in covert & overt investigation methods to verify that CSI professional standards are being met?
- Informal self-assessment without external validation
- Structured audits, peer reviews, and performance metrics aligned with industry benchmarks (Correct answer)
- Relying on client satisfaction surveys as the sole measure of quality
- Annual reviews conducted exclusively by non-technical management
Correct answer: Structured audits, peer reviews, and performance metrics aligned with industry benchmarks
Structured audits, peer reviews, and performance metrics aligned with industry benchmarks are the most effective quality assurance methods in covert & overt investigation methods, providing objective, measurable evidence that CSI standards are consistently met.
Question 60: During a mass evacuation drill, the security investigator notices that employees with mobility impairments have no designated rescue assistance procedure. The BEST immediate action is to:
- Post signs directing mobility-impaired employees to wait near elevators
- Evacuate all mobility-impaired employees immediately using the nearest stairwell
- Document the gap and establish a Personal Emergency Evacuation Plan (PEEP) for each affected individual (Correct answer)
- Report the finding only to senior management after the drill
Correct answer: Document the gap and establish a Personal Emergency Evacuation Plan (PEEP) for each affected individual
Establishing individual PEEPs ensures that employees with mobility impairments have a documented, rehearsed plan tailored to their specific needs and the building layout.
Question 61: Which phase of the emergency management cycle focuses on reducing the impact of future disasters through structural and non-structural measures?
- Mitigation (Correct answer)
- Preparedness
- Recovery
- Response
Correct answer: Mitigation
Mitigation involves actions taken before a disaster to reduce or eliminate long-term risk, such as reinforcing structures or relocating assets out of flood zones.
Question 62: A 'tabletop exercise' is most useful for:
- Testing physical evacuation routes under realistic conditions
- Training first responders in hands-on emergency techniques
- Measuring emergency response times for benchmarking
- Identifying gaps in plans through facilitated discussion without deploying resources (Correct answer)
Correct answer: Identifying gaps in plans through facilitated discussion without deploying resources
Tabletop exercises gather key stakeholders to walk through scenarios verbally, exposing plan gaps, coordination issues, and decision-making weaknesses without operational disruption.
Question 63: What is the correct procedure when a security investigator discovers that evidence has been tampered with during storage?
- Document the discovery, notify supervisors, and preserve the compromised evidence as a new finding (Correct answer)
- Correct the chain of custody log retroactively to show no break
- Re-collect replacement evidence from the original scene
- Discard the compromised evidence to avoid legal complications
Correct answer: Document the discovery, notify supervisors, and preserve the compromised evidence as a new finding
Tampering must be documented immediately and reported; the compromised evidence itself becomes relevant to the investigation of the tampering.
Question 64: Which quality assurance method is most commonly applied in emergency action planning to verify that CSI professional standards are being met?
- Informal self-assessment without external validation
- Structured audits, peer reviews, and performance metrics aligned with industry benchmarks (Correct answer)
- Relying on client satisfaction surveys as the sole measure of quality
- Annual reviews conducted exclusively by non-technical management
Correct answer: Structured audits, peer reviews, and performance metrics aligned with industry benchmarks
Structured audits, peer reviews, and performance metrics aligned with industry benchmarks are the most effective quality assurance methods in emergency action planning, providing objective, measurable evidence that CSI standards are consistently met.
Question 65: In security investigations, the PEACE model acronym stands for Preparation, Engage and Explain, Account, Closure, and what?
- Evaluation (Correct answer)
- Evidence
- Execution
- Examination
Correct answer: Evaluation
PEACE stands for Preparation, Engage and Explain, Account, Closure, and Evaluation — a non-coercive interview framework.
Question 66: Which standard is considered the primary benchmark for private sector business continuity and emergency management planning in the United States?
- ANSI/ASIS ORM.1
- OSHA 1910.119
- ISO 9001
- NFPA 1600 (Correct answer)
Correct answer: NFPA 1600
NFPA 1600 is the widely adopted standard for disaster/emergency management and business continuity programs in the private sector in the U.S.
Question 67: Which investigative technique involves calling a subject under a false pretext to elicit information, and what is a key legal limitation in most U.S. states?
- Social engineering; the investigator cannot discuss financial information
- Pretextual telephone contact; recording without consent may violate wiretapping laws (Correct answer)
- Consensual monitoring; the investigator must record all calls
- Cold calling; the investigator cannot claim to be law enforcement
Correct answer: Pretextual telephone contact; recording without consent may violate wiretapping laws
Pretextual phone calls are a covert technique, but recording them without at least one-party consent violates federal and many state wiretapping statutes.
Question 68: Which chain of custody principle ensures that digital evidence collected at a scene can be traced from collection through court presentation?
- Separation of duties
- Data minimization
- Non-repudiation
- Continuity of evidence documentation (Correct answer)
Correct answer: Continuity of evidence documentation
Continuity of evidence documentation (chain of custody) records every person who handled evidence and all transfers, ensuring traceability.
Question 69: A 'mutual aid agreement' between organizations or jurisdictions primarily establishes:
- Legal liability waivers for all responding personnel
- Mandatory response time standards for partner organizations
- A shared emergency operations center location
- Pre-arranged commitments to share resources and provide assistance during emergencies (Correct answer)
Correct answer: Pre-arranged commitments to share resources and provide assistance during emergencies
Mutual aid agreements formalize the terms under which organizations agree to share personnel, equipment, and resources during emergencies that exceed one party's capacity.
Question 70: The National Incident Management System (NIMS) was designed primarily to:
- Provide a consistent nationwide framework for government and private sector emergency management (Correct answer)
- Replace local emergency response plans with federal standards
- Establish liability protections for emergency volunteers
- Mandate specific equipment for all first responders
Correct answer: Provide a consistent nationwide framework for government and private sector emergency management
NIMS provides a scalable, flexible framework enabling all levels of government, NGOs, and the private sector to work together effectively during incidents of any size.
Question 71: Which term describes the pre-designated individual responsible for accounting for all personnel after an evacuation?
- Assembly Point Monitor
- Emergency Coordinator
- Incident Commander
- Floor Warden (Correct answer)
Correct answer: Floor Warden
A Floor Warden (also called an area warden) is responsible for sweeping their zone, directing occupants out, and accounting for personnel at the assembly point.
Question 72: Which document within an emergency plan specifies the order in which a facility will restore functions after an incident?
- Incident Action Plan
- Hazard Vulnerability Analysis
- Recovery Priorities List (Correct answer)
- Business Impact Analysis
Correct answer: Recovery Priorities List
A Recovery Priorities List (or restoration priority document) ranks critical functions and systems in the order they must be restored post-incident.
Question 73: Which type of transmission is most susceptible to interception when used in a wireless surveillance system?
- Twisted pair with encryption
- Coaxial cable
- Fiber optic
- Unencrypted 2.4 GHz RF (Correct answer)
Correct answer: Unencrypted 2.4 GHz RF
Unencrypted 2.4 GHz RF transmissions can be intercepted with readily available equipment, making them the least secure transmission method listed.
Question 74: A CSI investigator is reviewing chain of custody for digital evidence. Why is maintaining chain of custody critical?
- It speeds up the investigation process significantly
- It eliminates the need for witness testimony in court
- It allows investigators to modify evidence for clarity
- It ensures evidence admissibility by documenting who handled it and when (Correct answer)
Correct answer: It ensures evidence admissibility by documenting who handled it and when
Chain of custody documents every person who handled evidence and when, ensuring its integrity and admissibility in legal proceedings.
Question 75: In a workplace theft investigation report, recording that 'no forced entry was observed' is significant because:
- It suggests the offender may have had authorized access, narrowing the suspect pool (Correct answer)
- It satisfies the insurance carrier's documentation requirements
- It confirms the theft did not occur and the report should be closed
- It eliminates the need to interview internal employees
Correct answer: It suggests the offender may have had authorized access, narrowing the suspect pool
Absence of forced entry indicates the perpetrator likely had a key or access code, which focuses the investigation internally.
Question 76: A 'crisis communications plan' should specifically include which element to be effective during an emergency?
- Detailed technical specifications of all security systems
- A complete employee roster with personal contact information
- Pre-approved message templates and designated spokesperson protocols (Correct answer)
- Step-by-step instructions for activating all alarm systems
Correct answer: Pre-approved message templates and designated spokesperson protocols
Effective crisis communications plans include pre-drafted message templates for likely scenarios and clear protocols designating who speaks on behalf of the organization.
Question 77: When an investigator discovers new evidence after submitting a preliminary report, the correct action is to:
- Verbally inform the client without updating written records
- Issue a supplemental report documenting the new findings (Correct answer)
- Amend the original report by overwriting the existing content
- Discard the preliminary report and start fresh
Correct answer: Issue a supplemental report documenting the new findings
A supplemental report preserves the integrity of the original report while formally documenting newly discovered evidence.
Question 78: What is the primary objective of cybersecurity in investigative work?
- To store evidence safely in physical locations
- To monitor employee activities
- To focus only on physical evidence
- To ensure evidence is preserved and protected from cyber threats (Correct answer)
Correct answer: To ensure evidence is preserved and protected from cyber threats
In investigative work, digital evidence is often critical for solving cases. Cybersecurity's primary objective in this context is to safeguard this evidence from unauthorized access, alteration, or destruction by cyber threats, such as hacking or malware. Maintaining the integrity and confidentiality of digital evidence is paramount to its admissibility and credibility in legal proceedings.
Question 79: A CSI professional encounters an unfamiliar situation while performing emergency action planning duties. What is the most appropriate first action?
- Proceed based on general assumptions to avoid delays
- Skip the task entirely and move to the next assignment
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Apply a solution from an unrelated field without verification
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in emergency action planning, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 80: In risk management, 'defense in depth' refers to:
- Focusing all resources on perimeter security
- Layering multiple independent security controls so that failure of one does not compromise the system (Correct answer)
- Using only the most advanced technology available
- Conducting deep background checks on all employees
Correct answer: Layering multiple independent security controls so that failure of one does not compromise the system
Defense in depth is a strategy that employs multiple layers of security controls, ensuring no single point of failure can compromise the entire system.
Question 81: When multiple surveillance vehicles are working as a team, who typically has the 'eyeball' position?
- The vehicle that currently has direct visual contact with the subject (Correct answer)
- The team leader coordinating by radio from a fixed position
- The vehicle positioned furthest ahead of the subject's anticipated route
- The vehicle that last made contact with the subject
Correct answer: The vehicle that currently has direct visual contact with the subject
The 'eyeball' is the team member who currently has direct visual contact on the subject and is responsible for providing real-time updates to the rest of the surveillance team.
Question 82: A CSI investigator discovers a suspect used steganography to hide data in image files. What is steganography in the context of digital investigations?
- Encrypting files with a symmetric key algorithm
- Overwriting deleted files to prevent recovery
- Using VPN tunnels to hide network traffic
- Concealing data within seemingly innocuous carrier files (Correct answer)
Correct answer: Concealing data within seemingly innocuous carrier files
Steganography embeds hidden information within ordinary files like images or audio without visibly altering them.
Question 83: Which communication method is generally considered MOST reliable when normal telecommunications infrastructure fails during a major disaster?
- Amateur (ham) radio (Correct answer)
- Social media platforms
- Corporate email systems
- Cellular telephone networks
Correct answer: Amateur (ham) radio
Amateur (ham) radio operates independently of commercial infrastructure and is widely used as a backup emergency communication system when cellular and internet networks are down.
Question 84: What is the most effective deterrent against shoplifting at the point of entry in a retail store?
- Visible presence of uniformed loss prevention personnel or security officers (Correct answer)
- Reducing the number of store entry points
- Installing hidden cameras only
- Posting warning signs about shoplifting penalties
Correct answer: Visible presence of uniformed loss prevention personnel or security officers
Visible, uniformed loss prevention or security personnel at entry points serve as a strong deterrent because potential shoplifters know they are being observed.
Question 85: A security investigator conducting a 'gap analysis' of an existing Emergency Action Plan is primarily seeking to identify:
- Differences in emergency procedures between day and night shift employees
- Discrepancies between current capabilities and required or desired preparedness standards (Correct answer)
- The cost differential between current and best-practice security systems
- Personnel who have not completed emergency training certifications
Correct answer: Discrepancies between current capabilities and required or desired preparedness standards
A gap analysis compares the organization's current state against required standards or best practices to identify deficiencies that need to be addressed in the plan.
Question 86: What should investigators do if they encounter digital evidence stored on a password-protected device?
- Request proper authorization and use legal tools to access the device (Correct answer)
- Delete the password to simplify access
- Access the device without permission
- Try to bypass the password without recording the steps
Correct answer: Request proper authorization and use legal tools to access the device
When encountering a password-protected device, investigators must adhere to strict legal and ethical guidelines to ensure the admissibility of evidence. This involves obtaining proper legal authorization, such as a search warrant or court order, before attempting to access the device. Using authorized forensic tools and methods ensures that any attempts to bypass security are legally sound and forensically sound, preserving the chain of custody and data integrity.
Question 87: An investigator wants to capture license plates at a parking lot entrance at night. Which combination is most effective?
- Fisheye camera with visible light spotlight
- Standard color camera with wide-angle lens
- License plate recognition camera with integrated IR illuminator (Correct answer)
- Thermal camera with telephoto lens
Correct answer: License plate recognition camera with integrated IR illuminator
Dedicated LPR cameras are optimized for high-speed capture of plate characters and paired with IR illuminators to function effectively in darkness without disturbing drivers.
Question 88: A 'shelter-in-place' directive is MOST appropriate when:
- A hazardous material release occurs outdoors near the facility (Correct answer)
- An active shooter is moving toward the building from inside
- A power outage affects only part of the building
- A fire is detected inside the building
Correct answer: A hazardous material release occurs outdoors near the facility
Shelter-in-place is most appropriate for outdoor hazardous material releases where remaining indoors with sealed ventilation reduces exposure risk.
Question 89: When documenting activities related to threat & vulnerability assessment, which practice is considered essential for CSI certification holders?
- Recording only outcomes while omitting the methods and processes used
- Keeping documentation in personal notes that are not accessible to other team members
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Completing documentation only when requested by auditors or supervisors
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in threat & vulnerability assessment. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 90: A CSI professional encounters an unfamiliar situation while performing physical security surveys duties. What is the most appropriate first action?
- Consult relevant standards, guidelines, or a qualified supervisor before proceeding (Correct answer)
- Proceed based on general assumptions to avoid delays
- Skip the task entirely and move to the next assignment
- Apply a solution from an unrelated field without verification
Correct answer: Consult relevant standards, guidelines, or a qualified supervisor before proceeding
When facing unfamiliar situations in physical security surveys, the most appropriate action is to consult relevant standards, guidelines, or a qualified supervisor. This ensures safety, accuracy, and compliance while building professional knowledge.
Question 91: What is the role of employee training in risk management?
- It is optional for risk management
- It helps employees recognize risks and follow security protocols (Correct answer)
- It limits employee engagement in security practices
- It focuses only on reducing employee turnover
Correct answer: It helps employees recognize risks and follow security protocols
Employees are often the first line of defense against security threats, but they can also be a significant vulnerability if not properly trained. Effective security training educates staff on common risks, such as phishing or social engineering, and instructs them on how to adhere to established security protocols. This empowers employees to act as proactive security assets, reducing human error and strengthening the organization's overall security posture.
Question 92: Why is it essential to use write-blockers when handling digital evidence?
- To allow investigators to edit files on the device
- To remove unnecessary files from the device
- To allow faster data access
- To prevent altering the evidence during analysis (Correct answer)
Correct answer: To prevent altering the evidence during analysis
Write-blockers are crucial hardware or software tools used in digital forensics to prevent any modifications to the original digital evidence. By physically or logically blocking write commands, they ensure that the forensic analysis process does not inadvertently alter timestamps, metadata, or file contents on the source drive. This preservation of integrity is paramount for maintaining the admissibility and reliability of evidence in legal proceedings.
Question 93: What is the primary purpose of maintaining a 'chain of custody' for evidence in a security investigation?
- To document every person who handled the evidence from collection to presentation (Correct answer)
- To ensure evidence is stored in a locked room at all times
- To create a backup copy of all evidence collected on scene
- To limit the number of investigators who can access physical evidence
Correct answer: To document every person who handled the evidence from collection to presentation
Chain of custody documentation proves that evidence has not been tampered with, altered, or contaminated between collection and use in proceedings.
Question 94: A security surveyor is evaluating CCTV effectiveness. What is the MINIMUM recommended camera resolution for facial identification at a 10-foot distance?
- D1 (720x480)
- CIF (352x240)
- HD 720p (1280x720) or higher (Correct answer)
- VGA (640x480)
Correct answer: HD 720p (1280x720) or higher
HD 720p or higher resolution is generally required to capture sufficient facial detail for identification at distances around 10 feet.
Question 95: Which of the following BEST describes a zero-day vulnerability?
- A flaw that is publicly known and has an available patch
- A weakness that only affects systems that have been running for zero days
- A vulnerability that was patched within 24 hours of discovery
- A vulnerability that is unknown to the vendor and has no existing patch (Correct answer)
Correct answer: A vulnerability that is unknown to the vendor and has no existing patch
A zero-day vulnerability is a previously unknown flaw for which no patch exists; attackers can exploit it before the vendor has any opportunity to fix it.
Question 96: Which of the following best describes a 'fixed surveillance' (also called a 'stationary' or 'plant') observation post?
- A stationary position from which an investigator monitors a specific location or subject (Correct answer)
- An undercover operative embedded within an organization
- A moving vehicle that follows a subject at a constant speed
- A remote camera system that automatically tracks movement
Correct answer: A stationary position from which an investigator monitors a specific location or subject
A fixed surveillance post is a stationary location — such as a parked vehicle, building, or natural feature — from which an investigator observes a specific area or subject.
Question 97: A CSI investigator needs to identify all USB devices ever connected to a Windows suspect machine without physically examining every USB device. Where should they look?
- C:\Users\[user]\AppData\Local\Temp
- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR registry key (Correct answer)
- Windows Defender scan history logs
- C:\Windows\System32\drivers\etc\hosts
Correct answer: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USBSTOR registry key
The USBSTOR registry key records every USB storage device connected to the system, including device ID, vendor, and first/last connection times.
Question 98: Prior to conducting a suspect interview, a security investigator should first:
- Obtain a signed confession from a witness
- Consult only verbal accounts from bystanders
- Inform the suspect of all evidence collected
- Review all available evidence and background information (Correct answer)
Correct answer: Review all available evidence and background information
Thorough preparation by reviewing evidence ensures the investigator can ask informed questions and recognize inconsistencies.
Question 99: Which of the following BEST demonstrates 'security by obscurity' as a supplemental tactic in a physical security survey context?
- Using code words instead of standard security terminology
- Hiding server rooms behind unmarked doors without other controls
- Avoiding publication of facility layouts while maintaining robust physical controls (Correct answer)
- Painting security cameras to match the ceiling color
Correct answer: Avoiding publication of facility layouts while maintaining robust physical controls
Limiting public knowledge of facility details can supplement strong physical controls, but should never be the primary or sole security measure.
Question 100: Which document formally defines the acceptable level of risk an organization is willing to tolerate?
- Risk Appetite Statement (Correct answer)
- Incident Response Plan
- Business Continuity Plan
- Security Awareness Policy
Correct answer: Risk Appetite Statement
A Risk Appetite Statement defines the amount and type of risk an organization's leadership is willing to accept in pursuit of its objectives.
Question 101: Which of the following scenarios BEST illustrates a 'blended threat'?
- A criminal using a forged ID to enter a restricted area
- An external hacker remotely accessing a company database
- A disgruntled employee using stolen credentials to access and leak sensitive digital files (Correct answer)
- A natural disaster causing flooding in a server room
Correct answer: A disgruntled employee using stolen credentials to access and leak sensitive digital files
A blended threat combines multiple threat vectors—in this case, both an insider human element and a technical/digital exploitation—to carry out an attack.
Question 102: In a covert investigation involving potential insurance fraud, when should the investigator share surveillance results with the client's attorney rather than directly with the client?
- When litigation is anticipated, to ensure materials are protected by attorney-client or work-product privilege (Correct answer)
- Only when the investigator's license may be at risk from the content of the report
- Only when the subject has also retained legal counsel
- Whenever the subject is a public figure to prevent defamation claims
Correct answer: When litigation is anticipated, to ensure materials are protected by attorney-client or work-product privilege
Directing reports through retaining counsel when litigation is anticipated can protect the investigative materials under work-product doctrine, shielding them from discovery by opposing parties.
Question 103: An IP camera with PoE (Power over Ethernet) capability means it:
- Must be connected directly to a DVR
- Only operates on wireless networks
- Requires a separate power supply unit
- Receives both data and electrical power through the network cable (Correct answer)
Correct answer: Receives both data and electrical power through the network cable
PoE technology allows a single Ethernet cable to simultaneously carry data and supply electrical power to the camera, simplifying installation.
Question 104: In a CCTV layout plan for a retail loss prevention program, which areas should be prioritized for camera coverage?
- Customer service desks and restroom entrances
- Parking lots and external perimeters only
- High-value merchandise displays, cash registers, exits, and fitting rooms (where legally permitted) (Correct answer)
- Break rooms and administrative offices only
Correct answer: High-value merchandise displays, cash registers, exits, and fitting rooms (where legally permitted)
Effective CCTV placement targets high-theft risk areas such as high-value merchandise areas, POS terminals, store exits, and fitting rooms to detect and deter theft.
Question 105: A security investigator is asked to evaluate whether a policy is 'effective.' Which metric is most relevant?
- Employee satisfaction scores related to policy clarity
- The number of incidents that the policy was designed to prevent that still occurred (Correct answer)
- The length and detail of the written policy document
- The cost of printing and distributing the policy
Correct answer: The number of incidents that the policy was designed to prevent that still occurred
Policy effectiveness is measured by whether incidents the policy was designed to prevent actually decreased, not by the document's length or distribution.
Question 106: A security investigator is examining a Windows system and needs to find recently accessed files. Which registry hive would be MOST helpful?
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs (Correct answer)
- HKEY_CLASSES_ROOT
- HKEY_LOCAL_MACHINE\SYSTEM
- HKEY_LOCAL_MACHINE\SAM
Correct answer: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
The RecentDocs key in HKCU tracks files recently opened by the current user through Windows Explorer.
Question 107: The 'chain of succession' documented in an emergency plan is intended to:
- Identify the order in which contractors are notified during an emergency
- Establish the order for employee evacuation by seniority
- Ensure that leadership authority transfers to designated alternates when primary leaders are unavailable (Correct answer)
- Define the sequence in which critical business functions are restored
Correct answer: Ensure that leadership authority transfers to designated alternates when primary leaders are unavailable
Chain of succession identifies pre-designated alternates in rank order to assume authority and decision-making if primary leaders are incapacitated or unavailable during an emergency.
Question 108: Which surveillance technique involves an investigator following a subject using multiple vehicles that rotate positions to avoid detection?
- Parallel surveillance
- Leapfrog surveillance (Correct answer)
- Static surveillance
- Fixed-point observation
Correct answer: Leapfrog surveillance
Leapfrog surveillance uses multiple vehicles that take turns following the subject, with others moving ahead or dropping back to prevent the subject from identifying a single tail.
Question 109: A security investigator needs to preserve volatile data on a running system. Which should be collected FIRST?
- Configuration files in the file system
- Hard drive image
- Log files stored on disk
- RAM contents and running processes (Correct answer)
Correct answer: RAM contents and running processes
RAM, running processes, and network connections are volatile and lost when the system is powered off, so they must be captured first during live forensics.
Question 110: In the context of emergency action planning, what role does continuous professional development play for CSI practitioners?
- It is optional and only needed for career advancement
- It is required only during the first year of certification
- It ensures practitioners remain current with evolving standards, technologies, and best practices (Correct answer)
- It serves primarily as a networking opportunity with no practical benefit
Correct answer: It ensures practitioners remain current with evolving standards, technologies, and best practices
Continuous professional development is essential in emergency action planning because it ensures CSI practitioners remain current with evolving standards, technologies, and best practices, maintaining competency throughout their careers.
Question 111: A security investigator uses the phrase 'the suspect appeared nervous' in a report. This is an example of:
- An inference or opinion (Correct answer)
- A factual observation
- A legal conclusion
- An evidentiary finding
Correct answer: An inference or opinion
'Appeared nervous' is an inference drawn from observable behaviors, not a directly measurable fact.
Question 112: A CSI investigator is asked to examine cloud-stored evidence. Which legal instrument is typically required to compel a US-based cloud provider to disclose customer data?
- A civil lawsuit filing
- An informal written request from a corporate HR department
- An executive order from a federal agency
- A subpoena, court order, or search warrant under the Stored Communications Act (Correct answer)
Correct answer: A subpoena, court order, or search warrant under the Stored Communications Act
The Stored Communications Act (part of ECPA) governs law enforcement access to cloud-stored data and requires the appropriate legal process.
Question 113: Which of the following describes a phishing attack?
- Sending deceptive messages that appear legitimate to trick users into revealing credentials (Correct answer)
- Exploiting a buffer overflow vulnerability in a web application
- Scanning a network to map open ports and running services
- Encrypting an organization's data and demanding a ransom
Correct answer: Sending deceptive messages that appear legitimate to trick users into revealing credentials
Phishing uses deceptive emails or messages that mimic trusted entities to trick recipients into providing credentials or clicking malicious links.
Question 114: When should an Emergency Action Plan be reviewed and updated?
- When the plan is changed, facility layout changes, or when a drill reveals deficiencies (Correct answer)
- Only after a major emergency has occurred
- Every five years regardless of facility changes
- Whenever federal regulations require a new OSHA inspection
Correct answer: When the plan is changed, facility layout changes, or when a drill reveals deficiencies
OSHA requires EAP review whenever the plan itself changes, when occupancy or layout changes, or when post-drill/exercise review reveals inadequacies.
Question 115: In emergency planning, a 'hazard vulnerability analysis' (HVA) is used to:
- Determine insurance coverage requirements for natural disasters
- Identify and prioritize hazards based on likelihood and potential impact (Correct answer)
- Map evacuation routes from the facility to external assembly areas
- Assess employee readiness through written competency tests
Correct answer: Identify and prioritize hazards based on likelihood and potential impact
An HVA systematically identifies potential hazards, estimates their probability of occurrence, and evaluates the potential impact to prioritize planning resources.
Question 116: Which factor is MOST critical when selecting an alternate emergency operations center (EOC)?
- Availability of the location when the primary EOC is unavailable (Correct answer)
- Proximity to the primary EOC for quick staff transfers
- High public visibility to reassure community members
- Presence of a cafeteria for extended operations
Correct answer: Availability of the location when the primary EOC is unavailable
The alternate EOC must be reliably available precisely when the primary site is compromised, making availability the paramount selection criterion.
Question 117: What is the primary purpose of a 'pretext interview' in security investigations?
- To record a sworn statement for court use
- To formally charge a subject with a violation
- To legally compel a subject to answer questions
- To gather information without revealing the true purpose of the inquiry (Correct answer)
Correct answer: To gather information without revealing the true purpose of the inquiry
A pretext interview uses a cover story or false pretense to obtain information that a subject might withhold if they knew the real purpose.
Question 118: Which of the following best describes 'exception-based reporting' (EBR) in loss prevention?
- A method for documenting employee disciplinary actions
- A system for tracking customer complaints
- Software that flags POS transactions deviating from expected patterns (Correct answer)
- Filing incident reports for all security events
Correct answer: Software that flags POS transactions deviating from expected patterns
Exception-based reporting uses software to analyze POS data and flag transactions that deviate from normal patterns, helping identify potential fraud or theft.
Question 119: Which type of evidence is considered 'best evidence' in a security investigation?
- A surveillance video recording of the incident
- A sworn statement from the most credible witness
- The original document or item, rather than a copy (Correct answer)
- A forensic report prepared by a certified expert
Correct answer: The original document or item, rather than a copy
The best evidence rule requires that the original document or item be presented rather than a duplicate, unless the original is unavailable.
Question 120: When conducting a stationary surveillance of a subject's residence, what is the most important pre-operational step?
- Purchasing high-resolution cameras
- Conducting a route survey and identifying the optimal observation point (Correct answer)
- Installing a GPS tracker on nearby vehicles
- Notifying local law enforcement of the surveillance
Correct answer: Conducting a route survey and identifying the optimal observation point
A pre-operational route survey allows the investigator to identify effective observation positions, escape routes, cover stories, and potential detection risks before committing to the location.
Question 121: A CSI investigator reviewing a report finds it lacks specific times for key events. This deficiency most significantly affects the report's:
- Readability for general audiences
- Ability to establish a timeline and corroborate alibis (Correct answer)
- Compliance with formatting standards
- Suitability for media release
Correct answer: Ability to establish a timeline and corroborate alibis
Specific times are essential for constructing an accurate timeline, which is critical for corroborating or refuting alibis.
Question 122: Which principle states that during an incident, responders should request resources through their immediate supervisor rather than going around the chain of command?
- Modular organization
- Unity of command (Correct answer)
- Unified command
- Span of control
Correct answer: Unity of command
Unity of command means every individual reports to only one supervisor, ensuring clear accountability and preventing conflicting instructions during incident response.
Question 123: Why is it important to regularly update security policies?
- It focuses on minimizing employee responsibility
- It allows for more lenient enforcement of procedures
- It reduces the number of incidents and response time (Correct answer)
- It keeps the policies aligned with outdated practices
Correct answer: It reduces the number of incidents and response time
Regularly updating security policies is crucial because the threat landscape, technologies, and organizational needs are constantly evolving. Outdated policies can leave an organization vulnerable to new threats or fail to address current operational realities. Keeping policies current ensures they remain effective in mitigating risks, which in turn helps reduce the frequency of security incidents and improves the efficiency of incident response.
Question 124: In the context of CSI investigations, what does OSINT stand for and how is it used?
- Organized Subject Intelligence Network; coordinating multi-team surveillance
- Open-Source Intelligence; gathering information from publicly available sources (Correct answer)
- Operational Security Intelligence; protecting the investigator's identity
- On-Site Intelligence; direct physical observation of a location or subject
Correct answer: Open-Source Intelligence; gathering information from publicly available sources
Open-Source Intelligence (OSINT) involves collecting and analyzing information from publicly available sources such as social media, public records, news, and online databases.
Question 125: When collecting physical evidence at a security incident scene, what should an investigator do first?
- Package all visible evidence immediately to prevent loss
- Document and photograph the scene before touching anything (Correct answer)
- Contact law enforcement to take over the scene
- Interview nearby witnesses before any evidence is collected
Correct answer: Document and photograph the scene before touching anything
Documenting and photographing the scene before collection preserves the original state of evidence and its spatial relationships.
Question 126: A CSI uses a drone to conduct aerial surveillance of a subject's fenced private property. Which concern is MOST legally significant?
- FAA registration of the drone before conducting surveillance
- The cost of the drone operation and whether it is billable to the client
- Whether the drone footage is admissible as photographic evidence in civil court
- Potential violation of the subject's reasonable expectation of privacy over their curtilage (Correct answer)
Correct answer: Potential violation of the subject's reasonable expectation of privacy over their curtilage
Courts have extended Fourth Amendment-like privacy expectations to the curtilage (the area immediately surrounding a home), and aerial surveillance of enclosed private property may violate these expectations regardless of drone registration.
Question 127: A security investigator conducting workplace surveillance discovers an employee committing fraud and shares the footage with prosecutors. The key legal question regarding admissibility is:
- Whether the footage was stored on company servers
- Whether the investigator had a state PI license at the time of recording
- Whether the employer consented to the sharing of evidence with law enforcement
- Whether the investigator was acting as a government agent or purely as a private party (Correct answer)
Correct answer: Whether the investigator was acting as a government agent or purely as a private party
If the investigator acted independently as a private party, the Fourth Amendment exclusionary rule likely does not apply, and the evidence is admissible.
Question 128: A security investigator is conducting a Business Impact Analysis (BIA). What is the PRIMARY output of a BIA?
- A physical security upgrade plan
- Employee background check requirements
- Prioritized critical business functions and recovery time objectives (Correct answer)
- A list of potential threat actors
Correct answer: Prioritized critical business functions and recovery time objectives
A BIA identifies critical business functions and establishes the maximum tolerable downtime and recovery objectives for each.
Question 129: In covert investigations, 'pretext' most accurately refers to:
- Background research conducted before initiating contact with a subject
- Written authorization from a supervising attorney before starting an investigation
- A fabricated or assumed identity or scenario used to elicit information (Correct answer)
- A legal doctrine permitting searches without warrants in emergencies
Correct answer: A fabricated or assumed identity or scenario used to elicit information
Pretext involves assuming a false identity or creating a fictitious scenario to obtain information or access that would otherwise be denied.
Question 130: Which of the following BEST describes 'consequence management' in the context of emergency planning?
- Prosecuting individuals responsible for causing an emergency
- Managing media relations after a high-profile security incident
- Preventing an emergency from occurring through proactive security measures
- Addressing the effects of an emergency to protect public health, safety, and the environment (Correct answer)
Correct answer: Addressing the effects of an emergency to protect public health, safety, and the environment
Consequence management focuses on mitigating the effects of an incident on people, property, and the environment after it has occurred.
Question 131: Which interview technique involves asking open-ended questions to allow a subject to provide a narrative without interruption?
- PEACE model
- Cognitive interview (Correct answer)
- Reid Technique
- Structured interview
Correct answer: Cognitive interview
The cognitive interview uses open-ended questions and free recall to allow subjects to narrate events in their own words.
Question 132: When testifying about digital evidence findings, a CSI investigator should characterize their role as a:
- Consultant who advises only the retaining attorney on legal strategy
- Neutral expert witness who presents factual findings regardless of which party they favor (Correct answer)
- Advocate for the prosecution's theory of the case
- Fact witness limited to describing what they personally observed at the scene
Correct answer: Neutral expert witness who presents factual findings regardless of which party they favor
A digital forensics expert witness must remain objective and impartial, presenting accurate findings that support truth regardless of which side retained them.
Question 133: Which of the following is a fundamental principle of emergency action planning as it applies to Certified Security Investigator?
- Prioritizing speed of completion over accuracy and compliance
- Avoiding documentation to streamline workflow efficiency
- Systematic evaluation and adherence to established industry standards (Correct answer)
- Relying solely on personal experience without reference to guidelines
Correct answer: Systematic evaluation and adherence to established industry standards
A fundamental principle of emergency action planning in Certified Security Investigator is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.
Question 134: Which element is essential in a written security policy to ensure enforceability?
- Lengthy historical background on security threats
- Technical jargon understandable only to IT staff
- References to competitor security practices
- Clear consequences for policy violations (Correct answer)
Correct answer: Clear consequences for policy violations
Enforceable policies must specify consequences for violations so employees understand the stakes and management can act consistently.
Question 135: During post-incident analysis, the security investigator identifies that the emergency notification system failed to reach employees on the loading dock. The BEST corrective action is to:
- Discipline the supervisor responsible for the loading dock area
- Require all loading dock employees to carry personal radios at their own expense
- Add a secondary notification method (e.g., strobe lights or PA system) tailored to the loading dock environment (Correct answer)
- Remove the loading dock from the facility's emergency plan scope
Correct answer: Add a secondary notification method (e.g., strobe lights or PA system) tailored to the loading dock environment
Addressing notification gaps with environment-appropriate redundant methods—such as strobes in high-noise areas—ensures all personnel receive emergency alerts regardless of location.
Question 136: Which protocol is commonly used to synchronize the time across multiple IP cameras and recorders in a surveillance network?
- SMTP (Simple Mail Transfer Protocol)
- FTP (File Transfer Protocol)
- DHCP (Dynamic Host Configuration Protocol)
- NTP (Network Time Protocol) (Correct answer)
Correct answer: NTP (Network Time Protocol)
NTP synchronizes clocks across networked devices, ensuring that timestamps on footage from multiple cameras are consistent and accurate for forensic analysis.
Question 137: What should be done if a security policy is found to be ineffective?
- Ignore the policy and continue as is
- Revise the policy based on feedback and new threats (Correct answer)
- Focus on enforcing the policy more strictly without changes
- Reduce the scope of the policy
Correct answer: Revise the policy based on feedback and new threats
If a security policy is found to be ineffective, the appropriate action is to revise it based on feedback, incident analysis, and emerging threats. Ignoring an ineffective policy or simply enforcing it more strictly without addressing its flaws will not improve security. A proactive approach involves updating the policy to incorporate lessons learned, adapt to new technologies, and better address current risks, ensuring its continued relevance and efficacy.
Question 138: A 'continuity of operations plan' (COOP) primarily addresses which concern?
- How to communicate with media during a crisis
- How essential functions will continue during and after a disruption (Correct answer)
- How to extinguish industrial fires
- How to restore IT systems after a cyberattack
Correct answer: How essential functions will continue during and after a disruption
A COOP defines how an organization sustains its essential functions and critical operations during and following an emergency or major disruption.
Question 139: When collecting witness statements as evidence, a security investigator should ensure the statement is:
- Kept confidential and not shared with any other party
- Signed and dated by the witness and the collecting investigator (Correct answer)
- Submitted only in oral form to preserve natural expression
- Rewritten by the investigator in more professional language
Correct answer: Signed and dated by the witness and the collecting investigator
A signed and dated witness statement provides authentication and creates a verifiable record that the witness provided the account at a specific time.
Question 140: A CSI is hired to investigate a workers' compensation fraud claim. The claimant is observed performing strenuous yard work. Which method of documentation is MOST valuable for evidence purposes?
- A witness statement from a neighbor who observed the activity
- Video footage with date/time stamp showing the subject's activities (Correct answer)
- Photographs taken from a publicly accessible location
- A written description of the observed activities
Correct answer: Video footage with date/time stamp showing the subject's activities
Timestamped video footage is the most compelling documentary evidence of physical activity because it provides continuous, real-time proof that is difficult to dispute.
Question 141: How does thorough documentation of evidence contribute to investigative reporting?
- It limits the amount of evidence available
- It provides a foundation for further legal action (Correct answer)
- It makes the investigation less organized
- It focuses solely on the report's length
Correct answer: It provides a foundation for further legal action
Thorough documentation of evidence is fundamental because it creates a robust, verifiable record that can withstand scrutiny in legal proceedings. This detailed record establishes the chain of custody, authenticity, and relevance of each piece of evidence, forming a solid foundation for prosecution, defense, or other legal actions. Without comprehensive documentation, evidence may be deemed inadmissible or unreliable, jeopardizing the case.
Question 142: When evaluating a facility's key control program during a survey, which finding represents the MOST serious vulnerability?
- Key inventory is conducted annually
- Some keys are over 10 years old
- Keys are labeled with room numbers for convenience (Correct answer)
- Master keys are issued to all supervisors
Correct answer: Keys are labeled with room numbers for convenience
Labeling keys with room numbers enables a lost or stolen key to be used immediately against the targeted lock, creating a critical vulnerability.
Question 143: A 'rally point' in an active shooter emergency plan is BEST defined as:
- The command post where law enforcement coordinates their response
- A room designated for armed security personnel to stage a counterassault
- A medical triage area adjacent to the affected building
- A pre-designated secure location where survivors reconvene after evacuating a threat (Correct answer)
Correct answer: A pre-designated secure location where survivors reconvene after evacuating a threat
A rally point is a pre-identified, secure location away from danger where evacuees gather to be accounted for and to receive further instructions.
Question 144: For how long should a security investigator generally retain evidence after a case is closed?
- Only until the final report is submitted
- For a minimum of 30 days regardless of case type
- According to the organization's retention policy and applicable legal requirements (Correct answer)
- Until the investigator's employment ends
Correct answer: According to the organization's retention policy and applicable legal requirements
Retention periods vary by jurisdiction, type of case, and organizational policy, and may extend for years if appeals or litigation are possible.
Question 145: Which is an example of improper evidence documentation in a security investigation?
- Writing case numbers directly on evidence with permanent marker without bagging first (Correct answer)
- Photographing evidence before and after collection
- Sealing collected items in tamper-evident packaging
- Logging each item in an evidence inventory log
Correct answer: Writing case numbers directly on evidence with permanent marker without bagging first
Writing directly on evidence without proper collection procedures can contaminate or alter the evidence, compromising its admissibility and integrity.
Question 146: In a layered security policy framework, operational procedures differ from policies in that procedures:
- Require government approval before implementation
- Describe specific step-by-step actions to implement policy intent (Correct answer)
- Override policies when conflicts arise
- Apply only to executive leadership
Correct answer: Describe specific step-by-step actions to implement policy intent
Procedures provide detailed, actionable steps for staff to follow, operationalizing the broader directives established in policies.
Question 147: A security surveyor identifies a 'dead zone' in camera coverage. What is the PRIMARY corrective action?
- Install motion sensors in the dead zone
- Document and accept the risk
- Add a security guard post at the dead zone
- Reposition or add cameras to eliminate the coverage gap (Correct answer)
Correct answer: Reposition or add cameras to eliminate the coverage gap
Repositioning or adding cameras directly addresses the coverage gap, eliminating the vulnerability identified during the survey.
Question 148: In video forensics, 'de-interlacing' is necessary when:
- Converting color footage to black and white
- Removing audio tracks from video files
- Increasing the resolution of digital footage
- Analyzing footage captured by older analog cameras that recorded in interlaced format (Correct answer)
Correct answer: Analyzing footage captured by older analog cameras that recorded in interlaced format
Interlaced video from analog systems alternates odd and even scan lines, and de-interlacing combines them into full progressive frames for clearer still-image analysis.
Question 149: The Incident Command System (ICS) uses a 'span of control' that is ideally kept within what ratio?
- 1 supervisor to 3–7 personnel (Correct answer)
- 1 supervisor to 2–3 personnel
- 1 supervisor to 15–20 personnel
- 1 supervisor to 8–12 personnel
Correct answer: 1 supervisor to 3–7 personnel
ICS recommends a span of control between 1:3 and 1:7, with 1:5 considered optimal, to maintain effective supervision without overwhelming any single supervisor.
Question 150: What is 'spoliation of evidence,' and what are its consequences in a security investigation?
- The process of transferring evidence to an external forensic lab
- The accidental duplication of evidence records in multiple systems
- The intentional or negligent destruction of evidence, which can result in legal sanctions and adverse inferences (Correct answer)
- The gradual degradation of biological evidence over time in storage
Correct answer: The intentional or negligent destruction of evidence, which can result in legal sanctions and adverse inferences
Spoliation occurs when evidence is destroyed, altered, or concealed, and courts may draw adverse inferences or impose sanctions against the responsible party.
Question 151: What is the significance of 'metadata' embedded in digital surveillance video files?
- It is irrelevant to forensic investigations
- It contains information such as timestamp, GPS coordinates, and device ID that authenticates the recording (Correct answer)
- It compresses the video for storage
- It determines the camera's frame rate only
Correct answer: It contains information such as timestamp, GPS coordinates, and device ID that authenticates the recording
Embedded metadata provides critical authentication data including when, where, and by which device footage was captured, supporting or undermining evidentiary claims.
CSI® Certified Security Investigator
The CSI® certification validates specialist competence in corporate security investigations, covering the full lifecycle from case management and evidence gathering through interview methodology and investigation reporting. It is awarded by CorpSecurity International.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds