Systems 1
Systems 2
Legacy
Exploits
The Unit
100

This core system managed by ITMS is the nation’s premier clearinghouse for crime data, processing over 10 million inquiries every single day.

What is the National Crime Information Center (NCIC)?

100

Team that protects the confidentiality, integrity, and availability of government data and IT systems as mandated by the Federal Information Security Modernization Act.

What is FISCOM (FISMA Compliance)?

100

Before the formal creation of the CJIS Division, the finger-printing and record-keeping unit was referred to as.

What is Ident (Identification Division)?

100

This physical attack involves an unauthorized person closely following an employee through a secured door into a restricted facility.

What is tailgating (or piggybacking)?

200

ITMS infrastructure supports NICS, which is the system responsible for conducting these rapid background checks.

What is the National Instant Criminal Background Check System?

200

The predecessor to NGI that was limited to tenprint and latent fingerprint searches and was decommissioned in 2014.

What is IAFIS (The Integrated Automated Fingerprint Identification System)?

200

This type of flaw represents a security vulnerability that is completely unknown to the vendor, leaving defenders with no time to create a patch.

What is a Zero-Day vulnerability?



300

This flagship biometric identity system managed by ITMS replaced the legacy Integrated Automated Fingerprint Identification System (IAFIS) in 2014.

What is the Next Generation Identification (NGI) system?

300

The system that provides guidance, services, and capabilities so that customers see a CJIS view of our information.

What is CJIS Data Services Value Stream (DSVS)

300

This is the predecessor to the National Threat Operations Center established in 2001 after September 11 attacks.

What is the Public Access Line (PAL)?

300

A malicious technique where an attacker tricks a user into clicking a hidden or disguised user interface element on a website, causing them to unintentionally perform actions like downloading malware, changing account settings, or transferring funds.

What is clickjacking (User Interface redress attack)?

400

This system provides criminal justice agencies with an online tool for sharing, searching, linking, and analyzing information across jurisdictional boundaries. 

What is National Data Exchange (N-DEx)?

400

First Assistant Director of CJIS which was created in 1992 a month before this appointment.

Who is G. Norm Christensen?

400

Attackers exploit this type of volumetric network vulnerability by flooding a target server with massive amounts of junk traffic to knock its services offline for legitimate users.

What is a Denial of Service attack?

500

A secure, centralized digital gateway provided by the FBI's CJIS Division that allows law enforcement agencies, intelligence groups, and criminal justice professionals to access shared investigative tools, analytical resources, and national databases using a single login.

What is LEEP (Law Enforcement Enterprise Portal)?

500
This person was named the Director of the Bureau of Investigation in 1924 serving for nearly 48 years in this role.

Who is J. Edgar Hoover?

500

A vulnerability where an attacker manipulates a vulnerable server into sending unauthorized requests to internal or external systems on their behalf.

What is a Server-Side Request Forgery (SSRF) attack?

500

The original name of this unit when originally founded.

What is the Contract Administration Office (CAO)?

M
e
n
u