Cyber Awareness Challenge 2023 Answers

We thoroughly check each answer to a question to provide you with the most correct answers. Found a mistake? Let us know about it through the REPORT button at the bottom of the page. Ctrl+F (Cmd+F) will help you a lot when searching through such a large set of questions.

The annual Cyber Awareness Challenge is a course that helps authorized users learn how to best avoid and reduce threats and vulnerabilities in an organization’s system. In addition to offering an overview of cybersecurity best practices, the challenge also provides awareness of potential and common cyber threats. The challenge’s goal is simple: To change user behavior to reduce the risks and vulnerabilities DoD Information Systems face.

Here you can find answers to the DoD Cyber Awareness Challenge.

Cyber Awareness Challenge 2023 Answers

Standard Challenge Answers

Spillage

If spillage occurs:

  • Immediately notify your security POC;
  • Do not delete the suspected files;
  • Do not forward, read further, or manipulate the file;
  • Secure the area.
 
Which of the following does NOT constitute spillage?
Classified information that should be unclassified and is downgraded. Spillage occurs when information is “spilled” from a higher classification or protection level to a lower classification or protection level. Spillage can be either inadvertent or intentional.
 
Which of the following is NOT an appropriate way to protect against inadvertent spillage?
Use the classified network for all work, including unclassified work. Being cognizant of classification markings and labeling practices are good strategies to avoid inadvertent spillage. While it may seem safer, you should NOT use a classified network for unclassified work.
 
Which of the following should you NOT do if you find classified information on the internet?
Download the information. Leaked classified or controlled information is still classified/controlled even if it has already been compromised. Do not download it.

Classified Data

 
What level of damage to national security can you reasonably expect Top Secret information to cause if disclosed?
Exceptionally grave damage. Top Secret information could be expected to cause exceptionally grave damage to national security of disclosed.
 
Which of the following is true about telework?
You must have your organization’s permission to telework. When teleworking, you should always use authorized and software.
 
Which of the following is true of protecting classified data?
Classified material must be appropriately marked. Even within a secure facility, don’t assume open storage is permitted.

Insider Threat

 
In addition to avoiding the temptation of greed to betray his country, what should Alex do differently?
Avoid talking about work outside of the workplace or with people without a need-to-know.
 
How many insider threat indicators does Alex demonstrate?
Three or more. Alex demonstrates a lot of potential insider threat indicators.
 
What should Alex’s colleagues do?
Report the suspicious behavior in accordance with their organization’s insider threat policy.

Social Networking

 
Privacy settings
All to Friends Only. Only friends should see all biographical data such as where Alex lives and works.

Controlled Unclassified Information

 
Which of the following is NOT an example of CUI?
Press release data. CUI includes, but is not limited to Controlled Technical Information (CTI), Personally Identifiable Information (PII), Protected Health Information (PHI), financial information, personal or payroll information, proprietary data and operational information.
 
Which of the following is NOT a correct way to protect CUI?
CUI may be stored on any password-protected system. CUI may be stored only on authorized systems or approved devices.
 
Select the information on the data sheet that is personally identifiable information (PII).
PII includes, but is not limited to, social security numbers, date and places of birth, mothers’ maiden names, biometric records, and PHI.

Physical Security

CPCON LevelDoD Risk LevelPriority Focus
CPCON 1Very HighCritical Functions
CPCON 2HighCritical and Essential Functions
CPCON 3MediumCritical, Essential, and Support Functions
CPCON 4LowAll Functions
CPCON 5Very LowAll Functions
 
What should the employee do differently?
Remove his CAC and lock his workstation.
 
What should the employee do differently?
Decline to let the person in and redirect her to security. Don’t allow other access or to piggyback into secure areas.

Identity Management

 
Identify security violations:
Always take your CAC when you leave your workstation. Never write down the PIN for your CAC.

Sensitive Compartmented Information

 
When is it appropriate to have your security badge visible?
At all times while in the facility. Badges must be visible and displayed above the waist at all times when in the facility.
 
What should the owner of this printed SCI do differently?
Retrieve classified documents promptly from printers. ALways mark classified information appropriately and retrieve classified documents promptly from the printer.
 
What should the participants in this conversation involving SCI do differently?
Physically assess that everyone within listening distance is cleared and has a need-to-know for the information being discussed.

Removable Media in a SCIF

 
What portable electronic devices (PEDs) are permitted in a SCIF?
Only expressly authorized government-owned PEDs.
 
What is the response to an incident such as opening an uncontrolled DVD on a computer in a SCIF
All of these. Classified DVD distribution should be controlled just like any other classified media.

Malicious Code

Malicious code can do damage by corrupting files, erasing your hard drive, and/or allowing hackers access.

 
Which of the following is an example of malicious code?
Software that installs itself without the user’s knowledge. Malicious code can mask itself as a harmless e-mail attachment, downloadable file, or website.
 
How can malicious code cause damage?
All of these.
 
How can you avoid downloading malicious code?
Do not access website links in e-mail messages.

Website Use

 
What to choose?
Look for the HTTPS in URL.

Social Engineering

To protect against social engineering:

  • Do not participate in telephone surveys;
  • Do not give out personal information
  • Do not give out computer or network information
  • Do not follow instructions from unverified personnel
  • Contact your security POC or help desk
 
Required Profile Update
Report e-mail.
 
Account Alert
Delete e-mail.
 
Great Book Deals
Delete e-mail.

Travel

 
What should Sara do when publicly available Internet, such as hotel Wi-Fi?
Only connect with the Government VPN.
 
What is the danger of using public Wi-Fi connections?
Both of these.

Use of GFE

 
Permitted Uses of Government-Furnished Equipment (GFE)
Viewing or downloading pornography – No
Gambling online – No
Conducting a private money-making venture – No
Using unauthorized software – No
Illegaly downloading copyrighted material – No
Making unauthorized configuration changes – No

Mobile Devices

 
When is it okay to charge a personal mobile device using government-furnished equipment (GFE)?
This is never okay.
 
Which of the following demonstrates proper protection of mobile devices?
Linda encrypts all of the sensitive data on her government issued mobile devices.

Home Computer Security

 
What to choose?
Update – Install – Enable – Exit

Cyber Awareness Challenge Knowledge Check 2023 Answers

Spillage

 
What does “spillage” refer to?
Information improperly moved from a higher protection level to a lower protection level. – Correct
 
You find information that you know to be classified on the Internet. What should you do?
Note the website’s URL and report the situation to your security point of contact. – Correct
 
You receive an inquiry from a reporter about government information not cleared for public release. How should you respond?
Refer the reporter to your organization’s public affairs office. – Correct
 
A vendor conducting a pilot program with your organization contacts you for organizational data to use in a prototype. How should you respond?
Refer the vendor to the appropriate personnel. – Correct
 
Which of the following may help to prevent spillage?
Follow procedures for transferring data to and from outside agency and non-Government networks. – Correct.
 
Which of the following is a good practice to prevent spillage?
Always check to make sure you are using the correct network for the level of data. – Correct

Classified Data

 
Which of the following is a good practice for telework?
Position your monitor so that it is not facing others or easily observed by others when in use – Correct
 
What level of damage can the unauthorized disclosure of information classified as Top Secret reasonably be expected to cause?
Exceptionally grave damage to national security. – Correct
 
Which of the following is a good practice to protect classified information?
Power off any mobile devices when entering a secure area. – Not correct. Store classified data in a locked desk drawer when not in use – Maybe Transmit classified information via fax machine only – Not correct Don’t assume open storage in a secure facility is authorized – Maybe
 
What level of damage can the unauthorized disclosure of information classified as confidential reasonably be expected to cause?
Damage to national security. – Correct
 
Which of the following must you do before using an unclassified laptop and peripherals in a collateral classified environment?
Ensure that any cameras, microphones, and Wi-Fi embedded in the laptop are physically disabled.- Correct
 
What is the basis for the handling and storage of classified data?
Classification markings and handling caveats. – Not correct Security Classification Guides (SCGs).??? Organizational Policy – Not correct General Services Administration (GSA) approval
 
Who designates whether information is classified and its classification level?
Original classification authority – Correct

Insider Threat

 
Which of the following is a potential insider threat indicator?
Unusual interest in classified information. – Correct Dofficult life circumstances, such as death of spouse
 
What function do Insider Threat Programs aim to fulfill?
Proactively identify potential threats and formulate holistic mitigation responses. – Correct
 
What is an insider threat?
Someone who uses authorized access, wittingly or unwittingly, to harm national security through unauthorized disclosure or other actions that may cause the loss or degradation of resources or capabilities. – Correct
 
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague is playful and charming, consistently wins performance awards, and is occasionally aggressive in trying to access classified information.
1 indicator.
 
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague enjoys playing video games online, regularly use social media, and frequently forgets to secure her smartphone elsewhere before entering areas where it is prohibited.
1 indicator.
 
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague abruptly becomes hostile and unpleasant after previously enjoying positive working relationships with peers, purchases an unusually expensive new car, and has unexplained absences from work.
3 or more indicators. – Correct
 
Which of the following is a reportable insider threat activity?
Attempting to access sensitive information without need-to-know. – Not correct.
 
Which scenario might indicate a reportable insider threat?
A colleague removes sensitive information without seeking authorization in order to perform authorized telework. – Correct

Social Networking

 
A trusted friend in your social network posts a link to vaccine information on a website unknown to you. What action should you take?
Research the source to evaluate its credibility and reliability.
 
Which piece of information is safest to include on your social media profile?
Your favorite movie. – Correct Photos of your pet – Correct
 
When may you be subject to criminal, disciplinary, and/or administrative action due to online harassment, bullying, stalking, hazing, discrimination, or retaliation?
If you participate in or condone it at any time.
 
How can you protect yourself on social networking sites?
Validate friend requests through another source before confirming them. – Correct
 
Which of the following statements is true?
Many apps and smart devices collect and share your personal information and contribute to your online identity.
 
Which of the following statements is true?
Adversaries exploit social networking sites to disseminate fake news – Correct.
 
Which of the following is a security best practice when using social networking sites?
Accepting the default privacy settings. – Maybe

Controlled Unclassified Information

 
Which designation marks information that does not have potential to damage national security?
Unclassified – Correct
 
Which designation includes Personally Identifiable Information (PII) and Protected Health Information (PHI)?
Controlled unclassified information. – correct
 
What is a best practice for protecting controlled unclassified information (CUI)?
Store it in a locked desk drawer after working hours. – correct
 
Which of the following is true of Controlled Unclassified information (CUI)?
CUI must be handled using safeguarding or dissemination controls. – Correct
 
Which of the following is true of Protected Health Information (PHI)?
It is created or received by a healthcare provider, health plan, or employer. – Correct
 
Which of the following is NOT an example of Personally Identifiable Information (PII)?
High school attended. – correct
 
Which of the following is a security best practice for protecting Personally Identifiable Information (PII)?
Only use Government-furnished or Government-approved equipment to process PII. – correct
 
Which of the following best describes a way to safely transmit Controlled Unclassified Information (CUI)?
Paul verifies that the information is CUI, includes a CUI marking in the subject header, and digitally signs an e-mail containing CUI. – Maybe John submits CUI to his organization’s security office to transmit it on his behalf. not – correct Debra ensures – not correct Prudence faxes CUI using an Unclassified cover sheet via a Secret fax machine. – not correct
 
Which of the following is true of Unclassified Information?
It does not require markings or distribution controls. – not correct Aggregating it does not affect its sensitivyty level. – not correct It is releasable to the public without clearance. – not correct

Physical Security

 
Which of the following best describes good physical security?
Lionel stops an individual in his secure area who is not wearing a badge. – Correct
 
Which Cyber Protection Condition (CPCON) establishes a protection priority focus on critical functions only?
CPCON 1. – Correct

Identity Management

 
Which of the following is an example of a strong password?
%2ZN=Ugq – correct
 
What is the best way to protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card?
Store it in a shielded sleeve. – Correct
 
Which of the following is true of the Common Access Card (CAC) or Personal Identity Verification (PIV) card?
You should remove and take your CAC/PIV card whenever you leave your workstation. – correct
 
Which of the following is true of using DoD Public key Infrastructure (PKI) token?
It should only be in a system while actively using it for a PKI-required task. – Correct
 
Which of the following is true of the Common Access Card (CAC)?
It contains certificates for identification, encryption, and digital signature. – correct
 
Which of the following is an example of two-factor authentication?
A Common Access Card and Personal Identification Number. – correct

Sensitive Compartmented Information

 
What must authorized personnel do before permitting another individual to enter a Sensitive Compartmented Information Facility (SCIF)?
Confirm the individual’s need-to-know and access. – correct
 
Which of the following is true of Security Classification Guides?
They broadly describe the overall classification of a program or system. – Not correct They provide guidance on reasons for and duration of classification of information.
 
Which of the following is true of Sensitive Compartmented Information (SCI)?
Access requires a formal need-to-know determination issued by the Director of National Intelligence.??Access requires Top Secret clearance and indoctrination into SCI program.???
 
Which of the following is true of sharing information in a Sensitive Compartmented Information Facility (SCIF)?
Individuals must avoid referencing derivatively classified reports classified higher than the recipient.???
 
A compromise of Sensitive Compartmented Information (SCI) occurs when a person who does not have the required clearance or access caveats comes into possession of SCI_________.???
In any manner.
 
Which of the following is true of transmitting Sensitive Compartmented Information (SCI)?
You many only transmit SCI via certified mail. – not correct

Malicious Code

 
Which of the following is NOT a type of malicious code?
Macros. – Not correct.
 
Which of the following is true of downloading apps?
For Government-owned devices, use approved and authorized applications only. – Correct

Website Use

 
Which of the following actions can help to protect your identity?
Shred personal documents.

Social Engineering

 
What type of social engineering targets senior officials?
Whaling. – correct
 
How can you protect yourself from social engineering?
Verify the identity of all individuals.???
 
What actions should you take with a compressed Uniform Resource Locator (URL) on a website known to you?
Right-click the link and select the option to preview???
 
Which of the following is true?
Digitally signed e-mails are more secure. – correct
 
Which of the following is true of internet hoaxes?
They can be part of a distributed denial-of-service (DDoS) attack. – correct

Travel

 
Which of the following is a concern when using your Government-issued laptop in public?
Others may be able to view your screen. The physical security of the device. – Correct

Use of GFE

 
Which of the following personally-owned computer peripherals is permitted for use with Government-furnished equipment?
A headset with a microphone through a Universal Serial Bus (USB) port. – correct

Mobile Devices

 
Which of the following is an example of removable media?
Memory sticks, flash drives, or external hard drives. – correct
 
How can you protect data on your mobile computing and portable electronic devices (PEDs)?
Enable automatic screen locking after a period of inactivity. – correct

Home Computer Security

 
Which of the following is true of Internet of Things (IoT) devices?
They can become an attack vector to other devices on your home network. – correct

Cyber Awareness Challenge 2022 Knowledge Check Answers

 
CUI may be stored on any password-protected system.
 
Which of the following is a good practice to prevent spillage
Be aware of classification markings and all handling caveats.
 
*Spillage
Which of the following may help prevent inadvertent spillage?
Label all files, removable media, and subject headers with appropriate classification markings.
 
Which of the following is a good practice to protect classified information
Ensure proper labeling by appropriately marking all classified material.
 
Which of the following is true of traveling overseas with a mobile phone
Physical security of mobile phones carried overseas is not a major issue.
 
*Classified Data Which of the following individuals can access classified data?
Darryl is managing a project that requires access to classified information. He has the appropriate clearance and a signed, approved, non-disclosure agreement.
 
Which of the following best describes the sources that contribute to your online identity
Data about you collected from all sites, apps, and devices that you use can be aggregated to form a profile of you.
 
Which of the following is true of telework?
You must have your organization’s permission to telework.
 
*SOCIAL NETWORKING*
Which of the following is a security best practice when using social networking sites?
Understanding and using the available privacy settings.
 
Which scenario might indicate a reportable insider threat security incident?
A coworker is observed using a personal electronic device in an area where their use is prohibited.
 
Based on the description that follows how many potential insider threat indicators are displayed?
3 or more indicators
 
What can help to protect the data on your personal mobile device
Secure personal mobile devices to the same level as Government-issued systems.
 
You receive an inquiry from a reporter about potentially classified information on the internet. How do you respond?
Refer the reporter to your organization’s public affairs office
 
How should you protect a printed classified document when it is not in use?
Store it in a GSA approved vault or container.
 
Which of the following actions is appropriate after finding classified Government information on the internet?
Note any identifying information and the website’s URL
 
How many insider threat indicators does Alex demonstrate?
Three or more.
 
Which of the following information is a security risk when posted publicly on your social networking profile?
Your birthday
 
Which may be a security issue with compressed urls?
There is no way to know where the link actually leads.
 
Which of the following may help to prevent inadvertent spillage?
Label all files, removable media, and subject headers with appropriate classification markings.
 
A colleague asks to leave a report containing protected health information (PHI) on his desk overnight so he can continue working on it the next day. How do you respond?
tell your colleague that it needs to be secured in a cabinet or container
 
**Insider Threat Which type of behavior should you report as a potential insider threat?
Hostility or anger toward the United States and its policies.
 
Which of the following represents an ethical use of your Government-furnished equipment (GFE)?
E-mailing your co-workers to let them know you are taking a sick day
 
Which of the following is NOT an example of sensitive information?
press release data
 
What do you do if a spillage occurs?
Immediately notify your security point of contact.
 
What does Personally Identifiable information (PII) include?
Social Security Number, date and place of birth, mother’s maiden name
 
What is an indication that malicious code is running on your system?
file corruption
 
What should you consider when using a wireless keyboard with your home computer?
Reviewing and configuring the available security features, including encryption.
 
(Physical Security) which Cyberspace Protection Condition (CPCON) establishes a protection priority focus on critical and essential functions only?
CPCON 2 (High: Critical and Essential Functions) – CPCON 1 (Very High: Critical Functions) CPCON 3 (Medium: Critical, Essential, and Support Functions) CPCON 4 (Low: All Functions) CPCON 5 (Very Low: All Functions)
 
Which of the following is true of protecting classified data?
Classified material must be appropriately marked.
 
What is required for an individual to access classified data?
Appropriate clearance; signed and approved non-disclosure agreement; and need-to-know.
 
Which of the following is a best practice for physical security?
Report suspicious activity.
 
Which of the following should be reported as a potential security incident?
A coworker removes sensitive information without authorization
 
What are some potential insider threat indicators?
difficult life circumstances such as substance abuse, divided loyalty or allegiance to the U.S., and extreme, persistent interpersonal difficulties
 
When is the best time to post details of your vacation activities on your social networking website?
When your vacation is over, and you have returned home.
 
When can you check personal email on your government furnished equipment?
If your organization allows it.
 
Which of the following does not constitute spillage
Classified information that should be unclassified and is downgraded.
 
Which of the following is a best practice to protect information about you and your organization on social networking sites and applications?
Use only personal contact information when establishing personal social networking accounts, never use Government contact information.
 
You have reached the office door to exit your controlled area. As a security best practice, what should you do before exiting?
Remove your security badge, common access card (CAC), or personal identity verification (PIV) card.
 
What certificates are contained on the Common Access Card (CAC)?
Identification, encryption, and digital signature
 
How should you protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card?
Store it in a shielded sleeve to avoid chip cloning.
 
Which is it appropriate to have your security badge visible within a Sensitive Compartmented Information Facility (SCIF)
At all times when in the facility
 
What are the requirements to be granted access to sensitive compartmented information (SCI)?
The proper security clearance and indoctrination into the SCI program
 
Which is a risk associated with removable media?
Spillage of classified information.
 
While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?
Since the URL does not start with “https,” do not provide your credit card information.
 
What helps protect from spear phishing?
be wary of suspicious e-mails that use your name and/or appear to come from inside your organization.
 
What is a way to prevent the download of viruses and other malicious code when checking your e-mail?
View email in plain text and don’t view email in Preview Pane.
 
Which of the following is not a best practice to preserve the authenticity of your identity?
Write your password down on a device that only you access.
 
Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email?
Do not access links or hyperlinked media such as buttons and graphics in email messages.
 
What is best practice while traveling with mobile computing devices?
Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.
 
A Coworker has asked if you want to download a programmers game to play at work. what should be your response be?
I’ll pass
 
What is a rule for removable media, other portable electronic devices (PEDs), and mobile computing devices to protect Government systems?
Do not use any personally owned/non-organizational removable media on your organization’s systems.
 
A man you do not know is trying to look at your Government-issued phone and has asked to use it. What should you do?
Decline to lend the man your phone.
 
What is a security best practice to employ on your home computer?
Create separate user accounts with strong individual passwords.
 
(Spillage) What should you do if a reporter asks you about potentially classified information on the web?
Refer the reporter to your organization’s public affairs office.
 
(Spillage) Which of the following is a good practice to aid in preventing spillage?
Be aware of classification markings and all handling caveats.
 
*Social Networking Your cousin posted a link to an article with an incendiary headline on social media. What action should you take?
Research the source of the article to evaluate its credibility and reliability
 
(Spillage) After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know this project is classified. What should be your response?
Attempt to change the subject to something non-work related, but neither confirm nor deny the article’s authenticity.
 
(Spillage) What should you do when you are working on an unclassified system and receive an email with a classified attachment?
Call your security point of contact immediately.
 
(Spillage) What is required for an individual to access classified data?
Appropriate clearance; signed and approved non-disclosure agreement; and need-to-know.
 
(Spillage) When classified data is not in use, how can you protect it?
Store classified data appropriately in a GSA-approved vault/container.
 
(Insider Threat) A colleague vacations at the beach every year, is married and a father of four, his work quality is sometimes poor, and he is pleasant to work with. How many potential insider threat indicators does this employee display?
0 indicators
 
(Insider Threat) Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague is playful and charming, consistently wins performance awards, and is occasionally aggressive in trying to access classified information.
1 indicators
 
(Spillage) What type of activity or behavior should be reported as a potential insider threat?
Coworker making consistent statements indicative of hostility or anger toward the United States and its policies.
 
Which of the following is NOT an appropriate way to protect against inadvertent spillage?
Use the classified network for all work, including unclassified work
 
(Spillage) What advantages do “insider threats” have over others that allows them to cause damage to their organizations more easily?
Insiders are given a level of trust and have authorized access to Government information systems.
 
(Spillage) Which of the following is a best practice to protect information about you and your organization on social networking sites and applications?
Use only personal contact information when establishing personal social networking accounts, never use Government contact information.
 
(Spillage) When is the safest time to post details of your vacation activities on your social networking website?
When your vacation is over, after you have returned home
 
(social networking) When is the safest time to post details of your vacation activities on your social networking profile?
After you have returned home following the vacation
 
(Spillage) What level of damage can the unauthorized disclosure of information classified as confidential reasonably be expected to cause?
Damage to national security
 
(Spillage) Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?
Secret
 
(Spillage) Which of the following practices may reduce your appeal as a target for adversaries seeking to exploit your insider status?
Remove your security badge after leaving your controlled area or office building.
 
(Sensitive Information) What type of unclassified material should always be marked with a special handling caveat?
For Official Use Only (FOUO)
 
(Sensitive Information) Which of the following is NOT an example of sensitive information?
Press release data
 
(Sensitive Information) Which of the following is true about unclassified data?
When unclassified data is aggregated, its classification level may rise.
 
(Sensitive Information) Which of the following represents a good physical security practice?
Use your own security badge, key code, or Common Access Card (CAC)/Personal Identity Verification (PIV) card.
 
(Sensitive Information) What certificates are contained on the Common Access Card (CAC)?
Identification, encryption, and digital signature
 
(Sensitive Information) What should you do if a commercial entity, such as a hotel reception desk, asks to make a photocopy of your Common Access Card (CAC) for proof of Federal Government employment?
Do not allow your CAC to be photocopied.
 
(Sensitive Compartmented Information) What describes how Sensitive Compartmented Information is marked?
Approved Security Classification Guide (SCG)
 
(Sensitive Compartmented Information) Which of the following best describes the compromise of Sensitive Compartmented Information (SCI)?
A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.
 
(Sensitive Compartmented Information) What portable electronic devices (PEDs) are allow in a Secure Compartmented Information Facility (SCIF)?
Government-owned PEDs, if expressly authorized by your agency.
 
(Malicious Code) What are some examples of malicious code?
Viruses, Trojan horses, or worms
 
(Malicious Code) Which of the following is NOT a way that malicious code spreads?
Legitimate software updates
 
(Malicious Code) While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?
Since the URL does not start with “https,” do not provide your credit card information.
 
(Malicious Code) Which email attachments are generally SAFE to open?
Attachments contained in a digitally signed email from someone known
 
(Malicious Code) What is a common indicator of a phishing attempt?
It includes a threat of dire circumstances.
 
(Malicious Code) Which of the following is true of Internet hoaxes?
They can be part of a distributed denial-of-service (DDoS) attack.
 
(Malicious Code) Upon connecting your Government-issued laptop to a public wireless connection, what should you immediately do?
Connect to the Government Virtual Private Network (VPN).
 
(Malicious Code) A coworker has asked if you want to download a programmer’s game to play at work. What should be your response?
I’ll pass
 
(Malicious Code) What are some examples of removable media?
Memory sticks, flash drives, or external hard drives
 
(Malicious Code) Which are examples of portable electronic devices (PEDs)?
laptops, fitness bands, tablets, smartphones, electric readers, and Bluetooth devices
 
(Malicious Code) What is a good practice to protect data on your home wireless systems?
Ensure that the wireless security features are properly configured.
 
(social networking) When may you be subjected to criminal, disciplinary, and/or administrative action due to online misconduct?
If you participate in or condone it at any time
 
(controlled unclassified information) Which of the following is NOT an example of CUI?
press release data
 
(controlled unclassified information) Which of the following is NOT correct way to protect CUI?
CUI may be stored on any password-protected system.
 
(Physical Security) which Cyberspace Protection Condition (CPCON) establishes a protection priority focus on critical and essential functions only?
(Answer) CPCON 2 (High: Critical and Essential Functions) – CPCON 1 (Very High: Critical Functions) CPCON 3 (Medium: Critical, Essential, and Support Functions) CPCON 4 (Low: All Functions) CPCON 5 (Very Low: All Functions)
 
(Identity Management) What certificates are contained on the Common Access Card (CAC)?
Identification, encryption, and digital signature
 
(Identity Management) Which of the following is an example of two-factor authentication?
Your password and the second commonly includes a text with a code sent to your phone
 
(Sensitive Information) What guidance is available from marking Sensitive Information information (SCI)?
Security Classification Guide (SCG)
 
(Sensitive Information) What must the dissemination of information regarding intelligence sources, methods, or activities follow?
The Director of National Intelligence.
 
(removable media) If an incident occurs involving removable media in a Sensitive Compartmented Information Facility (SCIF), what action should you take?
Notify your security point of contact
 
Which of the following actions can help to protect your identity?
Order a credit report annually
 
What is whaling?
Looking at your MOTHER, and screaming “THERE SHE BLOWS!!” (A type of phishing targeted at senior officials) Which is still your FAT A$$ MOTHER!
 
Which is a best practice that can prevent viruses and other malicious code from being downloaded when checking your e-mail?
Do not access website links, buttons, or graphics in e-mail
 
What type of social engineering targets particular individuals, groups of people, or organizations?
Spear phishing
 
(Travel) Which of the following is a concern when using your Government-issued laptop in public?
Others may be able to view your screen.
 
(GFE) When can you check personal e-mail on your Government-furnished equipment (GFE)?
If allowed by organizational policy
 
(Mobile Devices) Which of the following statements is true?
Mobile devices and applications can track your location without your knowledge or consent.
 
(Mobile Devices) When can you use removable media on a Government system?
When operationally necessary, owned by your organization, and approved by the appropriate authority
 
(Home computer) Which of the following is best practice for securing your home computer?
Create separate accounts for each user
 
*SPILLAGE*
Which of the following may be helpful to prevent spillage?
Be aware of classification markings and all handling caveats.
 
*SPILLAGE*
Which of the following may be helpful to prevent spillage?
Label all files, removable media, and subject headers with appropriate classification markings.
 
* CLASSIFIED DATA*
Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?
Secret
 
*CLASSIFIED DATA*
What is a good practice to protect classified information?
Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material.
 
*INSIDER THREAT*
Based on the description below how many potential insider threat indicators are present? A colleague often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?
3 or more indicators
 
*INSIDER THREAT*
What threat do insiders with authorized access to information or information systems pose?
They may wittingly or unwittingly use their authorized access to perform actions that result in the loss or degradation of resources or capabilities.
 
*SOCIAL NETWORKING*
When may you be subject to criminal, disciplinary, and/or administrative action due to online misconduct?
If you participate in or condone it at any time.
 
*SOCIAL NETWORKING*
When is the safest time to post details of your vacation activities on your social networking profile?
After you have returned home following the vacation.
 
*UNCONTROLLED CLASSIFIED INFORMATION*
Which of the following is NOT an example of CUI?
Press release data
 
Select the information on the data sheet that is personally identifiable information (PII) But not protected health information (PHI)
Jane Jones
Social security number: 123-45-6789
 
Select the information on the data sheet that is protected health information (PHI)
Jane has been Dr…ect patient..ect.
 
*PHYSICAL SECURITY*
At which Cyberspace Protection Condition (CPCON) is the priority focus on critical and essential functions?
Answer: CPCON 2
 
*PHYSICAL SECURITY*
Within a secure area, you see an individual who you do not know and is not wearing a visible badge
Ask the individual to see an identification badge.
 
*IDENTITY MANAGEMENT*
What certificates does the Common Access Card (CAC) or Personal Identity Verification (PIV) card contain?
Identification, encryption, and digital signature
 
*IDENTITY MANAGEMENT*
Which of the following is an example of a strong password?
eA1xy2!P
 
*SENSITIVE COMPARTMENTED INFORMATION*
When faxing Sensitive Compartmented Information (SCI), what actions should you take?
Mark SCI documents appropriately and use an approved SCI fax machine.
 
*SENSITIVE COMPARTMENTED INFORMATION*
When is it appropriate to have your security badge visible within a sensitive compartmented information facility (SCIF)?
At all times while in the facility.
 
*REMOVABLE MEDIA IN A SCIF*
What action should you take when using removable media in a Sensitive Compartmented Information Facility (SCIF)?
Identify and disclose it with local Configuration/Change Management Control and Property Management authorities
 
Which of the following is true of telework?
You must have permission from your organization.
 
*MALICIOUS CODE*
Which of the following is NOT a way malicious code spreads?
Legitimate software updates
 
*WEBSITE USE*
Which of the following statements is true of cookies?
You should only accept cookies from reputable, trusted websites.
 
*SOCIAL ENGINEERING*
How can you protect yourself from internet hoaxes?
Use online sites to confirm or expose potential hoaxes
 
*SOCIAL ENGINEERING*
How can you protect yourself from social engineering?
Follow instructions given only by verified personnel
 
*SOCIAL ENGINEERING*
What action should you take with an e-mail from a friend containing a compressed Uniform Resource Locator (URL)?
Investigate the link’s actual destination using the preview feature
 
*TRAVEL*
Which of the following is a concern when using your Government-issued laptop in public?
Others may be able to view your screen.
 
*USE OF GFE*
What is a critical consideration on using cloud-based file sharing and storage applications on your Government-furnished equipment (GFE)?
Determine if the software or service is authorized
 
*MOBILE DEVICES*
Which of the following is an example of near field communication (NFC)?
A smartphone that transmits credit card payment information when held in proximity to a credit card reader.
 
*MOBILE DEVICES*
Which of the following is an example of removable media?
Flash Drive
 
*HOME COMPUTER SECURITY*
Which of the following is a best practice for securing your home computer?
Create separate accounts for each user.
 
*Spillage
A user writes down details marked as Secret from a report stored on a classified system and uses those details to draft a briefing on an unclassified system without authorization. What is the best choice to describe what has occurred?
Spillage because classified data was moved to a lower classification level system without authorization.
 
*Spillage
What should you do when you are working on an unclassified system and receive an email with a classified attachment?
Call your security point of contact immediately
 
*Spillage
Which of the following demonstrates proper protection of mobile devices?
Linda encrypts all of the sensitive data on her government-issued mobile devices.
 
*Spillage
What should you do if a reporter asks you about potentially classified information on the web?
Ask for information about the website, including the URL.
 
*Spillage
.What should you do if a reporter asks you about potentially classified information on the web?
Refer the reporter to your organization’s public affairs office.
 
*Spillage
What is a proper response if spillage occurs?
~Immediately notify your security POC.
 
**Classified Data
When classified data is not in use, how can you protect it?
Store classified data appropriately in a GSA-approved vault/container.
 
**Classified Data
What is required for an individual to access classified data?
Appropriate clearance, a signed and approved non-disclosure agreement, and need-to-know
 
**Classified Data
Which classification level is given to information that could reasonably be expected to cause serious damage to national security?
Secret
 
**Classified Data
What is a good practice to protect classified information?
Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material.
 
**Classified Data
Which of the following can an unauthorized disclosure of information classified as Confidential reasonably be expected to cause?
Damage to national security
 
**Insider Threat
A colleague has visited several foreign countries recently, has adequate work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his car repossessed. How many potential insider threat indicators does this employee display?
1 Indicator(wrong)
~3 or more indicators
 
**Insider Threat
A colleague vacations at the beach every year, is married and a father of four, his work quality is sometimes poor, and he is pleasant to work with. How many potential insider threat indicators does this employee display?
0 indicators
 
**Insider Threat
How many potential insider threat indicators does a coworker who often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?
3 or more indicators
 
**Insider Threat
How many potential insider threat indicators does a person who is playful and charming, consistently wins performance awards, but is occasionally aggressive in trying to access sensitive information display?
1 indicator
 
**Insider Threat
What advantages do “insider threats” have over others that allows them to cause damage to their organizations more easily?
Insiders are given a level of trust and have authorized access to Government information systems
 
**Insider Threat
What type of activity or behavior should be reported as a potential insider threat?
Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.
 
**Insider Threat
Which of the following should be reported as a potential security incident?
A coworker removes sensitive information without authorization
 
**Insider Threat
Which of the following should be reported as a potential security incident (in accordance with you Agency’s insider threat policy)?
~A coworker brings a personal electronic device into a prohibited area.
 
**Social Networking
When is the safest time to post details of your vacation activities on your social networking website?
When vacation is over, after you have returned home
 
**Social Networking
What should you do if you receive a game application request that includes permission to access your friends, profile information, cookies, and sires visited?
Decline the request
 
*Sensitive Information
Under which circumstances is it permitted to share an unclassified draft document with a non-DoD professional discussion group?
As long as the document is cleared for public release, you may share it outside of DoD.
 
*Sensitive Information
What is the best example of Personally Identifiable Information (PII)?
Date and place of birth
 
*Sensitive Information
Which of the following is the best example of Personally Identifiable Information (PII)?
Passport number
 
*Sensitive Information
Which of the following is an example of Protected Health Information (PHI)?
Medical test results
 
*Sensitive Information
What type of unclassified material should always be marked with a special handling caveat?
For Official Use Only (FOUO)
 
*Sensitive Information
Under what circumstances could classified information be considered a threat to national security?
If aggregated, the information could become classified.
 
**Physical Security
What is a good practice for physical security?
Challenge people without proper badges.
 
**Physical Security
At which Cyberspace Protection Condition (CPCON) is the priority focus on critical functions only?
CPCON 1
 
**Identity Management
Your DoD Common Access Card (CAC) has a Public Key Infrastructure (PKI) token approved for access to the NIPRNet. In which situation below are you permitted to use your PKI token?
On a NIPRNet system while using it for a PKI-required task
 
**Identity Management
Which of the following is the nest description of two-factor authentication?
Something you possess, like a CAC, and something you know, like a PIN or password
 
**Identity management
Which is NOT a sufficient way to protect your identity?
Use a common password for all your system and application logons.
 
**Identity management
What is the best way to protect your Common Access Card (CAC)?
Maintain possession of it at all times.
 
*Sensitive Compartmented Information
What is a Sensitive Compartmented Information (SCI) program?
A program that segregates various type of classified information into distinct compartments for added protection and dissemination for distribution control.
 
*Sensitive Compartmented Information
Which of the following best describes the compromise of Sensitive Compartmented Information (SCI)?
A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.
 
*Sensitive Compartmented Information
When should documents be marked within a Sensitive Compartmented Information Facility (SCIF)
~All documents should be appropriately marked, regardless of format, sensitivity, or classification.
Unclassified documents do not need to be marked as a SCIF.
Only paper documents that are in open storage need to be marked.
Only documents that are classified Secret, Top Secret, or SCI require marking. (Wrong)
 
*Sensitive Compartmented Information
Which must be approved and signed by a cognizant Original Classification Authority (OCA)?
Security Classification Guide (SCG)
 
**Removable Media in a SCIF
What must users ensure when using removable media such as compact disk (CD)?
It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number.
 
*Malicious Code
What are some examples of malicious code?
Viruses, Trojan horses, or worms
 
**Website Use
While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?
Since the URL does not start with “https,” do not provide you credit card information.
 
**Social Engineering
Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email?
Do not access links or hyperlinked media such as buttons and graphics in email messages.
 
**Social Engineering
What is TRUE of a phishing attack?
Phishing can be an email with a hyperlink as bait.
 
**Social Engineering
Which of the following is a way to protect against social engineering?
Follow instructions given only by verified personnel.
 
**Travel
What is a best practice while traveling with mobile computing devices?
Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.
 
**Use of GFE
Under what circumstances is it acceptable to use your Government-furnished computer to check personal e-mail and do other non-work-related activities?
If allowed by organizational policy
 
**Mobile Devices
Which is a rule for removable media, other portable electronic devices (PEDs), and mobile computing devices to protect Government systems?
Do not use any personally owned/non-organizational removable media on your organization’s systems.
 
**Mobile Devices
Which of the following helps protect data on your personal mobile devices?
Secure personal mobile devices to the same level as Government-issued systems.
 
**Home Computer Security
How can you protect your information when using wireless technology?
Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.
 
What is the best response if you find classified government data on the internet?
Note any identifying information, such as the website’s URL, and report the situation to your security POC.
 
What information posted publicly on your personal social networking profile represents a security risk?
Your place of birth
 
What is the best example of Protected Health Information (PHI)?
Your health insurance explanation of benefits (EOB)
 
What does Personally Identifiable Information (PII) include?
Social Security Number; date and place of birth; mother’s maiden name
 
What certificates are contained on the DoD Public Key Infrastructure (PKI) implemented by the Common Access Card (CAC)/Personal Identity Verification (PIV) card?
Identification, encryption, and digital signature
 
What describes how Sensitive Compartmented Information is marked?
Approved Security Classification Guide (SCG)
 
Which is a risk associated with removable media?
Spillage of classified information.
 
What is an indication that malicious code is running on your system?
File corruption
 
What is a valid response when identity theft occurs?
Report the crime to local law enforcement.
 
What is whaling?
A type of phishing targeted at high-level personnel such as senior officials.
 
What is a best practice to protect data on your mobile computing device?
Lock your device screen when not in use and require a password to reactivate.
 
What is a possible indication of a malicious code attack in progress?
A pop-up window that flashes and warns that your computer is infected with a virus.
 
Which of the following may be helpful to prevent inadvertent spillage?
Which of the following may be helpful to prevent inadvertent spillage?
 
What should you do after you have ended a call from a reporter asking you to confirm potentially classified info found on the web?
Alert your security point of contact.
 
Which of the following is NOT an example of sensitive information?
Which of the following is NOT an example of sensitive information?
 
PII
SSN, date and place of birth, mother’s maiden name, biometric records, PHI, passport number
 
PHI
Subset of PII, health information that identifies the individual, relates to physical or mental health of an individual, provision of health care to an individual, or payment of healthcare for individual
 
Which of the following is NOT a typical result from running malicious code?
Disable cookies
 
What kind of information could reasonably be expected to cause serious damage to national security in the event of unauthorized disclosure?
Secret
 
Telework
Have your permissions from your organization, follow your organization guideline, use authorized equipment and software, employ cyber security best practice, perform telework in dedicated when home.
 
Which of the following should be reported as a potential security incident (in accordance with your Agency’s insider threat policy)?
A coworker brings a personal electronic device into prohibited areas.
 
A colleague complains about anxiety and exhaustion, makes coworkers uncomfortable by asking excessive questions about classified projects, and complains about the credit card bills that his wife runs up. How many potential insider threat indicators does this employee display?
3 or more indicators
 
A colleague has won 10 high-performance awards, can be playful and charming, is not currently in a relationship, and occasionally aggressive in trying to access sensitive information. How many potential insider threat indicators does this employee display?
1 indicator
 
What information most likely presents a security risk on your personal social networking profile?
Mother’s maiden name
 
Which of the following represents a good physical security practice?
Use your own security badge, key code, or Common Access Card (CAC)/Personal Identity Verification (PIC) card.
 
How should you protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card?
Store it in a shielded sleeve to avoid chip cloning.
 
Which of the following statements is NOT true about protecting your virtual identity?
Use personal information to help create strong passwords.
 
While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?
Since the URL does not start with “https,” do not provide your credit card information.
 
You receive an email from the Internal Revenue Service (IRS) demanding immediate payment of back taxes of which you were not aware. The email provides a website and a toll-free number where you can make payment. What action should you take?
Contact the IRS using their publicly available, official contact information.
 
Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email?
Do not access links or hyperlinked media such as buttons and graphics in email messages.
 
Which of the following is NOT true of traveling overseas with a mobile phone?
Physical security of mobile phones carried overseas is not a major issue.
 
A coworker has asked if you want to download a programmer’s game to play at work. What should be your response?
I’ll pass.
 
A coworker wants to send you a sensitive document to review while you are at lunch and you only have your personal tablet. What should you do?
Never allow sensitive data on non-Government-issued mobile devices.
 
A man you do not know is trying to look at your Government-issued phone and has asked to use it. What should you do?
Decline to lend the man your phone.
 
How can you protect your information when using wireless technology?
Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.
 
What should you do if a reporter asks you about potentially classified information on the web?
Neither confirm or deny the information is classified.
 
Which of the following may be helpful to prevent inadvertent spillage?
Label all files, removable media, and subject headers with appropriate classification markings.
 
What kind of information could reasonably be expected to cause serious damage to national security in the event of unauthorized disclosure?
Secret
 
Which of the following is NOT true concerning a computer labeled SECRET?
May be used on an unclassified network.
 
A colleague complains about anxiety and exhaustion, makes coworkers uncomfortable by asking excessive questions about classified projects, and complains about the credit card bills that his wife runs up. How many potential insider threat indicators does this employee display?
3 or more indicators
 
Which of the following should be reported as a potential security incident?
A coworker removes sensitive information without approval.
 
Which of the following should be reported as a potential security incident (in accordance with your Agency’s insider threat policy)?
A coworker brings a personal electronic device into prohibited areas.
 
When would be a good time to post your vacation location and dates on your social networking website?
When you return from your vacation.
 
In setting up your personal social networking service account, what email address should you use?
Your personal email address.
 
Which of the following is NOT a correct way to protect sensitive information?
Sensitive information may be stored on any password-protected system.
 
Which of these is true of unclassified data?
It’s classification level may rise when aggregated.
 
Is it permitted to share an unclassified draft document with a non-DoD professional discussion group?
As long as the document is cleared for public release, you may share it outside of DoD.
 
Within a secure area, you see an individual you do not know. Her badge is not visible to you. What is the best course of action?
Ask the individual to identify herself.
 
How should you protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card?
Store it in a shielded sleeve to avoid chip cloning.
 
Your DoD Common Access Card (CAC) has a Public Key Infrastructure (PKI) token approves for access to the NIPRNET. In which situation below are you permitted to use your PKI token?
On a NIPRNET system while using it for a PKI-required task
 
After clicking on a link on a website, a box pops up and asks if you want to run an application. Is it okay to run it?
No. Only allow mobile code to run from your organization or your organization’s trusted sites.
 
Upon connecting your Government- issued laptop to a public wireless connection, what should you immediately do?
Connect to the Government Virtual Private Network (VPN).
 
What do you do if spillage occurs?
Immediately notify your security point of contact.
 
What should you do after you have ended a call from a reporter asking you to confirm potentially classified information found on the web?
Alert your security point of contact.
 
Which of the following is NOT a requirement for telework?
You must possess security clearance eligibility to telework.
 
Who can be permitted access to classified data?
Only persons with appropriate clearance, a non-disclosure agreement, and need-to-know can access classified data.
 
A colleague has won 10 high-performance awards, can be playful and charming, is not currently in a relationship, and is occasionally aggressive in trying to access sensitive information. How many potential insiders threat indicators does this employee display?
1 indicator
 
A colleague has visited several foreign countries recently, has adequate work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his car repossessed. How many potential insiders threat indicators does this employee display?
3 or more indicators
 
A colleague complains about anxiety and exhaustion, makes coworkers uncomfortable by asking excessive questions about classified projects, and complains about the credit card bills that his wife runs up. How many potential insiders threat indicators does this employee display?
3 or more indicators
 
In setting up your personal social networking service account, what email address should you use?
Your personal email address
 
What information most likely presents a security risk on your personal social networking profile?
Your place of birth
 
Which may be a security issue with compressed Uniform Resource Locators (URLs)?
There is no way to know where the link actually leads.
 
Which of the following is NOT an example of sensitive information?
Press release data
 
Is it permitted to share an unclassified draft document with a non-DoD professional discussion group?
As long as the document is cleared for public release, you may release it outside of DoD
 
Which of the following is an example of Protected Health Information (PHI)?
I’ve tried all the answers and it still tells me off. Examples are: Patient names, Social Security numbers, Driver’s license numbers, insurance details, and birth dates
 
Which of the following represents a good physical security practice?
Use your own security badge, key code, or Common Access Card (CAC)/Personal Identity Verification (PIC) card.
 
Which of the following is NOT a good way to protect your identity?
Use a single, complex password for your system and application logons.
 
Which of the following statements is TRUE about the use of DoD Public Key Infrastructure (PKI) tokens?
Always use DoD PKI tokens within their designated classification level.
 
Which of the following is NOT a typical means for spreading malicious code?
Patching from a trusted source
 
Which of the following is a practice that helps to protect you from identity theft?
Ordering a credit report annually
 
Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email?
Do not access links or hyperlinked media such as buttons and graphics in email messages.
 
You receive an unexpected email from a friend: “I think you’ll like this: https://tinyurl.com/2fcbvy.” What action should you take?
Use TinyURL’s preview feature to investigate where the link leads.
 
You receive an email from the Internal Revenue Service (IRS) demanding immediate payment of back taxes of which you were not aware. The email provides a website and a toll-free number where you can make payment. What action should you take?
Contact the IRS
 
When using your government-issued laptop in public environments, with which of the following should you be concerned?
The potential for unauthorized viewing of work-related information displayed on your screen.
 
Under what circumstances is it acceptable to check personal email on Government-furnished equipment (GFE)?
If your organization allows it.
 
Which of the following is NOT a best practice to protect data on your mobile computing device?
Lock your device screen when not in use and require a password to reactivate.
 
When checking in at the airline counter for a business trip, you are asked if you would like to check your laptop bag. This bag contains your government-issued laptop. What should you do?
I’ve tried all the answers and it still tells me off, part 2. Decline So That You Maintain Physical Control of Your Government-Issued Laptop.
 
How can you protect your information when using wireless technology?
Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.
Are you a Boot B*cht?
Are you a Boot B*cht?
Yes
 
It is getting late on Friday. You are reviewing your employees annual self evaluation. Your comments are due on Monday. You can email your employees information to yourself so you can work on it this weekend and go home now. Which method would be the BEST way to send this information?
Use the government email system so you can encrypt the information and open the email on your government issued laptop
 
What should you do if someone asks to use your government issued mobile device (phone/laptop..etc)?
Decline to lend your phone / laptop
 
Where should you store PII / PHI?
Information should be secured in a cabinet or container while not in use
 
Of the following, which is NOT an intelligence community mandate for passwords?
Maximum password age of 45 days
 
Which of the following is NOT Government computer misuse?
Checking work email
 
Which is NOT a telework guideline?
Taking classified documents from your workspace
 
What should you do if someone forgets their access badge (physical access)?
Alert the security office
 
What can you do to protect yourself against phishing?
All of the above
 
What should you do to protect classified data?
Answer 1 and 2 are correct
 
What action is recommended when somebody calls you to inquire about your work environment or specific account information?
Ask them to verify their name and office number
 
If classified information were released, which classification level would result in “Exceptionally grave damage to national security”?
Top Secret
 
Which of the following is NOT considered sensitive information?
Sanitized information gathered from personnel records
 
Which of the following is NOT a criterion used to grant an individual access to classified data?
Senior government personnel, military or civilian
 
Of the following, which is NOT a problem or concern of an Internet hoax?
Directing you to a website that looks real
 
Media containing Privacy Act information, PII, and PHI is not required to be labeled.
FALSE
 
Which of the following is NOT a home security best practice?
Setting weekly time for virus scan when you are not on the computer and it is powered off
 
Which of the following best describes wireless technology?
It is inherently not a secure technology
 
You are leaving the building where you work. What should you do?
Remove your security badge
 
Which of the following is a good practice to avoid email viruses?
Delete email from senders you do not know
 
What is considered a mobile computing device and therefore shouldn’t be plugged in to your Government computer?
All of the above
 
Which is NOT a way to protect removable media?
As a best practice, labeling all classified removable media and considering all unlabeled removable media as unclassified
 
What is NOT Personally Identifiable Information (PII)?
Hobby
 
Of the following, which is NOT a method to protect sensitive information?
After work hours, storing sensitive information in unlocked containers, desks, or cabinets if security is not present
 
There are many travel tips for mobile computing. Which of the following is NOT one?
When using a public device with a card reader, only use your DoD CAC to access unclassified information
 
The use of webmail is
is only allowed if the organization permits it
 
What is considered ethical use of the Government email system?
Distributing Company newsletter
 
Which of the following attacks target high ranking officials and executives?
Whaling
 
What constitutes a strong password?
all of the above
 
You are logged on to your unclassified computer and just received an encrypted email from a co-worker. The email has an attachment whose name contains the word “secret”. What should you do?
Contact your security POC right away
 
Which is a way to protect against phishing attacks?
Look for digital certificates
 
You receive an email from a company you have an account with. The email states your account has been compromised and you are invited to click on the link in order to reset your password. What action should you take?
Notify security
 
You are having lunch at a local restaurant outside the installation, and you find a cd labeled “favorite song”. What should you do?
Leave the cd where it is
 
How should you securely transport company information on a removable media?
Encrypt the removable media
 
Should you always label your removable media?
Yes
 
Which of the following is NOT Protected Health Information (PHI)?
Medical care facility name
 
If authorized, what can be done on a work computer?
Check personal email
 
Spear Phishing attacks commonly attempt to impersonate email from trusted entities. What security device is used in email to verify the identity of sender?
Digital Signatures
 
What type of security is “part of your responsibility” and “placed above all else?”
Physical
 
If your wireless device is improperly configured someone could gain control of the device? T/F
TRUE
 
Which of the following is a proper way to secure your CAC/PIV?
Remove and take it with you whenever you leave your workstation
 
What actions should you take prior to leaving the work environment and going to lunch?
All of the above
 
P2P (Peer-to-Peer) software can do the following except:
Allow attackers physical access to network assets
 
How can you guard yourself against Identity theft?
All of the above
 
When leaving your work area, what is the first thing you should do?
Remove your CAC/PIV
 
Using webmail may bypass built in security features.
TRUE
 
Of the following, which is NOT a characteristic of a phishing attempt?
Directing you to a web site that is real
 
Classified Information can only be accessed by individuals with
All of the above
 
Which of the following definitions is true about disclosure of confidential information?
Damage to national security
 
It is permissible to release unclassified information to the public prior to being cleared.
False
 
Which of the following is NOT sensitive information?
Unclassified information cleared for public release
 
What should you do to protect yourself while on social networks?
Validate all friend requests through another source before confirming them
 
Which is NOT a method of protecting classified data?
Assuming open storage is always authorized in a secure facility
 
What can you do to prevent spillage?
all of the above
 
Which of the following makes Alex’s personal information vulnerable to attacks by identity thieves?
Carrying his Social Security Card with him
 
DoD employees are prohibited from using a DoD CAC in card-reader-enabled public device
TRUE
 
Which of the following is an example of malicious code?
Trojan horses
 
Which of the following is NOT PII?
Mother’s maiden name
 
Classified Information is
Assigned a classification level by a supervisor
 
Maria is at home shopping for shoes on Amazon.com. Before long she has also purchased shoes from several other websites. What can be used to track Maria’s web browsing habits?
Cookies
 
Which is an untrue statement about unclassified data?
If aggregated, the classification of the information may not be changed
 
A medium secure password has at least 15 characters and one of the following.
Special character
 
PII, PHI, and financial information is classified as what type of information?
Sensitive
 
The CAC/PIV is a controlled item and contains certificates for:
All of the above
 
An individual who has attempted to access sensitive information without need-to-know and has made unusual requests for sensitive information is displaying indicators of what?
Potential Insider Threat
 
Which of the following is NOT a social engineering tip?
Following instructions from verified personnel
 
Bob, a coworker, has been going through a divorce, has financial difficulties and is displaying hostile behavior. How many potential insider threat indicators is Bob displaying?
3
 
You are working at your unclassified system and receive an email from a coworker containing a classified attachment. What should you do?
Alert your security POC
 
You check your bank statement and see several debits you did not authorize. You believe that you are a victim of identity theft. Which of the following should you do immediately?
Monitor credit card statements for unauthorized purchases
 
Thumb drives, memory sticks, and flash drives are examples of
Removable media
 
What information relates to the physical or mental health of an individual?
PHI
 
What should be done if you find classified Government Data/Information Not Cleared for Public Release on the Internet?
Make note of any identifying information and the website URL and report it to your security office
 
All https sites are legitimate and there is no risk to entering your personal info online.
FALSE
 
When using a fax machine to send sensitive information, the sender should do which of the following?
Contact the recipient to confirm receipt
 
What should be done to protect against insider threats?
Report any suspicious behavior
 
Which of the following is NOT a potential insider threat?
Member of a religion or faith
 
Of the following, which is NOT a security awareness tip?
Remove security badge as you enter a restaurant or retail establishment
 
ActiveX is a type of this?
Mobile code
 
Which of the following is NOT a security best practice when saving cookies to a hard drive?
Looking for “https” in the URL. All https sites are legitimate.
 
Which is NOT a requirement for telework?
Telework is only authorized for unclassified and confidential information
 
Someone calls from an unknown number and says they are from IT and need some information about your computer. What should you do?
Request the user’s full name and phone number
 
Which is NOT a wireless security practice?
Turning off computer when not in use
 
Malicious code can do the following except?
Make your computer more secure
 
What type of data must be handled and stored properly based on classification markings and handling caveats?
Classified
 
What information should you avoid posting on social networking sites?
All of the above
 
A coworker has left an unknown CD on your desk. What should you do?
Put the CD in the trash
 
Which of the following is NOT a DoD special requirement for tokens?
Using NIPRNet tokens on systems of higher classification level
 
UNCLASSIFIED is a designation to mark information that does not have potential to damage national security.
TRUE
 
You receive a call on your work phone and you’re asked to participate in a phone survey. As part of the survey the caller asks for birth date and address. What type of attack might this be?
Social Engineering
 
“Spillage” occurs when
Personal information is inadvertently posted at a website
 
What should be done to sensitive data on laptops and other mobile computing devices?
Encrypt the sensitive data
 
Which of the following should be done to keep your home computer secure?
All of the above
 
How are Trojan horses, worms, and malicious scripts spread?
By email attachments
 
The following practices help prevent viruses and the downloading of malicious code except.
Scan external files from only unverifiable sources before uploading to computer

Cyber Awareness Challenge 2022 Answers

  1. Who is responsible for information/data security?
    a) The IT department
    b) Security contractors
    c) Management
    d) All computer and system users
  2. Which of the following is a clue to recognizing a phishing email?
    a) Link to unknown website
    b) Sender’s email address not recognized
    c) Threats or promises of reward
    d) a, b, and c
  3. What does MFA stand for?
    a) Most Favored Ally
    b) Multi-Factor Authentication
    c) Mechanical Function Automation
    d) Many-Fingered Athlete
  4. When traveling or working away from your main location, what steps should you take to protect your devices and data?
    a) Do not connect to “free wi-fi”
    b) When connecting to your organization’s network, use a VPN program (Virtual Private Network)
    c) Make sure no one is reading your password or data over your shoulder
    d) a, b and c
  5. If you receive a phone call from a stranger asking for information about your invoice payment process, you should:
    a) Provide full and complete answers to all questions
    b) Take all questions down and send answers via email
    c) Answer only questions for which you know the answer for sure
    d) Do not answer questions, but take the caller’s contact info, and consult your IT department and purchasing department
  6. Crucial information about a user or organization can be gained through
    a) A phone call
    b) An email with no attachments
    c) A text message
    d) a, b, and c
  7. True or False – There is no danger related to clicking on internet links or attachments that come to your email box since the organization’s firewall and virus scan have approved it.
  8. True or False – The address an email comes from cannot be faked.
  9. True or False – If you click on a unknown link or attachment in an email and then wonder “what you just clicked”, you should wait five minutes to make sure nothing happens and there is no need to contact the IT department.
  10. True or False – When disposing of old computers or other electronic devices, emptying the recycle bin or “trash can” and signing out is all that is required.
 
*Spillage After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know that this project is classified. How should you respond?
Attempt to change the subject to something non-work related, but neither confirm nor deny the article’s authenticity
 
*Spillage Which of the following may help to prevent spillage?
Label all files, removable media, and subject headers with appropriate classification markings.
 
*Spillage A user writes down details marked as Secret from a report stored on a classified system and uses those details to draft a briefing on an unclassified system without authorization. What is the best choice to describe what has occurred?
Spillage because classified data was moved to a lower classification level system without authorization.
 
*Spillage What should you do when you are working on an unclassified system and receive an email with a classified attachment?
Call your security point of contact immediately
 
*Spillage What should you do if a reporter asks you about potentially classified information on the web?
Ask for information about the website, including the URL.
 
*Spillage .What should you do if a reporter asks you about potentially classified information on the web?
Refer the reporter to your organization’s public affairs office.
 
*Spillage What should you do if you suspect spillage has occurred?
Immediately notify your security point of contact
 
*Spillage Which of the following is a good practice to prevent spillage?
Be aware of classification markings and all handling caveats.
 
*Spillage Which of the following actions is appropriate after finding classified information on the Internet?
Note any identifying information and the website’s Uniform Resource Locator (URL)
 
**Classified Data When classified data is not in use, how can you protect it?
Store classified data appropriately in a GSA-approved vault/container.
 
**Classified Data What is required for an individual to access classified data?
Appropriate clearance, a signed and approved non-disclosure agreement, and need-to-know
 
**Classified Data Which classification level is given to information that could reasonably be expected to cause serious damage to national security?
Secret
 
**Classified Data Which of the following is a good practice to protect classified information?
Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material
 
**Classified Data Which of the following is true of protecting classified data?
Classified material must be appropriately marked.
 
**Classified Data What level of damage can the unauthorized disclosure of information classified as Confidential reasonably be expected to cause?
Damage to national security
 
**Classified Data Which of the following is true of telework?
You must have permission from your organization.
 
**Classified Data Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?
Secret
 
**Classified Data How should you protect a printed classified document when it is not in use?
Store it in a General Services Administration (GSA)-approved vault or container
 
What level of damage to national security could reasonably be expected if unauthorized disclosure of Top Secret information occurred?
Exceptionally grave Damage
 
**Insider Threat Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague vacations at the beach every year, is married and a father of four, sometimes has poor work quality, and works well with his team.
~0 indicator
 
**Insider Threat How many potential insider threat indicators does a coworker who often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?
3 or more indicators
 
**Insider Threat Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague is playful and charming, consistently wins performance awards, and is occasionally aggressive in trying to access classified information.
1 indicator
 
**Insider Threat What advantages do “insider threats” have over others that allows them to cause damage to their organizations more easily?
Insiders are given a level of trust and have authorized access to Government information systems
 
**Insider Threat What type of activity or behavior should be reported as a potential insider threat?
Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.
 
**Insider Threat Which of the following should be reported as a potential security incident?
A coworker removes sensitive information without authorization
 
**Insider Threat Which scenario might indicate a reportable insider threat?
A coworker uses a personal electronic device in a secure area where their use is prohibited.
 
**Insider Threat Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague often makes others uneasy with her persistent efforts to obtain information about classified project where she has no need-to-know, is vocal about her husband overspending on credit cards, and complains about anxiety and exhaustion.
3 or more indicators
 
**Insider Threat Which type of behavior should you report as a potential insider threat?
Hostility or anger toward the United States and its policies
 
**Insider Threat Which of the following is NOT considered a potential insider threat indicator?
Treated mental health issues
 
**Insider Threat What do insiders with authorized access to information or information systems pose?
 
 
**Social Networking When is the safest time to post details of your vacation activities on your social networking profile?
After you have returned home following the vacation
 
**Insider Threat Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague abruptly becomes hostile and unpleasant after previously enjoying positive working relationships with peers, purchases an unusually expensive car, and has unexplained absences from work.
3 or more indicators
 
**Insider Threat What is an insider threat?
Someone who uses authorized access, wittingly or unwittingly, to harm national security through unauthorized disclosure or other actions that may cause the loss or degradation of resources or capabilities.
 
*Insider Threat Which of the following is a potential insider threat indicator?
Interest in learning a foreign language
 
*Insider Threat Which of the following is a potential insider threat indicator?
Unusual interest in classified information
 
*Insider Threat Which of the following is a reportable insider threat activity?
Attempting to access sensitive information without need-to-know
 
In addition to avoiding the temptation of greed to betray his country, what should Alex do differently?
Avoid talking about work outside of the workplace or with people without a need-to-know
 
How many insider threat indicators does Alex demonstrate?
Three or more
 
What should Alex’s colleagues do?
Report the suspicious behavior in accordance with their organization’s insider threat policy
 
**Insider Threat What function do Insider Threat Programs aim to fulfill?
Proactively identify potential threats and formulate holistic mitigation responses
 
**Social Networking What should you do if you receive a game application request that includes permission to access your friends, profile information, cookies, and sites visited?
Decline the request
 
**Social Networking Which of the following information is a security risk when posted publicly on your social networking profile?
Your personal e-mail address
 
**Social Networking Which of the following is a security best practice when using social networking sites?
Understanding and using the available privacy settings
 
**Social Networking When may you be subject to criminal, disciplinary, and/or administrative action due to online misconduct?
If you participate in or condone it at any time
 
**Social Networking Which of the following is a security best practice when using social networking sites?
Use only your personal contact information when establishing your account
 
**Social Networking Which of the following information is a security risk when posted publicly on your social networking profile?
Your mother’s maiden name
 
**Social Networking Your cousin posted a link to an article with an incendiary headline on social media. What action should you take?
Research the source of the article to evaluate its credibility and reliability
 
**Social Networking Which of the following best describes the sources that contribute to your online identity?
Data about you collected from all sites, apps, and devices that you use can be aggregated to form a profile of you.
 
**Social Networking As someone who works with classified information, what should you do if you are contacted by a foreign national seeking information on a research project?
Inform your security point of contact
 
**Social Networking Which piece if information is safest to include on your social media profile?
Photos of your pet
 
**Social Networking Which piece if information is safest to include on your social media profile?
Your favorite movie
 
**Social Networking Which of the following statements is true?
Adversaries exploit social networking sites to disseminate fake news.
 
How can you protect your organization on social networking sites?
Ensure there are no identifiable landmarks visible in any photos taken in a work setting that you post
 
*Controlled Unclassified Information Which of the following is NOT an example of CUI?
Press release data
 
*Controlled Unclassified Information Which of the following is NOT a correct way to protect CUI?
CUI may be stored on any password-protected system.
 
*Controlled Unclassified Information Which of the following best describes a way to safely transmit Controlled Unclassified Information (CUI)?
Paul verifies that the information is CUI, includes a CUI marking in the subject header and digitally signs an e-mail containing CUI.
 
*Controlled Unclassified Information Which is a best practice for protecting Controlled Unclassified Information (CUI)?
Store it in a locked desk drawer after working hours.
 
Which of the following is not Controlled Unclassified Information (CUI)?
Press release data
 
Which of the following is true of Unclassified information?
It does not require markings or distribution controls
 
Which of the following includes Personally Identifiable Information (PII) and Protected Health Information (PHI)?
 
 
**Physical Security What is a good practice for physical security?
Challenge people without proper badges.
 
**Physical Security At which Cyberspace Protection Condition (CPCON) is the priority focus on critical functions only?
CPCON 1
 
**Physical Security Within a secure area, you see an individual who you do not know and is not wearing a visible badge. What should you do?
Ask the individual for identification
 
**Identity Management Your DoD Common Access Card (CAC) has a Public Key Infrastructure (PKI) token approved for access to the NIPRNet. In which situation below are you permitted to use your PKI token?
On a NIPRNet system while using it for a PKI-required task
 
**Identity Management Which of the following is the nest description of two-factor authentication?
Something you possess, like a CAC, and something you know, like a PIN or password
 
**Identity management Which is NOT a sufficient way to protect your identity?
Use a common password for all your system and application logons.
 
**Identity management What is the best way to protect your Common Access Card (CAC)?
Maintain possession of it at all times.
 
**Identity management Which of the following is NOT a best practice to preserve the authenticity of your identity?
Store your Common Access Card (CAC) or Personal Identity Verification (PIV) card in a shielded sleeve ~Write your password down on a device that only you access (e.g., your smartphone) Change your password at least every 3 months Enable two-factor authentication whenever available, even for personal accounts
 
**Identity management Which of the following is an example of two-factor authentication?
Your password and a code you receive via text message
 
**Identity management Which of the following is an example of a strong password?
eA1xy2!P
 
*Sensitive Compartmented Information What is Sensitive Compartmented Information (SCI)?
A program that segregates various types of classified information into distinct compartments for added protection and dissemination or distribution control
 
*Sensitive Compartmented Information Which of the following best describes the compromise of Sensitive Compartmented Information (SCI)?
A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.
 
*Sensitive Compartmented Information When should documents be marked within a Sensitive Compartmented Information Facility (SCIF)
~All documents should be appropriately marked, regardless of format, sensitivity, or classification. Unclassified documents do not need to be marked as a SCIF. Only paper documents that are in open storage need to be marked.
 
*Sensitive Compartmented Information Which must be approved and signed by a cognizant Original Classification Authority (OCA)?
Security Classification Guide (SCG)
 
*Sensitive Compartmented Information What must the dissemination of information regarding intelligence sources, methods, or activities follow?
Directives issued by the Director of National Intelligence
 
*Sensitive Compartmented Information When is it appropriate to have your security badge visible?
At all times when in the facility
 
*Sensitive Compartmented Information What should the owner of this printed SCI do differently?
Retrieve classified documents promptly from printers
 
*Sensitive Compartmented Information What should the participants in this conversation involving SCI do differently?
Physically assess that everyone within listening distance is cleared and has a need-to-know for the information being discussed
 
*Sensitive Compartmented Information When faxing Sensitive Compartmented Information (SCI), what actions should you take?
Mark SCI documents appropriately and use an approved SCI fax machine
 
**Removable Media in a SCIF What must users ensure when using removable media such as compact disk (CD)?
It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number.
 
**Removable Media in a SCIF What portable electronic devices (PEDs) are allowed in a Sensitive Compartmented Information Facility (SCIF)?
Government-owned PEDs when expressly authorized by your agency
 
**Removable Media in a SCIF What action should you take when using removable media in a Sensitive Compartmented Information Facility (SCIF)?
Identify and disclose it with local Configuration/Change Management Control and Property Management authorities
 
*Malicious Code What are some examples of malicious code?
Viruses, Trojan horses, or worms
 
*Malicious Code Which of the following is NOT a way that malicious code spreads?
Legitimate software updates
 
*Malicious Code After visiting a website on your Government device, a popup appears on your screen. The popup asks if you want to run an application. Is this safe?
No, you should only allow mobile code to run from your organization or your organization’s trusted sites.
 
**Website Use While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?
Since the URL does not start with “https,” do not provide you credit card information.
 
**Website Use How should you respond to the theft of your identity?
Report the crime to local law enforcement
 
**Website Use Which of the following statements is true of cookies?
You should only accept cookies from reputable, trusted websites.
 
**Social Engineering Which is a best practice that can prevent viruses and other malicious code from being downloaded when checking your e-mail?
Do not access website links, buttons, or graphics in e-mail
 
**Social Engineering What is TRUE of a phishing attack?
Phishing can be an email with a hyperlink as bait.
 
**Social Engineering Which of the following is a way to protect against social engineering?
Follow instructions given only by verified personnel.
 
**Social Engineering What is whaling?
A type of phishing targeted at senior officials
 
**Social Engineering What action should you take with an e-mail from a friend containing a compressed Uniform Resource Locator (URL)?
Investigate the link’s actual destination using the preview feature
 
**Social Engineering How can you protect yourself from internet hoaxes?
Use online sites to confirm or expose potential hoaxes
 
**Social Engineering Which may be a security issue with compressed Uniform Resource Locators (URLs)?
They may be used to mask malicious intent.
 
**Travel What is a best practice while traveling with mobile computing devices?
Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.
 
**Travel Which of the following is true of traveling overseas with a mobile phone?
It may be compromised as soon as you exit the plane.
 
**Travel What security risk does a public Wi-Fi connection pose?
It may expose the connected device to malware.
 
**Use of GFE When can you check personal e-mail on your Government-furnished equipment (GFE)?
If allowed by organizational policy
 
**Use of GFE What is a critical consideration on using cloud-based file sharing and storage applications on your Government-furnished equipment (GFE)?
Determine if the software or service is authorized
 
**Mobile Devices Which is a rule for removable media, other portable electronic devices (PEDs), and mobile computing devices to protect Government systems?
Do not use any personally owned/non-organizational removable media on your organization’s systems.
 
**Mobile Devices What can help to protect the data on your personal mobile device?
Secure it to the same level as Government-issued systems
 
**Mobile Devices What should you do when going through an airport security checkpoint with a Government-issued mobile device?
Maintain visual or physical control of the device
 
**Home Computer Security How can you protect your information when using wireless technology?
Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.
 
**Home Computer Security What should you consider when using a wireless keyboard with your home computer?
Reviewing and configuring the available security features, including encryption
 
**Home Computer Security Which of the following is a best practice for securing your home computer?
Create separate accounts for each user
 
(Spillage) What should you do if a reporter asks you about potentially classified information on the web?
Refer the reporter to your organization’s public affairs office.
 
(Spillage) Which of the following is a good practice to aid in preventing spillage?
Be aware of classification markings and all handling caveats.
 
(Spillage) After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know this project is classified. What should be your response?
Attempt to change the subject to something non-work related, but neither confirm nor deny the article’s authenticity.
 
(Spillage) What should you do when you are working on an unclassified system and receive an email with a classified attachment?
Call your security point of contact immediately.
 
(Spillage) What is required for an individual to access classified data?
Appropriate clearance; signed and approved non-disclosure agreement; and need-to-know.
 
(Spillage) When classified data is not in use, how can you protect it?
Store classified data appropriately in a GSA-approved vault/container.
 
(Insider Threat) A colleague vacations at the beach every year, is married and a father of four, his work quality is sometimes poor, and he is pleasant to work with. How many potential insider threat indicators does this employee display?
0 indicators
 
(Insider Threat) Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague is playful and charming, consistently wins performance awards, and is occasionally aggressive in trying to access classified information.
1 indicators
 
(Spillage) What type of activity or behavior should be reported as a potential insider threat?
Coworker making consistent statements indicative of hostility or anger toward the United States and its policies.
 
(Spillage) What advantages do “insider threats” have over others that allows them to cause damage to their organizations more easily?
Insiders are given a level of trust and have authorized access to Government information systems.
 
(Spillage) Which of the following is a best practice to protect information about you and your organization on social networking sites and applications?
Use only personal contact information when establishing personal social networking accounts, never use Government contact information.
 
(Spillage) When is the safest time to post details of your vacation activities on your social networking website?
When your vacation is over, after you have returned home
 
(social networking) When is the safest time to post details of your vacation activities on your social networking profile?
After you have returned home following the vacation
 
(Spillage) What level of damage can the unauthorized disclosure of information classified as confidential reasonably be expected to cause?
Damage to national security
 
(Spillage) Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?
Secret
 
(Spillage) Which of the following practices may reduce your appeal as a target for adversaries seeking to exploit your insider status?
Remove your security badge after leaving your controlled area or office building.
 
(Sensitive Information) What type of unclassified material should always be marked with a special handling caveat?
For Official Use Only (FOUO)
 
(Sensitive Information) Which of the following is NOT an example of sensitive information?
Press release data
 
(Sensitive Information) Which of the following is true about unclassified data?
When unclassified data is aggregated, its classification level may rise.
 
(Sensitive Information) Which of the following represents a good physical security practice?
Use your own security badge, key code, or Common Access Card (CAC)/Personal Identity Verification (PIV) card.
 
(Sensitive Information) What certificates are contained on the Common Access Card (CAC)?
Identification, encryption, and digital signature
 
(Sensitive Information) What should you do if a commercial entity, such as a hotel reception desk, asks to make a photocopy of your Common Access Card (CAC) for proof of Federal Government employment?
Do not allow your CAC to be photocopied.
 
(Sensitive Compartmented Information) What describes how Sensitive Compartmented Information is marked?
Approved Security Classification Guide (SCG)
 
(Sensitive Compartmented Information) Which of the following best describes the compromise of Sensitive Compartmented Information (SCI)?
A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.
 
(Sensitive Compartmented Information) What portable electronic devices (PEDs) are allow in a Secure Compartmented Information Facility (SCIF)?
Government-owned PEDs, if expressly authorized by your agency.
 
(Malicious Code) What are some examples of malicious code?
Viruses, Trojan horses, or worms
 
(Malicious Code) Which of the following is NOT a way that malicious code spreads?
Legitimate software updates
 
(Malicious Code) While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?
Since the URL does not start with “https,” do not provide your credit card information.
 
(Malicious Code) Which email attachments are generally SAFE to open?
Attachments contained in a digitally signed email from someone known
 
(Malicious Code) What is a common indicator of a phishing attempt?
It includes a threat of dire circumstances.
 
(Malicious Code) Which of the following is true of Internet hoaxes?
They can be part of a distributed denial-of-service (DDoS) attack.
 
(Malicious Code) Upon connecting your Government-issued laptop to a public wireless connection, what should you immediately do?
Connect to the Government Virtual Private Network (VPN).
 
(Malicious Code) A coworker has asked if you want to download a programmer’s game to play at work. What should be your response?
I’ll pass
 
(Malicious Code) What are some examples of removable media?
Memory sticks, flash drives, or external hard drives
 
(Malicious Code) Which are examples of portable electronic devices (PEDs)?
laptops, fitness bands, tablets, smartphones, electric readers, and Bluetooth devices
 
(Malicious Code) What is a good practice to protect data on your home wireless systems?
Ensure that the wireless security features are properly configured.
 
(social networking) When may you be subjected to criminal, disciplinary, and/or administrative action due to online misconduct?
If you participate in or condone it at any time
 
(social networking) Which of the following is a security best practice when using social networking sites?
Use only personal contact information when establishing your personal account
 
(controlled unclassified information) Which of the following is NOT an example of CUI?
press release data
 
(controlled unclassified information) Which of the following is NOT correct way to protect CUI?
CUI may be stored on any password-protected system.
 
(Physical Security) which Cyberspace Protection Condition (CPCON) establishes a protection priority focus on critical and essential functions only?
(Answer) CPCON 2 (High: Critical and Essential Functions) – CPCON 1 (Very High: Critical Functions) CPCON 3 (Medium: Critical, Essential, and Support Functions) CPCON 4 (Low: All Functions) CPCON 5 (Very Low: All Functions)
 
(Identity Management) What certificates are contained on the Common Access Card (CAC)?
Identification, encryption, and digital signature
 
(Identity Management) Which of the following is an example of two-factor authentication?
Your password and the second commonly includes a text with a code sent to your phone
 
(Sensitive Information) What guidance is available from marking Sensitive Information information (SCI)?
Security Classification Guide (SCG)
 
(Sensitive Information) What must the dissemination of information regarding intelligence sources, methods, or activities follow?
The Director of National Intelligence.
 
(removable media) If an incident occurs involving removable media in a Sensitive Compartmented Information Facility (SCIF), what action should you take?
Notify your security point of contact
 
Which of the following actions can help to protect your identity?
Order a credit report annually
 
What is whaling?
Looking at your MOTHER, and screaming “THERE SHE BLOWS!!” (A type of phishing targeted at senior officials) Which is still your FAT A$$ MOTHER!
 
Which is a best practice that can prevent viruses and other malicious code from being downloaded when checking your e-mail?
Do not access website links, buttons, or graphics in e-mail
 
What type of social engineering targets particular individuals, groups of people, or organizations?
Spear phishing
 
(Travel) Which of the following is a concern when using your Government-issued laptop in public?
Others may be able to view your screen.
 
(GFE) When can you check personal e-mail on your Government-furnished equipment (GFE)?
If allowed by organizational policy
 
(Mobile Devices) Which of the following statements is true?
Mobile devices and applications can track your location without your knowledge or consent.
 
(Mobile Devices) When can you use removable media on a Government system?
When operationally necessary, owned by your organization, and approved by the appropriate authority
 
(Home computer) Which of the following is best practice for securing your home computer?
Create separate accounts for each user
 
*Spillage After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know this project is classified. What should be your response?
Attempt to change the subject to something non-work related, but neither confirm nor deny the article’s authenticity.
 
*Spillage Which of the following may help prevent inadvertent spillage?
Label all files, removable media, and subject headers with appropriate classification markings.
 
*Spillage A user writes down details marked as Secret from a report stored on a classified system and uses those details to draft a briefing on an unclassified system without authorization. What is the best choice to describe what has occurred?
Spillage because classified data was moved to a lower classification level system without authorization.
 
*Spillage What should you do when you are working on an unclassified system and receive an email with a classified attachment?
Call your security point of contact immediately
 
*Spillage What should you do if a reporter asks you about potentially classified information on the web?
Ask for information about the website, including the URL.
 
*Spillage .What should you do if a reporter asks you about potentially classified information on the web?
Refer the reporter to your organization’s public affairs office.
 
*Spillage What is a proper response if spillage occurs?
~Immediately notify your security POC.
 
*Spillage Which of the following is a good practice to aid in preventing spillage?
Be aware of classification markings and all handling caveats.
 
*Spillage Which of the following may help to prevent spillage?
Follow procedures for transferring data to and from outside agency and non-Government networks.
 
*Spillage You find information that you know to be classified on the Internet. what should you do?
Note the website’s URL and report the situation to your security point of contact.
 
*Spillage Which of the following is a good practice to prevent spillage?
Always check to make sure you are using the correct network for the level of data.
 
**Classified Data When classified data is not in use, how can you protect it?
Store classified data appropriately in a GSA-approved vault/container.
 
**Classified Data What is required for an individual to access classified data?
Appropriate clearance, a signed and approved non-disclosure agreement, and need-to-know
 
**Classified Data Which classification level is given to information that could reasonably be expected to cause serious damage to national security?
Secret
 
**Classified Data What is a good practice to protect classified information?
Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material.
 
**Classified Data Which of the following can an unauthorized disclosure of information classified as Confidential reasonably be expected to cause?
Damage to national security
 
**Classified Data Which of the following must you do before using and unclassified laptop and peripherals in a collateral environment?
Use personally-owned wired headsets and microphones only in designated areas
 
**Insider Threat Which of the following is NOT considered a potential insider threat indicator?
New interest in learning a foreign language
 
**Insider Threat A colleague has visited several foreign countries recently, has adequate work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his car repossessed. How many potential insider threat indicators does this employee display?
1 Indicator(wrong) ~3 or more indicators
 
**Insider Threat A colleague vacations at the beach every year, is married and a father of four, his work quality is sometimes poor, and he is pleasant to work with. How many potential insider threat indicators does this employee display?
1 indicator
 
**Insider Threat How many potential insider threat indicators does a coworker who often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?
3 or more indicators
 
**Insider Threat How many potential insider threat indicators does a person who is playful and charming, consistently wins performance awards, but is occasionally aggressive in trying to access sensitive information display?
1 indicator
 
**Insider Threat What advantages do “insider threats” have over others that allows them to cause damage to their organizations more easily?
Insiders are given a level of trust and have authorized access to Government information systems
 
**Insider Threat What type of activity or behavior should be reported as a potential insider threat?
Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.
 
**Insider Threat Which of the following should be reported as a potential security incident?
A coworker removes sensitive information without authorization
 
**Insider Threat Which of the following should be reported as a potential security incident (in accordance with you Agency’s insider threat policy)?
~A coworker brings a personal electronic device into a prohibited area.
 
**Social Networking When is the safest time to post details of your vacation activities on your social networking website?
When vacation is over, after you have returned home
 
**Social Networking What should you do if you receive a game application request that includes permission to access your friends, profile information, cookies, and sires visited?
Decline the request
 
*Sensitive Information Under which circumstances is it permitted to share an unclassified draft document with a non-DoD professional discussion group?
As long as the document is cleared for public release, you may share it outside of DoD.
 
*Sensitive Information What is the best example of Personally Identifiable Information (PII)?
Date and place of birth
 
*Sensitive Information Which of the following is the best example of Personally Identifiable Information (PII)?
Passport number
 
*Sensitive Information Which of the following is an example of Protected Health Information (PHI)?
Medical test results
 
*Sensitive Information What type of unclassified material should always be marked with a special handling caveat?
For Official Use Only (FOUO)
 
*Sensitive Information Under what circumstances could classified information be considered a threat to national security?
If aggregated, the information could become classified.
 
**Physical Security What is a good practice for physical security?
Challenge people without proper badges.
 
**Physical Security At which Cyberspace Protection Condition (CPCON) is the priority focus on critical functions only?
CPCON 1
 
**Identity Management Your DoD Common Access Card (CAC) has a Public Key Infrastructure (PKI) token approved for access to the NIPRNet. In which situation below are you permitted to use your PKI token?
On a NIPRNet system while using it for a PKI-required task
 
**Identity Management Which of the following is the nest description of two-factor authentication?
Something you possess, like a CAC, and something you know, like a PIN or password
 
**Identity management Which is NOT a sufficient way to protect your identity?
Use a common password for all your system and application logons.
 
**Identity management What is the best way to protect your Common Access Card (CAC)?
Maintain possession of it at all times.
 
*Sensitive Compartmented Information What is a Sensitive Compartmented Information (SCI) program?
A program that segregates various type of classified information into distinct compartments for added protection and dissemination for distribution control.
 
*Sensitive Compartmented Information Which of the following best describes the compromise of Sensitive Compartmented Information (SCI)?
A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.
 
*Sensitive Compartmented Information When should documents be marked within a Sensitive Compartmented Information Facility (SCIF)
~All documents should be appropriately marked, regardless of format, sensitivity, or classification. Unclassified documents do not need to be marked as a SCIF. Only paper documents that are in open storage need to be marked. Only documents that are classified Secret, Top Secret, or SCI require marking. (Wrong)
 
*Sensitive Compartmented Information Which must be approved and signed by a cognizant Original Classification Authority (OCA)?
Security Classification Guide (SCG)
 
**Removable Media in a SCIF What must users ensure when using removable media such as compact disk (CD)?
It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number.
 
*Malicious Code What are some examples of malicious code?
Viruses, Trojan horses, or worms
 
**Website Use While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?
Since the URL does not start with “https,” do not provide you credit card information.
 
**Social Engineering Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email?
Do not access links or hyperlinked media such as buttons and graphics in email messages.
 
**Social Engineering What is TRUE of a phishing attack?
Phishing can be an email with a hyperlink as bait.
 
**Social Engineering Which of the following is a way to protect against social engineering?
Follow instructions given only by verified personnel.
 
**Travel What is a best practice while traveling with mobile computing devices?
Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.
 
**Use of GFE Under what circumstances is it acceptable to use your Government-furnished computer to check personal e-mail and do other non-work-related activities?
If allowed by organizational policy
 
**Mobile Devices Which is a rule for removable media, other portable electronic devices (PEDs), and mobile computing devices to protect Government systems?
Do not use any personally owned/non-organizational removable media on your organization’s systems.
 
**Mobile Devices Which of the following helps protect data on your personal mobile devices?
Secure personal mobile devices to the same level as Government-issued systems.
 
**Home Computer Security How can you protect your information when using wireless technology?
Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.
 
What is the best response if you find classified government data on the internet?
Note any identifying information, such as the website’s URL, and report the situation to your security POC.
 
What information posted publicly on your personal social networking profile represents a security risk?
Your place of birth
 
What is the best example of Protected Health Information (PHI)?
Your health insurance explanation of benefits (EOB)
 
What does Personally Identifiable Information (PII) include?
Social Security Number; date and place of birth; mother’s maiden name
 
What certificates are contained on the DoD Public Key Infrastructure (PKI) implemented by the Common Access Card (CAC)/Personal Identity Verification (PIV) card?
Identification, encryption, and digital signature
 
What describes how Sensitive Compartmented Information is marked?
Approved Security Classification Guide (SCG)
 
Which is a risk associated with removable media?
Spillage of classified information.
 
What is an indication that malicious code is running on your system?
File corruption
 
What is a valid response when identity theft occurs?
Report the crime to local law enforcement.
 
What is whaling?
A type of phishing targeted at high-level personnel such as senior officials.
 
What is a best practice to protect data on your mobile computing device?
Lock your device screen when not in use and require a password to reactivate.
 
What is a possible indication of a malicious code attack in progress?
A pop-up window that flashes and warns that your computer is infected with a virus.

Was this helpful?