DoD Annual TrainingComprehensive Study Set

Navy Cyber Awareness Challenge 2023

330 questions across 18 topics. Use the find bar or section chips to jump to what you need.

Community-sourced. Answers may be wrong or out of date. Always verify with your official training portal before submitting. Not affiliated with any branch, agency, or vendor. Details.
SpillageQUESTION 1

After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know that this project is classified. How should you respond?

ANSWER

Attempt to change the subject to something non-work related, but neither confirm nor deny the article's authenticity

SpillageQUESTION 2

Which of the following may help to prevent spillage?

ANSWER

Label all files, removable media, and subject headers with appropriate classification markings.

SpillageQUESTION 3

A user writes down details marked as Secret from a report stored on a classified system and uses those details to draft a briefing on an unclassified system without authorization. What is the best choice to describe what has occurred?

ANSWER

Spillage because classified data was moved to a lower classification level system without authorization.

SpillageQUESTION 4

What should you do when you are working on an unclassified system and receive an email with a classified attachment?

ANSWER

Store classified data appropriately in a GSA-approved vault/container.

SpillageQUESTION 5

What should you do if a reporter asks you about potentially classified information on the web?

ANSWER

~Verify that any government equipment used for processing classified information has valid anti-virus software before connecting it to the internet (wrong) ~Follow procedures for transferring data to and from outside agency and non-Government networks

SpillageQUESTION 6

What should you do if you suspect spillage has occurred?

ANSWER

~Note the website's URL and report the situation to your security point of contact

SpillageQUESTION 7

Which of the following is a good practice to prevent spillage?

ANSWER

Appropriate clearance, a signed and approved non-disclosure agreement, and need-to-know

SpillageQUESTION 8

Which of the following actions is appropriate after finding classified information on the Internet?

ANSWER

Appropriate clearance, a signed and approved non-disclosure agreement, and need-to-know

Classified DataQUESTION 9

When classified data is not in use, how can you protect it?

ANSWER

Store classified data appropriately in a GSA-approved vault/container.

Classified DataQUESTION 10

What is required for an individual to access classified data?

ANSWER

Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material.

Classified DataQUESTION 11

Which classification level is given to information that could reasonably be expected to cause serious damage to national security?

ANSWER

You must have permission from your organization.

Classified DataQUESTION 12

Which of the following is a good practice to protect classified information?

ANSWER

Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material

Classified DataQUESTION 13

Which of the following is true of protecting classified data?

ANSWER

Store it in a General Services Administration (GSA)-approved vault or container

Classified DataQUESTION 14

What level of damage can the unauthorized disclosure of information classified as Confidential reasonably be expected to cause?

ANSWER

~National Security Agency (NSA) (Wrong)

Classified DataQUESTION 15

Which of the following is true of telework?

ANSWER

~Use a Virtual Private Network (VPN) to obscure your true geographic location

Classified DataQUESTION 16

Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?

ANSWER

~0 indicator

Classified DataQUESTION 17

How should you protect a printed classified document when it is not in use?

ANSWER

Store it in a General Services Administration (GSA)-approved vault or container

QUESTION 18

What level of damage to national security could reasonably be expected if unauthorized disclosure of Top Secret information occurred?

ANSWER

Exceptionally grave Damage

Insider ThreatQUESTION 19

Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague vacations at the beach every year, is married and a father of four, sometimes has poor work quality, and works well with his team.

ANSWER

Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.

Insider ThreatQUESTION 20

How many potential insider threat indicators does a coworker who often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?

ANSWER

Insiders are given a level of trust and have authorized access to Government information systems

Insider ThreatQUESTION 21

Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague is playful and charming, consistently wins performance awards, and is occasionally aggressive in trying to access classified information.

ANSWER

Insiders are given a level of trust and have authorized access to Government information systems.

Insider ThreatQUESTION 22

What advantages do "insider threats" have over others that allows them to cause damage to their organizations more easily?

ANSWER

Insiders are given a level of trust and have authorized access to Government information systems

Insider ThreatQUESTION 23

What type of activity or behavior should be reported as a potential insider threat?

ANSWER

Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.

Insider ThreatQUESTION 24

Which of the following should be reported as a potential security incident?

ANSWER

A coworker removes sensitive information without authorization

Insider ThreatQUESTION 25

Which scenario might indicate a reportable insider threat?

ANSWER

A coworker uses a personal electronic device in a secure area where their use is prohibited.

Insider ThreatQUESTION 26

Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague often makes others uneasy with her persistent efforts to obtain information about classified project where she has no need-to-know, is vocal about her husband overspending on credit cards, and complains about anxiety and exhaustion.

ANSWER

Difficult life circumstances, such as death of a spouse

Insider ThreatQUESTION 27

Which type of behavior should you report as a potential insider threat?

ANSWER

Hostility or anger toward the United States and its policies

Insider ThreatQUESTION 28

Which of the following is NOT considered a potential insider threat indicator?

ANSWER

After you have returned home following the vacation

Insider ThreatQUESTION 29

What do insiders with authorized access to information or information systems pose?

ANSWER

After you have returned home following the vacation

Social NetworkingQUESTION 30

When is the safest time to post details of your vacation activities on your social networking profile?

ANSWER

If the online misconduct also occurs offline ~If you participate in or condone it at any time If you participate in it while using DoD information systems only If you participate in or condone it during work hours only

Insider ThreatQUESTION 31

Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague abruptly becomes hostile and unpleasant after previously enjoying positive working relationships with peers, purchases an unusually expensive car, and has unexplained absences from work.

ANSWER

Someone who uses authorized access, wittingly or unwittingly, to harm national security through unauthorized disclosure or other actions that may cause the loss or degradation of resources or capabilities.

Insider ThreatQUESTION 32

What is an insider threat?

ANSWER

Interest in learning a foreign language

Insider ThreatQUESTION 33

Which of the following is a potential insider threat indicator?

ANSWER

Pictures of your pet Your birthday Your hobbies ~Your personal e-mail address

Insider ThreatQUESTION 34

Which of the following is a reportable insider threat activity?

ANSWER

Avoid talking about work outside of the workplace or with people without a need-to-know

QUESTION 35

In addition to avoiding the temptation of greed to betray his country, what should Alex do differently?

ANSWER

It is often the default but can be prevented by disabling the location function.

QUESTION 36

How many insider threat indicators does Alex demonstrate?

ANSWER

Report the suspicious behavior in accordance with their organization's insider threat policy

QUESTION 37

What should Alex's colleagues do?

ANSWER

Proactively identify potential threats and formulate holistic mitigation responses

Insider ThreatQUESTION 38

What function do Insider Threat Programs aim to fulfill?

ANSWER

Decline the request

Social NetworkingQUESTION 39

What should you do if you receive a game application request that includes permission to access your friends, profile information, cookies, and sites visited?

ANSWER

Use only your personal contact information when establishing your account

Social NetworkingQUESTION 40

Which of the following information is a security risk when posted publicly on your social networking profile?

ANSWER

Ensure there are no identifiable landmarks visible in any photos taken in a work setting that you post

Social NetworkingQUESTION 41

Which of the following is a security best practice when using social networking sites?

ANSWER

Research the source of the article to evaluate its credibility and reliability

Social NetworkingQUESTION 42

When may you be subject to criminal, disciplinary, and/or administrative action due to online misconduct?

ANSWER

Data about you collected from all sites, apps, and devices that you use can be aggregated to form a profile of you.

Social NetworkingQUESTION 43

Your cousin posted a link to an article with an incendiary headline on social media. What action should you take?

ANSWER

Data about you collected from all sites, apps, and devices that you use can be aggregated to form a profile of you.

Social NetworkingQUESTION 44

Which of the following best describes the sources that contribute to your online identity?

ANSWER

Adversaries exploit social networking sites to disseminate fake news

Social NetworkingQUESTION 45

As someone who works with classified information, what should you do if you are contacted by a foreign national seeking information on a research project?

ANSWER

Photos of your pet

Social NetworkingQUESTION 46

Which piece if information is safest to include on your social media profile?

ANSWER

Adversaries exploit social networking sites to disseminate fake news.

Social NetworkingQUESTION 47

Which of the following statements is true?

ANSWER

Ensure there are no identifiable landmarks visible in any photos taken in a work setting that you post

QUESTION 48

How can you protect your organization on social networking sites?

ANSWER

Paul verifies that the information is CUI, includes a CUI marking in the subject header, and digitally signs an e-mail containing CUI.

Controlled Unclassified InformationQUESTION 49

Which of the following is NOT an example of CUI?

ANSWER

(Answer) CPCON 2 (High: Critical and Essential Functions) - CPCON 1 (Very High: Critical Functions) CPCON 3 (Medium: Critical, Essential, and Support Functions) CPCON 4 (Low: All Functions) CPCON 5 (Very Low: All Functions)

Controlled Unclassified InformationQUESTION 50

Which of the following is NOT a correct way to protect CUI?

ANSWER

Paul verifies that the information is CUI, includes a CUI marking in the subject header and digitally signs an e-mail containing CUI.

Controlled Unclassified InformationQUESTION 51

Which of the following best describes a way to safely transmit Controlled Unclassified Information (CUI)?

ANSWER

Store it in a locked desk drawer after working hours.

Controlled Unclassified InformationQUESTION 52

Which is a best practice for protecting Controlled Unclassified Information (CUI)?

ANSWER

Press release data

QUESTION 53

Which of the following is not Controlled Unclassified Information (CUI)?

ANSWER

It does not require markings or distribution controls

QUESTION 54

Which of the following is true of Unclassified information?

ANSWER

Challenge people without proper badges.

QUESTION 55

Which of the following includes Personally Identifiable Information (PII) and Protected Health Information (PHI)?

ANSWER

CPCON 1

Physical SecurityQUESTION 56

What is a good practice for physical security?

ANSWER

On a NIPRNet system while using it for a PKI-required task

Physical SecurityQUESTION 57

At which Cyberspace Protection Condition (CPCON) is the priority focus on critical functions only?

ANSWER

Something you possess, like a CAC, and something you know, like a PIN or password

Physical SecurityQUESTION 58

Within a secure area, you see an individual who you do not know and is not wearing a visible badge. What should you do?

ANSWER

Something you possess, like a CAC, and something you know, like a PIN or password

Identity ManagementQUESTION 59

Your DoD Common Access Card (CAC) has a Public Key Infrastructure (PKI) token approved for access to the NIPRNet. In which situation below are you permitted to use your PKI token?

ANSWER

Write your password down on a device that only you access (e.g., your smartphone)

Identity ManagementQUESTION 60

Which of the following is the nest description of two-factor authentication?

ANSWER

Your password and a code you receive via text message

Identity managementQUESTION 61

Which is NOT a sufficient way to protect your identity?

ANSWER

Store your Common Access Card (CAC) or Personal Identity Verification (PIV) card in a shielded sleeve ~Write your password down on a device that only you access (e.g., your smartphone) Change your password at least every 3 months Enable two-factor authentication whenever available, even for personal accounts

Identity managementQUESTION 62

What is the best way to protect your Common Access Card (CAC)?

ANSWER

A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.

Identity managementQUESTION 63

Which of the following is NOT a best practice to preserve the authenticity of your identity?

ANSWER

eA1xy2!P

Identity managementQUESTION 64

Which of the following is an example of two-factor authentication?

ANSWER

A program that segregates various types of classified information into distinct compartments for added protection and dissemination or distribution control

Identity managementQUESTION 65

Which of the following is an example of a strong password?

ANSWER

A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.

Sensitive Compartmented InformationQUESTION 66

What is Sensitive Compartmented Information (SCI)?

ANSWER

~All documents should be appropriately marked, regardless of format, sensitivity, or classification. Unclassified documents do not need to be marked as a SCIF. Only paper documents that are in open storage need to be marked.

Sensitive Compartmented InformationQUESTION 67

Which of the following best describes the compromise of Sensitive Compartmented Information (SCI)?

ANSWER

Security Classification Guide (SCG)

Sensitive Compartmented InformationQUESTION 68

When should documents be marked within a Sensitive Compartmented Information Facility (SCIF)

ANSWER

It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number.

Sensitive Compartmented InformationQUESTION 69

Which must be approved and signed by a cognizant Original Classification Authority (OCA)?

ANSWER

Physically assess that everyone within listening distance is cleared and has a need-to-know for the information being discussed

Sensitive Compartmented InformationQUESTION 70

What must the dissemination of information regarding intelligence sources, methods, or activities follow?

ANSWER

Mark SCI documents appropriately and use an approved SCI fax machine

Sensitive Compartmented InformationQUESTION 71

When is it appropriate to have your security badge visible?

ANSWER

Evaluate the causes of the compromise E-mail detailed information about the incident to your security point of contact (Wrong) Assess the amount of damage that could be caused by the compromise ~Contact your security point of contact to report the incident

Sensitive Compartmented InformationQUESTION 72

What should the owner of this printed SCI do differently?

ANSWER

Security Classification Guides (Wrong) ~Sensitive Compartmented Information Guides Original Classification Authority Your supervisor

Sensitive Compartmented InformationQUESTION 73

What should the participants in this conversation involving SCI do differently?

ANSWER

It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number.

Sensitive Compartmented InformationQUESTION 74

When faxing Sensitive Compartmented Information (SCI), what actions should you take?

ANSWER

~Access requires a formal need-to-know determination issued by the Director of National Intelligence

Removable Media in a SCIFQUESTION 75

What must users ensure when using removable media such as compact disk (CD)?

ANSWER

Identify and disclose it with local Configuration/Change Management Control and Property Management authorities

Removable Media in a SCIFQUESTION 76

What portable electronic devices (PEDs) are allowed in a Sensitive Compartmented Information Facility (SCIF)?

ANSWER

Viruses, Trojan horses, or worms

Removable Media in a SCIFQUESTION 77

What action should you take when using removable media in a Sensitive Compartmented Information Facility (SCIF)?

ANSWER

No, you should only allow mobile code to run from your organization or your organization's trusted sites.

Malicious CodeQUESTION 78

What are some examples of malicious code?

ANSWER

No, you should only allow mobile code to run from your organization or your organization's trusted sites.

Malicious CodeQUESTION 79

Which of the following is NOT a way that malicious code spreads?

ANSWER

Since the URL does not start with "https," do not provide you credit card information.

Malicious CodeQUESTION 80

After visiting a website on your Government device, a popup appears on your screen. The popup asks if you want to run an application. Is this safe?

ANSWER

You should only accept cookies from reputable, trusted websites.

Website UseQUESTION 81

While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?

ANSWER

You should only accept cookies from reputable, trusted websites.

Website UseQUESTION 82

How should you respond to the theft of your identity?

ANSWER

Do not access website links, buttons, or graphics in e-mail

Website UseQUESTION 83

Which of the following statements is true of cookies?

ANSWER

Follow instructions given only by verified personnel.

Social EngineeringQUESTION 84

Which is a best practice that can prevent viruses and other malicious code from being downloaded when checking your e-mail?

ANSWER

Investigate the link's actual destination using the preview feature

Social EngineeringQUESTION 85

What is TRUE of a phishing attack?

ANSWER

Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.

Social EngineeringQUESTION 86

Which of the following is a way to protect against social engineering?

ANSWER

Investigate the link's actual destination using the preview feature

Social EngineeringQUESTION 87

What is whaling?

ANSWER

Use online sites to confirm or expose potential hoaxes

Social EngineeringQUESTION 88

What action should you take with an e-mail from a friend containing a compressed Uniform Resource Locator (URL)?

ANSWER

They can be part of a distributed denial of service (DDoS) attack.

Social EngineeringQUESTION 89

How can you protect yourself from internet hoaxes?

ANSWER

Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.

Social EngineeringQUESTION 90

Which may be a security issue with compressed Uniform Resource Locators (URLs)?

ANSWER

It may be compromised as soon as you exit the plane.

TravelQUESTION 91

What is a best practice while traveling with mobile computing devices?

ANSWER

A personally owned device approved under Bring Your Own Approved Device (BYOAD) policy must be unenrolled while out of the country.

TravelQUESTION 92

Which of the following is true of traveling overseas with a mobile phone?

ANSWER

Do not use any personally owned/non-organizational removable media on your organization's systems.

TravelQUESTION 93

What security risk does a public Wi-Fi connection pose?

ANSWER

Determine if the software or service is authorized

Use of GFEQUESTION 94

When can you check personal e-mail on your Government-furnished equipment (GFE)?

ANSWER

Do not use any personally owned/non-organizational removable media on your organization's systems.

Use of GFEQUESTION 95

What is a critical consideration on using cloud-based file sharing and storage applications on your Government-furnished equipment (GFE)?

ANSWER

Secure it to the same level as Government-issued systems

Mobile DevicesQUESTION 96

Which is a rule for removable media, other portable electronic devices (PEDs), and mobile computing devices to protect Government systems?

ANSWER

Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.

Mobile DevicesQUESTION 97

What can help to protect the data on your personal mobile device?

ANSWER

Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.

Mobile DevicesQUESTION 98

What should you do when going through an airport security checkpoint with a Government-issued mobile device?

ANSWER

Reviewing and configuring the available security features, including encryption

Home Computer SecurityQUESTION 99

How can you protect your information when using wireless technology?

ANSWER

Classified material must be appropriately marked.

Home Computer SecurityQUESTION 100

What should you consider when using a wireless keyboard with your home computer?

ANSWER

Refer the reporter to your organization's public affairs office.

Home Computer SecurityQUESTION 101

Which of the following is a best practice for securing your home computer?

ANSWER

Store classified data appropriately in a GSA-approved vault/container.

QUESTION 102

(Spillage) Which of the following is a good practice to aid in preventing spillage?

ANSWER

Note the website's URL and report the situation to your security point of contact.

QUESTION 103

(Spillage) After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know this project is classified. What should be your response?

ANSWER

Spillage because classified data was moved to a lower classification level system without authorization.

QUESTION 104

(Spillage) What is required for an individual to access classified data?

ANSWER

0 indicators

QUESTION 105

(Spillage) When classified data is not in use, how can you protect it?

ANSWER

1 indicators

QUESTION 106

(Insider Threat) A colleague vacations at the beach every year, is married and a father of four, his work quality is sometimes poor, and he is pleasant to work with. How many potential insider threat indicators does this employee display?

ANSWER

Coworker making consistent statements indicative of hostility or anger toward the United States and its policies.

QUESTION 107

(Spillage) What type of activity or behavior should be reported as a potential insider threat?

ANSWER

Use only personal contact information when establishing personal social networking accounts, never use Government contact information.

QUESTION 108

(Spillage) What advantages do "insider threats" have over others that allows them to cause damage to their organizations more easily?

ANSWER

When your vacation is over, after you have returned home

QUESTION 109

(Spillage) Which of the following is a best practice to protect information about you and your organization on social networking sites and applications?

ANSWER

After you have returned home following the vacation

QUESTION 110

(Spillage) When is the safest time to post details of your vacation activities on your social networking website?

ANSWER

Damage to national security

QUESTION 111

(Spillage) What level of damage can the unauthorized disclosure of information classified as confidential reasonably be expected to cause?

ANSWER

Remove your security badge after leaving your controlled area or office building.

QUESTION 112

(Spillage) Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?

ANSWER

For Official Use Only (FOUO)

QUESTION 113

(Spillage) Which of the following practices may reduce your appeal as a target for adversaries seeking to exploit your insider status?

ANSWER

Press release data

QUESTION 114

(Sensitive Information) What type of unclassified material should always be marked with a special handling caveat?

ANSWER

When unclassified data is aggregated, its classification level may rise.

QUESTION 115

(Sensitive Information) Which of the following is NOT an example of sensitive information?

ANSWER

Use your own security badge, key code, or Common Access Card (CAC)/Personal Identity Verification (PIV) card.

QUESTION 116

(Sensitive Information) Which of the following is true about unclassified data?

ANSWER

Identification, encryption, and digital signature

QUESTION 117

(Sensitive Information) Which of the following represents a good physical security practice?

ANSWER

Do not allow your CAC to be photocopied.

QUESTION 118

(Sensitive Information) What certificates are contained on the Common Access Card (CAC)?

ANSWER

Approved Security Classification Guide (SCG)

QUESTION 119

(Sensitive Information) What should you do if a commercial entity, such as a hotel reception desk, asks to make a photocopy of your Common Access Card (CAC) for proof of Federal Government employment?

ANSWER

A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.

QUESTION 120

(Sensitive Compartmented Information) What describes how Sensitive Compartmented Information is marked?

ANSWER

Government-owned PEDs, if expressly authorized by your agency.

QUESTION 121

(Sensitive Compartmented Information) What portable electronic devices (PEDs) are allow in a Secure Compartmented Information Facility (SCIF)?

ANSWER

Legitimate software updates

QUESTION 122

(Malicious Code) While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?

ANSWER

It includes a threat of dire circumstances.

QUESTION 123

(Malicious Code) Which email attachments are generally SAFE to open?

ANSWER

They can be part of a distributed denial-of-service (DDoS) attack.

QUESTION 124

(Malicious Code) What is a common indicator of a phishing attempt?

ANSWER

Connect to the Government Virtual Private Network (VPN).

QUESTION 125

(Malicious Code) Which of the following is true of Internet hoaxes?

ANSWER

I'll pass

QUESTION 126

(Malicious Code) Upon connecting your Government-issued laptop to a public wireless connection, what should you immediately do?

ANSWER

Memory sticks, flash drives, or external hard drives

QUESTION 127

(Malicious Code) A coworker has asked if you want to download a programmer's game to play at work. What should be your response?

ANSWER

laptops, fitness bands, tablets, smartphones, electric readers, and Bluetooth devices

QUESTION 128

(Malicious Code) What are some examples of removable media?

ANSWER

Ensure that the wireless security features are properly configured.

QUESTION 129

(Malicious Code) Which are examples of portable electronic devices (PEDs)?

ANSWER

If you participate in or condone it at any time

QUESTION 130

(Malicious Code) What is a good practice to protect data on your home wireless systems?

ANSWER

Use only personal contact information when establishing your personal account

QUESTION 131

(social networking) When may you be subjected to criminal, disciplinary, and/or administrative action due to online misconduct?

ANSWER

press release data

QUESTION 132

(controlled unclassified information) Which of the following is NOT correct way to protect CUI?

ANSWER

Identification, encryption, and digital signature

QUESTION 133

(Physical Security) which Cyberspace Protection Condition (CPCON) establishes a protection priority focus on critical and essential functions only?

ANSWER

Your password and the second commonly includes a text with a code sent to your phone

QUESTION 134

(Identity Management) What certificates are contained on the Common Access Card (CAC)?

ANSWER

Security Classification Guide (SCG)

QUESTION 135

(Sensitive Information) What guidance is available from marking Sensitive Information information (SCI)?

ANSWER

Notify your security point of contact

QUESTION 136

(Sensitive Information) What must the dissemination of information regarding intelligence sources, methods, or activities follow?

ANSWER

Order a credit report annually

QUESTION 137

(removable media) If an incident occurs involving removable media in a Sensitive Compartmented Information Facility (SCIF), what action should you take?

ANSWER

Looking at your MOTHER, and screaming "THERE SHE BLOWS!!" (A type of phishing targeted at senior officials) Which is still your FAT A$$ MOTHER!

QUESTION 138

Which of the following actions can help to protect your identity?

ANSWER

Do not access website links, buttons, or graphics in e-mail

QUESTION 139

What is whaling?

ANSWER

A pop-up window that flashes and warns that your computer is infected with a virus.

QUESTION 140

Which is a best practice that can prevent viruses and other malicious code from being downloaded when checking your e-mail?

ANSWER

Others may be able to view your screen.

QUESTION 141

What type of social engineering targets particular individuals, groups of people, or organizations?

ANSWER

If allowed by organizational policy

QUESTION 142

(Travel) Which of the following is a concern when using your Government-issued laptop in public?

ANSWER

Mobile devices and applications can track your location without your knowledge or consent.

QUESTION 143

(GFE) When can you check personal e-mail on your Government-furnished equipment (GFE)?

ANSWER

When operationally necessary, owned by your organization, and approved by the appropriate authority

QUESTION 144

(Mobile Devices) Which of the following statements is true?

ANSWER

Create separate accounts for each user

QUESTION 145

(Mobile Devices) When can you use removable media on a Government system?

ANSWER

Attempt to change the subject to something non-work related, but neither confirm nor deny the article's authenticity.

QUESTION 146

(Home computer) Which of the following is best practice for securing your home computer?

ANSWER

Label all files, removable media, and subject headers with appropriate classification markings.

SpillageQUESTION 147

Which of the following may help prevent inadvertent spillage?

ANSWER

Call your security point of contact immediately

SpillageQUESTION 148

What is a proper response if spillage occurs?

ANSWER

Follow procedures for transferring data to and from outside agency and non-Government networks.

SpillageQUESTION 149

You find information that you know to be classified on the Internet. what should you do?

ANSWER

Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material

Classified DataQUESTION 150

What is a good practice to protect classified information?

ANSWER

Use personally-owned wired headsets and microphones only in designated areas

Classified DataQUESTION 151

Which of the following can an unauthorized disclosure of information classified as Confidential reasonably be expected to cause?

ANSWER

New interest in learning a foreign language

Classified DataQUESTION 152

Which of the following must you do before using and unclassified laptop and peripherals in a collateral environment?

ANSWER

1 Indicator(wrong) ~3 or more indicators

Insider ThreatQUESTION 153

A colleague has visited several foreign countries recently, has adequate work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his car repossessed. How many potential insider threat indicators does this employee display?

ANSWER

3 or more indicators

Insider ThreatQUESTION 154

How many potential insider threat indicators does a person who is playful and charming, consistently wins performance awards, but is occasionally aggressive in trying to access sensitive information display?

ANSWER

Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.

Insider ThreatQUESTION 155

Which of the following should be reported as a potential security incident (in accordance with you Agency's insider threat policy)?

ANSWER

Decline the request

Social NetworkingQUESTION 156

When is the safest time to post details of your vacation activities on your social networking website?

ANSWER

As long as the document is cleared for public release, you may share it outside of DoD.

Social NetworkingQUESTION 157

What should you do if you receive a game application request that includes permission to access your friends, profile information, cookies, and sires visited?

ANSWER

Date and place of birth

Sensitive InformationQUESTION 158

Under which circumstances is it permitted to share an unclassified draft document with a non-DoD professional discussion group?

ANSWER

Passport number

Sensitive InformationQUESTION 159

What is the best example of Personally Identifiable Information (PII)?

ANSWER

Medical test results

Sensitive InformationQUESTION 160

Which of the following is the best example of Personally Identifiable Information (PII)?

ANSWER

For Official Use Only (FOUO)

Sensitive InformationQUESTION 161

Which of the following is an example of Protected Health Information (PHI)?

ANSWER

If aggregated, the information could become classified.

Sensitive InformationQUESTION 162

Under what circumstances could classified information be considered a threat to national security?

ANSWER

CPCON 1

Sensitive Compartmented InformationQUESTION 163

What is a Sensitive Compartmented Information (SCI) program?

ANSWER

~All documents should be appropriately marked, regardless of format, sensitivity, or classification. Unclassified documents do not need to be marked as a SCIF. Only paper documents that are in open storage need to be marked. Only documents that are classified Secret, Top Secret, or SCI require marking. (Wrong)

Social EngineeringQUESTION 164

Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email?

ANSWER

Follow instructions given only by verified personnel.

Use of GFEQUESTION 165

Under what circumstances is it acceptable to use your Government-furnished computer to check personal e-mail and do other non-work-related activities?

ANSWER

Secure personal mobile devices to the same level as Government-issued systems.

Mobile DevicesQUESTION 166

Which of the following helps protect data on your personal mobile devices?

ANSWER

Note any identifying information, such as the website's URL, and report the situation to your security POC.

QUESTION 167

What is the best response if you find classified government data on the internet?

ANSWER

Your health insurance explanation of benefits (EOB)

QUESTION 168

What information posted publicly on your personal social networking profile represents a security risk?

ANSWER

Social Security Number; date and place of birth; mother's maiden name

QUESTION 169

What is the best example of Protected Health Information (PHI)?

ANSWER

Identification, encryption, and digital signature

QUESTION 170

What does Personally Identifiable Information (PII) include?

ANSWER

Approved Security Classification Guide (SCG)

QUESTION 171

What certificates are contained on the DoD Public Key Infrastructure (PKI) implemented by the Common Access Card (CAC)/Personal Identity Verification (PIV) card?

ANSWER

Spillage of classified information.

QUESTION 172

What describes how Sensitive Compartmented Information is marked?

ANSWER

File corruption

QUESTION 173

Which is a risk associated with removable media?

ANSWER

Report the crime to local law enforcement.

QUESTION 174

What is an indication that malicious code is running on your system?

ANSWER

A type of phishing targeted at high-level personnel such as senior officials.

QUESTION 175

What is a valid response when identity theft occurs?

ANSWER

Lock your device screen when not in use and require a password to reactivate.

QUESTION 176

What is a best practice to protect data on your mobile computing device?

ANSWER

Refer the vendor to the appropriate personnel.

QUESTION 177

What is a possible indication of a malicious code attack in progress?

ANSWER

Store classified data appropriately in a GSA-approved vault/container.

QUESTION 178

A vendor conducting a pilot program with your organization contacts you for organizational data to use in a prototype. How should you respond?

ANSWER

Classification markings and handling caveats.

QUESTION 179

When classified data is not in use, how can you protect it?

ANSWER

Ensure that any cameras, microphones, and Wi-Fi embedded in the laptop are physically disabled.

QUESTION 180

What is the basis for handling and storage of classified data?

ANSWER

Exceptionally grave damage.

QUESTION 181

Which of the following must you do before using an unclassified laptop and peripherals in a collateral classified environment?

ANSWER

You must have your organization's permission to telework.

QUESTION 182

What level of damage to national security can you reasonably expect Top secret information to cause if disclosed?

ANSWER

Classified material must be appropriately marked.

QUESTION 183

Which of the following is true about telework?

ANSWER

Attempting to access sensitive information without need-to-know.

QUESTION 184

Which of the following is true of protecting classified data?

ANSWER

a colleague removes sensitive information without seeking authorization in order to perform authorized telework.

QUESTION 185

Which of the following is a reportable insider threat activity?

ANSWER

1) Unusual interest in classified information. 2) Difficult life circumstances, such as death of spouse.

QUESTION 186

Which scenario might indicate a reportable insider threat?

ANSWER

Your favorite movie.

QUESTION 187

Which of the following is a potential insider threat indicator?

ANSWER

Many apps and smart devices collect and share your personal information and contribute to your online identity.

QUESTION 188

Which piece of information is safest to include on your social media profile?

ANSWER

Ensure there are no identifiable landmarks visible in any photos taken in a work setting that you post.

QUESTION 189

Which of the following statements is true?

ANSWER

Research the source to evaluate its credibility and reliability.

QUESTION 190

Which is a best practice for protecting Controlled Unclassified Information (CUI)?

ANSWER

Controlled Unclassified Information (CUI)

QUESTION 191

Which of the following best describes a way to safely transmit Controlled Unclassified Information (CUI)?

ANSWER

Press release data.

QUESTION 192

Which designation includes Personally Identifiable Information (PII) and Protected Health Information (PHI)?

ANSWER

CUI may be stored on any password-protected system.

QUESTION 193

Which of the following is NOT an example of CUI?

ANSWER

Lionel stops an individual in his secure area who is not wearing a badge.

QUESTION 194

Which of the following is NOT a correct way to protect CUI?

ANSWER

A Common Access Card and Personal Identification Number.

QUESTION 195

Which of the following best describes good physical security?

ANSWER

Store it in a shielded sleeve.

QUESTION 196

Which of the following is an example of two-factor authentication?

ANSWER

Confirm the individual's need-to-know and access.

QUESTION 197

What is the best way to protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card?

ANSWER

Access requires Top Secret clearance and indoctrination into the SCI program.

QUESTION 198

What must authorized personnel do before permitting another individual to enter a Sensitive Compartmented Information Facility (SCIF)?

ANSWER

Damage to the removable media.

QUESTION 199

Which of the following is true of Sensitive Compartmented Information (SCI)?

ANSWER

Only expressly authorized government-owned PEDs.

QUESTION 200

Which of the following is NOT a potential consequence of using removable media unsafely in a Sensitive Compartmented Information Facility (SCIF)?

ANSWER

All of these.

QUESTION 201

What portable electronic devices (PEDs) are permitted in a SCIF?

ANSWER

Executables.

QUESTION 202

What is the response to an incident such as opening an uncontrolled DVD on a computer in a SCIF?

ANSWER

Shred personal documents.

QUESTION 203

Which of the following is NOT a type of malicious code?

ANSWER

Use a digital signature when sending attachments or hyperlinks.

QUESTION 204

Which of the following actions can help tp protect your identity?

ANSWER

Spear phishing.

QUESTION 205

Which is an appropriate use of government e-mail?

ANSWER

Verify the identity of all individuals.

QUESTION 206

What type of social engineering targets particular groups of people?

ANSWER

A personally owned device approved under Bring Your Own Approved Device (BYOAD) policy must be unenrolled while out of the country.

QUESTION 207

How can you protect yourself from social engineering?

ANSWER

Only connect with Government VPN.

QUESTION 208

Which of the following is true of traveling overseas with a mobile phone?

ANSWER

Both of these.

QUESTION 209

What should Sara do when using publicly available Internet, such as hotel Wi-Fi?

ANSWER

A headset with a microphone through a Universal Serial Bus (USB) port.

QUESTION 210

What is the danger of using public Wi-Fi connections?

ANSWER

Enable automatic screen locking after a period of inactivity.

QUESTION 211

Which of the following personally-owned computer peripherals is permitted for use with Government-furnished equipment?

ANSWER

External hard drive.

QUESTION 212

How can you protect data on your mobile computing and portable electronic devices (PEDs)?

ANSWER

They can become an attack vector to other devices on your home network.

QUESTION 213

Which of the following is an example of removable media?

ANSWER

At all times when in the facility.

QUESTION 214

Which of the following is true of Internet of Things (IoT) devices?

ANSWER

Linda encrypts all of the sensitive data on her government-issued mobile devices.

QUESTION 215

When is it appropriate to have your security badge visible?

ANSWER

Physically assess that everyone within listening distance is cleared and has a need-to-know for the information being discussed.

QUESTION 216

What should the owner of this printed SCI do differently?

ANSWER

Linda encrypts all of the sensitive data on her government-issued mobile devices.

QUESTION 217

What should the participants in this conversation involving SCI do differently?

ANSWER

Follow procedures for transferring data to and from outside agency and non-government networks.

QUESTION 218

Which of the following demonstrates proper protection of mobile devices?

ANSWER

Validate friend requests through another source through another source before confirming them.

QUESTION 219

Which of the following does NOT constitute spillage?

ANSWER

Download the information.

QUESTION 220

Which of the following is NOT an appropriate way to protect against inadvertent spillage?

ANSWER

Follow procedures for transferring data to and from outside agency and non-government networks.

QUESTION 221

Which of the following should you NOT do if you find classified information on the internet?

ANSWER

Original classification authority.

QUESTION 222

Who designates whether information is classified and its classification level?

ANSWER

Avoid talking about work outside of the workplace or with people without a need-to-know.

QUESTION 223

Which of the following is a good practice to protect classified information?

ANSWER

Three or more.

QUESTION 224

Which of the following may help to prevent spillage?

ANSWER

Report the suspicious behave in accordance with their organization's threat policy.

QUESTION 225

Which of the following is true?

ANSWER

It may prohibit the use of a virtual private network (VPN).

QUESTION 226

Which of the following best describes the conditions under which mobile devices and applications can track your location?

ANSWER

Checking personal e-mail when allowed by your organization.

QUESTION 227

When is it okay to charge a personal mobile device using government-furnished equipment (GFE)?

ANSWER

If you participate in or condone it at any time.

QUESTION 228

What security risk does a public Wi-Fi connection pose?

ANSWER

Photos of your pet.

QUESTION 229

Which of the following represents an ethical use of your Government-furnished equipment (GFE)?

ANSWER

They have similar features, and the same rules and protections apply to both.

QUESTION 230

When may you be subject to criminal, disciplinary, and/or administrative action due to online harassment, bullying, stalking, hazing, discrimination, or retaliation?

ANSWER

Only use Government-approved equipment to process PII.

QUESTION 231

How can you protect yourself on social networking sites?

ANSWER

CUI must be handled using safeguarding or dissemination controls.

QUESTION 232

Which of the following is true of removable media and portable electronic devices (PEDs)?

ANSWER

You should remove and take your CAC/PIV card whenever you leave your workstation.

QUESTION 233

Which of the following is a security best practice for protecting Personally Identifiable Information (PII)?

ANSWER

%2ZN=Ugq

QUESTION 234

Which of the following is true of Controlled Unclassified Information (CUI)?

ANSWER

in any manner.

QUESTION 235

Which Cyber Protection Condition (CPCON) establishes a protection priority focus on critical functions only?

ANSWER

Don't assume open storage in a secure facility is authorized.

QUESTION 236

Which of the following is true of the Common Access Card (CAC) or Personal Identity Verification (PIV) card?

ANSWER

2 indicators.

QUESTION 237

Which of the following is an example of a strong password?

ANSWER

Adversaries exploit social networking sites to disseminate fake news.

QUESTION 238

A compromise of Sensitive Compartmented Information (SCI) occurs when a person who does not have the required clearance or access caveats comes into possession of SCI________.

ANSWER

May be used to mask malicious intent.

QUESTION 239

Which of the following is a good practice to protest classified information?

ANSWER

Information improperly moved from a higher protection level to a lower protection level.

QUESTION 240

Based on the description that follows, how many potential insider threat indicators(s) are displayed? A colleague saves money for an overseas vacation every year, is a single father, and occasionally consumes alcohol.

ANSWER

1 indicator

QUESTION 241

Which of the following is true about URLs?

ANSWER

It contains certificates for identification, encryption, and digital signature.

QUESTION 242

What does "spillage refer to?

ANSWER

only connect government-owned PEDs to the same level classification information system when authorized.

QUESTION 243

Based on the description that follows, haw many potential insider threat indicator(s) are displayed? a colleague enjoys playing videos games, regularly uses social media, and frequently forgets to secure her smartphone elsewhere before entering areas where it is prohibited.

ANSWER

For Government-owned devices, use approved and authorized applications only.

QUESTION 244

A trusted friend in your social network posts a link to vaccine information on a website unknown to you. What action should you take?

ANSWER

You should confirm that a site that wants to store a cookie uses an encrypted link.

QUESTION 245

Which of the following is true of the Common Access Card (CAC)?

ANSWER

Search for instructions on how to preview where the link actually leads.

QUESTION 246

Which of the following is true of portable electronic devices (PEDs) in a Sensitive Compartmented Information Facility (SCIF)?

ANSWER

Avoid inserting removable media with unknown content into your computer.

QUESTION 247

Which of the following is true of downloading apps?

ANSWER

Implement Wi-Fi Protected Access 2 (WPA2) Personal encryption at a minimum.

QUESTION 248

Which of the following statements is true of cookies?

ANSWER

Attempt to change the subject to something non-work related, but neither confirm nor deny the article's authenticity

QUESTION 249

What action should you take with a compressed Uniform Resource Locator (URL) on a website known to you?

ANSWER

Label all files, removable media, and subject headers with appropriate classification markings.

QUESTION 250

Which of the following is a best practice for using removable media?

ANSWER

Spillage because classified data was moved to a lower classification level system without authorization.

QUESTION 251

How should you secure your home wireless network for teleworking?

ANSWER

Call your security point of contact immediately

SpillageQUESTION 252

Which of the following may help to prevent spillage? -Verify that any government equipment used for processing classified information has valid anti-virus software before connecting it to the internet -Follow procedures for transferring data to and from outside agency and non-Government networks -Purge the memory of any device removed from a classified network before connecting it to an unclassified network -Process all data at the highest classification or protection level available, including unclassified data

ANSWER

Secret

Classified DataQUESTION 253

Who designates whether information is classified and its classification level?

ANSWER

1 indicator

Classified DataQUESTION 254

Which of the following is a good practice for telework?

ANSWER

Insiders are given a level of trust and have authorized access to Government information systems

Social NetworkingQUESTION 255

-How can you protect your organization on social networking sites?

ANSWER

CUI may be stored on any password-protected system.

Social NetworkingQUESTION 256

When may you be subject to criminal, disciplinary, and/or administrative action due to online harassment, bullying, stalking, hazing, discrimination, or retaliation?

ANSWER

Unclassified

Controlled Unclassified InformationQUESTION 257

Which designation marks information that does not have potential to damage national security?

ANSWER

CPCON 1

Controlled Unclassified InformationQUESTION 258

Which of the following is true of Controlled Unclassified Information (CUI)?

ANSWER

CPCON 2

Controlled Unclassified InformationQUESTION 259

Which of the following is a security practice for protecting Personally Identifiable Information (PII)?

ANSWER

Ask the individual for identification

Physical SecurityQUESTION 260

Which Cyber Protection Condition (CPCON) is the priority focus on critical and essential functions only?

ANSWER

Something you possess, like a CAC, and something you know, like a PIN or password

Physical SecurityQUESTION 261

Which of the following is a best practice for physical security?

ANSWER

Maintain possession of it at all times.

Identity ManagementQUESTION 262

Which of the following is true of using a DoD Public Key Infrastructure (PKI) token?

ANSWER

A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.

Identity ManagementQUESTION 263

Which of the following is true of the Common Access Card (CAC)?

ANSWER

~All documents should be appropriately marked, regardless of format, sensitivity, or classification. Unclassified documents do not need to be marked as a SCIF. Only paper documents that are in open storage need to be marked.

Sensitive Compartmented InformationQUESTION 264

What action should you take if you become aware that Sensitive Compartmented Information (SCI) has been compromised?

ANSWER

It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number.

Sensitive Compartmented InformationQUESTION 265

What guidance is available for marking Sensitive Compartmented Information (SCI)?

ANSWER

Government-owned PEDs when expressly authorized by your agency

Sensitive Compartmented InformationQUESTION 266

Which of the following is true of transmitting Sensitive Compartmented Information (SCI)?

ANSWER

Identify and disclose it with local Configuration/Change Management Control and Property Management authorities

Sensitive Compartmented InformationQUESTION 267

Which of the following is true of Sensitive Compartmented Information (SCI)?

ANSWER

Damage to the removable media

Removable Media in a SCIFQUESTION 268

Which of the following is NOT a potential consequence of using removable media unsafely in a Sensitive Compartmented Information Facility (SCIF)?

ANSWER

Executables

Malicious CodeQUESTION 269

Which of the following is NOT a type of malicious code?

ANSWER

~By accepting cookies, you authorize websites to store your personal data on a web server. (Wrong)

Social EngineeringQUESTION 270

What is a common indicator of a phishing attempt?

ANSWER

Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.

Social EngineeringQUESTION 271

Which of the following is true of internet hoaxes?

ANSWER

It may be compromised as soon as you exit the plane.

Social EngineeringQUESTION 272

Which of the following is true?

ANSWER

It may expose the connected device to malware.

Social EngineeringQUESTION 273

What security issue is associated with compressed Uniform Resource Locators (URLs)?

ANSWER

Others may be able to view your screen.

Use of GFEQUESTION 274

Which of the following personally-owned computer peripherals is permitted for use with Government-furnished equipment?

ANSWER

When operationally necessary, owned by your organization, and approved by the appropriate authority

Mobile DevicesQUESTION 275

Which of the following is an example of removable media?

ANSWER

Reviewing and configuring the available security features, including encryption

Mobile DevicesQUESTION 276

Which of the following is a best practice for using removable media?

ANSWER

Implement Wi-Fi Protected Access 2 (WPA2) Personal encryption at a minimum

Home Computer SecurityQUESTION 277

How should you secure your home wireless network for teleworking?

ANSWER

Classification markings and handling caveats.

QUESTION 278

Which of the following is true of protecting classified data? (CLASSIFIED DATA)

ANSWER

Don't assume open storage in a secure facility is permitted.

QUESTION 279

A vendor conducting a pilot program with your organization contacts you for organizational data to use in a prototype. How should you respond? (CLASSIFIED DATA)

ANSWER

Ensure that any cameras, microphones, and Wi-Fi embedded in the laptop are physically disabled.

QUESTION 280

When classified data is not in use, how can you protect it? (CLASSIFIED DATA)

ANSWER

Exceptionally grave damage.

QUESTION 281

What is the basis for handling and storage of classified data? (CLASSIFIED DATA)

ANSWER

Implement Wi-Fi Protected Access 2 (WPA2) Personal encryption at a minimum.

QUESTION 282

Which of the following is a good practice to protect classified information? (CLASSIFIED DATA)

ANSWER

You must have your organization's permission to telework.

QUESTION 283

Which of the following must you do before using an unclassified laptop and peripherals in a collateral classified environment? (CLASSIFIED DATA)

ANSWER

Attempting to access sensitive information without need-to-know.

QUESTION 284

What level of damage to national security can you reasonably expect Top secret information to cause if disclosed? (CLASSIFIED DATA)

ANSWER

A colleague removes sensitive information without seeking authorization in order to perform authorized telework.

QUESTION 285

How should you secure your home wireless network for teleworking? (HOME COMPUTER SECURITY)

ANSWER

1) Unusual interest in classified information. 2) Difficult life circumstances, such as death of spouse.

QUESTION 286

Which of the following is true about telework? (HOME COMPUTER SECURITY)

ANSWER

0 indicators.

QUESTION 287

Which of the following is a reportable insider threat activity? (INSIDER THREAT)

ANSWER

Your favorite movie.

QUESTION 288

Which scenario might indicate a reportable insider threat? (INSIDER THREAT)

ANSWER

1) Many apps and smart devices collect and share your personal information and contribute to your online identity. 2) Adversaries exploit social networking sites to disseminate fake news.

QUESTION 289

Which of the following is a potential insider threat indicator? (INSIDER THREAT)

ANSWER

Ensure there are no identifiable landmarks visible in any photos taken in a work setting that you post.

QUESTION 290

Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague saves money for an overseas vacation every year, is a single father, and occasionally consumes alcohol. (INSIDER THREAT)

ANSWER

Unclassified.

QUESTION 291

Which piece of information is safest to include on your social media profile? (SOCIAL NETWORKING)

ANSWER

It is releasable to the public without clearance.??

QUESTION 292

Which of the following statements is true? (SOCIAL NETWORKING)

ANSWER

Store it in a locked desk drawer after working hours.

QUESTION 293

How can you protect your organization on social networking sites? (SOCIAL NETWORKING)

ANSWER

Paul verifies that the information is CUI, includes a CUI marking in the subject header, and digitally signs an e-mail containing CUI.

QUESTION 294

Which designation marks information that does not have potential to damage national security? (CONTROLLED UNCLASSIFIED INFORMATION)

ANSWER

Controlled Unclassified Information (CUI).

QUESTION 295

Which of the following is true of Unclassified information? (CONTROLLED UNCLASSIFIED INFORMATION)

ANSWER

Press release data.

QUESTION 296

Which is a best practice for protecting Controlled Unclassified Information (CUI)? (CONTROLLED UNCLASSIFIED INFORMATION)

ANSWER

CUI may be stored on any password-protected system.

QUESTION 297

Which of the following best describes a way to safely transmit Controlled Unclassified Information (CUI)? (CONTROLLED UNCLASSIFIED INFORMATION)

ANSWER

Lionel stops an individual in his secure area who is not wearing a badge.

QUESTION 298

Which designation includes Personally Identifiable Information (PII) and Protected Health Information (PHI)? (CONTROLLED UNCLASSIFIED INFORMATION)

ANSWER

Report suspicious activity.

QUESTION 299

Which of the following is NOT an example of CUI? (CONTROLLED UNCLASSIFIED INFORMATION)

ANSWER

A Common Access Card and Personal Identification Number.

QUESTION 300

Which of the following is NOT a correct way to protect CUI? (CONTROLLED UNCLASSIFIED INFORMATION)

ANSWER

Store it in a shielded sleeve.

QUESTION 301

Which of the following best describes good physical security? (PHYSICAL SECURITY)

ANSWER

It should only be in a system while actively using it for a PKI-required task.

QUESTION 302

Which of the following is a best practice for physical security? (PHYSICAL SECURITY)

ANSWER

Confirm the individual's need-to-know and access.

QUESTION 303

Which of the following is an example of two-factor authentication? (IDENTITY MANAGEMENT)

ANSWER

Access requires Top Secret clearance and indoctrination into the SCI program.

QUESTION 304

What is the best way to protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card? (IDENTITY MANAGEMENT)

ANSWER

Damage to the removable media.

QUESTION 305

Which of the following is true of using a DoD Public Key Infrastructure (PKI) token? (IDENTITY MANAGEMENT)

ANSWER

You many only transport SCI if you have been courier-briefed for SCI.

QUESTION 306

What must authorized personnel do before permitting another individual to enter a Sensitive Compartmented Information Facility (SCIF)? (SENSITIVE COMPARTMENTED INFORMATION)

ANSWER

In any manner.

QUESTION 307

Which of the following is true of Sensitive Compartmented Information (SCI)? (SENSITIVE COMPARTMENTED INFORMATION)

ANSWER

Only expressly authorized government-owned PEDs.

QUESTION 308

Which of the following is NOT a potential consequence of using removable media unsafely in a Sensitive Compartmented Information Facility (SCIF)? (SENSITIVE COMPARTMENTED INFORMATION)

ANSWER

With the maximum classification, date of creation, point of contact, and Change Management (CM) Control Number.

QUESTION 309

Which of the following is true of transmitting Sensitive Compartmented Information (SCI)? (SENSITIVE COMPARTMENTED INFORMATION)

ANSWER

All of these.

QUESTION 310

A compromise of Sensitive Compartmented Information (SCI) occurs when a person who does not have the required clearance or access caveats comes into possession of SCI _________. (SENSITIVE COMPARTMENTED INFORMATION)

ANSWER

Executables.

QUESTION 311

What portable electronic devices (PEDs) are permitted in a SCIF? (REMOVABLE MEDIA IN A SCIF)

ANSWER

Scan all external files before uploading to your computer.

QUESTION 312

How should you label removable media used in a Sensitive Compartmented Information Facility (SCIF)? (REMOVABLE MEDIA IN A SCIF)

ANSWER

Shred personal documents.

QUESTION 313

What is the response to an incident such as opening an uncontrolled DVD on a computer in a SCIF? (REMOVABLE MEDIA IN A SCIF)

ANSWER

Use a digital signature when sending attachments or hyperlinks.

QUESTION 314

Which of the following is NOT a type of malicious code? (MALICIOUS CODE)

ANSWER

Spear phishing.

QUESTION 315

Which of the following is a way to prevent the spread of malicious code? (MALICIOUS CODE)

ANSWER

Whaling.

QUESTION 316

Which of the following actions can help to protect your identity? (WEBSITE USE)

ANSWER

Verify the identity of all individuals.

QUESTION 317

Which is an appropriate use of government e-mail? (SOCIAL ENGINEERING)

ANSWER

Digitally signed e-mails are more secure.

QUESTION 318

What type of social engineering targets particular groups of people? (SOCIAL ENGINEERING)

ANSWER

A personally owned device approved under Bring Your Own Approved Device (BYOAD) policy must be unenrolled while out of the country.

QUESTION 319

What type of social engineering targets senior officials? (SOCIAL ENGINEERING)

ANSWER

The physical security of the device.

QUESTION 320

How can you protect yourself from social engineering? (SOCIAL ENGINEERING)

ANSWER

Only connect with Government VPN.

QUESTION 321

Which of the following is true? (SOCIAL ENGINEERING)

ANSWER

Both of these.

QUESTION 322

Which of the following is true of traveling overseas with a mobile phone? (TRAVEL)

ANSWER

A headset with a microphone through a Universal Serial Bus (USB) port.

QUESTION 323

Which of the following is a concern when using your Government-issued laptop in public? (TRAVEL)

ANSWER

Enable automatic screen locking after a period of inactivity.

QUESTION 324

What should Sara do when using publicly available Internet, such as hotel Wi-Fi? (TRAVEL)

ANSWER

Additional data charges.

QUESTION 325

What is the danger of using public Wi-Fi connections? (TRAVEL)

ANSWER

It may occur at any time without your knowledge or consent.

QUESTION 326

Which of the following personally-owned computer peripherals is permitted for use with Government-furnished equipment? (USE OF GFE)

ANSWER

External hard drive.

QUESTION 327

How can you protect data on your mobile computing and portable electronic devices (PEDs)? (MOBILE DEVICES)

ANSWER

They can become an attack vector to other devices on your home network.

QUESTION 328

Which of the following is NOT a risk associated with near field communication (NFC)? (MOBILE DEVICES)

ANSWER

At all times when in the facility.

QUESTION 329

Which of the following best describes the conditions under which mobile devices and applications can track your location? (MOBILE DEVICES)

ANSWER

Retrieve classified documents promptly from printers.

QUESTION 330

Which of the following is an example of removable media? (MOBILE DEVICES)

ANSWER

Physically assess that everyone within listening distance is cleared and has a need-to-know for the information being discussed.

Looking for a different version?

CBTs get updated every year. Search for the exact version you're taking (e.g. "cyber awareness 2025").

Search all study materials