DoD Annual TrainingComprehensive Study Set

Cyberawareness Army

93 questions across 0 topics. Use the find bar or section chips to jump to what you need.

Community-sourced. Answers may be wrong or out of date. Always verify with your official training portal before submitting. Not affiliated with any branch, agency, or vendor. Details.
QUESTION 1

It is getting late on Friday. You are reviewing your employees annual self evaluation. Your comments are due on Monday. You can email your employees information to yourself so you can work on it this weekend and go home now. Which method would be the BEST way to send this information?

ANSWER

Use the government email system so you can encrypt the information and open the email on your government issued laptop

QUESTION 2

What should you do if someone asks to use your government issued mobile device (phone/laptop..etc)?

ANSWER

Decline to lend your phone / laptop

QUESTION 3

Where should you store PII / PHI?

ANSWER

Information should be secured in a cabinet or container while not in use

QUESTION 4

Of the following, which is NOT an intelligence community mandate for passwords?

ANSWER

Maximum password age of 45 days

QUESTION 5

Which of the following is NOT Government computer misuse?

ANSWER

Checking work email

QUESTION 6

Which is NOT a telework guideline?

ANSWER

Taking classified documents from your workspace

QUESTION 7

What should you do if someone forgets their access badge (physical access)?

ANSWER

Alert the security office

QUESTION 8

What can you do to protect yourself against phishing?

ANSWER

All of the above

QUESTION 9

What should you do to protect classified data?

ANSWER

Answer 1 and 2 are correct

QUESTION 10

What action is recommended when somebody calls you to inquire about your work environment or specific account information?

ANSWER

Ask them to verify their name and office number

QUESTION 11

If classified information were released, which classification level would result in "Exceptionally grave damage to national security"?

ANSWER

Top Secret

QUESTION 12

Which of the following is NOT considered sensitive information?

ANSWER

Sanitized information gathered from personnel records

QUESTION 13

Which of the following is NOT a criterion used to grant an individual access to classified data?

ANSWER

Senior government personnel, military or civilian

QUESTION 14

Of the following, which is NOT a problem or concern of an Internet hoax?

ANSWER

Directing you to a website that looks real

QUESTION 15

Media containing Privacy Act information, PII, and PHI is not required to be labeled.

ANSWER

FALSE

QUESTION 16

Which of the following is NOT a home security best practice?

ANSWER

Setting weekly time for virus scan when you are not on the computer and it is powered off

QUESTION 17

Which of the following best describes wireless technology?

ANSWER

It is inherently not a secure technology

QUESTION 18

You are leaving the building where you work. What should you do?

ANSWER

Remove your security badge

QUESTION 19

Which of the following is a good practice to avoid email viruses?

ANSWER

Delete email from senders you do not know

QUESTION 20

What is considered a mobile computing device and therefore shouldn't be plugged in to your Government computer?

ANSWER

All of the above

QUESTION 21

Which is NOT a way to protect removable media?

ANSWER

As a best practice, labeling all classified removable media and considering all unlabeled removable media as unclassified

QUESTION 22

What is NOT Personally Identifiable Information (PII)?

ANSWER

Hobby

QUESTION 23

Of the following, which is NOT a method to protect sensitive information?

ANSWER

After work hours, storing sensitive information in unlocked containers, desks, or cabinets if security is not present

QUESTION 24

There are many travel tips for mobile computing. Which of the following is NOT one?

ANSWER

When using a public device with a card reader, only use your DoD CAC to access unclassified information

QUESTION 25

The use of webmail is

ANSWER

is only allowed if the organization permits it

QUESTION 26

What is considered ethical use of the Government email system?

ANSWER

Distributing Company newsletter

QUESTION 27

Which of the following attacks target high ranking officials and executives?

ANSWER

Whaling

QUESTION 28

What constitutes a strong password?

ANSWER

all of the above

QUESTION 29

You are logged on to your unclassified computer and just received an encrypted email from a co-worker. The email has an attachment whose name contains the word "secret". What should you do?

ANSWER

Contact your security POC right away

QUESTION 30

Which is a way to protect against phishing attacks?

ANSWER

Look for digital certificates

QUESTION 31

You receive an email from a company you have an account with. The email states your account has been compromised and you are invited to click on the link in order to reset your password. What action should you take?

ANSWER

Notify security

QUESTION 32

You are having lunch at a local restaurant outside the installation, and you find a cd labeled "favorite song". What should you do?

ANSWER

Leave the cd where it is

QUESTION 33

How should you securely transport company information on a removable media?

ANSWER

Encrypt the removable media

QUESTION 34

Should you always label your removable media?

ANSWER

Yes

QUESTION 35

Which of the following is NOT Protected Health Information (PHI)?

ANSWER

Medical care facility name

QUESTION 36

If authorized, what can be done on a work computer?

ANSWER

Check personal email

QUESTION 37

Spear Phishing attacks commonly attempt to impersonate email from trusted entities. What security device is used in email to verify the identity of sender?

ANSWER

Digital Signatures

QUESTION 38

What type of security is "part of your responsibility" and "placed above all else?"

ANSWER

Physical

QUESTION 39

If your wireless device is improperly configured someone could gain control of the device? T/F

ANSWER

TRUE

QUESTION 40

Which of the following is a proper way to secure your CAC/PIV?

ANSWER

Remove and take it with you whenever you leave your workstation

QUESTION 41

What actions should you take prior to leaving the work environment and going to lunch?

ANSWER

All of the above

QUESTION 42

P2P (Peer-to-Peer) software can do the following except:

ANSWER

Allow attackers physical access to network assets

QUESTION 43

How can you guard yourself against Identity theft?

ANSWER

All of the above

QUESTION 44

When leaving your work area, what is the first thing you should do?

ANSWER

Remove your CAC/PIV

QUESTION 45

Using webmail may bypass built in security features.

ANSWER

TRUE

QUESTION 46

Of the following, which is NOT a characteristic of a phishing attempt?

ANSWER

Directing you to a web site that is real

QUESTION 47

Classified Information can only be accessed by individuals with

ANSWER

All of the above

QUESTION 48

Which of the following definitions is true about disclosure of confidential information?

ANSWER

Damage to national security

QUESTION 49

It is permissible to release unclassified information to the public prior to being cleared.

ANSWER

False

QUESTION 50

Which of the following is NOT sensitive information?

ANSWER

Unclassified information cleared for public release

QUESTION 51

What should you do to protect yourself while on social networks?

ANSWER

Validate all friend requests through another source before confirming them

QUESTION 52

Which is NOT a method of protecting classified data?

ANSWER

Assuming open storage is always authorized in a secure facility

QUESTION 53

What can you do to prevent spillage?

ANSWER

all of the above

QUESTION 54

Which of the following makes Alex's personal information vulnerable to attacks by identity thieves?

ANSWER

Carrying his Social Security Card with him

QUESTION 55

DoD employees are prohibited from using a DoD CAC in card-reader-enabled public device

ANSWER

TRUE

QUESTION 56

Which of the following is an example of malicious code?

ANSWER

Trojan horses

QUESTION 57

Which of the following is NOT PII?

ANSWER

Mother's maiden name

QUESTION 58

Classified Information is

ANSWER

Assigned a classification level by a supervisor

QUESTION 59

Maria is at home shopping for shoes on Amazon.com. Before long she has also purchased shoes from several other websites. What can be used to track Maria's web browsing habits?

ANSWER

Cookies

QUESTION 60

Which is an untrue statement about unclassified data?

ANSWER

If aggregated, the classification of the information may not be changed

QUESTION 61

A medium secure password has at least 15 characters and one of the following.

ANSWER

Special character

QUESTION 62

PII, PHI, and financial information is classified as what type of information?

ANSWER

Sensitive

QUESTION 63

The CAC/PIV is a controlled item and contains certificates for:

ANSWER

All of the above

QUESTION 64

An individual who has attempted to access sensitive information without need-to-know and has made unusual requests for sensitive information is displaying indicators of what?

ANSWER

Potential Insider Threat

QUESTION 65

Which of the following is NOT a social engineering tip?

ANSWER

Following instructions from verified personnel

QUESTION 66

Bob, a coworker, has been going through a divorce, has financial difficulties and is displaying hostile behavior. How many potential insider threat indicators is Bob displaying?

ANSWER

3

QUESTION 67

You are working at your unclassified system and receive an email from a coworker containing a classified attachment. What should you do?

ANSWER

Alert your security POC

QUESTION 68

You check your bank statement and see several debits you did not authorize. You believe that you are a victim of identity theft. Which of the following should you do immediately?

ANSWER

Monitor credit card statements for unauthorized purchases

QUESTION 69

Thumb drives, memory sticks, and flash drives are examples of

ANSWER

Removable media

QUESTION 70

What information relates to the physical or mental health of an individual?

ANSWER

PHI

QUESTION 71

What should be done if you find classified Government Data/Information Not Cleared for Public Release on the Internet?

ANSWER

Make note of any identifying information and the website URL and report it to your security office

QUESTION 72

All https sites are legitimate and there is no risk to entering your personal info online.

ANSWER

FALSE

QUESTION 73

When using a fax machine to send sensitive information, the sender should do which of the following?

ANSWER

Contact the recipient to confirm receipt

QUESTION 74

What should be done to protect against insider threats?

ANSWER

Report any suspicious behavior

QUESTION 75

Which of the following is NOT a potential insider threat?

ANSWER

Member of a religion or faith

QUESTION 76

Of the following, which is NOT a security awareness tip?

ANSWER

Remove security badge as you enter a restaurant or retail establishment

QUESTION 77

ActiveX is a type of this?

ANSWER

Mobile code

QUESTION 78

Which of the following is NOT a security best practice when saving cookies to a hard drive?

ANSWER

Looking for "https" in the URL. All https sites are legitimate.

QUESTION 79

Which is NOT a requirement for telework?

ANSWER

Telework is only authorized for unclassified and confidential information

QUESTION 80

Someone calls from an unknown number and says they are from IT and need some information about your computer. What should you do?

ANSWER

Request the user's full name and phone number

QUESTION 81

Which is NOT a wireless security practice?

ANSWER

Turning off computer when not in use

QUESTION 82

Malicious code can do the following except?

ANSWER

Make your computer more secure

QUESTION 83

What type of data must be handled and stored properly based on classification markings and handling caveats?

ANSWER

Classified

QUESTION 84

What information should you avoid posting on social networking sites?

ANSWER

All of the above

QUESTION 85

A coworker has left an unknown CD on your desk. What should you do?

ANSWER

Put the CD in the trash

QUESTION 86

Which of the following is NOT a DoD special requirement for tokens?

ANSWER

Using NIPRNet tokens on systems of higher classification level

QUESTION 87

UNCLASSIFIED is a designation to mark information that does not have potential to damage national security.

ANSWER

TRUE

QUESTION 88

You receive a call on your work phone and you're asked to participate in a phone survey. As part of the survey the caller asks for birth date and address. What type of attack might this be?

ANSWER

Social Engineering

QUESTION 89

"Spillage" occurs when

ANSWER

Personal information is inadvertently posted at a website

QUESTION 90

What should be done to sensitive data on laptops and other mobile computing devices?

ANSWER

Encrypt the sensitive data

QUESTION 91

Which of the following should be done to keep your home computer secure?

ANSWER

All of the above

QUESTION 92

How are Trojan horses, worms, and malicious scripts spread?

ANSWER

By email attachments

QUESTION 93

The following practices help prevent viruses and the downloading of malicious code except.

ANSWER

Scan external files from only unverifiable sources before uploading to computer

Looking for a different version?

CBTs get updated every year. Search for the exact version you're taking (e.g. "cyber awareness 2025").

Search all study materials