Navy Cyber Awareness Challenge 2023
330 questions across 18 topics. Use the find bar or section chips to jump to what you need.
After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know that this project is classified. How should you respond?
Attempt to change the subject to something non-work related, but neither confirm nor deny the article's authenticity
Which of the following may help to prevent spillage?
Label all files, removable media, and subject headers with appropriate classification markings.
A user writes down details marked as Secret from a report stored on a classified system and uses those details to draft a briefing on an unclassified system without authorization. What is the best choice to describe what has occurred?
Spillage because classified data was moved to a lower classification level system without authorization.
What should you do when you are working on an unclassified system and receive an email with a classified attachment?
Store classified data appropriately in a GSA-approved vault/container.
What should you do if a reporter asks you about potentially classified information on the web?
~Verify that any government equipment used for processing classified information has valid anti-virus software before connecting it to the internet (wrong) ~Follow procedures for transferring data to and from outside agency and non-Government networks
What should you do if you suspect spillage has occurred?
~Note the website's URL and report the situation to your security point of contact
Which of the following is a good practice to prevent spillage?
Appropriate clearance, a signed and approved non-disclosure agreement, and need-to-know
Which of the following actions is appropriate after finding classified information on the Internet?
Appropriate clearance, a signed and approved non-disclosure agreement, and need-to-know
When classified data is not in use, how can you protect it?
Store classified data appropriately in a GSA-approved vault/container.
What is required for an individual to access classified data?
Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material.
Which classification level is given to information that could reasonably be expected to cause serious damage to national security?
You must have permission from your organization.
Which of the following is a good practice to protect classified information?
Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material
Which of the following is true of protecting classified data?
Store it in a General Services Administration (GSA)-approved vault or container
What level of damage can the unauthorized disclosure of information classified as Confidential reasonably be expected to cause?
~National Security Agency (NSA) (Wrong)
Which of the following is true of telework?
~Use a Virtual Private Network (VPN) to obscure your true geographic location
Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?
~0 indicator
How should you protect a printed classified document when it is not in use?
Store it in a General Services Administration (GSA)-approved vault or container
What level of damage to national security could reasonably be expected if unauthorized disclosure of Top Secret information occurred?
Exceptionally grave Damage
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague vacations at the beach every year, is married and a father of four, sometimes has poor work quality, and works well with his team.
Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.
How many potential insider threat indicators does a coworker who often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?
Insiders are given a level of trust and have authorized access to Government information systems
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague is playful and charming, consistently wins performance awards, and is occasionally aggressive in trying to access classified information.
Insiders are given a level of trust and have authorized access to Government information systems.
What advantages do "insider threats" have over others that allows them to cause damage to their organizations more easily?
Insiders are given a level of trust and have authorized access to Government information systems
What type of activity or behavior should be reported as a potential insider threat?
Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.
Which of the following should be reported as a potential security incident?
A coworker removes sensitive information without authorization
Which scenario might indicate a reportable insider threat?
A coworker uses a personal electronic device in a secure area where their use is prohibited.
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague often makes others uneasy with her persistent efforts to obtain information about classified project where she has no need-to-know, is vocal about her husband overspending on credit cards, and complains about anxiety and exhaustion.
Difficult life circumstances, such as death of a spouse
Which type of behavior should you report as a potential insider threat?
Hostility or anger toward the United States and its policies
Which of the following is NOT considered a potential insider threat indicator?
After you have returned home following the vacation
What do insiders with authorized access to information or information systems pose?
After you have returned home following the vacation
When is the safest time to post details of your vacation activities on your social networking profile?
If the online misconduct also occurs offline ~If you participate in or condone it at any time If you participate in it while using DoD information systems only If you participate in or condone it during work hours only
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague abruptly becomes hostile and unpleasant after previously enjoying positive working relationships with peers, purchases an unusually expensive car, and has unexplained absences from work.
Someone who uses authorized access, wittingly or unwittingly, to harm national security through unauthorized disclosure or other actions that may cause the loss or degradation of resources or capabilities.
What is an insider threat?
Interest in learning a foreign language
Which of the following is a potential insider threat indicator?
Pictures of your pet Your birthday Your hobbies ~Your personal e-mail address
Which of the following is a reportable insider threat activity?
Avoid talking about work outside of the workplace or with people without a need-to-know
In addition to avoiding the temptation of greed to betray his country, what should Alex do differently?
It is often the default but can be prevented by disabling the location function.
How many insider threat indicators does Alex demonstrate?
Report the suspicious behavior in accordance with their organization's insider threat policy
What should Alex's colleagues do?
Proactively identify potential threats and formulate holistic mitigation responses
What function do Insider Threat Programs aim to fulfill?
Decline the request
What should you do if you receive a game application request that includes permission to access your friends, profile information, cookies, and sites visited?
Use only your personal contact information when establishing your account
Which of the following information is a security risk when posted publicly on your social networking profile?
Ensure there are no identifiable landmarks visible in any photos taken in a work setting that you post
Which of the following is a security best practice when using social networking sites?
Research the source of the article to evaluate its credibility and reliability
When may you be subject to criminal, disciplinary, and/or administrative action due to online misconduct?
Data about you collected from all sites, apps, and devices that you use can be aggregated to form a profile of you.
Your cousin posted a link to an article with an incendiary headline on social media. What action should you take?
Data about you collected from all sites, apps, and devices that you use can be aggregated to form a profile of you.
Which of the following best describes the sources that contribute to your online identity?
Adversaries exploit social networking sites to disseminate fake news
As someone who works with classified information, what should you do if you are contacted by a foreign national seeking information on a research project?
Photos of your pet
Which piece if information is safest to include on your social media profile?
Adversaries exploit social networking sites to disseminate fake news.
Which of the following statements is true?
Ensure there are no identifiable landmarks visible in any photos taken in a work setting that you post
How can you protect your organization on social networking sites?
Paul verifies that the information is CUI, includes a CUI marking in the subject header, and digitally signs an e-mail containing CUI.
Which of the following is NOT an example of CUI?
(Answer) CPCON 2 (High: Critical and Essential Functions) - CPCON 1 (Very High: Critical Functions) CPCON 3 (Medium: Critical, Essential, and Support Functions) CPCON 4 (Low: All Functions) CPCON 5 (Very Low: All Functions)
Which of the following is NOT a correct way to protect CUI?
Paul verifies that the information is CUI, includes a CUI marking in the subject header and digitally signs an e-mail containing CUI.
Which of the following best describes a way to safely transmit Controlled Unclassified Information (CUI)?
Store it in a locked desk drawer after working hours.
Which is a best practice for protecting Controlled Unclassified Information (CUI)?
Press release data
Which of the following is not Controlled Unclassified Information (CUI)?
It does not require markings or distribution controls
Which of the following is true of Unclassified information?
Challenge people without proper badges.
Which of the following includes Personally Identifiable Information (PII) and Protected Health Information (PHI)?
CPCON 1
What is a good practice for physical security?
On a NIPRNet system while using it for a PKI-required task
At which Cyberspace Protection Condition (CPCON) is the priority focus on critical functions only?
Something you possess, like a CAC, and something you know, like a PIN or password
Within a secure area, you see an individual who you do not know and is not wearing a visible badge. What should you do?
Something you possess, like a CAC, and something you know, like a PIN or password
Your DoD Common Access Card (CAC) has a Public Key Infrastructure (PKI) token approved for access to the NIPRNet. In which situation below are you permitted to use your PKI token?
Write your password down on a device that only you access (e.g., your smartphone)
Which of the following is the nest description of two-factor authentication?
Your password and a code you receive via text message
Which is NOT a sufficient way to protect your identity?
Store your Common Access Card (CAC) or Personal Identity Verification (PIV) card in a shielded sleeve ~Write your password down on a device that only you access (e.g., your smartphone) Change your password at least every 3 months Enable two-factor authentication whenever available, even for personal accounts
What is the best way to protect your Common Access Card (CAC)?
A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.
Which of the following is NOT a best practice to preserve the authenticity of your identity?
eA1xy2!P
Which of the following is an example of two-factor authentication?
A program that segregates various types of classified information into distinct compartments for added protection and dissemination or distribution control
Which of the following is an example of a strong password?
A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.
What is Sensitive Compartmented Information (SCI)?
~All documents should be appropriately marked, regardless of format, sensitivity, or classification. Unclassified documents do not need to be marked as a SCIF. Only paper documents that are in open storage need to be marked.
Which of the following best describes the compromise of Sensitive Compartmented Information (SCI)?
Security Classification Guide (SCG)
When should documents be marked within a Sensitive Compartmented Information Facility (SCIF)
It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number.
Which must be approved and signed by a cognizant Original Classification Authority (OCA)?
Physically assess that everyone within listening distance is cleared and has a need-to-know for the information being discussed
What must the dissemination of information regarding intelligence sources, methods, or activities follow?
Mark SCI documents appropriately and use an approved SCI fax machine
When is it appropriate to have your security badge visible?
Evaluate the causes of the compromise E-mail detailed information about the incident to your security point of contact (Wrong) Assess the amount of damage that could be caused by the compromise ~Contact your security point of contact to report the incident
What should the owner of this printed SCI do differently?
Security Classification Guides (Wrong) ~Sensitive Compartmented Information Guides Original Classification Authority Your supervisor
What should the participants in this conversation involving SCI do differently?
It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number.
When faxing Sensitive Compartmented Information (SCI), what actions should you take?
~Access requires a formal need-to-know determination issued by the Director of National Intelligence
What must users ensure when using removable media such as compact disk (CD)?
Identify and disclose it with local Configuration/Change Management Control and Property Management authorities
What portable electronic devices (PEDs) are allowed in a Sensitive Compartmented Information Facility (SCIF)?
Viruses, Trojan horses, or worms
What action should you take when using removable media in a Sensitive Compartmented Information Facility (SCIF)?
No, you should only allow mobile code to run from your organization or your organization's trusted sites.
What are some examples of malicious code?
No, you should only allow mobile code to run from your organization or your organization's trusted sites.
Which of the following is NOT a way that malicious code spreads?
Since the URL does not start with "https," do not provide you credit card information.
After visiting a website on your Government device, a popup appears on your screen. The popup asks if you want to run an application. Is this safe?
You should only accept cookies from reputable, trusted websites.
While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?
You should only accept cookies from reputable, trusted websites.
How should you respond to the theft of your identity?
Do not access website links, buttons, or graphics in e-mail
Which of the following statements is true of cookies?
Follow instructions given only by verified personnel.
Which is a best practice that can prevent viruses and other malicious code from being downloaded when checking your e-mail?
Investigate the link's actual destination using the preview feature
What is TRUE of a phishing attack?
Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.
Which of the following is a way to protect against social engineering?
Investigate the link's actual destination using the preview feature
What is whaling?
Use online sites to confirm or expose potential hoaxes
What action should you take with an e-mail from a friend containing a compressed Uniform Resource Locator (URL)?
They can be part of a distributed denial of service (DDoS) attack.
How can you protect yourself from internet hoaxes?
Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.
Which may be a security issue with compressed Uniform Resource Locators (URLs)?
It may be compromised as soon as you exit the plane.
What is a best practice while traveling with mobile computing devices?
A personally owned device approved under Bring Your Own Approved Device (BYOAD) policy must be unenrolled while out of the country.
Which of the following is true of traveling overseas with a mobile phone?
Do not use any personally owned/non-organizational removable media on your organization's systems.
What security risk does a public Wi-Fi connection pose?
Determine if the software or service is authorized
When can you check personal e-mail on your Government-furnished equipment (GFE)?
Do not use any personally owned/non-organizational removable media on your organization's systems.
What is a critical consideration on using cloud-based file sharing and storage applications on your Government-furnished equipment (GFE)?
Secure it to the same level as Government-issued systems
Which is a rule for removable media, other portable electronic devices (PEDs), and mobile computing devices to protect Government systems?
Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.
What can help to protect the data on your personal mobile device?
Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.
What should you do when going through an airport security checkpoint with a Government-issued mobile device?
Reviewing and configuring the available security features, including encryption
How can you protect your information when using wireless technology?
Classified material must be appropriately marked.
What should you consider when using a wireless keyboard with your home computer?
Refer the reporter to your organization's public affairs office.
Which of the following is a best practice for securing your home computer?
Store classified data appropriately in a GSA-approved vault/container.
(Spillage) Which of the following is a good practice to aid in preventing spillage?
Note the website's URL and report the situation to your security point of contact.
(Spillage) After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know this project is classified. What should be your response?
Spillage because classified data was moved to a lower classification level system without authorization.
(Spillage) What is required for an individual to access classified data?
0 indicators
(Spillage) When classified data is not in use, how can you protect it?
1 indicators
(Insider Threat) A colleague vacations at the beach every year, is married and a father of four, his work quality is sometimes poor, and he is pleasant to work with. How many potential insider threat indicators does this employee display?
Coworker making consistent statements indicative of hostility or anger toward the United States and its policies.
(Spillage) What type of activity or behavior should be reported as a potential insider threat?
Use only personal contact information when establishing personal social networking accounts, never use Government contact information.
(Spillage) What advantages do "insider threats" have over others that allows them to cause damage to their organizations more easily?
When your vacation is over, after you have returned home
(Spillage) Which of the following is a best practice to protect information about you and your organization on social networking sites and applications?
After you have returned home following the vacation
(Spillage) When is the safest time to post details of your vacation activities on your social networking website?
Damage to national security
(Spillage) What level of damage can the unauthorized disclosure of information classified as confidential reasonably be expected to cause?
Remove your security badge after leaving your controlled area or office building.
(Spillage) Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?
For Official Use Only (FOUO)
(Spillage) Which of the following practices may reduce your appeal as a target for adversaries seeking to exploit your insider status?
Press release data
(Sensitive Information) What type of unclassified material should always be marked with a special handling caveat?
When unclassified data is aggregated, its classification level may rise.
(Sensitive Information) Which of the following is NOT an example of sensitive information?
Use your own security badge, key code, or Common Access Card (CAC)/Personal Identity Verification (PIV) card.
(Sensitive Information) Which of the following is true about unclassified data?
Identification, encryption, and digital signature
(Sensitive Information) Which of the following represents a good physical security practice?
Do not allow your CAC to be photocopied.
(Sensitive Information) What certificates are contained on the Common Access Card (CAC)?
Approved Security Classification Guide (SCG)
(Sensitive Information) What should you do if a commercial entity, such as a hotel reception desk, asks to make a photocopy of your Common Access Card (CAC) for proof of Federal Government employment?
A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.
(Sensitive Compartmented Information) What describes how Sensitive Compartmented Information is marked?
Government-owned PEDs, if expressly authorized by your agency.
(Sensitive Compartmented Information) What portable electronic devices (PEDs) are allow in a Secure Compartmented Information Facility (SCIF)?
Legitimate software updates
(Malicious Code) While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?
It includes a threat of dire circumstances.
(Malicious Code) Which email attachments are generally SAFE to open?
They can be part of a distributed denial-of-service (DDoS) attack.
(Malicious Code) What is a common indicator of a phishing attempt?
Connect to the Government Virtual Private Network (VPN).
(Malicious Code) Which of the following is true of Internet hoaxes?
I'll pass
(Malicious Code) Upon connecting your Government-issued laptop to a public wireless connection, what should you immediately do?
Memory sticks, flash drives, or external hard drives
(Malicious Code) A coworker has asked if you want to download a programmer's game to play at work. What should be your response?
laptops, fitness bands, tablets, smartphones, electric readers, and Bluetooth devices
(Malicious Code) What are some examples of removable media?
Ensure that the wireless security features are properly configured.
(Malicious Code) Which are examples of portable electronic devices (PEDs)?
If you participate in or condone it at any time
(Malicious Code) What is a good practice to protect data on your home wireless systems?
Use only personal contact information when establishing your personal account
(social networking) When may you be subjected to criminal, disciplinary, and/or administrative action due to online misconduct?
press release data
(controlled unclassified information) Which of the following is NOT correct way to protect CUI?
Identification, encryption, and digital signature
(Physical Security) which Cyberspace Protection Condition (CPCON) establishes a protection priority focus on critical and essential functions only?
Your password and the second commonly includes a text with a code sent to your phone
(Identity Management) What certificates are contained on the Common Access Card (CAC)?
Security Classification Guide (SCG)
(Sensitive Information) What guidance is available from marking Sensitive Information information (SCI)?
Notify your security point of contact
(Sensitive Information) What must the dissemination of information regarding intelligence sources, methods, or activities follow?
Order a credit report annually
(removable media) If an incident occurs involving removable media in a Sensitive Compartmented Information Facility (SCIF), what action should you take?
Looking at your MOTHER, and screaming "THERE SHE BLOWS!!" (A type of phishing targeted at senior officials) Which is still your FAT A$$ MOTHER!
Which of the following actions can help to protect your identity?
Do not access website links, buttons, or graphics in e-mail
What is whaling?
A pop-up window that flashes and warns that your computer is infected with a virus.
Which is a best practice that can prevent viruses and other malicious code from being downloaded when checking your e-mail?
Others may be able to view your screen.
What type of social engineering targets particular individuals, groups of people, or organizations?
If allowed by organizational policy
(Travel) Which of the following is a concern when using your Government-issued laptop in public?
Mobile devices and applications can track your location without your knowledge or consent.
(GFE) When can you check personal e-mail on your Government-furnished equipment (GFE)?
When operationally necessary, owned by your organization, and approved by the appropriate authority
(Mobile Devices) Which of the following statements is true?
Create separate accounts for each user
(Mobile Devices) When can you use removable media on a Government system?
Attempt to change the subject to something non-work related, but neither confirm nor deny the article's authenticity.
(Home computer) Which of the following is best practice for securing your home computer?
Label all files, removable media, and subject headers with appropriate classification markings.
Which of the following may help prevent inadvertent spillage?
Call your security point of contact immediately
What is a proper response if spillage occurs?
Follow procedures for transferring data to and from outside agency and non-Government networks.
You find information that you know to be classified on the Internet. what should you do?
Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material
What is a good practice to protect classified information?
Use personally-owned wired headsets and microphones only in designated areas
Which of the following can an unauthorized disclosure of information classified as Confidential reasonably be expected to cause?
New interest in learning a foreign language
Which of the following must you do before using and unclassified laptop and peripherals in a collateral environment?
1 Indicator(wrong) ~3 or more indicators
A colleague has visited several foreign countries recently, has adequate work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his car repossessed. How many potential insider threat indicators does this employee display?
3 or more indicators
How many potential insider threat indicators does a person who is playful and charming, consistently wins performance awards, but is occasionally aggressive in trying to access sensitive information display?
Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.
Which of the following should be reported as a potential security incident (in accordance with you Agency's insider threat policy)?
Decline the request
When is the safest time to post details of your vacation activities on your social networking website?
As long as the document is cleared for public release, you may share it outside of DoD.
What should you do if you receive a game application request that includes permission to access your friends, profile information, cookies, and sires visited?
Date and place of birth
Under which circumstances is it permitted to share an unclassified draft document with a non-DoD professional discussion group?
Passport number
What is the best example of Personally Identifiable Information (PII)?
Medical test results
Which of the following is the best example of Personally Identifiable Information (PII)?
For Official Use Only (FOUO)
Which of the following is an example of Protected Health Information (PHI)?
If aggregated, the information could become classified.
Under what circumstances could classified information be considered a threat to national security?
CPCON 1
What is a Sensitive Compartmented Information (SCI) program?
~All documents should be appropriately marked, regardless of format, sensitivity, or classification. Unclassified documents do not need to be marked as a SCIF. Only paper documents that are in open storage need to be marked. Only documents that are classified Secret, Top Secret, or SCI require marking. (Wrong)
Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email?
Follow instructions given only by verified personnel.
Under what circumstances is it acceptable to use your Government-furnished computer to check personal e-mail and do other non-work-related activities?
Secure personal mobile devices to the same level as Government-issued systems.
Which of the following helps protect data on your personal mobile devices?
Note any identifying information, such as the website's URL, and report the situation to your security POC.
What is the best response if you find classified government data on the internet?
Your health insurance explanation of benefits (EOB)
What information posted publicly on your personal social networking profile represents a security risk?
Social Security Number; date and place of birth; mother's maiden name
What is the best example of Protected Health Information (PHI)?
Identification, encryption, and digital signature
What does Personally Identifiable Information (PII) include?
Approved Security Classification Guide (SCG)
What certificates are contained on the DoD Public Key Infrastructure (PKI) implemented by the Common Access Card (CAC)/Personal Identity Verification (PIV) card?
Spillage of classified information.
What describes how Sensitive Compartmented Information is marked?
File corruption
Which is a risk associated with removable media?
Report the crime to local law enforcement.
What is an indication that malicious code is running on your system?
A type of phishing targeted at high-level personnel such as senior officials.
What is a valid response when identity theft occurs?
Lock your device screen when not in use and require a password to reactivate.
What is a best practice to protect data on your mobile computing device?
Refer the vendor to the appropriate personnel.
What is a possible indication of a malicious code attack in progress?
Store classified data appropriately in a GSA-approved vault/container.
A vendor conducting a pilot program with your organization contacts you for organizational data to use in a prototype. How should you respond?
Classification markings and handling caveats.
When classified data is not in use, how can you protect it?
Ensure that any cameras, microphones, and Wi-Fi embedded in the laptop are physically disabled.
What is the basis for handling and storage of classified data?
Exceptionally grave damage.
Which of the following must you do before using an unclassified laptop and peripherals in a collateral classified environment?
You must have your organization's permission to telework.
What level of damage to national security can you reasonably expect Top secret information to cause if disclosed?
Classified material must be appropriately marked.
Which of the following is true about telework?
Attempting to access sensitive information without need-to-know.
Which of the following is true of protecting classified data?
a colleague removes sensitive information without seeking authorization in order to perform authorized telework.
Which of the following is a reportable insider threat activity?
1) Unusual interest in classified information. 2) Difficult life circumstances, such as death of spouse.
Which scenario might indicate a reportable insider threat?
Your favorite movie.
Which of the following is a potential insider threat indicator?
Many apps and smart devices collect and share your personal information and contribute to your online identity.
Which piece of information is safest to include on your social media profile?
Ensure there are no identifiable landmarks visible in any photos taken in a work setting that you post.
Which of the following statements is true?
Research the source to evaluate its credibility and reliability.
Which is a best practice for protecting Controlled Unclassified Information (CUI)?
Controlled Unclassified Information (CUI)
Which of the following best describes a way to safely transmit Controlled Unclassified Information (CUI)?
Press release data.
Which designation includes Personally Identifiable Information (PII) and Protected Health Information (PHI)?
CUI may be stored on any password-protected system.
Which of the following is NOT an example of CUI?
Lionel stops an individual in his secure area who is not wearing a badge.
Which of the following is NOT a correct way to protect CUI?
A Common Access Card and Personal Identification Number.
Which of the following best describes good physical security?
Store it in a shielded sleeve.
Which of the following is an example of two-factor authentication?
Confirm the individual's need-to-know and access.
What is the best way to protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card?
Access requires Top Secret clearance and indoctrination into the SCI program.
What must authorized personnel do before permitting another individual to enter a Sensitive Compartmented Information Facility (SCIF)?
Damage to the removable media.
Which of the following is true of Sensitive Compartmented Information (SCI)?
Only expressly authorized government-owned PEDs.
Which of the following is NOT a potential consequence of using removable media unsafely in a Sensitive Compartmented Information Facility (SCIF)?
All of these.
What portable electronic devices (PEDs) are permitted in a SCIF?
Executables.
What is the response to an incident such as opening an uncontrolled DVD on a computer in a SCIF?
Shred personal documents.
Which of the following is NOT a type of malicious code?
Use a digital signature when sending attachments or hyperlinks.
Which of the following actions can help tp protect your identity?
Spear phishing.
Which is an appropriate use of government e-mail?
Verify the identity of all individuals.
What type of social engineering targets particular groups of people?
A personally owned device approved under Bring Your Own Approved Device (BYOAD) policy must be unenrolled while out of the country.
How can you protect yourself from social engineering?
Only connect with Government VPN.
Which of the following is true of traveling overseas with a mobile phone?
Both of these.
What should Sara do when using publicly available Internet, such as hotel Wi-Fi?
A headset with a microphone through a Universal Serial Bus (USB) port.
What is the danger of using public Wi-Fi connections?
Enable automatic screen locking after a period of inactivity.
Which of the following personally-owned computer peripherals is permitted for use with Government-furnished equipment?
External hard drive.
How can you protect data on your mobile computing and portable electronic devices (PEDs)?
They can become an attack vector to other devices on your home network.
Which of the following is an example of removable media?
At all times when in the facility.
Which of the following is true of Internet of Things (IoT) devices?
Linda encrypts all of the sensitive data on her government-issued mobile devices.
When is it appropriate to have your security badge visible?
Physically assess that everyone within listening distance is cleared and has a need-to-know for the information being discussed.
What should the owner of this printed SCI do differently?
Linda encrypts all of the sensitive data on her government-issued mobile devices.
What should the participants in this conversation involving SCI do differently?
Follow procedures for transferring data to and from outside agency and non-government networks.
Which of the following demonstrates proper protection of mobile devices?
Validate friend requests through another source through another source before confirming them.
Which of the following does NOT constitute spillage?
Download the information.
Which of the following is NOT an appropriate way to protect against inadvertent spillage?
Follow procedures for transferring data to and from outside agency and non-government networks.
Which of the following should you NOT do if you find classified information on the internet?
Original classification authority.
Who designates whether information is classified and its classification level?
Avoid talking about work outside of the workplace or with people without a need-to-know.
Which of the following is a good practice to protect classified information?
Three or more.
Which of the following may help to prevent spillage?
Report the suspicious behave in accordance with their organization's threat policy.
Which of the following is true?
It may prohibit the use of a virtual private network (VPN).
Which of the following best describes the conditions under which mobile devices and applications can track your location?
Checking personal e-mail when allowed by your organization.
When is it okay to charge a personal mobile device using government-furnished equipment (GFE)?
If you participate in or condone it at any time.
What security risk does a public Wi-Fi connection pose?
Photos of your pet.
Which of the following represents an ethical use of your Government-furnished equipment (GFE)?
They have similar features, and the same rules and protections apply to both.
When may you be subject to criminal, disciplinary, and/or administrative action due to online harassment, bullying, stalking, hazing, discrimination, or retaliation?
Only use Government-approved equipment to process PII.
How can you protect yourself on social networking sites?
CUI must be handled using safeguarding or dissemination controls.
Which of the following is true of removable media and portable electronic devices (PEDs)?
You should remove and take your CAC/PIV card whenever you leave your workstation.
Which of the following is a security best practice for protecting Personally Identifiable Information (PII)?
%2ZN=Ugq
Which of the following is true of Controlled Unclassified Information (CUI)?
in any manner.
Which Cyber Protection Condition (CPCON) establishes a protection priority focus on critical functions only?
Don't assume open storage in a secure facility is authorized.
Which of the following is true of the Common Access Card (CAC) or Personal Identity Verification (PIV) card?
2 indicators.
Which of the following is an example of a strong password?
Adversaries exploit social networking sites to disseminate fake news.
A compromise of Sensitive Compartmented Information (SCI) occurs when a person who does not have the required clearance or access caveats comes into possession of SCI________.
May be used to mask malicious intent.
Which of the following is a good practice to protest classified information?
Information improperly moved from a higher protection level to a lower protection level.
Based on the description that follows, how many potential insider threat indicators(s) are displayed? A colleague saves money for an overseas vacation every year, is a single father, and occasionally consumes alcohol.
1 indicator
Which of the following is true about URLs?
It contains certificates for identification, encryption, and digital signature.
What does "spillage refer to?
only connect government-owned PEDs to the same level classification information system when authorized.
Based on the description that follows, haw many potential insider threat indicator(s) are displayed? a colleague enjoys playing videos games, regularly uses social media, and frequently forgets to secure her smartphone elsewhere before entering areas where it is prohibited.
For Government-owned devices, use approved and authorized applications only.
A trusted friend in your social network posts a link to vaccine information on a website unknown to you. What action should you take?
You should confirm that a site that wants to store a cookie uses an encrypted link.
Which of the following is true of the Common Access Card (CAC)?
Search for instructions on how to preview where the link actually leads.
Which of the following is true of portable electronic devices (PEDs) in a Sensitive Compartmented Information Facility (SCIF)?
Avoid inserting removable media with unknown content into your computer.
Which of the following is true of downloading apps?
Implement Wi-Fi Protected Access 2 (WPA2) Personal encryption at a minimum.
Which of the following statements is true of cookies?
Attempt to change the subject to something non-work related, but neither confirm nor deny the article's authenticity
What action should you take with a compressed Uniform Resource Locator (URL) on a website known to you?
Label all files, removable media, and subject headers with appropriate classification markings.
Which of the following is a best practice for using removable media?
Spillage because classified data was moved to a lower classification level system without authorization.
How should you secure your home wireless network for teleworking?
Call your security point of contact immediately
Which of the following may help to prevent spillage? -Verify that any government equipment used for processing classified information has valid anti-virus software before connecting it to the internet -Follow procedures for transferring data to and from outside agency and non-Government networks -Purge the memory of any device removed from a classified network before connecting it to an unclassified network -Process all data at the highest classification or protection level available, including unclassified data
Secret
Who designates whether information is classified and its classification level?
1 indicator
Which of the following is a good practice for telework?
Insiders are given a level of trust and have authorized access to Government information systems
-How can you protect your organization on social networking sites?
CUI may be stored on any password-protected system.
When may you be subject to criminal, disciplinary, and/or administrative action due to online harassment, bullying, stalking, hazing, discrimination, or retaliation?
Unclassified
Which designation marks information that does not have potential to damage national security?
CPCON 1
Which of the following is true of Controlled Unclassified Information (CUI)?
CPCON 2
Which of the following is a security practice for protecting Personally Identifiable Information (PII)?
Ask the individual for identification
Which Cyber Protection Condition (CPCON) is the priority focus on critical and essential functions only?
Something you possess, like a CAC, and something you know, like a PIN or password
Which of the following is a best practice for physical security?
Maintain possession of it at all times.
Which of the following is true of using a DoD Public Key Infrastructure (PKI) token?
A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.
Which of the following is true of the Common Access Card (CAC)?
~All documents should be appropriately marked, regardless of format, sensitivity, or classification. Unclassified documents do not need to be marked as a SCIF. Only paper documents that are in open storage need to be marked.
What action should you take if you become aware that Sensitive Compartmented Information (SCI) has been compromised?
It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number.
What guidance is available for marking Sensitive Compartmented Information (SCI)?
Government-owned PEDs when expressly authorized by your agency
Which of the following is true of transmitting Sensitive Compartmented Information (SCI)?
Identify and disclose it with local Configuration/Change Management Control and Property Management authorities
Which of the following is true of Sensitive Compartmented Information (SCI)?
Damage to the removable media
Which of the following is NOT a potential consequence of using removable media unsafely in a Sensitive Compartmented Information Facility (SCIF)?
Executables
Which of the following is NOT a type of malicious code?
~By accepting cookies, you authorize websites to store your personal data on a web server. (Wrong)
What is a common indicator of a phishing attempt?
Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.
Which of the following is true of internet hoaxes?
It may be compromised as soon as you exit the plane.
Which of the following is true?
It may expose the connected device to malware.
What security issue is associated with compressed Uniform Resource Locators (URLs)?
Others may be able to view your screen.
Which of the following personally-owned computer peripherals is permitted for use with Government-furnished equipment?
When operationally necessary, owned by your organization, and approved by the appropriate authority
Which of the following is an example of removable media?
Reviewing and configuring the available security features, including encryption
Which of the following is a best practice for using removable media?
Implement Wi-Fi Protected Access 2 (WPA2) Personal encryption at a minimum
How should you secure your home wireless network for teleworking?
Classification markings and handling caveats.
Which of the following is true of protecting classified data? (CLASSIFIED DATA)
Don't assume open storage in a secure facility is permitted.
A vendor conducting a pilot program with your organization contacts you for organizational data to use in a prototype. How should you respond? (CLASSIFIED DATA)
Ensure that any cameras, microphones, and Wi-Fi embedded in the laptop are physically disabled.
When classified data is not in use, how can you protect it? (CLASSIFIED DATA)
Exceptionally grave damage.
What is the basis for handling and storage of classified data? (CLASSIFIED DATA)
Implement Wi-Fi Protected Access 2 (WPA2) Personal encryption at a minimum.
Which of the following is a good practice to protect classified information? (CLASSIFIED DATA)
You must have your organization's permission to telework.
Which of the following must you do before using an unclassified laptop and peripherals in a collateral classified environment? (CLASSIFIED DATA)
Attempting to access sensitive information without need-to-know.
What level of damage to national security can you reasonably expect Top secret information to cause if disclosed? (CLASSIFIED DATA)
A colleague removes sensitive information without seeking authorization in order to perform authorized telework.
How should you secure your home wireless network for teleworking? (HOME COMPUTER SECURITY)
1) Unusual interest in classified information. 2) Difficult life circumstances, such as death of spouse.
Which of the following is true about telework? (HOME COMPUTER SECURITY)
0 indicators.
Which of the following is a reportable insider threat activity? (INSIDER THREAT)
Your favorite movie.
Which scenario might indicate a reportable insider threat? (INSIDER THREAT)
1) Many apps and smart devices collect and share your personal information and contribute to your online identity. 2) Adversaries exploit social networking sites to disseminate fake news.
Which of the following is a potential insider threat indicator? (INSIDER THREAT)
Ensure there are no identifiable landmarks visible in any photos taken in a work setting that you post.
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague saves money for an overseas vacation every year, is a single father, and occasionally consumes alcohol. (INSIDER THREAT)
Unclassified.
Which piece of information is safest to include on your social media profile? (SOCIAL NETWORKING)
It is releasable to the public without clearance.??
Which of the following statements is true? (SOCIAL NETWORKING)
Store it in a locked desk drawer after working hours.
How can you protect your organization on social networking sites? (SOCIAL NETWORKING)
Paul verifies that the information is CUI, includes a CUI marking in the subject header, and digitally signs an e-mail containing CUI.
Which designation marks information that does not have potential to damage national security? (CONTROLLED UNCLASSIFIED INFORMATION)
Controlled Unclassified Information (CUI).
Which of the following is true of Unclassified information? (CONTROLLED UNCLASSIFIED INFORMATION)
Press release data.
Which is a best practice for protecting Controlled Unclassified Information (CUI)? (CONTROLLED UNCLASSIFIED INFORMATION)
CUI may be stored on any password-protected system.
Which of the following best describes a way to safely transmit Controlled Unclassified Information (CUI)? (CONTROLLED UNCLASSIFIED INFORMATION)
Lionel stops an individual in his secure area who is not wearing a badge.
Which designation includes Personally Identifiable Information (PII) and Protected Health Information (PHI)? (CONTROLLED UNCLASSIFIED INFORMATION)
Report suspicious activity.
Which of the following is NOT an example of CUI? (CONTROLLED UNCLASSIFIED INFORMATION)
A Common Access Card and Personal Identification Number.
Which of the following is NOT a correct way to protect CUI? (CONTROLLED UNCLASSIFIED INFORMATION)
Store it in a shielded sleeve.
Which of the following best describes good physical security? (PHYSICAL SECURITY)
It should only be in a system while actively using it for a PKI-required task.
Which of the following is a best practice for physical security? (PHYSICAL SECURITY)
Confirm the individual's need-to-know and access.
Which of the following is an example of two-factor authentication? (IDENTITY MANAGEMENT)
Access requires Top Secret clearance and indoctrination into the SCI program.
What is the best way to protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card? (IDENTITY MANAGEMENT)
Damage to the removable media.
Which of the following is true of using a DoD Public Key Infrastructure (PKI) token? (IDENTITY MANAGEMENT)
You many only transport SCI if you have been courier-briefed for SCI.
What must authorized personnel do before permitting another individual to enter a Sensitive Compartmented Information Facility (SCIF)? (SENSITIVE COMPARTMENTED INFORMATION)
In any manner.
Which of the following is true of Sensitive Compartmented Information (SCI)? (SENSITIVE COMPARTMENTED INFORMATION)
Only expressly authorized government-owned PEDs.
Which of the following is NOT a potential consequence of using removable media unsafely in a Sensitive Compartmented Information Facility (SCIF)? (SENSITIVE COMPARTMENTED INFORMATION)
With the maximum classification, date of creation, point of contact, and Change Management (CM) Control Number.
Which of the following is true of transmitting Sensitive Compartmented Information (SCI)? (SENSITIVE COMPARTMENTED INFORMATION)
All of these.
A compromise of Sensitive Compartmented Information (SCI) occurs when a person who does not have the required clearance or access caveats comes into possession of SCI _________. (SENSITIVE COMPARTMENTED INFORMATION)
Executables.
What portable electronic devices (PEDs) are permitted in a SCIF? (REMOVABLE MEDIA IN A SCIF)
Scan all external files before uploading to your computer.
How should you label removable media used in a Sensitive Compartmented Information Facility (SCIF)? (REMOVABLE MEDIA IN A SCIF)
Shred personal documents.
What is the response to an incident such as opening an uncontrolled DVD on a computer in a SCIF? (REMOVABLE MEDIA IN A SCIF)
Use a digital signature when sending attachments or hyperlinks.
Which of the following is NOT a type of malicious code? (MALICIOUS CODE)
Spear phishing.
Which of the following is a way to prevent the spread of malicious code? (MALICIOUS CODE)
Whaling.
Which of the following actions can help to protect your identity? (WEBSITE USE)
Verify the identity of all individuals.
Which is an appropriate use of government e-mail? (SOCIAL ENGINEERING)
Digitally signed e-mails are more secure.
What type of social engineering targets particular groups of people? (SOCIAL ENGINEERING)
A personally owned device approved under Bring Your Own Approved Device (BYOAD) policy must be unenrolled while out of the country.
What type of social engineering targets senior officials? (SOCIAL ENGINEERING)
The physical security of the device.
How can you protect yourself from social engineering? (SOCIAL ENGINEERING)
Only connect with Government VPN.
Which of the following is true? (SOCIAL ENGINEERING)
Both of these.
Which of the following is true of traveling overseas with a mobile phone? (TRAVEL)
A headset with a microphone through a Universal Serial Bus (USB) port.
Which of the following is a concern when using your Government-issued laptop in public? (TRAVEL)
Enable automatic screen locking after a period of inactivity.
What should Sara do when using publicly available Internet, such as hotel Wi-Fi? (TRAVEL)
Additional data charges.
What is the danger of using public Wi-Fi connections? (TRAVEL)
It may occur at any time without your knowledge or consent.
Which of the following personally-owned computer peripherals is permitted for use with Government-furnished equipment? (USE OF GFE)
External hard drive.
How can you protect data on your mobile computing and portable electronic devices (PEDs)? (MOBILE DEVICES)
They can become an attack vector to other devices on your home network.
Which of the following is NOT a risk associated with near field communication (NFC)? (MOBILE DEVICES)
At all times when in the facility.
Which of the following best describes the conditions under which mobile devices and applications can track your location? (MOBILE DEVICES)
Retrieve classified documents promptly from printers.
Which of the following is an example of removable media? (MOBILE DEVICES)
Physically assess that everyone within listening distance is cleared and has a need-to-know for the information being discussed.
Looking for a different version?
CBTs get updated every year. Search for the exact version you're taking (e.g. "cyber awareness 2025").
Search all study materials