CUI Training Answers — Controlled Unclassified Information
CUI Training answers for independent study: search 41 Controlled Unclassified Information questions, compare cited regulations and review the bank with free flashcards.
Study Controlled Unclassified Information questions by separating the program's authority, the CUI Basic and CUI Specified categories, and the handling decision being asked about. This bank covers NARA's role, the CUI Registry, markings, access and dissemination. Quoted 32 CFR Part 2002 passages accompany supported answers so you can compare the regulatory wording with the training question, including corrections to imprecise older keys.
Studying for this with your unit? Send it to them.
01What is Controlled Unclassified Information (CUI)?
CUI is information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that a law, regulation, or government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. It is NOT classified but still requires protection.
VERIFIED AGAINST THE SOURCE
“Controlled Unclassified Information (CUI) is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. However, CUI does not include classified information”
— 32 CFR 2002.4(h) ↗02What DoD Instruction governs CUI within the Department of Defense?
DoDI 5200.48, Controlled Unclassified Information (CUI). It implements the CUI program within the DoD, establishes policy for identifying, marking, safeguarding, and disseminating CUI, and assigns responsibilities for compliance.
03What federal regulation establishes the government-wide CUI program?
32 CFR Part 2002, Controlled Unclassified Information. This regulation, issued by the National Archives and Records Administration (NARA), implements Executive Order 13556 and establishes the uniform program for managing CUI across the executive branch.
VERIFIED AGAINST THE SOURCE
“PART 2002--CONTROLLED UNCLASSIFIED INFORMATION (CUI) Authority: E.O. 13556, 75 FR 68675, 3 CFR, 2010 Comp., pp. 267-270. ... This part describes the executive branch's Controlled Unclassified Information (CUI) Program (the CUI Program)”
— 32 CFR 2002.1(a); Authority note to 32 CFR Part 2002 ↗04What is the role of NARA in the CUI program?
The National Archives and Records Administration (NARA) serves as the CUI Executive Agent (EA) for the federal government. NARA establishes and maintains the CUI Registry, develops policy and guidance, resolves disputes, approves CUI categories, and monitors agency implementation of the CUI program.
Why this answer
NARA's designation and ISOO's operational role are not competing answers. NARA is the designated CUI Executive Agent, while the quoted regulation says NARA delegated those responsibilities to the Director of ISOO and that ISOO staff perform the oversight and program management work.
VERIFIED AGAINST THE SOURCE
“Section 2(c) of the Order designates NARA as the CUI Executive Agent (EA) to implement the Order and to oversee agency efforts to comply with the Order, this part, and the CUI Registry. (b) NARA has delegated the CUI EA responsibilities to the Director of ISOO. Under this authority, ISOO staff carry out CUI oversight responsibilities and manage the Federal CUI program.”
— 32 CFR 2002.4(m); 32 CFR 2002.6(a)-(b) ↗05What is the CUI Registry?
The CUI Registry is the government-wide online repository maintained by NARA that lists all approved CUI categories and subcategories, the authorizing laws/regulations/policies for each, applicable markings, and handling requirements. It is the authoritative source for determining what information qualifies as CUI. Found at www.archives.gov/cui.
06What are the two types of CUI categories?
Imprecise on CUI Specified. 32 CFR 2002.4(r) says the Specified controls DIFFER from CUI Basic -- not necessarily that they are 'additional'/'beyond' it: 'CUI Specified controls may be more stringent than, or may simply differ from, those required by CUI Basic; the distinction is that the underlying authority spells out specific controls for CUI Specified information and does not for CUI Basic information.'
VERIFIED AGAINST THE SOURCE
“CUI Basic is the subset of CUI for which the authorizing law, regulation, or Government-wide policy does not set out specific handling or dissemination controls. Agencies handle CUI Basic according to the uniform set of controls set forth in this part and the CUI Registry. ... CUI Specified is the subset of CUI in which the authorizing law, regulation, or Government-wide policy contains specific handling controls that it requires or permits agencies to use that differ from those for CUI Basic.”
— 32 CFR 2002.4(j) and 2002.4(r) ↗07How is CUI different from classified information?
Classified information (Confidential, Secret, Top Secret) is protected under Executive Order 13526 and requires a security clearance for access. CUI is unclassified information that requires safeguarding but does NOT require a security clearance. CUI is protected by specific laws or regulations, not by classification authority. Unauthorized disclosure of CUI does not carry the same penalties as classified spillage.
08What are the required markings for a CUI document?
CUI documents must include: (1) the CUI banner marking at the top and bottom of each page ('CUI' or 'CONTROLLED'), (2) a CUI designation indicator identifying the specific category (e.g., CUI//SP-PRVCY for privacy), (3) the controlling office and contact information, (4) dissemination controls if applicable, and (5) a decontrol indicator when CUI status no longer applies.
VERIFIED AGAINST THE SOURCE
“The CUI banner marking. Designators of CUI must mark all CUI with a CUI banner marking, which may include up to three elements: (1) The CUI control marking (mandatory). (i) The CUI control marking may consist of either the word "CONTROLLED" or the acronym "CUI," at the designator's discretion. Agencies may specify in their CUI policy that employees must use one or the other. ... (iii) Authorized holders who designate CUI may not use alternative markings to identify or mark items as CUI.”
— 32 CFR 2002.20(b)(1) ↗09What does the CUI banner marking 'CUI//SP-' indicate?
The 'SP-' prefix indicates CUI Specified. The category abbreviation following SP- identifies which specific CUI Specified category applies (e.g., CUI//SP-PRVCY for privacy information, CUI//SP-EXPT for export-controlled technical data). CUI Specified information has handling requirements beyond the standard CUI Basic controls.
VERIFIED AGAINST THE SOURCE
“CUI category or subcategory markings (mandatory for CUI Specified). (i) The CUI Registry lists the category and subcategory markings ... authorized holders must include in the CUI banner marking all CUI Specified category or subcategory markings that pertain to the information in the document.”
— 32 CFR 2002.20(b)(2) ↗10Who can designate information as CUI?
Only authorized holders — government employees or contractors acting on behalf of the government — who have a lawful government purpose and are familiar with the CUI categories can designate information as CUI. The designation must be based on a specific authorizing law, regulation, or government-wide policy listed in the CUI Registry.
11How must CUI be transmitted via email?
CUI must be transmitted via encrypted email. Within the DoD, this typically means using digitally signed and encrypted email (S/MIME or PKI encryption). Sending CUI over unencrypted email is prohibited. The email subject line should include the CUI marking, and the body should contain appropriate CUI markings.
12What are acceptable methods for destroying CUI?
CUI in paper form must be destroyed by shredding (cross-cut shredder meeting DoDM 5200.01 standards), burning, pulping, or disintegrating. CUI on electronic media must be destroyed using methods that prevent reconstruction, such as degaussing, physical destruction, or sanitization per NIST SP 800-88 guidelines. Simply deleting files or placing paper in a regular trash bin is NOT acceptable.
Why this answer
Choose a destruction method by checking the governing authority first. If a law, regulation, or government-wide policy specifies a method for that CUI, the quoted rule requires that method. The NIST-guidance route described here applies when the authority does not specify one; a generally suitable technique is not a substitute for a specifically required method.
VERIFIED AGAINST THE SOURCE
“When destroying CUI, including in electronic form, agencies must do so in a manner that makes it unreadable, indecipherable, and irrecoverable. Agencies must use any destruction method specifically required by law, regulation, or Government-wide policy for that CUI. If the authority does not specify a destruction method, agencies must use one of the following methods: (i) Guidance for destruction in NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, and NIST SP 800-88, Guidelines for Media Sanitization”
— 32 CFR 2002.14(f)(2) ↗13True or False: CUI can be stored on a personally owned mobile device.
False. CUI should only be stored on government-authorized information systems and devices that meet the security requirements specified in DoDI 8510.01 (Risk Management Framework). Personal devices, personal email accounts, and unauthorized cloud services are not approved for CUI storage or processing.
14What is a Limited Dissemination Control?
A Limited Dissemination Control restricts who can access CUI beyond the basic 'lawful government purpose' standard. Examples include NOFORN (not releasable to foreign nationals), FEDCON (federal employees and contractors only), FED ONLY (federal employees only), and DL ONLY (dissemination list only). These controls are marked on the document.
VERIFIED AGAINST THE SOURCE
“Limited dissemination control is any CUI EA-approved control that agencies may use to limit or specify CUI dissemination.”
— 32 CFR 2002.4(dd) ↗15What physical safeguards are required for CUI documents?
CUI documents must be stored in a controlled environment such as a locked desk, cabinet, or room when not under the direct control of an authorized user. Access must be limited to authorized individuals with a lawful government purpose. CUI should not be left unattended on desks, printers, or in unsecured areas.
16Which of the following is a CUI category: (a) For Official Use Only (FOUO), (b) Privacy Information, (c) Sensitive But Unclassified (SBU), (d) Limited Official Use (LOU)?
(b) Privacy Information. The CUI program replaced legacy markings such as FOUO, SBU, LOU, and others with standardized CUI categories listed in the CUI Registry. These legacy markings are no longer authorized for use on new documents.
17What replaced the legacy 'For Official Use Only' (FOUO) marking?
CUI replaced FOUO and all other agency-specific legacy markings (SBU, LES, PROPIN, etc.) as part of the standardization under Executive Order 13556 and 32 CFR Part 2002. Information previously marked FOUO should be re-evaluated against the CUI Registry and re-marked with the appropriate CUI category.
18What is the 'lawful government purpose' standard for CUI access?
Lawful government purpose means any activity, mission, function, operation, or endeavor that the U.S. government authorizes or recognizes as within the scope of government business. A person needs a lawful government purpose to access CUI — unlike classified information, no security clearance is required, but access must be justified by a legitimate need.
Why this answer
The quoted definition is not limited to work performed by federal employees. It expressly includes recognized activities within the legal authorities of non-executive-branch entities, such as state and local law enforcement. The test concerns the legally authorized purpose, not simply whether the recipient works for a federal agency.
VERIFIED AGAINST THE SOURCE
“Lawful Government purpose is any activity, mission, function, operation, or endeavor that the U.S. Government authorizes or recognizes as within the scope of its legal authorities or the legal authorities of non-executive branch entities (such as state and local law enforcement).”
— 32 CFR 2002.4(bb) ↗19What should you do if you discover CUI on an unauthorized system?
Report the incident to your Information Security Officer, command security manager, or the organization's CUI program manager immediately. Follow your organization's incident response procedures. Do not attempt to forward, copy, or delete the CUI — allow security personnel to handle remediation and determine if further reporting is required.
20What is decontrolling CUI?
Decontrolling is the process of removing CUI status from information when it no longer requires safeguarding or dissemination controls. Only an authorized holder with decontrolling authority can decontrol CUI. Once decontrolled, the information is treated as ordinary unclassified information and does not require CUI markings or safeguards.
21How should CUI be marked on a portion-marked document?
When portion marking, each portion (paragraph, section, title, subject line) is marked with '(CUI)' at the beginning to indicate it contains CUI. Non-CUI portions are marked with '(U)' for Unclassified. The overall document still carries the CUI banner marking at the top and bottom of each page.
VERIFIED AGAINST THE SOURCE
“CUI portion markings consist of the following elements: (i) The CUI control marking, which must be the acronym "CUI"; (ii) CUI category/subcategory portion markings (if required or permitted); and (iii) CUI limited dissemination control portion markings (if required).”
— 32 CFR 2002.20(f)(3) ↗22What is the relationship between CUI and the Freedom of Information Act (FOIA)?
CUI designation does not automatically exempt information from FOIA release. When a FOIA request covers CUI, the information must still be reviewed under applicable FOIA exemptions. Some CUI categories may qualify for FOIA exemptions (e.g., privacy, law enforcement), but the CUI marking alone is not a basis for withholding information.
23What training is required for personnel who handle CUI?
All personnel who create, handle, or have access to CUI must complete CUI awareness training. This includes initial training before accessing CUI and annual refresher training thereafter. The training covers identification, marking, safeguarding, disseminating, decontrolling, and destroying CUI, as well as reporting requirements for unauthorized disclosures.
24True or False: Contractors who handle CUI on behalf of the DoD must comply with CUI requirements.
True. Contractors who create, receive, or handle CUI must comply with CUI safeguarding requirements as specified in their contracts. DFARS clause 252.204-7012 (Safeguarding Covered Defense Information) and NIST SP 800-171 establish the cybersecurity requirements contractors must meet to handle CUI.
25What is NIST SP 800-171 and how does it relate to CUI?
NIST Special Publication 800-171 establishes the cybersecurity requirements for protecting CUI in nonfederal systems and organizations (such as defense contractors). It contains 110 security requirements across 14 families. Compliance with NIST SP 800-171 is mandatory for contractors handling DoD CUI under DFARS 252.204-7012.
26What is the CMMC program and how does it relate to CUI?
The Cybersecurity Maturity Model Certification (CMMC) is a DoD program that verifies defense contractors have adequate cybersecurity practices to protect CUI. It requires third-party assessments (at Level 2 and above) to certify compliance with NIST SP 800-171 requirements before contractors can handle CUI.
27Which of the following is NOT an acceptable way to share CUI: (a) encrypted email on a government system, (b) hand-delivery in a sealed envelope, (c) posting to a personal cloud storage account, (d) approved secure file sharing platform?
(c) Posting to a personal cloud storage account. CUI may only be shared through authorized methods that provide adequate protection: government encrypted email, approved secure platforms, hand-delivery, or approved mailing methods. Personal cloud storage, personal email, and social media are never authorized for CUI.
28What Executive Order established the CUI program?
Executive Order 13556, Controlled Unclassified Information, signed on November 4, 2010. It established the CUI program to standardize the way the executive branch handles unclassified information that requires safeguarding, replacing the confusing patchwork of over 100 agency-specific markings.
VERIFIED AGAINST THE SOURCE
“Order is Executive Order 13556, Controlled Unclassified Information, November 4, 2010 (3 CFR, 2011 Comp., p. 267), or any successor order.”
— 32 CFR 2002.4(ii) ↗29What is a CUI Specified category example?
Examples of CUI Specified categories include Export Controlled (EXPT), Nuclear (NUKE), Intelligence (INTEL), NATO Restricted, and certain Privacy Act information. CUI Specified categories have additional handling requirements beyond CUI Basic, as defined by their authorizing law or regulation.
30How should CUI be handled during travel?
During travel, CUI documents should be kept in a locked briefcase or bag under your direct control at all times. Do not leave CUI in hotel rooms, vehicles, or unattended luggage. CUI on electronic devices should be encrypted, and devices should use strong passwords/PINs. Do not discuss CUI in public areas where it could be overheard.
31What is an unauthorized disclosure of CUI?
An unauthorized disclosure occurs when CUI is released, transmitted, or made accessible to individuals without a lawful government purpose, or through unauthorized channels. This includes sending CUI over unencrypted email, posting it on public websites, leaving it in unsecured locations, or sharing it with unauthorized persons. Unauthorized disclosures must be reported.
Why this answer
Intent is not a prerequisite: the regulation includes both intentional and unintentional disclosure. Accidentally making CUI available contrary to a dissemination restriction can therefore fall within the definition even if the holder did not mean to share it.
VERIFIED AGAINST THE SOURCE
“Unauthorized disclosure occurs when an authorized holder of CUI intentionally or unintentionally discloses CUI without a lawful Government purpose, in violation of restrictions imposed by safeguarding or dissemination controls, or contrary to limited dissemination controls.”
— 32 CFR 2002.4(rr) ↗32True or False: All unclassified information in the DoD is CUI.
False. CUI is a specific subset of unclassified information that requires safeguarding based on law, regulation, or policy. Most unclassified information does NOT meet the criteria for CUI and can be handled as routine unclassified information without special markings or controls.
VERIFIED AGAINST THE SOURCE
“Uncontrolled unclassified information is information that neither the Order nor the authorities governing classified information cover as protected.”
— 32 CFR 2002.4(ss) ↗33What are the organizational CUI categories in the CUI Registry?
The CUI Registry organizes categories into groupings such as: Critical Infrastructure, Defense, Export Control, Financial, Immigration, Intelligence, International Agreements, Law Enforcement, Legal, Natural and Cultural Resources, NATO, Nuclear, Patent, Privacy, Procurement and Acquisition, Proprietary Business Information, Statistical, Tax, and Transportation.
34What is the CUI Senior Agency Official (SAO)?
The CUI SAO is the senior official within each agency designated to oversee and manage the agency's CUI program. In the DoD, the SAO is responsible for policy implementation, compliance monitoring, training oversight, and serving as the agency's liaison with NARA on CUI matters.
VERIFIED AGAINST THE SOURCE
“CUI Program within that agency. The CUI SAO is the primary point of contact for official correspondence, accountability reporting, and other matters of record between the agency and the CUI EA.”
— 32 CFR 2002.4(q) ↗35How should CUI be mailed outside of the organization?
CUI sent through the U.S. Postal Service or commercial carriers must be enclosed in an opaque, sealed envelope or container. There is no requirement for double wrapping (unlike classified). The outer envelope should not indicate it contains CUI. Use certified mail, registered mail, or a tracked commercial delivery service for accountability.
36What should be included in a CUI designation indicator block?
A CUI designation indicator block (typically on the first page or cover) should include: the CUI category or categories, the designating agency or office, a point of contact, the dissemination controls (if any), the decontrol instructions or date, and any handling caveats applicable to the specific CUI Specified category.
37What happens if you improperly mark unclassified information as CUI?
Improperly marking information as CUI (overmarking) unnecessarily restricts information sharing, increases costs, and undermines the credibility of the CUI program. It can also impede FOIA compliance. Personnel who identify improperly marked CUI should notify the originating office so corrections can be made.
38What is the difference between CUI and Classified National Security Information?
Classified information (Confidential, Secret, Top Secret) is protected because its unauthorized disclosure could cause damage to national security, and access requires a security clearance. CUI is unclassified information protected by laws, regulations, or policies unrelated to national security classification. CUI does not require a clearance but does require safeguarding and authorized access.
39What role do information systems play in CUI protection?
Information systems processing CUI must be authorized under the Risk Management Framework (RMF) per DoDI 8510.01 and meet security controls commensurate with the CUI level. For DoD systems, this typically means meeting a moderate confidentiality impact level. Systems must have proper access controls, audit logging, encryption, and incident response capabilities.
40What should you do if you receive a document with legacy markings like FOUO or SBU?
Treat the document with the same protections as CUI until it can be properly evaluated. Contact the originating office to determine the appropriate CUI category and request re-marking. Legacy markings are no longer authorized for new documents but may still appear on older materials that have not yet been re-marked.
VERIFIED AGAINST THE SOURCE
“Legacy material is unclassified information that an agency marked as restricted from access or dissemination in some way, or otherwise controlled, prior to the CUI Program.”
— 32 CFR 2002.4(cc) ↗41True or False: CUI can be discussed over unsecured telephone lines.
Generally True for CUI Basic, but with caution. CUI Basic may be discussed on standard government phone lines, but should not be discussed on speakerphone in unsecured areas or where unauthorized persons might overhear. CUI Specified categories may have additional restrictions. Always be aware of your surroundings and who might be listening.
Know questions we're missing?
Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.
Study these as flashcards
Load all 41 questions into a free study set — flashcards, a practice test, and spaced repetition. No account.
Works on any PDF, doc or web page too — not just military training.
Most-searched questions from this course
Individual answer pages with the keyed answer verified across every CBT version we index.
Veteran? vetaid.ai — free VA benefits help.