← Back to CBT Library

Cyber Awareness Challenge

DoD annual cybersecurity training covering phishing, social engineering, data protection, and more

122 questions and answers — updated 2025/2026
01

You receive an email asking you to click a link within two days to verify your account and keep it active. Your IT department has never sent emails like this, and the email does not have a digital signature. What action should you take?

02

What is spear phishing?

03

What is whaling?

04

What is smishing?

05

What is vishing?

06

Which of the following is a best practice to protect against phishing? (A) Click links in emails to verify if they are real (B) Type the web address directly or use bookmarks instead of clicking links in emails (C) Reply to the sender to ask if it is legitimate (D) Forward the email to coworkers for their opinion

07

How can you protect against phishing emails requesting personal information?

08

You receive a suspicious email that uses your name and appears to come from inside your organization. What type of attack is this likely to be?

09

Trisha receives an email containing a dramatic rumor about a celebrity. Which action should Trisha AVOID taking with this email?

10

What should you assume about all unsolicited information requests you receive via email?

11

What are compressed URLs (such as TinyURLs) and why should you exercise caution with them?

12

An unknown caller contacts your office and asks for names from a personnel directory. What should you do?

13

What methods do social engineers use to obtain information?

14

To protect against social engineering, what should you do if an unverified person contacts you requesting information?

15

Sara, a government expert, receives an email from a foreign national who praises her work and asks to connect to learn more about her field. What must Sara do?

16

How do adversaries exploit social media to target DoD personnel?

17

What should you do to protect against social engineering during phone calls?

18

You receive a text message from a commercial shipping company claiming they need an updated address to deliver a package, with a link provided. What should you do?

19

What are the three classification levels for national security information?

20

What three conditions must be met for an individual to access classified data?

21

How should classified data be stored when not in use?

22

What is spillage in the context of classified information?

23

Which of the following may help to prevent spillage? (A) Using classified networks for unclassified work (B) Labeling all files, removable media, and subject headers with appropriate classification markings (C) Removing equipment from classified networks for use on unclassified networks (D) Connecting unauthorized devices to any network

24

If spillage occurs, what should you do?

25

A user writes down details marked as Secret from a classified system and uses those details to draft a briefing on an unclassified system without authorization. What has occurred?

26

If you find classified government data on the internet that has not been cleared for public release, what should you do?

27

Why should you NOT use a classified network for unclassified work?

28

What is Controlled Unclassified Information (CUI)?

29

What type of sensitive information does a roster containing employee names and passport numbers represent?

30

What is Personally Identifiable Information (PII)?

31

What is the most commonly reported cause of PII breaches?

32

What is Protected Health Information (PHI)?

33

Paula is organizing data about healthcare provided to service members that includes PHI. What is the most secure way to handle this data?

34

Can PII be transmitted via personal email accounts?

35

Does the following social media post raise security concerns? (Post includes mother's maiden name, home address, and birthday.)

36

How should CUI be stored after working hours if no security is present or it is deemed inadequate?

37

What DoD instruction governs CUI handling?

38

When faxing CUI, what precautions must be taken?

39

What are best practices for physical security at a government facility?

40

What should you do after leaving your controlled area or office building regarding your security badge?

41

What is piggybacking (tailgating) and how should you respond to it?

42

An unfamiliar person without a visible badge is in your secure work area. What should you do?

43

You are working at your desk and hear an unusual sound near the office door. Before leaving your workstation to investigate, what critical security step must you perform?

44

Within a SCIF, where must badges be displayed?

45

What are the risks associated with removable media on government systems?

46

What is the primary security risk that removable storage devices pose to government computer systems?

47

Can personally owned USB drives or removable media be used on government systems?

48

What must users ensure when using removable media such as a CD in a SCIF?

49

What is the best practice for labeling removable media?

50

You find an unattended USB drive in your office. What should you do?

51

Ed is authorized to work in a SCIF today. Which personal electronic items is he forbidden from bringing inside?

52

Which peripherals are you allowed to connect to Government Furnished Equipment (GFE)?

53

What two types of credentials does two-factor authentication combine?

54

Which of the following examples uses two different types of authentication factors? (A) Password and PIN (B) Two different passwords (C) Password and fingerprint (D) PIN and security question

55

What certificates does the Common Access Card (CAC)/PIV card contain?

56

How should you protect your CAC/PIV card?

57

When creating strong passwords, which practices should you follow?

58

At what level of network system are you authorized to use a SIPRNet PKI token?

59

When should you leave a DoD PKI token in a system?

60

What should you be aware of when using public Wi-Fi with a mobile device?

61

What precaution should you take when connecting a laptop to a hotel internet connection?

62

What should you assume about electronic transmissions when traveling overseas with mobile devices?

63

What is a best practice for protecting your home wireless network for telework?

64

Are DoD employees allowed to use their CAC in card-reader-enabled public devices?

65

What should you do before using a mobile device in public?

66

What is malicious code and what forms can it take?

67

Which of the following email habits helps protect against downloading viruses? (A) Open all attachments quickly (B) View email in Preview Pane (C) Look for a digital signature on emails (D) Forward suspicious emails to friends

68

What are indicators that your computer may be infected with malicious code?

69

How can you prevent the download of malicious code?

70

How should you handle email to prevent virus downloads?

71

What is Near Field Communication (NFC) and what are its security risks?

72

When you are issued a new Government mobile phone, what is the essential first step to secure it?

73

What should you do if your government mobile device is lost or stolen?

74

How can mobile device tracking be a security concern?

75

If you want to install an application on a Government-owned mobile device, what step must you take first?

76

Why is powering off a mobile device or putting it in airplane mode NOT sufficient in a classified environment?

77

What is an insider threat?

78

Which of the following is a potential insider threat indicator? (A) Taking approved vacation time (B) Untreated alcohol use disorder (C) Volunteering for extra projects (D) Arriving early to work

79

What is the specific way that an insider threat causes damage?

80

What is the primary method that Insider Threat Programs use to defend the organization?

81

John frequently appears hungover at work, handles classified information carelessly, and brings a cell phone into restricted classified areas. How many insider threat indicators is John exhibiting?

82

What behaviors should you report as potential insider threat indicators?

83

In a study of known U.S. spies, what percentage demonstrated behaviors of security concern?

84

If SCI is exposed or compromised, what action must you take immediately?

85

What is Sensitive Compartmented Information (SCI)?

86

Which statement is correct regarding SCI handling? (A) SCI can be discussed on unencrypted phones (B) SCI may be printed using an authorized printer when retrieved promptly (C) SCI can be taken home for review (D) SCI can be stored in any locked cabinet

87

Who has overarching authority concerning SCI policy?

88

What is a Security Classification Guide (SCG)?

89

Devon receives an email on her unclassified computer with an unmarked attachment she recognizes as containing classified information. What is the first thing she must do?

90

What should you do to report a cybersecurity incident?

91

If an incident occurs in a SCIF, what steps must be taken?

92

If you find classified data on the internet, what identifying information should you note?

93

Who should you report cultivation contacts by foreign nationals to?

94

What are Cyberspace Protection Conditions (CPCON)?

95

What is the Unclassified designation?

96

Can CUI be marked on any information?

97

What encryption is required when emailing PII or other CUI?

98

Oliver searched for a jacket on his phone and later saw ads for that same jacket on his laptop. Why?

99

How should you protect your identity online?

100

What is a cookie and why can it pose a security threat?

101

What should you avoid posting on social networking sites?

102

Is the social networking app TikTok allowed on government devices?

103

What should you do when posting pictures in uniform or at work on social media?

104

What is the Bring Your Own Approved Device (BYOAD) program?

105

What are prohibited uses of Government Furnished Equipment (GFE)?

106

Why is peer-to-peer (P2P) software prohibited on government systems?

107

Are all DoD-owned devices subject to monitoring?

108

What are best practices for using government email?

109

What precaution should be taken regarding monitors displaying classified information?

110

What wireless technologies are prohibited in DoD classified spaces?

111

What types of personally-owned peripherals can be used in a collateral classified environment?

112

How should you handle unclassified laptops in a collateral classified environment?

113

When can classified information be discussed on a smartphone?

114

What steps should you take to avoid being misled by online disinformation?

115

What is online misconduct according to DoD policy?

116

If you post content to a social networking site and regret it, what can you do?

117

What IoT devices pose security risks while teleworking?

118

What is a best practice for securing a home computer used by multiple family members?

119

How should data on removable media be encrypted?

120

What should you do before downloading data from classified networks onto removable storage media?

121

How should classified removable media be destroyed?

122

What is the significance of digital signatures on DoD emails?

Know questions we're missing?

Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.

Want to study these as flashcards?

Create a free study set with spaced repetition, multiple choice tests, and AI explanations.

Create Study Set