Cyber Awareness Challenge Answers
Cyber Awareness Challenge answers for independent study: search 155 questions or use the linked flashcards. This mixed-version bank is not an official Army or DoD 2026 exam key.
Review Cyber Awareness Challenge questions about deceptive messages, device use and protecting information. Compare phishing, spear phishing, smishing and vishing by the clues in each question, then check the cited DoD Cyber Awareness Challenge 2026 job-aid passages alongside the answers. The bank also includes scenario wording from earlier training sets; a citation identifies the source used, not a guarantee that every exam version uses the same wording.
Studying for this with your unit? Send it to them.
01You receive an email asking you to click a link within two days to verify your account and keep it active. Your IT department has never sent emails like this, and the email does not have a digital signature. What action should you take?
Report the email to your security POC or help desk. This is a phishing attempt using urgency to trick you into clicking a malicious link.
VERIFIED AGAINST THE SOURCE
“Assume all unsolicited information requests are phishing attempts and follow your organization’s IT security policies and guidelines.”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗02What is spear phishing?
Spear phishing is a type of phishing attack that targets particular individuals, groups of people, or organizations using personalized information to appear legitimate.
VERIFIED AGAINST THE SOURCE
“Spear phishing is a type of phishing attack that targets particular individuals, groups of people, or organizations.”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗03What is whaling?
Whaling is a complex, targeted phishing attack aimed at senior officials. It uses personalized information such as the target's name, title, official email address, and sender names from personal contacts lists to create an individualized, believable message.
VERIFIED AGAINST THE SOURCE
“Uses personalized information: name, title, official e-mail address, sender names from personal contacts lists”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗04What is smishing?
Smishing is a type of social engineering that uses Short Message Service (SMS) text messages to deceive you into providing personal information or gaining access to your device. Do not reply or click the link -- delete the message.
VERIFIED AGAINST THE SOURCE
“Smishing is a type of social engineering that uses a Short Message Service (SMS) message to deceive you.”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗05What is vishing?
Vishing is a type of social engineering that uses voice calls to deceive you into giving up personal information or installing software that provides access to your devices or network. Let calls from unknown numbers go to voicemail.
VERIFIED AGAINST THE SOURCE
“Vishing is a type of social engineering that uses voice calls to deceive you into giving up personal information or installing software that provides access to your devices or network.”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗06Which of the following is a best practice to protect against phishing? (A) Click links in emails to verify if they are real (B) Type the web address directly or use bookmarks instead of clicking links in emails (C) Reply to the sender to ask if it is legitimate (D) Forward the email to coworkers for their opinion
B. Do not access sites by selecting links in emails or pop-up messages. Type the address or use bookmarks. Contact the organization using a phone number you know to be legitimate if suspicious.
VERIFIED AGAINST THE SOURCE
“Do not access sites by selecting links in e-mails or pop-up messages. Type the address or use bookmarks.”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗07How can you protect against phishing emails requesting personal information?
Never give out organizational, personal, or financial information to anyone by email. Look for digital signatures. Report emails requesting personal information to your security POC or help desk. Delete the email.
VERIFIED AGAINST THE SOURCE
“Never give out organizational, personal, or financial information to anyone by e-mail”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗08You receive a suspicious email that uses your name and appears to come from inside your organization. What type of attack is this likely to be?
This is likely a spear phishing attack. Be wary of suspicious emails that use your name and/or appear to come from inside your organization or a related organization. Report the email to your security POC.
VERIFIED AGAINST THE SOURCE
“Be wary of suspicious e-mails that use your name and/or appear to come from inside your organization or a related organization”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗09Trisha receives an email containing a dramatic rumor about a celebrity. Which action should Trisha AVOID taking with this email?
Do not forward it. Email hoaxes clog networks, slow down internet and email services, and can be part of a distributed denial of service (DDoS) attack.
VERIFIED AGAINST THE SOURCE
“Internet hoaxes clog networks, slow down internet and e-mail services, and can be part of a distributed denial of service (DDoS) attack.”
— DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange) ↗10What should you assume about all unsolicited information requests you receive via email?
Assume all unsolicited information requests are phishing attempts and follow your organization's IT security policies and guidelines.
VERIFIED AGAINST THE SOURCE
“Assume all unsolicited information requests are phishing attempts and follow your organization’s IT security policies and guidelines.”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗11What are compressed URLs (such as TinyURLs) and why should you exercise caution with them?
Compressed URLs convert a long URL into a short URL for convenience but may be used to mask malicious intent. Investigate the destination by using the preview feature to see where the link actually leads before clicking.
VERIFIED AGAINST THE SOURCE
“Compressed URLs convert a long URL into a short URL for convenience but may be used to mask malicious intent”
— DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange) ↗12An unknown caller contacts your office and asks for names from a personnel directory. What should you do?
Do not give out personal or organizational information. Document the interaction -- verify the caller's identity, write down their phone number, and take detailed notes. Contact your security POC or help desk.
VERIFIED AGAINST THE SOURCE
“Do not give out personal information”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗13What methods do social engineers use to obtain information?
Social engineers use telephone surveys, email messages, websites, text messages, automated phone calls, and in-person interviews to trick targets into revealing information.
VERIFIED AGAINST THE SOURCE
“Social engineers use telephone surveys, e-mail messages, websites, text messages, automated phone calls, and in-person interviews.”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗14To protect against social engineering, what should you do if an unverified person contacts you requesting information?
Do not participate in telephone surveys. Do not give out personal, computer, or network information. Do not follow instructions from unverified personnel. Document the interaction, verify their identity, and contact your security POC or help desk.
VERIFIED AGAINST THE SOURCE
“Do not follow instructions from unverified personnel”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗15Sara, a government expert, receives an email from a foreign national who praises her work and asks to connect to learn more about her field. What must Sara do?
Report the contact to her security POC. If you work with classified or sensitive material, you must inform your security POC of all non-professional or non-routine contacts with foreign nationals.
VERIFIED AGAINST THE SOURCE
“Inform your security POC of all non-professional or non-routine contacts with foreign nationals, including, but not limited to, joining each other’s social media sites”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗16How do adversaries exploit social media to target DoD personnel?
Adversaries disseminate fake news and propaganda, share fake audio/video (deepfakes), and gather personal information shared on social media to devise social engineering attacks against military and national security targets.
VERIFIED AGAINST THE SOURCE
“Gather personal information shared on social media to devise social engineering attacks”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗17What should you do to protect against social engineering during phone calls?
Let calls from unknown numbers go to voicemail -- legitimate callers will leave a message. Never provide personal or organizational information to unverified callers. Document the interaction and report it to your security POC.
VERIFIED AGAINST THE SOURCE
“Let calls from unknown numbers go to voicemail. Legitimate callers will leave a message.”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗18You receive a text message from a commercial shipping company claiming they need an updated address to deliver a package, with a link provided. What should you do?
Delete the message. This is a smishing attack. Do not reply or click the link in the message.
VERIFIED AGAINST THE SOURCE
“To protect against smishing: Do not reply or click the link in the message”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗19What are the three classification levels for national security information?
Confidential (damage to national security), Secret (serious damage to national security), and Top Secret (exceptionally grave damage to national security).
VERIFIED AGAINST THE SOURCE
“"Confidential" shall be applied to information, the unauthorized disclosure of which reasonably could be expected to cause damage to the national security that the original classification authority is able to identify or describe.”
— Executive Order 13526, Sec. 1.2 (Classification Levels), ISOO / National Archives ↗20What three conditions must be met for an individual to access classified data?
The individual must have: (1) an appropriate security clearance, (2) a signed and approved non-disclosure agreement, and (3) a need-to-know for the specific information.
VERIFIED AGAINST THE SOURCE
“Can only be accessed by individuals with all of the following: Appropriate clearance; Signed and approved non-disclosure agreement; Need-to-know”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗21How should classified data be stored when not in use?
Store classified data appropriately in a GSA-approved vault or security container when not in use. Do not assume open storage in a secure facility is authorized.
VERIFIED AGAINST THE SOURCE
“Store classified data appropriately in a GSA-approved vault/container when not in use”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗22What is spillage in the context of classified information?
Spillage occurs when information is 'spilled' from a higher classification or protection level to a lower classification or protection level. Spillage can be either inadvertent or intentional.
VERIFIED AGAINST THE SOURCE
“Spillage occurs when information is “spilled” from a higher classification or protection level to a lower classification or protection level. Spillage can be either inadvertent or intentional.”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗23Which of the following may help to prevent spillage? (A) Using classified networks for unclassified work (B) Labeling all files, removable media, and subject headers with appropriate classification markings (C) Removing equipment from classified networks for use on unclassified networks (D) Connecting unauthorized devices to any network
B. Label all files, removable media, and subject headers with appropriate classification markings. Also be aware of classification markings and all handling caveats.
VERIFIED AGAINST THE SOURCE
“Label all files, removable media, and subject headers with appropriate classification markings”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗24If spillage occurs, what should you do?
Immediately notify your security POC. Do not delete the suspected files. Do not forward, read further, or manipulate the file. Secure the area.
VERIFIED AGAINST THE SOURCE
“If spillage occurs: Immediately notify your security POC; Do not delete the suspected files; Do not forward, read further, or manipulate the file; Secure the area”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗25A user writes down details marked as Secret from a classified system and uses those details to draft a briefing on an unclassified system without authorization. What has occurred?
Spillage, because classified data was moved to a lower classification level system without authorization.
VERIFIED AGAINST THE SOURCE
“Spillage occurs when information is “spilled” from a higher classification or protection level to a lower classification or protection level.”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗26If you find classified government data on the internet that has not been cleared for public release, what should you do?
Do not download the information (it may create a new spillage). Note any identifying information and the website's URL. Report the situation to your security POC. Refer any inquiries to your public affairs office. Remember it is still classified even if compromised.
VERIFIED AGAINST THE SOURCE
“Do not download leaked classified or controlled information because you are not allowed to have classified information on your computer and downloading it may create a new case of spillage”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗27Why should you NOT use a classified network for unclassified work?
It can unnecessarily consume mission-essential bandwidth, may illegally shield information from FOIA disclosure, and creates a danger of spillage when attempting to remove the information to unclassified media or hard copy.
VERIFIED AGAINST THE SOURCE
“Can unnecessarily consume mission-essential bandwidth”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗28What is Controlled Unclassified Information (CUI)?
CUI is Government information that must be handled using safeguarding or dissemination controls. It includes Controlled Technical Information (CTI), PII, PHI, financial information, personal/payroll information, and operational information. CUI is NOT classified information.
VERIFIED AGAINST THE SOURCE
“Controlled Unclassified Information (CUI) is Government information that must be handled using safeguarding or dissemination controls.”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗29What type of sensitive information does a roster containing employee names and passport numbers represent?
Controlled Unclassified Information (CUI), because it contains Personally Identifiable Information (PII) -- specifically names combined with passport numbers.
VERIFIED AGAINST THE SOURCE
“It includes, but is not limited to, Controlled Technical Information (CTI), Personally Identifiable Information (PII), Protected Health Information (PHI), financial information, personal or payroll information, and operational information.”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗30What is Personally Identifiable Information (PII)?
PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other linked information. It includes Social Security Number, date and place of birth, mother's maiden name, biometric records, Protected Health Information, and passport number.
Why this answer
A detail does not have to identify someone by itself to qualify as PII. For example, an otherwise ambiguous record can become identifying when linked to another record about the same person. The test is whether identity can be distinguished or traced using the available combination, not whether each field looks identifying in isolation.
VERIFIED AGAINST THE SOURCE
“Personally Identifiable Information (PII) is information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other information that is linked or linkable to a specific individual.”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗31What is the most commonly reported cause of PII breaches?
The most commonly reported cause of PII breaches is failure to encrypt email messages containing PII.
VERIFIED AGAINST THE SOURCE
“The most commonly reported cause of PII breaches is failure to encrypt e-mail messages containing PII.”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗32What is Protected Health Information (PHI)?
PHI is a subset of PII requiring additional protection. It is health information that identifies the individual, created or received by a healthcare provider, health plan, employer, or business associate, relating to physical/mental health, healthcare provision, or payment for healthcare.
VERIFIED AGAINST THE SOURCE
“Is a subset of PII requiring additional protection”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗33Paula is organizing data about healthcare provided to service members that includes PHI. What is the most secure way to handle this data?
Use Government-furnished or Government-approved equipment with extra protection and encryption, especially on mobile devices.
VERIFIED AGAINST THE SOURCE
“Only use Government-furnished or Government-approved equipment to process CUI, including PII.”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗34Can PII be transmitted via personal email accounts?
No. Never use personal email accounts for transmitting PII. PII may only be emailed between Government email accounts and must be encrypted and digitally signed when possible.
VERIFIED AGAINST THE SOURCE
“Never use personal e-mail accounts for transmitting PII. PII may only be e-mailed between Government e-mail accounts and must be encrypted and digitally signed when possible.”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗35Does the following social media post raise security concerns? (Post includes mother's maiden name, home address, and birthday.)
Yes. It contains several items of PII including mother's maiden name, home address, and birthday. Avoid posting PII on social media.
VERIFIED AGAINST THE SOURCE
“Avoid posting personally identifiable information (PII): Social Security Number; Date and place of birth; Mother’s maiden name; Home address”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗36How should CUI be stored after working hours if no security is present or it is deemed inadequate?
In locked containers, desks, or cabinets. If security is present, locked or unlocked containers are acceptable.
VERIFIED AGAINST THE SOURCE
“Locked containers, desks, cabinets if no security is present or is deemed inadequate”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗37What DoD instruction governs CUI handling?
DoD Instruction 5200.48, 'Controlled Unclassified Information (CUI),' along with Defense Federal Acquisition Regulation Supplement (DFARS) for CUI and Controlled Technical Information (CTI) handling requirements.
VERIFIED AGAINST THE SOURCE
“Follow policy in DoD Instruction 5200.48, “Controlled Unclassified Information (CUI)” for retention or disposal”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗38When faxing CUI, what precautions must be taken?
Ensure the recipient is at the receiving end, use the correct cover sheet, and contact the recipient to confirm receipt.
VERIFIED AGAINST THE SOURCE
“If faxing CUI: Ensure recipient is at the receiving end; Use correct cover sheet; Contact the recipient to confirm receipt”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗39What are best practices for physical security at a government facility?
Use your own security badge/key code, don't allow others to piggyback into secure areas, challenge people without proper badges, report suspicious activity, and protect access rosters from public view.
VERIFIED AGAINST THE SOURCE
“Use your own security badge/key code. Note that your Common Access Card (CAC)/Personal Identity Verification (PIV) card is sometimes used as a facility access badge.”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗40What should you do after leaving your controlled area or office building regarding your security badge?
Remove your security badge after leaving your controlled area or office building to avoid being targeted by adversaries.
VERIFIED AGAINST THE SOURCE
“Remove your security badge after leaving your controlled area or office building”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗41What is piggybacking (tailgating) and how should you respond to it?
Piggybacking is when someone follows an authorized person through a secure entrance without badging in themselves. Do not allow others access or to piggyback into secure areas. Everyone must badge in individually.
VERIFIED AGAINST THE SOURCE
“Don’t allow others access or to piggyback into secure areas”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗42An unfamiliar person without a visible badge is in your secure work area. What should you do?
Challenge people without proper badges. Report suspicious activity to your security POC. Ensure uncleared persons are escorted by a cleared person familiar with facility security procedures.
VERIFIED AGAINST THE SOURCE
“Challenge people without proper badges”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗43You are working at your desk and hear an unusual sound near the office door. Before leaving your workstation to investigate, what critical security step must you perform?
Remove your Common Access Card (CAC) from your workstation to lock it before walking away.
VERIFIED AGAINST THE SOURCE
“Remove and take your CAC/PIV card whenever you leave your workstation”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗44Within a SCIF, where must badges be displayed?
Badges must be visible and displayed above the waist at all times while in the facility. Badges must be removed when leaving the facility.
VERIFIED AGAINST THE SOURCE
“Badges must be visible and displayed above the waist at all times while in the facility”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗45What are the risks associated with removable media on government systems?
Introduction of malicious code, compromise of systems' confidentiality, availability, and/or integrity, and spillage of classified information. Potential consequences include shutdown of systems, compromise of information, loss of mission, and loss of life.
VERIFIED AGAINST THE SOURCE
“The risks associated with removable media include: Introduction of malicious code; Compromise of systems’ confidentiality, availability, and/or integrity; Spillage of classified information”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗46What is the primary security risk that removable storage devices pose to government computer systems?
Their data storage and ability to connect to systems can lead to unintended transfers of information, such as introduction of malicious code or spillage of classified data.
VERIFIED AGAINST THE SOURCE
“Potential consequences: Shutdown of systems; Compromise of information, systems, programs, and/or assets; Loss of mission; Loss of life”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗47Can personally owned USB drives or removable media be used on government systems?
No. Do not use any personally owned or non-organizational removable media on your organization's systems. Only use removable media approved by your organization.
VERIFIED AGAINST THE SOURCE
“Do not use any personally owned/non-organizational removable media on your organization’s systems”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗48What must users ensure when using removable media such as a CD in a SCIF?
Media shall display a label inclusive of maximum classification, date of creation, point of contact (POC), and Configuration Management (CM) Control Number.
VERIFIED AGAINST THE SOURCE
“Media shall display a label inclusive of maximum classification, date of creation, POC, and CM Control Number”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗49What is the best practice for labeling removable media?
Label all removable media regardless of classification or environment, and avoid inserting removable media with unknown content into your computer.
VERIFIED AGAINST THE SOURCE
“As a best practice, label all removable media regardless of classification or environment and avoid inserting removable media with unknown content into your computer”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗50You find an unattended USB drive in your office. What should you do?
Do not plug it into any computer. Turn it in to your security office. Unattended removable media may contain malware or could be part of a baiting social engineering attack.
VERIFIED AGAINST THE SOURCE
“Never plug unauthorized devices into a government system”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗51Ed is authorized to work in a SCIF today. Which personal electronic items is he forbidden from bringing inside?
All personal portable electronic devices (PEDs) are forbidden in a SCIF -- including cell phones, smart watches, fitness trackers, tablets, and any device with Wi-Fi, Bluetooth, cellular, image capturing, video, or audio recording capabilities.
VERIFIED AGAINST THE SOURCE
“No personal PEDs are allowed in a Sensitive Compartmented Information Facility (SCIF).”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗52Which peripherals are you allowed to connect to Government Furnished Equipment (GFE)?
Personally-owned peripherals are permitted with GFE: monitors via VGA, DVI, HDMI, or DisplayPort (with nothing else connected to the monitor); wired keyboards, mice, and trackballs via USB; USB hubs; and headphones/headsets, with or without microphones, through a USB port. Not permitted: monitors connected via USB, peripherals from a prohibited source, Bluetooth or other wireless external peripherals, and installing drivers to support personally-owned peripherals. (The stricter government-issued-only rule applies inside DoD classified spaces, not to GFE generally.)
VERIFIED AGAINST THE SOURCE
“Wired keyboards, mice, and trackballs through a Universal Serial Bus (USB) connection”
— DoD Cyber Awareness Challenge 2026, Telework and Home Computer Security job aid (DISA / DoD Cyber Exchange) ↗53What two types of credentials does two-factor authentication combine?
Two-factor authentication combines two of these three types: something you possess (such as a CAC), something you know (such as a PIN), and something you are (such as a fingerprint or biometrics).
Why this answer
Count credential types, not the number of things entered. A password and a PIN are both things you know, so that pair does not span two of the listed types. A CAC and its PIN do: the card is something you possess and the PIN is something you know.
VERIFIED AGAINST THE SOURCE
“Something you possess, such as a Common Access Card (CAC); Something you know, such as your Personal Identification Number (PIN); Something you are, such as a fingerprint or other biometrics”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗54Which of the following examples uses two different types of authentication factors? (A) Password and PIN (B) Two different passwords (C) Password and fingerprint (D) PIN and security question
C. Password and fingerprint -- these combine something you know (password) with something you are (biometrics). The others all use the same factor type (something you know).
VERIFIED AGAINST THE SOURCE
“Something you know, such as your Personal Identification Number (PIN); Something you are, such as a fingerprint or other biometrics”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗55What certificates does the Common Access Card (CAC)/PIV card contain?
The CAC/PIV implements DoD Public Key Infrastructure (PKI) and contains certificates for identification, encryption, and digital signature.
VERIFIED AGAINST THE SOURCE
“It implements DoD Public Key Infrastructure (PKI) and contains certificates for: Identification; Encryption; Digital signature”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗56How should you protect your CAC/PIV card?
Maintain possession at all times. Remove it whenever leaving your workstation. Never surrender it for building access. Store in a shielded sleeve to prevent cloning. Do not write down or share your PIN. Report it immediately if lost.
VERIFIED AGAINST THE SOURCE
“Store it in a shielded sleeve to mitigate card and chip cloning”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗57When creating strong passwords, which practices should you follow?
Combine letters, numbers, and special characters. Do not use personal information, common phrases, or dictionary words in any language. Do not write it down -- memorize it. Change passwords at least every 3 months. Avoid using the same password across systems.
VERIFIED AGAINST THE SOURCE
“Combine letters, numbers, and special characters; Do not use personal information; Do not use common phrases or dictionary words in any language”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗58At what level of network system are you authorized to use a SIPRNet PKI token?
SIPRNet only. Never use a token approved for NIPRNet on a higher classification system, and never use a SIPRNet token on the NIPRNet. Only use a token within its designated classification level.
VERIFIED AGAINST THE SOURCE
“Only use a token within its designated classification level”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗59When should you leave a DoD PKI token in a system?
Only leave it in a system while actively using it for a PKI-required task. Never use on publicly accessible computers such as kiosks, internet cafes, or public libraries.
VERIFIED AGAINST THE SOURCE
“Only leave in a system while actively using it for a PKI-required task”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗60What should you be aware of when using public Wi-Fi with a mobile device?
Information sent over public Wi-Fi connections may be exposed to theft, and the device may be exposed to malware. Fake Wi-Fi access points may be used for deception. Use public or free Wi-Fi only with the Government VPN.
VERIFIED AGAINST THE SOURCE
“Be aware that information sent over public Wi-Fi connections may be exposed to theft, and the device may be exposed to malware”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗61What precaution should you take when connecting a laptop to a hotel internet connection?
Use caution -- if you are directed to a login page before you can connect by VPN, the risk of malware loading or data compromise is substantially increased.
VERIFIED AGAINST THE SOURCE
“Use caution when connecting laptops to hotel Internet connections. If you are directed to a login page before you can connect by VPN, the risk of malware loading or data compromise is substantially increased.”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗62What should you assume about electronic transmissions when traveling overseas with mobile devices?
Assume that any electronic transmission (voice or data) may be monitored. Mobile phones carried overseas are often compromised upon exiting the plane. Devices not in your custody or in secure U.S. Government facility storage should be assumed compromised.
VERIFIED AGAINST THE SOURCE
“Assume that any electronic transmission you make (voice or data) may be monitored”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗63What is a best practice for protecting your home wireless network for telework?
Implement, at a minimum, Wi-Fi Protected Access 2 (WPA2) Personal encryption on your home wireless network.
VERIFIED AGAINST THE SOURCE
“Implement Wi-Fi Protected Access 2 (WPA2) Personal”
— DoD Cyber Awareness Challenge 2026, Telework and Home Computer Security job aid (DISA / DoD Cyber Exchange) ↗64Are DoD employees allowed to use their CAC in card-reader-enabled public devices?
No. DoD employees are prohibited from using a DoD CAC in card-reader-enabled public devices such as those found in public libraries and internet cafes.
VERIFIED AGAINST THE SOURCE
“DoD employees are prohibited from using a DoD CAC in card-reader-enabled public devices such as those found in public libraries and Internet cafes”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗65What should you do before using a mobile device in public?
Be careful of information visible on the screen (consider screen protection), maintain possession of the device at all times, use password or two-factor authentication, ensure all sensitive data is encrypted, and never discuss sensitive information in public.
VERIFIED AGAINST THE SOURCE
“Be careful of information visible on your mobile computing device; consider screen protection”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗66What is malicious code and what forms can it take?
Malicious code can corrupt files, encrypt or erase your hard drive, and allow hackers access. It includes viruses, Trojan horses, worms, macros, and scripts. It can spread via email attachments, downloading files, and visiting infected websites.
VERIFIED AGAINST THE SOURCE
“Malicious code can do damage by corrupting files, encrypting or erasing your hard drive, and/or allowing hackers access. Malicious code includes viruses, Trojan horses, worms, macros, and scripts.”
— DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange) ↗67Which of the following email habits helps protect against downloading viruses? (A) Open all attachments quickly (B) View email in Preview Pane (C) Look for a digital signature on emails (D) Forward suspicious emails to friends
C. Look for digital signatures if your organization uses them. Digitally signed emails are more secure. Also view email in plain text, scan all attachments, and don't access links or graphics in emails.
VERIFIED AGAINST THE SOURCE
“Use caution when opening e-mail: Look for digital signatures if your organization uses them. Digitally signed e-mails are more secure.”
— DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange) ↗68What are indicators that your computer may be infected with malicious code?
Sudden flashing pop-ups warning of virus infection, sudden appearance of new apps or programs, strange pop-ups during startup/operation/shutdown, device slowing down, new browser extensions or tabs, and loss of control of mouse or keyboard.
VERIFIED AGAINST THE SOURCE
“Sudden flashing pop-ups that warn that your computer is infected with a virus”
— DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange) ↗69How can you prevent the download of malicious code?
Scan all external files before uploading. For personal devices, research apps before downloading. For Government devices, use only approved and authorized applications. Only allow mobile code from your organization's trusted sites to run.
VERIFIED AGAINST THE SOURCE
“Scan all external files before uploading to your computer”
— DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange) ↗70How should you handle email to prevent virus downloads?
View email in plain text (not Preview Pane), look for digital signatures, scan all attachments, delete emails from unknown senders if authenticity cannot be confirmed, and do not click links, buttons, or graphics in emails or email-generated pop-ups.
VERIFIED AGAINST THE SOURCE
“View e-mail in plain text and don’t view e-mail in Preview Pane”
— DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange) ↗71What is Near Field Communication (NFC) and what are its security risks?
NFC is wireless technology enabling devices to communicate when placed next to each other (e.g., contactless payments). Risks include eavesdropping (adversary intercepts signal), data manipulation/corruption, and viruses targeting stored financial or mission information.
VERIFIED AGAINST THE SOURCE
“NFC is wireless technology that enables your electronic devices to establish communications and exchange information when placed next to each other.”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗72When you are issued a new Government mobile phone, what is the essential first step to secure it?
Set up a passcode to unlock it. Additionally, enable automatic screen locking, encrypt all sensitive data, and use two-factor authentication if possible.
VERIFIED AGAINST THE SOURCE
“At a minimum, password protect Government-issued mobile computing devices; use two-factor authentication if possible”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗73What should you do if your government mobile device is lost or stolen?
Immediately report the loss to your security POC.
VERIFIED AGAINST THE SOURCE
“If lost or stolen, immediately report the loss to your security POC”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗74How can mobile device tracking be a security concern?
Many mobile devices and apps can track your location without your knowledge or consent. They can geolocate you, display your location, record location history, and activate tracking by default.
VERIFIED AGAINST THE SOURCE
“Many mobile devices and applications can track your location without your knowledge or consent.”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗75If you want to install an application on a Government-owned mobile device, what step must you take first?
Ensure that it is an approved and authorized application. Only use applications authorized by your organization on Government devices.
VERIFIED AGAINST THE SOURCE
“For Government-owned devices, use approved and authorized applications only”
— DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange) ↗76Why is powering off a mobile device or putting it in airplane mode NOT sufficient in a classified environment?
Mobile devices may be hacked or infected with malware and can be used to track, record, photograph, or videotape the environment. Powering off or airplane mode is not sufficient to mitigate these risks and the threat to classified information.
VERIFIED AGAINST THE SOURCE
“Mobile devices and peripherals may be hacked or infected with malware and can be used to track, record, photograph, or videotape the environment around them. Powering off or putting devices in airplane mode is not sufficient to mitigate these risks and the threat these devices pose to classified information.”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗77What is an insider threat?
An insider threat uses authorized access, wittingly or unwittingly, to harm national security through unauthorized disclosure, data modification, espionage, terrorism, or kinetic actions resulting in loss or degradation of resources or capabilities.
VERIFIED AGAINST THE SOURCE
“An insider threat uses authorized access, wittingly or unwittingly, to harm national security through unauthorized disclosure, data modification, espionage, terrorism, or kinetic actions resulting in loss or degradation of resources or capabilities.”
— DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange) ↗78Which of the following is a potential insider threat indicator? (A) Taking approved vacation time (B) Untreated alcohol use disorder (C) Volunteering for extra projects (D) Arriving early to work
B. Untreated alcohol use disorder is a recognized insider threat indicator. Other indicators include financial difficulties, unexplained affluence, unreported foreign contact, hostile behavior, and inappropriate interest in classified information.
VERIFIED AGAINST THE SOURCE
“We detect insider threats by using our powers of observation to recognize potential insider threat indicators. These include, but are not limited to: Difficult life circumstances; Divorce or death of spouse; Alcohol or other substance misuse or dependence; Untreated mental health issues; Financial difficulties”
— DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange) ↗79What is the specific way that an insider threat causes damage?
By exploiting their trusted status and authorized access to government information systems and resources.
VERIFIED AGAINST THE SOURCE
“Insiders are able to do extraordinary damage to their organizations by exploiting their trusted status and authorized access to government information systems.”
— DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange) ↗80What is the primary method that Insider Threat Programs use to defend the organization?
Intervening early to help individuals with issues -- such as referring them to counseling or assistance to alleviate personal stressors, requiring security training, and developing protocols to secure information, resources, and personnel.
VERIFIED AGAINST THE SOURCE
“We defend against the damage insider threats can cause by deterring insiders from becoming threats.”
— DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange) ↗81John frequently appears hungover at work, handles classified information carelessly, and brings a cell phone into restricted classified areas. How many insider threat indicators is John exhibiting?
Three or more: alcohol misuse, mishandling of classified information, and bringing electronic devices into prohibited areas.
VERIFIED AGAINST THE SOURCE
“Bringing an electronic device into prohibited areas”
— DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange) ↗82What behaviors should you report as potential insider threat indicators?
Attempting to access information without need-to-know, unauthorized removal of sensitive information, unusual requests for sensitive data, electronic devices in prohibited areas, sudden high-value purchases, unexplained overseas trips, substance problems, personality changes, and hostile statements.
VERIFIED AGAINST THE SOURCE
“Attempt to access sensitive information without the need-to-know; Unauthorized removal of sensitive information; Unusual request for sensitive information; Bringing an electronic device into prohibited areas; Sudden purchases of high value items/living beyond one’s means”
— DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange) ↗83In a study of known U.S. spies, what percentage demonstrated behaviors of security concern?
80% demonstrated behaviors of security concern, 25% experienced a life crisis, and 70% volunteered their services (were not recruited).
VERIFIED AGAINST THE SOURCE
“In one report on known U.S. spies, these individuals: Demonstrated behaviors of security concerns: 80% of the time; Experienced a life crisis: 25% of the time; Volunteered: 70% of the time”
— DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange) ↗84If SCI is exposed or compromised, what action must you take immediately?
Call your security point of contact (POC). Do not elaborate on sensitive/classified details until secure two-way communications (verbal or transmitted) can be achieved.
VERIFIED AGAINST THE SOURCE
“You are required to contact your security Point of Contact (POC) to report the incident.”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗85What is Sensitive Compartmented Information (SCI)?
SCI is a program that segregates classified information into distinct compartments for added protection and dissemination control. It overlays Top Secret, Secret, and Confidential information. Access requires Top Secret clearance and indoctrination into the specific SCI program.
VERIFIED AGAINST THE SOURCE
“Sensitive Compartmented Information (SCI) is a program that segregates various types of classified information into distinct compartments for added protection and dissemination or distribution control.”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗86Which statement is correct regarding SCI handling? (A) SCI can be discussed on unencrypted phones (B) SCI may be printed using an authorized printer when retrieved promptly (C) SCI can be taken home for review (D) SCI can be stored in any locked cabinet
B. SCI may be printed using an authorized printer when retrieved promptly. Use appropriate classification cover sheets and ensure classified material is not mixed with unclassified material being removed from the SCIF.
VERIFIED AGAINST THE SOURCE
“Retrieve classified documents promptly from printers”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗87Who has overarching authority concerning SCI policy?
The Director of National Intelligence has overarching authority concerning SCI policy.
VERIFIED AGAINST THE SOURCE
“The Director of National Intelligence has overarching authority concerning SCI policy.”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗88What is a Security Classification Guide (SCG)?
An SCG provides precise, comprehensive guidance on classifying specific program, system, operation, or weapon system information -- including classification levels, reasons, and duration. It is approved by the Original Classification Authority (OCA) and is an authoritative source for derivative classification.
VERIFIED AGAINST THE SOURCE
“Provides precise, comprehensive guidance regarding specific program, system, operation, or weapon system elements of information to be classified”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗89Devon receives an email on her unclassified computer with an unmarked attachment she recognizes as containing classified information. What is the first thing she must do?
Immediately notify her security point of contact (POC). Do not delete, forward, read further, or manipulate the file.
VERIFIED AGAINST THE SOURCE
“If spillage occurs: Immediately notify your security POC; Do not delete the suspected files; Do not forward, read further, or manipulate the file”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗90What should you do to report a cybersecurity incident?
Immediately notify your security POC or help desk. Do not delete suspected files. Do not forward or manipulate evidence. Secure the area. Document what happened and when.
VERIFIED AGAINST THE SOURCE
“Immediately notify your security POC”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗91If an incident occurs in a SCIF, what steps must be taken?
Notify your security POC, analyze the media for viruses or malicious code, analyze other workstations in the SCIF, and if unintentional, the person may attend a refresher training course in security awareness.
VERIFIED AGAINST THE SOURCE
“Notify your security POC about the incident; An analysis of the media must be conducted for viruses or malicious code; The other workstations in the SCIF must also be analyzed”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗92If you find classified data on the internet, what identifying information should you note?
Note any identifying information and the website's URL, then report it to your security POC. Do not download the information. Remember that leaked classified information is still classified even if it has been compromised.
VERIFIED AGAINST THE SOURCE
“Note any identifying information and the website’s URL”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗93Who should you report cultivation contacts by foreign nationals to?
Report cultivation contacts by foreign nationals to your security POC. Inform your security POC of all non-professional or non-routine contacts with foreign nationals.
VERIFIED AGAINST THE SOURCE
“Report cultivation contacts by foreign nationals”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗94What are Cyberspace Protection Conditions (CPCON)?
CPCON levels established by USCYBERCOM set protection priorities during significant cyberspace events. CPCON 1 = Very High risk (Critical Functions only), CPCON 2 = High, CPCON 3 = Medium, CPCON 4 = Low, CPCON 5 = Very Low (All Functions).
VERIFIED AGAINST THE SOURCE
“The United States Cyber Command (USCYBERCOM) Instruction 5200-13 establishes Cyberspace Protection Conditions (CPCON) for the DoD. CPCON establishes protection priorities for each level during significant cyberspace events”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid, citing USCYBERCOM Instruction 5200-13 (DISA / DoD Cyber Exchange) ↗95What is the Unclassified designation?
Unclassified marks information that does not have potential to damage national security. It must be cleared before public release, may require CUI controls, and if aggregated, may be elevated to a higher sensitivity level or even become classified.
VERIFIED AGAINST THE SOURCE
“Unclassified is a designation to mark information that does not have potential to damage national security (i.e., not been determined to be Confidential, Secret, or Top Secret).”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗96Can CUI be marked on any information?
No. CUI may only be marked as CUI if it belongs to a category established in the DoD CUI Registry.
VERIFIED AGAINST THE SOURCE
“CUI is NOT classified information and may only be marked as CUI if it belongs to a category established in the DoD CUI Registry.”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗97What encryption is required when emailing PII or other CUI?
Use encryption when emailing PII or other types of CUI, as required by the DoD. The DoD requires use of two-factor authentication for access to systems processing CUI.
VERIFIED AGAINST THE SOURCE
“Use encryption when e-mailing Personally Identifiable Information (PII) or other types of CUI, as required by the DoD”
— DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange) ↗98Oliver searched for a jacket on his phone and later saw ads for that same jacket on his laptop. Why?
Oliver's apps and devices collect and share information about him. Online data aggregators collect and catalogue your information from apps, smart devices, and public records, which can be used to target you with tailored advertisements and scams.
VERIFIED AGAINST THE SOURCE
“online data aggregators collect and catalogue information about you. This information can be used to further target you, such as with scams posing as advertisements that are tailored to your preferences.”
— DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange) ↗99How should you protect your identity online?
Ask how information will be used before giving it out, pay attention to financial statements, avoid common names/dates for passwords, never share passwords, shred personal documents, refrain from carrying SSN card, and order your credit report annually.
VERIFIED AGAINST THE SOURCE
“Ask how information will be used before giving it out; Pay attention to credit card and bank statements; Avoid common names/dates for passwords and PINs; Never share passwords and PINs”
— DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange) ↗100What is a cookie and why can it pose a security threat?
A cookie is a text file stored on your hard drive by a web server. Cookies may pose a security threat when they save unencrypted personal information and may track your web activities. Only accept cookies from reputable, trusted websites using encrypted (HTTPS) links.
VERIFIED AGAINST THE SOURCE
“A cookie is a text file that a web server stores on your hard drive. Cookies may pose a security threat, particularly when they save unencrypted personal information.”
— DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange) ↗101What should you avoid posting on social networking sites?
Avoid posting PII (SSN, date/place of birth, mother's maiden name, home address), GPS/location information, and any content that could reveal operational details. Do not connect with people you don't know, even if you share mutual connections.
VERIFIED AGAINST THE SOURCE
“Don’t connect with people you don’t know, even if you share mutual connections”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗102Is the social networking app TikTok allowed on government devices?
No. TikTok is banned on all Government devices.
VERIFIED AGAINST THE SOURCE
“The social networking app TikTok is banned on all Government devices.”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗103What should you do when posting pictures in uniform or at work on social media?
Make sure there are no identifiable landmarks or items visible. When establishing personal social networking accounts, use only personal contact information, never your Government contact information.
VERIFIED AGAINST THE SOURCE
“If posting pictures of yourself in uniform or in a work-setting, make sure there are no identifiable landmarks or items visible”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗104What is the Bring Your Own Approved Device (BYOAD) program?
BYOAD allows use of personal devices per organization policy. You must read and sign a User Agreement, and the approved device will be provisioned to employ necessary security measures. Use depends on your organization's specific policies.
VERIFIED AGAINST THE SOURCE
“Read and sign the User Agreement that includes the program’s requirements and policies; Use of your personal device depends on your organization’s policies; The approved device will be provisioned to employ necessary security measures to secure it and its data when accessed”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid — "AMD Programs" (DISA / DoD Cyber Exchange) ↗105What are prohibited uses of Government Furnished Equipment (GFE)?
Do not: view/download pornography, gamble online, conduct private business, load unauthorized software (including DropBox or P2P), illegally download copyrighted material, make unauthorized configuration changes. Use GFE for official purposes only.
VERIFIED AGAINST THE SOURCE
“Use GFE for official purposes only; Don’t allow unauthorized users to use your GFE; Don’t view or download pornography; Don’t gamble on the Internet; Don’t conduct private business/money-making ventures”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗106Why is peer-to-peer (P2P) software prohibited on government systems?
P2P software can compromise network configurations, spread viruses and spyware, and allow unauthorized access to data.
VERIFIED AGAINST THE SOURCE
“P2P software can compromise network configurations, spread viruses and spyware, and allow unauthorized access to data”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗107Are all DoD-owned devices subject to monitoring?
Yes. All DoD-owned devices are subject to monitoring. When you use these devices, you authorize the monitoring of your activity on them.
VERIFIED AGAINST THE SOURCE
“All DoD-owned devices are subject to monitoring. When you use these devices, you authorize the monitoring of your activity on these devices.”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗108What are best practices for using government email?
Do not use email to sell anything. Do not send chain letters, offensive letters, mass emails, jokes, or unnecessary pictures. Use digital signatures when sending attachments/hyperlinks. Do not use personal accounts for official DoD communication.
VERIFIED AGAINST THE SOURCE
“Do not use personal accounts, such as webmail, to conduct official DoD communication”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗109What precaution should be taken regarding monitors displaying classified information?
Ensure monitors do not provide unobstructed views of classified information. Monitors facing windows should be turned or window blinds should be closed.
VERIFIED AGAINST THE SOURCE
“Ensure monitors do not provide unobstructed views of classified information”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗110What wireless technologies are prohibited in DoD classified spaces?
All wireless headsets, microphones, and webcams are prohibited. As a general rule, there should be no Wi-Fi, Bluetooth, cellular, image capturing, video recording, or audio recording capabilities or wearable devices in a SCIF.
VERIFIED AGAINST THE SOURCE
“All wireless headsets, microphones, and webcams are prohibited in DoD classified spaces, as well as all personally-owned external peripherals other than wired headsets.”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗111What types of personally-owned peripherals can be used in a collateral classified environment?
Only personally-owned wired headsets without a microphone are permitted. All other personally-owned external peripherals are prohibited in DoD classified spaces.
VERIFIED AGAINST THE SOURCE
“Personally-owned wired headsets without a microphone”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗112How should you handle unclassified laptops in a collateral classified environment?
Ensure any embedded cameras, microphones, and Wi-Fi are physically disabled. Use only authorized external peripherals.
VERIFIED AGAINST THE SOURCE
“Ensure that any embedded cameras, microphones, and Wi-Fi are physically disabled”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗113When can classified information be discussed on a smartphone?
Never. Do not discuss classified information over smartphones, and do not view classified information via a device when not in a cleared space.
VERIFIED AGAINST THE SOURCE
“Don’t discuss classified information over smartphones”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗114What steps should you take to avoid being misled by online disinformation?
Research the source's credibility, read beyond the headline, check against known facts and other sources, consider if it's intended as a joke, and check your personal biases -- actively seek opposing or disconfirming content.
VERIFIED AGAINST THE SOURCE
“Research the source to evaluate its credibility and reliability; Read beyond the headline; Check against known facts and other sources on the topic; Consider whether the story is intended as a joke; Check your personal biases”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗115What is online misconduct according to DoD policy?
Online misconduct is inconsistent with DoD values. Do NOT use electronic communications for harassment, bullying, hazing, stalking, discrimination, or retaliation. Individuals who participate may face criminal, disciplinary, or administrative action. No one is truly anonymous online.
VERIFIED AGAINST THE SOURCE
“Online misconduct is inconsistent with DoD values. Individuals who participate in or condone misconduct, whether offline or online, may be subject to criminal, disciplinary, and/or administrative action.”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗116If you post content to a social networking site and regret it, what can you do?
You can delete the post, but be aware that once content is posted, it may have already been shared, cached, or archived. Sites may own content you post, and it may not be fully removable.
VERIFIED AGAINST THE SOURCE
“Sites own any content you post. Once you post content, it can’t be taken back.”
— DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange) ↗117What IoT devices pose security risks while teleworking?
All internet-connected devices in a telework environment pose risks, including smart speakers, fitness trackers, smart TVs, home security cameras, and personal digital assistants. These devices collect data and may be exploited.
VERIFIED AGAINST THE SOURCE
“When using your home network to telework, an unsecured IoT device could become an attack vector to any attached government-furnished equipment (GFE).”
— DoD Cyber Awareness Challenge 2026, Telework and Home Computer Security job aid (DISA / DoD Cyber Exchange) ↗118What is a best practice for securing a home computer used by multiple family members?
Create separate user accounts for each user and have each user create their own password.
Why this answer
The quoted practice has three parts: enable passwords, separate the accounts, and let each user create a strong password of their own. A single password-protected family account satisfies only the first part; it does not satisfy the separate-account recommendation.
VERIFIED AGAINST THE SOURCE
“Turn on password feature, create separate accounts for each user, and have them create their own passwords using a strong password creation method”
— DoD Cyber Awareness Challenge 2026, Telework and Home Computer Security job aid (DISA / DoD Cyber Exchange) ↗119How should data on removable media be encrypted?
Encrypt data appropriately and in accordance with its classification or sensitivity level. Store according to the appropriate security classification in GSA-approved storage containers.
VERIFIED AGAINST THE SOURCE
“Encrypt data appropriately and in accordance with its classification or sensitivity level”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗120What should you do before downloading data from classified networks onto removable storage media?
Do not download data from classified networks onto removable storage media. Follow your organization's strict policies on transferring data to/from outside agency and non-Government networks.
VERIFIED AGAINST THE SOURCE
“Do not download data from the classified networks onto removable storage media”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗121How should classified removable media be destroyed?
Destroy classified removable media in accordance with its classification level, following your organization's policy for sanitizing, purging, discarding, and destroying removable media.
VERIFIED AGAINST THE SOURCE
“Follow your organization’s policy for sanitizing, purging, discarding, and destroying removable media; Destroy classified removable media in accordance with its classification level”
— DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange) ↗122What is the significance of digital signatures on DoD emails?
Digital signatures verify the sender's identity and the integrity of the message. The DoD requires use of a digital signature when sending attachments or hyperlinks. Digitally signed emails are more secure and help protect against phishing.
VERIFIED AGAINST THE SOURCE
“Use a digital signature when sending attachments or hyperlinks, as required by the DoD”
— DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange) ↗123Evelyn is a system administrator at her agency. As part of her duties, she occasionally uses a thumb drive to perform necessary system tasks, as outlined in her agency's procedures. The thumb drive is provided by the Government for this purpose. Is this an appropriate use of removable media?
Yes. Only use removable media when operationally necessary, Government-owned, and approved in accordance with policy
124How can you identify the separation of Sensitive Compartmented Information (SCI) classified material from collateral classified material?
Markings that identify the compartment with which it is affiliated
125What should you do with your badge within a Sensitive Compartmented Information Facility (SCIF)?
Wear it visibly and above the waist
126Which of the following is a best practice when browsing the Internet?
Look for an icon to indicate encryption is functioning
127You have been issued a new Government-owned mobile device. What is a step you should take to secure it?
Set up a passcode to unlock
128How do Insider Threat Programs defend against insider threats?
Intervening early to help individuals with issues
129How can you protect your home computer?
Turn on spyware protection
130Which of the following is an example of Protected Health Information (PHI)?
An individual's medical record maintained by a healthcare provider
131Ed has authorized access to his agency's Sensitive Compartmented Information Facility (SCIF) and plans to work on a project there today. Which of the following can't he take into the SCIF?
All of these.
132Trisha receives an e-mail with a sensational rumor about a celebrity's personal life. Which of the following actions should Trisha NOT take with the e-mail?
Forward it
133How does an insider threat harm national security?
Exploiting their trusted status and authorized access to government resources
134In what level of system can you use a SIPRNet public key infrastructure (PKI) token?
SIPRNet.
135What risk is posed by Internet of Things (IoT) devices?
Their connectivity can be exploited as an attack vector to any other device on the same network.
136Martha supervises a government unit. To improve morale, she frequently e-mails inspirational stories and photos with inspirational quotes on them to her team. Is this an appropriate use of government e-mail?
No. These email's generate unnecessary e-mail traffic.
137What is a risk to Government systems posed by removable media?
Their data storage and ability to connect to systems can lead to unintended transfers of information, such as introduction of malicious code or spillage.
138Paula is compiling statistics on healthcare provided to Service members over the last fiscal year. Some of her source data includes Protected Health Information (PHI). How can she properly process this data?
Use an encrypted device that requires a passcode or biometrics to unlock
139On a Government-owned mobile device, what should you do before installing an application?
Ensure that it is an approved and authorized application.
140Devon receives an e-mail on her Unclassified Computer. The e-mail has an unmarked attachment that contains what she recognizes as classified information. What should Devon do?
Immediately notify her security POC
141Which of the following is permitted within a collateral classified environment?
A wired headset without a microphone
142Based on the description provided, how many insider threat indicators are present? John frequently comes to work appearing to be hungover. While his access to classified information is consistent with his clearance eligibility and need-to-know, his handling of the information does not protect it from other without eligibility and a need-to-know in accordance with security guidelines. Several coworkers have observed John bringing a call phone into classified areas where devices are prohibited.
3+
143Oscar is on official Government travel with Government-issued laptop. While at the airport, he uses the laptop to work on a report containing controlled unclassified information (CUI). For connectivity, he uses his personal phone as a mobile hotspot. Are there any security concerns here?
Yes. He should be vigilant for "shoulder surfing," where others may be able to view the information on his screen.
144Sara is a government employee with a high degree of expertise in her field. She receives an e-mail from a foreign nation that is complimentary of Sara's expertise and seeks to make a connection with her to learn more about her work. What should Sara do?
Report the contact to her security POC.
145Which of the following is true of information designated as Unclassified?
It does not have the potential to damage national security.
146Oliver users his phone to look up information about a jacket he might want to purchase. Later, he notices ads for the jacket appearing on the websites that he views using his laptop. Why would he see this happen?
Oliver's apps and devices collect and share information about him.
147What is the best practice for user accounts on your home computer?
Each user should have their own account.
148Which of the following is true of transmitting Sensitive Compartmented Information(SCI)?
SCI may be printed using an authorized printer when retrieved promptly.
149You receive a suspicious e-mail that appears to have come from an organization that partners with your agency. Your co-workers have received a similar e-mail. What might this be?
Spear phishing
150Which of the following is an example of a correct way to protect classified data?
Andrea verifies need-to-know and security eligibility before sharing classified information.
151How to prevent spillage?
Label all files with appropriate classification markings
152Knowing indicators of an unstable person can allow you to identify a potential insider threat before an incident.
True
153You receive an e-mail with a link to verify that your account is active. It says you must click the link within 2 days. Your IT department has not sent links like this in the past. The e-mail is not digitally signed. What action should you take?
Report the e-mail to your security POC or help desk
154Which of the following is a potential insider threat indicator?
untreated alcohol use disorder
155Kevin is working with a new foreign contact for a project. While working with the individual, Kevin notices them browsing a website that appears to advocate violence against the United States. What should Kevin do in this instance?
Report potential terrorism behaviors
Know questions we're missing?
Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.
Study these as flashcards
Load all 155 questions into a free study set — flashcards, a practice test, and spaced repetition. No account.
Works on any PDF, doc or web page too — not just military training.
Frequently asked study questions
how can you prevent spillage cyber awareness
Label all files, removable media, and subject headers with appropriate classification markings. The DoD Cyber Awareness Challenge 2026 job aid lists this as a spillage-prevention measure.
This answers the marking-related question in this bank; it is not a complete checklist for every spillage scenario.
Label all files, removable media, and subject headers with appropriate classification markingsDoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
Most-searched questions from this course
Individual answer pages with the keyed answer verified across every CBT version we index.
Veteran? vetaid.ai — free VA benefits help.