← Back to CBT Library

Cyber Awareness Challenge Answers

Cyber Awareness Challenge answers for independent study: search 155 questions or use the linked flashcards. This mixed-version bank is not an official Army or DoD 2026 exam key.

Review Cyber Awareness Challenge questions about deceptive messages, device use and protecting information. Compare phishing, spear phishing, smishing and vishing by the clues in each question, then check the cited DoD Cyber Awareness Challenge 2026 job-aid passages alongside the answers. The bank also includes scenario wording from earlier training sets; a citation identifies the source used, not a guarantee that every exam version uses the same wording.

155 questions and answers122 of 155 verified against the official source

Studying for this with your unit? Send it to them.

🃏 Flashcards
01You receive an email asking you to click a link within two days to verify your account and keep it active. Your IT department has never sent emails like this, and the email does not have a digital signature. What action should you take?
A:

Report the email to your security POC or help desk. This is a phishing attempt using urgency to trick you into clicking a malicious link.

VERIFIED AGAINST THE SOURCE

Assume all unsolicited information requests are phishing attempts and follow your organization’s IT security policies and guidelines.

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
02What is spear phishing?
A:

Spear phishing is a type of phishing attack that targets particular individuals, groups of people, or organizations using personalized information to appear legitimate.

VERIFIED AGAINST THE SOURCE

Spear phishing is a type of phishing attack that targets particular individuals, groups of people, or organizations.

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
03What is whaling?
A:

Whaling is a complex, targeted phishing attack aimed at senior officials. It uses personalized information such as the target's name, title, official email address, and sender names from personal contacts lists to create an individualized, believable message.

VERIFIED AGAINST THE SOURCE

Uses personalized information: name, title, official e-mail address, sender names from personal contacts lists

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
04What is smishing?
A:

Smishing is a type of social engineering that uses Short Message Service (SMS) text messages to deceive you into providing personal information or gaining access to your device. Do not reply or click the link -- delete the message.

VERIFIED AGAINST THE SOURCE

Smishing is a type of social engineering that uses a Short Message Service (SMS) message to deceive you.

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
05What is vishing?
A:

Vishing is a type of social engineering that uses voice calls to deceive you into giving up personal information or installing software that provides access to your devices or network. Let calls from unknown numbers go to voicemail.

VERIFIED AGAINST THE SOURCE

Vishing is a type of social engineering that uses voice calls to deceive you into giving up personal information or installing software that provides access to your devices or network.

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
06Which of the following is a best practice to protect against phishing? (A) Click links in emails to verify if they are real (B) Type the web address directly or use bookmarks instead of clicking links in emails (C) Reply to the sender to ask if it is legitimate (D) Forward the email to coworkers for their opinion
A:

B. Do not access sites by selecting links in emails or pop-up messages. Type the address or use bookmarks. Contact the organization using a phone number you know to be legitimate if suspicious.

VERIFIED AGAINST THE SOURCE

Do not access sites by selecting links in e-mails or pop-up messages. Type the address or use bookmarks.

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
07How can you protect against phishing emails requesting personal information?
A:

Never give out organizational, personal, or financial information to anyone by email. Look for digital signatures. Report emails requesting personal information to your security POC or help desk. Delete the email.

VERIFIED AGAINST THE SOURCE

Never give out organizational, personal, or financial information to anyone by e-mail

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
08You receive a suspicious email that uses your name and appears to come from inside your organization. What type of attack is this likely to be?
A:

This is likely a spear phishing attack. Be wary of suspicious emails that use your name and/or appear to come from inside your organization or a related organization. Report the email to your security POC.

VERIFIED AGAINST THE SOURCE

Be wary of suspicious e-mails that use your name and/or appear to come from inside your organization or a related organization

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
09Trisha receives an email containing a dramatic rumor about a celebrity. Which action should Trisha AVOID taking with this email?
A:

Do not forward it. Email hoaxes clog networks, slow down internet and email services, and can be part of a distributed denial of service (DDoS) attack.

VERIFIED AGAINST THE SOURCE

Internet hoaxes clog networks, slow down internet and e-mail services, and can be part of a distributed denial of service (DDoS) attack.

DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange)
10What should you assume about all unsolicited information requests you receive via email?
A:

Assume all unsolicited information requests are phishing attempts and follow your organization's IT security policies and guidelines.

VERIFIED AGAINST THE SOURCE

Assume all unsolicited information requests are phishing attempts and follow your organization’s IT security policies and guidelines.

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
11What are compressed URLs (such as TinyURLs) and why should you exercise caution with them?
A:

Compressed URLs convert a long URL into a short URL for convenience but may be used to mask malicious intent. Investigate the destination by using the preview feature to see where the link actually leads before clicking.

VERIFIED AGAINST THE SOURCE

Compressed URLs convert a long URL into a short URL for convenience but may be used to mask malicious intent

DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange)
12An unknown caller contacts your office and asks for names from a personnel directory. What should you do?
A:

Do not give out personal or organizational information. Document the interaction -- verify the caller's identity, write down their phone number, and take detailed notes. Contact your security POC or help desk.

VERIFIED AGAINST THE SOURCE

Do not give out personal information

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
13What methods do social engineers use to obtain information?
A:

Social engineers use telephone surveys, email messages, websites, text messages, automated phone calls, and in-person interviews to trick targets into revealing information.

VERIFIED AGAINST THE SOURCE

Social engineers use telephone surveys, e-mail messages, websites, text messages, automated phone calls, and in-person interviews.

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
14To protect against social engineering, what should you do if an unverified person contacts you requesting information?
A:

Do not participate in telephone surveys. Do not give out personal, computer, or network information. Do not follow instructions from unverified personnel. Document the interaction, verify their identity, and contact your security POC or help desk.

VERIFIED AGAINST THE SOURCE

Do not follow instructions from unverified personnel

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
15Sara, a government expert, receives an email from a foreign national who praises her work and asks to connect to learn more about her field. What must Sara do?
A:

Report the contact to her security POC. If you work with classified or sensitive material, you must inform your security POC of all non-professional or non-routine contacts with foreign nationals.

VERIFIED AGAINST THE SOURCE

Inform your security POC of all non-professional or non-routine contacts with foreign nationals, including, but not limited to, joining each other’s social media sites

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
16How do adversaries exploit social media to target DoD personnel?
A:

Adversaries disseminate fake news and propaganda, share fake audio/video (deepfakes), and gather personal information shared on social media to devise social engineering attacks against military and national security targets.

VERIFIED AGAINST THE SOURCE

Gather personal information shared on social media to devise social engineering attacks

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
17What should you do to protect against social engineering during phone calls?
A:

Let calls from unknown numbers go to voicemail -- legitimate callers will leave a message. Never provide personal or organizational information to unverified callers. Document the interaction and report it to your security POC.

VERIFIED AGAINST THE SOURCE

Let calls from unknown numbers go to voicemail. Legitimate callers will leave a message.

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
18You receive a text message from a commercial shipping company claiming they need an updated address to deliver a package, with a link provided. What should you do?
A:

Delete the message. This is a smishing attack. Do not reply or click the link in the message.

VERIFIED AGAINST THE SOURCE

To protect against smishing: Do not reply or click the link in the message

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
19What are the three classification levels for national security information?
A:

Confidential (damage to national security), Secret (serious damage to national security), and Top Secret (exceptionally grave damage to national security).

VERIFIED AGAINST THE SOURCE

"Confidential" shall be applied to information, the unauthorized disclosure of which reasonably could be expected to cause damage to the national security that the original classification authority is able to identify or describe.

Executive Order 13526, Sec. 1.2 (Classification Levels), ISOO / National Archives
20What three conditions must be met for an individual to access classified data?
A:

The individual must have: (1) an appropriate security clearance, (2) a signed and approved non-disclosure agreement, and (3) a need-to-know for the specific information.

VERIFIED AGAINST THE SOURCE

Can only be accessed by individuals with all of the following: Appropriate clearance; Signed and approved non-disclosure agreement; Need-to-know

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
21How should classified data be stored when not in use?
A:

Store classified data appropriately in a GSA-approved vault or security container when not in use. Do not assume open storage in a secure facility is authorized.

VERIFIED AGAINST THE SOURCE

Store classified data appropriately in a GSA-approved vault/container when not in use

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
22What is spillage in the context of classified information?
A:

Spillage occurs when information is 'spilled' from a higher classification or protection level to a lower classification or protection level. Spillage can be either inadvertent or intentional.

VERIFIED AGAINST THE SOURCE

Spillage occurs when information is “spilled” from a higher classification or protection level to a lower classification or protection level. Spillage can be either inadvertent or intentional.

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
23Which of the following may help to prevent spillage? (A) Using classified networks for unclassified work (B) Labeling all files, removable media, and subject headers with appropriate classification markings (C) Removing equipment from classified networks for use on unclassified networks (D) Connecting unauthorized devices to any network
A:

B. Label all files, removable media, and subject headers with appropriate classification markings. Also be aware of classification markings and all handling caveats.

VERIFIED AGAINST THE SOURCE

Label all files, removable media, and subject headers with appropriate classification markings

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
24If spillage occurs, what should you do?
A:

Immediately notify your security POC. Do not delete the suspected files. Do not forward, read further, or manipulate the file. Secure the area.

VERIFIED AGAINST THE SOURCE

If spillage occurs: Immediately notify your security POC; Do not delete the suspected files; Do not forward, read further, or manipulate the file; Secure the area

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
25A user writes down details marked as Secret from a classified system and uses those details to draft a briefing on an unclassified system without authorization. What has occurred?
A:

Spillage, because classified data was moved to a lower classification level system without authorization.

VERIFIED AGAINST THE SOURCE

Spillage occurs when information is “spilled” from a higher classification or protection level to a lower classification or protection level.

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
26If you find classified government data on the internet that has not been cleared for public release, what should you do?
A:

Do not download the information (it may create a new spillage). Note any identifying information and the website's URL. Report the situation to your security POC. Refer any inquiries to your public affairs office. Remember it is still classified even if compromised.

VERIFIED AGAINST THE SOURCE

Do not download leaked classified or controlled information because you are not allowed to have classified information on your computer and downloading it may create a new case of spillage

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
27Why should you NOT use a classified network for unclassified work?
A:

It can unnecessarily consume mission-essential bandwidth, may illegally shield information from FOIA disclosure, and creates a danger of spillage when attempting to remove the information to unclassified media or hard copy.

VERIFIED AGAINST THE SOURCE

Can unnecessarily consume mission-essential bandwidth

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
28What is Controlled Unclassified Information (CUI)?
A:

CUI is Government information that must be handled using safeguarding or dissemination controls. It includes Controlled Technical Information (CTI), PII, PHI, financial information, personal/payroll information, and operational information. CUI is NOT classified information.

VERIFIED AGAINST THE SOURCE

Controlled Unclassified Information (CUI) is Government information that must be handled using safeguarding or dissemination controls.

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
29What type of sensitive information does a roster containing employee names and passport numbers represent?
A:

Controlled Unclassified Information (CUI), because it contains Personally Identifiable Information (PII) -- specifically names combined with passport numbers.

VERIFIED AGAINST THE SOURCE

It includes, but is not limited to, Controlled Technical Information (CTI), Personally Identifiable Information (PII), Protected Health Information (PHI), financial information, personal or payroll information, and operational information.

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
30What is Personally Identifiable Information (PII)?
A:

PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other linked information. It includes Social Security Number, date and place of birth, mother's maiden name, biometric records, Protected Health Information, and passport number.

Why this answer

A detail does not have to identify someone by itself to qualify as PII. For example, an otherwise ambiguous record can become identifying when linked to another record about the same person. The test is whether identity can be distinguished or traced using the available combination, not whether each field looks identifying in isolation.

VERIFIED AGAINST THE SOURCE

Personally Identifiable Information (PII) is information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other information that is linked or linkable to a specific individual.

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
31What is the most commonly reported cause of PII breaches?
A:

The most commonly reported cause of PII breaches is failure to encrypt email messages containing PII.

VERIFIED AGAINST THE SOURCE

The most commonly reported cause of PII breaches is failure to encrypt e-mail messages containing PII.

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
32What is Protected Health Information (PHI)?
A:

PHI is a subset of PII requiring additional protection. It is health information that identifies the individual, created or received by a healthcare provider, health plan, employer, or business associate, relating to physical/mental health, healthcare provision, or payment for healthcare.

VERIFIED AGAINST THE SOURCE

Is a subset of PII requiring additional protection

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
33Paula is organizing data about healthcare provided to service members that includes PHI. What is the most secure way to handle this data?
A:

Use Government-furnished or Government-approved equipment with extra protection and encryption, especially on mobile devices.

VERIFIED AGAINST THE SOURCE

Only use Government-furnished or Government-approved equipment to process CUI, including PII.

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
34Can PII be transmitted via personal email accounts?
A:

No. Never use personal email accounts for transmitting PII. PII may only be emailed between Government email accounts and must be encrypted and digitally signed when possible.

VERIFIED AGAINST THE SOURCE

Never use personal e-mail accounts for transmitting PII. PII may only be e-mailed between Government e-mail accounts and must be encrypted and digitally signed when possible.

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
35Does the following social media post raise security concerns? (Post includes mother's maiden name, home address, and birthday.)
A:

Yes. It contains several items of PII including mother's maiden name, home address, and birthday. Avoid posting PII on social media.

VERIFIED AGAINST THE SOURCE

Avoid posting personally identifiable information (PII): Social Security Number; Date and place of birth; Mother’s maiden name; Home address

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
36How should CUI be stored after working hours if no security is present or it is deemed inadequate?
A:

In locked containers, desks, or cabinets. If security is present, locked or unlocked containers are acceptable.

VERIFIED AGAINST THE SOURCE

Locked containers, desks, cabinets if no security is present or is deemed inadequate

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
37What DoD instruction governs CUI handling?
A:

DoD Instruction 5200.48, 'Controlled Unclassified Information (CUI),' along with Defense Federal Acquisition Regulation Supplement (DFARS) for CUI and Controlled Technical Information (CTI) handling requirements.

VERIFIED AGAINST THE SOURCE

Follow policy in DoD Instruction 5200.48, “Controlled Unclassified Information (CUI)” for retention or disposal

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
38When faxing CUI, what precautions must be taken?
A:

Ensure the recipient is at the receiving end, use the correct cover sheet, and contact the recipient to confirm receipt.

VERIFIED AGAINST THE SOURCE

If faxing CUI: Ensure recipient is at the receiving end; Use correct cover sheet; Contact the recipient to confirm receipt

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
39What are best practices for physical security at a government facility?
A:

Use your own security badge/key code, don't allow others to piggyback into secure areas, challenge people without proper badges, report suspicious activity, and protect access rosters from public view.

VERIFIED AGAINST THE SOURCE

Use your own security badge/key code. Note that your Common Access Card (CAC)/Personal Identity Verification (PIV) card is sometimes used as a facility access badge.

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
40What should you do after leaving your controlled area or office building regarding your security badge?
A:

Remove your security badge after leaving your controlled area or office building to avoid being targeted by adversaries.

VERIFIED AGAINST THE SOURCE

Remove your security badge after leaving your controlled area or office building

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
41What is piggybacking (tailgating) and how should you respond to it?
A:

Piggybacking is when someone follows an authorized person through a secure entrance without badging in themselves. Do not allow others access or to piggyback into secure areas. Everyone must badge in individually.

VERIFIED AGAINST THE SOURCE

Don’t allow others access or to piggyback into secure areas

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
42An unfamiliar person without a visible badge is in your secure work area. What should you do?
A:

Challenge people without proper badges. Report suspicious activity to your security POC. Ensure uncleared persons are escorted by a cleared person familiar with facility security procedures.

43You are working at your desk and hear an unusual sound near the office door. Before leaving your workstation to investigate, what critical security step must you perform?
A:

Remove your Common Access Card (CAC) from your workstation to lock it before walking away.

VERIFIED AGAINST THE SOURCE

Remove and take your CAC/PIV card whenever you leave your workstation

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
44Within a SCIF, where must badges be displayed?
A:

Badges must be visible and displayed above the waist at all times while in the facility. Badges must be removed when leaving the facility.

VERIFIED AGAINST THE SOURCE

Badges must be visible and displayed above the waist at all times while in the facility

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
45What are the risks associated with removable media on government systems?
A:

Introduction of malicious code, compromise of systems' confidentiality, availability, and/or integrity, and spillage of classified information. Potential consequences include shutdown of systems, compromise of information, loss of mission, and loss of life.

VERIFIED AGAINST THE SOURCE

The risks associated with removable media include: Introduction of malicious code; Compromise of systems’ confidentiality, availability, and/or integrity; Spillage of classified information

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
46What is the primary security risk that removable storage devices pose to government computer systems?
A:

Their data storage and ability to connect to systems can lead to unintended transfers of information, such as introduction of malicious code or spillage of classified data.

VERIFIED AGAINST THE SOURCE

Potential consequences: Shutdown of systems; Compromise of information, systems, programs, and/or assets; Loss of mission; Loss of life

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
47Can personally owned USB drives or removable media be used on government systems?
A:

No. Do not use any personally owned or non-organizational removable media on your organization's systems. Only use removable media approved by your organization.

VERIFIED AGAINST THE SOURCE

Do not use any personally owned/non-organizational removable media on your organization’s systems

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
48What must users ensure when using removable media such as a CD in a SCIF?
A:

Media shall display a label inclusive of maximum classification, date of creation, point of contact (POC), and Configuration Management (CM) Control Number.

VERIFIED AGAINST THE SOURCE

Media shall display a label inclusive of maximum classification, date of creation, POC, and CM Control Number

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
49What is the best practice for labeling removable media?
A:

Label all removable media regardless of classification or environment, and avoid inserting removable media with unknown content into your computer.

VERIFIED AGAINST THE SOURCE

As a best practice, label all removable media regardless of classification or environment and avoid inserting removable media with unknown content into your computer

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
50You find an unattended USB drive in your office. What should you do?
A:

Do not plug it into any computer. Turn it in to your security office. Unattended removable media may contain malware or could be part of a baiting social engineering attack.

VERIFIED AGAINST THE SOURCE

Never plug unauthorized devices into a government system

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
51Ed is authorized to work in a SCIF today. Which personal electronic items is he forbidden from bringing inside?
A:

All personal portable electronic devices (PEDs) are forbidden in a SCIF -- including cell phones, smart watches, fitness trackers, tablets, and any device with Wi-Fi, Bluetooth, cellular, image capturing, video, or audio recording capabilities.

VERIFIED AGAINST THE SOURCE

No personal PEDs are allowed in a Sensitive Compartmented Information Facility (SCIF).

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
52Which peripherals are you allowed to connect to Government Furnished Equipment (GFE)?
A:

Personally-owned peripherals are permitted with GFE: monitors via VGA, DVI, HDMI, or DisplayPort (with nothing else connected to the monitor); wired keyboards, mice, and trackballs via USB; USB hubs; and headphones/headsets, with or without microphones, through a USB port. Not permitted: monitors connected via USB, peripherals from a prohibited source, Bluetooth or other wireless external peripherals, and installing drivers to support personally-owned peripherals. (The stricter government-issued-only rule applies inside DoD classified spaces, not to GFE generally.)

VERIFIED AGAINST THE SOURCE

Wired keyboards, mice, and trackballs through a Universal Serial Bus (USB) connection

DoD Cyber Awareness Challenge 2026, Telework and Home Computer Security job aid (DISA / DoD Cyber Exchange)
53What two types of credentials does two-factor authentication combine?
A:

Two-factor authentication combines two of these three types: something you possess (such as a CAC), something you know (such as a PIN), and something you are (such as a fingerprint or biometrics).

Why this answer

Count credential types, not the number of things entered. A password and a PIN are both things you know, so that pair does not span two of the listed types. A CAC and its PIN do: the card is something you possess and the PIN is something you know.

VERIFIED AGAINST THE SOURCE

Something you possess, such as a Common Access Card (CAC); Something you know, such as your Personal Identification Number (PIN); Something you are, such as a fingerprint or other biometrics

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
54Which of the following examples uses two different types of authentication factors? (A) Password and PIN (B) Two different passwords (C) Password and fingerprint (D) PIN and security question
A:

C. Password and fingerprint -- these combine something you know (password) with something you are (biometrics). The others all use the same factor type (something you know).

VERIFIED AGAINST THE SOURCE

Something you know, such as your Personal Identification Number (PIN); Something you are, such as a fingerprint or other biometrics

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
55What certificates does the Common Access Card (CAC)/PIV card contain?
A:

The CAC/PIV implements DoD Public Key Infrastructure (PKI) and contains certificates for identification, encryption, and digital signature.

VERIFIED AGAINST THE SOURCE

It implements DoD Public Key Infrastructure (PKI) and contains certificates for: Identification; Encryption; Digital signature

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
56How should you protect your CAC/PIV card?
A:

Maintain possession at all times. Remove it whenever leaving your workstation. Never surrender it for building access. Store in a shielded sleeve to prevent cloning. Do not write down or share your PIN. Report it immediately if lost.

VERIFIED AGAINST THE SOURCE

Store it in a shielded sleeve to mitigate card and chip cloning

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
57When creating strong passwords, which practices should you follow?
A:

Combine letters, numbers, and special characters. Do not use personal information, common phrases, or dictionary words in any language. Do not write it down -- memorize it. Change passwords at least every 3 months. Avoid using the same password across systems.

VERIFIED AGAINST THE SOURCE

Combine letters, numbers, and special characters; Do not use personal information; Do not use common phrases or dictionary words in any language

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
58At what level of network system are you authorized to use a SIPRNet PKI token?
A:

SIPRNet only. Never use a token approved for NIPRNet on a higher classification system, and never use a SIPRNet token on the NIPRNet. Only use a token within its designated classification level.

VERIFIED AGAINST THE SOURCE

Only use a token within its designated classification level

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
59When should you leave a DoD PKI token in a system?
A:

Only leave it in a system while actively using it for a PKI-required task. Never use on publicly accessible computers such as kiosks, internet cafes, or public libraries.

VERIFIED AGAINST THE SOURCE

Only leave in a system while actively using it for a PKI-required task

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
60What should you be aware of when using public Wi-Fi with a mobile device?
A:

Information sent over public Wi-Fi connections may be exposed to theft, and the device may be exposed to malware. Fake Wi-Fi access points may be used for deception. Use public or free Wi-Fi only with the Government VPN.

VERIFIED AGAINST THE SOURCE

Be aware that information sent over public Wi-Fi connections may be exposed to theft, and the device may be exposed to malware

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
61What precaution should you take when connecting a laptop to a hotel internet connection?
A:

Use caution -- if you are directed to a login page before you can connect by VPN, the risk of malware loading or data compromise is substantially increased.

VERIFIED AGAINST THE SOURCE

Use caution when connecting laptops to hotel Internet connections. If you are directed to a login page before you can connect by VPN, the risk of malware loading or data compromise is substantially increased.

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
62What should you assume about electronic transmissions when traveling overseas with mobile devices?
A:

Assume that any electronic transmission (voice or data) may be monitored. Mobile phones carried overseas are often compromised upon exiting the plane. Devices not in your custody or in secure U.S. Government facility storage should be assumed compromised.

VERIFIED AGAINST THE SOURCE

Assume that any electronic transmission you make (voice or data) may be monitored

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
63What is a best practice for protecting your home wireless network for telework?
A:

Implement, at a minimum, Wi-Fi Protected Access 2 (WPA2) Personal encryption on your home wireless network.

VERIFIED AGAINST THE SOURCE

Implement Wi-Fi Protected Access 2 (WPA2) Personal

DoD Cyber Awareness Challenge 2026, Telework and Home Computer Security job aid (DISA / DoD Cyber Exchange)
64Are DoD employees allowed to use their CAC in card-reader-enabled public devices?
A:

No. DoD employees are prohibited from using a DoD CAC in card-reader-enabled public devices such as those found in public libraries and internet cafes.

VERIFIED AGAINST THE SOURCE

DoD employees are prohibited from using a DoD CAC in card-reader-enabled public devices such as those found in public libraries and Internet cafes

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
65What should you do before using a mobile device in public?
A:

Be careful of information visible on the screen (consider screen protection), maintain possession of the device at all times, use password or two-factor authentication, ensure all sensitive data is encrypted, and never discuss sensitive information in public.

VERIFIED AGAINST THE SOURCE

Be careful of information visible on your mobile computing device; consider screen protection

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
66What is malicious code and what forms can it take?
A:

Malicious code can corrupt files, encrypt or erase your hard drive, and allow hackers access. It includes viruses, Trojan horses, worms, macros, and scripts. It can spread via email attachments, downloading files, and visiting infected websites.

VERIFIED AGAINST THE SOURCE

Malicious code can do damage by corrupting files, encrypting or erasing your hard drive, and/or allowing hackers access. Malicious code includes viruses, Trojan horses, worms, macros, and scripts.

DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange)
67Which of the following email habits helps protect against downloading viruses? (A) Open all attachments quickly (B) View email in Preview Pane (C) Look for a digital signature on emails (D) Forward suspicious emails to friends
A:

C. Look for digital signatures if your organization uses them. Digitally signed emails are more secure. Also view email in plain text, scan all attachments, and don't access links or graphics in emails.

VERIFIED AGAINST THE SOURCE

Use caution when opening e-mail: Look for digital signatures if your organization uses them. Digitally signed e-mails are more secure.

DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange)
68What are indicators that your computer may be infected with malicious code?
A:

Sudden flashing pop-ups warning of virus infection, sudden appearance of new apps or programs, strange pop-ups during startup/operation/shutdown, device slowing down, new browser extensions or tabs, and loss of control of mouse or keyboard.

VERIFIED AGAINST THE SOURCE

Sudden flashing pop-ups that warn that your computer is infected with a virus

DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange)
69How can you prevent the download of malicious code?
A:

Scan all external files before uploading. For personal devices, research apps before downloading. For Government devices, use only approved and authorized applications. Only allow mobile code from your organization's trusted sites to run.

VERIFIED AGAINST THE SOURCE

Scan all external files before uploading to your computer

DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange)
70How should you handle email to prevent virus downloads?
A:

View email in plain text (not Preview Pane), look for digital signatures, scan all attachments, delete emails from unknown senders if authenticity cannot be confirmed, and do not click links, buttons, or graphics in emails or email-generated pop-ups.

VERIFIED AGAINST THE SOURCE

View e-mail in plain text and don’t view e-mail in Preview Pane

DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange)
71What is Near Field Communication (NFC) and what are its security risks?
A:

NFC is wireless technology enabling devices to communicate when placed next to each other (e.g., contactless payments). Risks include eavesdropping (adversary intercepts signal), data manipulation/corruption, and viruses targeting stored financial or mission information.

VERIFIED AGAINST THE SOURCE

NFC is wireless technology that enables your electronic devices to establish communications and exchange information when placed next to each other.

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
72When you are issued a new Government mobile phone, what is the essential first step to secure it?
A:

Set up a passcode to unlock it. Additionally, enable automatic screen locking, encrypt all sensitive data, and use two-factor authentication if possible.

VERIFIED AGAINST THE SOURCE

At a minimum, password protect Government-issued mobile computing devices; use two-factor authentication if possible

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
73What should you do if your government mobile device is lost or stolen?
A:

Immediately report the loss to your security POC.

VERIFIED AGAINST THE SOURCE

If lost or stolen, immediately report the loss to your security POC

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
74How can mobile device tracking be a security concern?
A:

Many mobile devices and apps can track your location without your knowledge or consent. They can geolocate you, display your location, record location history, and activate tracking by default.

VERIFIED AGAINST THE SOURCE

Many mobile devices and applications can track your location without your knowledge or consent.

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
75If you want to install an application on a Government-owned mobile device, what step must you take first?
A:

Ensure that it is an approved and authorized application. Only use applications authorized by your organization on Government devices.

VERIFIED AGAINST THE SOURCE

For Government-owned devices, use approved and authorized applications only

DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange)
76Why is powering off a mobile device or putting it in airplane mode NOT sufficient in a classified environment?
A:

Mobile devices may be hacked or infected with malware and can be used to track, record, photograph, or videotape the environment. Powering off or airplane mode is not sufficient to mitigate these risks and the threat to classified information.

VERIFIED AGAINST THE SOURCE

Mobile devices and peripherals may be hacked or infected with malware and can be used to track, record, photograph, or videotape the environment around them. Powering off or putting devices in airplane mode is not sufficient to mitigate these risks and the threat these devices pose to classified information.

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
77What is an insider threat?
A:

An insider threat uses authorized access, wittingly or unwittingly, to harm national security through unauthorized disclosure, data modification, espionage, terrorism, or kinetic actions resulting in loss or degradation of resources or capabilities.

VERIFIED AGAINST THE SOURCE

An insider threat uses authorized access, wittingly or unwittingly, to harm national security through unauthorized disclosure, data modification, espionage, terrorism, or kinetic actions resulting in loss or degradation of resources or capabilities.

DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange)
78Which of the following is a potential insider threat indicator? (A) Taking approved vacation time (B) Untreated alcohol use disorder (C) Volunteering for extra projects (D) Arriving early to work
A:

B. Untreated alcohol use disorder is a recognized insider threat indicator. Other indicators include financial difficulties, unexplained affluence, unreported foreign contact, hostile behavior, and inappropriate interest in classified information.

VERIFIED AGAINST THE SOURCE

We detect insider threats by using our powers of observation to recognize potential insider threat indicators. These include, but are not limited to: Difficult life circumstances; Divorce or death of spouse; Alcohol or other substance misuse or dependence; Untreated mental health issues; Financial difficulties

DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange)
79What is the specific way that an insider threat causes damage?
A:

By exploiting their trusted status and authorized access to government information systems and resources.

VERIFIED AGAINST THE SOURCE

Insiders are able to do extraordinary damage to their organizations by exploiting their trusted status and authorized access to government information systems.

DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange)
80What is the primary method that Insider Threat Programs use to defend the organization?
A:

Intervening early to help individuals with issues -- such as referring them to counseling or assistance to alleviate personal stressors, requiring security training, and developing protocols to secure information, resources, and personnel.

VERIFIED AGAINST THE SOURCE

We defend against the damage insider threats can cause by deterring insiders from becoming threats.

DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange)
81John frequently appears hungover at work, handles classified information carelessly, and brings a cell phone into restricted classified areas. How many insider threat indicators is John exhibiting?
A:

Three or more: alcohol misuse, mishandling of classified information, and bringing electronic devices into prohibited areas.

VERIFIED AGAINST THE SOURCE

Bringing an electronic device into prohibited areas

DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange)
82What behaviors should you report as potential insider threat indicators?
A:

Attempting to access information without need-to-know, unauthorized removal of sensitive information, unusual requests for sensitive data, electronic devices in prohibited areas, sudden high-value purchases, unexplained overseas trips, substance problems, personality changes, and hostile statements.

VERIFIED AGAINST THE SOURCE

Attempt to access sensitive information without the need-to-know; Unauthorized removal of sensitive information; Unusual request for sensitive information; Bringing an electronic device into prohibited areas; Sudden purchases of high value items/living beyond one’s means

DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange)
83In a study of known U.S. spies, what percentage demonstrated behaviors of security concern?
A:

80% demonstrated behaviors of security concern, 25% experienced a life crisis, and 70% volunteered their services (were not recruited).

VERIFIED AGAINST THE SOURCE

In one report on known U.S. spies, these individuals: Demonstrated behaviors of security concerns: 80% of the time; Experienced a life crisis: 25% of the time; Volunteered: 70% of the time

DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange)
84If SCI is exposed or compromised, what action must you take immediately?
A:

Call your security point of contact (POC). Do not elaborate on sensitive/classified details until secure two-way communications (verbal or transmitted) can be achieved.

VERIFIED AGAINST THE SOURCE

You are required to contact your security Point of Contact (POC) to report the incident.

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
85What is Sensitive Compartmented Information (SCI)?
A:

SCI is a program that segregates classified information into distinct compartments for added protection and dissemination control. It overlays Top Secret, Secret, and Confidential information. Access requires Top Secret clearance and indoctrination into the specific SCI program.

VERIFIED AGAINST THE SOURCE

Sensitive Compartmented Information (SCI) is a program that segregates various types of classified information into distinct compartments for added protection and dissemination or distribution control.

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
86Which statement is correct regarding SCI handling? (A) SCI can be discussed on unencrypted phones (B) SCI may be printed using an authorized printer when retrieved promptly (C) SCI can be taken home for review (D) SCI can be stored in any locked cabinet
A:

B. SCI may be printed using an authorized printer when retrieved promptly. Use appropriate classification cover sheets and ensure classified material is not mixed with unclassified material being removed from the SCIF.

VERIFIED AGAINST THE SOURCE

Retrieve classified documents promptly from printers

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
87Who has overarching authority concerning SCI policy?
A:

The Director of National Intelligence has overarching authority concerning SCI policy.

VERIFIED AGAINST THE SOURCE

The Director of National Intelligence has overarching authority concerning SCI policy.

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
88What is a Security Classification Guide (SCG)?
A:

An SCG provides precise, comprehensive guidance on classifying specific program, system, operation, or weapon system information -- including classification levels, reasons, and duration. It is approved by the Original Classification Authority (OCA) and is an authoritative source for derivative classification.

VERIFIED AGAINST THE SOURCE

Provides precise, comprehensive guidance regarding specific program, system, operation, or weapon system elements of information to be classified

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
89Devon receives an email on her unclassified computer with an unmarked attachment she recognizes as containing classified information. What is the first thing she must do?
A:

Immediately notify her security point of contact (POC). Do not delete, forward, read further, or manipulate the file.

VERIFIED AGAINST THE SOURCE

If spillage occurs: Immediately notify your security POC; Do not delete the suspected files; Do not forward, read further, or manipulate the file

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
90What should you do to report a cybersecurity incident?
A:

Immediately notify your security POC or help desk. Do not delete suspected files. Do not forward or manipulate evidence. Secure the area. Document what happened and when.

VERIFIED AGAINST THE SOURCE

Immediately notify your security POC

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
91If an incident occurs in a SCIF, what steps must be taken?
A:

Notify your security POC, analyze the media for viruses or malicious code, analyze other workstations in the SCIF, and if unintentional, the person may attend a refresher training course in security awareness.

VERIFIED AGAINST THE SOURCE

Notify your security POC about the incident; An analysis of the media must be conducted for viruses or malicious code; The other workstations in the SCIF must also be analyzed

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
92If you find classified data on the internet, what identifying information should you note?
A:

Note any identifying information and the website's URL, then report it to your security POC. Do not download the information. Remember that leaked classified information is still classified even if it has been compromised.

VERIFIED AGAINST THE SOURCE

Note any identifying information and the website’s URL

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
93Who should you report cultivation contacts by foreign nationals to?
A:

Report cultivation contacts by foreign nationals to your security POC. Inform your security POC of all non-professional or non-routine contacts with foreign nationals.

VERIFIED AGAINST THE SOURCE

Report cultivation contacts by foreign nationals

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
94What are Cyberspace Protection Conditions (CPCON)?
A:

CPCON levels established by USCYBERCOM set protection priorities during significant cyberspace events. CPCON 1 = Very High risk (Critical Functions only), CPCON 2 = High, CPCON 3 = Medium, CPCON 4 = Low, CPCON 5 = Very Low (All Functions).

VERIFIED AGAINST THE SOURCE

The United States Cyber Command (USCYBERCOM) Instruction 5200-13 establishes Cyberspace Protection Conditions (CPCON) for the DoD. CPCON establishes protection priorities for each level during significant cyberspace events

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid, citing USCYBERCOM Instruction 5200-13 (DISA / DoD Cyber Exchange)
95What is the Unclassified designation?
A:

Unclassified marks information that does not have potential to damage national security. It must be cleared before public release, may require CUI controls, and if aggregated, may be elevated to a higher sensitivity level or even become classified.

VERIFIED AGAINST THE SOURCE

Unclassified is a designation to mark information that does not have potential to damage national security (i.e., not been determined to be Confidential, Secret, or Top Secret).

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
96Can CUI be marked on any information?
A:

No. CUI may only be marked as CUI if it belongs to a category established in the DoD CUI Registry.

VERIFIED AGAINST THE SOURCE

CUI is NOT classified information and may only be marked as CUI if it belongs to a category established in the DoD CUI Registry.

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
97What encryption is required when emailing PII or other CUI?
A:

Use encryption when emailing PII or other types of CUI, as required by the DoD. The DoD requires use of two-factor authentication for access to systems processing CUI.

VERIFIED AGAINST THE SOURCE

Use encryption when e-mailing Personally Identifiable Information (PII) or other types of CUI, as required by the DoD

DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)
98Oliver searched for a jacket on his phone and later saw ads for that same jacket on his laptop. Why?
A:

Oliver's apps and devices collect and share information about him. Online data aggregators collect and catalogue your information from apps, smart devices, and public records, which can be used to target you with tailored advertisements and scams.

VERIFIED AGAINST THE SOURCE

online data aggregators collect and catalogue information about you. This information can be used to further target you, such as with scams posing as advertisements that are tailored to your preferences.

DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange)
99How should you protect your identity online?
A:

Ask how information will be used before giving it out, pay attention to financial statements, avoid common names/dates for passwords, never share passwords, shred personal documents, refrain from carrying SSN card, and order your credit report annually.

VERIFIED AGAINST THE SOURCE

Ask how information will be used before giving it out; Pay attention to credit card and bank statements; Avoid common names/dates for passwords and PINs; Never share passwords and PINs

DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange)
100What is a cookie and why can it pose a security threat?
A:

A cookie is a text file stored on your hard drive by a web server. Cookies may pose a security threat when they save unencrypted personal information and may track your web activities. Only accept cookies from reputable, trusted websites using encrypted (HTTPS) links.

VERIFIED AGAINST THE SOURCE

A cookie is a text file that a web server stores on your hard drive. Cookies may pose a security threat, particularly when they save unencrypted personal information.

DoD Cyber Awareness Challenge 2026, Web Use and Your Safety job aid (DISA / DoD Cyber Exchange)
101What should you avoid posting on social networking sites?
A:

Avoid posting PII (SSN, date/place of birth, mother's maiden name, home address), GPS/location information, and any content that could reveal operational details. Do not connect with people you don't know, even if you share mutual connections.

VERIFIED AGAINST THE SOURCE

Don’t connect with people you don’t know, even if you share mutual connections

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
102Is the social networking app TikTok allowed on government devices?
A:

No. TikTok is banned on all Government devices.

VERIFIED AGAINST THE SOURCE

The social networking app TikTok is banned on all Government devices.

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
103What should you do when posting pictures in uniform or at work on social media?
A:

Make sure there are no identifiable landmarks or items visible. When establishing personal social networking accounts, use only personal contact information, never your Government contact information.

VERIFIED AGAINST THE SOURCE

If posting pictures of yourself in uniform or in a work-setting, make sure there are no identifiable landmarks or items visible

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
104What is the Bring Your Own Approved Device (BYOAD) program?
A:

BYOAD allows use of personal devices per organization policy. You must read and sign a User Agreement, and the approved device will be provisioned to employ necessary security measures. Use depends on your organization's specific policies.

VERIFIED AGAINST THE SOURCE

Read and sign the User Agreement that includes the program’s requirements and policies; Use of your personal device depends on your organization’s policies; The approved device will be provisioned to employ necessary security measures to secure it and its data when accessed

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid — "AMD Programs" (DISA / DoD Cyber Exchange)
105What are prohibited uses of Government Furnished Equipment (GFE)?
A:

Do not: view/download pornography, gamble online, conduct private business, load unauthorized software (including DropBox or P2P), illegally download copyrighted material, make unauthorized configuration changes. Use GFE for official purposes only.

VERIFIED AGAINST THE SOURCE

Use GFE for official purposes only; Don’t allow unauthorized users to use your GFE; Don’t view or download pornography; Don’t gamble on the Internet; Don’t conduct private business/money-making ventures

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
106Why is peer-to-peer (P2P) software prohibited on government systems?
A:

P2P software can compromise network configurations, spread viruses and spyware, and allow unauthorized access to data.

VERIFIED AGAINST THE SOURCE

P2P software can compromise network configurations, spread viruses and spyware, and allow unauthorized access to data

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
107Are all DoD-owned devices subject to monitoring?
A:

Yes. All DoD-owned devices are subject to monitoring. When you use these devices, you authorize the monitoring of your activity on them.

VERIFIED AGAINST THE SOURCE

All DoD-owned devices are subject to monitoring. When you use these devices, you authorize the monitoring of your activity on these devices.

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
108What are best practices for using government email?
A:

Do not use email to sell anything. Do not send chain letters, offensive letters, mass emails, jokes, or unnecessary pictures. Use digital signatures when sending attachments/hyperlinks. Do not use personal accounts for official DoD communication.

VERIFIED AGAINST THE SOURCE

Do not use personal accounts, such as webmail, to conduct official DoD communication

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
109What precaution should be taken regarding monitors displaying classified information?
A:

Ensure monitors do not provide unobstructed views of classified information. Monitors facing windows should be turned or window blinds should be closed.

VERIFIED AGAINST THE SOURCE

Ensure monitors do not provide unobstructed views of classified information

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
110What wireless technologies are prohibited in DoD classified spaces?
A:

All wireless headsets, microphones, and webcams are prohibited. As a general rule, there should be no Wi-Fi, Bluetooth, cellular, image capturing, video recording, or audio recording capabilities or wearable devices in a SCIF.

VERIFIED AGAINST THE SOURCE

All wireless headsets, microphones, and webcams are prohibited in DoD classified spaces, as well as all personally-owned external peripherals other than wired headsets.

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
111What types of personally-owned peripherals can be used in a collateral classified environment?
A:

Only personally-owned wired headsets without a microphone are permitted. All other personally-owned external peripherals are prohibited in DoD classified spaces.

VERIFIED AGAINST THE SOURCE

Personally-owned wired headsets without a microphone

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
112How should you handle unclassified laptops in a collateral classified environment?
A:

Ensure any embedded cameras, microphones, and Wi-Fi are physically disabled. Use only authorized external peripherals.

VERIFIED AGAINST THE SOURCE

Ensure that any embedded cameras, microphones, and Wi-Fi are physically disabled

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
113When can classified information be discussed on a smartphone?
A:

Never. Do not discuss classified information over smartphones, and do not view classified information via a device when not in a cleared space.

VERIFIED AGAINST THE SOURCE

Don’t discuss classified information over smartphones

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
114What steps should you take to avoid being misled by online disinformation?
A:

Research the source's credibility, read beyond the headline, check against known facts and other sources, consider if it's intended as a joke, and check your personal biases -- actively seek opposing or disconfirming content.

VERIFIED AGAINST THE SOURCE

Research the source to evaluate its credibility and reliability; Read beyond the headline; Check against known facts and other sources on the topic; Consider whether the story is intended as a joke; Check your personal biases

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
115What is online misconduct according to DoD policy?
A:

Online misconduct is inconsistent with DoD values. Do NOT use electronic communications for harassment, bullying, hazing, stalking, discrimination, or retaliation. Individuals who participate may face criminal, disciplinary, or administrative action. No one is truly anonymous online.

VERIFIED AGAINST THE SOURCE

Online misconduct is inconsistent with DoD values. Individuals who participate in or condone misconduct, whether offline or online, may be subject to criminal, disciplinary, and/or administrative action.

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
116If you post content to a social networking site and regret it, what can you do?
A:

You can delete the post, but be aware that once content is posted, it may have already been shared, cached, or archived. Sites may own content you post, and it may not be fully removable.

VERIFIED AGAINST THE SOURCE

Sites own any content you post. Once you post content, it can’t be taken back.

DoD Cyber Awareness Challenge 2026, Online Behavior job aid (DISA / DoD Cyber Exchange)
117What IoT devices pose security risks while teleworking?
A:

All internet-connected devices in a telework environment pose risks, including smart speakers, fitness trackers, smart TVs, home security cameras, and personal digital assistants. These devices collect data and may be exploited.

VERIFIED AGAINST THE SOURCE

When using your home network to telework, an unsecured IoT device could become an attack vector to any attached government-furnished equipment (GFE).

DoD Cyber Awareness Challenge 2026, Telework and Home Computer Security job aid (DISA / DoD Cyber Exchange)
118What is a best practice for securing a home computer used by multiple family members?
A:

Create separate user accounts for each user and have each user create their own password.

Why this answer

The quoted practice has three parts: enable passwords, separate the accounts, and let each user create a strong password of their own. A single password-protected family account satisfies only the first part; it does not satisfy the separate-account recommendation.

VERIFIED AGAINST THE SOURCE

Turn on password feature, create separate accounts for each user, and have them create their own passwords using a strong password creation method

DoD Cyber Awareness Challenge 2026, Telework and Home Computer Security job aid (DISA / DoD Cyber Exchange)
119How should data on removable media be encrypted?
A:

Encrypt data appropriately and in accordance with its classification or sensitivity level. Store according to the appropriate security classification in GSA-approved storage containers.

VERIFIED AGAINST THE SOURCE

Encrypt data appropriately and in accordance with its classification or sensitivity level

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
120What should you do before downloading data from classified networks onto removable storage media?
A:

Do not download data from classified networks onto removable storage media. Follow your organization's strict policies on transferring data to/from outside agency and non-Government networks.

VERIFIED AGAINST THE SOURCE

Do not download data from the classified networks onto removable storage media

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
121How should classified removable media be destroyed?
A:

Destroy classified removable media in accordance with its classification level, following your organization's policy for sanitizing, purging, discarding, and destroying removable media.

VERIFIED AGAINST THE SOURCE

Follow your organization’s policy for sanitizing, purging, discarding, and destroying removable media; Destroy classified removable media in accordance with its classification level

DoD Cyber Awareness Challenge 2026, Removable Media and Mobile Devices job aid (DISA / DoD Cyber Exchange)
122What is the significance of digital signatures on DoD emails?
A:

Digital signatures verify the sender's identity and the integrity of the message. The DoD requires use of a digital signature when sending attachments or hyperlinks. Digitally signed emails are more secure and help protect against phishing.

VERIFIED AGAINST THE SOURCE

Use a digital signature when sending attachments or hyperlinks, as required by the DoD

DoD Cyber Awareness Challenge 2026, Government Facilities and Resources job aid (DISA / DoD Cyber Exchange)
123Evelyn is a system administrator at her agency. As part of her duties, she occasionally uses a thumb drive to perform necessary system tasks, as outlined in her agency's procedures. The thumb drive is provided by the Government for this purpose. Is this an appropriate use of removable media?
A:

Yes. Only use removable media when operationally necessary, Government-owned, and approved in accordance with policy

124How can you identify the separation of Sensitive Compartmented Information (SCI) classified material from collateral classified material?
A:

Markings that identify the compartment with which it is affiliated

125What should you do with your badge within a Sensitive Compartmented Information Facility (SCIF)?
A:

Wear it visibly and above the waist

126Which of the following is a best practice when browsing the Internet?
A:

Look for an icon to indicate encryption is functioning

127You have been issued a new Government-owned mobile device. What is a step you should take to secure it?
A:

Set up a passcode to unlock

128How do Insider Threat Programs defend against insider threats?
A:

Intervening early to help individuals with issues

129How can you protect your home computer?
A:

Turn on spyware protection

130Which of the following is an example of Protected Health Information (PHI)?
A:

An individual's medical record maintained by a healthcare provider

131Ed has authorized access to his agency's Sensitive Compartmented Information Facility (SCIF) and plans to work on a project there today. Which of the following can't he take into the SCIF?
A:

All of these.

132Trisha receives an e-mail with a sensational rumor about a celebrity's personal life. Which of the following actions should Trisha NOT take with the e-mail?
A:

Forward it

133How does an insider threat harm national security?
A:

Exploiting their trusted status and authorized access to government resources

134In what level of system can you use a SIPRNet public key infrastructure (PKI) token?
A:

SIPRNet.

135What risk is posed by Internet of Things (IoT) devices?
A:

Their connectivity can be exploited as an attack vector to any other device on the same network.

136Martha supervises a government unit. To improve morale, she frequently e-mails inspirational stories and photos with inspirational quotes on them to her team. Is this an appropriate use of government e-mail?
A:

No. These email's generate unnecessary e-mail traffic.

137What is a risk to Government systems posed by removable media?
A:

Their data storage and ability to connect to systems can lead to unintended transfers of information, such as introduction of malicious code or spillage.

138Paula is compiling statistics on healthcare provided to Service members over the last fiscal year. Some of her source data includes Protected Health Information (PHI). How can she properly process this data?
A:

Use an encrypted device that requires a passcode or biometrics to unlock

139On a Government-owned mobile device, what should you do before installing an application?
A:

Ensure that it is an approved and authorized application.

140Devon receives an e-mail on her Unclassified Computer. The e-mail has an unmarked attachment that contains what she recognizes as classified information. What should Devon do?
A:

Immediately notify her security POC

141Which of the following is permitted within a collateral classified environment?
A:

A wired headset without a microphone

142Based on the description provided, how many insider threat indicators are present? John frequently comes to work appearing to be hungover. While his access to classified information is consistent with his clearance eligibility and need-to-know, his handling of the information does not protect it from other without eligibility and a need-to-know in accordance with security guidelines. Several coworkers have observed John bringing a call phone into classified areas where devices are prohibited.
A:

3+

143Oscar is on official Government travel with Government-issued laptop. While at the airport, he uses the laptop to work on a report containing controlled unclassified information (CUI). For connectivity, he uses his personal phone as a mobile hotspot. Are there any security concerns here?
A:

Yes. He should be vigilant for "shoulder surfing," where others may be able to view the information on his screen.

144Sara is a government employee with a high degree of expertise in her field. She receives an e-mail from a foreign nation that is complimentary of Sara's expertise and seeks to make a connection with her to learn more about her work. What should Sara do?
A:

Report the contact to her security POC.

145Which of the following is true of information designated as Unclassified?
A:

It does not have the potential to damage national security.

146Oliver users his phone to look up information about a jacket he might want to purchase. Later, he notices ads for the jacket appearing on the websites that he views using his laptop. Why would he see this happen?
A:

Oliver's apps and devices collect and share information about him.

147What is the best practice for user accounts on your home computer?
A:

Each user should have their own account.

148Which of the following is true of transmitting Sensitive Compartmented Information(SCI)?
A:

SCI may be printed using an authorized printer when retrieved promptly.

149You receive a suspicious e-mail that appears to have come from an organization that partners with your agency. Your co-workers have received a similar e-mail. What might this be?
A:

Spear phishing

150Which of the following is an example of a correct way to protect classified data?
A:

Andrea verifies need-to-know and security eligibility before sharing classified information.

151How to prevent spillage?
A:

Label all files with appropriate classification markings

152Knowing indicators of an unstable person can allow you to identify a potential insider threat before an incident.
A:

True

153You receive an e-mail with a link to verify that your account is active. It says you must click the link within 2 days. Your IT department has not sent links like this in the past. The e-mail is not digitally signed. What action should you take?
A:

Report the e-mail to your security POC or help desk

154Which of the following is a potential insider threat indicator?
A:

untreated alcohol use disorder

155Kevin is working with a new foreign contact for a project. While working with the individual, Kevin notices them browsing a website that appears to advocate violence against the United States. What should Kevin do in this instance?
A:

Report potential terrorism behaviors

Know questions we're missing?

Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.

Study these as flashcards

Load all 155 questions into a free study set — flashcards, a practice test, and spaced repetition. No account.

Works on any PDF, doc or web page too — not just military training.

Frequently asked study questions

how can you prevent spillage cyber awareness

Label all files, removable media, and subject headers with appropriate classification markings. The DoD Cyber Awareness Challenge 2026 job aid lists this as a spillage-prevention measure.

This answers the marking-related question in this bank; it is not a complete checklist for every spillage scenario.

Label all files, removable media, and subject headers with appropriate classification markings
DoD Cyber Awareness Challenge 2026, Information Security job aid (DISA / DoD Cyber Exchange)

Veteran? vetaid.ai — free VA benefits help.