← Back to CBT Library

DoD Annual Security Awareness Refresher Answers

DoD Annual Security Awareness Refresher answers for independent study: review 39 questions on suspicious contacts, reporting requirements and classified spillage, or use the linked flashcards.

DoD Annual Security Awareness training covering insider threat indicators, counterintelligence, suspicious contacts, foreign travel, social media risks, security violations, reporting requirements, and classified spillage procedures. Based on CDSE curriculum.

39 questions and answers7 of 39 verified against the official source

Studying for this with your unit? Send it to them.

🃏 Flashcards
01What is the primary purpose of the DoD Annual Security Awareness Refresher training?
A:

To ensure all personnel with access to classified information or who hold security clearances maintain awareness of their security responsibilities, current threats, and reporting requirements.

02What is an insider threat?
A:

An insider threat is a person with authorized access to DoD resources who uses that access — wittingly or unwittingly — to harm national security, including espionage, unauthorized disclosure, sabotage, or workplace violence.

VERIFIED AGAINST THE SOURCE

It is a threat posed to U.S. national security by someone who misuses or betrays, wittingly or unwittingly, their authorized access to any U.S. Government resource. This threat can include damage through espionage, terrorism, unauthorized disclosure of national security information, or through the loss or degradation of departmental resources or capabilities.

NITTF Mission Fact Sheet, ODNI/NCSC
03Name five behavioral indicators of a potential insider threat.
A:

Unexplained affluence, working unusual hours without authorization, attempts to access information beyond need-to-know, disgruntlement with the organization, and unreported foreign contacts or travel.

04What is counterintelligence (CI)?
A:

Counterintelligence encompasses activities conducted to identify, deceive, exploit, disrupt, or protect against espionage, sabotage, or other intelligence activities conducted by foreign powers, organizations, or persons.

05What should you do if approached by someone you suspect is attempting to collect classified information?
A:

Do not provide any information, disengage from the conversation, note details about the person and encounter, and immediately report the contact to your security manager and local counterintelligence office.

06What are 'suspicious contacts' that require reporting?
A:

Any contact with known or suspected foreign intelligence officers, any attempt by anyone to obtain classified or sensitive information without authorization, and any contact that suggests you may be a target of exploitation.

07What are your reporting obligations before foreign travel?
A:

Report planned foreign travel to your security manager in advance, complete a foreign travel briefing, understand country-specific threats, know what devices you can take, and complete a debrief upon return.

08What precautions should you take with electronic devices during foreign travel?
A:

Use only clean/burner devices if possible, never connect to unsecured networks, never leave devices unattended, assume all communications are monitored, disable Bluetooth and Wi-Fi when not in use, and consider that hotel safes are not secure.

09What social media risks exist for cleared personnel?
A:

Social media can reveal duty stations, deployment info, security clearance levels, and personal vulnerabilities. Foreign intelligence services actively mine social media to identify, target, and recruit cleared personnel.

10What information should cleared personnel never post on social media?
A:

Classified information, security clearance level, specific job functions involving classified work, deployment details, unit movements, operational information, or details that could be used for blackmail or recruitment.

11What is a security violation?
A:

A security violation is any knowing, willful, or negligent action that results in the unauthorized disclosure of classified information, or an action that could reasonably be expected to result in such disclosure.

12What is a security infraction versus a security violation?
A:

A security infraction is a deviation from security regulations that does not result in the actual or probable compromise of classified information. A violation involves known or probable compromise. Both require reporting.

13What is classified spillage?
A:

Classified spillage occurs when classified data is placed on an unclassified information system (e.g., sending SECRET info via unclassified email). It is a security incident requiring immediate reporting and remediation.

14What steps must be taken when classified spillage is discovered?
A:

Stop the spillage (don't forward/copy), disconnect the affected system from the network if possible, do not delete the data, notify your security manager and Information System Security Officer (ISSO) immediately, and document the incident.

15Who do you report security incidents to?
A:

Report to your immediate supervisor, your organization's security manager, and your Information System Security Officer (ISSO). For imminent threats to life or national security, contact law enforcement or counterintelligence directly.

16What are the three levels of classified information and their definitions?
A:

Confidential: damage to national security. Secret: serious damage to national security. Top Secret: exceptionally grave damage to national security. Each level requires its own safeguarding procedures.

VERIFIED AGAINST THE SOURCE

(1) "Top Secret" shall be applied to information, the unauthorized disclosure of which reasonably could be expected to cause exceptionally grave damage to the national security that the original classification authority is able to identify or describe. (2) "Secret" shall be applied to information, the unauthorized disclosure of which reasonably could be expected to cause serious damage to the national security ... (3) "Confidential" shall be applied to information, the unauthorized disclosure of which reasonably could be expected to cause damage to the national security ...

Executive Order 13526, Sec. 1.2(a)
17What is the 'need-to-know' principle?
A:

Need-to-know means that even with the proper clearance level, a person must have an official need to access specific classified information to perform their duties. Clearance alone is not sufficient for access.

18What is the 'two-person integrity' (TPI) rule for classified materials?
A:

TPI requires that at least two authorized persons be present when accessing or handling certain highly sensitive classified materials (e.g., COMSEC, nuclear-related) to prevent unauthorized access or tampering.

19What is a Sensitive Compartmented Information Facility (SCIF)?
A:

A SCIF is an accredited area where Sensitive Compartmented Information (SCI) can be stored, discussed, and processed. It has enhanced physical security, access controls, and technical countermeasures against surveillance.

20What items are typically prohibited in a SCIF?
A:

Personal electronic devices (cell phones, smartwatches, fitness trackers, personal laptops), unauthorized recording devices, cameras, and any non-authorized portable electronic device that could transmit or store data.

21What is the SF-86 and why is it important for security awareness?
A:

The SF-86 (Questionnaire for National Security Positions) is used for background investigations. Personnel must report changes to information on their SF-86 — such as foreign contacts, financial problems, or arrests — to their security manager.

22What types of personal conduct must be self-reported to your security manager?
A:

Arrests, charges, convictions, bankruptcies, significant financial difficulties, foreign contacts or relationships, foreign travel, suspicious contacts, mental health treatment (with limitations), and any activity that could affect your clearance eligibility.

23What is Continuous Evaluation (CE) and how does it affect cleared personnel?
A:

CE is the ongoing review of a cleared person's background between periodic reinvestigations. It uses automated checks of financial, criminal, and other records to detect issues that may affect clearance eligibility.

24What is the Insider Threat Program and what does Executive Order 13587 require?
A:

EO 13587 requires all federal agencies with classified networks to establish insider threat programs that deter, detect, and mitigate insider threats through monitoring, training, and integrated CI and security capabilities.

VERIFIED AGAINST THE SOURCE

insider threat. The threat insiders may pose to DoD and U.S. Government installations, facilities, personnel, missions, or resources. This threat can include damage to the United States through espionage, terrorism, unauthorized disclosure of national security information, or through the loss or degradation of departmental resources or capabilities.

DoDD 5205.16, The DoD Insider Threat Program (Incorporating Change 2, August 28, 2017)
25What is the role of the Insider Threat Program Senior Official (ITPSO)?
A:

The ITPSO leads the organization's insider threat program, coordinates between security, CI, human resources, IT, and legal, and ensures compliance with NITTF (National Insider Threat Task Force) minimum standards.

26How should classified documents be stored when not in use?
A:

In GSA-approved security containers appropriate for the classification level, in a locked SCIF/vault for SCI materials, with proper end-of-day security checks. Secret and Confidential require GSA Class 5 or 6 containers.

27What are the approved methods for destroying classified documents?
A:

NSA/CSS-approved crosscut shredders (for up to Secret), burning, pulping, or disintegration. Top Secret destruction typically requires burning or pulping with two-person witnessing and a destruction certificate.

28What is the significance of derivative classification?
A:

Derivative classification is incorporating, paraphrasing, restating, or generating classified information from existing classified sources into a new document. The person doing so must be trained and must properly mark the new document.

VERIFIED AGAINST THE SOURCE

"Derivative classification" means the incorporating, paraphrasing, restating, or generating in new form information that is already classified, and marking the newly developed material consistent with the classification markings that apply to the source information. Derivative classification includes the classification of information based on classification guidance. The duplication or reproduction of existing classified information is not derivative classification.

Executive Order 13526, Sec. 6.1(o)
29How often must derivative classifiers receive training?
A:

INCOMPLETE for DoD. EO 13526 Sec. 2.1(d)'s 'at least once every 2 years' is a government-wide floor. CDSE's IF103.16 student guide states verbatim: 'Derivative Classification training is mandatory and an annual requirement. Personnel shall receive this training prior to derivatively classifying information.' On a DoD Annual Security Awareness quiz this should read: before first use, then ANNUALLY per DoD/CDSE (EO floor: every 2 years).

VERIFIED AGAINST THE SOURCE

Persons who apply derivative classification markings shall receive training in the proper application of the derivative classification principles of the order, with an emphasis on avoiding over-classification, at least once every 2 years. Derivative classifiers who do not receive such training at least once every 2 years shall have their authority to apply derivative classification markings suspended until they have received such training.

Executive Order 13526, Sec. 2.1(d); CDSE IF103.16 Student Guide (July 2021), p. 1-3
30What is a Foreign Intelligence Entity (FIE)?
A:

An FIE is any known or suspected foreign government, organization, or person that conducts intelligence activities, including espionage, against the United States. FIEs target cleared personnel for recruitment and information theft.

31What are common recruitment techniques used by Foreign Intelligence Entities?
A:

MICE: Money (bribery), Ideology (appealing to beliefs), Compromise/Coercion (blackmail), and Ego (flattery). Modern additions include cyber exploitation, social media targeting, and academic/conference approaches.

32What is an 'elicitation' technique in counterintelligence?
A:

Elicitation is the subtle extraction of information through seemingly normal conversation. Techniques include flattery, deliberate provocation, assumed knowledge, and casual questioning in social settings.

33What should you do if you suspect you are being elicited for sensitive information?
A:

Deflect the conversation to non-sensitive topics, do not confirm or deny any classified information, end the interaction politely, note details of the encounter, and report it to your security manager and CI.

34What is the significance of SF-312 (Classified Information Nondisclosure Agreement)?
A:

The SF-312 is a legally binding agreement signed by all persons granted access to classified information. It obligates them to protect classified information for life and acknowledges criminal penalties for unauthorized disclosure.

35What are the consequences of a security violation?
A:

Consequences range from security awareness counseling and additional training to suspension or revocation of clearance, administrative action, termination of employment, and criminal prosecution depending on severity and intent.

VERIFIED AGAINST THE SOURCE

Officers and employees of the United States Government, and its contractors, licensees, certificate holders, and grantees shall be subject to appropriate sanctions if they knowingly, willfully, or negligently: (1) disclose to unauthorized persons information properly classified under this order or predecessor orders; (2) classify or continue the classification of information in violation of this order or any implementing directive; (3) create or continue a special access program contrary to the requirements of this order; or (4) contravene any other provision of this order or its implementing directives.

Executive Order 13526, Sec. 5.5(b)
36What is 'classification by compilation'?
A:

Classification by compilation occurs when individually unclassified pieces of information, when combined, reveal classified information. The compiled document must be classified at the appropriate level.

VERIFIED AGAINST THE SOURCE

Compilations of items of information that are individually unclassified may be classified if the compiled information reveals an additional association or relationship that: (1) meets the standards for classification under this order; and (2) is not otherwise revealed in the individual items of information.

Executive Order 13526, Sec. 1.7(e)
37What are the reporting requirements for contact with foreign nationals?
A:

Report close and continuing contact with foreign nationals (personal relationships, cohabitation, financial obligations) to your security manager. Some organizations require reporting all foreign national contacts. Requirements vary by agency and clearance level.

38What is a 'dead drop' in the context of espionage awareness?
A:

A dead drop is a prearranged secret location where materials (documents, data, money) are left for another person to pick up later without direct contact. It is a classic espionage tradecraft technique personnel should be aware of.

39What must you do at the end of each workday if you handle classified materials?
A:

Conduct an end-of-day security check: verify all classified materials are properly stored in approved containers, lock all safes/vaults, verify security of the area, and complete the SF-702 (Security Container Check Sheet).

Know questions we're missing?

Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.

Study these as flashcards

Load all 39 questions into a free study set — flashcards, a practice test, and spaced repetition. No account.

Works on any PDF, doc or web page too — not just military training.

Veteran? vetaid.ai — free VA benefits help.