← Back to CBT Library

Cyber Fundamentals

DoD Cyber Fundamentals and Information Assurance training. Covers PKI, CAC authentication, STIG compliance, DISA, incident response, CCRI, ATO process, Risk Management Framework (RMF), and FISMA. Based on DoDI 8510.01 and NIST SP 800-37.

41 questions and answers

Studying for this with your unit? Send it to them.

πŸƒ Flashcards
01What is the Risk Management Framework (RMF)?
A:

RMF is the DoD process for managing cybersecurity risk to information systems. It replaced DIACAP and aligns with NIST SP 800-37. The six steps are: Categorize, Select, Implement, Assess, Authorize, and Monitor. It provides a structured approach to integrating security into the system development lifecycle.

02What are the six steps of the RMF?
A:

Step 1: Categorize the information system. Step 2: Select security controls. Step 3: Implement security controls. Step 4: Assess security controls. Step 5: Authorize the information system. Step 6: Monitor security controls on an ongoing basis. These steps are defined in NIST SP 800-37.

03What is an Authorization to Operate (ATO)?
A:

An ATO is the official management decision by an Authorizing Official (AO) to allow operation of an information system at an acceptable level of risk. It is granted after assessing the security controls through the RMF process. ATOs typically have a 3-year duration with continuous monitoring.

04What is FISMA?
A:

The Federal Information Security Modernization Act (FISMA) of 2014 (originally 2002) requires federal agencies to develop, document, and implement agency-wide information security programs. It mandates annual security assessments, risk management, incident response plans, and reporting to OMB and Congress.

05What is DISA?
A:

The Defense Information Systems Agency (DISA) is the DoD agency that provides IT and communications support. DISA develops and maintains STIGs, operates the DoD Information Network (DoDIN), provides cybersecurity tools and services, and manages the DoD PKI infrastructure.

06What is a STIG?
A:

A Security Technical Implementation Guide (STIG) is a configuration standard published by DISA for securing information systems and software. STIGs contain technical guidance for hardening systems to reduce vulnerabilities. Compliance with applicable STIGs is mandatory for all DoD information systems.

07What is PKI (Public Key Infrastructure)?
A:

PKI is a framework of policies, hardware, software, and procedures for creating, managing, distributing, and revoking digital certificates. DoD PKI provides authentication, digital signatures, and encryption capabilities. It is the backbone of CAC-based identity verification.

08What is the Common Access Card (CAC)?
A:

The CAC is the standard DoD identification card that serves as the principal card for physical access to buildings and controlled spaces, and as the primary token for logical access to DoD networks and systems. It contains PKI certificates for authentication, digital signatures, and encryption.

09What certificates are on a CAC?
A:

A CAC contains three PKI certificates: (1) Identity/Authentication certificate for network logon, (2) Digital Signature certificate for signing emails and documents, and (3) Encryption certificate for encrypting/decrypting emails. Each serves a distinct purpose in the DoD PKI framework.

10What is a CCRI?
A:

A Command Cyber Readiness Inspection (CCRI) is a DISA-conducted assessment of a command's cybersecurity posture. It evaluates STIG compliance, vulnerability management, physical security, user training, and incident response. Findings are rated as CAT I (critical), CAT II (high), or CAT III (medium).

11What are the CCRI finding categories?
A:

CAT I β€” Critical vulnerability that directly results in loss of confidentiality, availability, or integrity. Must be remediated immediately. CAT II β€” Vulnerability that has potential for loss but has some mitigating factors. CAT III β€” Vulnerability that degrades measures to protect against loss but is low severity.

12What is the Authorizing Official (AO)?
A:

The Authorizing Official is the senior official with the authority to formally assume responsibility for operating an information system at an acceptable level of risk. The AO grants or denies the ATO and is accountable for the security of the system and its data.

13What is a Plan of Action and Milestones (POA&M)?
A:

A POA&M is a document that identifies tasks needed to remediate security weaknesses found during assessment, the resources required, milestones with dates, and scheduled completion. It tracks the status of corrective actions and is required for any system with identified vulnerabilities operating under an ATO.

14What is the difference between an ATO and an IATT?
A:

An ATO (Authorization to Operate) allows full operational use. An Interim Authorization to Test (IATT) provides limited authorization for testing purposes only, typically with restrictions on data types and connectivity. An IATT is temporary and must be converted to an ATO or the system must be disconnected.

15What is NIST SP 800-53?
A:

NIST Special Publication 800-53 provides the catalog of security and privacy controls for federal information systems. It organizes controls into 20 families (e.g., Access Control, Audit and Accountability, Incident Response). DoD selects controls from this catalog based on system categorization.

16What is system categorization under RMF?
A:

System categorization (RMF Step 1) determines the impact level of the information system based on the potential impact of a security breach on confidentiality, integrity, and availability. Using FIPS 199/CNSSI 1253, systems are categorized as Low, Moderate, or High impact, which drives control selection.

17What is FIPS 199?
A:

Federal Information Processing Standard 199 establishes standards for categorizing federal information and information systems. It defines three impact levels (Low, Moderate, High) for three security objectives (Confidentiality, Integrity, Availability). The highest impact level across the three objectives determines the overall system categorization.

18What is the DoD Information Network (DoDIN)?
A:

The DoDIN is the globally interconnected set of information capabilities for collecting, processing, storing, disseminating, and managing information on demand. It includes all DoD-owned and leased communications and computing systems and services. DISA is responsible for DoDIN operations.

19What is an Assured Compliance Assessment Solution (ACAS)?
A:

ACAS is the DoD's vulnerability scanning and management solution. It includes Tenable Nessus scanners and Security Center for centralized management. ACAS identifies vulnerabilities, misconfigurations, and policy violations on DoD networks and generates compliance reports for CCRI and RMF.

20What is Host-Based Security System (HBSS)?
A:

HBSS is the DoD's endpoint security suite based on McAfee/Trellix ePolicy Orchestrator (ePO). It provides host intrusion prevention, antivirus, device control, and asset baseline monitoring. HBSS is mandatory on all DoD endpoints and is assessed during CCRIs.

21What is a cybersecurity incident?
A:

A cybersecurity incident is an occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of an information system or the information it processes, stores, or transmits, or constitutes a violation of security policies, procedures, or acceptable use policies.

22What are the incident response reporting timelines?
A:

Category 1 incidents (root-level compromise, data exfiltration) must be reported within 1 hour. Category 2-6 incidents have varying timelines per CJCSM 6510.01B. All incidents must be reported to the Component Cyber Operations Center (CCOC) and US-CERT/CISA as applicable.

23What is the DoD Cybersecurity Scorecard?
A:

The DoD Cybersecurity Scorecard tracks the cybersecurity posture of DoD components using key metrics including STIG compliance, vulnerability management, incident response, PKI adoption, and privileged access management. It is used to report cybersecurity readiness to senior leadership.

24What is DoDI 8510.01?
A:

DoDI 8510.01, Risk Management Framework for DoD Systems, establishes the RMF as the DoD cybersecurity authorization process. It defines roles, responsibilities, and procedures for categorizing systems, selecting and assessing controls, authorizing systems, and conducting continuous monitoring.

25What is multifactor authentication (MFA) in the DoD context?
A:

DoD requires MFA for all network access. The CAC provides two factors: something you have (the physical card) and something you know (the PIN). Privileged users may require additional factors. MFA is mandated by OMB M-22-09 (Zero Trust) and HSPD-12.

26What is the Zero Trust security model?
A:

Zero Trust assumes no user, device, or network is inherently trusted, even inside the perimeter. It requires continuous verification, least-privilege access, micro-segmentation, and monitoring. DoD adopted Zero Trust per the DoD Zero Trust Strategy (November 2022), targeting full implementation by FY2027.

27What is a Boundary/Cross Domain Solution (CDS)?
A:

A Cross Domain Solution is a system that provides the ability to access or transfer information between two or more security domains (e.g., unclassified to classified). CDS must be approved and accredited, and are tightly controlled. They enable information sharing while maintaining security separation.

28What are the three security objectives defined by FIPS 199?
A:

Confidentiality β€” preserving authorized restrictions on information access and disclosure. Integrity β€” guarding against improper information modification or destruction. Availability β€” ensuring timely and reliable access to and use of information. Each is rated Low, Moderate, or High impact.

29What is a Security Control Assessment (SCA)?
A:

An SCA (RMF Step 4) is the formal evaluation of security controls to determine if they are implemented correctly, operating as intended, and producing the desired outcome. An independent assessor conducts the SCA and documents results in the Security Assessment Report (SAR).

30What is the Security Assessment Report (SAR)?
A:

The SAR documents the results of the security control assessment, identifying which controls passed, which failed, and the associated risks. The AO uses the SAR, along with the POA&M and system security plan, to make the authorization decision (ATO, denial, or IATT).

31What is the System Security Plan (SSP)?
A:

The SSP describes the security requirements for the system, the controls in place or planned to meet those requirements, and the responsibilities of individuals who operate the system. It is a living document updated throughout the system lifecycle and is required for RMF authorization.

32What is Continuous Monitoring in the RMF?
A:

Continuous Monitoring (RMF Step 6) is the ongoing awareness of information security, vulnerabilities, and threats to support risk management decisions. It includes automated scanning, configuration management, security impact analysis of changes, and regular reassessment of selected controls.

33What is a Denial of Service (DoS) attack?
A:

A DoS attack is an attempt to make a system, service, or network unavailable to its intended users by overwhelming it with traffic, exploiting vulnerabilities, or consuming resources. A Distributed Denial of Service (DDoS) uses multiple compromised systems. DoS attacks must be reported as cybersecurity incidents.

34What is privileged access management?
A:

Privileged access management controls and monitors access by users with elevated permissions (system administrators, database admins). DoD requires privileged users to be specially trained, use separate accounts for privileged/unprivileged actions, and undergo additional vetting. Privileged access is a primary CCRI focus area.

35What is the purpose of audit logs in cybersecurity?
A:

Audit logs record system events (logins, access attempts, configuration changes, errors) to support accountability, incident investigation, and continuous monitoring. DoD systems must enable auditing per STIG requirements, protect logs from tampering, and retain them for the period specified in records schedules.

36What is a vulnerability assessment?
A:

A vulnerability assessment is a systematic examination of an information system to identify security weaknesses. In DoD, vulnerability assessments are conducted using ACAS (Nessus) scanners and STIG checklists. Results are used for remediation prioritization, POA&M development, and CCRI readiness.

37What is a Security Impact Analysis (SIA)?
A:

An SIA determines the potential impact of proposed changes to an information system's security posture. Before any system change (patches, configuration changes, new software), an SIA assesses whether the change introduces new vulnerabilities or affects existing security controls.

38What is the role of the Information System Security Manager (ISSM)?
A:

The ISSM is responsible for the cybersecurity of an information system or program. They develop and maintain the SSP, ensure STIG compliance, manage POA&Ms, oversee security assessments, coordinate with the AO, and ensure personnel complete required cybersecurity training.

39What is the role of the Information System Security Officer (ISSO)?
A:

The ISSO assists the ISSM in implementing the cybersecurity program for assigned systems. They conduct day-to-day security operations including monitoring audit logs, managing user accounts, applying patches, running vulnerability scans, and reporting security incidents.

40What is network segmentation and why is it important?
A:

Network segmentation divides a network into smaller zones to limit lateral movement by attackers, contain breaches, and enforce access controls between zones. It is a key component of Zero Trust architecture and defense-in-depth. DoD networks use VLANs, firewalls, and access control lists for segmentation.

41What is the Cybersecurity Maturity Model Certification (CMMC)?
A:

CMMC is the DoD framework for assessing and certifying the cybersecurity practices of defense contractors. It ensures contractors handling Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) meet required cybersecurity standards. CMMC 2.0 has three levels aligned with NIST SP 800-171.

Know questions we're missing?

Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.

Study these as flashcards

Load all 41 questions into a free study set β€” flashcards, a practice test, and spaced repetition. No account.

Works on any PDF, doc or web page too β€” not just military training.

Veteran? vetaid.ai β€” free VA benefits help.