← Back to CBT Library

Insider Threat Awareness Answers

Insider Threat Awareness answers and free flashcard study for 61 questions, including potential insider threat indicators and reporting scenarios.

Review Insider Threat Awareness scenarios by comparing the action, intent and recipient described in each question. The bank covers spills, unauthorized disclosures, espionage, sabotage and targeted violence. Citations to the February 2024 CDSE INT101.16 student guide let you compare the course definitions directly instead of treating these different situations as interchangeable terms.

61 questions and answers10 of 61 verified against the official source

Studying for this with your unit? Send it to them.

πŸƒ Flashcards
01What is the name for the unintentional transfer of classified or proprietary information to unaccredited or unauthorized systems, individuals, applications, or media?
A:

The definition is correct, but the added claim 'Spills are the most common form of insider threat' is NOT supported by the February 2024 INT101.16 student guide, which makes no such statement. The only 'most common' claim in that guide concerns adversary collection methods ('The most common methods, used in over 80% of cases'). Recommend dropping the 'most common' sentence.

VERIFIED AGAINST THE SOURCE

β€œA spill is the unintentional transfer of classified or proprietary information to unaccredited or unauthorized systems, individuals, applications, or media.”

β€” CDSE INT101.16 Insider Threat Awareness Student Guide (February 2024), p. 2-7 β†—
02What Targeted Violence subcategory results in physical or psychological harm to the safety and well-being of an employee?
A:

Workplace Bullying/Violence. It is intentional, disruptive physical, verbal, or written behavior committed by an individual or group that physically damages a facility, or psychologically or physically harms an employee.

03What is the name for the intentional, unauthorized disclosure of classified or proprietary information to a person or an organization that does not have a 'need-to-know'?
A:

Leak. Leaks are the intentional, unauthorized disclosure of classified or proprietary information to an unauthorized person or organization.

VERIFIED AGAINST THE SOURCE

β€œan intentional, unauthorized disclosure of classified or proprietary information to a person or organization that doesn't have a "need-to-know."”

β€” CDSE INT101.16 Insider Threat Awareness Student Guide (February 2024), p. 2-7 β†—
04Which of the following is NOT an example of a potential insider threat vulnerability? (Obesity, Drug/alcohol use, Loneliness, Promiscuity)
A:

Obesity. Examples of insider threat vulnerabilities include: financial stress, exploitable promiscuity, addictive behaviors (drug/alcohol abuse, gambling, pornography), loneliness, and disgruntlement.

05Which of the following are examples of behavioral indicators associated with insider threat? (Significant changes in personality/behavior/work habits, Disregard for security procedures, Access to facilities outside normal hours, All of the above)
A:

All of the above. All of these are reportable behavioral indicators that have been associated with insider threat.

06True or False: Adversaries only target you if you have a security clearance.
A:

False. Since the end of the Cold War, 37% of spies had no security clearance. Adversaries target anyone with access to useful information, regardless of clearance level.

07Which of the following is NOT a way to deflect an elicitation attempt? (Ignoring improper questions and changing topic, Tell them what they want to know up front, Stating that you do not know, Deflecting a question with one of your own)
A:

Tell them what they want to know up front. Proper deflection methods include referring to public sources, stating you don't know, deflecting with your own question, or stating you cannot discuss the matter.

08Technological advances impact the insider threat by:
A:

All of the above: Allowing more information to be accessed easily, allowing more information to be transmitted easily, and allowing more information to be edited easily.

09Which of the following is a technology indicator of an insider threat? (Listening to music on Internet, Using Google for open source info, Hoarding files/data/code/programs, Reading online newspapers)
A:

Hoarding files, data, code, and programs. This is a technology-related behavioral indicator that should raise suspicion of insider threat activity.

10How did Manning remove classified documents from a secure facility?
A:

Copied the documents onto a rewritable music CD. Manning brought music CDs to work under the pretense of listening to them, erased the music, then wrote compressed classified data to them.

11Which of the following behavioral indicators would you report to your Security office? (Disregard for security procedures, Seeking access without need-to-know, Access to facilities outside normal hours, All of the above)
A:

All of the above. If you witness or experience any behavioral indicators, you must report them to your immediate supervisor and/or your local Security office.

12How does DoD Directive 5205.16 define an 'insider'?
A:

A person who has or had been granted eligibility for access to classified information or eligibility to hold a sensitive position. (DoDD 5205.16 keys the definition to clearance/sensitive-position eligibility β€” not merely to having access to DoD resources through employment, volunteering, or a contract.)

VERIFIED AGAINST THE SOURCE

β€œinsider. A person who has or had been granted eligibility for access to classified information or eligibility to hold a sensitive position. These individuals include Active and Reserve Component (including National Guard) military personnel, civilian employees (including non-appropriated fund employees), and DoD contractor personnel; this includes officials or employees from federal, State, local, tribal and private sector entities affiliated with or working with DoD who have been granted access to classified information by DoD based on an eligibility determination”

β€” DoDD 5205.16, The DoD Insider Threat Program, Glossary (Incorporating Change 2, August 28, 2017) β†—
13How does the National Insider Threat Task Force (NITTF) define 'insider threat'?
A:

The threat that an insider will use his or her authorized access, wittingly or unwittingly, to do harm to the security of the United States. This can include damage through espionage, terrorism, unauthorized disclosure, or loss/degradation of department resources or capabilities.

Why this answer

The words "wittingly or unwittingly" mean that this definition does not require a person to intend the harm. Someone with authorized access can create an insider threat through an unintended disclosure; the relevant distinction is misuse of that access and harm to security, not simply whether the person meant well.

VERIFIED AGAINST THE SOURCE

β€œIt is a threat posed to U.S. national security by someone who misuses or betrays, wittingly or unwittingly, their authorized access to any U.S. Government resource. This threat can include damage through espionage, terrorism, unauthorized disclosure of national security information, or through the loss or degradation of departmental resources or capabilities.”

β€” NITTF Mission Fact Sheet, ODNI/NCSC β†—
14What are the five main categories of insider threat defined by the NITTF?
A:

OUT OF DATE: the current (February 2024) INT101.16 guide lists FOUR categories, not five, and does not attribute them to the NITTF. They are: (1) Unauthorized disclosure -- which SUBSUMES both leak (intentional) and spill (unintentional) as its two forms, (2) Espionage, (3) Sabotage, (4) Targeted violence. The 'five categories (Leaks, Spills, Espionage, Sabotage, Targeted Violence)' framing is from a retired version of the course. Recommend rewriting to: 'Four: Unauthorized disclosure (leaks and spills), Espionage, Sabotage, and Targeted Violence.'

VERIFIED AGAINST THE SOURCE

β€œThreat Categories. Insider threat categories include: Unauthorized disclosure, which can be in the form of a leak ... Espionage is the unauthorized transmittal of classified or proprietary information ... Sabotage is the act of deliberately destroying, damaging, or obstructing ... Targeted violence is violence directed at an individual or group for a specific reason.”

β€” CDSE INT101.16 Insider Threat Awareness Student Guide (February 2024), p. 2-7 β†—
15What is espionage in the context of insider threat?
A:

The unauthorized transmittal of classified or proprietary information to a competitor, foreign nation, or entity with the intent to harm.

Why this answer

Apply the whole definition: what information was transmitted, whether the transmission was unauthorized, who received it, and whether there was intent to harm. An unauthorized transmission alone does not establish every element of this course definition of espionage; the recipient and intent also matter.

VERIFIED AGAINST THE SOURCE

β€œEspionage is the unauthorized transmittal of classified or proprietary information to a competitor, foreign nation, or entity with the intent to harm.”

β€” CDSE INT101.16 Insider Threat Awareness Student Guide (February 2024), p. 2-7 β†—
16What is sabotage in the context of insider threat?
A:

To deliberately destroy, damage, or obstruct, especially for political or military advantage. Motivations can also include personal disgruntlement.

Why this answer

Destruction is not required by this definition: deliberate obstruction is also included. A scenario about someone intentionally blocking work because of personal disgruntlement can therefore fit sabotage even when it describes no destroyed equipment and no political motive.

VERIFIED AGAINST THE SOURCE

β€œSabotage is the act of deliberately destroying, damaging, or obstructing. While sabotage is often conducted for political or military advantage, personal disgruntlement may also be a motivation.”

β€” CDSE INT101.16 Insider Threat Awareness Student Guide (February 2024), p. 2-7 β†—
17What is targeted violence?
A:

Any form of violence that is directed at an individual or group for a specific reason. Targeted violence is not a random act.

Why this answer

In this course, targeted violence is broader than an active-shooter incident. The guide expressly includes harassment and workplace bullying, so the absence of a weapon does not by itself rule the category out. Look for conduct directed at a particular person or group for a specific reason.

VERIFIED AGAINST THE SOURCE

β€œTargeted violence is violence directed at an individual or group for a specific reason. It includes everything from active shooter to harassment to workplace bullying.”

β€” CDSE INT101.16 Insider Threat Awareness Student Guide (February 2024), p. 2-7 β†—
18What are the subcategories of Targeted Violence?
A:

Active Shooter, Domestic Violence, Harassment, Hostile Work Environment, Sexual Assault, Stalking, Threats/Threatening Behavior, and Workplace Bullying/Violence.

19What is an active shooter?
A:

A person actively engaged in killing, or trying to kill, people in a confined and populated area. Active shooters are not limited only to the use of guns.

20What is the definition of harassment in the context of insider threat?
A:

Any unwelcome written, verbal, or physical conduct that objectively creates a hostile or offensive work environment. It may or may not be based on age, color, gender, disabilities, national origin, race, religion, or other protected categories.

21What behaviors create a hostile work environment?
A:

Behaviors that are severe or pervasive, and perceived as unwelcome or offensive.

22What is stalking in the context of insider threat?
A:

Harassment, unwanted, or threatening physical, verbal, written, or virtual conduct that causes the victim, or could cause the victim, to fear for his or her safety or the safety of a family member.

23What is threatening behavior?
A:

Any use of words or actions that may intimidate or provoke a reasonable person and/or interfere with the performance of official duties.

24What are examples of insider threat vulnerabilities?
A:

Financial stress, exploitable promiscuity, addictive behaviors (drug/alcohol abuse, gambling, pornography), loneliness, and disgruntlement.

25Research has shown that malicious acts by insiders are:
A:

Seldom impulsive. Something happens over time that contributes to a trusted insider evolving into a malicious one, usually some sort of perceived life crisis.

26What are the reportable behavioral indicators associated with insider threat?
A:

Significant changes in personality/behavior/work habits, substance abuse or addictive behaviors, considerable financial change (unexplained affluence or excessive debt), disgruntlement to the point of retaliation, disregard for security procedures, seeking access without need-to-know, after-hours access, and unauthorized copying/hoarding of classified material.

27What should you do if you notice a coworker exhibiting insider threat vulnerabilities?
A:

Say something. Notify the appropriate company representative who can help get the assistance they need before the situation escalates. Identifying colleagues who may be in need of help is not an act of betrayal; it is an act of respect.

28What is a 'honey trap' in the context of insider threat?
A:

A technique where an adversary uses romantic or sexual relationships to recruit or exploit an insider. Benjamin Bishop, a 59-year-old defense contractor, was caught in a honey trap when he passed nuclear secrets to a 27-year-old Chinese graduate student.

29What is elicitation?
A:

A technique used to discreetly gather information through a conversation with a specific purpose: to collect information that is not readily available and do so without raising suspicion. The conversation can be in person, over the phone, or in writing.

30Why does elicitation work?
A:

It exploits natural human tendencies: desire to be polite and helpful, desire to appear well-informed, tendency to expand when given praise, tendency to gossip, tendency to correct others, tendency to underestimate the value of information, and disinclination to be suspicious.

31How can you deflect elicitation attempts?
A:

Refer them to public sources, ignore improper questions and change the topic, deflect a question with your own, respond with 'Why do you ask?', give a nondescript answer, state you don't know, state you'd need to clear discussions with your security office, or state you cannot discuss the matter.

32What types of adversaries want non-public information from insiders?
A:

Foreign governments, terrorist organizations, competitors, and non-state actors all want non-public information that an insider can provide.

33What do adversaries want to know about organizations?
A:

Who are the organization's personnel, with which countries does the organization work, what are the organization's methodologies/capabilities/limitations, and where are the organization's facilities located worldwide.

34What techniques do adversaries use to gather information?
A:

Direct approaches (during travel, persistent requests to socialize, conference requests), exploitation (excessive photography, concealed listening devices, malicious emails, unsecured Wi-Fi), and elicitation.

35If contacted by a member of the media about information you are not authorized to share, what should you do?
A:

Take down the person's name and organization, date, time, location, method of contact, and reason for contact. Report this information to your organization's security office.

36Since the end of the Cold War, what percentage of spies have been civilians?
A:

67% of spies have been civilians. Also, 37% had no security clearance, 84% were successful, and 67% volunteered to commit espionage.

37What percentage of post-Cold War spies received no money for their services?
A:

81% received no money for their services. 94% went to prison.

38What are technology-related indicators of insider threat?
A:

Improper use of privileged access, working odd hours without authorization, bypassing security rules/protocols, inappropriate copying of classified info, requests for access beyond scope, introducing unauthorized devices, keeping unauthorized backups, unauthorized removal of equipment, and hoarding files/data/code.

39How did Harold T. Martin III demonstrate insider threat through technology?
A:

Two refinements per the current CDSE guide: the guide says Martin stole classified data 'over 30 years' (the answer says 'more than two decades'), and it records the disposition -- he was SENTENCED TO 9 YEARS, not merely 'arrested.' The guide describes him as 'a defense contractor' rather than specifically 'an NSA contractor.'

VERIFIED AGAINST THE SOURCE

β€œHarold Martin III, a defense contractor, was sentenced to 9 years for stealing 50 terabytes of classified information. ... Real-life insider threat Harold Martin III used his position as a contractor to steal terabytes of classified data over 30 years. Clearly, he must have displayed some concerning behavior over that time. Improper use of privileged access, hoarding, and knowingly bypassing protocols are all reportable technology-related behaviors.”

β€” CDSE INT101.16 Insider Threat Awareness Student Guide (February 2024), pp. 3-1, 4-4 β†—
40What is the story of Daniela Greene as an insider threat case?
A:

Greene was an FBI translator with Top Secret clearance who was assigned to investigate an ISIS recruiter. Instead, she traveled to Syria to marry the terrorist she was supposed to be watching, after falsely stating she was visiting family in Germany. She was sentenced to two years in prison.

41How can you help reduce technology-associated insider threat?
A:

Use strong passwords, keep out unauthorized devices, prevent unauthorized access, inventory tech holdings, ask questions and take training, watch for behavioral indicators, and be cautious on social media.

42Why is social media a vulnerability for insider threat?
A:

In the social media age, people share details of their personal and professional lives online, making them much more vulnerable to adversaries, competitors, and cyber-criminals, who all use the Internet as a key targeting tool.

43What is an Employee Assistance Program (EAP)?
A:

A program that offers financial counseling, mental health support, and other services to help employees address problems before they escalate. Most EAPs recognize diagnosable addictive disorders as treatable illnesses.

44What are employee reporting obligations related to insider threat?
A:

Personal foreign travel (even Canada) must be reported. Personal foreign contacts and outside activities involving Intelligence Community information must also be reported.

45What should contractors report regarding insider threat?
A:

Events that impact facility status, personnel security clearance, proper safeguarding of classified information, or indications that classified information has been lost or compromised. Reports go to DSS and the FBI.

46What are reportable activities related to insider threat?
A:

Unauthorized disclosure, improper use of privileged access, working odd hours without authorization, bypassing security rules, inappropriate copying, requests for access beyond scope, unauthorized devices, unauthorized backups, unauthorized removal of equipment, and hoarding files/data.

47What is the most challenging barrier to reporting insider threat activity?
A:

The belief that we are not susceptible. People are naive and complacent, in denial that something could happen to their organization.

48In the 'Betrayed' video scenario, what insider threat indicators did coworkers observe?
A:

Photographing documents with a cell phone in the SCIF, changing screens when people entered the room, a new unexplained romantic relationship, unreported foreign travel (London), and suspicious online gaming contacts.

49What mistake did the coworkers make in the 'Betrayed' video scenario?
A:

They rationalized and explained away the suspicious behavior instead of reporting it. Tom even tipped off the suspect by confronting him directly, instead of reporting to the security officer. They should have contacted their security officer immediately.

50Gregory Allen Justice was convicted of what insider threat category?
A:

Espionage. Justice, an aerospace engineer, attempted to sell satellite secrets to someone he believed was Russian intelligence. His vulnerabilities included disgruntlement (felt unappreciated at work) and personal stress (caring for a sick wife).

51What insider threat category did John Robert Neumann represent?
A:

Targeted Violence (Active Shooter). The disgruntled former employee returned to his workplace and killed five coworkers. He had a history of negative relationships and had battered another employee previously.

52What insider threat category did Chelsea Manning represent?
A:

Leak. Manning, a U.S. Army intelligence analyst, leaked more than 750,000 classified documents to WikiLeaks in 2010 by copying data onto rewritable CDs labeled as music.

53Studies of inside offenders have shown that most:
A:

Were known to have displayed concerning or problematic behavior before acting directly against their organization. This behavior included violations of policies, standard procedures, accepted practices, or laws observed by managers, supervisors, and coworkers.

VERIFIED AGAINST THE SOURCE

β€œresponsibility to be aware of concerning behavior. It is not up to you to speculate if it may indicate an actual threat.”

β€” CDSE INT101.16 Insider Threat Awareness Student Guide (February 2024), p. 4-4 β†—
54What is domestic violence in the context of insider threat targeted violence?
A:

Violence, usually physical abuse or threat, that creates a risk to the health and safety of an employee. It includes any abusive, violent, coercive, forceful, or threatening act used to gain power and control over a household or family member, current or former spouse or partner.

55What is sexual assault in the context of insider threat targeted violence?
A:

A range of behaviors including completed or attempted nonconsensual sex acts and abusive sexual contact. It includes any sexual act perpetrated without consent, whether due to force, threat, incapacitation, minority, or inability to consent.

56True or False: Seeking assistance to deal with life's challenges is a sign of weakness.
A:

False. Seeking assistance is a sign of good judgment and an act of bravery. Identifying colleagues who may need help is an ultimate act of respect for their safety, the company, and the nation.

57What should you do to protect against adversary elicitation at conferences?
A:

Be prepared by talking to your security officer first, beware of odd behaviors like repeat requests or suspicious business cards, and reduce exploitation by using VPN on Wi-Fi, screening suspicious emails, and never loaning your devices.

58How much American intellectual property is stolen yearly by foreign adversaries?
A:

$300 billion worth of American intellectual property and business intelligence are stolen yearly by China, Russia, Iran, and others.

59What was the Benjamin Bishop insider threat case about?
A:

Bishop, a 59-year-old civilian defense contractor, pleaded guilty to passing nuclear weapons secrets to a 27-year-old Chinese graduate student he met at an international military conference. He was caught in a honey trap and sentenced to 87 months in prison.

60What should you report if you notice a coworker discussing financial difficulties and expressing excessive debt while asking about overtime?
A:

Report the concerning behavior to your security officer. Financial stress combined with seeking additional income opportunities is a behavioral indicator of potential insider threat vulnerability that could be exploited by adversaries.

61True or False: It is your responsibility to investigate a coworker's suspicious behavior before reporting it.
A:

False. You should report suspicious behavior to your security office. It is their job to investigate. Do NOT confront the individual or conduct your own investigation, as this could compromise an official investigation.

Know questions we're missing?

Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.

Study these as flashcards

Load all 61 questions into a free study set β€” flashcards, a practice test, and spaced repetition. No account.

Works on any PDF, doc or web page too β€” not just military training.

Frequently asked study questions

which of the following is a potential insider threat indicator

Alcohol or other substance misuse or dependence is one potential insider threat indicator listed in the DoD job aid.

This is an example, not a selection of every correct option. Compare the choices in your course; the question wording alone does not identify a unique keyed choice.

We detect insider threats by using our powers of observation to recognize potential insider threat indicators. These include, but are not limited to: Difficult life circumstances; Divorce or death of spouse; Alcohol or other substance misuse or dependence; Untreated mental health issues; Financial difficulties
DoD Cyber Awareness Challenge 2026, Insider Threat job aid (DISA / DoD Cyber Exchange)

Veteran? vetaid.ai β€” free VA benefits help.