OPSEC CBT Answers
OPSEC CBT answers for independent study: search 61 operations security questions or use the free flashcards to review the five-step process.
Study OPSEC by following the five-step process from identifying critical information through applying protective measures. This bank separates questions about what an adversary wants to learn, how that adversary can collect it and what friendly activities expose. The quoted AR 530-1 passages provide a reference for checking those distinctions against the course questions.
Studying for this with your unit? Send it to them.
01Operational Security (OPSEC) defines Critical Information as:
Specific facts about friendly intentions, capabilities, and activities needed by adversaries to plan and act effectively against friendly mission accomplishment.
Why this answer
The deciding test is how an adversary could use a fact to interfere with the mission, not merely whether the fact concerns the organization. The definition also includes friendly limitations and vulnerabilities: knowing what a force cannot do can help an adversary plan just as knowing its capabilities can.
VERIFIED AGAINST THE SOURCE
βCritical information consists of specific facts about friendly capabilities, activities, limitations (includes vulnerabilities), and intentions needed by adversaries for them to plan and act effectively so as to degrade friendly mission accomplishment.β
β AR 530-1, Operations Security (26 September 2014), para 3-1b(2) β02OPSEC is:
A process that is a systematic method used to identify, control, and protect critical information and subsequently analyze friendly actions associated with military operations and other activities.
03A vulnerability exists when:
The adversary is capable of collecting critical information, correctly analyzing it, and then taking timely action.
04A threat is an adversary that has the _____ + _____ to take any actions detrimental to the success of DOD activities or operations.
Intent + Capability
05The purpose of OPSEC is to:
Reduce the vulnerability of U.S. and multinational forces from successful adversary exploitation of critical information.
06OPSEC as a capability of Information Operations:
Denies the adversary the information needed to correctly assess friendly capabilities and intentions.
07The identification of critical information is a key part of the OPSEC process because:
It focuses the remainder of the OPSEC process on protecting vital information rather than attempting to protect all unclassified information.
08Protection of sensitive unclassified information is:
The responsibility of all persons, including civilians and contractors.
09OPSEC is concerned with:
Identifying, controlling, and protecting unclassified information that is associated with specific military operations and activities.
10If it is believed that an OPSEC disclosure has occurred, you should:
Report the OPSEC disclosure to your OPSEC representative or the EUCOM OPSEC PM.
11Which one would be considered critical information?
Deployment dates and location.
12True or False: An indicator is a comprehensive analysis of critical information by an adversary normally providing the whole picture of an agency's capabilities.
False. An indicator is a piece of friendly detectable action or open-source information that can be interpreted or pieced together by an adversary to derive critical information.
13True or False: Critical unclassified information is sometimes revealed by publicly available information.
True. Critical Information is unclassified and controlled unclassified information (CUI) that can be revealed through publicly available sources.
14Which of the following are good OPSEC countermeasures?
Use social media with caution by limiting the amount of personal information you post, and be aware that the photos you take with smartphones and load to the internet may have been geotagged.
15A service member tells a family member about a sensitive training exercise. The family member posts details of the event on a social media site. Could an adversary use this information as an indicator to obtain critical information?
Yes. Even seemingly innocent information shared by family members on social media can serve as indicators that adversaries can piece together to derive critical information.
16A person leaving a facility and failing to remove their ID badge. Could an adversary use this information as an indicator to obtain critical information?
Yes. Wearing an ID badge outside a facility reveals organizational affiliation, facility location, and potentially access levels to adversaries conducting surveillance.
17OPSEC planning should focus on:
Identifying and protecting critical information.
18OPSEC is:
An operations function, not a security function.
19What are the five steps of the OPSEC process?
1) Identify critical information, 2) Analyze threats, 3) Analyze vulnerabilities, 4) Assess risk, 5) Apply appropriate countermeasures.
Why this answer
Threat analysis and vulnerability analysis ask different questions. An adversary's ability to collect a transmission belongs to threat analysis; the friendly activity exposing critical information belongs to vulnerability analysis. Risk assessment then considers protective measures, while the final step puts the selected measures into practice.
VERIFIED AGAINST THE SOURCE
βIt uses the following steps: (a) Identification of critical information. Determine what information needs protection. (b) Analysis of threats. Identify the adversaries and how they can collect information. (c) Analysis of vulnerabilities. Analyze what critical information friendly forces are exposing. (d) Assessment of risk. Assess what protective measures should be implemented. (e) Application of appropriate OPSEC measures that protect critical information.β
β AR 530-1, Operations Security (26 September 2014), para 3-2b(1) β20What is the first step of the OPSEC process?
Identify critical information. This involves determining what information, if available to adversaries, would harm friendly operations or give them an advantage.
VERIFIED AGAINST THE SOURCE
βIdentification of critical information. Determine what information needs protection.β
β AR 530-1, Operations Security (26 September 2014), para 3-2b(1)(a) β21What is an OPSEC indicator?
Friendly detectable actions and open-source information that can be interpreted or pieced together by an adversary to derive critical information.
22OPSEC countermeasures can be used to:
Prevent the adversary from detecting an indicator, prevent the adversary from collecting an indicator, and/or prevent the adversary from correctly analyzing and interpreting critical information.
23True or False: OPSEC is a cycle that involves all members of the organization.
True. OPSEC is a continuous cycle and is the responsibility of every member of the organization, not just security personnel.
VERIFIED AGAINST THE SOURCE
βPersonnel must know the unit's or organization's OPSEC measures and practice them on a consistent and continuous basis.β
β AR 530-1, Operations Security (26 September 2014), para 3-2c(4) β24Discussing sensitive information in public, in person, or on the telephone: Could an adversary use this information as an indicator to obtain critical information?
Yes. Adversaries can overhear conversations in public places, intercept phone communications, and piece together fragments of information to develop intelligence.
25What is the OPSEC process?
A five-step process to identify, control, and protect critical information and analyze friendly actions and indicators that would allow adversaries or potential adversaries to identify and exploit vulnerabilities.
VERIFIED AGAINST THE SOURCE
βThe OPSEC process can apply to any plan, operation, program, project, or activity. It provides a framework for the systematic and continuous process necessary to identify and protect critical information.β
β AR 530-1, Operations Security (26 September 2014), para 3-2b(1) β26OPSEC's most important characteristic is that:
It is a process. OPSEC is not a collection of specific rules and instructions that can be applied to every operation, but rather a methodology that can be applied to any operation or activity.
VERIFIED AGAINST THE SOURCE
βThe OPSEC process can apply to any plan, operation, program, project, or activity. It provides a framework for the systematic and continuous process necessary to identify and protect critical information.β
β AR 530-1, Operations Security (26 September 2014), para 3-2b(1) β27True or False: A sudden change to a predictable routine is an example of an OPSEC countermeasure.
True. Varying routines and patterns makes it harder for adversaries to predict activities and exploit predictable behavior.
28An OPSEC threat is:
An adversary who has the intent and capability to collect, analyze, and exploit critical information about friendly operations.
29What is Step 2 (Analyze Threats) in the OPSEC process?
Identifying who the adversaries are, what their goals are, what intelligence collection capabilities they have, and what critical information they already possess or need.
VERIFIED AGAINST THE SOURCE
βAnalysis of threats. Identify the adversaries and how they can collect information.β
β AR 530-1, Operations Security (26 September 2014), para 3-2b(1)(b) β30What is Step 3 (Analyze Vulnerabilities) in the OPSEC process?
Examining each aspect of the planned operation to identify OPSEC indicators that could reveal critical information and determining which vulnerabilities an adversary could exploit.
VERIFIED AGAINST THE SOURCE
βAnalysis of vulnerabilities. Analyze what critical information friendly forces are exposing.β
β AR 530-1, Operations Security (26 September 2014), para 3-2b(1)(c) β31What is Step 4 (Assess Risk) in the OPSEC process?
Evaluating the risks by weighing the potential damage of a vulnerability being exploited against the cost of implementing countermeasures. Commanders decide which vulnerabilities require countermeasures.
VERIFIED AGAINST THE SOURCE
βAssessment of risk. Assess what protective measures should be implemented.β
β AR 530-1, Operations Security (26 September 2014), para 3-2b(1)(d) β32What is Step 5 (Apply Countermeasures) in the OPSEC process?
Selecting and implementing measures to eliminate vulnerabilities, indicators, and threats, or reduce them to an acceptable level. Examples include action control, counter-analysis, and diversions.
VERIFIED AGAINST THE SOURCE
βApplication of appropriate OPSEC measures that protect critical information.β
β AR 530-1, Operations Security (26 September 2014), para 3-2b(1)(e) β33Who is responsible for OPSEC?
Everyone. OPSEC is the responsibility of all personnel, including military members, DOD civilians, and contractors. Every individual must protect critical information in daily activities.
VERIFIED AGAINST THE SOURCE
βPersonnel must know the unit's or organization's OPSEC measures and practice them on a consistent and continuous basis.β
β AR 530-1, Operations Security (26 September 2014), para 3-2c(4) β34Why is social media a significant OPSEC concern?
Personnel can unknowingly post details about operations, schedules, unit movements, capabilities, and personal information that adversaries aggregate into actionable intelligence. Geotagged photos can reveal locations.
35What is the difference between OPSEC and traditional security?
Traditional security protects classified information through established standards. OPSEC protects unclassified but critical information and indicators that, when aggregated, could reveal classified or sensitive activities.
36What is OSINT (Open Source Intelligence)?
Intelligence collected from publicly available sources such as newspapers, social media, websites, public databases, and government reports. Adversaries use OSINT extensively because it is legal and low-risk.
37What does 'aggregation' or 'mosaic effect' mean in OPSEC?
Individually insignificant pieces of unclassified information, when combined and analyzed together, can reveal a classified or sensitive picture of operations. Adversaries assemble many small data points into comprehensive intelligence.
38What is an Essential Element of Friendly Information (EEFI)?
Key questions about friendly force capabilities, activities, and intentions that adversaries are likely to ask. EEFI are used to build the Critical Information List (CIL) and guide OPSEC analysis.
VERIFIED AGAINST THE SOURCE
βCritical information, formerly known as essential elements of friendly information, is defined as information important to the successful achievement of U.S. objectives and missions, or which may be of use to an adversary of the United States.β
β AR 530-1, Operations Security (26 September 2014), para 3-1b(1) β39What is a Critical Information List (CIL)?
A list of specific items of critical information approved by the commander that identifies the most important information to protect. It focuses the OPSEC process and is distributed to all personnel.
VERIFIED AGAINST THE SOURCE
βthe CIL must be disseminated or communicated to the lowest organizational level and personnelβ
β AR 530-1, Operations Security (26 September 2014), para 3-2c(3) β40What are examples of OPSEC countermeasures?
Action control (modifying routines), counter-analysis (misleading indicators), diversions, communication discipline, cover and deception, use of secure communications, and varying predictable patterns.
41How do adversaries use pattern analysis against friendly forces?
They monitor routine activities and identify predictable patterns such as communication surges, supply build-ups, personnel movements, and shift changes. Changes in patterns can signal upcoming operations.
42What OPSEC precautions should be taken with personal electronic devices?
Disable GPS/location services, turn off Bluetooth and Wi-Fi auto-connect, do not use personal devices in classified areas, use strong passwords and encryption, avoid connecting to unknown networks.
43How should family members practice OPSEC?
Avoid posting deployment dates, return dates, or specific locations on social media. Do not discuss operational details. Be cautious with strangers asking about their service member's duties or whereabouts.
44What is the origin of OPSEC?
OPSEC originated from a Vietnam War study called 'Purple Dragon' in 1966 after discovering the enemy was anticipating U.S. operations by exploiting unclassified indicators.
45What is the relationship between OPSEC and Information Operations (IO)?
OPSEC is one of the core capabilities of Information Operations. OPSEC supports IO by denying adversaries information needed to counter friendly operations.
46How does OPSEC apply during off-duty hours?
OPSEC applies 24/7. Conversations in public places, social media posts, phone calls, and daily routines can all reveal critical information. Personnel must be cautious even when not at work.
47What OPSEC risks do geotagged photos create?
GPS metadata (EXIF data) embedded in photos can reveal exact coordinates, potentially exposing military facility locations, personnel unit assignments, and facility layouts. The 2018 Strava incident revealed secret base locations.
48What Army regulation governs OPSEC?
AR 530-1, Operations Security, establishes OPSEC policy for the Army. DoD Manual 5205.02-M provides overarching DoD OPSEC guidance.
VERIFIED AGAINST THE SOURCE
βArmy Regulation 530-1 Operations and Signal Security Operations Securityβ
β AR 530-1, Operations Security (26 September 2014), cover β49What is an OPSEC assessment?
A formal evaluation of an organization's OPSEC posture to identify vulnerabilities in the protection of critical information. It examines policies, procedures, personnel practices, and security measures.
50What is 'action control' as an OPSEC countermeasure?
Eliminating or altering indicators by changing schedules, varying routes, modifying operational patterns, or timing activities to avoid adversary detection windows.
51A unit suddenly increases ammunition and fuel orders. What is the OPSEC concern?
This is an OPSEC indicator that could reveal an upcoming operation. Adversaries monitoring supply channels could infer the timing, scale, and potential location of the operation.
52During a deployment, family members post countdown timers for return. What OPSEC violation is this?
This reveals the exact timeline of the deployment and return date, which is critical information. Adversaries could use this to plan attacks timed to troop movements or identify windows of reduced security.
53What is an OPSEC 'red team'?
A group that thinks and acts like the adversary to identify vulnerabilities in friendly operations. They attempt to collect critical information using adversary methods and report findings to improve OPSEC posture.
54How does logistics information create OPSEC vulnerabilities?
Supply orders, shipping manifests, fuel deliveries, and equipment requests can reveal the timing, scale, and nature of operations. Adversaries actively target logistics channels for intelligence.
55What is the 'need-to-know' principle in OPSEC?
Restricting access to information to only those who require it for their duties. Limiting the number of people with access to critical information reduces potential sources of leakage and overall vulnerability.
56What is 'communication discipline' in OPSEC?
Controlling the content and methods of communications to prevent adversary interception. It includes using secure channels, limiting sensitive discussion over unsecured lines, and avoiding patterns that signal operations.
57You overhear a coworker discussing classified project details at an off-base restaurant. What should you do?
Immediately but discreetly ask the coworker to stop the conversation. After returning to a secure environment, remind them of OPSEC procedures and report the incident to your security manager or OPSEC officer.
58True or False: OPSEC only applies to classified information.
False. OPSEC primarily protects unclassified but critical information and indicators that, when aggregated, could reveal classified or sensitive operational details.
59What OPSEC considerations apply to video teleconferences (VTCs)?
Ensure classification level matches discussion, remove or cover visible sensitive materials, verify all participants are authorized, use encryption for sensitive topics, and do not record or distribute beyond need-to-know.
60How can phishing and social engineering compromise OPSEC?
Adversaries use phishing and social engineering to trick personnel into revealing critical information or credentials. Spear-phishing using personal details from social media can lead to network compromise and data theft.
61What is OPSEC's role in force protection?
OPSEC supports force protection by concealing vulnerabilities, movements, schedules, and security gaps that adversaries could exploit for attacks against personnel and facilities.
Know questions we're missing?
Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.
Study these as flashcards
Load all 61 questions into a free study set β flashcards, a practice test, and spaced repetition. No account.
Works on any PDF, doc or web page too β not just military training.
Most-searched questions from this course
Individual answer pages with the keyed answer verified across every CBT version we index.
Veteran? vetaid.ai β free VA benefits help.