TARP Answers — Threat Awareness and Reporting Program
TARP answers for Threat Awareness and Reporting Program study: search 47 questions on counterintelligence reporting and elicitation, or review them with free flashcards.
Threat Awareness and Reporting Program — counterintelligence reporting requirements (AR 381-12 / CI116)
Studying for this with your unit? Send it to them.
01What does TARP stand for?
The expansion is historically correct, but the PROGRAM NO LONGER CARRIES THIS NAME. Effective 13 July 2025, AR 381-12 (13 June 2025) renamed it from the Threat Awareness and Reporting Program (TARP) to Counterintelligence Awareness and Reporting (CIAR). "TARP" appears nowhere in the current regulation. Soldiers searching "TARP" are looking for what is now called CIAR.
VERIFIED AGAINST THE SOURCE
“Changes the title of this regulation from Threat Awareness and Reporting Program to Counterintelligence Awareness and Reporting (cover).”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), Summary of Change ↗02What Army regulation governs TARP?
AR 381-12, Threat Awareness and Reporting Program.
VERIFIED AGAINST THE SOURCE
“This regulation supersedes AR 381-12, dated 1 June 2016.”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), cover ↗03What is the purpose of TARP?
To educate and train all Department of the Army (DA) personnel to recognize and report threats from espionage, international terrorism, sabotage, subversion, and other intelligence-related activities directed against the U.S. Army.
VERIFIED AGAINST THE SOURCE
“This regulation implements DoDD 5240.06, establishes policy, assigns responsibilities, and establishes requirements for the Army's Counterintelligence Awareness and Reporting (CIAR) program; it establishes the reporting responsibilities for DA personnel and the potential punitive actions for those who violate reporting responsibilities.”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), para 1-1 ↗04Who is required to complete annual TARP training?
All DA personnel including active duty soldiers, Army National Guard, Army Reserve, DA civilians, and all supporting contractors with access to Army facilities or information.
05What is the CDSE course that satisfies the TARP annual training requirement?
Course ID refinement: the current AR 381-12 (13 June 2025), para 3-2b names "Counterintelligence Awareness and Reporting for DoD Employees" - CI116.16 (not CI116), hosted at cdse.edu.
VERIFIED AGAINST THE SOURCE
“DA personnel will complete "Counterintelligence Awareness and Reporting for DoD Employees" - CI116.16, located at https://www.cdse.edu/, to satisfy Army annual training requirements.”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), para 3-2b ↗06What is an insider threat?
A person with authorized access to U.S. government resources who uses that access to harm the security of the United States. This includes espionage, terrorism, unauthorized disclosure of classified information, or actions that could threaten the health and safety of the workforce.
07What are the five threat categories that must be reported under TARP?
Espionage, international terrorism, sabotage, subversion, and theft or illegal diversion of military technology.
08What is espionage?
The act of obtaining, delivering, transmitting, communicating, or receiving information about the national defense with intent or reason to believe that it will be used to the injury of the United States or to the advantage of a foreign nation.
VERIFIED AGAINST THE SOURCE
“The act of obtaining, delivering, transmitting, communicating, or receiving information in respect to the national defense with an intent or reason to believe that the information may be used to the injury of the United States or to the advantage of any foreign nation.”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), Glossary ↗09What is elicitation?
A technique used by foreign intelligence entities to subtly extract information from people during what appears to be normal and innocent conversation. The target may not even realize they are being pumped for information.
10What are common elicitation techniques?
Flattery, false statements to provoke a correction, appealing to ego, sharing false or sensitive information to encourage reciprocity, deliberate provocation, feigning ignorance, and asking leading questions in a casual setting.
11What is a honeypot or honey trap?
A counterintelligence technique where a person uses romantic or sexual relationships to compromise an intelligence target and extract classified information or recruit them as an agent.
12How quickly must suspicious activity be reported?
As soon as possible, typically within 24 hours of the observation or event.
VERIFIED AGAINST THE SOURCE
“DA personnel will report suspicious activity referenced in this publication to an ACI office within 24 hours after learning of the incident.”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), para 6-2a ↗13Who should you report suspicious contacts or activities to?
Your chain of command, security manager, or Military Intelligence/Counterintelligence (CI) personnel. You can also report through the iSalute portal or by calling the Army CI hotline.
VERIFIED AGAINST THE SOURCE
“DA personnel will report suspicious activity referenced in this publication to an ACI office within 24 hours after learning of the incident.”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), para 6-2a ↗14What is the iSalute reporting system?
A web-based system that allows Army personnel to submit online reports of suspicious activity, foreign contacts, and other counterintelligence-related information.
VERIFIED AGAINST THE SOURCE
“The iSalute online CI incident tipline located at https://www.usainscom.army.mil/”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), para 6-2b ↗15What types of suspicious contacts must be reported?
Any contact with a known or suspected foreign intelligence officer, any request for classified or sensitive information by unauthorized persons, attempts to recruit you as a source, suspicious approaches at conferences or trade shows, and any unexplained contact with foreign nationals that seems intelligence-related.
VERIFIED AGAINST THE SOURCE
“Contact with an individual who is known or suspected of being associated with a foreign intelligence or security organization.”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), Table 4-1 ↗16What foreign travel must be reported under TARP?
All personal foreign travel must be reported to your security manager or command. This includes travel to countries that are known intelligence threats, and any suspicious contacts during foreign travel.
17What are indicators that you may be a target of foreign intelligence?
Persistent contact by a foreign national who is overly interested in your work, unexpected invitations to social events by foreign nationals, unsolicited gifts or offers of financial assistance, requests to provide information outside official channels, and being approached at conferences or professional events.
18How do foreign intelligence services use social media for targeting?
They create fake profiles to establish relationships with military and government personnel, use social engineering to extract information, monitor open-source postings about military operations or capabilities, and identify potential recruitment targets based on vulnerabilities revealed online.
19What is the difference between a 'foreign intelligence entity' and a 'foreign intelligence service'?
A foreign intelligence service (FIS) is a government-run intelligence organization. A foreign intelligence entity (FIE) is broader and includes any foreign government or non-government entity that engages in intelligence activities directed against the United States, including terrorist organizations and foreign corporations.
20What should you do if you are approached by someone you suspect is a foreign intelligence officer?
Do not provide any information. End the conversation politely. Report the contact immediately through proper channels. Document as many details as possible including the person's description, what was discussed, and any business cards or contact information provided.
21What is subversion?
Actions designed to undermine the military, economic, psychological, or political strength of a nation. It includes attempts to influence military personnel to violate their duties or act against the interests of the United States.
VERIFIED AGAINST THE SOURCE
“Advocating or encouraging military, civilian, or contractor personnel within the DoD or United States Coast Guard to violate the laws of the United States”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), Glossary ↗22What is sabotage in the TARP context?
An act or acts with intent to injure, interfere with, or obstruct the national defense by willfully destroying, damaging, or obstructing national defense material, premises, or utilities.
VERIFIED AGAINST THE SOURCE
“Damaging, manipulating, or defacing part of a facility/infrastructure or protected site to injure or interfere with, or obstruct, the national defense by willfully injuring, destroying, or attempting to destroy any national defense or war material, premises, or utilities, to include human and natural resources.”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), Glossary ↗23What is the significance of 'need to know' in counterintelligence?
Even if a person has a security clearance, they should only be given access to classified information that they need for the performance of their official duties. Unauthorized sharing of classified information — even with cleared personnel — can constitute a security violation.
24What are indicators of a potential insider threat?
Working unusual hours without authorization, unexplained affluence, interest in matters outside job responsibilities, unauthorized removal of classified material, excessive copying of sensitive documents, attempts to bypass security procedures, and significant changes in behavior or lifestyle.
25What is the Army CI hotline?
A phone line available for reporting suspicious activity and potential counterintelligence threats. Personnel can call to report concerns anonymously if needed.
VERIFIED AGAINST THE SOURCE
“The 1-800-CALL-SPY tipline (1-800-225-5779) if located in the United States.”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), para 6-2b(2) ↗26What are the consequences of failing to report under TARP?
Failure to report can result in UCMJ action for military personnel, disciplinary action for civilians, and potential criminal prosecution. It may also enable foreign intelligence activities that harm national security.
VERIFIED AGAINST THE SOURCE
“may be subject to judicial and/or administrative action”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), Table 4-1 note ↗27What is 'technology transfer' in the TARP context?
The unauthorized or illegal transfer of sensitive or classified military technology, equipment, data, or know-how to a foreign entity, whether by espionage, theft, or circumvention of export controls.
28What methods do foreign intelligence entities use to collect information?
Human intelligence (HUMINT) through agents and elicitation, signals intelligence (SIGINT) through electronic eavesdropping, cyber operations targeting networks and systems, open source intelligence (OSINT) from public information, and technical surveillance.
29What is a 'false flag' recruitment approach?
When a foreign intelligence officer misrepresents their true affiliation or nationality during a recruitment attempt — for example, claiming to work for an allied nation's intelligence service when they actually work for a hostile nation.
30What should you report about contacts at international conferences?
Any unusual or persistent interest in your work, any requests for information that seems beyond normal professional exchange, any offers of gifts, travel, or hospitality that seem excessive, and any attempts to establish personal relationships that feel manipulative.
31What is the role of counterintelligence (CI) in the Army?
CI identifies, deceives, exploits, disrupts, or neutralizes foreign intelligence entities, insider threats, and terrorist organizations that threaten the U.S. Army, DoD, or national security.
32What is Operations Security (OPSEC) and how does it relate to TARP?
OPSEC is the process of identifying critical information, analyzing threats and vulnerabilities, and applying countermeasures to deny adversaries information about friendly activities. TARP awareness supports OPSEC by helping personnel recognize when foreign entities are attempting to collect such information.
33What are 'indicators' in counterintelligence?
Observable actions, conditions, or information that suggest foreign intelligence activity, insider threat behavior, or terrorist planning. Recognizing indicators is the first step in threat reporting.
34Can a foreign intelligence entity target unclassified information?
Yes. Foreign intelligence entities actively collect unclassified information including organizational charts, personnel directories, training schedules, and technical manuals. Aggregation of unclassified information can reveal classified capabilities.
35What is the 'mosaic effect' in intelligence?
When individually insignificant pieces of unclassified information are combined to reveal classified or sensitive information about military capabilities, operations, or vulnerabilities.
36What are cyber threats relevant to TARP?
Phishing emails designed to steal credentials, social engineering attacks, malware targeting military networks, unauthorized access to information systems, and data exfiltration by insiders or foreign actors.
37What should you do if you receive a suspicious email that may be a phishing attempt?
Do not click any links or open attachments. Report it to your Information Assurance (IA) officer or security manager. Do not forward it to others. Document the sender's information.
38What is the relationship between TARP and the Insider Threat Program?
TARP addresses external threats (foreign intelligence, terrorism) while the Insider Threat Program focuses on threats from within the organization. Both require awareness and reporting, and an insider can be recruited by an external foreign intelligence entity.
39What personal vulnerabilities do foreign intelligence services exploit?
Financial difficulties, substance abuse, relationship problems, disgruntlement with employer, ego/desire for recognition, ideology, and susceptibility to blackmail or compromise.
40The acronym MICE describes motivations for espionage. What does it stand for?
Money, Ideology, Compromise (or Coercion), and Ego.
41What is the penalty for espionage under U.S. law?
Under 18 U.S.C. 794, espionage can be punished by death or imprisonment for any term of years, including life.
42When did TARP replace the SAEDA program?
TARP replaced Subversion and Espionage Directed Against the U.S. Army (SAEDA) to expand the scope of threat awareness beyond just espionage to include terrorism, sabotage, subversion, and technology theft.
43What is the authorized CBT alternative when live TARP training is not possible?
OUTDATED. The current AR 381-12 (13 June 2025) contains no reference to ALMS and does not designate an "only authorized alternative." Para 3-2b now directs: DA personnel will complete "Counterintelligence Awareness and Reporting for DoD Employees" - CI116.16, located at https://www.cdse.edu/, to satisfy Army annual training requirements. The 2025 revision expressly removed the train-the-trainer certification and standard briefing tool requirements.
VERIFIED AGAINST THE SOURCE
“DA personnel will complete "Counterintelligence Awareness and Reporting for DoD Employees" - CI116.16, located at https://www.cdse.edu/, to satisfy Army annual training requirements.”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), para 3-2b ↗44How often must TARP training be completed?
Within 30 days of assignment and annually (every 12 months) thereafter.
VERIFIED AGAINST THE SOURCE
“and every 12 months thereafter pursuant to DoDD 5240.06”
— AR 381-12, Counterintelligence Awareness and Reporting (13 June 2025), para 3-2a ↗45Pat works for the DOD as a counterintelligence analyst. Recently, he was invited by a foreign contact to attend a conference in the contact's country. He declined but met the foreign contact on a recent trip overseas and they became romantically involved. In this example, what was an indicator of foreign intelligence entity targeting?
Being invited to attend a conference in a foreign country; Becoming romantically involved with a foreign national
46What are some examples of foreign intelligence entity threats?
Hackers; State-sponsored computer experts of foreign nations; Foreign Corporations
47During which phase of the recruitment process does the foreign intelligence officer look for exploitable weaknesses, such as alcohol abuse, drug use, extramarital affairs, gambling, or other financial problems?
Assessing
Know questions we're missing?
Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.
Study these as flashcards
Load all 47 questions into a free study set — flashcards, a practice test, and spaced repetition. No account.
Works on any PDF, doc or web page too — not just military training.
Most-searched questions from this course
Individual answer pages with the keyed answer verified across every CBT version we index.
Veteran? vetaid.ai — free VA benefits help.