Annual DoD Cyber Awareness Challenge Exam

25 July 2022
4.7 (114 reviews)
93 test answers

Unlock all answers in this set

Unlock answers (89)
question
It is getting late on Friday. You are reviewing your employees annual self evaluation. Your comments are due on Monday. You can email your employees information to yourself so you can work on it this weekend and go home now. Which method would be the BEST way to send this information?
answer
Use the government email system so you can encrypt the information and open the email on your government issued laptop
question
What should you do if someone asks to use your government issued mobile device (phone/laptop..etc)?
answer
Decline to lend your phone / laptop
question
Where should you store PII / PHI?
answer
Information should be secured in a cabinet or container while not in use
question
Of the following, which is NOT an intelligence community mandate for passwords?
answer
Maximum password age of 45 days
question
Which of the following is NOT Government computer misuse?
answer
Checking work email
question
Which is NOT a telework guideline?
answer
Taking classified documents from your workspace
question
What should you do if someone forgets their access badge (physical access)?
answer
Alert the security office
question
What can you do to protect yourself against phishing?
answer
All of the above
question
What should you do to protect classified data?
answer
Answer 1 and 2 are correct
question
What action is recommended when somebody calls you to inquire about your work environment or specific account information?
answer
Ask them to verify their name and office number
question
If classified information were released, which classification level would result in "Exceptionally grave damage to national security"?
answer
Top Secret
question
Which of the following is NOT considered sensitive information?
answer
Sanitized information gathered from personnel records
question
Which of the following is NOT a criterion used to grant an individual access to classified data?
answer
Senior government personnel, military or civilian
question
Of the following, which is NOT a problem or concern of an Internet hoax?
answer
Directing you to a website that looks real
question
Media containing Privacy Act information, PII, and PHI is not required to be labeled.
answer
FALSE
question
Which of the following is NOT a home security best practice?
answer
Setting weekly time for virus scan when you are not on the computer and it is powered off
question
Which of the following best describes wireless technology?
answer
It is inherently not a secure technology
question
You are leaving the building where you work. What should you do?
answer
Remove your security badge
question
Which of the following is a good practice to avoid email viruses?
answer
Delete email from senders you do not know
question
What is considered a mobile computing device and therefore shouldn't be plugged in to your Government computer?
answer
All of the above
question
Which is NOT a way to protect removable media?
answer
As a best practice, labeling all classified removable media and considering all unlabeled removable media as unclassified
question
What is NOT Personally Identifiable Information (PII)?
answer
Hobby
question
Of the following, which is NOT a method to protect sensitive information?
answer
After work hours, storing sensitive information in unlocked containers, desks, or cabinets if security is not present
question
There are many travel tips for mobile computing. Which of the following is NOT one?
answer
When using a public device with a card reader, only use your DoD CAC to access unclassified information
question
The use of webmail is
answer
is only allowed if the organization permits it
question
What is considered ethical use of the Government email system?
answer
Distributing Company newsletter
question
Which of the following attacks target high ranking officials and executives?
answer
Whaling
question
What constitutes a strong password?
answer
all of the above
question
You are logged on to your unclassified computer and just received an encrypted email from a co-worker. The email has an attachment whose name contains the word "secret". What should you do?
answer
Contact your security POC right away
question
Which is a way to protect against phishing attacks?
answer
Look for digital certificates
question
You receive an email from a company you have an account with. The email states your account has been compromised and you are invited to click on the link in order to reset your password. What action should you take?
answer
Notify security
question
You are having lunch at a local restaurant outside the installation, and you find a cd labeled "favorite song". What should you do?
answer
Leave the cd where it is
question
How should you securely transport company information on a removable media?
answer
Encrypt the removable media
question
Should you always label your removable media?
answer
Yes
question
Which of the following is NOT Protected Health Information (PHI)?
answer
Medical care facility name
question
If authorized, what can be done on a work computer?
answer
Check personal email
question
Spear Phishing attacks commonly attempt to impersonate email from trusted entities. What security device is used in email to verify the identity of sender?
answer
Digital Signatures
question
What type of security is "part of your responsibility" and "placed above all else?"
answer
Physical
question
If your wireless device is improperly configured someone could gain control of the device? T/F
answer
TRUE
question
Which of the following is a proper way to secure your CAC/PIV?
answer
Remove and take it with you whenever you leave your workstation
question
What actions should you take prior to leaving the work environment and going to lunch?
answer
All of the above
question
P2P (Peer-to-Peer) software can do the following except:
answer
Allow attackers physical access to network assets
question
How can you guard yourself against Identity theft?
answer
All of the above
question
When leaving your work area, what is the first thing you should do?
answer
Remove your CAC/PIV
question
Using webmail may bypass built in security features.
answer
TRUE
question
Of the following, which is NOT a characteristic of a phishing attempt?
answer
Directing you to a web site that is real
question
Classified Information can only be accessed by individuals with
answer
All of the above
question
Which of the following definitions is true about disclosure of confidential information?
answer
Damage to national security
question
It is permissible to release unclassified information to the public prior to being cleared.
answer
False
question
Which of the following is NOT sensitive information?
answer
Unclassified information cleared for public release
question
What should you do to protect yourself while on social networks?
answer
Validate all friend requests through another source before confirming them
question
Which is NOT a method of protecting classified data?
answer
Assuming open storage is always authorized in a secure facility
question
What can you do to prevent spillage?
answer
all of the above
question
Which of the following makes Alex's personal information vulnerable to attacks by identity thieves?
answer
Carrying his Social Security Card with him
question
DoD employees are prohibited from using a DoD CAC in card-reader-enabled public device
answer
TRUE
question
Which of the following is an example of malicious code?
answer
Trojan horses
question
Which of the following is NOT PII?
answer
Mother's maiden name
question
Classified Information is
answer
Assigned a classification level by a supervisor
question
Maria is at home shopping for shoes on Amazon.com. Before long she has also purchased shoes from several other websites. What can be used to track Maria's web browsing habits?
answer
Cookies
question
Which is an untrue statement about unclassified data?
answer
If aggregated, the classification of the information may not be changed
question
A medium secure password has at least 15 characters and one of the following.
answer
Special character
question
PII, PHI, and financial information is classified as what type of information?
answer
Sensitive
question
The CAC/PIV is a controlled item and contains certificates for:
answer
All of the above
question
An individual who has attempted to access sensitive information without need-to-know and has made unusual requests for sensitive information is displaying indicators of what?
answer
Potential Insider Threat
question
Which of the following is NOT a social engineering tip?
answer
Following instructions from verified personnel
question
Bob, a coworker, has been going through a divorce, has financial difficulties and is displaying hostile behavior. How many potential insider threat indicators is Bob displaying?
answer
3
question
You are working at your unclassified system and receive an email from a coworker containing a classified attachment. What should you do?
answer
Alert your security POC
question
You check your bank statement and see several debits you did not authorize. You believe that you are a victim of identity theft. Which of the following should you do immediately?
answer
Monitor credit card statements for unauthorized purchases
question
Thumb drives, memory sticks, and flash drives are examples of
answer
Removable media
question
What information relates to the physical or mental health of an individual?
answer
PHI
question
What should be done if you find classified Government Data/Information Not Cleared for Public Release on the Internet?
answer
Make note of any identifying information and the website URL and report it to your security office
question
All https sites are legitimate and there is no risk to entering your personal info online.
answer
FALSE
question
When using a fax machine to send sensitive information, the sender should do which of the following?
answer
Contact the recipient to confirm receipt
question
What should be done to protect against insider threats?
answer
Report any suspicious behavior
question
Which of the following is NOT a potential insider threat?
answer
Member of a religion or faith
question
Of the following, which is NOT a security awareness tip?
answer
Remove security badge as you enter a restaurant or retail establishment
question
ActiveX is a type of this?
answer
Mobile code
question
Which of the following is NOT a security best practice when saving cookies to a hard drive?
answer
Looking for "https" in the URL. All https sites are legitimate.
question
Which is NOT a requirement for telework?
answer
Telework is only authorized for unclassified and confidential information
question
Someone calls from an unknown number and says they are from IT and need some information about your computer. What should you do?
answer
Request the user's full name and phone number
question
Which is NOT a wireless security practice?
answer
Turning off computer when not in use
question
Malicious code can do the following except?
answer
Make your computer more secure
question
What type of data must be handled and stored properly based on classification markings and handling caveats?
answer
Classified
question
What information should you avoid posting on social networking sites?
answer
All of the above
question
A coworker has left an unknown CD on your desk. What should you do?
answer
Put the CD in the trash
question
Which of the following is NOT a DoD special requirement for tokens?
answer
Using NIPRNet tokens on systems of higher classification level
question
UNCLASSIFIED is a designation to mark information that does not have potential to damage national security.
answer
TRUE
question
You receive a call on your work phone and you're asked to participate in a phone survey. As part of the survey the caller asks for birth date and address. What type of attack might this be?
answer
Social Engineering
question
"Spillage" occurs when
answer
Personal information is inadvertently posted at a website
question
What should be done to sensitive data on laptops and other mobile computing devices?
answer
Encrypt the sensitive data
question
Which of the following should be done to keep your home computer secure?
answer
All of the above
question
How are Trojan horses, worms, and malicious scripts spread?
answer
By email attachments
question
The following practices help prevent viruses and the downloading of malicious code except.
answer
Scan external files from only unverifiable sources before uploading to computer