Cyber Awareness Challenge 2022 (Incomplete)

25 July 2022
4.7 (114 reviews)
93 test answers

Unlock all answers in this set

Unlock answers (89)
question
*Spillage After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know that this project is classified. How should you respond?
answer
Attempt to change the subject to something non-work related, but neither confirm nor deny the article's authenticity
question
*Spillage Which of the following may help to prevent spillage?
answer
Label all files, removable media, and subject headers with appropriate classification markings.
question
*Spillage A user writes down details marked as Secret from a report stored on a classified system and uses those details to draft a briefing on an unclassified system without authorization. What is the best choice to describe what has occurred?
answer
Spillage because classified data was moved to a lower classification level system without authorization.
question
*Spillage What should you do when you are working on an unclassified system and receive an email with a classified attachment?
answer
Call your security point of contact immediately
question
*Spillage What should you do if a reporter asks you about potentially classified information on the web?
answer
Ask for information about the website, including the URL.
question
*Spillage .What should you do if a reporter asks you about potentially classified information on the web?
answer
Refer the reporter to your organization's public affairs office.
question
*Spillage What should you do if you suspect spillage has occurred?
answer
Immediately notify your security point of contact
question
*Spillage Which of the following is a good practice to prevent spillage?
answer
Be aware of classification markings and all handling caveats.
question
*Spillage Which of the following actions is appropriate after finding classified information on the Internet?
answer
Note any identifying information and the website's Uniform Resource Locator (URL)
question
**Classified Data When classified data is not in use, how can you protect it?
answer
Store classified data appropriately in a GSA-approved vault/container.
question
**Classified Data What is required for an individual to access classified data?
answer
Appropriate clearance, a signed and approved non-disclosure agreement, and need-to-know
question
**Classified Data Which classification level is given to information that could reasonably be expected to cause serious damage to national security?
answer
Secret
question
**Classified Data Which of the following is a good practice to protect classified information?
answer
Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material
question
**Classified Data Which of the following is true of protecting classified data?
answer
Classified material must be appropriately marked.
question
**Classified Data What level of damage can the unauthorized disclosure of information classified as Confidential reasonably be expected to cause?
answer
Damage to national security
question
**Classified Data Which of the following is true of telework?
answer
You must have permission from your organization.
question
**Classified Data Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?
answer
Secret
question
**Classified Data How should you protect a printed classified document when it is not in use?
answer
Store it in a General Services Administration (GSA)-approved vault or container
question
**Insider Threat Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague vacations at the beach every year, is married and a father of four, sometimes has poor work quality, and works well with his team.
answer
~0 indicator
question
**Insider Threat How many potential insider threat indicators does a coworker who often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?
answer
3 or more indicators
question
**Insider Threat Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague is playful and charming, consistently wins performance awards, and is occasionally aggressive in trying to access classified information.
answer
1 indicator
question
**Insider Threat What advantages do "insider threats" have over others that allows them to cause damage to their organizations more easily?
answer
Insiders are given a level of trust and have authorized access to Government information systems
question
**Insider Threat What type of activity or behavior should be reported as a potential insider threat?
answer
Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.
question
**Insider Threat Which of the following should be reported as a potential security incident?
answer
A coworker removes sensitive information without authorization
question
**Insider Threat Which scenario might indicate a reportable insider threat?
answer
A coworker uses a personal electronic device in a secure area where their use is prohibited.
question
**Insider Threat Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague often makes others uneasy with her persistent efforts to obtain information about classified project where she has no need-to-know, is vocal about her husband overspending on credit cards, and complains about anxiety and exhaustion.
answer
3 or more indicators
question
**Insider Threat Which type of behavior should you report as a potential insider threat?
answer
Hostility or anger toward the United States and its policies
question
**Insider Threat Which of the following is NOT considered a potential insider threat indicator?
answer
Treated mental health issues
question
**Social Networking When is the safest time to post details of your vacation activities on your social networking profile?
answer
After you have returned home following the vacation
question
**Social Networking What should you do if you receive a game application request that includes permission to access your friends, profile information, cookies, and sites visited?
answer
Decline the request
question
**Social Networking Which of the following information is a security risk when posted publicly on your social networking profile?
answer
Pictures of your pet Your birthday Your hobbies ~Your personal e-mail address
question
**Social Networking Which of the following is a security best practice when using social networking sites?
answer
Understanding and using the available privacy settings
question
**Social Networking When may you be subject to criminal, disciplinary, and/or administrative action due to online misconduct?
answer
If the online misconduct also occurs offline ~If you participate in or condone it at any time If you participate in it while using DoD information systems only If you participate in or condone it during work hours only
question
**Social Networking Which of the following is a security best practice when using social networking sites?
answer
Use only your personal contact information when establishing your account
question
**Social Networking Which of the following information is a security risk when posted publicly on your social networking profile?
answer
Your mother's maiden name
question
**Social Networking Your cousin posted a link to an article with an incendiary headline on social media. What action should you take?
answer
Research the source of the article to evaluate its credibility and reliability
question
**Social Networking Which of the following best describes the sources that contribute to your online identity?
answer
Data about you collected from all sites, apps, and devices that you use can be aggregated to form a profile of you.
question
**Social Networking As someone who works with classified information, what should you do if you are contacted by a foreign national seeking information on a research project?
answer
Inform your security point of contact
question
*Controlled Unclassified Information Which of the following is NOT an example of CUI?
answer
Press release data
question
*Controlled Unclassified Information Which of the following is NOT a correct way to protect CUI?
answer
CUI may be stored on any password-protected system.
question
**Physical Security What is a good practice for physical security?
answer
Challenge people without proper badges.
question
**Physical Security At which Cyberspace Protection Condition (CPCON) is the priority focus on critical functions only?
answer
CPCON 1
question
**Physical Security Which Cyber Protection Condition (CPCON) is the priority focus on critical and essential functions only?
answer
CPCON 2
question
**Physical Security Within a secure area, you see an individual who you do not know and is not wearing a visible badge. What should you do?
answer
Ask the individual for identification
question
**Identity Management Your DoD Common Access Card (CAC) has a Public Key Infrastructure (PKI) token approved for access to the NIPRNet. In which situation below are you permitted to use your PKI token?
answer
On a NIPRNet system while using it for a PKI-required task
question
**Identity Management Which of the following is the nest description of two-factor authentication?
answer
Something you possess, like a CAC, and something you know, like a PIN or password
question
**Identity management Which is NOT a sufficient way to protect your identity?
answer
Use a common password for all your system and application logons.
question
**Identity management What is the best way to protect your Common Access Card (CAC)?
answer
Maintain possession of it at all times.
question
**Identity management Which of the following is NOT a best practice to preserve the authenticity of your identity?
answer
Write your password down on a device that only you access (e.g., your smartphone)
question
**Identity management Which of the following is an example of two-factor authentication?
answer
Your password and a code you receive via text message
question
**Identity management Which of the following is an example of a strong password?
answer
eA1xy2!P
question
*Sensitive Compartmented Information What is Sensitive Compartmented Information (SCI)?
answer
A program that segregates various types of classified information into distinct compartments for added protection and dissemination or distribution control
question
*Sensitive Compartmented Information Which of the following best describes the compromise of Sensitive Compartmented Information (SCI)?
answer
A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.
question
*Sensitive Compartmented Information When should documents be marked within a Sensitive Compartmented Information Facility (SCIF)
answer
~All documents should be appropriately marked, regardless of format, sensitivity, or classification. Unclassified documents do not need to be marked as a SCIF. Only paper documents that are in open storage need to be marked.
question
*Sensitive Compartmented Information Which must be approved and signed by a cognizant Original Classification Authority (OCA)?
answer
Security Classification Guide (SCG)
question
*Sensitive Compartmented Information What must the dissemination of information regarding intelligence sources, methods, or activities follow?
answer
Directives issued by the Director of National Intelligence
question
*Sensitive Compartmented Information When is it appropriate to have your security badge visible?
answer
At all times when in the facility
question
*Sensitive Compartmented Information What should the owner of this printed SCI do differently?
answer
Retrieve classified documents promptly from printers
question
*Sensitive Compartmented Information What should the participants in this conversation involving SCI do differently?
answer
Physically assess that everyone within listening distance is cleared and has a need-to-know for the information being discussed
question
*Sensitive Compartmented Information When faxing Sensitive Compartmented Information (SCI), what actions should you take?
answer
Mark SCI documents appropriately and use an approved SCI fax machine
question
*Sensitive Compartmented Information What action should you take if you become aware that Sensitive Compartmented Information (SCI) has been compromised?
answer
Evaluate the causes of the compromise E-mail detailed information about the incident to your security point of contact (Wrong) Assess the amount of damage that could be caused by the compromise ~Contact your security point of contact to report the incident
question
*Sensitive Compartmented Information What guidance is available for marking Sensitive Compartmented Information (SCI)?
answer
Security Classification Guides (Wrong) ~Sensitive Compartmented Information Guides Original Classification Authority Your supervisor
question
**Removable Media in a SCIF What must users ensure when using removable media such as compact disk (CD)?
answer
It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number.
question
**Removable Media in a SCIF What portable electronic devices (PEDs) are allowed in a Sensitive Compartmented Information Facility (SCIF)?
answer
Government-owned PEDs when expressly authorized by your agency
question
**Removable Media in a SCIF What action should you take when using removable media in a Sensitive Compartmented Information Facility (SCIF)?
answer
Identify and disclose it with local Configuration/Change Management Control and Property Management authorities
question
*Malicious Code What are some examples of malicious code?
answer
Viruses, Trojan horses, or worms
question
*Malicious Code Which of the following is NOT a way that malicious code spreads?
answer
Legitimate software updates
question
*Malicious Code After visiting a website on your Government device, a popup appears on your screen. The popup asks if you want to run an application. Is this safe?
answer
No, you should only allow mobile code to run from your organization or your organization's trusted sites.
question
**Website Use While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?
answer
Since the URL does not start with "https," do not provide you credit card information.
question
**Website Use How should you respond to the theft of your identity?
answer
Report the crime to local law enforcement
question
**Website Use Which of the following statements is true of cookies?
answer
You should only accept cookies from reputable, trusted websites.
question
**Social Engineering Which is a best practice that can prevent viruses and other malicious code from being downloaded when checking your e-mail?
answer
Do not access website links, buttons, or graphics in e-mail
question
**Social Engineering What is TRUE of a phishing attack?
answer
Phishing can be an email with a hyperlink as bait.
question
**Social Engineering Which of the following is a way to protect against social engineering?
answer
Follow instructions given only by verified personnel.
question
**Social Engineering What is whaling?
answer
A type of phishing targeted at senior officials
question
**Social Engineering What action should you take with an e-mail from a friend containing a compressed Uniform Resource Locator (URL)?
answer
Investigate the link's actual destination using the preview feature
question
**Social Engineering How can you protect yourself from internet hoaxes?
answer
Use online sites to confirm or expose potential hoaxes
question
**Social Engineering Which may be a security issue with compressed Uniform Resource Locators (URLs)?
answer
They may be used to mask malicious intent.
question
**Social Engineering What is a common indicator of a phishing attempt?
answer
A threat of dire consequence
question
**Travel What is a best practice while traveling with mobile computing devices?
answer
Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.
question
**Travel Which of the following is true of traveling overseas with a mobile phone?
answer
It may be compromised as soon as you exit the plane.
question
**Travel What security risk does a public Wi-Fi connection pose?
answer
It may expose the connected device to malware.
question
**Travel Which of the following is a concern when using your Government-issued laptop in public?
answer
Others may be able to view your screen.
question
**Use of GFE When can you check personal e-mail on your Government-furnished equipment (GFE)?
answer
If allowed by organizational policy
question
**Use of GFE What is a critical consideration on using cloud-based file sharing and storage applications on your Government-furnished equipment (GFE)?
answer
Determine if the software or service is authorized
question
**Mobile Devices Which is a rule for removable media, other portable electronic devices (PEDs), and mobile computing devices to protect Government systems?
answer
Do not use any personally owned/non-organizational removable media on your organization's systems.
question
**Mobile Devices What can help to protect the data on your personal mobile device?
answer
Secure it to the same level as Government-issued systems
question
**Mobile Devices What should you do when going through an airport security checkpoint with a Government-issued mobile device?
answer
Maintain visual or physical control of the device
question
**Mobile Devices When can you use removable media on a Government system?
answer
When operationally necessary, owned by your organization, and approved by the appropriate authority
question
**Mobile Devices Which of the following is an example of removable media?
answer
Flash drive
question
**Home Computer Security How can you protect your information when using wireless technology?
answer
Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.
question
**Home Computer Security What should you consider when using a wireless keyboard with your home computer?
answer
Reviewing and configuring the available security features, including encryption
question
**Home Computer Security Which of the following is a best practice for securing your home computer?
answer
Create separate accounts for each user