DOD Cyber Awareness 2022 Knowledge Check

¡Supera tus tareas y exámenes ahora con Quizwiz!

What is a good practice for physical security?

Challenge people without proper badges.

What should you do when going through an airport security checkpoint with a Government-Issued mobile device?

Maintain visual or physical control of the device.

When faxing Sensitive Compartmented Information (SCI), what actions should you take?

Mark SCI documents appropriately and use an approved SCI fax machine

Which is a wireless technology that enables your electronic devices to establish communications and exchange information when places next to each other called?

Near field communication (NFC)

Is it acceptable to take a short break while a coworker monitors your computer while logged on with your CAC?

No. Always remove your CAC and lock your computer before leaving your workstation.

What is the best response if you find classified government data on the internet?

Note any identifying information, such as the website's URL, and report the situation to your security POC.

Your DoD Common Access Card (CAC) has a Public Key Infrastructure (PKI) token approved for access to the Non-Classified Internet Protocol Router Network NIPRNet. In which situation below are you permitted to use your PKI token?

On a NIPRNet system while using it for a PKI-required task.

What are some actions you can take to try to protect your identity?

Shred personal documents; never share passwords, and order a credit report annually.

What threat do insiders with authorized access to information or information Systems pose??

They may wittingly or unwittingly use their authorized access to perform actions that result in the loss or degradation of resources or capabilities.

What must you ensure before transmitting Personally Identifiable Information (PII) or Protected Health Information (PHI) via e-mail?

Transmissions must be between Government e-mail accounts and must be encrypted and digitally signed when possible.

Which is NOT a sufficient way to protect your identity?

Use a common password for all your system and application logons.

Which is an appropriate use of government e-mail?

Use a digital signature when sending attachments or hyperlinks.

Which of the following is a best practice for securing your home computer?

Use antivirus software and keep it up to date.

Which of the following is a best practice to protect information about you and your organization on social networking sites and applications?

Use only personal contact information when establishing personal social networking accounts, never use Government contact information.

Which of the following is true about unclassified data?

When unclassified data is aggregated, its classification level may rise.

When is the best time to post details of your vacation activities on your social networking website?

When your vacation is over, and you have returned home

Which of the following is NOT a best practice to preserve the authenticity of your identity?

Write your password down on a device that only you access (e.g., your smartphone)

What is the best example of Protected Health Information (PHI)?

Your health insurance explanation of benefits (EOB)

What is Sensitive Compartment Information (SCI)?

is a program that segregates various types of classified information into distinct compartments for added protection and dissemination or distribution control.

Which of the following is true?

mobile devices and applications can track Your location without your knowledge or consent

What is whaling?

A type of phishing targeted at high-level personnel such as senior officials.

What must you ensure if you work involves the use of different types of smart card security tokens?

Avoid a potential security violation by using the appropriate token for each system.

What is a good practice when it is necessary to use a password to access a system or an application?

Avoid using the same password between systems or applications.

What is a good practice to protect data on your home wireless systems?

Ensure that the wireless security features are properly configured.

What is an individual's Personally Identifiable Information (PII) or Protected Health Information (PHI) considered?

Sensitive information.

Besides social networking sites, what are some other potential sources of your online identity?

All of the above

What describes how Sensitive Compartmented Information is marked?

Approved Security Classification Guide (SCG)

What is an indication that malicious code is running on your system?

File corruption

What is a best practice to protect data on your mobile computing device?

Lock your device screen when not in use and require a password to reactivate.

What are some examples of removable media?

Memory sticks, flash drives, or external hard drives

Which of the following is NOT considered a potential insider threat indicator?

New interest in learning a foreign language

Which of the following is the best example of Personally Identifiable Information (PII)?

Passport number

What is a valid response when identity theft occurs?

Report the crime to local law enforcement.

Which is a risk associated with removable media?

Spillage of classified information.

What is a common method used in social engineering?

Telephone surveys

When using your Government-issued laptop in public environments, with which of the following should you be concerned?

The potential for unauthorized viewing of work-related information displayed on your screen.

What are the requirements to be granted access to SCI material?

The proper security clearance and indoctrination into the SCI program.

Which may be a security issue with compressed URLs?

There is no way to know where the link actually leads.

Which are examples of portable electronic devices (PEDs)?

Thumb drives, memory sticks, and optical disks

Which represents a security best practice when using social networking?

Understanding and using available privacy settings.

Which of the following is a security best practice when using social networking sites?

Understanding and using the available privacy settings.

What is a protection against internet hoaxes?

Use online sites to confirm or expose potential hoaxes.

What is a way to prevent the download of viruses and other malicious code when checking your e-mail?

View e-mail in plain text and don't view e-mail in Preview Pane.

While on vacation, a coworker calls and asks you to access a site to review and approve a document that is hosted behind a DoD Public Key Infrastructure (PKI) protected webpage. You do not have your government-issued laptop. What action should you take?

Wait until you have access to your government-issued laptop.

What information posted publicly on your personal social networking profile represents a security risk?

Your place of birth

Which of the following is NOT a correct way to protect CUI?

CUI may be stored on any password-protected system.

Which must be approved and signed by a cognizant Original Classification Authority (OCA)?

Security Classification Guide (SCG)

Based on the description that follows, how many potential insider threat indicator(s) are displayed? A coach lleague vacations at the beach every year, is marriednd apleasant to work with, but sometimes has poor work quality display?

0

How many potential insider threat indicators does a person who is married with two children, vacations at the beach every year, is pleasant to work with, but sometimes has poor work quality display?

0 indicators

Based on the description that follows, how many potential insider threat indicator(s) are displayed?A colleague saves money for an overseas vacation every year, is a single father, and occasionally consumes alcohol.(INSIDER THREAT)

0 indicators.

How many potential insider threat indicators does a person who is playful and charming, consistently win performance awards, but is occasionally aggressive in trying to access sensitive information?

1 Indicator

Based on the description that follows how many potential insider threat indicators are displayed? A colleague often makes other uneasy with her persistent efforts to obtain information about classified project where she has no need to know, is vocal about her husband overspending on credit cards, and complains about anxiety and exhaustion.

3 or more indicators

How many potential insider threat indicators does a coworker who often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?

3 or more indicators

Which is true of cookies?

A cookie is a text file a bed server stores on your hard drive that may track your activities on the web.

Which of the following should be reported as a potential security incident (in accordance with your Agency's insider threat policy)?

A coworker brings a personal electronic device into a prohibited area.

Which scenario might indicate a reportable insider threat security incident?

A coworker is observed using a personal electronic device in an area where their use is prohibited.

What is a possible indication of a malicious code attack in progress?

A pop-up window that flashes and warns that your computer is infected with a virus.

What describes a Sensitive Compartmented Information (SCI) program?

A program that segregates various type of classified information into distinct compartments for added protection and dissemination for distribution control.

When should documents be marked within a Sensitive Compartmented Information Facility (SCIF)?

All documents should be appropriately marked, regardless of format, sensitivity, or classification.

Under which circumstances may you be subject to criminal, disciplinary, and/or administrative action due to online misconduct?

Any time you participate in or condone misconduct, whether offline or online.

What is required for an individual to access classified data?

Appropriate clearance; signed and approved non-disclosure agreement; and need-to-know.

What should you do if a reporter asks you about potentially classified information on the web?

Ask for information about the website, including the URL.

After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know this project is classified. What should be your response?

Attempt to change the subject to something non-work related, but neither confirm nor deny the article's authenticity.

How can you protect your information when using wireless technology?

Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.

Which of the following is a good practice to aid in preventing spillage?

Be aware of classification markings and all handling caveats.

Which is true for protecting classified data?

Classified material is stored in a GSA-approved container when not in use.

Which of the following is true of protecting classified data?

Classified material must be appropriately marked.

Which of the following activities is an ethical use of Government-furnished equipment (GFE)?

Completing your expense report for your government travel.

What must users do when using removable media within a Sensitive Compartmented Information Facility (SCIF)?

Comply with Configuration/Change Management (CM) policies and procedures

Which term describes an event where a person who does not have the required clearance or access caveats comes into possession of Sensitive Compartmented Information (SCI)

Compromise

Upon connecting your Government-issued laptop to a public wireless connection, what should you immediately do?

Connect to the Government Virtual Private Network (VPN).

You receive an email from the Internal Revenue Service (IRS) demanding immediate payment of back taxes of which you were not aware. The email provides a website and a toll-free number where you can make payment. What action should you take?

Contact the IRS using their publicly available, official contact information.

What type of activity or behavior should be reported as a potential insider threat?

Coworker making consistent statements indicative of hostility or anger toward the United States and its policies.

Which of the following can an unauthorized disclosure of information classified as Confidential reasonably be expected to cause?

Damage to national security

Which of the following individuals can access classified data?

Darryl is managing a project that requires access to classified information. He has the appropriate clearance and a signed, approved non-disclosure agreement.

What is the best example of Personally Identifiable Information (PII)?

Date and place of birth

What action should you take if you receive a friend request on your social networking website from someone in Germany you met casually at a conference last year?

Decline the request.

What organization issues the directives concerning the dissemination of information regarding intelligence sources, methods, or activities?

Department of Defense.

What are some potential insider threat indicators?

Difficult life circumstances such as substance abuse; divided loyalty or allegiance to the U.S.; or extreme, persistent interpersonal difficulties.

Which of the following is an appropriate use of Government e-mail?

Digitally signing e-mails that contain attachments or hyperlinks.

What should you do if a commercial entity, such as a hotel reception desk, asks for Government identification so that they can make a photocopy?

Do not allow you Common Access Card (CAC) to be photocopied.

What should you do if an individual asks you to let her follow you into your controlled space, stating that she left her security badge at her desk?

Don't allow her access into secure areas and report suspicious activity.

Which of the following is a good practice to protect classified information?(CLASSIFIED DATA)

Don't assume open storage in a secure facility is permitted.

Which of the following practices reduces the chance of becoming a target by adversaries seeking insider information?

Don't talk about work outside your workspace unless it is a specifically designated public meeting environment and is controlled by the event planners.

Which of the following represents an ethical use of Your Government-furnished Equipment (GFE)?

E-mailing your co-workers to let them know you are taking a sick day.

What must you do when e-mailing Personally Identifiable Information (PII) or Protected Health Information (PHI)?

Encrypt the e-mail and use your Government e-mail account.

Which is a good practice to protect classified information?

Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material.

Which of the following must you do before using an unclassified laptop and peripherals in a collateral classified environment?

Ensure that any cameras, microphones, and Wi-Fi embedded in the laptop are physically disabled.

What is a possible effect of malicious code?

Files may be corrupted, erased, or compromised.

Which of the following may help to prevent spillage?

Follow procedures for transferring data to and from outside agency and non-Government networks

What type of unclassified material should always be marked with a special handling caveat?

For Official Use Only (FOUO)

What portable electronic devices (PEDs) are allowed in a Sensitive Compartmented Information Facility (SCIF)?

Government-owned PEDs when expressly authorized by your agency

What portable electronic devices (PEDs) are allowed in a Secure Compartmented Information Facility (SCIF)?

Government-owned PEDs, if expressly authorized by your agency.

What certificates are contained on the Common Access Card (CAC)?

Identification, encryption, and digital signature

What certificates are contained on the DoD Public Key Infrastructure (PKI) implemented by the Common Access Card (CAC)/Personal Identity Verification (PIV) card?

Identification, encryption, and digital signature

Under what circumstances could unclassified information be considered a threat to national security?

If aggregated, the information could become classified.

Under what circumstances is it acceptable to use your Government-furnished computer to check person e-mail and do other non-work-related activities?

If allowed by organization policy.

What is a proper response if spillage occurs?

Immediately notify your security POC.

As someone who works with classified information, what should you do if you are contacted by a foreign national seeking information on a research project?

Inform your security POC of all non-professional or non-routine contacts with foreign nations, including, but not limited to, joining each other's social media sites.

Which of the following terms refers to harm inflicted on national security through authorized access to information or information systems?

Insider Threat

What advantages do "insider threats" have over others that allows them to cause damage to their organizations more easily?

Insiders are given a level of trust and have authorized access to Government information systems.

Why might "insiders" be able to cause damage to their organizations more easily than others?

Insiders are given a level of trust and have authorized access to Government information systems.

Select the information on the data sheet that is protected health information (PHI).

Interview: Dr. Martin Stanisky Dr. Stanisky was Ms. Jones psychiatrist for three months.Dr. Stanisky reports that Ms. Jones's depression, which poses no national security risk.

What can malicious code do?

It can cause damage by corrupting files, erasing your hard drive, and/or allowing hackers access.

What is a common indicator of a phishing attempt?

It includes a threat of dire circumstances.

When is conducting a private money-making venture using your Government-furnished computer permitted?

It is never permitted.

Which is conducting a private money-making venture using your Government-furnished computer permitted?

It is never permitted.

What Security risk does a public Wi-Fi connection pose?

It may expose the connected device to malware.

Select the information on the data sheet that is personally identifiable information (PII) but not protected health information (PHI).

Jane Jones Social Security Number: 432-66-8321

Which of the following is NOT an example of CUI?

Press release data

You received an inquiry from a reporter about government information not cleared for public release. How should you respond?

Refer the reporter to your organization's public affairs office

How should you respond to the theft of your identity?

Report the crime to local law enforcement.

Your cousin posted a link to an article with an incendiary headline on Social media. What action should you take?

Research the source of the article to evaluate its credibility and reliability

What should you consider when using a wireless keyboard with your home computer?

Reviewing and configuring the available security features, including encryption

Which classification level is given to information that could reasonably be expected to cause serious damage to national security?

Secret

Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?

Secret

Which of the following helps protect data on your personal mobile devices?

Secure personal mobile devices to the same level as Government-issued systems.

What does Personally Identifiable Information (PII) include?

Social Security Number; date and place of birth; mother's maiden name

What is the best description of two-factor authentication?

Something you possess, like a CAC, and something you know, like a PIN or password.

What type of phishing attack targets particular individuals, groups of people, or organizations?

Spear phishing

A user writes down details from a report stored on a classified system marked as Secret and uses those details to draft an unclassified briefing on an unclassified system without authorization. What is the best choice to describe what has occurred?

Spillage because classified data was moved to a lower classification level system without authorization.

When classified data is not in use, how can you protect it?

Store classified data appropriately in a GSA-approved vault/container when not in use.

A colleague asks to leave a report containing Protected Health Information (PHI) on his desk overnight so he can continue working on it the next day. How do you respond?

Tell your colleague that it needs to be secured in a cabinet or container.

Which organization issues the directives concerning the dissemination of information regarding intelligence sources, methods, or activities?

The Director of National Intelligence


Conjuntos de estudio relacionados

Emergency Medicine Genitourinary

View Set

Bus 121: Employee Benefits Chapter 5

View Set

Microeconomics Unit 6 - Market Failures

View Set

International Environmental Politics Final

View Set

SAP Review -MAD, Mean, Median, Mode & Range

View Set