Cyber Awareness Challenge 2024
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague is playful and charming, consistently wins performance awards, and is occasionally aggressive in trying to access classified information.
1 indicator
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague often makes others uneasy with her persistent efforts to obtain information about classified project where she has no need-to-know, is vocal about her husband overspending on credit cards, and complains about anxiety and exhaustion.
3 or more indicators
How many potential insider threat indicators does a coworker who often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?
3 or more indicators
what is a common indicator of a phishing attempt?
A claim that you must update or validate information.
Which of the following should be reported as a potential security incident?
A coworker removes sensitive information without authorization
Which scenario might indicate a reportable insider threat?
A coworker uses a personal electronic device in a secure area where their use is prohibited.
Which of the following best describes the compromise of Sensitive Compartmented Information (SCI)?
A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.
which of the following is true of traveling overseas with a mobile phone?
A personally owned device approved under Bring Your Own Approved Device
Which of the following is true of traveling overseas with a mobile phone?
A personally owned device approved under Bring Your Own Approved Device (BYOAD) policy must be unenrolled while out of the country.
What is Sensitive Compartmented Information (SCI)?
A program that segregates various types of classified information into distinct compartments for added protection and dissemination or distribution control
What is a common indicator of a phishing attempt?
A threat of dire consequence
What is whaling?
A type of phishing targeted at senior officials
Which of the following is NOT a risk associated with near field communication (NFC)?
Additional data charges
Which of the following statements is true?
Adversaries exploit social networking sites to disseminate fake news
When is the safest time to post details of your vacation activities on your social networking profile?
After you have returned home following the vacation
What is the response to an incident such as opening an uncontrolled DVD on a computer in a SCIF?
All of these
What is required for an individual to access classified data?
Appropriate clearance, a signed and approved non-disclosure agreement, and need-to-know
What should you do if a reporter asks you about potentially classified information on the web?
Ask for information about the website, including the URL.
Within a secure area, you see an individual who you do not know and is not wearing a visible badge. What should you do?
Ask the individual for identification
When is it appropriate to have your security badge visible?
At all times when in the facility
After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know that this project is classified. How should you respond?
Attempt to change the subject to something non-work related, but neither confirm nor deny the article's authenticity
Which of the following is a reportable insider threat activity?
Attempting to access sensitive information without need-to-know.
Which of the following is a best practice for using removable media?
Avoid inserting removable media with unknown content into your computer
How can you protect your information when using wireless technology?
Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.
Which of the following is a good practice to prevent spillage?
Be aware of classification markings and all handling caveats.
At which Cyberspace Protection Condition (CPCON) is the priority focus on critical functions only?
CPCON 1
Which Cyber Protection Condition (CPCON) is the priority focus on critical and essential functions only?
CPCON 2
Which of the following is NOT a correct way to protect CUI?
CUI may be stored on any password-protected system.
Which of the following is true of Controlled Unclassified Information (CUI)?
CUI must be handled using safeguarding or dissemination controls
What should you do when you are working on an unclassified system and receive an email with a classified attachment?
Call your security point of contact immediately
What is a good practice for physical security?
Challenge people without proper badges.
Which of the following is an allowed use of Government-furnished equipment (GFE)?
Checking personal em-mail If allowed by organizational policy
Which of the following is true of protecting classified data?
Classified material must be appropriately marked.
What type of activity or behavior should be reported as a potential insider threat?
Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.
Which of the following is a best practice for securing your home computer?
Create separate accounts for each user
What level of damage can the unauthorized disclosure of information classified as Confidential reasonably be expected to cause?
Damage to national security
Which of the following is NOT a potential consequence of using removable media unsafely in a Sensitive Compartmented Information Facility (SCIF)?
Damage to the removable media
Which of the following best describes the sources that contribute to your online identity?
Data about you collected from all sites, apps, and devices that you use can be aggregated to form a profile of you.
What should you do if you receive a game application request that includes permission to access your friends, profile information, cookies, and sites visited?
Decline the request
You receive a phone call offering you a $50 gift care if your participate in a survey. Which course of action should you take?
Decline to participate. This may be a social engineering attempt.
What is a critical consideration on using cloud-based file sharing and storage applications on your Government-furnished equipment (GFE)?
Determine if the software or service is authorized
Which of the following is true?
Digitally signed e-mails are more secure.
What must the dissemination of information regarding intelligence sources, methods, or activities follow?
Directives issued by the Director of National Intelligence
Which is a best practice that can prevent viruses and other malicious code from being downloaded when checking your e-mail?
Do not access website links, buttons, or graphics in e-mail
Which is a rule for removable media, other portable electronic devices (PEDs), and mobile computing devices to protect Government systems?
Do not use any personally owned/non-organizational removable media on your organization's systems.
Which of the following is a good practice to protect classified information?
Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material
How can you protect your organization on social networking sites?
Ensure there are no identifiable landmarks visible in any photos taken in a work setting that you post
What action should you take if you become aware that Sensitive Compartmented Information (SCI) has been compromised?
Evaluate the causes of the compromise E-mail detailed information about the incident to your security point of contact (Wrong) Assess the amount of damage that could be caused by the compromise ~Contact your security point of contact to report the incident
Which of the following is NOT a type of malicious code?
Executables
Which of the following is an example of removable media?
External hard drive
Which of the following is an example of removable media?
Flash drive
Which of the following is a way to protect against social engineering?
Follow instructions given only by verified personnel.
What portable electronic devices (PEDs) are allowed in a Sensitive Compartmented Information Facility (SCIF)?
Government-owned PEDs when expressly authorized by your agency
Which type of behavior should you report as a potential insider threat?
Hostility or anger toward the United States and its policies
What action should you take when using removable media in a Sensitive Compartmented Information Facility (SCIF)?
Identify and disclose it with local Configuration/Change Management Control and Property Management authorities
When may you be subject to criminal, disciplinary, and/or administrative action due to online misconduct?
If the online misconduct also occurs offline ~If you participate in or condone it at any time If you participate in it while using DoD information systems only If you participate in or condone it during work hours only
When may you be subject to criminal, disciplinary, and/or administrative action due to online harassment, bullying, stalking, hazing, discrimination, or retaliation?
If you participate in or condone it at any time
What should you do if you suspect spillage has occurred?
Immediately notify your security point of contact
how should you secure your home wireless network for teleworking?
Implement Wi-Fi Protected Access 2 (WPA2) Personal encryption at
How should you secure your home wireless network for teleworking?
Implement Wi-Fi Protected Access 2 (WPA2) Personal encryption at a minimum
As someone who works with classified information, what should you do if you are contacted by a foreign national seeking information on a research project?
Inform your security point of contact
What advantages do "insider threats" have over others that allows them to cause damage to their organizations more easily?
Insiders are given a level of trust and have authorized access to Government information systems
What action should you take with an e-mail from a friend containing a compressed Uniform Resource Locator (URL)?
Investigate the link's actual destination using the preview feature
Which of the following is true of the Common Access Card (CAC)?
It contains certificates for identification, encryption, and digital signature
What must users ensure when using removable media such as compact disk (CD)?
It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number.
which of the following is true of unclassified information
It is releasable to the public without clearance.
Which of the following is true of traveling overseas with a mobile phone?
It may be compromised as soon as you exit the plane.
What security risk does a public Wi-Fi connection pose?
It may expose the connected device to malware.
Which of the following is true of using a DoD Public Key Infrastructure (PKI) token?
It should only be in a system while actively using it for a PKI-required task
Which of the following may help to prevent spillage?
Label all files, removable media, and subject headers with appropriate classification markings.
Which of the following is NOT a way that malicious code spreads?
Legitimate software updates
What is the best way to protect your Common Access Card (CAC)?
Maintain possession of it at all times.
What is a best practice while traveling with mobile computing devices?
Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.
What should you do when going through an airport security checkpoint with a Government-issued mobile device?
Maintain visual or physical control of the device
Which of the following statements is true?
Many apps and smart devices collect and share your personal information and contribute to your online identity.
When faxing Sensitive Compartmented Information (SCI), what actions should you take?
Mark SCI documents appropriately and use an approved SCI fax machine
After visiting a website on your Government device, a popup appears on your screen. The popup asks if you want to run an application. Is this safe?
No, you should only allow mobile code to run from your organization or your organization's trusted sites.
Which of the following actions is appropriate after finding classified information on the Internet?
Note any identifying information and the website's Uniform Resource Locator (URL)
Your DoD Common Access Card (CAC) has a Public Key Infrastructure (PKI) token approved for access to the NIPRNet. In which situation below are you permitted to use your PKI token?
On a NIPRNet system while using it for a PKI-required task
Which of the following is true of portable electronic devices (PEDs) in a Sensitive Compartmented Information Facility (SCIF)?
Only expressly authorized government-owned PEDs
Which of the following is a security practice for protecting Personally Identifiable Information (PII)?
Only use Government-furnished or Government-approved equipment to process PII
Which of the following is a concern when using your Government-issued laptop in public?
Others may be able to view your screen.
which of the following is true of sensitive compartmented information facilities (SCIFs)?
Personnel with access to a SCIF have a need-to-know for all information processed with the SCIF
What is TRUE of a phishing attack?
Phishing can be an email with a hyperlink as bait.
What should the participants in this conversation involving SCI do differently?
Physically assess that everyone within listening distance is cleared and has a need-to-know for the information being discussed
Which of the following information is a security risk when posted publicly on your social networking profile?
Pictures of your pet Your birthday Your hobbies ~Your personal e-mail address
Which of the following is NOT an example of CUI?
Press release data
What function do Insider Threat Programs aim to fulfill?
Proactively identify potential threats and formulate holistic mitigation responses
What should you do if a reporter asks you about potentially classified information on the web?
Refer the reporter to your organization's public affairs office.
Which of the following is a best practice for physical security?
Report suspicious activity
How should you respond to the theft of your identity?
Report the crime to local law enforcement
Your cousin posted a link to an article with an incendiary headline on social media. What action should you take?
Research the source of the article to evaluate its credibility and reliability
A trusted friend in your social network posts a link to vaccine information on a website unknown to you. What actions should you take?
Research the source to evaluate its credibility and reliability.
What should the owner of this printed SCI do differently?
Retrieve classified documents promptly from printers
What should you consider when using a wireless keyboard with your home computer?
Reviewing and configuring the available security features, including encryption
which of the following is a way to prevent the spread of malicious code?
Scan all external files before uploading to your computer
Which classification level is given to information that could reasonably be expected to cause serious damage to national security?
Secret
Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?
Secret
What can help to protect the data on your personal mobile device?
Secure it to the same level as Government-issued systems
Which must be approved and signed by a cognizant Original Classification Authority (OCA)?
Security Classification Guide (SCG)
What guidance is available for marking Sensitive Compartmented Information (SCI)?
Security Classification Guides (Wrong) ~Sensitive Compartmented Information Guides Original Classification Authority Your supervisor
While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?
Since the URL does not start with "https," do not provide you credit card information.
Which of the following is the nest description of two-factor authentication?
Something you possess, like a CAC, and something you know, like a PIN or password
A user writes down details marked as Secret from a report stored on a classified system and uses those details to draft a briefing on an unclassified system without authorization. What is the best choice to describe what has occurred?
Spillage because classified data was moved to a lower classification level system without authorization.
When classified data is not in use, how can you protect it?
Store classified data appropriately in a GSA-approved vault/container.
How should you protect a printed classified document when it is not in use?
Store it in a General Services Administration (GSA)-approved vault or container
Which of the following is not an example of Personally Identifiable Information (PII)?
The name of your high school
Which of the following is true of internet hoaxes?
They can be part of a distributed denial of service (DDoS) attack.
Which of the following is true of removable media and portable electronic devices (PEDs)?
They have similar features, and the same rules and protections apply
What security issue is associated with compressed Uniform Resource Locators (URLs)?
They may be used to mask malicious intent.
Which may be a security issue with compressed Uniform Resource Locators (URLs)?
They may be used to mask malicious intent.
which of the following is true of security classification guides?
They provide guidance on reasons for and duration of classification of information.
Which of the following is NOT considered a potential insider threat indicator?
Treated mental health issues
Which of the following is NOT a permitted way to connect a personally-owned monitor to your GFE?
USB
Which designation marks information that does not have potential to damage national security?
Unclassified
Which of the following is a potential insider threat indicator?
Unusual interest in classified information
Which is NOT a sufficient way to protect your identity?
Use a common password for all your system and application logons.
which is an appropriate use of government e-mail?
Use a digital signature when sending attachments or hyperlinks.
How can you protect yourself from internet hoaxes?
Use online sites to confirm or expose potential hoaxes
Which of the following is a security best practice when using social networking sites?
Use only your personal contact information when establishing your account
How can you protect your organization on social networking sites?
Validate friend request through another source before confirming them.
What are some examples of malicious code?
Viruses, Trojan horses, or worms
What Type of Social Engineering Targets Senior Officials?
Whaling
When can you use removable media on a Government system?
When operationally necessary, owned by your organization, and approved by the appropriate authority
Which of the following is NOT a best practice to preserve the authenticity of your identity?
Write your password down on a device that only you access (e.g., your smartphone)
Which of the following is true of telework?
You must have permission from your organization.
Which of the following statements is true of cookies?
You should only accept cookies from reputable, trusted websites.
Which of the following is true of the Common Access Card (CAC) or Personal Identity Verification (PIV) card?
You should remove and take your CAC/PIV card
Which of the following information is a security risk when posted publicly on your social networking profile?
Your mother's maiden name
Which of the following is an example of two-factor authentication?
Your password and a code you receive via text message
which of these is NOT a potential indicator that your device may be under a malicious code attack?
a notification for a system update that has been publicized
Which best describes and insider threat? Someone who uses _______ access, _______________, to harm national security through unauthorized disclosure, data modification, espionage, terrorism, or kinetic actions.
authorized access, wittingly or unwittingly
which of the following is NOT a best practice for traveling overseas with a mobile device?
do not travel with a mobile device if you can avoid it
tom is working on a report that contains employees names, home addresses, and salary. Which of the following is TOM prohibited from doing with the report?
e-mailing it to a colleague who needs to provide missing data
Which of the following is an example of a strong password?
eA1xy2!P
which of the following uses of removable media is appropriate?
encrypting data stored on removable media
A compromise occurs when a person who does not have the required clearance or access caveats comes into possession of SCI
in any manner
which of the following is a best practice to protect your identity
order a credit report annually
which of the following is a step you should not take to protect against spillage?
purge any devices memory before connecting it to a classified network
how can you protect your home computer?
regularly back up your files
how can you mitigate the potential risk associated with a compressed URL?
use the preview function to see where the link actually leads
which of the following is a best practice for managing connection requests on social networking sites?
validate connection requests through another source if possible.
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague vacations at the beach every year, is married and a father of four, sometimes has poor work quality, and works well with his team.
~0 indicator
Which of the following personally-owned computer peripherals is permitted for use with Government-furnished equipment?
~A wired keyboard that requires the installation of drivers (Wrong)
Which of the following is true of Sensitive Compartmented Information (SCI)?
~Access requires a formal need-to-know determination issued by the Director of National Intelligence
When should documents be marked within a Sensitive Compartmented Information Facility (SCIF)
~All documents should be appropriately marked, regardless of format, sensitivity, or classification. Unclassified documents do not need to be marked as a SCIF. Only paper documents that are in open storage need to be marked.
Who designates whether information is classified and its classification level?
~National Security Agency (NSA) (Wrong)
You find information that you know to be classified on the Internet. What should you do?
~Note the website's URL and report the situation to your security point of contact
Which of the following is a good practice for telework?
~Use a Virtual Private Network (VPN) to obscure your true geographic location
Which of the following may help to prevent spillage? -Verify that any government equipment used for processing classified information has valid anti-virus software before connecting it to the internet -Follow procedures for transferring data to and from outside agency and non-Government networks -Purge the memory of any device removed from a classified network before connecting it to an unclassified network -Process all data at the highest classification or protection level available, including unclassified data
~Verify that any government equipment used for processing classified information has valid anti-virus software before connecting it to the internet (wrong) ~Follow procedures for transferring data to and from outside agency and non-Government networks
Which of the following is true of transmitting Sensitive Compartmented Information (SCI)?
~You must never transmit SCI via fax machine (Wrong)