Cyber Awareness Challenge

Lakukan tugas rumah & ujian kamu dengan baik sekarang menggunakan Quizwiz!

**Insider Threat A colleague has visited several foreign countries recently, has adequate work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his car repossessed. How many potential insider threat indicators does this employee display?

1 Indicator(wrong) ~3 or more indicators

**Insider Threat A colleague vacations at the beach every year, is married and a father of four, his work quality is sometimes poor, and he is pleasant to work with. How many potential insider threat indicators does this employee display?

1 indicator

**Insider Threat How many potential insider threat indicators does a person who is playful and charming, consistently wins performance awards, but is occasionally aggressive in trying to access sensitive information display?

1 indicator

**Insider Threat How many potential insider threat indicators does a coworker who often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?

3 or more indicators

**Insider Threat Which of the following should be reported as a potential security incident?

A coworker removes sensitive information without authorization

*Sensitive Compartmented Information Which of the following best describes the compromise of Sensitive Compartmented Information (SCI)?

A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.

What is a possible indication of a malicious code attack in progress?

A pop-up window that flashes and warns that your computer is infected with a virus.

*Sensitive Compartmented Information What is a Sensitive Compartmented Information (SCI) program?

A program that segregates various type of classified information into distinct compartments for added protection and dissemination for distribution control.

What is whaling?

A type of phishing targeted at high-level personnel such as senior officials.

**Classified Data What is required for an individual to access classified data?

Appropriate clearance, a signed and approved non-disclosure agreement, and need-to-know

What describes how Sensitive Compartmented Information is marked?

Approved Security Classification Guide (SCG)

*Sensitive Information Under which circumstances is it permitted to share an unclassified draft document with a non-DoD professional discussion group?

As long as the document is cleared for public release, you may share it outside of DoD.

*Spillage What should you do if a reporter asks you about potentially classified information on the web?

Ask for information about the website, including the URL.

*Spillage After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know this project is classified. What should be your response?

Attempt to change the subject to something non-work related, but neither confirm nor deny the article's authenticity.

**Home Computer Security How can you protect your information when using wireless technology?

Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.

*Spillage Which of the following is a good practice to aid in preventing spillage?

Be aware of classification markings and all handling caveats.

**Physical Security At which Cyberspace Protection Condition (CPCON) is the priority focus on critical functions only?

CPCON 1

*Spillage What should you do when you are working on an unclassified system and receive an email with a classified attachment?

Call your security point of contact immediately

**Physical Security What is a good practice for physical security?

Challenge people without proper badges.

**Classified Data Which of the following is true of protecting classified data?

Classified material must be appropriately marked.

**Insider Threat What type of activity or behavior should be reported as a potential insider threat?

Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.

**Classified Data Which of the following can an unauthorized disclosure of information classified as Confidential reasonably be expected to cause?

Damage to national security

*Sensitive Information What is the best example of Personally Identifiable Information (PII)?

Date and place of birth

**Social Networking What should you do if you receive a game application request that includes permission to access your friends, profile information, cookies, and sires visited?

Decline the request

**Social Engineering Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email?

Do not access links or hyperlinked media such as buttons and graphics in email messages.

**Mobile Devices Which is a rule for removable media, other portable electronic devices (PEDs), and mobile computing devices to protect Government systems?

Do not use any personally owned/non-organizational removable media on your organization's systems.

**Classified Data What is a good practice to protect classified information?

Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material.

What is an indication that malicious code is running on your system?

File corruption

**Social Engineering Which of the following is a way to protect against social engineering?

Follow instructions given only by verified personnel.

*Sensitive Information What type of unclassified material should always be marked with a special handling caveat?

For Official Use Only (FOUO)

What certificates are contained on the DoD Public Key Infrastructure (PKI) implemented by the Common Access Card (CAC)/Personal Identity Verification (PIV) card?

Identification, encryption, and digital signature

*Sensitive Information Under what circumstances could classified information be considered a threat to national security?

If aggregated, the information could become classified.

**Use of GFE Under what circumstances is it acceptable to use your Government-furnished computer to check personal e-mail and do other non-work-related activities?

If allowed by organizational policy

**Insider Threat What advantages do "insider threats" have over others that allows them to cause damage to their organizations more easily?

Insiders are given a level of trust and have authorized access to Government information systems

**Removable Media in a SCIF What must users ensure when using removable media such as compact disk (CD)?

It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number.

*Spillage Which of the following may help prevent inadvertent spillage?

Label all files, removable media, and subject headers with appropriate classification markings.

What is a best practice to protect data on your mobile computing device?

Lock your device screen when not in use and require a password to reactivate.

**Identity management What is the best way to protect your Common Access Card (CAC)?

Maintain possession of it at all times.

**Travel What is a best practice while traveling with mobile computing devices?

Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.

*Sensitive Information Which of the following is an example of Protected Health Information (PHI)?

Medical test results

**Insider Threat Which of the following is NOT considered a potential insider threat indicator?

New interest in learning a foreign language

What is the best response if you find classified government data on the internet?

Note any identifying information, such as the website's URL, and report the situation to your security POC.

**Identity Management Your DoD Common Access Card (CAC) has a Public Key Infrastructure (PKI) token approved for access to the NIPRNet. In which situation below are you permitted to use your PKI token?

On a NIPRNet system while using it for a PKI-required task

*Sensitive Information Which of the following is the best example of Personally Identifiable Information (PII)?

Passport number

**Social Engineering What is TRUE of a phishing attack?

Phishing can be an email with a hyperlink as bait.

*Spillage .What should you do if a reporter asks you about potentially classified information on the web?

Refer the reporter to your organization's public affairs office.

What is a valid response when identity theft occurs?

Report the crime to local law enforcement.

**Classified Data Which classification level is given to information that could reasonably be expected to cause serious damage to national security?

Secret

**Mobile Devices Which of the following helps protect data on your personal mobile devices?

Secure personal mobile devices to the same level as Government-issued systems.

*Sensitive Compartmented Information Which must be approved and signed by a cognizant Original Classification Authority (OCA)?

Security Classification Guide (SCG)

**Website Use While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you do?

Since the URL does not start with "https," do not provide you credit card information.

What does Personally Identifiable Information (PII) include?

Social Security Number; date and place of birth; mother's maiden name

**Identity Management Which of the following is the nest description of two-factor authentication?

Something you possess, like a CAC, and something you know, like a PIN or password

*Spillage A user writes down details marked as Secret from a report stored on a classified system and uses those details to draft a briefing on an unclassified system without authorization. What is the best choice to describe what has occurred?

Spillage because classified data was moved to a lower classification level system without authorization.

Which is a risk associated with removable media?

Spillage of classified information.

**Classified Data When classified data is not in use, how can you protect it?

Store classified data appropriately in a GSA-approved vault/container.

**Identity management Which is NOT a sufficient way to protect your identity?

Use a common password for all your system and application logons.

*Malicious Code What are some examples of malicious code?

Viruses, Trojan horses, or worms

**Social Networking When is the safest time to post details of your vacation activities on your social networking website?

When vacation is over, after you have returned home

What is the best example of Protected Health Information (PHI)?

Your health insurance explanation of benefits (EOB)

What information posted publicly on your personal social networking profile represents a security risk?

Your place of birth

**Insider Threat Which of the following should be reported as a potential security incident (in accordance with you Agency's insider threat policy)?

~A coworker brings a personal electronic device into a prohibited area.

*Sensitive Compartmented Information When should documents be marked within a Sensitive Compartmented Information Facility (SCIF)

~All documents should be appropriately marked, regardless of format, sensitivity, or classification. Unclassified documents do not need to be marked as a SCIF. Only paper documents that are in open storage need to be marked. Only documents that are classified Secret, Top Secret, or SCI require marking. (Wrong)

*Spillage What is a proper response if spillage occurs?

~Immediately notify your security POC.


Set pelajaran terkait

Multiplication Set 12 (3x5, 3x6, 3x7, 3x8)

View Set

Financial Accounting Midterm review

View Set

патфіз тести модуль 1

View Set

AP Government Chapter 4: Civil Liberties

View Set

Introduction to Philosophy FINAL!!!!!!!

View Set

Ch 8 commercial Property Insurance

View Set

Organic Chemistry Distillation Quiz (Lab 1)

View Set

Gen Bio II: Ch. 35 Connect LS questions

View Set