{"id":117147,"date":"2023-08-27T21:00:54","date_gmt":"2023-08-27T21:00:54","guid":{"rendered":"https:\/\/learnexams.com\/blog\/?p=117147"},"modified":"2023-08-27T21:00:57","modified_gmt":"2023-08-27T21:00:57","slug":"cyber-awareness-challenge-bundled-exams-with-complete-questions-and-answers","status":"publish","type":"post","link":"https:\/\/www.learnexams.com\/blog\/2023\/08\/27\/cyber-awareness-challenge-bundled-exams-with-complete-questions-and-answers\/","title":{"rendered":"Cyber Awareness Challenge Bundled Exams with complete Questions and Answers"},"content":{"rendered":"\n<p>This article will provide you with all the questions and answers for Cyber Awareness Challenge.<\/p>\n\n\n\n<p>ActiveX is a type of this?<\/p>\n\n\n\n<p>-Mobile code<\/p>\n\n\n\n<p>All https sites are legitimate and there is no risk to entering your personal info online.<\/p>\n\n\n\n<p>-FALSE<\/p>\n\n\n\n<p>Bob, a coworker, has been going through a divorce, has financial difficulties and is displaying hostile behavior. How many potential insider threat indicators is Bob displaying?<\/p>\n\n\n\n<p>-3<\/p>\n\n\n\n<p>The CAC\/PIV is a controlled item and contains certificates for:<\/p>\n\n\n\n<p>-All of the above<\/p>\n\n\n\n<p>Classified Information can only be accessed by individuals with<\/p>\n\n\n\n<p>-All of the above<\/p>\n\n\n\n<p>Classified Information is<\/p>\n\n\n\n<p>-Assigned a classification level by a supervisor<\/p>\n\n\n\n<p>A coworker has left an unknown CD on your desk. What should you do?<\/p>\n\n\n\n<p>-Put the CD in the trash<\/p>\n\n\n\n<p>DoD employees are prohibited from using a DoD CAC in card-reader-enabled public devices.<\/p>\n\n\n\n<p>-TRUE<\/p>\n\n\n\n<p>The following practices help prevent viruses and the downloading of malicious code except.<\/p>\n\n\n\n<p>-Scan external files from only unverifiable sources before uploading to computer<\/p>\n\n\n\n<p>How are Trojan horses, worms, and malicious scripts spread?<\/p>\n\n\n\n<p>-By email attachments<\/p>\n\n\n\n<p>How can you guard yourself against Identity theft?<\/p>\n\n\n\n<p>-All of the above<\/p>\n\n\n\n<p>How should you securely transport company information on a removable media?<\/p>\n\n\n\n<p>-Encrypt the removable media<\/p>\n\n\n\n<p>If authorized, what can be done on a work computer?<\/p>\n\n\n\n<p>-Check personal email<\/p>\n\n\n\n<p>If classified information were released, which classification level would result in &#8220;Exceptionally grave damage to national security&#8221;?<\/p>\n\n\n\n<p>-Top Secret<\/p>\n\n\n\n<p>If your wireless device is improperly configured someone could gain control of the device? T\/F<\/p>\n\n\n\n<p>-TRUE<\/p>\n\n\n\n<p>An individual who has attempted to access sensitive information without need-to-know and has made unusual requests for sensitive information is displaying indicators of what?<\/p>\n\n\n\n<p>-Potential Insider Threat<\/p>\n\n\n\n<p>It is getting late on Friday. You are reviewing your employees annual self evaluation. Your comments are due on Monday. You can email your employees information to yourself so you can work on it this weekend and go home now. Which method would be the BEST way to send this information?<\/p>\n\n\n\n<p>-Use the government email system so you can encrypt the information and open the email on your government issued laptop<\/p>\n\n\n\n<p>It is permissible to release unclassified information to the public prior to being cleared.<\/p>\n\n\n\n<p>-False<\/p>\n\n\n\n<p>Malicious code can do the following except?<\/p>\n\n\n\n<p>-Make your computer more secure<\/p>\n\n\n\n<p>Maria is at home shopping for shoes on Amazon.com. Before long she has also purchased shoes from several other websites. What can be used to track Maria&#8217;s web browsing habits?<\/p>\n\n\n\n<p>-Cookies<\/p>\n\n\n\n<p>Media containing Privacy Act information, PII, and PHI is not required to be labeled.<\/p>\n\n\n\n<p>-FALSE<\/p>\n\n\n\n<p>A medium secure password has at least 15 characters and one of the following.<\/p>\n\n\n\n<p>-Special character<\/p>\n\n\n\n<p>Of the following, which is NOT a characteristic of a phishing attempt?<\/p>\n\n\n\n<p>-Directing you to a web site that is real<\/p>\n\n\n\n<p>Of the following, which is NOT a method to protect sensitive information?<\/p>\n\n\n\n<p>-After work hours, storing sensitive information in unlocked containers, desks, or cabinets if security is not present<\/p>\n\n\n\n<p>Of the following, which is NOT an intelligence community mandate for passwords?<\/p>\n\n\n\n<p>-Maximum password age of 45 days<\/p>\n\n\n\n<p>Of the following, which is NOT a problem or concern of an Internet hoax?<\/p>\n\n\n\n<p>-Directing you to a website that looks real<\/p>\n\n\n\n<p>Of the following, which is NOT a security awareness tip?<\/p>\n\n\n\n<p>-Remove security badge as you enter a restaurant or retail establishment<\/p>\n\n\n\n<p>P2P (Peer-to-Peer) software can do the following except:<\/p>\n\n\n\n<p>-Allow attackers physical access to network assets<\/p>\n\n\n\n<p>PII, PHI, and financial information is classified as what type of information?<\/p>\n\n\n\n<p>-Sensitive<\/p>\n\n\n\n<p>Should you always label your removable media?<\/p>\n\n\n\n<p>-Yes<\/p>\n\n\n\n<p>Someone calls from an unknown number and says they are from IT and need some information about your computer. What should you do?<\/p>\n\n\n\n<p>-Request the user&#8217;s full name and phone number<\/p>\n\n\n\n<p>Spear Phishing attacks commonly attempt to impersonate email from trusted entities. What security device is used in email to verify the identity of sender?<\/p>\n\n\n\n<p>-Digital Signatures<\/p>\n\n\n\n<p>Spillage occurs when<\/p>\n\n\n\n<p>-Personal information is inadvertently posted at a website<\/p>\n\n\n\n<p>There are many travel tips for mobile computing. Which of the following is NOT one?<\/p>\n\n\n\n<p>-When using a public device with a card reader, only use your DoD CAC to access unclassified information<\/p>\n\n\n\n<p>Thumb drives, memory sticks, and flash drives are examples of<\/p>\n\n\n\n<p>-Removable media<\/p>\n\n\n\n<p>UNCLASSIFIED is a designation to mark information that does not have potential to damage national security.<\/p>\n\n\n\n<p>-TRUE<\/p>\n\n\n\n<p>The use of webmail is<\/p>\n\n\n\n<p>-is only allowed if the organization permits it<\/p>\n\n\n\n<p>Using webmail may bypass built in security features.<\/p>\n\n\n\n<p>-TRUE<\/p>\n\n\n\n<p>What action is recommended when somebody calls you to inquire about your work environment or specific account information?<\/p>\n\n\n\n<p>-Ask them to verify their name and office number<\/p>\n\n\n\n<p>What actions should you take prior to leaving the work environment and going to lunch?<\/p>\n\n\n\n<p>-All of the above<\/p>\n\n\n\n<p>What can you do to prevent spillage?<\/p>\n\n\n\n<p>-all of the above<\/p>\n\n\n\n<p>What can you do to protect yourself against phishing?<\/p>\n\n\n\n<p>-All of the above<\/p>\n\n\n\n<p>What constitutes a strong password?<\/p>\n\n\n\n<p>-all of the above<\/p>\n\n\n\n<p>What information relates to the physical or mental health of an individual?<\/p>\n\n\n\n<p>-PHI<\/p>\n\n\n\n<p>What information should you avoid posting on social networking sites?<\/p>\n\n\n\n<p>-All of the above<\/p>\n\n\n\n<p>What is considered a mobile computing device and therefore shouldn&#8217;t be plugged in to your Government computer?<\/p>\n\n\n\n<p>-All of the above<\/p>\n\n\n\n<p>What is considered ethical use of the Government email system?<\/p>\n\n\n\n<p>-Distributing Company newsletter<\/p>\n\n\n\n<p>What is NOT Personally Identifiable Information (PII)?<\/p>\n\n\n\n<p>-Hobby<\/p>\n\n\n\n<p>What should be done if you find classified Government Data\/Information Not Cleared for Public Release on the Internet?<\/p>\n\n\n\n<p>-Make note of any identifying information and the website URL and report it to your security office<\/p>\n\n\n\n<p>What should be done to protect against insider threats?<\/p>\n\n\n\n<p>-Report any suspicious behavior<\/p>\n\n\n\n<p>What should be done to sensitive data on laptops and other mobile computing devices?<\/p>\n\n\n\n<p>-Encrypt the sensitive data<\/p>\n\n\n\n<p>What should you do if someone asks to use your government issued mobile device (phone\/laptop..etc)?<\/p>\n\n\n\n<p>-Decline to lend your phone \/ laptop<\/p>\n\n\n\n<p>What should you do if someone forgets their access badge (physical access)?<\/p>\n\n\n\n<p>-Alert the security office<\/p>\n\n\n\n<p>What should you do to protect classified data?<\/p>\n\n\n\n<p>-Answer 1 and 2<\/p>\n\n\n\n<p>What should you do to protect yourself while on social networks?<\/p>\n\n\n\n<p>-Validate all friend requests through another source before confirming them<\/p>\n\n\n\n<p>What type of data must be handled and stored properly based on classification markings and handling caveats?<\/p>\n\n\n\n<p>-Classified<\/p>\n\n\n\n<p>What type of security is &#8220;part of your responsibility&#8221; and &#8220;placed above all else?&#8221;<\/p>\n\n\n\n<p>-Physical<\/p>\n\n\n\n<p>When leaving your work area, what is the first thing you should do?<\/p>\n\n\n\n<p>-Remove your CAC\/PIV<\/p>\n\n\n\n<p>When using a fax machine to send sensitive information, the sender should do which of the following?<\/p>\n\n\n\n<p>-Contact the recipient to confirm receipt<\/p>\n\n\n\n<p>Where should you store PII \/ PHI?<\/p>\n\n\n\n<p>-Information should be secured in a cabinet or container while not in use<\/p>\n\n\n\n<p>Which is an untrue statement about unclassified data?<\/p>\n\n\n\n<p>-If aggregated, the classification of the information may not be changed<\/p>\n\n\n\n<p>Which is a way to protect against phishing attacks?<\/p>\n\n\n\n<p>-Look for digital certificates<\/p>\n\n\n\n<p>Which is NOT a method of protecting classified data?<\/p>\n\n\n\n<p>-Assuming open storage is always authorized in a secure facility<\/p>\n\n\n\n<p>Which is NOT a requirement for telework?<\/p>\n\n\n\n<p>-Telework is only authorized for unclassified and confidential information<\/p>\n\n\n\n<p>Which is NOT a telework guideline?<\/p>\n\n\n\n<p>-Taking classified documents from your workspace<\/p>\n\n\n\n<p>Which is NOT a way to protect removable media?<\/p>\n\n\n\n<p>-As a best practice, labeling all classified removable media and considering all unlabeled removable media as unclassified<\/p>\n\n\n\n<p>Which is NOT a wireless security practice?<\/p>\n\n\n\n<p>-Turning off computer when not in use<\/p>\n\n\n\n<p>Which of the following attacks target high ranking officials and executives?<\/p>\n\n\n\n<p>-Whaling<\/p>\n\n\n\n<p>Which of the following best describes wireless technology?<\/p>\n\n\n\n<p>-It is inherently not a secure technology<\/p>\n\n\n\n<p>Which of the following definitions is true about disclosure of confidential information?<\/p>\n\n\n\n<p>-Damage to national security<\/p>\n\n\n\n<p>Which of the following is a good practice to avoid email viruses?<\/p>\n\n\n\n<p>-Delete email from senders you do not know<\/p>\n\n\n\n<p>Which of the following is an example of malicious code?<\/p>\n\n\n\n<p>-Trojan horses<\/p>\n\n\n\n<p>Which of the following is a proper way to secure your CAC\/PIV?<\/p>\n\n\n\n<p>-Remove and take it with you whenever you leave your workstation<\/p>\n\n\n\n<p>Which of the following is NOT a criterion used to grant an individual access to classified data?<\/p>\n\n\n\n<p>-Senior government personnel, military or civilian<\/p>\n\n\n\n<p>Which of the following is NOT a DoD special requirement for tokens?<\/p>\n\n\n\n<p>-Using NIPRNet tokens on systems of higher classification level<\/p>\n\n\n\n<p>Which of the following is NOT a home security best practice?<\/p>\n\n\n\n<p>-Setting weekly time for virus scan when you are not on the computer and it is powered off<\/p>\n\n\n\n<p>Which of the following is NOT a potential insider threat?<\/p>\n\n\n\n<p>-Member of a religion or faith<\/p>\n\n\n\n<p>Which of the following is NOT a security best practice when saving cookies to a hard drive?<\/p>\n\n\n\n<p>-Looking for &#8220;https&#8221; in the URL. All https sites are legitimate.<\/p>\n\n\n\n<p>Which of the following is NOT a social engineering tip?<\/p>\n\n\n\n<p>-Following instructions from verified personnel<\/p>\n\n\n\n<p>Which of the following is NOT considered sensitive information?<\/p>\n\n\n\n<p>-Sanitized information gathered from personnel records<\/p>\n\n\n\n<p>Which of the following is NOT Government computer misuse?<\/p>\n\n\n\n<p>-Checking work email<\/p>\n\n\n\n<p>Which of the following is NOT PII?<\/p>\n\n\n\n<p>-Mother&#8217;s maiden name, favorite color<\/p>\n\n\n\n<p>Which of the following is NOT Protected Health Information (PHI)?<\/p>\n\n\n\n<p>-Medical care facility name<\/p>\n\n\n\n<p>Which of the following is NOT sensitive information?<\/p>\n\n\n\n<p>-Unclassified information cleared for public release<\/p>\n\n\n\n<p>Which of the following makes Alex&#8217;s personal information vulnerable to attacks by identity thieves?<\/p>\n\n\n\n<p>-Carrying his Social Security Card with him<\/p>\n\n\n\n<p>Which of the following should be done to keep your home computer secure?<\/p>\n\n\n\n<p>-All of the above<\/p>\n\n\n\n<p>You are having lunch at a local restaurant outside the installation, and you find a cd labeled &#8220;favorite song&#8221;. What should you do?<\/p>\n\n\n\n<p>-Leave the cd where it is<\/p>\n\n\n\n<p>You are leaving the building where you work. What should you do?<\/p>\n\n\n\n<p>-Remove your security badge<\/p>\n\n\n\n<p>You are logged on to your unclassified computer and just received an encrypted email from a co-worker. The email has an attachment whose name contains the word &#8220;secret&#8221;. What should you do?<\/p>\n\n\n\n<p>-Contact your security POC right away<\/p>\n\n\n\n<p>You are working at your unclassified system and receive an email from a coworker containing a classified attachment. What should you do?<\/p>\n\n\n\n<p>-Alert your security POC<\/p>\n\n\n\n<p>You check your bank statement and see several debits you did not authorize. You believe that you are a victim of identity theft. Which of the following should you do immediately?<\/p>\n\n\n\n<p>-Monitor credit card statements for unauthorized purchases<\/p>\n\n\n\n<p>You receive a call on your work phone and you&#8217;re asked to participate in a phone survey. As part of the survey the caller asks for birth date and address. What type of attack might this be?<\/p>\n\n\n\n<p>-Social Engineering<\/p>\n\n\n\n<p>You receive an email from a company you have an account with. The email states your account has been compromised and you are invited to click on the link in order to reset your password. What action should you take?<\/p>\n\n\n\n<p>-Notify security<\/p>\n\n\n\n<p>Which of these is true of unclassified data?<\/p>\n\n\n\n<p>-Its classification level may rise when aggregated. (Correct)<\/p>\n\n\n\n<p>Which type of information includes personal, payroll, medical, and operational information?<\/p>\n\n\n\n<p>Sensitive<\/p>\n\n\n\n<p>Which of the following is NOT a correct way to protect sensitive information?<\/p>\n\n\n\n<p>Sensitive information may be stored on any password-protected system.<\/p>\n\n\n\n<p>Which of the following is NOT a typical result from running malicious code?<\/p>\n\n\n\n<p>Disabling cookies<\/p>\n\n\n\n<p>What level of damage to national security could reasonably be expected if unauthorized disclosure of Top Secret information occurred?<\/p>\n\n\n\n<p>Exceptionally grave damage<\/p>\n\n\n\n<p>Which of the following is true about telework?<\/p>\n\n\n\n<p>-You must have your organization&#8217;s permission to telework.<\/p>\n\n\n\n<p>Which of following is true of protecting classified data?<\/p>\n\n\n\n<p>-Classified material must be appropriately marked.<\/p>\n\n\n\n<p>New interest in learning another language?<\/p>\n\n\n\n<p>A colleague has visited several foreign countries recently, has adequate work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his car repossessed. How many indicators does this employee display?<\/p>\n\n\n\n<p>03<\/p>\n\n\n\n<p>Which of the following is NOT considered a potential insider threat indicator?<\/p>\n\n\n\n<p>-Treated mental health issues.<\/p>\n\n\n\n<p>What would you do if you receive a game application request on your government computer that includes permission to access your friends, profile information, cookies, and sites visited?<\/p>\n\n\n\n<p>-Decline the request.<\/p>\n\n\n\n<p>What information most likely presents a security risk on your personal social networking profile?<\/p>\n\n\n\n<p>-Birthplace<\/p>\n\n\n\n<p>You have reached the office door to exit your controlled area. As a security best practice, what should you do before exiting?<\/p>\n\n\n\n<p>-Remove your security badge, common access card (CAC), or personal identity verification (PIV) card.<\/p>\n\n\n\n<p>How should you protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card?<\/p>\n\n\n\n<p>-Store it in a shielded sleeve to avoid chip cloning.<\/p>\n\n\n\n<p>Which of the following statements is TRUE about the use of DoD Public Key Infrastructure (PKI) tokens?<\/p>\n\n\n\n<p>-Always use DoD PKI tokens within their designated classification level.<\/p>\n\n\n\n<p>Which of the following is a best practice for handling cookies?<\/p>\n\n\n\n<p>-If possible, set your browser preferences to prompt you each time a website wants to store a cookie.<\/p>\n\n\n\n<p>You receive an unexpected email from a friend: &#8220;I think you&#8217;ll like this: (URL)&#8221; What action should you take?<\/p>\n\n\n\n<p>-Use TinyURL&#8217;s preview feature to investigate where the link leads.<\/p>\n\n\n\n<p>You receive an email at your official Government email address from an individual at the Office of Personnel Management (OPM). The email provides a link to a personnel portal where you must enter your personal information as part of an effort to standardize recordkeeping. What action should you take first?<\/p>\n\n\n\n<p>-Look for a digital signature on the email.<\/p>\n\n\n\n<p>What is TRUE of a phishing attack?<\/p>\n\n\n\n<p>-Phishing can be an email with a hyperlink as bait.<\/p>\n\n\n\n<p>Upon connecting your Government-issued laptop to a public wireless connection, what should you immediately do?<\/p>\n\n\n\n<p>-Connect to the Government Virtual Private Network (VPN).??<\/p>\n\n\n\n<p>A coworker has asked if you want to download a programmer&#8217;s game to play at work. What should be your response?<\/p>\n\n\n\n<p>-I&#8217;ll pass.<\/p>\n\n\n\n<p>A coworker wants to send you a sensitive document to review while you are at lunch and you only have your personal tablet. What should you do?<\/p>\n\n\n\n<p>-Never allow sensitive data on non-Government-issued mobile devices.<\/p>\n\n\n\n<p>Which of the following demonstrates proper protection of mobile devices?<\/p>\n\n\n\n<p>-Linda encrypts all of the sensitive data on her government-issued mobile devices.<\/p>\n\n\n\n<p>How can you protect your information when using wireless technology?<\/p>\n\n\n\n<p>-Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.<\/p>\n\n\n\n<p>Which of the following is NOT true of traveling overseas with a mobile phone<\/p>\n\n\n\n<p>Physical security of mobile phones carried overseas is not a major issue<\/p>\n\n\n\n<p><em>SPILLAGE<\/em><br>Which of the following may be helpful to prevent spillage?<\/p>\n\n\n\n<p>Be aware of classification markings and all handling caveats.<\/p>\n\n\n\n<p><em>SPILLAGE<\/em><br>Which of the following may be helpful to prevent spillage?<\/p>\n\n\n\n<p>Label all files, removable media, and subject headers with appropriate classification markings.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>CLASSIFIED DATA*<br>Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?<\/li>\n<\/ul>\n\n\n\n<p>Secret<\/p>\n\n\n\n<p><em>CLASSIFIED DATA<\/em><br>What is a good practice to protect classified information?<\/p>\n\n\n\n<p>Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material.<\/p>\n\n\n\n<p><em>INSIDER THREAT<\/em><br>Based on the description below how many potential insider threat indicators are present? A colleague often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?<\/p>\n\n\n\n<p>3 or more indicators<\/p>\n\n\n\n<p><em>INSIDER THREAT<\/em><br>What threat do insiders with authorized access to information or information systems pose?<\/p>\n\n\n\n<p>They may wittingly or unwittingly use their authorized access to perform actions that result in the loss or degradation of resources or capabilities.<\/p>\n\n\n\n<p><em>INSIDER THREAT<\/em><br>Which of the following is NOT considered a potential insider threat indicator?<\/p>\n\n\n\n<p>New interest in learning a foregin language.<\/p>\n\n\n\n<p><em>SOCIAL NETWORKING<\/em><br>When may you be subject to criminal, disciplinary, and\/or administrative action due to online misconduct?<\/p>\n\n\n\n<p>If you participate in or condone it at any time.<\/p>\n\n\n\n<p><em>SOCIAL NETWORKING<\/em><br>When is the safest time to post details of your vacation activities on your social networking profile?<\/p>\n\n\n\n<p>After you have returned home following the vacation.<\/p>\n\n\n\n<p><em>SOCIAL NETWORKING<\/em><br>Which of the following is a security best practice when using social networking sites?<\/p>\n\n\n\n<p>Understanding and using the available privacy settings.<\/p>\n\n\n\n<p><em>UNCONTROLLED CLASSIFIED INFORMATION<\/em><br>Which of the following is NOT an example of CUI?<\/p>\n\n\n\n<p>Press release data<\/p>\n\n\n\n<p><em>UNCONTROLLED CLASSIFIED INFORMATION<\/em><br>Which of the following is NOT a correct way to protect CUI?<\/p>\n\n\n\n<p>CUI may be stored on any password-protected system.<\/p>\n\n\n\n<p>Select the information on the data sheet that is personally identifiable information (PII) But not protected health information (PHI)<\/p>\n\n\n\n<p>Jane Jones<br>Social security number: 123-45-6789<\/p>\n\n\n\n<p>Select the information on the data sheet that is protected health information (PHI)<\/p>\n\n\n\n<p>Jane has been Dr\u2026ect patient..ect.<\/p>\n\n\n\n<p><em>PHYSICAL SECURITY<\/em><br>At which Cyberspace Protection Condition (CPCON) is the priority focus on critical and essential functions?<\/p>\n\n\n\n<p>Answer: CPCON 2<\/p>\n\n\n\n<p><em>PHYSICAL SECURITY<\/em><br>Within a secure area, you see an individual who you do not know and is not wearing a visible badge<\/p>\n\n\n\n<p>Ask the individual to see an identification badge.<\/p>\n\n\n\n<p><em>IDENTITY MANAGEMENT<\/em><br>What certificates does the Common Access Card (CAC) or Personal Identity Verification (PIV) card contain?<\/p>\n\n\n\n<p>Identification, encryption, and digital signature<\/p>\n\n\n\n<p><em>IDENTITY MANAGEMENT<\/em><br>Which of the following is an example of a strong password?<\/p>\n\n\n\n<p>eA1xy2!P<\/p>\n\n\n\n<p><em>SENSITIVE COMPARTMENTED INFORMATION<\/em><br>When faxing Sensitive Compartmented Information (SCI), what actions should you take?<\/p>\n\n\n\n<p>Mark SCI documents appropriately and use an approved SCI fax machine.<\/p>\n\n\n\n<p><em>SENSITIVE COMPARTMENTED INFORMATION<\/em><br>When is it appropriate to have your security badge visible within a sensitive compartmented information facility (SCIF)?<\/p>\n\n\n\n<p>At all times while in the facility.<\/p>\n\n\n\n<p><em>REMOVABLE MEDIA IN A SCIF<\/em><br>What action should you take when using removable media in a Sensitive Compartmented Information Facility (SCIF)?<\/p>\n\n\n\n<p>Identify and disclose it with local Configuration\/Change Management Control and Property Management authorities<\/p>\n\n\n\n<p><em>MALICIOUS CODE<\/em><br>Which of the following is NOT a way malicious code spreads?<\/p>\n\n\n\n<p>Legitimate software updates<\/p>\n\n\n\n<p><em>WEBSITE USE<\/em><br>Which of the following statements is true of cookies?<\/p>\n\n\n\n<p>You should only accept cookies from reputable, trusted websites.<\/p>\n\n\n\n<p><em>SOCIAL ENGINEERING<\/em><br>How can you protect yourself from internet hoaxes?<\/p>\n\n\n\n<p>Use online sites to confirm or expose potential hoaxes<\/p>\n\n\n\n<p><em>SOCIAL ENGINEERING<\/em><br>How can you protect yourself from social engineering?<\/p>\n\n\n\n<p>Follow instructions given only by verified personnel<\/p>\n\n\n\n<p><em>SOCIAL ENGINEERING<\/em><br>What action should you take with an e-mail from a friend containing a compressed Uniform Resource Locator (URL)?<\/p>\n\n\n\n<p>Investigate the link\u2019s actual destination using the preview feature<\/p>\n\n\n\n<p><em>TRAVEL<\/em><br>Which of the following is a concern when using your Government-issued laptop in public?<\/p>\n\n\n\n<p>Others may be able to view your screen.<\/p>\n\n\n\n<p><em>USE OF GFE<\/em><br>What is a critical consideration on using cloud-based file sharing and storage applications on your Government-furnished equipment (GFE)?<\/p>\n\n\n\n<p>Determine if the software or service is authorized<\/p>\n\n\n\n<p><em>MOBILE DEVICES<\/em><br>Which of the following is an example of near field communication (NFC)?<\/p>\n\n\n\n<p>A smartphone that transmits credit card payment information when held in proximity to a credit card reader.<\/p>\n\n\n\n<p><em>MOBILE DEVICES<\/em><br>Which of the following is an example of removable media?<\/p>\n\n\n\n<p>Flash Drive<\/p>\n\n\n\n<p><em>HOME COMPUTER SECURITY<\/em><br>Which of the following is a best practice for securing your home computer?<\/p>\n\n\n\n<p>Create separate accounts for each user.<\/p>\n\n\n\n<p>*Spillage<br>After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you to comment about the article. You know this project is classified. What should be your response?<\/p>\n\n\n\n<p>Attempt to change the subject to something non-work related, but neither confirm nor deny the article\u2019s authenticity.<\/p>\n\n\n\n<p>*Spillage<br>Which of the following may help prevent inadvertent spillage?<\/p>\n\n\n\n<p>Label all files, removable media, and subject headers with appropriate classification markings.<\/p>\n\n\n\n<p>*Spillage<br>A user writes down details marked as Secret from a report stored on a classified system and uses those details to draft a briefing on an unclassified system without authorization. What is the best choice to describe what has occurred?<\/p>\n\n\n\n<p>Spillage because classified data was moved to a lower classification level system without authorization.<\/p>\n\n\n\n<p>*Spillage<br>What should you do when you are working on an unclassified system and receive an email with a classified attachment?<\/p>\n\n\n\n<p>Call your security point of contact immediately<\/p>\n\n\n\n<p>*Spillage<br>What should you do if a reporter asks you about potentially classified information on the web?<\/p>\n\n\n\n<p>Ask for information about the website, including the URL.<\/p>\n\n\n\n<p>*Spillage<br>.What should you do if a reporter asks you about potentially classified information on the web?<\/p>\n\n\n\n<p>Refer the reporter to your organization\u2019s public affairs office.<\/p>\n\n\n\n<p>*Spillage<br>What is a proper response if spillage occurs?<\/p>\n\n\n\n<p>~Immediately notify your security POC.<\/p>\n\n\n\n<p>*Spillage<br>Which of the following is a good practice to aid in preventing spillage?<\/p>\n\n\n\n<p>Be aware of classification markings and all handling caveats.<\/p>\n\n\n\n<p>**Classified Data<br>When classified data is not in use, how can you protect it?<\/p>\n\n\n\n<p>Store classified data appropriately in a GSA-approved vault\/container.<\/p>\n\n\n\n<p>**Classified Data<br>What is required for an individual to access classified data?<\/p>\n\n\n\n<p>Appropriate clearance, a signed and approved non-disclosure agreement, and need-to-know<\/p>\n\n\n\n<p>**Classified Data<br>Which classification level is given to information that could reasonably be expected to cause serious damage to national security?<\/p>\n\n\n\n<p>Secret<\/p>\n\n\n\n<p>**Classified Data<br>What is a good practice to protect classified information?<\/p>\n\n\n\n<p>Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material.<\/p>\n\n\n\n<p>**Classified Data<br>Which of the following is true of protecting classified data?<\/p>\n\n\n\n<p>Classified material must be appropriately marked.<\/p>\n\n\n\n<p>**Classified Data<br>Which of the following can an unauthorized disclosure of information classified as Confidential reasonably be expected to cause?<\/p>\n\n\n\n<p>Damage to national security<\/p>\n\n\n\n<p>**Insider Threat<br>Which of the following is NOT considered a potential insider threat indicator?<\/p>\n\n\n\n<p>New interest in learning a foreign language<\/p>\n\n\n\n<p>**Insider Threat<br>A colleague has visited several foreign countries recently, has adequate work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his car repossessed. How many potential insider threat indicators does this employee display?<\/p>\n\n\n\n<p>1 Indicator(wrong)<br>~3 or more indicators<\/p>\n\n\n\n<p>**Insider Threat<br>A colleague vacations at the beach every year, is married and a father of four, his work quality is sometimes poor, and he is pleasant to work with. How many potential insider threat indicators does this employee display?<\/p>\n\n\n\n<p>0 indicators<\/p>\n\n\n\n<p>**Insider Threat<br>How many potential insider threat indicators does a coworker who often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?<\/p>\n\n\n\n<p>3 or more indicators<\/p>\n\n\n\n<p>**Insider Threat<br>How many potential insider threat indicators does a person who is playful and charming, consistently wins performance awards, but is occasionally aggressive in trying to access sensitive information display?<\/p>\n\n\n\n<p>1 indicator<\/p>\n\n\n\n<p>**Insider Threat<br>What advantages do \u201cinsider threats\u201d have over others that allows them to cause damage to their organizations more easily?<\/p>\n\n\n\n<p>Insiders are given a level of trust and have authorized access to Government information systems<\/p>\n\n\n\n<p>**Insider Threat<br>What type of activity or behavior should be reported as a potential insider threat?<\/p>\n\n\n\n<p>Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.<\/p>\n\n\n\n<p>**Insider Threat<br>Which of the following should be reported as a potential security incident?<\/p>\n\n\n\n<p>A coworker removes sensitive information without authorization<\/p>\n\n\n\n<p>**Insider Threat<br>Which of the following should be reported as a potential security incident (in accordance with you Agency\u2019s insider threat policy)?<\/p>\n\n\n\n<p>~A coworker brings a personal electronic device into a prohibited area.<\/p>\n\n\n\n<p>**Social Networking<br>When is the safest time to post details of your vacation activities on your social networking website?<\/p>\n\n\n\n<p>When vacation is over, after you have returned home<\/p>\n\n\n\n<p>**Social Networking<br>What should you do if you receive a game application request that includes permission to access your friends, profile information, cookies, and sires visited?<\/p>\n\n\n\n<p>Decline the request<\/p>\n\n\n\n<p>*Sensitive Information<br>Under which circumstances is it permitted to share an unclassified draft document with a non-DoD professional discussion group?<\/p>\n\n\n\n<p>As long as the document is cleared for public release, you may share it outside of DoD.<\/p>\n\n\n\n<p>*Sensitive Information<br>What is the best example of Personally Identifiable Information (PII)?<\/p>\n\n\n\n<p>Date and place of birth<\/p>\n\n\n\n<p>*Sensitive Information<br>Which of the following is the best example of Personally Identifiable Information (PII)?<\/p>\n\n\n\n<p>Passport number<\/p>\n\n\n\n<p>*Sensitive Information<br>Which of the following is an example of Protected Health Information (PHI)?<\/p>\n\n\n\n<p>Medical test results<\/p>\n\n\n\n<p>*Sensitive Information<br>What type of unclassified material should always be marked with a special handling caveat?<\/p>\n\n\n\n<p>For Official Use Only (FOUO)<\/p>\n\n\n\n<p>*Sensitive Information<br>Under what circumstances could classified information be considered a threat to national security?<\/p>\n\n\n\n<p>If aggregated, the information could become classified.<\/p>\n\n\n\n<p>**Physical Security<br>What is a good practice for physical security?<\/p>\n\n\n\n<p>Challenge people without proper badges.<\/p>\n\n\n\n<p>**Physical Security<br>At which Cyberspace Protection Condition (CPCON) is the priority focus on critical functions only?<\/p>\n\n\n\n<p>CPCON 1<\/p>\n\n\n\n<p>**Identity Management<br>Your DoD Common Access Card (CAC) has a Public Key Infrastructure (PKI) token approved for access to the NIPRNet. In which situation below are you permitted to use your PKI token?<\/p>\n\n\n\n<p>On a NIPRNet system while using it for a PKI-required task<\/p>\n\n\n\n<p>**Identity Management<br>Which of the following is the nest description of two-factor authentication?<\/p>\n\n\n\n<p>Something you possess, like a CAC, and something you know, like a PIN or password<\/p>\n\n\n\n<p>**Identity management<br>Which is NOT a sufficient way to protect your identity?<\/p>\n\n\n\n<p>Use a common password for all your system and application logons.<\/p>\n\n\n\n<p>**Identity management<br>What is the best way to protect your Common Access Card (CAC)?<\/p>\n\n\n\n<p>Maintain possession of it at all times.<\/p>\n\n\n\n<p>*Sensitive Compartmented Information<br>What is a Sensitive Compartmented Information (SCI) program?<\/p>\n\n\n\n<p>A program that segregates various type of classified information into distinct compartments for added protection and dissemination for distribution control.<\/p>\n\n\n\n<p>*Sensitive Compartmented Information<br>Which of the following best describes the compromise of Sensitive Compartmented Information (SCI)?<\/p>\n\n\n\n<p>A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.<\/p>\n\n\n\n<p>*Sensitive Compartmented Information<br>When should documents be marked within a Sensitive Compartmented Information Facility (SCIF)<\/p>\n\n\n\n<p>~All documents should be appropriately marked, regardless of format, sensitivity, or classification.<br>Unclassified documents do not need to be marked as a SCIF.<br>Only paper documents that are in open storage need to be marked.<br>Only documents that are classified Secret, Top Secret, or SCI require marking. (Wrong)<\/p>\n\n\n\n<p>*Sensitive Compartmented Information<br>Which must be approved and signed by a cognizant Original Classification Authority (OCA)?<\/p>\n\n\n\n<p>Security Classification Guide (SCG)<\/p>\n\n\n\n<p>**Removable Media in a SCIF<br>What must users ensure when using removable media such as compact disk (CD)?<\/p>\n\n\n\n<p>It displays a label showing maximum classification, date of creation, point of contact, and Change Management 9CM) Control Number.<\/p>\n\n\n\n<p>*Malicious Code<br>What are some examples of malicious code?<\/p>\n\n\n\n<p>Viruses, Trojan horses, or worms<\/p>\n\n\n\n<p>**Website Use<br>While you are registering for a conference, you arrive at the website http:\/\/www.dcsecurityconference.org\/registration\/. The website requires a credit card for registration. What should you do?<\/p>\n\n\n\n<p>Since the URL does not start with \u201chttps,\u201d do not provide you credit card information.<\/p>\n\n\n\n<p>**Social Engineering<br>Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email?<\/p>\n\n\n\n<p>Do not access links or hyperlinked media such as buttons and graphics in email messages.<\/p>\n\n\n\n<p>**Social Engineering<br>What is TRUE of a phishing attack?<\/p>\n\n\n\n<p>Phishing can be an email with a hyperlink as bait.<\/p>\n\n\n\n<p>**Social Engineering<br>Which of the following is a way to protect against social engineering?<\/p>\n\n\n\n<p>Follow instructions given only by verified personnel.<\/p>\n\n\n\n<p>**Travel<br>What is a best practice while traveling with mobile computing devices?<\/p>\n\n\n\n<p>Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.<\/p>\n\n\n\n<p>**Use of GFE<br>Under what circumstances is it acceptable to use your Government-furnished computer to check personal e-mail and do other non-work-related activities?<\/p>\n\n\n\n<p>If allowed by organizational policy<\/p>\n\n\n\n<p>**Mobile Devices<br>Which is a rule for removable media, other portable electronic devices (PEDs), and mobile computing devices to protect Government systems?<\/p>\n\n\n\n<p>Do not use any personally owned\/non-organizational removable media on your organization\u2019s systems.<\/p>\n\n\n\n<p>**Mobile Devices<br>Which of the following helps protect data on your personal mobile devices?<\/p>\n\n\n\n<p>Secure personal mobile devices to the same level as Government-issued systems.<\/p>\n\n\n\n<p>**Home Computer Security<br>How can you protect your information when using wireless technology?<\/p>\n\n\n\n<p>Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.<\/p>\n\n\n\n<p>What is the best response if you find classified government data on the internet?<\/p>\n\n\n\n<p>Note any identifying information, such as the website\u2019s URL, and report the situation to your security POC.<\/p>\n\n\n\n<p>What information posted publicly on your personal social networking profile represents a security risk?<\/p>\n\n\n\n<p>Your place of birth<\/p>\n\n\n\n<p>What is the best example of Protected Health Information (PHI)?<\/p>\n\n\n\n<p>Your health insurance explanation of benefits (EOB)<\/p>\n\n\n\n<p>What does Personally Identifiable Information (PII) include?<\/p>\n\n\n\n<p>Social Security Number; date and place of birth; mother\u2019s maiden name<\/p>\n\n\n\n<p>What certificates are contained on the DoD Public Key Infrastructure (PKI) implemented by the Common Access Card (CAC)\/Personal Identity Verification (PIV) card?<\/p>\n\n\n\n<p>Identification, encryption, and digital signature<\/p>\n\n\n\n<p>What describes how Sensitive Compartmented Information is marked?<\/p>\n\n\n\n<p>Approved Security Classification Guide (SCG)<\/p>\n\n\n\n<p>Which is a risk associated with removable media?<\/p>\n\n\n\n<p>Spillage of classified information.<\/p>\n\n\n\n<p>What is an indication that malicious code is running on your system?<\/p>\n\n\n\n<p>File corruption<\/p>\n\n\n\n<p>What is a valid response when identity theft occurs?<\/p>\n\n\n\n<p>Report the crime to local law enforcement.<\/p>\n\n\n\n<p>What is whaling?<\/p>\n\n\n\n<p>A type of phishing targeted at high-level personnel such as senior officials.<\/p>\n\n\n\n<p>What is a best practice to protect data on your mobile computing device?<\/p>\n\n\n\n<p>Lock your device screen when not in use and require a password to reactivate.<\/p>\n\n\n\n<p>What is a possible indication of a malicious code attack in progress?<\/p>\n\n\n\n<p>A pop-up window that flashes and warns that your computer is infected with a virus.<\/p>\n\n\n\n<p>Which of the following may be helpful to prevent inadvertent spillage?<\/p>\n\n\n\n<p>What should you do after you have ended a call from a reporter asking you to confirm potentially classified info found on the web?<\/p>\n\n\n\n<p>Alert your security point of contact.<\/p>\n\n\n\n<p>Which of the following is NOT an example of sensitive information?<\/p>\n\n\n\n<p>PII<\/p>\n\n\n\n<p>SSN, date and place of birth, mother\u2019s maiden name, biometric records, PHI, passport number<\/p>\n\n\n\n<p>PHI<\/p>\n\n\n\n<p>Subset of PII, health information that identifies the individual, relates to physical or mental health of an individual, provision of health care to an individual, or payment of healthcare for individual<\/p>\n\n\n\n<p>Which of the following is NOT a typical result from running malicious code?<\/p>\n\n\n\n<p>Disable cookies<\/p>\n\n\n\n<p>What kind of information could reasonably be expected to cause serious damage to national security in the event of unauthorized disclosure?<\/p>\n\n\n\n<p>Secret<\/p>\n\n\n\n<p>Telework<\/p>\n\n\n\n<p>Have your permissions from your organization, follow your organization guideline, use authorized equipment and software, employ cyber security best practice, perform telework in dedicated when home.<\/p>\n\n\n\n<p>Which of the following should be reported as a potential security incident (in accordance with your Agency\u2019s insider threat policy)?<\/p>\n\n\n\n<p>A coworker brings a personal electronic device into prohibited areas.<\/p>\n\n\n\n<p>A colleague complains about anxiety and exhaustion, makes coworkers uncomfortable by asking excessive questions about classified projects, and complains about the credit card bills that his wife runs up. How many potential insider threat indicators does this employee display?<\/p>\n\n\n\n<p>3 or more indicators<\/p>\n\n\n\n<p>A colleague has won 10 high-performance awards, can be playful and charming, is not currently in a relationship, and occasionally aggressive in trying to access sensitive information. How many potential insider threat indicators does this employee display?<\/p>\n\n\n\n<p>1 indicator<\/p>\n\n\n\n<p>What information most likely presents a security risk on your personal social networking profile?<\/p>\n\n\n\n<p>Mother\u2019s maiden name<\/p>\n\n\n\n<p>Which of the following represents a good physical security practice?<\/p>\n\n\n\n<p>Use your own security badge, key code, or Common Access Card (CAC)\/Personal Identity Verification (PIC) card.<\/p>\n\n\n\n<p>How should you protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card?<\/p>\n\n\n\n<p>Store it in a shielded sleeve to avoid chip cloning.<\/p>\n\n\n\n<p>Which of the following statements is NOT true about protecting your virtual identity?<\/p>\n\n\n\n<p>Use personal information to help create strong passwords.<\/p>\n\n\n\n<p>While you are registering for a conference, you arrive at the website http:\/\/www.dcsecurityconference.org\/registration\/. The website requires a credit card for registration. What should you do?<\/p>\n\n\n\n<p>Since the URL does not start with \u201chttps,\u201d do not provide your credit card information.<\/p>\n\n\n\n<p>You receive an email from the Internal Revenue Service (IRS) demanding immediate payment of back taxes of which you were not aware. The email provides a website and a toll-free number where you can make payment. What action should you take?<\/p>\n\n\n\n<p>Contact the IRS using their publicly available, official contact information.<\/p>\n\n\n\n<p>Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email?<\/p>\n\n\n\n<p>Do not access links or hyperlinked media such as buttons and graphics in email messages.<\/p>\n\n\n\n<p>Which of the following is true of Internet hoaxes?<\/p>\n\n\n\n<p>They can be part of a distributed denial-of-service (DDoS) attack.<\/p>\n\n\n\n<p>Which of the following is NOT true of traveling overseas with a mobile phone?<\/p>\n\n\n\n<p>Physical security of mobile phones carried overseas is not a major issue.<\/p>\n\n\n\n<p>A coworker has asked if you want to download a programmer\u2019s game to play at work. What should be your response?<\/p>\n\n\n\n<p>I\u2019ll pass.<\/p>\n\n\n\n<p>A coworker wants to send you a sensitive document to review while you are at lunch and you only have your personal tablet. What should you do?<\/p>\n\n\n\n<p>Never allow sensitive data on non-Government-issued mobile devices.<\/p>\n\n\n\n<p>A man you do not know is trying to look at your Government-issued phone and has asked to use it. What should you do?<\/p>\n\n\n\n<p>Decline to lend the man your phone.<\/p>\n\n\n\n<p>How can you protect your information when using wireless technology?<\/p>\n\n\n\n<p>Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.<\/p>\n\n\n\n<p>What should you do if a reporter asks you about potentially classified information on the web?<\/p>\n\n\n\n<p>Neither confirm or deny the information is classified<\/p>\n\n\n\n<p>.<\/p>\n\n\n\n<p>Which of the following may be helpful to prevent inadvertent spillage?<\/p>\n\n\n\n<p>Label all files, removable media, and subject headers with appropriate classification markings.<\/p>\n\n\n\n<p>What kind of information could reasonably be expected to cause serious damage to national security in the event of unauthorized disclosure?<\/p>\n\n\n\n<p>Secret<\/p>\n\n\n\n<p>Which of the following is NOT true concerning a computer labeled SECRET?<\/p>\n\n\n\n<p>May be used on an unclassified network.<\/p>\n\n\n\n<p>A colleague complains about anxiety and exhaustion, makes coworkers uncomfortable by asking excessive questions about classified projects, and complains about the credit card bills that his wife runs up. How many potential insider threat indicators does this employee display?<\/p>\n\n\n\n<p>3 or more indicators<\/p>\n\n\n\n<p>Which of the following should be reported as a potential security incident?<\/p>\n\n\n\n<p>A coworker removes sensitive information without approval.<\/p>\n\n\n\n<p>Which of the following should be reported as a potential security incident (in accordance with your Agency\u2019s insider threat policy)?<\/p>\n\n\n\n<p>A coworker brings a personal electronic device into prohibited areas.<\/p>\n\n\n\n<p>When would be a good time to post your vacation location and dates on your social networking website?<\/p>\n\n\n\n<p>When you return from your vacation.<\/p>\n\n\n\n<p>In setting up your personal social networking service account, what email address should you use?<\/p>\n\n\n\n<p>Your personal email address.<\/p>\n\n\n\n<p>Which of the following is NOT a correct way to protect sensitive information?<\/p>\n\n\n\n<p>Sensitive information may be stored on any password-protected system.<\/p>\n\n\n\n<p>Which of these is true of unclassified data?<\/p>\n\n\n\n<p>It\u2019s classification level may rise when aggregated.<\/p>\n\n\n\n<p>Is it permitted to share an unclassified draft document with a non-DoD professional discussion group?<\/p>\n\n\n\n<p>As long as the document is cleared for public release, you may share it outside of DoD.<\/p>\n\n\n\n<p>Within a secure area, you see an individual you do not know. Her badge is not visible to you. What is the best course of action?<\/p>\n\n\n\n<p>Ask the individual to identify herself.<\/p>\n\n\n\n<p>How should you protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card?<\/p>\n\n\n\n<p>Store it in a shielded sleeve to avoid chip cloning.<\/p>\n\n\n\n<p>Your DoD Common Access Card (CAC) has a Public Key Infrastructure (PKI) token approves for access to the NIPRNET. In which situation below are you permitted to use your PKI token?<\/p>\n\n\n\n<p>On a NIPRNET system while using it for a PKI-required task<\/p>\n\n\n\n<p>After clicking on a link on a website, a box pops up and asks if you want to run an application. Is it okay to run it?<\/p>\n\n\n\n<p>No. Only allow mobile code to run from your organization or your organization\u2019s trusted sites.<\/p>\n\n\n\n<p>Upon connecting your Government- issued laptop to a public wireless connection, what should you immediately do?<\/p>\n\n\n\n<p>Connect to the Government Virtual Private Network (VPN).<\/p>\n\n\n\n<p>What do you do if spillage occurs?<\/p>\n\n\n\n<p>Immediately notify your security point of contact.<\/p>\n\n\n\n<p>What should you do after you have ended a call from a reporter asking you to confirm potentially classified information found on the web?<\/p>\n\n\n\n<p>Alert your security point of contact.<\/p>\n\n\n\n<p>Which of the following is NOT a requirement for telework?<\/p>\n\n\n\n<p>You must possess security clearance eligibility to telework.<\/p>\n\n\n\n<p>Who can be permitted access to classified data?<\/p>\n\n\n\n<p>Only persons with appropriate clearance, a non-disclosure agreement, and need-to-know can access classified data.<\/p>\n\n\n\n<p>A colleague has won 10 high-performance awards, can be playful and charming, is not currently in a relationship, and is occasionally aggressive in trying to access sensitive information. How many potential insiders threat indicators does this employee display?<\/p>\n\n\n\n<p>1 indicator<\/p>\n\n\n\n<p>A colleague has visited several foreign countries recently, has adequate work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his car repossessed. How many potential insiders threat indicators does this employee display?<\/p>\n\n\n\n<p>3 or more indicators<\/p>\n\n\n\n<p>A colleague complains about anxiety and exhaustion, makes coworkers uncomfortable by asking excessive questions about classified projects, and complains about the credit card bills that his wife runs up. How many potential insiders threat indicators does this employee display?<\/p>\n\n\n\n<p>3 or more indicators<\/p>\n\n\n\n<p>In setting up your personal social networking service account, what email address should you use?<\/p>\n\n\n\n<p>Your personal email address<\/p>\n\n\n\n<p>What information most likely presents a security risk on your personal social networking profile?<\/p>\n\n\n\n<p>Your place of birth<\/p>\n\n\n\n<p>Which of the following is NOT an example of sensitive information?<\/p>\n\n\n\n<p>Press release data<\/p>\n\n\n\n<p>Is it permitted to share an unclassified draft document with a non-DoD professional discussion group?<\/p>\n\n\n\n<p>As long as the document is cleared for public release, you may release it outside of DoD<\/p>\n\n\n\n<p>Which of the following is an example of Protected Health Information (PHI)?<\/p>\n\n\n\n<p>I\u2019ve tried all the answers and it still tells me off. Examples are: Patient names, Social Security numbers, Driver\u2019s license numbers, insurance details, and birth dates<\/p>\n\n\n\n<p>Which of the following represents a good physical security practice?<\/p>\n\n\n\n<p>Use your own security badge, key code, or Common Access Card (CAC)\/Personal Identity Verification (PIC) card.<\/p>\n\n\n\n<p>Which of the following is NOT a good way to protect your identity?<\/p>\n\n\n\n<p>Use a single, complex password for your system and application logons.<\/p>\n\n\n\n<p>Which of the following statements is TRUE about the use of DoD Public Key Infrastructure (PKI) tokens?<\/p>\n\n\n\n<p>Always use DoD PKI tokens within their designated classification level.<\/p>\n\n\n\n<p>Which of the following is NOT a typical means for spreading malicious code?<\/p>\n\n\n\n<p>Patching from a trusted source<\/p>\n\n\n\n<p>Which of the following is a practice that helps to protect you from identity theft?<\/p>\n\n\n\n<p>Ordering a credit report annually<\/p>\n\n\n\n<p>Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email?<\/p>\n\n\n\n<p>Do not access links or hyperlinked media such as buttons and graphics in email messages.<\/p>\n\n\n\n<p>You receive an unexpected email from a friend: \u201cI think you\u2019ll like this: https:\/\/tinyurl.com\/2fcbvy.\u201d What action should you take?<\/p>\n\n\n\n<p>Use TinyURL\u2019s preview feature to investigate where the link leads.<\/p>\n\n\n\n<p>You receive an email from the Internal Revenue Service (IRS) demanding immediate payment of back taxes of which you were not aware. The email provides a website and a toll-free number where you can make payment. What action should you take?<\/p>\n\n\n\n<p>Contact the IRS<\/p>\n\n\n\n<p>When using your government-issued laptop in public environments, with which of the following should you be concerned?<\/p>\n\n\n\n<p>The potential for unauthorized viewing of work-related information displayed on your screen.<\/p>\n\n\n\n<p>Under what circumstances is it acceptable to check personal email on Government-furnished equipment (GFE)?<\/p>\n\n\n\n<p>If your organization allows it.<\/p>\n\n\n\n<p>Which of the following is NOT a best practice to protect data on your mobile computing device?<\/p>\n\n\n\n<p>Lock your device screen when not in use and require a password to reactivate.<\/p>\n\n\n\n<p>When checking in at the airline counter for a business trip, you are asked if you would like to check your laptop bag. This bag contains your government-issued laptop. What should you do?<\/p>\n\n\n\n<p>I\u2019ve tried all the answers and it still tells me off, part 2. Decline So That You Maintain Physical Control of Your Government-Issued Laptop.<\/p>\n\n\n\n<p>How can you protect your information when using wireless technology?<\/p>\n\n\n\n<p>Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.<\/p>\n\n\n\n<p>not an example of cui<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Press Release Data<\/li>\n<\/ul>\n\n\n\n<p>which is not an example of cui<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Press Release Data<\/li>\n<\/ul>\n\n\n\n<p>what is not an example of cui<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Press Release Data<\/li>\n<\/ul>\n\n\n\n<p>example of cui cyber awareness<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>CUI is an umbrella term that encompasses many different markings to identify information that is not classified but which should be protected. Some examples you may be familiar with: Personally Identifiable Information (PII) Sensitive Personally Identifiable Information (SPII)<\/li>\n<\/ul>\n\n\n\n<p>cui examples<\/p>\n\n\n\n<p>examples of cui<\/p>\n\n\n\n<p>examples of cui include<\/p>\n\n\n\n<p>what are examples of cui<\/p>\n\n\n\n<p>what is not an example of cui cyber awareness<\/p>\n\n\n\n<p>which is not an example of cui cyber awareness<\/p>\n\n\n\n<p>cui example<\/p>\n\n\n\n<p>example of cui<\/p>\n\n\n\n<p>examples of controlled unclassified information include<\/p>\n\n\n\n<p>examples of controlled unclassified information includes<\/p>\n\n\n\n<p>what are examples of controlled unclassified information<\/p>\n\n\n\n<p>what is considered cui<\/p>\n\n\n\n<p>controlled unclassified information examples<\/p>\n\n\n\n<p>correct way to protect cui<\/p>\n\n\n\n<p>cui cyber awareness<\/p>\n\n\n\n<p>cui protection<\/p>\n\n\n\n<p>examples of controlled unclassified information<\/p>\n\n\n\n<p>how to protect cui cyber awareness<\/p>\n\n\n\n<p>is pii controlled unclassified information<\/p>\n\n\n\n<p>not a correct way to store cui<\/p>\n\n\n\n<p>what is considered cui data<\/p>\n\n\n\n<p>what is controlled unclassified information basic<\/p>\n\n\n\n<p>what is cui data<\/p>\n\n\n\n<p>what is not a correct way to protect cui<\/p>\n\n\n\n<p>a cui<\/p>\n\n\n\n<p>controlled classified information<\/p>\n\n\n\n<p>controlled unclassified information<\/p>\n\n\n\n<p>cui controlled unclassified information<\/p>\n\n\n\n<p>cui cyber security<\/p>\n\n\n\n<p>cui data classification<\/p>\n\n\n\n<p>cui documents<\/p>\n\n\n\n<p>cui security<\/p>\n\n\n\n<p>cui security classification<\/p>\n\n\n\n<p>cui vs unclassified<\/p>\n\n\n\n<p>cyber awareness cui<\/p>\n\n\n\n<p>define controlled unclassified information<\/p>\n\n\n\n<p>examples of controlled unclassified information cui include<\/p>\n\n\n\n<p>is pii cui<\/p>\n\n\n\n<p>is press release data cui<\/p>\n\n\n\n<p>protecting cui<\/p>\n\n\n\n<p>what cui basic<\/p>\n\n\n\n<p>what is a controlled unclassified information<\/p>\n\n\n\n<p>what is a cui<\/p>\n\n\n\n<p>what is considered controlled unclassified information<\/p>\n\n\n\n<p>what is controlled unclassified information<\/p>\n\n\n\n<p>what is controlled unclassified information cui<\/p>\n\n\n\n<p>what is cui cyber awareness<\/p>\n\n\n\n<p>what is the correct way to protect cui<\/p>\n\n\n\n<p>who is responsible for protecting cui markings and dissemination instructions<\/p>\n\n\n\n<p>army cui<\/p>\n\n\n\n<p>classification cui<\/p>\n\n\n\n<p>controlled technical information<\/p>\n\n\n\n<p>controlled unclassified info<\/p>\n\n\n\n<p>controlled unclassified information categories<\/p>\n\n\n\n<p>controlled unclassified information cui<\/p>\n\n\n\n<p>controlled unclassified information marking<\/p>\n\n\n\n<p>controlled unclassified information markings<\/p>\n\n\n\n<p>controlled unclassified information registry<\/p>\n\n\n\n<p>cui basic<\/p>\n\n\n\n<p>cui classification<\/p>\n\n\n\n<p>cui defined<\/p>\n\n\n\n<p>cui distribution<\/p>\n\n\n\n<p>cui documents must be reviewed<\/p>\n\n\n\n<p>cui guidance<\/p>\n\n\n\n<p>cui guide<\/p>\n\n\n\n<p>cui markings<\/p>\n\n\n\n<p>cui means<\/p>\n\n\n\n<p>cui pii<\/p>\n\n\n\n<p>cui registry<\/p>\n\n\n\n<p>cui requirements<\/p>\n\n\n\n<p>cui security classification guide<\/p>\n\n\n\n<p>cui specified<\/p>\n\n\n\n<p>cui transmission<\/p>\n\n\n\n<p>define cui<\/p>\n\n\n\n<p>definition of controlled unclassified information<\/p>\n\n\n\n<p>how to protect cui<\/p>\n\n\n\n<p>how to store cui<\/p>\n\n\n\n<p>in order to obtain access to cui<\/p>\n\n\n\n<p>information may be cui in accordance with<\/p>\n\n\n\n<p>marking controlled unclassified information<\/p>\n\n\n\n<p>protect cui<\/p>\n\n\n\n<p>protecting cui includes which steps<\/p>\n\n\n\n<p>security cui<\/p>\n\n\n\n<p>types of cui<\/p>\n\n\n\n<p>unclassified cui<\/p>\n\n\n\n<p>unclassified information<\/p>\n\n\n\n<p>what cui<\/p>\n\n\n\n<p>what is controlled unclassified information specified<\/p>\n\n\n\n<p>what is cui basic<\/p>\n\n\n\n<p>what is cui dod<\/p>\n\n\n\n<p>what is cui information<\/p>\n\n\n\n<p>what is cui specific<\/p>\n\n\n\n<p>what level of system and network is required for cui<\/p>\n\n\n\n<p>when destroying or disposing of classified information you must<\/p>\n\n\n\n<p>32 cfr part 2002<\/p>\n\n\n\n<p>air force cui<\/p>\n\n\n\n<p>army controlled unclassified information training<\/p>\n\n\n\n<p>at the time of creation of cui<\/p>\n\n\n\n<p>can cui<\/p>\n\n\n\n<p>can cui be stored in a locked desk<\/p>\n\n\n\n<p>can cui be stored on any password protected system<\/p>\n\n\n\n<p>controlled unclassified information cover sheet<\/p>\n\n\n\n<p>controlled unclassified information cui awareness training<\/p>\n\n\n\n<p>controlled unclassified information meaning<\/p>\n\n\n\n<p>controlled unclassified information training<\/p>\n\n\n\n<p>controlled unclassified information training army<\/p>\n\n\n\n<p>correct banner marking for unclassified documents with cui<\/p>\n\n\n\n<p>cui<\/p>\n\n\n\n<p>cui acronym<\/p>\n\n\n\n<p>cui army<\/p>\n\n\n\n<p>cui basic definition<\/p>\n\n\n\n<p>cui categories<\/p>\n\n\n\n<p>cui category<\/p>\n\n\n\n<p>cui classification marking<\/p>\n\n\n\n<p>cui data<\/p>\n\n\n\n<p>cui definition<\/p>\n\n\n\n<p>cui distribution statement<\/p>\n\n\n\n<p>cui distribution statements<\/p>\n\n\n\n<p>cui dod<\/p>\n\n\n\n<p>cui government<\/p>\n\n\n\n<p>cui includes information traditionally marked as<\/p>\n\n\n\n<p>cui information<\/p>\n\n\n\n<p>cui labeling<\/p>\n\n\n\n<p>cui marking examples<\/p>\n\n\n\n<p>cui marking handbook<\/p>\n\n\n\n<p>cui markings dod<\/p>\n\n\n\n<p>cui meaning<\/p>\n\n\n\n<p>cui navy<\/p>\n\n\n\n<p>cui specified definition<\/p>\n\n\n\n<p>cui stands for<\/p>\n\n\n\n<p>cui.<\/p>\n\n\n\n<p>definition of cui<\/p>\n\n\n\n<p>dod cui instruction<\/p>\n\n\n\n<p>dod cui marking examples<\/p>\n\n\n\n<p>dod cui markings<\/p>\n\n\n\n<p>is proprietary data cui<\/p>\n\n\n\n<p>it is mandatory to include a banner<\/p>\n\n\n\n<p>it is mandatory to include a banner marking<\/p>\n\n\n\n<p>level of system and network configuration is required for cui<\/p>\n\n\n\n<p>navy cui<\/p>\n\n\n\n<p>sensitive unclassified information<\/p>\n\n\n\n<p>the correct banner for unclassified documents with cui is<\/p>\n\n\n\n<p>the correct banner marking for unclassified documents with cui is<\/p>\n\n\n\n<p>understanding that protection of sensitive unclassified information is<\/p>\n\n\n\n<p>understanding that protection of sensitive unclassified information is:<\/p>\n\n\n\n<p>what dod instructions implements the dod cui program<\/p>\n\n\n\n<p>what does cui mean<\/p>\n\n\n\n<p>what is basic cui<\/p>\n\n\n\n<p>what is cui specified<\/p>\n\n\n\n<p>what is the goal of destroying cui<\/p>\n\n\n\n<p>which of the following individuals can access classified data<\/p>\n\n\n\n<p>who can control cui<\/p>\n\n\n\n<p>who is responsible for applying cui markings<\/p>\n\n\n\n<p>who is responsible for protecting cui<\/p>\n\n\n\n<p>32 cfr 2002<\/p>\n\n\n\n<p>army controlled unclassified information<\/p>\n\n\n\n<p>army cui training<\/p>\n\n\n\n<p>army unclassified<\/p>\n\n\n\n<p>at the time of creation of cui material<\/p>\n\n\n\n<p>at the time of creation of cui material the authorized<\/p>\n\n\n\n<p>can cui be emailed if encrypted<\/p>\n\n\n\n<p>cmmc cui<\/p>\n\n\n\n<p>controlled unclassified information army<\/p>\n\n\n\n<p>controlled unclassified information dod<\/p>\n\n\n\n<p>cui army training<\/p>\n\n\n\n<p>cui banner<\/p>\n\n\n\n<p>cui banner marking<\/p>\n\n\n\n<p>cui category markings<\/p>\n\n\n\n<p>cui cdi<\/p>\n\n\n\n<p>cui cmmc<\/p>\n\n\n\n<p>cui date<\/p>\n\n\n\n<p>cui designation indicator<\/p>\n\n\n\n<p>cui documents must be reviewed according to which<\/p>\n\n\n\n<p>cui documents must be reviewed according to which procedures<\/p>\n\n\n\n<p>cui documents must be reviewed to which procedures before destruction<\/p>\n\n\n\n<p>cui email<\/p>\n\n\n\n<p>cui email marking<\/p>\n\n\n\n<p>cui fouo<\/p>\n\n\n\n<p>cui marking<\/p>\n\n\n\n<p>cui marking guidance<\/p>\n\n\n\n<p>cui marking guide<\/p>\n\n\n\n<p>cui stand for<\/p>\n\n\n\n<p>cui training<\/p>\n\n\n\n<p>cui training air force<\/p>\n\n\n\n<p>cui vs fouo<\/p>\n\n\n\n<p>cui&#8217;s<\/p>\n\n\n\n<p>dod controlled unclassified information<\/p>\n\n\n\n<p>dod controlled unclassified information training<\/p>\n\n\n\n<p>dod cui guidance<\/p>\n\n\n\n<p>dod cui program instruction<\/p>\n\n\n\n<p>dod instruction cui program<\/p>\n\n\n\n<p>dod instruction implements the dod cui program<\/p>\n\n\n\n<p>dod mandatory controlled unclassified information<\/p>\n\n\n\n<p>eo 13556<\/p>\n\n\n\n<p>executive order 13556<\/p>\n\n\n\n<p>fouo vs cui<\/p>\n\n\n\n<p>how long is your nda applicable<\/p>\n\n\n\n<p>how should you protect a printed classified document<\/p>\n\n\n\n<p>is financial information cui<\/p>\n\n\n\n<p>isoo cui<\/p>\n\n\n\n<p>isoo cui registry<\/p>\n\n\n\n<p>isoo registry<\/p>\n\n\n\n<p>marking cui<\/p>\n\n\n\n<p>proprietary data cui<\/p>\n\n\n\n<p>unclasified<\/p>\n\n\n\n<p>unclassifed<\/p>\n\n\n\n<p>unclassified<\/p>\n\n\n\n<p>under what circumstances could unclassified information be considered a threat<\/p>\n\n\n\n<p>under which circumstances is it permitted to share an unclassified<\/p>\n\n\n\n<p>what dod instruction implements cui<\/p>\n\n\n\n<p>what dod instruction implements cui program<\/p>\n\n\n\n<p>what dod instruction implements dod cui program<\/p>\n\n\n\n<p>what dod instruction implements the cui program<\/p>\n\n\n\n<p>what dod instruction implements the dod cui<\/p>\n\n\n\n<p>what dod instruction implements the dod cui program<\/p>\n\n\n\n<p>what does cui stand for<\/p>\n\n\n\n<p>what is cui<\/p>\n\n\n\n<p>what is fouo<\/p>\n\n\n\n<p>what is purpose of isoo cui registry<\/p>\n\n\n\n<p>what is sensitive unclassified information<\/p>\n\n\n\n<p>what is the purpose of the isoo cui registry<\/p>\n\n\n\n<p>what level of system is required for cui<\/p>\n\n\n\n<p>what marking banner and footer<\/p>\n\n\n\n<p>which of the following is true about markings<\/p>\n\n\n\n<p>which of the following is true about unclassified data<\/p>\n\n\n\n<p>which of the following may help to prevent inadvertent spillage<\/p>\n\n\n\n<p>who can decontrol cui<\/p>\n\n\n\n<p>who is responsible for applying cui markings and dissemination<\/p>\n\n\n\n<p>why is cui important<\/p>\n\n\n\n<p>2002 date<\/p>\n\n\n\n<p>2002 h<\/p>\n\n\n\n<p>200squared<\/p>\n\n\n\n<p>2022 cyber awareness challenge<\/p>\n\n\n\n<p>32 2002<\/p>\n\n\n\n<p>32 cfr 2002 controlled unclassified information<\/p>\n\n\n\n<p>32 cfr part 2002 controlled unclassified information<\/p>\n\n\n\n<p>32 part<\/p>\n\n\n\n<p>access to classified information<\/p>\n\n\n\n<p>access to sensitive or restricted information is controlled describes which<\/p>\n\n\n\n<p>adversaries mc<\/p>\n\n\n\n<p>af cyber awareness challenge<\/p>\n\n\n\n<p>air force cyber awareness challenge<\/p>\n\n\n\n<p>air force fouo cover sheet<\/p>\n\n\n\n<p>all classified<\/p>\n\n\n\n<p>application sensitive but unclassified sbu<\/p>\n\n\n\n<p>army cyber awareness 2022<\/p>\n\n\n\n<p>army jko cyber awareness<\/p>\n\n\n\n<p>army privacy act cover sheet<\/p>\n\n\n\n<p>army sipr email address format<\/p>\n\n\n\n<p>army unclassified powerpoint template<\/p>\n\n\n\n<p>banner markings identify the<\/p>\n\n\n\n<p>c ui<\/p>\n\n\n\n<p>can 2002<\/p>\n\n\n\n<p>cbt cyber security<\/p>\n\n\n\n<p>compressed url cyber awareness<\/p>\n\n\n\n<p>controlled government<\/p>\n\n\n\n<p>critical unclassified information is sometimes<\/p>\n\n\n\n<p>ctp requirements<\/p>\n\n\n\n<p>cui can<\/p>\n\n\n\n<p>cui cbt<\/p>\n\n\n\n<p>cui certification<\/p>\n\n\n\n<p>cui compliance<\/p>\n\n\n\n<p>cui cover sheet<\/p>\n\n\n\n<p>cui cti<\/p>\n\n\n\n<p>cui cui<\/p>\n\n\n\n<p>cui dfars<\/p>\n\n\n\n<p>cui fedcon<\/p>\n\n\n\n<p>cui itar<\/p>\n\n\n\n<p>cui label<\/p>\n\n\n\n<p>cui labels<\/p>\n\n\n\n<p>cui propin<\/p>\n\n\n\n<p>cui training army<\/p>\n\n\n\n<p>cui.me<\/p>\n\n\n\n<p>cui\/\/sp-cti<\/p>\n\n\n\n<p>cyber awareness cbt<\/p>\n\n\n\n<p>cyber awareness challenge 2022<\/p>\n\n\n\n<p>cyber awareness challenge 2022 cheat code<\/p>\n\n\n\n<p>cyber awareness challenge insider threat<\/p>\n\n\n\n<p>cyber awareness challenge jko<\/p>\n\n\n\n<p>cyber awareness how can you protect yourself from internet hoaxes<\/p>\n\n\n\n<p>cyber awareness jko<\/p>\n\n\n\n<p>cyber awareness training 2022<\/p>\n\n\n\n<p>cyber awarness 2022<\/p>\n\n\n\n<p>cyber security cbt<\/p>\n\n\n\n<p>define counterintelligence<\/p>\n\n\n\n<p>dfars cui<\/p>\n\n\n\n<p>disclosure con<\/p>\n\n\n\n<p>dod 5200.48<\/p>\n\n\n\n<p>dod cui training<\/p>\n\n\n\n<p>dod cyber awareness challenge 2022<\/p>\n\n\n\n<p>dod instruction 5200.48<\/p>\n\n\n\n<p>dod mandatory controlled unclassified information cui training<\/p>\n\n\n\n<p>dod mandatory controlled unclassified information training<\/p>\n\n\n\n<p>dod mandatory cui training<\/p>\n\n\n\n<p>dodi 5200.48<\/p>\n\n\n\n<p>email marking<\/p>\n\n\n\n<p>example of near field communication cyber awareness<\/p>\n\n\n\n<p>good practice to prevent spillage<\/p>\n\n\n\n<p>how can you avoid downloading malicious code cyber awareness challenge<\/p>\n\n\n\n<p>how can you protect yourself from internet hoaxes<\/p>\n\n\n\n<p>how can you protect yourself from internet hoaxes cyber awareness<\/p>\n\n\n\n<p>how can you protect yourself from social engineering cyber awareness<\/p>\n\n\n\n<p>how long is your non disclosure agreement applicable<\/p>\n\n\n\n<p>how long is your non-disclosure agreement applicable<\/p>\n\n\n\n<p>how many insider threat indicators does alex<\/p>\n\n\n\n<p>how many insider threat indicators does alex demonstrate<\/p>\n\n\n\n<p>how should you respond to the theft of your identity<\/p>\n\n\n\n<p>how to prevent spillage cyber awareness<\/p>\n\n\n\n<p>how to protect yourself from internet hoaxes<\/p>\n\n\n\n<p>i hate cbts cyber awareness<\/p>\n\n\n\n<p>identify the correct and incorrect statements about executive orders.<\/p>\n\n\n\n<p>if you are a military personnel and you knowingly leaked<\/p>\n\n\n\n<p>ihatecbts cyber awareness 2022<\/p>\n\n\n\n<p>inadvertent spillage<\/p>\n\n\n\n<p>information may be cui in accordance with executive order 13526<\/p>\n\n\n\n<p>intentional unauthorized disclosure of classified information<\/p>\n\n\n\n<p>internet hoaxes cyber awareness<\/p>\n\n\n\n<p>is it permitted to share an unclassified draft document<\/p>\n\n\n\n<p>is press release data sensitive information<\/p>\n\n\n\n<p>is whistleblowing the same as reporting an unauthorized disclosure<\/p>\n\n\n\n<p>isoo cui registry purpose<\/p>\n\n\n\n<p>isso cui registry<\/p>\n\n\n\n<p>itar cui<\/p>\n\n\n\n<p>itar vs cui<\/p>\n\n\n\n<p>jko cyber awareness<\/p>\n\n\n\n<p>jko cyber awareness 2022 answers<\/p>\n\n\n\n<p>jko cyber security<\/p>\n\n\n\n<p>malicious code cyber awareness<\/p>\n\n\n\n<p>mc requirements<\/p>\n\n\n\n<p>near field communication cyber awareness<\/p>\n\n\n\n<p>near field communication cyber awareness 2022<\/p>\n\n\n\n<p>network configuration for cui<\/p>\n\n\n\n<p>non federal systems<\/p>\n\n\n\n<p>opsec is a dissemination control category<\/p>\n\n\n\n<p>opsec is a dissemination control category within the cui program<\/p>\n\n\n\n<p>penalties for unauthorized disclosure of classified information<\/p>\n\n\n\n<p>portion mark<\/p>\n\n\n\n<p>portion markings<\/p>\n\n\n\n<p>possible effect of malicious code<\/p>\n\n\n\n<p>prevent spillage<\/p>\n\n\n\n<p>purpose of isoo cui registry<\/p>\n\n\n\n<p>relates to reporting of gross mismanagement and\/or abuse of authority<\/p>\n\n\n\n<p>requirements to access classified information<\/p>\n\n\n\n<p>sensitive but unclassified<\/p>\n\n\n\n<p>spillage definition cyber awareness<\/p>\n\n\n\n<p>the act of publicly documenting and sharing information is called<\/p>\n\n\n\n<p>the whistleblower protection enhancement act relates to reporting<\/p>\n\n\n\n<p>transfer email from nipr to sipr<\/p>\n\n\n\n<p>unauthorized disclosure of classified<\/p>\n\n\n\n<p>unauthorized disclosure of classified information<\/p>\n\n\n\n<p>unauthorized disclosure of classified information for dod and industry<\/p>\n\n\n\n<p>unauthorized disclosure of information classified as confidential<\/p>\n\n\n\n<p>unclassified banner<\/p>\n\n\n\n<p>unclassified cover sheet<\/p>\n\n\n\n<p>unclassified resume<\/p>\n\n\n\n<p>unnpi<\/p>\n\n\n\n<p>what can malicious code do cyber awareness challenge<\/p>\n\n\n\n<p>what dod instruction implements the dod program<\/p>\n\n\n\n<p>what is a possible effect of malicious code<\/p>\n\n\n\n<p>what is a possible effect of malicious code cyber awareness<\/p>\n\n\n\n<p>what is a protection against internet hoaxes<\/p>\n\n\n\n<p>what is a protection against internet hoaxes cyber awareness<\/p>\n\n\n\n<p>what is controlled<\/p>\n\n\n\n<p>what is possible effect of malicious code<\/p>\n\n\n\n<p>what is protection against internet hoaxes<\/p>\n\n\n\n<p>what is purpose of the isoo cui registry<\/p>\n\n\n\n<p>what is required for an individual to access classified data<\/p>\n\n\n\n<p>what is sensitive compartmented information cyber awareness 2022<\/p>\n\n\n\n<p>what is spillage cyber awareness<\/p>\n\n\n\n<p>what is spillage in cyber awareness<\/p>\n\n\n\n<p>what is the possible effect of malicious code<\/p>\n\n\n\n<p>what is the purpose of isoo cui registry<\/p>\n\n\n\n<p>what is the purpose of the isoo registry<\/p>\n\n\n\n<p>what level of damage can the unauthorized disclosure of information<\/p>\n\n\n\n<p>what security risk does a public wi-fi connection pose<\/p>\n\n\n\n<p>what should the owner of this printed sci do differently<\/p>\n\n\n\n<p>what should you do if you suspect spillage has occurred<\/p>\n\n\n\n<p>what threat do insiders with authorized<\/p>\n\n\n\n<p>what threat do insiders with authorized access to information<\/p>\n\n\n\n<p>what threat do insiders with authorized access to information pose<\/p>\n\n\n\n<p>when can you check personal email on your gfe<\/p>\n\n\n\n<p>when using social networking services the penalties for ignoring requirements<\/p>\n\n\n\n<p>which of the following individuals can access classified data 2022<\/p>\n\n\n\n<p>which of the following is an<\/p>\n\n\n\n<p>which of the following is an example of nfc<\/p>\n\n\n\n<p>which of the following is good practice to prevent spillage<\/p>\n\n\n\n<p>which of the following is not an<\/p>\n\n\n\n<p>which of the following is true about protecting classified data<\/p>\n\n\n\n<p>which of the following is true of protecting classified data<\/p>\n\n\n\n<p>which of the following may help prevent spillage<\/p>\n\n\n\n<p>which of the following may help to prevent spillage<\/p>\n\n\n\n<p>which of the following represents a good physical security practice<\/p>\n\n\n\n<p>which of these is true of unclassified data<\/p>\n\n\n\n<p>whistleblowing should be used to report which of the following<\/p>\n\n\n\n<p>who is responsible for applying cui markings and dissemination instructions<\/p>\n\n\n\n<p>working papers must be remarked within<\/p>\n\n\n\n<p>Which of the following is an example of malicious code? Software that install itself without the user&#8217;s knowledge.<\/p>\n\n\n\n<p>It is getting late on Friday. You are reviewing your employees annual self evaluation. Your comments are due on Monday. You can email your employees information to yourself so you can work on it this weekend and go home now. Which method would be the BEST way to send this information?<br>Use the government email system so you can encrypt the information and open the email on your government issued laptop<\/p>\n\n\n\n<p>What should you do if someone asks to use your government issued mobile device (phone\/laptop..etc)?<br>Decline to lend your phone \/ laptop<\/p>\n\n\n\n<p>Where should you store PII \/ PHI?<br>Information should be secured in a cabinet or container while not in use<\/p>\n\n\n\n<p>Of the following, which is NOT an intelligence community mandate for passwords?<br>Maximum password age of 45 days<\/p>\n\n\n\n<p>Which of the following is NOT Government computer misuse?<br>Checking work email<\/p>\n\n\n\n<p>Which is NOT a telework guideline?<br>Taking classified documents from your workspace<\/p>\n\n\n\n<p>What should you do if someone forgets their access badge (physical access)?<br>Alert the security office<\/p>\n\n\n\n<p>What can you do to protect yourself against phishing?<br>All of the above<\/p>\n\n\n\n<p>What should you do to protect classified data?<br>Answer 1 and 2 are correct<\/p>\n\n\n\n<p>What action is recommended when somebody calls you to inquire about your work environment or specific account information?<br>Ask them to verify their name and office number<\/p>\n\n\n\n<p>If classified information were released, which classification level would result in &#8220;Exceptionally grave damage to national security&#8221;?<br>Top Secret<\/p>\n\n\n\n<p>Which of the following is NOT considered sensitive information?<br>Sanitized information gathered from personnel records<\/p>\n\n\n\n<p>Which of the following is NOT a criterion used to grant an individual access to classified data?<br>Senior government personnel, military or civilian<\/p>\n\n\n\n<p>Of the following, which is NOT a problem or concern of an Internet hoax?<br>Directing you to a website that looks real<\/p>\n\n\n\n<p>Media containing Privacy Act information, PII, and PHI is not required to be labeled.<br>FALSE<\/p>\n\n\n\n<p>Which of the following is NOT a home security best practice?<br>Setting weekly time for virus scan when you are not on the computer and it is powered off<\/p>\n\n\n\n<p>Which of the following best describes wireless technology?<br>It is inherently not a secure technology<\/p>\n\n\n\n<p>You are leaving the building where you work. What should you do?<br>Remove your security badge<\/p>\n\n\n\n<p>Which of the following is a good practice to avoid email viruses?<br>Delete email from senders you do not know<\/p>\n\n\n\n<p>What is considered a mobile computing device and therefore shouldn&#8217;t be plugged in to your Government computer?<br>All of the above<\/p>\n\n\n\n<p>Which is NOT a way to protect removable media?<br>As a best practice, labeling all classified removable media and considering all unlabeled removable media as unclassified<\/p>\n\n\n\n<p>What is NOT Personally Identifiable Information (PII)?<br>Hobby<\/p>\n\n\n\n<p>Of the following, which is NOT a method to protect sensitive information?<br>After work hours, storing sensitive information in unlocked containers, desks, or cabinets if security is not present<\/p>\n\n\n\n<p>There are many travel tips for mobile computing. Which of the following is NOT one?<br>When using a public device with a card reader, only use your DoD CAC to access unclassified information<\/p>\n\n\n\n<p>The use of webmail is<br>is only allowed if the organization permits it<\/p>\n\n\n\n<p>What is considered ethical use of the Government email system?<br>Distributing Company newsletter<\/p>\n\n\n\n<p>Which of the following attacks target high ranking officials and executives?<br>Whaling<\/p>\n\n\n\n<p>What constitutes a strong password?<br>all of the above<\/p>\n\n\n\n<p>You are logged on to your unclassified computer and just received an encrypted email from a co-worker. The email has an attachment whose name contains the word &#8220;secret&#8221;. What should you do?<br>Contact your security POC right away<\/p>\n\n\n\n<p>Which is a way to protect against phishing attacks?<br>Look for digital certificates<\/p>\n\n\n\n<p>You receive an email from a company you have an account with. The email states your account has been compromised and you are invited to click on the link in order to reset your password. What action should you take?<br>Notify security<\/p>\n\n\n\n<p>You are having lunch at a local restaurant outside the installation, and you find a cd labeled &#8220;favorite song&#8221;. What should you do?<br>Leave the cd where it is<\/p>\n\n\n\n<p>How should you securely transport company information on a removable media?<br>Encrypt the removable media<\/p>\n\n\n\n<p>Should you always label your removable media?<br>Yes<\/p>\n\n\n\n<p>Which of the following is NOT Protected Health Information (PHI)?<br>Medical care facility name<\/p>\n\n\n\n<p>If authorized, what can be done on a work computer?<br>Check personal email<\/p>\n\n\n\n<p>Spear Phishing attacks commonly attempt to impersonate email from trusted entities. What security device is used in email to verify the identity of sender?<br>Digital Signatures<\/p>\n\n\n\n<p>What type of security is &#8220;part of your responsibility&#8221; and &#8220;placed above all else?&#8221;<br>Physical<\/p>\n\n\n\n<p>If your wireless device is improperly configured someone could gain control of the device? T\/F<br>TRUE<\/p>\n\n\n\n<p>Which of the following is a proper way to secure your CAC\/PIV?<br>Remove and take it with you whenever you leave your workstation<\/p>\n\n\n\n<p>What actions should you take prior to leaving the work environment and going to lunch?<br>All of the above<\/p>\n\n\n\n<p>P2P (Peer-to-Peer) software can do the following except:<br>Allow attackers physical access to network assets<\/p>\n\n\n\n<p>How can you guard yourself against Identity theft?<br>All of the above<\/p>\n\n\n\n<p>When leaving your work area, what is the first thing you should do?<br>Remove your CAC\/PIV<\/p>\n\n\n\n<p>Using webmail may bypass built in security features.<br>TRUE<\/p>\n\n\n\n<p>Of the following, which is NOT a characteristic of a phishing attempt?<br>Directing you to a web site that is real<\/p>\n\n\n\n<p>Classified Information can only be accessed by individuals with<br>All of the above<\/p>\n\n\n\n<p>Which of the following definitions is true about disclosure of confidential information?<br>Damage to national security<\/p>\n\n\n\n<p>It is permissible to release unclassified information to the public prior to being cleared.<br>False<\/p>\n\n\n\n<p>Which of the following is NOT sensitive information?<br>Unclassified information cleared for public release<\/p>\n\n\n\n<p>What should you do to protect yourself while on social networks?<br>Validate all friend requests through another source before confirming them<\/p>\n\n\n\n<p>Which is NOT a method of protecting classified data?<br>Assuming open storage is always authorized in a secure facility<\/p>\n\n\n\n<p>What can you do to prevent spillage?<br>all of the above<\/p>\n\n\n\n<p>Which of the following makes Alex&#8217;s personal information vulnerable to attacks by identity thieves?<br>Carrying his Social Security Card with him<\/p>\n\n\n\n<p>DoD employees are prohibited from using a DoD CAC in card-reader-enabled public device<br>TRUE<\/p>\n\n\n\n<p>Which of the following is an example of malicious code?<br>Trojan horses<\/p>\n\n\n\n<p>Which of the following is NOT PII?<br>Mother&#8217;s maiden name<\/p>\n\n\n\n<p>Classified Information is<br>Assigned a classification level by a supervisor<\/p>\n\n\n\n<p>Maria is at home shopping for shoes on Amazon.com. Before long she has also purchased shoes from several other websites. What can be used to track Maria&#8217;s web browsing habits?<br>Cookies<\/p>\n\n\n\n<p>Which is an untrue statement about unclassified data?<br>If aggregated, the classification of the information may not be changed<\/p>\n\n\n\n<p>A medium secure password has at least 15 characters and one of the following.<br>Special character<\/p>\n\n\n\n<p>PII, PHI, and financial information is classified as what type of information?<br>Sensitive<\/p>\n\n\n\n<p>The CAC\/PIV is a controlled item and contains certificates for:<br>All of the above<\/p>\n\n\n\n<p>An individual who has attempted to access sensitive information without need-to-know and has made unusual requests for sensitive information is displaying indicators of what?<br>Potential Insider Threat<\/p>\n\n\n\n<p>Which of the following is NOT a social engineering tip?<br>Following instructions from verified personnel<\/p>\n\n\n\n<p>Bob, a coworker, has been going through a divorce, has financial difficulties and is displaying hostile behavior. How many potential insider threat indicators is Bob displaying?<br>3<\/p>\n\n\n\n<p>You are working at your unclassified system and receive an email from a coworker containing a classified attachment. What should you do?<br>Alert your security POC<\/p>\n\n\n\n<p>You check your bank statement and see several debits you did not authorize. You believe that you are a victim of identity theft. Which of the following should you do immediately?<br>Monitor credit card statements for unauthorized purchases<\/p>\n\n\n\n<p>Thumb drives, memory sticks, and flash drives are examples of<br>Removable media<\/p>\n\n\n\n<p>What information relates to the physical or mental health of an individual?<br>PHI<\/p>\n\n\n\n<p>What should be done if you find classified Government Data\/Information Not Cleared for Public Release on the Internet?<br>Make note of any identifying information and the website URL and report it to your security office<\/p>\n\n\n\n<p>All https sites are legitimate and there is no risk to entering your personal info online.<br>FALSE<\/p>\n\n\n\n<p>When using a fax machine to send sensitive information, the sender should do which of the following?<br>Contact the recipient to confirm receipt<\/p>\n\n\n\n<p>What should be done to protect against insider threats?<br>Report any suspicious behavior<\/p>\n\n\n\n<p>Which of the following is NOT a potential insider threat?<br>Member of a religion or faith<\/p>\n\n\n\n<p>Of the following, which is NOT a security awareness tip?<br>Remove security badge as you enter a restaurant or retail establishment<\/p>\n\n\n\n<p>ActiveX is a type of this?<br>Mobile code<\/p>\n\n\n\n<p>Which of the following is NOT a security best practice when saving cookies to a hard drive?<br>Looking for &#8220;https&#8221; in the URL. All https sites are legitimate.<\/p>\n\n\n\n<p>Which is NOT a requirement for telework?<br>Telework is only authorized for unclassified and confidential information<\/p>\n\n\n\n<p>Someone calls from an unknown number and says they are from IT and need some information about your computer. What should you do?<br>Request the user&#8217;s full name and phone number<\/p>\n\n\n\n<p>Which is NOT a wireless security practice?<br>Turning off computer when not in use<\/p>\n\n\n\n<p>Malicious code can do the following except?<br>Make your computer more secure<\/p>\n\n\n\n<p>What type of data must be handled and stored properly based on classification markings and handling caveats?<br>Classified<\/p>\n\n\n\n<p>What information should you avoid posting on social networking sites?<br>All of the above<\/p>\n\n\n\n<p>A coworker has left an unknown CD on your desk. What should you do?<br>Put the CD in the trash<\/p>\n\n\n\n<p>Which of the following is NOT a DoD special requirement for tokens?<br>Using NIPRNet tokens on systems of higher classification level<\/p>\n\n\n\n<p>UNCLASSIFIED is a designation to mark information that does not have potential to damage national security.<br>TRUE<\/p>\n\n\n\n<p>You receive a call on your work phone and you&#8217;re asked to participate in a phone survey. As part of the survey the caller asks for birth date and address. What type of attack might this be?<br>Social Engineering<\/p>\n\n\n\n<p>&#8220;Spillage&#8221; occurs when<br>Personal information is inadvertently posted at a website<\/p>\n\n\n\n<p>What should be done to sensitive data on laptops and other mobile computing devices?<br>Encrypt the sensitive data<\/p>\n\n\n\n<p>Which of the following should be done to keep your home computer secure?<br>All of the above<\/p>\n\n\n\n<p>How are Trojan horses, worms, and malicious scripts spread?<br>By email attachments<\/p>\n\n\n\n<p>The following practices help prevent viruses and the downloading of malicious code except.<br>Scan external files from only unverifiable sources before uploading to computer<\/p>\n\n\n\n<p>Questions and Answers<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>1.&nbsp;Which of the below is not used for Multi-factor authentication?<ul><li>A.&nbsp;Something you do<\/li><li>B.&nbsp;Something you have<\/li><li>C.&nbsp;Something you know<\/li><li>D.&nbsp;Something you are<\/li><\/ul><strong>Correct Answer<\/strong><br>A. Something you do<strong>Explanation<\/strong><br>&#8220;Something you do&#8221; is not used for multi-factor authentication. Multi-factor authentication typically involves using a combination of two or more factors to verify a user&#8217;s identity. These factors can include &#8220;something you have&#8221; (such as a physical token or a mobile device), &#8220;something you know&#8221; (such as a password or PIN), and &#8220;something you are&#8221; (such as biometric data like fingerprints or facial recognition). However, &#8220;something you do&#8221; refers to behavioral biometrics, which is a separate authentication method that analyzes patterns of behavior, such as typing speed or mouse movements, to verify identity.Rate this question:<\/li>\n\n\n\n<li>2.&nbsp;Which of the below is not a best practice of choosing Strong Passwords?<ul><li>A.&nbsp;Make it impersonal<\/li><li>B.&nbsp;Make it long<\/li><li>C.&nbsp;Make it diverse<\/li><li>D.&nbsp;Make it numeric<\/li><\/ul><strong>Correct Answer<\/strong><br>D. Make it numeric<strong>Explanation<\/strong><br>Making a password numeric is actually a best practice for choosing strong passwords. Including numbers in a password adds complexity and makes it harder for attackers to guess or crack the password. Therefore, the given answer is incorrect.Rate this question:<\/li>\n\n\n\n<li>3.&nbsp;Which of the below is not a part of the Clean Desk Policy?<ul><li>A.&nbsp;Tidy your desk<\/li><li>B.&nbsp;Lock your screen<\/li><li>C.&nbsp;Hiding passwords below keyboard<\/li><li>D.&nbsp;Put away sensitive documents<\/li><\/ul><strong>Correct Answer<\/strong><br>C. Hiding passwords below keyboard<strong>Explanation<\/strong><br>The Clean Desk Policy aims to maintain a clutter-free and secure work environment. Tidying your desk, locking your screen, and putting away sensitive documents are all practices that align with this policy. However, hiding passwords below the keyboard is not a part of the Clean Desk Policy. This action poses a security risk as it makes it easier for unauthorized individuals to access sensitive information.Rate this question:<\/li>\n\n\n\n<li>4.&nbsp;Which of the below is not a part of the appropriate use &#8211; Laptop Security Policy?<ul><li>A.&nbsp;Return your laptop when you resign<\/li><li>B.&nbsp;Prevent damage to loss\/theft of Laptop<\/li><li>C.&nbsp;Report loss of Laptop to HR &amp; IT Department<\/li><li>D.&nbsp;Install any software without approval<\/li><\/ul><strong>Correct Answer<\/strong><br>D. Install any software without approval<strong>Explanation<\/strong><br>The correct answer is &#8220;Install any software without approval.&#8221; This is not a part of the appropriate use &#8211; Laptop Security Policy because it can pose a security risk to the laptop and the network. Installing software without approval can introduce malware or other malicious programs, compromise the laptop&#8217;s security, and violate company policies. It is important to obtain proper approval before installing any software to ensure the security and integrity of the laptop and the organization&#8217;s network.Rate this question:<\/li>\n\n\n\n<li>5.&nbsp;Which of the below is not a part of the appropriate use &#8211; Email Security Policy?<ul><li>A.&nbsp;Don&#8217;t access your personal email account<\/li><li>B.&nbsp;Use official Email ID for personal purposes<\/li><li>C.&nbsp;Don&#8217;t send spam<\/li><li>D.&nbsp;Don&#8217;t do Email Forging<\/li><\/ul><strong>Correct Answer<\/strong><br>B. Use official Email ID for personal purposes<strong>Explanation<\/strong><br>The statement &#8220;Use official Email ID for personal purposes&#8221; is not a part of the appropriate use &#8211; Email Security Policy. This policy is designed to ensure the security and confidentiality of email communication within an organization. Using official email IDs for personal purposes may compromise the security of sensitive information and increase the risk of unauthorized access or data breaches. It is important to separate personal and official email accounts to maintain the integrity of the organization&#8217;s email security policy.Rate this question:<\/li>\n\n\n\n<li>6.&nbsp;When receiving a Email from a unknown contact that has an attachment, you should:<ul><li>A.&nbsp;Open the attachment to view its contents<\/li><li>B.&nbsp;Delete the mail<\/li><li>C.&nbsp;Forward the email to your co-workers to allow them to open the attachment first<\/li><li>D.&nbsp;Forward the email to your personal email account so you can open it at home<\/li><\/ul><strong>Correct Answer<\/strong><br>B. Delete the mail<strong>Explanation<\/strong><br>When receiving an email from an unknown contact that has an attachment, it is recommended to delete the mail. Opening the attachment can pose a security risk as it may contain malware or viruses that can harm your computer or compromise your personal information. Forwarding the email to co-workers or personal email accounts can potentially spread the risk to others or expose personal information to unauthorized individuals. Therefore, the safest course of action is to delete the email to protect yourself and your system from potential harm.Rate this question:<\/li>\n\n\n\n<li>7.&nbsp;The mouse on your computer begins moving across the screen and clicking on things without you even touching it. What will you do?<ul><li>A.&nbsp;Unplug your mouse<\/li><li>B.&nbsp;Disconnect your computer from the network &amp; call the IT Support Desk<\/li><li>C.&nbsp;Turn your computer OFF<\/li><li>D.&nbsp;Call your colleagues over so they can see this miracle!<\/li><\/ul><strong>Correct Answer<\/strong><br>B. Disconnect your computer from the network &amp; call the IT Support Desk<strong>Explanation<\/strong><br>If the mouse on your computer is moving and clicking on things without you touching it, it is likely that your computer has been compromised by malware or a hacker. Disconnecting your computer from the network is important to prevent further unauthorized access or potential damage. Calling the IT Support Desk is necessary to report the incident and seek assistance in resolving the issue and ensuring the security of your computer system.Rate this question:<\/li>\n\n\n\n<li>8.&nbsp;Which of the following is an Online Malware Scanning Service for suspicious files and URLs?<ul><li>A.&nbsp;Www.serials.ws<\/li><li>B.&nbsp;Www.crackme.us<\/li><li>C.&nbsp;Www.totalvirus.com<\/li><li>D.&nbsp;Www.virustotal.com<\/li><\/ul><strong>Correct Answer<\/strong><br>D. Www.virustotal.com<strong>Explanation<\/strong><br>www.virustotal.com is an online malware scanning service that allows users to scan suspicious files and URLs for potential malware or viruses. It provides a comprehensive analysis by using multiple antivirus engines and other tools to detect any malicious content. Users can upload files or enter URLs to be scanned, and the service provides detailed reports on the potential threats found. It is a trusted platform used by individuals and organizations to ensure the safety of their files and websites.Rate this question:<\/li>\n\n\n\n<li>9.&nbsp;When is the best time to lie to your information security auditor or officer?<ul><li>A.&nbsp;If you want to cover up your best friend\u2019s faults or mistakes<\/li><li>B.&nbsp;If the security auditor is not your friend and cannot be trusted<\/li><li>C.&nbsp;If it impacts the termination of the key people in your organization<\/li><li>D.&nbsp;None of the above<\/li><\/ul><strong>Correct Answer<\/strong><br>D. None of the above<strong>Explanation<\/strong><br>The best time to lie to your information security auditor or officer is never. Lying to cover up someone else&#8217;s faults or mistakes, or because you don&#8217;t trust the auditor, or to protect key people in your organization is unethical and can have serious consequences. It is always best to be honest and transparent with auditors and officers to maintain the integrity and security of the organization&#8217;s information.Rate this question:<\/li>\n\n\n\n<li>10.&nbsp;You went to Starbucks\/CCD to buy a coffee and then while waiting for your order, you decided to connect to their Free WIIFI. While browsing your Google Mail (https:\/\/mail.google.com\/), the page redirects to http:\/\/www.googlemail.anish.net. What do you think should you do?<ul><li>A.&nbsp;Login to where Google Mail has redirected, it\u2019s just one of Google\u2019s web sites \u2013 not suspicious at all.<\/li><li>B.&nbsp;Disconnect to Starbucks\/CCD WIFI network.<\/li><li>C.&nbsp;Ask the person sitting next to you if his Google Mail also redirects to http:\/\/www.googlemail.anish.net.<\/li><li>D.&nbsp;Find the Wireless Access Point (Wi-Fi device) and reboot it<\/li><\/ul><strong>Correct Answer<\/strong><br>B. Disconnect to Starbucks\/CCD WIFI network.<strong>Explanation<\/strong><br>The correct answer is to disconnect from the Starbucks\/CCD WIFI network. This is because when browsing Google Mail, the page redirects to a suspicious website (http:\/\/www.googlemail.anish.net) instead of the legitimate Google Mail website (https:\/\/mail.google.com\/). This could indicate a potential security threat or a man-in-the-middle attack. To ensure the safety of personal information, it is best to disconnect from the WIFI network to prevent any unauthorized access or data breach.Rate this question:<\/li>\n\n\n\n<li>11.&nbsp;Which of the following could help you mitigate malwares and viruses from infecting your PC?<ul><li>A.&nbsp;Download software from trusted sources only<\/li><li>B.&nbsp;Install an antivirus program and enable firewall<\/li><li>C.&nbsp;Always update your PC when prompted for system updates<\/li><li>D.&nbsp;Monitor and analyze the network traffic of your PC<\/li><\/ul><strong>Correct Answer<\/strong><br>B. Install an antivirus program and enable firewall<\/li>\n\n\n\n<li>12.&nbsp;You have a hard copy of a design document that you want to dispose of. What would you do?<ul><li>A.&nbsp;Throw it in any dustbin<\/li><li>B.&nbsp;Shred it using a shredder<\/li><li>C.&nbsp;Give it to the office boy to reuse it for other purposes<\/li><li>D.&nbsp;Be environment friendly and reuse it for writing<\/li><\/ul><strong>Correct Answer<\/strong><br>B. Shred it using a shredder<strong>Explanation<\/strong><br>Shredding the hard copy of the design document is the correct answer because it ensures that the sensitive information contained in the document is destroyed and cannot be accessed by unauthorized individuals. This helps to protect the confidentiality of the information and prevent any potential misuse or data breaches. Shredding is a secure and reliable method of disposing of confidential documents.Rate this question:<\/li>\n\n\n\n<li>13.&nbsp;What is social engineering?<ul><li>A.&nbsp;A group planning for a social activity in the organization<\/li><li>B.&nbsp;Creating a situation wherein a third party gains confidential information from you<\/li><li>C.&nbsp;The organization planning an activity for welfare of the neighbourhood<\/li><li>D.&nbsp;None of the above<\/li><\/ul><strong>Correct Answer<\/strong><br>B. Creating a situation wherein a third party gains confidential information from you<strong>Explanation<\/strong><br>Social engineering refers to the act of manipulating individuals into divulging confidential information or performing actions that may compromise their security. This can be done through various techniques such as impersonation, deception, or psychological manipulation. The correct answer states that social engineering involves creating a situation where a third party gains confidential information from the individual, which accurately describes the concept. It is important to be aware of social engineering tactics to protect oneself from potential security breaches.Rate this question:<\/li>\n\n\n\n<li>14.&nbsp;How can you report a security incident?<ul><li>A.&nbsp;Email<\/li><li>B.&nbsp;Phone<\/li><li>C.&nbsp;Any of the above<\/li><li>D.&nbsp;None of the above<\/li><\/ul><strong>Correct Answer<\/strong><br>C. Any of the above<strong>Explanation<\/strong><br>The correct answer is &#8220;Any of the above&#8221; because reporting a security incident can be done through various means, including email and phone. This allows individuals to choose the most convenient method for them to report the incident and ensure that it is communicated to the appropriate authorities.Rate this question:<\/li>\n\n\n\n<li>15.&nbsp;You see a non familiar face in the access controlled areas of our office, the person does not have the a ITZCASH ID\/Visitor\/Vendor tag with him. What would you do?<ul><li>A.&nbsp;None of my business, let some body else take care of it<\/li><li>B.&nbsp;Ask the person to leave the facility<\/li><li>C.&nbsp;Escort the person to the security and raise a security incident<\/li><li>D.&nbsp;Scream and yell till the person leaves<\/li><\/ul><strong>Correct Answer<\/strong><br>C. Escort the person to the security and raise a security incident<strong>Explanation<\/strong><br>If a non-familiar face is seen in the access controlled areas of the office without any proper identification, the appropriate action would be to escort the person to the security and raise a security incident. This ensures that the person is properly addressed and investigated by the security team, maintaining the safety and security protocols of the office.<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This article will provide you with all the questions and answers for Cyber Awareness Challenge. ActiveX is a type of this? -Mobile code All https sites are legitimate and there is no risk to entering your personal info online. -FALSE Bob, a coworker, has been going through a divorce, has financial difficulties and is displaying [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[25],"tags":[],"class_list":["post-117147","post","type-post","status-publish","format-standard","hentry","category-exams-certification"],"_links":{"self":[{"href":"https:\/\/www.learnexams.com\/blog\/wp-json\/wp\/v2\/posts\/117147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.learnexams.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.learnexams.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.learnexams.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.learnexams.com\/blog\/wp-json\/wp\/v2\/comments?post=117147"}],"version-history":[{"count":0,"href":"https:\/\/www.learnexams.com\/blog\/wp-json\/wp\/v2\/posts\/117147\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.learnexams.com\/blog\/wp-json\/wp\/v2\/media?parent=117147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.learnexams.com\/blog\/wp-json\/wp\/v2\/categories?post=117147"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.learnexams.com\/blog\/wp-json\/wp\/v2\/tags?post=117147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}