in Internet by (257k points)
edited ago by

Cyber Awareness Challenge 2024 - MCQs Answer

This post contains a collection of most asked questions and answers of Cyber Awareness Challenge quiz.

The course provides practical knowledge and best practices to keep systems secure at home and at workplace.


Scroll down for most common questions and answers.

Additionally, you can use  Search Box  above or, visit this page for all answer (500+ questions).

Please log in or register to answer this question.

2 Answers

0 votes
by (973k points)
edited ago by
 
Best answer

Cyber Awareness Challenge 2024 - MCQs Answer (PART - 1)


1. Which of the following may be helpful to prevent spillage?
 → Label all files, removable media, and subject headers with appropriate classification markings.

2. Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?
 → Secret

3. What is a good practice to protect classified information?
 → Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material.

4. What threat do insiders with authorized access to information or information systems pose?
 → They may wittingly or unwittingly use their authorized access to perform actions that result in the loss or degradation of resources or capabilities.

5. Which of the following is NOT considered a potential insider threat indicator?
 → New interest in learning a foreign language.

6. When may you be subject to criminal, disciplinary, and/or administrative action due to online misconduct?
 → If you participate in or condone it at any time.

7. When is the safest time to post details of your vacation activities on your social networking profile?
 → After you have returned home following the vacation.

8. Which of the following is a security best practice when using social networking sites?
→ Understanding and using the available privacy settings.

9. Within a secure area, you see an individual who you do not know and is not wearing a visible badge
 → Ask the individual to see an identification badge.

10. What certificates does the Common Access Card (CAC) or Personal Identity Verification (PIV) card contain?
 → Identification, encryption, and digital signature

11. When faxing Sensitive Compartmented Information (SCI), what actions should you take?
 → Mark SCI documents appropriately and use an approved SCI fax machine.

12. When is it appropriate to have your security badge visible within a sensitive compartmented information facility (SCIF)?
 → At all times while in the facility.

13. When using your government-issued laptop in public environments, with which of the following should you be concerned?
 → The potential for unauthorized viewing of work-related information displayed on your screen.

14. Under what circumstances is it acceptable to check personal email on Government-furnished equipment (GFE)?
 → If your organization allows it.

15. Which of the following is NOT a best practice to protect data on your mobile computing device?
 → Lock your device screen when not in use and require a password to reactivate.

16. How can you protect your information when using wireless technology?
 → Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.

17. What action should you take when using removable media in a Sensitive Compartmented Information Facility (SCIF)?
 → Identify and disclose it with local Configuration/Change Management Control and Property Management authorities

18. Which of the following is NOT a way malicious code spreads?
 → Legitimate software updates

19. Which of the following statements is true of cookies?
 → You should only accept cookies from reputable, trusted websites.

20. How can you protect yourself from internet hoaxes?
 → Use online sites to confirm or expose potential hoaxes

21. How can you protect yourself from social engineering?
 → Follow instructions given only by verified personnel

22. What action should you take with an e-mail from a friend containing a compressed Uniform Resource Locator (URL)?
 → Investigate the link's actual destination using the preview feature

23. Which of the following is a concern when using your Government-issued laptop in public?
 → Others may be able to view your screen.

24. What is a critical consideration on using cloud-based file sharing and storage applications on your Government-furnished equipment (GFE)?
 → Determine if the software or service is authorized

25. Is it permitted to share an unclassified draft document with a non-DoD professional discussion group?
 → As long as the document is cleared for public release, you may release it outside of DoD.

26. Which of the following is NOT a good way to protect your identity?
 → Use a single, complex password for your system and application logons.

27. Which of the following statements is TRUE about the use of DoD Public Key Infrastructure (PKI) tokens?
 → Always use DoD PKI tokens within their designated classification level.

28. Which of the following is an example of near field communication (NFC)?
 → A smartphone that transmits credit card payment information when held in proximity to a credit card reader.

29. Which of the following is NOT a typical means for spreading malicious code?
 → Patching from a trusted source

30. What should you do if a reporter asks you about potentially classified information on the web?
 → Refer the reporter to your organization's public affairs office.

31. Which of the following is a good practice to aid in preventing spillage?
 → Be aware of classification markings and all handling caveats.

32. What should you do when you are working on an unclassified system and receive an email with a classified attachment?
 → Call your security point of contact immediately.

33. What is required for an individual to access classified data?
 → Appropriate clearance; signed and approved non-disclosure agreement; and need-to-know.

34. When classified data is not in use, how can you protect it?
 → Store classified data appropriately in a GSA-approved vault/container.

35. What type of activity or behavior should be reported as a potential insider threat?
 → Coworker making consistent statements indicative of hostility or anger toward the United States and its policies.

36. What advantages do "insider threats" have over others that allows them to cause damage to their organizations more easily?
 → Insiders are given a level of trust and have authorized access to Government information systems.
 

ago by (735k points)
Thanks a lot, You literally saved me!
0 votes
by (973k points)
edited ago by

Cyber Awareness Challenge 2024 - MCQs Answer (PART - 2)


37. When is the safest time to post details of your vacation activities on your social networking website?
 → When your vacation is over, after you have returned home

38. What level of damage can the unauthorized disclosure of information classified as confidential reasonably be expected to cause?
 → Damage to national security

39. Which is a best practice that can prevent viruses and other malicious code from being downloaded when checking your e-mail?
 → Do not access website links, buttons, or graphics in e-mail

40. What type of social engineering targets particular individuals, groups of people, or organizations?
 → Spear phishing

41. What should you do after you have ended a call from a reporter asking you to confirm potentially classified information found on the web?
 → Alert your security point of contact.

42. Which of the following practices may reduce your appeal as a target for adversaries seeking to exploit your insider status?
 → Remove your security badge after leaving your controlled area or office building.

43. What type of unclassified material should always be marked with a special handling caveat?
 → For Official Use Only (FOUO)

44. Which of the following represents a good physical security practice?
 → Use your own security badge, key code, or Common Access Card (CAC)/Personal Identity Verification (PIV) card.

45. What certificates are contained on the Common Access Card (CAC)?
 → Identification, encryption, and digital signature
 

46. What describes how Sensitive Compartmented Information is marked?
 → Approved Security Classification Guide (SCG)
 

47. What should you do if a commercial entity, such as a hotel reception desk, asks to make a photocopy of your Common Access Card (CAC) for proof of Federal Government employment?
 → Do not allow your CAC to be photocopied.

48. Which of the following best describes the compromise of Sensitive Compartmented Information (SCI)?
 → A person who does not have the required clearance or assess caveats comes into possession of SCI in any manner.

49. What portable electronic devices (PEDs) are allow in a Secure Compartmented Information Facility (SCIF)?
 → Government-owned PEDs, if expressly authorized by your agency.

50. Which of the following is NOT a way that malicious code spreads?
 → Legitimate software updates

51. When can you check personal e-mail on your Government-furnished equipment (GFE)?
 → If allowed by organizational policy

52. When can you use removable media on a Government system?
 → When operationally necessary, owned by your organization, and approved by the appropriate authority

53. Upon connecting your Government-issued laptop to a public wireless connection, what should you immediately do?
 → Connect to the Government Virtual Private Network (VPN).

54. A coworker has asked if you want to download a programmer's game to play at work. What should be your response?
 → I'll pass

55. What is a good practice to protect data on your home wireless systems?
 → Ensure that the wireless security features are properly configured.

56. When may you be subjected to criminal, disciplinary, and/or administrative action due to online misconduct?
 → If you participate in or condone it at any time

57. Which Cyberspace Protection Condition (CPCON) establishes a protection priority focus on critical and essential functions only?
 → CPCON 2 (High: Critical and Essential Functions)

58. What certificates are contained on the Common Access Card (CAC)?
 → Identification, encryption, and digital signature

59. What guidance is available from marking Sensitive Information information (SCI)?
 → Security Classification Guide (SCG)

60. What must the dissemination of information regarding intelligence sources, methods, or activities follow?
 → The Director of National Intelligence.

61. If an incident occurs involving removable media in a Sensitive Compartmented Information Facility (SCIF), what action should you take?
 → Notify your security point of contact

62. Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your email?
 → Do not access links or hyperlinked media such as buttons and graphics in email messages.

63. Which of the following is a best practice to protect information about you and your organization on social networking sites and applications?
 → Use only personal contact information when establishing personal social networking accounts, never use Government contact information.

64. You receive an email from the Internal Revenue Service (IRS) demanding immediate payment of back taxes of which you were not aware. The email provides a website and a toll-free number where you can make payment. What action should you take?
 → Contact the IRS

65. A colleague vacations at the beach every year, is married and a father of four, his work quality is sometimes poor, and he is pleasant to work with. How many potential insider threat indicators does this employee display?
 → 0 indicators

66. A colleague has won 10 high-performance awards, can be playful and charming, is not currently in a relationship, and is occasionally aggressive in trying to access sensitive information. How many potential insiders threat indicators does this employee display?
 → 1 indicator

67. A colleague has visited several foreign countries recently, has adequate work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his car repossessed. How many potential insiders threat indicators does this employee display?
 → 3 or more indicators

68. A colleague complains about anxiety and exhaustion, makes coworkers uncomfortable by asking excessive questions about classified projects, and complains about the credit card bills that his wife runs up. How many potential insiders threat indicators does this employee display?
 → 3 or more indicators

69. Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague is playful and charming, consistently wins performance awards, and is occasionally aggressive in trying to access classified information.
 → 1 indicators

70. Based on the description below how many potential insider threat indicators are present? A colleague often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?
→ 3 or more indicators
 

Related questions

...