100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

Annual DoD Cyber Awareness Challenge Exam

Rating
-
Sold
-
Pages
7
Grade
A+
Uploaded on
04-12-2023
Written in
2023/2024

Annual DoD Cyber Awareness Challenge Exam It is getting late on Friday. You are reviewing your employees annual self evaluation. Your comments are due on Monday. You can email your employees information to yourself so you can work on it this weekend and go home now. Which method would be the BEST way to send this information? - ANS Use the government email system so you can encrypt the information and open the email on your government issued laptop What should you do if someone asks to use your government issued mobile device (phone/laptop..etc)? - ANS Decline to lend your phone / laptop Where should you store PII / PHI? - ANS Information should be secured in a cabinet or container while not in use Of the following, which is NOT an intelligence community mandate for passwords? - ANS Maximum password age of 45 days Which of the following is NOT Government computer misuse? - ANS Checking work email Which is NOT a telework guideline? - ANS Taking classified documents from your workspace What should you do if someone forgets their access badge (physical access)? - ANS Alert the security office What can you do to protect yourself against phishing? - ANS All of the above What should you do to protect classified data? - ANS Answer 1 and 2 are correct What action is recommended when somebody calls you to inquire about your work environment or specific account information? - ANS Ask them to verify their name and office number If classified information were released, which classification level would result in "Exceptionally grave damage to national security"? - ANS Top Secret Which of the following is NOT considered sensitive information? - ANS Sanitized information gathered from personnel records Which of the following is NOT a criterion used to grant an individual access to classified data? - ANS Senior government personnel, military or civilian Of the following, which is NOT a problem or concern of an Internet hoax? - ANS Directing you to a website that looks real Media containing Privacy Act information, PII, and PHI is not required to be labeled. - ANS FALSE Which of the following is NOT a home security best practice? - ANS Setting weekly time for virus scan when you are not on the computer and it is powered off Which of the following best describes wireless technology? - ANS It is inherently not a secure technology You are leaving the building where you work. What should you do? - ANS Remove your security badge Which of the following is a good practice to avoid email viruses? - ANS Delete email from senders you do not know What is considered a mobile computing device and therefore shouldn't be plugged in to your Government computer? - ANS All of the above Which is NOT a way to protect removable media? - ANS As a best practice, labeling all classified removable media and considering all unlabeled removable media as unclassified What is NOT Personally Identifiable Information (PII)? - ANS Hobby Of the following, which is NOT a method to protect sensitive information? - ANS After work hours, storing sensitive information in unlocked containers, desks, or cabinets if security is not present There are many travel tips for mobile computing. Which of the following is NOT one? - ANS When using a public device with a card reader, only use your DoD CAC to access unclassified information The use of webmail is - ANS is only allowed if the organization permits it What is considered ethical use of the Government email system? - ANS Distributing Company newsletter Which of the following attacks target high ranking officials and executives? - ANS Whaling What constitutes a strong password? - ANS all of the above You are logged on to your unclassified computer and just received an encrypted email from a co-worker. The email has an attachment whose name contains the word "secret". What should you do? - ANS Contact your security POC right away Which is a way to protect against phishing attacks? - ANS Look for digital certificates You receive an email from a company you have an account with. The email states your account has been compromised and you are invited to click on the link in order to reset your password. What action should you take? - ANS Notify security You are having lunch at a local restaurant outside the installation, and you find a cd labeled "favorite song". What should you do? - ANS Leave the cd where it is How should you securely transport company information on a removable media? - ANS Encrypt the removable media Should you always label your removable media? - ANS Yes Which of the following is NOT Protected Health Information (PHI)? - ANS Medical care facility name If authorized, what can be done on a work computer? - ANS Check personal email Spear Phishing attacks commonly attempt to impersonate email from trusted entities. What security device is used in email to verify the identity of sender? - ANS Digital Signatures What type of security is "part of your responsibility" and "placed above all else?" - ANS Physical If your wireless device is improperly configured someone could gain control of the device? T/F - ANS TRUE Which of the following is a proper way to secure your CAC/PIV? - ANS Remove and take it with you whenever you leave your workstation What actions should you take prior to leaving the work environment and going to lunch? - ANS All of the above P2P (Peer-to-Peer) software can do the following except: - ANS Allow attackers physical access to network assets How can you guard yourself against Identity theft? - ANS All of the above When leaving your work area, what is the first thing you should do? - ANS Remove your CAC/PIV Using webmail may bypass built in security features. - ANS TRUE Of the following, which is NOT a characteristic of a phishing attempt? - ANS Directing you to a web site that is real Classified Information can only be accessed by individuals with - ANS All of the above Which of the following definitions is true about disclosure of confidential information? - ANS Damage to national security It is permissible to release unclassified information to the public prior to being cleared. - ANS False Which of the following is NOT sensitive information? - ANS Unclassified information cleared for public release What should you do to protect yourself while on social networks? - ANS Validate all friend requests through another source before confirming them Which is NOT a method of protecting classified data? - ANS Assuming open storage is always authorized in a secure facility What can you do to prevent spillage? - ANS all of the above Which of the following makes Alex's personal information vulnerable to attacks by identity thieves? - ANS Carrying his Social Security Card with him DoD employees are prohibited from using a DoD CAC in card-reader-enabled public device - ANS TRUE Which of the following is an example of malicious code? - ANS Trojan horses Which of the following is NOT PII? - ANS Mother's maiden name Classified Information is - ANS Assigned a classification level by a supervisor Maria is at home shopping for shoes on A. Before long she has also purchased shoes from several other websites. What can be used to track Maria's web browsing habits? - ANS Cookies Which is an untrue statement about unclassified data? - ANS If aggregated, the classification of the information may not be changed A medium secure password has at least 15 characters and one of the following. - ANS Special character PII, PHI, and financial information is classified as what type of information? - ANS Sensitive The CAC/PIV is a controlled item and contains certificates for: - ANS All of the above An individual who has attempted to access sensitive information without need-to-know and has made unusual requests for sensitive information is displaying indicators of what? - ANS Potential Insider Threat Which of the following is NOT a social engineering tip? - ANS Following instructions from verified personnel Bob, a coworker, has been going through a divorce, has financial difficulties and is displaying hostile behavior. How many potential insider threat indicators is Bob displaying? - ANS 3 You are working at your unclassified system and receive an email from a coworker containing a classified attachment. What should you do? - ANS Alert your security POC You check your bank statement and see several debits you did not authorize. You believe that you are a victim of identity theft. Which of the following should you do immediately? - ANS Monitor credit card statements for unauthorized purchases Thumb drives, memory sticks, and flash drives are examples of - ANS Removable media What information relates to the physical or mental health of an individual? - ANS PHI What should be done if you find classified Government Data/Information Not Cleared for Public Release on the Internet? - ANS Make note of any identifying information and the website URL and report it to your security office All https sites are legitimate and there is no risk to entering your personal info online. - ANS FALSE When using a fax machine to send sensitive information, the sender should do which of the following? - ANS Contact the recipient to confirm receipt What should be done to protect against insider threats? - ANS Report any suspicious behavior Which of the following is NOT a potential insider threat? - ANS Member of a religion or faith Of the following, which is NOT a security awareness tip? - ANS Remove security badge as you enter a restaurant or retail establishment ActiveX is a type of this? - ANS Mobile code Which of the following is NOT a security best practice when saving cookies to a hard drive? - ANS Looking for "https" in the URL. All https sites are legitimate. Which is NOT a requirement for telework? - ANS Telework is only authorized for unclassified and confidential information Someone calls from an unknown number and says they are from IT and need some information about your computer. What should you do? - ANS Request the user's full name and phone number Which is NOT a wireless security practice? - ANS Turning off computer when not in use Malicious code can do the following except? - ANS Make your computer more secure What type of data must be handled and stored properly based on classification markings and handling caveats? - ANS Classified What information should you avoid posting on social networking sites? - ANS All of the above A coworker has left an unknown CD on your desk. What should you do? - ANS Put the CD in the trash Which of the following is NOT a DoD special requirement for tokens? - ANS Using NIPRNet tokens on systems of higher classification level UNCLASSIFIED is a designation to mark information that does not have potential to damage national security. - ANS TRUE You receive a call on your work phone and you're asked to participate in a phone survey. As part of the survey the caller asks for birth date and address. What type of attack might this be? - ANS Social Engineering "Spillage" occurs when - ANS Personal information is inadvertently posted at a website What should be done to sensitive data on laptops and other mobile computing devices? - ANS Encrypt the sensitive data Which of the following should be done to keep your home computer secure? - ANS All of the above How are Trojan horses, worms, and malicious scripts spread? - ANS By email attachments The following practices help prevent viruses and the downloading of malicious code except. - ANS Scan external files from only unverifiable sources before uploading to computer

Show more Read less
Module









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Module
Unknown

Document information

Uploaded on
December 4, 2023
Number of pages
7
Written in
2023/2024
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
DocLaura Galen College Of Nursing
View profile
Follow You need to be logged in order to follow users or courses
Sold
152
Member since
2 year
Number of followers
38
Documents
6404
Last sold
2 weeks ago

4.2

44 reviews

5
27
4
4
3
10
2
2
1
1

Trending documents

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these revision notes.

Didn't get what you expected? Choose another document

No problem! You can straightaway pick a different document that better suits what you're after.

Pay as you like, start learning straight away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and smashed it. It really can be that simple.”

Alisha Student

Frequently asked questions