DOD Cyber Awareness Challenge 2019

Which of these is true of unclassified data?

-It must be released to the public immediately. -Its classification level may rise when aggregated. (Correct) -It does not affect the safety of Government missions. -It never requires classification markings.

Which type of information includes personal, payroll, medical, and operational information?


Which of the following is NOT a correct way to protect sensitive information?

Sensitive information may be stored on any password-protected system.

Which of the following is NOT a typical result from running malicious code?

Disabling cookies

What level of damage to national security could reasonably be expected if unauthorized disclosure of Top Secret information occurred?

Exceptionally grave damage

Which of the following is true about telework?

You must have your organization’s permission to telework.

Which of following is true of protecting classified data?

Classified material must be appropriately marked.

Which of the following is NOT considered a potential insider threat indicator?

New interest in learning another language?

A colleague has visited several foreign countries recently, has adequate work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his car repossessed. How many indicators does this employee display?

3 or more?

Which of the following is NOT considered a potential insider threat indicator?

Treated mental health issues.

What would you do if you receive a game application request on your government computer that includes permission to access your friends, profile information, cookies, and sites visited?

Decline the request.

What information most likely presents a security risk on your personal social networking profile?


You have reached the office door to exit your controlled area. As a security best practice, what should you do before exiting?

Remove your security badge, common access card (CAC), or personal identity verification (PIV) card.

How should you protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card?

Store it in a shielded sleeve to avoid chip cloning.

Which of the following statements is TRUE about the use of DoD Public Key Infrastructure (PKI) tokens?

Always use DoD PKI tokens within their designated classification level.

Which of the following is a best practice for handling cookies?

If possible, set your browser preferences to prompt you each time a website wants to store a cookie.

You receive an unexpected email from a friend: "I think you’ll like this: (URL)" What action should you take?

Use TinyURL’s preview feature to investigate where the link leads.

You receive an email at your official Government email address from an individual at the Office of Personnel Management (OPM). The email provides a link to a personnel portal where you must enter your personal information as part of an effort to standardize recordkeeping. What action should you take first?

Look for a digital signature on the email.

What is TRUE of a phishing attack?

Phishing can be an email with a hyperlink as bait.

Upon connecting your Government-issued laptop to a public wireless connection, what should you immediately do?

Connect to the Government Virtual Private Network (VPN).??

A coworker has asked if you want to download a programmer’s game to play at work. What should be your response?

I’ll pass.

A coworker wants to send you a sensitive document to review while you are at lunch and you only have your personal tablet. What should you do?

Never allow sensitive data on non-Government-issued mobile devices.

Which of the following demonstrates proper protection of mobile devices?

Linda encrypts all of the sensitive data on her government-issued mobile devices.

How can you protect your information when using wireless technology?

Avoid using non-Bluetooth-paired or unencrypted wireless computer peripherals.

