Javascript required
Skip to content Skip to sidebar Skip to footer

Under What Circumstances Is It Acceptable to Check Personal Email on Government Furnished Equipment

Nosotros thoroughly check each answer to a question to provide you lot with the almost correct answers. Found a fault? Let united states know about information technology through the Written report button at the bottom of the folio.

  1. What is the best response if y'all notice classified government data on the internet?
    Note whatsoever identifying information, such as the website's URL, and report the state of affairs to your security POC.
  2. What is a good do to protect classified information?
    Ensure proper labeling past appropriately marking all classified material and when required, sensitive cloth.
  3. How many potential insider threat indicators does a person who is playful and charming, consistently wins performance awards, but is occasionally ambitious in trying to admission information brandish?
    Secret.
  4. Who might "insiders" be able to crusade impairment to their organizations more hands than others.
    Insiders are given a level of trust and take authorized access to Government information systems.

*Spillage
After reading an online story about a new security project being developed on the military installation where yous work, your neighbor asks you lot to comment virtually the article. You know this project is classified. What should be your response?

Attempt to alter the subject to something non-piece of work related, just neither confirm nor deny the article'due south authenticity.

*Spillage
Which of the post-obit may help prevent inadvertent spillage?

Label all files, removable media, and subject field headers with appropriate nomenclature markings.

*Spillage
A user writes downward details marked as Hugger-mugger from a written report stored on a classified arrangement and uses those details to typhoon a briefing on an unclassified organisation without authorisation. What is the all-time choice to describe what has occurred?

Spillage because classified data was moved to a lower classification level system without authorization.

*Spillage
What should yous do when you are working on an unclassified system and receive an e-mail with a classified zipper?

Call your security signal of contact immediately

*Spillage
What should y'all do if a reporter asks yous near potentially classified information on the web?

Ask for information about the website, including the URL.

*Spillage
.What should you exercise if a reporter asks you nigh potentially classified information on the web?

Refer the reporter to your arrangement'southward public diplomacy office.

*Spillage
What is a proper response if spillage occurs?

~Immediately notify your security POC.

*Spillage
Which of the post-obit is a skilful do to help in preventing spillage?

Be aware of nomenclature markings and all handling caveats.

**Classified Data
When classified information is not in use, how can you protect it?

Store classified data accordingly in a GSA-approved vault/container.

**Classified Information
What is required for an individual to admission classified information?

Advisable clearance, a signed and approved not-disclosure understanding, and need-to-know

**Classified Data
Which classification level is given to information that could reasonably be expected to cause serious damage to national security?

Secret

**Classified Data
What is a good practice to protect classified information?

Ensure proper labeling past appropriately marking all classified material and, when required, sensitive material.

**Classified Information
Which of the post-obit is true of protecting classified data?

Classified fabric must be appropriately marked.

**Classified Information
Which of the following can an unauthorized disclosure of information classified equally Confidential reasonably exist expected to cause?

Impairment to national security

**Insider Threat
Which of the post-obit is NOT considered a potential insider threat indicator?

New interest in learning a foreign language

**Insider Threat
A colleague has visited several foreign countries recently, has adequate piece of work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his machine repossessed. How many potential insider threat indicators does this employee display?

ane Indicator(wrong)
~iii or more indicators

**Insider Threat
A colleague vacations at the embankment every year, is married and a father of four, his work quality is sometimes poor, and he is pleasant to work with. How many potential insider threat indicators does this employee display?

1 indicator

**Insider Threat
How many potential insider threat indicators does a coworker who oftentimes makes others uneasy by being persistent in trying to obtain data nearly classified projects to which he has no access, is boisterous about his wife putting them in credit bill of fare debt, and often complains near feet and burnout display?

iii or more indicators

**Insider Threat
How many potential insider threat indicators does a person who is playful and charming, consistently wins performance awards, only is occasionally aggressive in trying to access sensitive information brandish?

one indicator

**Insider Threat
What advantages do "insider threats" accept over others that allows them to cause harm to their organizations more hands?

Insiders are given a level of trust and have authorized access to Government information systems

**Insider Threat
What type of activity or beliefs should be reported every bit a potential insider threat?

Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.

**Insider Threat
Which of the following should be reported equally a potential security incident?

A coworker removes sensitive data without potency

**Insider Threat
Which of the following should be reported as a potential security incident (in accord with you Agency's insider threat policy)?

~A coworker brings a personal electronic device into a prohibited area.

**Social Networking
When is the safest fourth dimension to post details of your vacation activities on your social networking website?

When vacation is over, afterwards you have returned home

**Social Networking
What should you practice if you receive a game application request that includes permission to access your friends, profile data, cookies, and sires visited?

Decline the request

*Sensitive Information
Under which circumstances is information technology permitted to share an unclassified draft document with a non-DoD professional word grouping?

Every bit long as the document is cleared for public release, yous may share it exterior of DoD.

*Sensitive Information
What is the best example of Personally Identifiable Information (PII)?

Engagement and place of nativity

*Sensitive Information
Which of the following is the best example of Personally Identifiable Data (PII)?

Passport number

*Sensitive Information
Which of the post-obit is an example of Protected Health Information (PHI)?

Medical examination results

*Sensitive Information
What type of unclassified material should e'er exist marked with a special handling caveat?

For Official Use Only (FOUO)

*Sensitive Information
Nether what circumstances could classified information be considered a threat to national security?

If aggregated, the information could become classified.

**Physical Security
What is a good exercise for concrete security?

Challenge people without proper badges.

**Physical Security
At which Cyberspace Protection Condition (CPCON) is the priority focus on disquisitional functions only?

CPCON 1

**Identity Management
Your DoD Common Admission Card (CAC) has a Public Key Infrastructure (PKI) token approved for admission to the NIPRNet. In which situation below are you permitted to utilise your PKI token?

On a NIPRNet system while using information technology for a PKI-required task

**Identity Management
Which of the post-obit is the nest description of 2-factor authentication?

Something you possess, like a CAC, and something yous know, like a PIN or password

**Identity management
Which is Non a sufficient way to protect your identity?

Use a common password for all your system and application logons.

**Identity management
What is the best style to protect your Mutual Access Card (CAC)?

Maintain possession of it at all times.

*Sensitive Compartmented Information
What is a Sensitive Compartmented Data (SCI) program?

A program that segregates diverse type of classified information into distinct compartments for added protection and dissemination for distribution command.

*Sensitive Compartmented Information
Which of the post-obit best describes the compromise of Sensitive Compartmented Information (SCI)?

A person who does non have the required clearance or assess caveats comes into possession of SCI in any manner.

*Sensitive Compartmented Information
When should documents be marked within a Sensitive Compartmented Information Facility (SCIF)

~All documents should be accordingly marked, regardless of format, sensitivity, or nomenclature.
Unclassified documents do not need to exist marked as a SCIF.
Only newspaper documents that are in open up storage need to exist marked.
Only documents that are classified Secret, Height Secret, or SCI require mark. (Wrong)

*Sensitive Compartmented Information
Which must be approved and signed by a cognizant Original Classification Authority (OCA)?

Security Classification Guide (SCG)

**Removable Media in a SCIF
What must users ensure when using removable media such as compact deejay (CD)?

It displays a label showing maximum nomenclature, date of cosmos, signal of contact, and Change Management 9CM) Command Number.

*Malicious Code
What are some examples of malicious code?

Viruses, Trojan horses, or worms

**Website Use
While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should yous do?

Since the URL does not get-go with "https," exercise not provide you credit bill of fare information.

**Social Engineering science
Which of the post-obit is a practise that helps to prevent the download of viruses and other malicious lawmaking when checking your email?

Do not admission links or hyperlinked media such every bit buttons and graphics in email messages.

**Social Engineering
What is Truthful of a phishing attack?

Phishing can be an email with a hyperlink as allurement.

**Social Engineering
Which of the following is a way to protect against social engineering?

Follow instructions given only by verified personnel.

**Travel
What is a all-time practice while traveling with mobile computing devices?

Maintain possession of your laptop and other government-furnished equipment (GFE) at all times.

**Use of GFE
Under what circumstances is it acceptable to use your Government-furnished figurer to check personal e-mail and exercise other not-work-related activities?

If allowed past organizational policy

**Mobile Devices
Which is a rule for removable media, other portable electronic devices (PEDs), and mobile computing devices to protect Government systems?

Do not use whatever personally owned/non-organizational removable media on your organization'southward systems.

**Mobile Devices
Which of the following helps protect information on your personal mobile devices?

Secure personal mobile devices to the aforementioned level equally Regime-issued systems.

**Dwelling house Reckoner Security
How can you protect your information when using wireless engineering science?

Avert using non-Bluetooth-paired or unencrypted wireless computer peripherals.

What is the best response if you find classified government information on the internet?

Note any identifying information, such as the website'south URL, and written report the situation to your security POC.

What information posted publicly on your personal social networking contour represents a security gamble?

Your place of nascency

What is the all-time example of Protected Health Data (PHI)?

Your health insurance caption of benefits (EOB)

What does Personally Identifiable Information (PII) include?

Social Security Number; date and place of birth; mother'south maiden proper noun

What certificates are contained on the DoD Public Central Infrastructure (PKI) implemented by the Mutual Access Card (CAC)/Personal Identity Verification (PIV) menu?

Identification, encryption, and digital signature

What describes how Sensitive Compartmented Information is marked?

Approved Security Classification Guide (SCG)

Which is a hazard associated with removable media?

Spillage of classified information.

What is an indication that malicious code is running on your arrangement?

File corruption

What is a valid response when identity theft occurs?

Report the criminal offence to local police enforcement.

What is whaling?

A type of phishing targeted at high-level personnel such every bit senior officials.

What is a best exercise to protect information on your mobile computing device?

Lock your device screen when not in use and crave a password to reactivate.

What is a possible indication of a malicious lawmaking attack in progress?

A pop-upward window that flashes and warns that your computer is infected with a virus.

Which of the following may be helpful to prevent inadvertent spillage?

Which of the following may be helpful to prevent inadvertent spillage?

What should you do after you have ended a call from a reporter asking you to confirm potentially classified info found on the web?

Alert your security point of contact.

Which of the following is NOT an instance of sensitive data?

Which of the following is NOT an instance of sensitive data?

PII

SSN, date and identify of nascence, female parent'due south maiden name, biometric records, PHI, passport number

PHI

Subset of PII, health information that identifies the individual, relates to physical or mental health of an individual, provision of health intendance to an private, or payment of healthcare for private

Which of the following is Non a typical result from running malicious code?

Disable cookies

What kind of information could reasonably be expected to cause serious damage to national security in the event of unauthorized disclosure?

Cloak-and-dagger

Telework

Take your permissions from your system, follow your organization guideline, apply authorized equipment and software, employ cyber security best practice, perform telework in dedicated when abode.

Which of the post-obit should be reported as a potential security incident (in accordance with your Agency'southward insider threat policy)?

A coworker brings a personal electronic device into prohibited areas.

A colleague complains about anxiety and burnout, makes coworkers uncomfortable by request excessive questions about classified projects, and complains about the credit card bills that his married woman runs upwardly. How many potential insider threat indicators does this employee display?

3 or more indicators

A colleague has won 10 loftier-operation awards, can be playful and mannerly, is not currently in a relationship, and occasionally aggressive in trying to access sensitive information. How many potential insider threat indicators does this employee brandish?

1 indicator

What data near likely presents a security gamble on your personal social networking profile?

Mother's maiden proper noun

Which of the following represents a adept physical security practice?

Use your own security badge, key lawmaking, or Mutual Access Carte du jour (CAC)/Personal Identity Verification (PIC) card.

How should you protect your Mutual Access Bill of fare (CAC) or Personal Identity Verification (PIV) carte?

Shop it in a shielded sleeve to avoid bit cloning.

Which of the following statements is NOT truthful virtually protecting your virtual identity?

Use personal information to assist create strong passwords.

While you are registering for a conference, you arrive at the website http://www.dcsecurityconference.org/registration/. The website requires a credit card for registration. What should you lot do?

Since the URL does not start with "https," practice not provide your credit card information.

You lot receive an email from the Internal Revenue Service (IRS) demanding immediate payment of back taxes of which you were not aware. The e-mail provides a website and a toll-free number where you can make payment. What activeness should you lot take?

Contact the IRS using their publicly available, official contact information.

Which of the following is a practice that helps to prevent the download of viruses and other malicious code when checking your electronic mail?

Do not access links or hyperlinked media such equally buttons and graphics in email messages.

Which of the following is true of Internet hoaxes?

They tin be part of a distributed denial-of-service (DDoS) set on.

Which of the following is NOT truthful of traveling overseas with a mobile phone?

Physical security of mobile phones carried overseas is non a major issue.

A coworker has asked if you want to download a programmer's game to play at piece of work. What should be your response?

I'll laissez passer.

A coworker wants to send you a sensitive certificate to review while you are at lunch and you lot only have your personal tablet. What should y'all do?

Never permit sensitive information on not-Regime-issued mobile devices.

A man you do not know is trying to await at your Government-issued telephone and has asked to apply it. What should you do?

Decline to lend the man your telephone.

How can yous protect your information when using wireless engineering?

Avert using not-Bluetooth-paired or unencrypted wireless computer peripherals.

What should you do if a reporter asks you well-nigh potentially classified information on the web?

Neither confirm or deny the information is classified.

Which of the following may be helpful to prevent inadvertent spillage?

Characterization all files, removable media, and subject headers with appropriate classification markings.

What kind of information could reasonably be expected to cause serious damage to national security in the issue of unauthorized disclosure?

Secret

Which of the post-obit is Non true apropos a calculator labeled SECRET?

May be used on an unclassified network.

A colleague complains most anxiety and exhaustion, makes coworkers uncomfortable past asking excessive questions about classified projects, and complains virtually the credit card bills that his wife runs up. How many potential insider threat indicators does this employee display?

3 or more indicators

Which of the following should be reported as a potential security incident?

A coworker removes sensitive data without approval.

Which of the following should be reported every bit a potential security incident (in accord with your Agency's insider threat policy)?

A coworker brings a personal electronic device into prohibited areas.

When would be a good time to post your vacation location and dates on your social networking website?

When you return from your vacation.

In setting upward your personal social networking service business relationship, what e-mail address should y'all utilize?

Your personal electronic mail accost.

Which of the following is Non a right fashion to protect sensitive information?

Sensitive information may be stored on whatever password-protected organization.

Which of these is truthful of unclassified data?

It'due south classification level may rise when aggregated.

Is it permitted to share an unclassified draft certificate with a non-DoD professional discussion grouping?

Equally long as the document is cleared for public release, y'all may share it exterior of DoD.

Within a secure area, you lot see an individual you exercise non know. Her badge is non visible to yous. What is the all-time course of action?

Ask the private to place herself.

How should yous protect your Common Access Card (CAC) or Personal Identity Verification (PIV) card?

Shop information technology in a shielded sleeve to avoid bit cloning.

Your DoD Common Access Carte du jour (CAC) has a Public Key Infrastructure (PKI) token approves for access to the NIPRNET. In which situation below are yous permitted to use your PKI token?

On a NIPRNET system while using information technology for a PKI-required job

After clicking on a link on a website, a box pops upwards and asks if you want to run an application. Is it okay to run it?

No. Just allow mobile code to run from your organization or your organisation's trusted sites.

Upon connecting your Government- issued laptop to a public wireless connection, what should you immediately practice?

Connect to the Government Virtual Private Network (VPN).

What do you do if spillage occurs?

Immediately notify your security point of contact.

What should y'all do after you take ended a phone call from a reporter asking you lot to ostend potentially classified information found on the web?

Alert your security point of contact.

Which of the following is NOT a requirement for telework?

You must possess security clearance eligibility to telework.

Who can exist permitted admission to classified information?

Merely persons with advisable clearance, a non-disclosure agreement, and need-to-know can access classified data.

A colleague has won ten loftier-performance awards, can be playful and charming, is not currently in a human relationship, and is occasionally aggressive in trying to access sensitive information. How many potential insiders threat indicators does this employee display?

one indicator

A colleague has visited several foreign countries recently, has acceptable work quality, speaks openly of unhappiness with U.S. foreign policy, and recently had his car repossessed. How many potential insiders threat indicators does this employee display?

three or more indicators

A colleague complains about anxiety and exhaustion, makes coworkers uncomfortable by asking excessive questions about classified projects, and complains about the credit card bills that his wife runs up. How many potential insiders threat indicators does this employee brandish?

three or more than indicators

In setting up your personal social networking service business relationship, what email address should you lot use?

Your personal electronic mail address

What information virtually likely presents a security risk on your personal social networking profile?

Your place of birth

Which of the post-obit is NOT an example of sensitive information?

Press release data

Is it permitted to share an unclassified draft document with a non-DoD professional person discussion grouping?

Every bit long every bit the document is cleared for public release, you may release it outside of DoD

Which of the following is an example of Protected Health Data (PHI)?

I've tried all the answers and it notwithstanding tells me off. Examples are: Patient names, Social Security numbers, Driver's license numbers, insurance details, and birth dates

Which of the post-obit represents a good physical security practice?

Use your own security badge, key code, or Mutual Access Menu (CAC)/Personal Identity Verification (PIC) card.

Which of the post-obit is Non a expert mode to protect your identity?

Use a unmarried, complex password for your system and application logons.

Which of the following statements is TRUE most the use of DoD Public Key Infrastructure (PKI) tokens?

Always use DoD PKI tokens inside their designated nomenclature level.

Which of the following is Non a typical ways for spreading malicious code?

Patching from a trusted source

Which of the following is a practice that helps to protect you from identity theft?

Ordering a credit report annually

Which of the following is a practice that helps to prevent the download of viruses and other malicious lawmaking when checking your email?

Exercise not access links or hyperlinked media such as buttons and graphics in email messages.

Yous receive an unexpected electronic mail from a friend: "I think yous'll like this: https://tinyurl.com/2fcbvy." What action should yous take?

Use TinyURL'southward preview characteristic to investigate where the link leads.

You receive an email from the Internal Revenue Service (IRS) demanding immediate payment of back taxes of which you lot were not aware. The electronic mail provides a website and a toll-free number where y'all can brand payment. What action should you have?

Contact the IRS

When using your authorities-issued laptop in public environments, with which of the following should you be concerned?

The potential for unauthorized viewing of piece of work-related information displayed on your screen.

Under what circumstances is it adequate to bank check personal electronic mail on Government-furnished equipment (GFE)?

If your system allows it.

Which of the following is Non a best practice to protect data on your mobile computing device?

Lock your device screen when non in use and require a password to reactivate.

When checking in at the airline counter for a business organisation trip, y'all are asked if you would similar to check your laptop purse. This bag contains your regime-issued laptop. What should y'all practise?

I've tried all the answers and information technology all the same tells me off, part ii. Turn down Then That You lot Maintain Concrete Command of Your Regime-Issued Laptop.

How can you protect your data when using wireless technology?

Avert using non-Bluetooth-paired or unencrypted wireless computer peripherals.

Are you a Boot B*cht?

Are yous a Kick B*cht?

Yep




laybeettlithe.blogspot.com

Source: https://quizzma.com/cyber-awareness-answers/