Exam prep
IT & Cybersecurity study guides
Phishing, passwords, and safe computing — with interactive checkers and clear rules.
18 explained questions, each with the answer, a worked explanation, and something interactive to help it stick.
- How can you prevent viruses and malicious code?Scan all email attachments and removable media before opening them, avoid clicking unknown links or pop-ups, keep your operating system and antivirus updated, and download software only from trusted sources. Layering these habits blocks the common ways malicious code spreads.Read the guide
- Which of the following is responsible for most of the recent PII data breaches?Phishing is responsible for most recent PII data breaches. Attackers use fraudulent emails, texts, and fake websites to trick people into revealing credentials or personal data, an approach that scales far more easily and cheaply than insider theft, physical break-ins, or data reconstruction.Read the guide
- Which of the following is an example of a strong password?A strong password is long (16+ characters) and unpredictable — a random mix of upper- and lowercase letters, numbers, and symbols such as 'fR7!cP02mv9@QeZ8', or a long random passphrase. Names, dictionary words, and short simple strings like 'Password1' are weak.Read the guide
- Which of the Following Is True of Spillage?Spillage can be either inadvertent or intentional. It occurs when information moves from a higher classification or protection level to a lower, unauthorized one. It must be reported immediately to your security point of contact (POC) and never deleted or forwarded.Read the guide
- Which of the Following Is True of Transmitting Sensitive Compartmented Information (SCI)?SCI may be transmitted or transported only through approved secure channels — encrypted, accredited systems and authorized, SCI-briefed couriers. It must never be sent over unclassified networks, personal email, or non-secure means, and it may only be handled within a SCIF by cleared, need-to-know personnel.Read the guide
- Which of the following is a best practice when browsing the internet?The best practice is to confirm the site uses an encrypted connection — look for HTTPS and the padlock icon in the address bar — before entering any sensitive information. HTTPS encrypts data between your browser and the website so it cannot be intercepted in transit.Read the guide
- Which personally owned peripherals can you use with government furnished equipment (GFE)?You may use a monitor connected through a video-only cable (VGA, DVI, HDMI, or DisplayPort) and a USB or 3.5mm audio headset with microphone. USB flash drives, external hard drives, and most other personal data-carrying peripherals are prohibited on GFE.Read the guide
- Which Action Requires an Organization to Carry Out a Privacy Impact Assessment?Collecting personally identifiable information (PII) to store in a new or substantially modified information system requires a Privacy Impact Assessment. Under the E-Government Act of 2002 (Section 208), developing or procuring IT that collects, maintains, or disseminates PII triggers a PIA; de-identified data or paper records generally do not.Read the guide
- Which of the Following Is an Example of Two-Factor Authentication?Two-factor authentication combines two different factor types — for example, a password (something you know) plus a one-time code from your phone (something you have), or an ATM card (have) plus a PIN (know). Using two of the same factor, such as a password and a security question, is not 2FA.Read the guide
- How is a security infraction different from a security violation?A security infraction is a security incident that does NOT result in — and could not reasonably be expected to result in — the loss or compromise of classified information. A security violation does result in, or could reasonably result in, such loss or compromise, so it is the more serious event.Read the guide
- Evelyn is a system administrator at her agency and wants to use a thumb drive — is her use acceptable?Yes, her use is acceptable. Removable media such as a thumb drive may be used on a government system only when the device is Government-owned or Government-provided, its use is operationally necessary, and it is approved under agency policy. Evelyn's use meets all three conditions.Read the guide
- How can you protect your home computer? (Cyber Awareness Challenge)Protect your home computer by regularly installing security patches and software updates, running antivirus/anti-spyware, enabling a firewall, using strong passwords with multi-factor authentication, and backing up your files. Keeping software current is the single most emphasized action.Read the guide
- When Opening and Closing a Security Container, Which Form Do You Complete?You complete the SF 702, the Security Container Check Sheet. It records the name and time each time the container is opened, closed, and checked. The SF 700 holds combination information and the SF 701 is the end-of-day activity checklist.Read the guide
- While picking up lunch at a cafe, Thom leaves his devices unattended — what should he do?Thom should never leave his laptop, phone, or Common Access Card (CAC) unattended in a public place. He should keep his devices with him or physically secured, and always take his CAC. Unattended devices invite theft and unauthorized access.Read the guide
- CUI Documents Must Be Reviewed According to Which Procedures?CUI documents must be reviewed according to Records Management procedures before destruction, ensuring compliance with retention schedules and proper disposal. Under DoDI 5200.48, this review confirms records aren't destroyed prematurely and that CUI is disposed of using approved methods.Read the guide
- What Is NOT a Physical Security Measure for Your Home?A homeowners or renters insurance policy is NOT a physical security measure. Neither are passwords, alarm-monitoring subscriptions, or neighborhood-watch apps. Physical security measures are tangible barriers and devices such as locks, deadbolts, cameras, fences, motion sensors, and lighting.Read the guide
- Which of the Following Is True of Internet Hoaxes?True: internet hoaxes use social engineering to spread false information and can be used maliciously—clogging networks or forming part of DDoS-style attacks. The best protection is verifying claims with trusted, fact-checking sources before believing or sharing them.Read the guide
- Your Organization Has a New Requirement for Annual Security Training: Which Practice Is NOT Compliant?Using employees' Social Security Numbers to track training completion is NOT compliant with PII safeguarding rules. SSNs are high-risk PII and must be minimized; the compliant practice is to track completion with a non-sensitive unique employee ID instead.Read the guide