Exam prep
IT & Cybersecurity study guides
Phishing, passwords, and safe computing — with interactive checkers and clear rules.
26 explained questions, each with the answer, a worked explanation, and something interactive to help it stick.
- How can you prevent viruses and malicious code?Scan all email attachments and removable media before opening them, avoid clicking unknown links or pop-ups, keep your operating system and antivirus updated, and download software only from trusted sources. Layering these habits blocks the common ways malicious code spreads.Read the guide
- Which of the following is responsible for most of the recent PII data breaches?Phishing is responsible for most recent PII data breaches. Attackers use fraudulent emails, texts, and fake websites to trick people into revealing credentials or personal data, an approach that scales far more easily and cheaply than insider theft, physical break-ins, or data reconstruction.Read the guide
- Which of the following is an example of a strong password?A strong password is long (16+ characters) and unpredictable — a random mix of upper- and lowercase letters, numbers, and symbols such as 'fR7!cP02mv9@QeZ8', or a long random passphrase. Names, dictionary words, and short simple strings like 'Password1' are weak.Read the guide
- Which of the Following Is True of Spillage?Spillage can be either inadvertent or intentional. It occurs when information moves from a higher classification or protection level to a lower, unauthorized one. It must be reported immediately to your security point of contact (POC) and never deleted or forwarded.Read the guide
- Which of the Following Is True of Transmitting Sensitive Compartmented Information (SCI)?SCI may be transmitted or transported only through approved secure channels — encrypted, accredited systems and authorized, SCI-briefed couriers. It must never be sent over unclassified networks, personal email, or non-secure means, and it may only be handled within a SCIF by cleared, need-to-know personnel.Read the guide
- Which of the following is a best practice when browsing the internet?The best practice is to confirm the site uses an encrypted connection — look for HTTPS and the padlock icon in the address bar — before entering any sensitive information. HTTPS encrypts data between your browser and the website so it cannot be intercepted in transit.Read the guide
- Which personally owned peripherals can you use with government furnished equipment (GFE)?You may use a monitor connected through a video-only cable (VGA, DVI, HDMI, or DisplayPort) and a USB or 3.5mm audio headset with microphone. USB flash drives, external hard drives, and most other personal data-carrying peripherals are prohibited on GFE.Read the guide
- Which Action Requires an Organization to Carry Out a Privacy Impact Assessment?Collecting personally identifiable information (PII) to store in a new or substantially modified information system requires a Privacy Impact Assessment. Under the E-Government Act of 2002 (Section 208), developing or procuring IT that collects, maintains, or disseminates PII triggers a PIA; de-identified data or paper records generally do not.Read the guide
- Which of the Following Is an Example of Two-Factor Authentication?Two-factor authentication combines two different factor types — for example, a password (something you know) plus a one-time code from your phone (something you have), or an ATM card (have) plus a PIN (know). Using two of the same factor, such as a password and a security question, is not 2FA.Read the guide
- How is a security infraction different from a security violation?A security infraction is a security incident that does NOT result in — and could not reasonably be expected to result in — the loss or compromise of classified information. A security violation does result in, or could reasonably result in, such loss or compromise, so it is the more serious event.Read the guide
- Evelyn is a system administrator at her agency and wants to use a thumb drive — is her use acceptable?Yes, her use is acceptable. Removable media such as a thumb drive may be used on a government system only when the device is Government-owned or Government-provided, its use is operationally necessary, and it is approved under agency policy. Evelyn's use meets all three conditions.Read the guide
- How can you protect your home computer? (Cyber Awareness Challenge)Protect your home computer by regularly installing security patches and software updates, running antivirus/anti-spyware, enabling a firewall, using strong passwords with multi-factor authentication, and backing up your files. Keeping software current is the single most emphasized action.Read the guide
- When Opening and Closing a Security Container, Which Form Do You Complete?You complete the SF 702, the Security Container Check Sheet. It records the name and time each time the container is opened, closed, and checked. The SF 700 holds combination information and the SF 701 is the end-of-day activity checklist.Read the guide
- While picking up lunch at a cafe, Thom leaves his devices unattended — what should he do?Thom should never leave his laptop, phone, or Common Access Card (CAC) unattended in a public place. He should keep his devices with him or physically secured, and always take his CAC. Unattended devices invite theft and unauthorized access.Read the guide
- CUI Documents Must Be Reviewed According to Which Procedures?CUI documents must be reviewed according to Records Management procedures before destruction, ensuring compliance with retention schedules and proper disposal. Under DoDI 5200.48, this review confirms records aren't destroyed prematurely and that CUI is disposed of using approved methods.Read the guide
- What Is NOT a Physical Security Measure for Your Home?A homeowners or renters insurance policy is NOT a physical security measure. Neither are passwords, alarm-monitoring subscriptions, or neighborhood-watch apps. Physical security measures are tangible barriers and devices such as locks, deadbolts, cameras, fences, motion sensors, and lighting.Read the guide
- Which of the Following Is True of Internet Hoaxes?True: internet hoaxes use social engineering to spread false information and can be used maliciously—clogging networks or forming part of DDoS-style attacks. The best protection is verifying claims with trusted, fact-checking sources before believing or sharing them.Read the guide
- Your Organization Has a New Requirement for Annual Security Training: Which Practice Is NOT Compliant?Using employees' Social Security Numbers to track training completion is NOT compliant with PII safeguarding rules. SSNs are high-risk PII and must be minimized; the compliant practice is to track completion with a non-sensitive unique employee ID instead.Read the guide
- Which of the following is NOT an example of PII?Anything that cannot be tied back to a specific person is not PII. Aggregated, anonymized, or generic data — a company's public product description, or a random number not linked to anyone — is not PII. Names, SSNs, addresses, dates of birth, and biometrics are PII.Read the guide
- Which physical security countermeasures are designed to prevent unauthorized access?All of the above—barriers, intrusion detection systems, and access controls. Together these layered countermeasures deter, detect, delay, and deny unauthorized access, forming a defense-in-depth strategy that no single measure could achieve alone.Read the guide
- Which of the following is true of removable media and portable electronic devices (PEDs)?The same rules and protections apply to both, and both pose real risks such as malicious code and data spillage. Use only organization-owned, authorized media, never personal devices, and follow any organizational restrictions or prohibitions on their use.Read the guide
- How can you protect yourself from identity theft? (Cyber Awareness)Review your credit report annually. In the DoD Cyber Awareness Challenge, the correct action is to order and review your free annual credit report so you can spot unauthorized accounts, inquiries, or activity that signal identity theft early.Read the guide
- Phishing Is Responsible for Most of the Recent PII Breaches: True or False?True. On DoD/DHA PII awareness training, the expected answer is True: phishing is cited as responsible for most recent PII breaches. If you discover exposed PII, report it immediately to your supervisor, privacy officer, or security team.Read the guide
- Which of the Following Is True of Compressed URLs?Compressed (shortened) URLs may be used to mask malicious intent. Because a service like TinyURL or bit.ly hides the true destination behind a short link, attackers can disguise phishing or malware sites as harmless, so you should preview the full address before clicking.Read the guide
- William Is a Sanitation Worker at a DoD Facility Who Posts a Photo Exposing Secret Documents — Is He an Insider Threat?Yes. William is a potential insider threat. He has authorized access to the facility, and intent is irrelevant — his photo unintentionally exposed Secret documents, compromising classified information. An insider threat can act unwittingly, and no security clearance is required to be one.Read the guide
- What type of information does this personnel roster represent?It represents Controlled Unclassified Information (CUI). A personnel roster contains personally identifiable information (PII) such as names and duty data, which requires safeguarding, so it is categorized as CUI rather than plain unclassified information.Read the guide