*Spillage
After reading an online story about a new security project being developed on the military installation where you work, your neighbor asks you
... [Show More] to comment about the article. You know that this project is classified. How should you respond?
Attempt to change the subject to something non-work related, but neither confirm nor deny the article's authenticity
*Spillage
Which of the following may help to prevent spillage?
Label all files, removable media, and subject headers with appropriate classification markings.
*Spillage
A user writes down details marked as Secret from a report stored on a classified system and uses those details to draft a briefing on an unclassified system without authorization. What is the best choice to describe what has occurred?
Spillage because classified data was moved to a lower classification level system without authorization.
*Spillage
What should you do when you are working on an unclassified system and receive an email with a classified attachment?
Call your security point of contact immediately
*Spillage
What should you do if a reporter asks you about potentially classified information on the web?
Ask for information about the website, including the URL.
*Spillage
.What should you do if a reporter asks you about potentially classified information on the web?
Refer the reporter to your organization's public affairs office.
*Spillage
What should you do if you suspect spillage has occurred?
Immediately notify your security point of contact
*Spillage
Which of the following is a good practice to prevent spillage?
Be aware of classification markings and all handling caveats.
*Spillage
Which of the following actions is appropriate after finding classified information on the Internet?
Note any identifying information and the website's Uniform Resource Locator (URL)
*Spillage
Which of the following may help to prevent spillage?
-Verify that any government equipment used for processing classified information has valid anti-virus software before connecting it to the internet
-Follow procedures for transferring data to and from outside agency and non-Government networks
-Purge the memory of any device removed from a classified network before connecting it to an unclassified network
-Process all data at the highest classification or protection level available, including unclassified data
~Verify that any government equipment used for processing classified information has valid anti-virus software before connecting it to the internet (wrong)
~Follow procedures for transferring data to and from outside agency and non-Government networks
*Spillage
You find information that you know to be classified on the Internet. What should you do?
~Note the website's URL and report the situation to your security point of contact
**Classified Data
When classified data is not in use, how can you protect it?
Store classified data appropriately in a GSA-approved vault/container.
**Classified Data
What is required for an individual to access classified data?
Appropriate clearance, a signed and approved non-disclosure agreement, and need-to-know
**Classified Data
Which classification level is given to information that could reasonably be expected to cause serious damage to national security?
Secret
**Classified Data
Which of the following is a good practice to protect classified information?
Ensure proper labeling by appropriately marking all classified material and, when required, sensitive material
**Classified Data
Which of the following is true of protecting classified data?
Classified material must be appropriately marked.
**Classified Data
What level of damage can the unauthorized disclosure of information classified as Confidential reasonably be expected to cause?
Damage to national security
**Classified Data
Which of the following is true of telework?
You must have permission from your organization.
**Classified Data
Which type of information could reasonably be expected to cause serious damage to national security if disclosed without authorization?
Secret
**Classified Data
How should you protect a printed classified document when it is not in use?
Store it in a General Services Administration (GSA)-approved vault or container
**Classified Data
Who designates whether information is classified and its classification level?
~National Security Agency (NSA) (Wrong)
**Classified Data
Which of the following is a good practice for telework?
~Use a Virtual Private Network (VPN) to obscure your true geographic location
**Insider Threat
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague vacations at the beach every year, is married and a father of four, sometimes has poor work quality, and works well with his team.
~0 indicator
**Insider Threat
How many potential insider threat indicators does a coworker who often makes others uneasy by being persistent in trying to obtain information about classified projects to which he has no access, is boisterous about his wife putting them in credit card debt, and often complains about anxiety and exhaustion display?
3 or more indicators
**Insider Threat
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague is playful and charming, consistently wins performance awards, and is occasionally aggressive in trying to access classified information.
1 indicator
**Insider Threat
What advantages do "insider threats" have over others that allows them to cause damage to their organizations more easily?
Insiders are given a level of trust and have authorized access to Government information systems
**Insider Threat
What type of activity or behavior should be reported as a potential insider threat?
Coworker making consistent statements indicative of hostility or anger toward the United States in its policies.
**Insider Threat
Which of the following should be reported as a potential security incident?
A coworker removes sensitive information without authorization
**Insider Threat
Which scenario might indicate a reportable insider threat?
A coworker uses a personal electronic device in a secure area where their use is prohibited.
**Insider Threat
Based on the description that follows, how many potential insider threat indicator(s) are displayed? A colleague often makes others uneasy with her persistent efforts to obtain information about classified project where she has no need-to-know, is vocal about her husband overspending on credit cards, and complains about anxiety and exhaustion.
3 or more indicators
**Insider Threat
Which type of behavior should you report as a potential insider threat?
Hostility or anger toward the United States and its policies
**Insider Threat
Which of the following is NOT considered a potential insider threat indicator?
Treated mental health issues
**Insider Threat
What function do Insider Threat Programs aim to fulfill?
Proactively identify potential threats and formulate holistic mitigation responses
**Insider Threat
Which of the following is a potential insider threat indicator?
Difficult life circumstances, such as death of a spouse
**Insider Threat
Which of the following is a potential insider threat indicator?
Unusual interest in classified information
**Social Networking
When is the safest time to post details of your vacation activities on your social networking profile?
After you have returned home following the vacation
**Social Networking
What should you do if you receive a game application request that includes permission to access your friends, profile information, cookies, and sites visited?
Decline the request
**Social Networking
Which of the following information is a security risk when posted publicly on your social networking profile?
Pictures of your pet
Your birthday
Your hobbies
~Your personal e-mail address
**Social Networking
Which of the following is a security best practice when using social networking sites?
Understanding and using the available privacy settings [Show Less]