Docsity
Docsity

Prepare for your exams
Prepare for your exams

Study with the several resources on Docsity


Earn points to download
Earn points to download

Earn points by helping other students or get them with a premium plan


Guidelines and tips
Guidelines and tips

Cyber Awareness Challenge, Exercises of Cybercrime, Cybersecurity and Data Privacy

Various cybersecurity best practices and guidelines related to handling sensitive information, protecting against cyber threats, and maintaining secure computing environments. It covers topics such as email security, mobile device usage, password management, physical security, social engineering, and insider threats. Information on how to properly handle classified data, protect against identity theft, and prevent data spillage. It also addresses wireless security, malicious code, and the use of removable media. The document aims to educate users on cybersecurity awareness and the importance of following security protocols to safeguard sensitive information and mitigate potential risks.

Typology: Exercises

2023/2024

Available from 10/08/2024

peter-githongo
peter-githongo 🇺🇸

11 documents

1 / 6

Toggle sidebar

This page cannot be seen from the preview

Don't miss anything!

bg1
Cyber Awareness Challenge
It is getting late on Friday. You are reviewing your employees annual self evaluation.
Your comments are due on Monday. You can email your employees information to
yourself so you can work on it this weekend and go home now. Which method would be
the BEST way to send this information? - Use the government email system so you can
encrypt the information and open the email on your government issued laptop
What should you do if someone asks to use your government issued mobile device
(phone/laptop..etc)? - Decline to lend your phone / laptop
Where should you store PII / PHI? - Information should be secured in a cabinet or
container while not in use
Of the following, which is NOT an intelligence community mandate for passwords? -
Maximum password age of 45 days
Which of the following is NOT Government computer misuse? - Checking work email
Which is NOT a telework guideline? - Taking classified documents from your workspace
What should you do if someone forgets their access badge (physical access)? - Alert
the security office
What can you do to protect yourself against phishing? - All of the above
What should you do to protect classified data? - Answer 1 and 2 are correct
What action is recommended when somebody calls you to inquire about your work
environment or specific account information? - Ask them to verify their name and office
number
If classified information were released, which classification level would result in
"Exceptionally grave damage to national security"? - Top Secret
Which of the following is NOT considered sensitive information? - Sanitized information
gathered from personnel records
Which of the following is NOT a criterion used to grant an individual access to classified
data? - Senior government personnel, military or civilian
Of the following, which is NOT a problem or concern of an Internet hoax? - Directing
you to a website that looks real
Media containing Privacy Act information, PII, and PHI is not required to be labeled. -
FALSE
pf3
pf4
pf5

Partial preview of the text

Download Cyber Awareness Challenge and more Exercises Cybercrime, Cybersecurity and Data Privacy in PDF only on Docsity!

It is getting late on Friday. You are reviewing your employees annual self evaluation. Your comments are due on Monday. You can email your employees information to yourself so you can work on it this weekend and go home now. Which method would be the BEST way to send this information? - Use the government email system so you can encrypt the information and open the email on your government issued laptop What should you do if someone asks to use your government issued mobile device (phone/laptop..etc)? - Decline to lend your phone / laptop Where should you store PII / PHI? - Information should be secured in a cabinet or container while not in use Of the following, which is NOT an intelligence community mandate for passwords? - Maximum password age of 45 days Which of the following is NOT Government computer misuse? - Checking work email Which is NOT a telework guideline? - Taking classified documents from your workspace What should you do if someone forgets their access badge (physical access)? - Alert the security office What can you do to protect yourself against phishing? - All of the above What should you do to protect classified data? - Answer 1 and 2 are correct What action is recommended when somebody calls you to inquire about your work environment or specific account information? - Ask them to verify their name and office number If classified information were released, which classification level would result in "Exceptionally grave damage to national security"? - Top Secret Which of the following is NOT considered sensitive information? - Sanitized information gathered from personnel records Which of the following is NOT a criterion used to grant an individual access to classified data? - Senior government personnel, military or civilian Of the following, which is NOT a problem or concern of an Internet hoax? - Directing you to a website that looks real Media containing Privacy Act information, PII, and PHI is not required to be labeled. - FALSE

Which of the following is NOT a home security best practice? - Setting weekly time for virus scan when you are not on the computer and it is powered off Which of the following best describes wireless technology? - It is inherently not a secure technology You are leaving the building where you work. What should you do? - Remove your security badge Which of the following is a good practice to avoid email viruses? - Delete email from senders you do not know What is considered a mobile computing device and therefore shouldn't be plugged in to your Government computer? - All of the above Which is NOT a way to protect removable media? - As a best practice, labeling all classified removable media and considering all unlabeled removable media as unclassified What is NOT Personally Identifiable Information (PII)? - Hobby Of the following, which is NOT a method to protect sensitive information? - After work hours, storing sensitive information in unlocked containers, desks, or cabinets if security is not present There are many travel tips for mobile computing. Which of the following is NOT one? - When using a public device with a card reader, only use your DoD CAC to access unclassified information The use of webmail is - is only allowed if the organization permits it What is considered ethical use of the Government email system? - Distributing Company newsletter Which of the following attacks target high ranking officials and executives? - Whaling What constitutes a strong password? - all of the above You are logged on to your unclassified computer and just received an encrypted email from a co-worker. The email has an attachment whose name contains the word "secret". What should you do? - Contact your security POC right away Which is a way to protect against phishing attacks? - Look for digital certificates

Classified Information can only be accessed by individuals with - All of the above Which of the following definitions is true about disclosure of confidential information? - Damage to national security It is permissible to release unclassified information to the public prior to being cleared. - False Which of the following is NOT sensitive information? - Unclassified information cleared for public release What should you do to protect yourself while on social networks? - Validate all friend requests through another source before confirming them Which is NOT a method of protecting classified data? - Assuming open storage is always authorized in a secure facility What can you do to prevent spillage? - all of the above Which of the following makes Alex's personal information vulnerable to attacks by identity thieves? - Carrying his Social Security Card with him DoD employees are prohibited from using a DoD CAC in card-reader-enabled public devices. - TRUE Which of the following is an example of malicious code? - Trojan horses Which of the following is NOT PII? - Mother's maiden name, favorite color Classified Information is - Assigned a classification level by a supervisor Maria is at home shopping for shoes on Amazon.com. Before long she has also purchased shoes from several other websites. What can be used to track Maria's web browsing habits? - Cookies Which is an untrue statement about unclassified data? - If aggregated, the classification of the information may not be changed A medium secure password has at least 15 characters and one of the following. - Special character PII, PHI, and financial information is classified as what type of information? - Sensitive The CAC/PIV is a controlled item and contains certificates for: - All of the above

An individual who has attempted to access sensitive information without need-to-know and has made unusual requests for sensitive information is displaying indicators of what? - Potential Insider Threat Which of the following is NOT a social engineering tip? - Following instructions from verified personnel Bob, a coworker, has been going through a divorce, has financial difficulties and is displaying hostile behavior. How many potential insider threat indicators is Bob displaying? - 3 You are working at your unclassified system and receive an email from a coworker containing a classified attachment. What should you do? - Alert your security POC You check your bank statement and see several debits you did not authorize. You believe that you are a victim of identity theft. Which of the following should you do immediately? - Monitor credit card statements for unauthorized purchases Thumb drives, memory sticks, and flash drives are examples of - Removable media What information relates to the physical or mental health of an individual? - PHI What should be done if you find classified Government Data/Information Not Cleared for Public Release on the Internet? - Make note of any identifying information and the website URL and report it to your security office All https sites are legitimate and there is no risk to entering your personal info online. - FALSE When using a fax machine to send sensitive information, the sender should do which of the following? - Contact the recipient to confirm receipt What should be done to protect against insider threats? - Report any suspicious behavior Which of the following is NOT a potential insider threat? - Member of a religion or faith Of the following, which is NOT a security awareness tip? - Remove security badge as you enter a restaurant or retail establishment ActiveX is a type of this? - Mobile code Which of the following is NOT a security best practice when saving cookies to a hard drive? - Looking for "https" in the URL. All https sites are legitimate.