SECURITY FUNDAMENTALS PROFESSIONAL CERTIFICATION (SFPC)
300 PRACTICE QUESTIONS WITH
CORRECT ANSWERS & DETAILED RATIONALES 2026–2027 UPDATE |
COMPREHENSIVE TEST BANK
TABLE OF CONTENTS
SECTION 1: INFORMATION SECURITY ...................................... Questions 1-80
Classification & Declassification Concepts ....................... Q1-25
Classification Management & Markings ............................. Q26-45
Information Security Program & Cyber ............................. Q46-65
Data Spills, Compilation & Special Considerations ............... Q66-80
SECTION 2: PERSONNEL SECURITY ........................................ Questions 81-140
Personnel Security Investigations (PSI) .......................... Q81-100
Adjudication & Clearance Eligibility ............................. Q101-120
Continuous Vetting, Briefings & Reporting ........................ Q121-140
SECTION 3: PHYSICAL SECURITY ......................................... Questions 141-190
Physical Security Concepts & Access Control ...................... Q141-160
Security Containers, Facilities & Intrusion Detection ............ Q161-180
Emergency Preparedness & Anti-Terrorism .......................... Q181-190
SECTION 4: INDUSTRIAL SECURITY ....................................... Questions 191-245
National Industrial Security Program (NISP) & NISPOM ............ Q191-210
Facility Security Clearances (FCL) & FOCI ........................ Q211-225
DD Form 254, Contracts & Cognizant Security Agencies (CSAs) ..... Q226-245
SECTION 5: GENERAL SECURITY .......................................... Questions 246-300
Threat, Vulnerability & Risk Assessment .......................... Q246-265
Counterintelligence (CI) Concepts ................................ Q266-280
Operations Security (OPSEC) ...................................... Q281-295
Security Governance & Miscellaneous .............................. Q296-300
SECTION 1: INFORMATION SECURITY (Questions 1-80)
Q1. What is the definition of non-repudiation in information security?
A) Protection against an individual falsely denying having performed a particular
action
1
,B) Preserving authorized restrictions on information access and disclosure
C) The process of determining the potential impact of a security breach
D) The unauthorized disclosure of classified information
Answer: A
Rationale: Non-repudiation provides the capability to determine whether a given
individual took a particular action such as creating information, sending a
message, approving information, or receiving a message[reference:0]. B describes
confidentiality. C describes system categorization. D describes a data spill.
Q2. Which of the following best describes the impact of a cybersecurity lapse
on non-repudiation?
A) The sender could deny the message was sent
B) Unauthorized persons could gain access to classified information
C) Information could be modified without detection
D) The system could become unavailable to users
Answer: A
Rationale: Without non-repudiation, a sender could deny that a message was
sent,
and a recipient could change a message and contest that the altered version was
the original[reference:1]. B describes a confidentiality breach. C relates to
integrity. D relates to availability.
Q3. What is the definition of confidentiality in information security?
A) Preserving authorized restrictions on information access and disclosure
B) Protection against an individual falsely denying an action
2
,C) The process of categorizing information systems
D) The unauthorized transmission of classified information
Answer: A
Rationale: Confidentiality means preserving authorized restrictions on
information access and disclosure, including means for protecting personal
privacy and proprietary information[reference:2]. B describes non-repudiation.
C describes system categorization. D describes a data spill.
Q4. Which of the following is a negative impact of a cybersecurity lapse on
confidentiality?
A) Persons could be granted access to information beyond their need-to-know
B) The sender could deny the message was sent
C) Information could be altered without detection
D) Systems could become unavailable
Answer: A
Rationale: Without confidentiality, persons could be granted access to
information beyond their need-to-know, and sensitive or classified information
could be disclosed to an unauthorized system[reference:3]. B describes
non-repudiation. C describes integrity. D describes availability.
Q5. What is system categorization?
A) The process by which the Information Owner identifies the potential impact
(low, moderate, or high) from loss of confidentiality, integrity, and availability
B) The process of assigning classification markings to documents
C) The process of determining who has access to a system
3
, D) The process of declassifying information after 25 years
Answer: A
Rationale: System categorization is the process by which the Information Owner
identifies the potential impact (low, moderate, or high) that would result from
the loss of confidentiality, integrity, and availability should a security breach
occur[reference:4]. B describes classification marking. C describes access
control. D describes automatic declassification.
Q6. What are the three security objectives evaluated during system
categorization?
A) Confidentiality, Integrity, and Availability
B) Secrecy, Privacy, and Non-repudiation
C) Authentication, Authorization, and Accounting
D) Prevention, Detection, and Response
Answer: A
Rationale: System categorization evaluates the potential impact from the loss of
confidentiality, integrity, and availability (the CIA triad)[reference:5]. B includes
non-repudiation but is not the primary triad. C is the AAA model for access
control. D is not a standard security triad.
Q7. What is a data spill?
A) The unauthorized transfer of classified information to an unclassified system
B) The authorized declassification of information
C) The proper destruction of classified documents
D) The routine transmission of classified information
4