SFPC ACTUAL FINALS QUESTIONS AND ANSWERS
SET A+
✔✔What is the purpose of DD Form 254?
a. To convey security classification guidance and to advise contractors on the handling
procedures for classified material.
b. To document the formal agreement between the US government and a cleared
contractor in which the contactor agrees to maintain a security program in compliance
with the NISPOM and the government agrees to security guidance and program
oversight.
c. To validate details regarding the foreign ownership, control or influence affecting that
cleared contractor facility.
d. It replaces the actual contract document for any contract requiring access to
classified information. - ✔✔A
✔✔As part of Operations Security (OPSEC), a program coordinator should use which of
the following tools to assess assets as part of the risk management process for critical
information?
a. Critical Information List
b. Threat vulnerability matrix
c. Risk Rating Table
d. Security Classification Guide - ✔✔A
✔✔What is the role of the Special Access Program Oversight Committee (SAPOC)
during the maintenance phase
of the Special Access Program (SAP) lifecycle?
a. To ensure that the SAP has adequate Internal Review and Audit Compliance (IRAC)
support, including accessed auditors at supporting offices, to meet program audit
needs.
b. To review existing programs annually to determine whether to revalidate them as
SAPs.
c. To provide oversight of SAP program and budget accomplishments.
d. To provide oversight of SAP audits and inspections. - ✔✔B
, ✔✔Which of the following describes a Special Access Program (SAP) that is
established to protect sensitive research, development, testing and evaluation,
modification, and procurement activities?
a. Research and Technology SAP
b. Operations and Support SAP
c. Acquisition SAP
d. Intelligence SAP - ✔✔C
✔✔Which type of briefing is used to identify security responsibilities, provide a basic
understanding of DoD security policies, and explain the importance of protecting
government assets?
a. Indoctrination Briefing
b. Original Classification Authority (OCA)
Briefing
c. Foreign Travel Briefing
d. Debriefing - ✔✔A
✔✔Which type of briefing is used to reinforce the information provided during the initial
security briefing and to keep cleared employees informed of appropriate changes in
security regulations?
a. Annual Refresher Briefings
b. Indoctrination Briefings
c. Attestation Briefings
d. Courier Briefings - ✔✔A
✔✔Which step of the Operations Security (OPSEC) process would be applied when
conducting exercises, red teaming and analyzing operations?
a. Conduct a Risk Assessment
b. Apply OPSEC Countermeasures
c. Conduct a Threat Analysis
d. Conduct a Vulnerability Analysis - ✔✔B
✔✔Which step of the Operations Security (OPSEC) process would be applied when
identifying potential adversaries and the associated capabilities and intentions
to collect, analyze, and exploit critical information and indicators?
a. Conduct a Vulnerability Analysis
b. Conduct a Threat Analysis
c. Conduct a Risk Assessment
d. Apply OPSEC Countermeasures - ✔✔B
✔✔Please determine which of the following is an element of an Operations Security
(OPSEC) Assessment.
a. Small in scale and focused on evaluating the effectiveness of the OPSEC program.
b. Conducted on an annual basis.
SET A+
✔✔What is the purpose of DD Form 254?
a. To convey security classification guidance and to advise contractors on the handling
procedures for classified material.
b. To document the formal agreement between the US government and a cleared
contractor in which the contactor agrees to maintain a security program in compliance
with the NISPOM and the government agrees to security guidance and program
oversight.
c. To validate details regarding the foreign ownership, control or influence affecting that
cleared contractor facility.
d. It replaces the actual contract document for any contract requiring access to
classified information. - ✔✔A
✔✔As part of Operations Security (OPSEC), a program coordinator should use which of
the following tools to assess assets as part of the risk management process for critical
information?
a. Critical Information List
b. Threat vulnerability matrix
c. Risk Rating Table
d. Security Classification Guide - ✔✔A
✔✔What is the role of the Special Access Program Oversight Committee (SAPOC)
during the maintenance phase
of the Special Access Program (SAP) lifecycle?
a. To ensure that the SAP has adequate Internal Review and Audit Compliance (IRAC)
support, including accessed auditors at supporting offices, to meet program audit
needs.
b. To review existing programs annually to determine whether to revalidate them as
SAPs.
c. To provide oversight of SAP program and budget accomplishments.
d. To provide oversight of SAP audits and inspections. - ✔✔B
, ✔✔Which of the following describes a Special Access Program (SAP) that is
established to protect sensitive research, development, testing and evaluation,
modification, and procurement activities?
a. Research and Technology SAP
b. Operations and Support SAP
c. Acquisition SAP
d. Intelligence SAP - ✔✔C
✔✔Which type of briefing is used to identify security responsibilities, provide a basic
understanding of DoD security policies, and explain the importance of protecting
government assets?
a. Indoctrination Briefing
b. Original Classification Authority (OCA)
Briefing
c. Foreign Travel Briefing
d. Debriefing - ✔✔A
✔✔Which type of briefing is used to reinforce the information provided during the initial
security briefing and to keep cleared employees informed of appropriate changes in
security regulations?
a. Annual Refresher Briefings
b. Indoctrination Briefings
c. Attestation Briefings
d. Courier Briefings - ✔✔A
✔✔Which step of the Operations Security (OPSEC) process would be applied when
conducting exercises, red teaming and analyzing operations?
a. Conduct a Risk Assessment
b. Apply OPSEC Countermeasures
c. Conduct a Threat Analysis
d. Conduct a Vulnerability Analysis - ✔✔B
✔✔Which step of the Operations Security (OPSEC) process would be applied when
identifying potential adversaries and the associated capabilities and intentions
to collect, analyze, and exploit critical information and indicators?
a. Conduct a Vulnerability Analysis
b. Conduct a Threat Analysis
c. Conduct a Risk Assessment
d. Apply OPSEC Countermeasures - ✔✔B
✔✔Please determine which of the following is an element of an Operations Security
(OPSEC) Assessment.
a. Small in scale and focused on evaluating the effectiveness of the OPSEC program.
b. Conducted on an annual basis.