SAPPC EXAM PAPER QUESTIONS AND ANSWERS
SURE A+
✔✔The concept of an insider threat - ✔✔An employee who may represent a threat to
national security. These threats encompass potential espionage, violent acts against the
Government or the nation, and unauthorized disclosure of classified information,
including the vast amounts of classified data available on interconnected United States
Government computer networks and systems.
✔✔The purpose of the Foreign Visitor Program - ✔✔To track and approve access by a
foreign entity to information that is classified; and to approve access by a foreign entity
to information that is unclassified, related to a U.S. Government contract, or plant visits
covered by ITAR.
✔✔True - ✔✔True or False: Special access requirements are designed to provide an
additional layer of security to some of our nation's most valuable assets.
✔✔False. Threats and vulnerabilities are related but distinct. Threats to national security
exploit vulnerabilities. - ✔✔True or False: There is no difference between a threat and a
vulnerability.
✔✔What SAPs aim to achieve - ✔✔1. Protect technological breakthroughs
2. Cover exploitation of adversary vulnerabilities
3. Protect sensitive operational plans
4. Reduce intelligence on U.S. capabilities
✔✔Protection Level - ✔✔This communicates how the SAP is acknowledged and
protected.
✔✔Acknowledged - ✔✔This protection level describes a SAP whose existence may be
openly recognized. Its purpose may be identified. However, the details of the program
(including its technologies, materials, and techniques) are classified as dictated by their
,vulnerability to exploitation and the risk of compromise. The funding is generally
unclassified.
✔✔Unacknowledged - ✔✔This protection level describes a SAP whose existence and
purpose are protected. The details, technologies, materials, and techniques are
classified as dictated by their vulnerability to exploitation and the risk of compromise.
The program funding is often classified, unacknowledged, or not directly linked to the
program.
✔✔SAP Lifecycle - ✔✔1. Establishment (is extra protection warranted?)
2. Management and Administration (continued need? processed followed?)
3. Apportionment (proper measures in place? approval received)
4. Disestablishment (program no longer needed?)
✔✔Component-level SAP Central Offices - ✔✔Exist for each military component, the
Joint Chiefs of Staff, Defense Advanced Research Projects Agency (DARPA), and
Missile Defense Agency (MDA)
✔✔Special Access Program Oversight Committee (SAPOC) - ✔✔The final SAP
approving body chaired by the Deputy Secretary of Defense
✔✔Senior Review Group (SRG) - ✔✔This group ensures there are no duplicative efforts
across SAPs
✔✔DoD Special Access Central Office (SAPCO) - ✔✔DoD SAP legislative liaison that
notifies Congress of SAP approval
✔✔Authorization, Appropriations, and Intelligence Congressional - ✔✔Congressional
committees granted SAP access
✔✔OSD-level SAP Central Offices - ✔✔Exercise oversight authority for the specific
SAP category under their purview.
✔✔Information System Security Managers (ISSM) - ✔✔Responsible for the security of
information systems. They coordinate physical security measures and develop
contingency plans for the protection of the information system.
✔✔DD 1540 - ✔✔Registration for scientific and technical info specs, government and
contractors are required to fill out form, contractor a separate form for each request
valid until contract expires
✔✔DD 441 DoD Security agreement - ✔✔a contractual agreement between the U.S.
government and a cleared contractor facility
, ✔✔DD 441-1 - ✔✔Appendage to Security Agreement - list cleared divisions or branch
offices that are included in and covered by the provisions of the organizations security
agreement and certification pertaining to foreign interest
✔✔DD 254 DoD Contract Security Classification Spec - ✔✔provides to the contractor
(or subcontractor) the security requirements and the classification guidance that would
be necessary to perform on a classified contract
✔✔DD 1847 - ✔✔SCI Indoctrination Memo - Used to precisely identify individuals when
it is necessary to certify their access to SCI
✔✔DD 1847-1 - ✔✔SCI NDA - used to precisely identify individuals when it is
necessary to certify their access to SCI, non-disclosure agreement
✔✔DD 1848 - ✔✔SCI Debrief memo - A memo that records the fact that and individual
was debriefed on a SCI SAP
✔✔DD 1870 - ✔✔Request for personnel security investigation SSBI, PR, SII or ENAC
✔✔DD 2024 - ✔✔DoD SCG Data Elements - this form is executed by the originator of
each SCG issued pursuant to the req of DoD 5200.1-R, info sec program regulation to
report: - approval (promulgation) of a new SCG; - revision of a SCG; reissuance;
accomplishment of the biennial review; - cancellation; - correction of data on previously
submitted form
✔✔DD 2056 - ✔✔Telephone monitoring notification decal. Used to notify a user that the
telephone is subject to monitoring at all times, used of that telephone constitutes
consent to monitoring
✔✔DD 2501 - ✔✔Courier Authorization - used to identify appropriately cleared
personnel 1) recurrent need, 2) signed by appropriate security person, 3) Forms are
controlled to preclude unauthorized use, 4) issued for no more than 1 year, 5) followed
approved processes for SCI or SAP
✔✔DIS FL 381-R - ✔✔Letter of notification of facility security clearance. This document
notifies a facility that they are cleared to handle classified material
✔✔DISCO Form 2 - ✔✔Request for Forms - additional PSQ and NAQ forms may be
ordered from DISCO with this form
✔✔DISCO Form 560 - ✔✔Letter of Consent - Used by DISCO to notify a contractor that
a PCL or limited access authorization has been granted to an employee
SURE A+
✔✔The concept of an insider threat - ✔✔An employee who may represent a threat to
national security. These threats encompass potential espionage, violent acts against the
Government or the nation, and unauthorized disclosure of classified information,
including the vast amounts of classified data available on interconnected United States
Government computer networks and systems.
✔✔The purpose of the Foreign Visitor Program - ✔✔To track and approve access by a
foreign entity to information that is classified; and to approve access by a foreign entity
to information that is unclassified, related to a U.S. Government contract, or plant visits
covered by ITAR.
✔✔True - ✔✔True or False: Special access requirements are designed to provide an
additional layer of security to some of our nation's most valuable assets.
✔✔False. Threats and vulnerabilities are related but distinct. Threats to national security
exploit vulnerabilities. - ✔✔True or False: There is no difference between a threat and a
vulnerability.
✔✔What SAPs aim to achieve - ✔✔1. Protect technological breakthroughs
2. Cover exploitation of adversary vulnerabilities
3. Protect sensitive operational plans
4. Reduce intelligence on U.S. capabilities
✔✔Protection Level - ✔✔This communicates how the SAP is acknowledged and
protected.
✔✔Acknowledged - ✔✔This protection level describes a SAP whose existence may be
openly recognized. Its purpose may be identified. However, the details of the program
(including its technologies, materials, and techniques) are classified as dictated by their
,vulnerability to exploitation and the risk of compromise. The funding is generally
unclassified.
✔✔Unacknowledged - ✔✔This protection level describes a SAP whose existence and
purpose are protected. The details, technologies, materials, and techniques are
classified as dictated by their vulnerability to exploitation and the risk of compromise.
The program funding is often classified, unacknowledged, or not directly linked to the
program.
✔✔SAP Lifecycle - ✔✔1. Establishment (is extra protection warranted?)
2. Management and Administration (continued need? processed followed?)
3. Apportionment (proper measures in place? approval received)
4. Disestablishment (program no longer needed?)
✔✔Component-level SAP Central Offices - ✔✔Exist for each military component, the
Joint Chiefs of Staff, Defense Advanced Research Projects Agency (DARPA), and
Missile Defense Agency (MDA)
✔✔Special Access Program Oversight Committee (SAPOC) - ✔✔The final SAP
approving body chaired by the Deputy Secretary of Defense
✔✔Senior Review Group (SRG) - ✔✔This group ensures there are no duplicative efforts
across SAPs
✔✔DoD Special Access Central Office (SAPCO) - ✔✔DoD SAP legislative liaison that
notifies Congress of SAP approval
✔✔Authorization, Appropriations, and Intelligence Congressional - ✔✔Congressional
committees granted SAP access
✔✔OSD-level SAP Central Offices - ✔✔Exercise oversight authority for the specific
SAP category under their purview.
✔✔Information System Security Managers (ISSM) - ✔✔Responsible for the security of
information systems. They coordinate physical security measures and develop
contingency plans for the protection of the information system.
✔✔DD 1540 - ✔✔Registration for scientific and technical info specs, government and
contractors are required to fill out form, contractor a separate form for each request
valid until contract expires
✔✔DD 441 DoD Security agreement - ✔✔a contractual agreement between the U.S.
government and a cleared contractor facility
, ✔✔DD 441-1 - ✔✔Appendage to Security Agreement - list cleared divisions or branch
offices that are included in and covered by the provisions of the organizations security
agreement and certification pertaining to foreign interest
✔✔DD 254 DoD Contract Security Classification Spec - ✔✔provides to the contractor
(or subcontractor) the security requirements and the classification guidance that would
be necessary to perform on a classified contract
✔✔DD 1847 - ✔✔SCI Indoctrination Memo - Used to precisely identify individuals when
it is necessary to certify their access to SCI
✔✔DD 1847-1 - ✔✔SCI NDA - used to precisely identify individuals when it is
necessary to certify their access to SCI, non-disclosure agreement
✔✔DD 1848 - ✔✔SCI Debrief memo - A memo that records the fact that and individual
was debriefed on a SCI SAP
✔✔DD 1870 - ✔✔Request for personnel security investigation SSBI, PR, SII or ENAC
✔✔DD 2024 - ✔✔DoD SCG Data Elements - this form is executed by the originator of
each SCG issued pursuant to the req of DoD 5200.1-R, info sec program regulation to
report: - approval (promulgation) of a new SCG; - revision of a SCG; reissuance;
accomplishment of the biennial review; - cancellation; - correction of data on previously
submitted form
✔✔DD 2056 - ✔✔Telephone monitoring notification decal. Used to notify a user that the
telephone is subject to monitoring at all times, used of that telephone constitutes
consent to monitoring
✔✔DD 2501 - ✔✔Courier Authorization - used to identify appropriately cleared
personnel 1) recurrent need, 2) signed by appropriate security person, 3) Forms are
controlled to preclude unauthorized use, 4) issued for no more than 1 year, 5) followed
approved processes for SCI or SAP
✔✔DIS FL 381-R - ✔✔Letter of notification of facility security clearance. This document
notifies a facility that they are cleared to handle classified material
✔✔DISCO Form 2 - ✔✔Request for Forms - additional PSQ and NAQ forms may be
ordered from DISCO with this form
✔✔DISCO Form 560 - ✔✔Letter of Consent - Used by DISCO to notify a contractor that
a PCL or limited access authorization has been granted to an employee