SAPPC CERTIFICATION 409 COMPREHENSIVE
TEST PAPER QUESTIONS AND SOLUTIONS
GRADED A+
◉ Regulation providing procedures to follow when classified
information is compromised?
Answer: DoD 5200.1-R: information Security Program
◉ What are three principle incidents/events required to report to
DoD counterintelligence (CI) organizations?
Answer: Espionage, Sabotage, Terrorism & Cyber Policy
◉ List three different types of threats to classified information?
Answer: Insider Threat, Foreign Intelligence Entities (FIE),
Cybersecurity Threat
◉ List three indicators of insider threats?
Answer: Failure to report overseas travel or contact with foreign
nationals.
Seeking to gain higher clearance or expand access outside the job
scope.
Engaging in classified conversations without a need to know.
,Working hours inconsistent with job assignment or insistence on
working in private.
Exploitable behavior traits.
Repeated security violations.
Attempting to enter areas not granted access to.
◉ List three elements that should be considered in identifying
Critical Program Information?
Answer: - Cause significant degradation in mission effectiveness
- Shorten the expected combat-effective life of the system
- Reduce technological advantage
- Significantly alter program direction
- Enable an adversary to defeat, counter, copy, or reverse-engineer
the technology or capability.
◉ Briefly describe the concept of insider threat?
Answer: An employee who may represent a threat to national
security. These threats encompass potential espionage, violent acts
against the Government or the nation, and unauthorized disclosure
of classified information, including the vast amounts of classified
data available on interconnected United States Government
computer networks and systems.
, ◉ List three elements that a security professional should consider
when assessing and managing risks to DoD assets?
Answer: Asset
Threat
Vulnerability
Risk
Countermeasures
◉ Describe the purpose of the Foreign Visitor Program?
Answer: To track and approve access by a foreign entity to
information that is classified; and to approve access by a foreign
entity to information that is unclassified, related to a U.S.
Government contract, or plant visits covered by ITAR.
◉ Briefly define a Special Access Program (SAP)?
Answer: A program established for a specific class of classified
information that imposes safeguarding and access requirements that
exceed those normally required for information at the same
classification level.
◉ List three enhanced security requirements for protecting Special
Access Program (SAP) Information within Personnel Security?
Answer: Access Rosters
Billet Structures (if required)
TEST PAPER QUESTIONS AND SOLUTIONS
GRADED A+
◉ Regulation providing procedures to follow when classified
information is compromised?
Answer: DoD 5200.1-R: information Security Program
◉ What are three principle incidents/events required to report to
DoD counterintelligence (CI) organizations?
Answer: Espionage, Sabotage, Terrorism & Cyber Policy
◉ List three different types of threats to classified information?
Answer: Insider Threat, Foreign Intelligence Entities (FIE),
Cybersecurity Threat
◉ List three indicators of insider threats?
Answer: Failure to report overseas travel or contact with foreign
nationals.
Seeking to gain higher clearance or expand access outside the job
scope.
Engaging in classified conversations without a need to know.
,Working hours inconsistent with job assignment or insistence on
working in private.
Exploitable behavior traits.
Repeated security violations.
Attempting to enter areas not granted access to.
◉ List three elements that should be considered in identifying
Critical Program Information?
Answer: - Cause significant degradation in mission effectiveness
- Shorten the expected combat-effective life of the system
- Reduce technological advantage
- Significantly alter program direction
- Enable an adversary to defeat, counter, copy, or reverse-engineer
the technology or capability.
◉ Briefly describe the concept of insider threat?
Answer: An employee who may represent a threat to national
security. These threats encompass potential espionage, violent acts
against the Government or the nation, and unauthorized disclosure
of classified information, including the vast amounts of classified
data available on interconnected United States Government
computer networks and systems.
, ◉ List three elements that a security professional should consider
when assessing and managing risks to DoD assets?
Answer: Asset
Threat
Vulnerability
Risk
Countermeasures
◉ Describe the purpose of the Foreign Visitor Program?
Answer: To track and approve access by a foreign entity to
information that is classified; and to approve access by a foreign
entity to information that is unclassified, related to a U.S.
Government contract, or plant visits covered by ITAR.
◉ Briefly define a Special Access Program (SAP)?
Answer: A program established for a specific class of classified
information that imposes safeguarding and access requirements that
exceed those normally required for information at the same
classification level.
◉ List three enhanced security requirements for protecting Special
Access Program (SAP) Information within Personnel Security?
Answer: Access Rosters
Billet Structures (if required)