Bank 2026/2027: 100 Practice Questions with
Answers | DoDD 5240.06, FIE Threats,
Insider Risk, Cybersecurity, PEIs & GAO
Updates
Description:
Master the DOD Counterintelligence and Security Awareness Exam with this comprehensive
2026/2027 test bank featuring 100 expertly crafted multiple-choice questions and detailed
explanations. Covers DoDD 5240.06 reporting requirements, Foreign Intelligence Entity
(FIE) collection methods, Potential Espionage Indicators (PEIs), insider threat detection,
cybersecurity vulnerabilities, NIST SP 800-171 Revision 3, DFARS compliance, False
Claims Act enforcement, Civil Cyber-Fraud Initiative, emerging AI threats, and the latest
GAO findings on digital footprint risks. Updated for 2026/2027 academic standards with
scenario-based questions, regulatory frameworks, and contemporary threat landscape coverage.
Perfect for DOD personnel, contractors, security professionals, and students preparing for CI
awareness certification.
Download now and pass with confidence!
, DOD CI Exam Bank 2026: 100 Questions & Answers
SECTION A: FOUNDATIONAL CONCEPTS AND DEFINITIONS
Question 1:
Which of the following represents a complete list of cybersecurity vulnerabilities to Department
of Defense-controlled unclassified information (CUI) and classified systems?
A. Disgruntled or co-opted employees and weak password protocols
B. Illegal downloads and unauthorized data transfers
C. Weak passwords, illegal downloads, and disgruntled employees
D. All of the above
Answer: D
Explanation: All listed elements constitute significant cybersecurity vulnerabilities. Disgruntled
employees pose insider threats, weak passwords create access vulnerabilities, and illegal
downloads can introduce malware or facilitate data exfiltration. The comprehensive nature of
these vulnerabilities requires multilayered defensive strategies.
Question 2:
According to DOD Directive 5240.06, personnel who fail to report counterintelligence (CI)
activities of concern are subject to appropriate disciplinary action under applicable regulations.
A. True
B. False
Answer: A
Explanation: Enclosure 4 of DOD Directive 5240.06 explicitly mandates reporting requirements
for CI activities of concern. Failure to comply with these reporting obligations constitutes a
violation of regulatory requirements and subjects personnel to disciplinary measures under
applicable military and civilian personnel regulations.
,Question 3:
The definition of Counterintelligence (CI) as established in Executive Order 12333, as amended,
encompasses which of the following activities?
A. Information gathered and activities conducted to protect against espionage and sabotage
B. Protection against assassinations conducted by foreign governments or organizations
C. Protection against international terrorist activities
D. All of the above
Answer: D
Explanation: Executive Order 12333, as amended, defines counterintelligence broadly as
information gathered and activities conducted to protect against espionage, other intelligence
activities, sabotage, and assassinations conducted by or on behalf of foreign governments,
foreign organizations, foreign persons, or international terrorist activities. This comprehensive
definition establishes the framework for CI operations and responsibilities.
Question 4:
Which statement accurately characterizes Foreign Intelligence Entities (FIE) and their use of
elicitation techniques?
A. Foreign Intelligence Entities seldom use elicitation to extract information from personnel with
classified access
B. Foreign Intelligence Entities primarily rely on cyber exploitation rather than human elicitation
C. Foreign Intelligence Entities frequently use elicitation as a primary collection method
D. Elicitation techniques are only effective against personnel without security clearances
Answer: C
Explanation: Foreign Intelligence Entities extensively employ elicitation techniques as a
primary human intelligence collection method. These techniques involve subtle, seemingly
innocuous questioning designed to extract sensitive information from personnel with access to
classified or privileged information, making them particularly effective and dangerous.
, SECTION B: POTENTIAL ESPIONAGE INDICATORS (PEIs)
Question 5:
Potential Espionage Indicators (PEIs) are observable activities, behaviors, or circumstances that
may suggest potential espionage activities. Which of the following constitutes a valid PEI?
A. Unexplained affluence and concealing foreign travel
B. Taking classified material home without authorization
C. Attempting to access information without a valid need-to-know
D. All of the above
Answer: D
Explanation: All listed behaviors are recognized PEIs under current counterintelligence
doctrine. Additional PEIs include working unusual hours, avoiding polygraph examinations,
engaging in illegal downloads, maintaining unreported contact with foreign nationals, exhibiting
disgruntlement, taking unexplained short trips, and copying files without authorization.
Question 6:
An individual who demonstrates unexplained affluence, frequently travels abroad without
reporting these trips, and attempts to access classified information without a valid need-to-know
is exhibiting:
A. Normal professional behavior in the intelligence community
B. Potential Espionage Indicators that warrant investigation
C. Standard clearance verification procedures
D. Acceptable deviations from security protocols
Answer: B
Explanation: The combination of unexplained affluence, concealed foreign travel, and
unauthorized access attempts represents multiple PEIs that collectively suggest possible
espionage activity. Security personnel should report such behavioral patterns through proper CI
channels for assessment.