Basic COMSEC Policies and Procedures
Which best describes the purpose of COMSEC? - Answer-Denies adversaries access to information
Which of the following measures is taken to ensure the authenticity of information? - Answer-COMSEC
What COMSEC component provides protection from interception and exploitation? - Answer-
Transmission Security
Tier 0 - Answer-Consists of the key production facilities and NSA's Central Office of Record. Provides
centralized key management services for all forms of COMSEC key
Tier 1 - Answer-Intermediate key generation and distribution center, Central Office of Record (COR), and
privilege managers for COMSEC accounts
Tier 2 - Answer-Layer of COMSEC Material Control System (CMCS) comprised of the COMSEC Accounts
that manage key and other COMSEC material
Tier 3 - Answer-End user of COMSEC equipment and/or material (LE)
Who is the Commanding Officer's primary advisor on matters concerning the security and handling of
COMSEC material and the associated record, reports, and audits? - Answer-COMSEC Manager
,At which Tier do LEs reside? - Answer-Tier 3
Which entity operates as part of the NSA and functions primarily as a high volume key generation and
distribution center? - Answer-Central Facility
Which of the following is used to distribute, control, and safeguard COMSEC material? - Answer-CMCS
All COMSEC related information is covered within CMCS. - Answer-False
Effective key is key that is in the current period of time allowed for use. - Answer-True
For routine modification for material NOT previously authorized, managers must submit a request how
many days in advance? - Answer-60 Days
What term best describes the series of letters and numbers used to facilitate identification, handling,
accounting, and control of COMSEC material? - Answer-Short Title
Which of the following would be part of a short title for a United States Electronic Key? - Answer-USEAD
The quantity of future editions of keying material (i.e., ROB) to be held by a COMSEC account is
determined by the CNO, CMC, COGARD TISCOM, FLTCINCs, and/or ISICs. - Answer-True
Allowances are unique to the individual account. - Answer-True
Which are the responsibilities of the Controlling Authority? - Answer-Directs the establishment and
operations of cryptonet/circuits and manages the operational use and control of KEYMAT assigned to a
,cryptonet/circuit. Manages traditional COMSEC material. Evaluates COMSEC incidents and authorizes
the issue/destruction of COMSEC material.
Which are the responsibilities of the CA/CMDAUTH? - Answer-Validates CF Form 1206 prior to
submission to Central Facility. Grants privileges to URs and associated key ordering privileges. Manages
modern key assets for a department, agency, or command
What type of accounts are Command Authorities responsible for establishing and managing? - Answer-
User Representatives
Who is responsible for managing traditional COMSEC material? - Answer-CONAUTH
Who manages Modern Key? - Answer-Command Authority
A CF Form 1205 is also known as a User Representative Partition Privilege Registration Request. -
Answer-True
What is a DAO code used to associate? - Answer-Ordering Privileges
When does a Modern Key expire? - Answer-One year from the date is was generated
How many spot check can CO delegate to XO? - Answer-Up to 2 of 4
How often should CO conduct spot checks? - Answer-Quarterly, at minimum
How often should Account Manager conduct spot checks? - Answer-Monthly, at minimum
, What are the guidelines for Account Manager? - Answer-Inspect/Spot Check each LE, annually
How often must a CO perform spot checks? - Answer-Quarterly
Self-assessments must be conducted at least quarterly. - Answer-True
An access list is the only method allowed for a CO to "grant access in writing to a COMSEC user." -
Answer-False (a Designation or Appointment Letter for each individual may also be used)
All COMSEC users must sign which document acknowledging access to COMSEC material? - Answer-SD-
572
What COMSEC component includes secure storage, limited access, life-cycle accountability, and
irretrievable destruction? - Answer-Physical Destruction
What type of information is needed by an adversary to develop measures or tactics to increase their
ability to exploit our vulnerabilities? - Answer-Mission Critical Information
Communications Security (COMSEC) is the prevention of unauthorized access to telecommunications
traffic, or to any written information that is transmitted or transferred. - Answer-True
What is the purpose of Tier 0? - Answer-Centralized key management for all forms of COMSEC key
Who is the end user that is responsible for the proper use, accountability, and destruction of material
assigned to their control by the COMSEC Manager? - Answer-LE
The CMCS consists of production facilities, COMSEC COR, distribution facilities (i.e., depots), and
COMSEC accounts - Answer-True
Which best describes the purpose of COMSEC? - Answer-Denies adversaries access to information
Which of the following measures is taken to ensure the authenticity of information? - Answer-COMSEC
What COMSEC component provides protection from interception and exploitation? - Answer-
Transmission Security
Tier 0 - Answer-Consists of the key production facilities and NSA's Central Office of Record. Provides
centralized key management services for all forms of COMSEC key
Tier 1 - Answer-Intermediate key generation and distribution center, Central Office of Record (COR), and
privilege managers for COMSEC accounts
Tier 2 - Answer-Layer of COMSEC Material Control System (CMCS) comprised of the COMSEC Accounts
that manage key and other COMSEC material
Tier 3 - Answer-End user of COMSEC equipment and/or material (LE)
Who is the Commanding Officer's primary advisor on matters concerning the security and handling of
COMSEC material and the associated record, reports, and audits? - Answer-COMSEC Manager
,At which Tier do LEs reside? - Answer-Tier 3
Which entity operates as part of the NSA and functions primarily as a high volume key generation and
distribution center? - Answer-Central Facility
Which of the following is used to distribute, control, and safeguard COMSEC material? - Answer-CMCS
All COMSEC related information is covered within CMCS. - Answer-False
Effective key is key that is in the current period of time allowed for use. - Answer-True
For routine modification for material NOT previously authorized, managers must submit a request how
many days in advance? - Answer-60 Days
What term best describes the series of letters and numbers used to facilitate identification, handling,
accounting, and control of COMSEC material? - Answer-Short Title
Which of the following would be part of a short title for a United States Electronic Key? - Answer-USEAD
The quantity of future editions of keying material (i.e., ROB) to be held by a COMSEC account is
determined by the CNO, CMC, COGARD TISCOM, FLTCINCs, and/or ISICs. - Answer-True
Allowances are unique to the individual account. - Answer-True
Which are the responsibilities of the Controlling Authority? - Answer-Directs the establishment and
operations of cryptonet/circuits and manages the operational use and control of KEYMAT assigned to a
,cryptonet/circuit. Manages traditional COMSEC material. Evaluates COMSEC incidents and authorizes
the issue/destruction of COMSEC material.
Which are the responsibilities of the CA/CMDAUTH? - Answer-Validates CF Form 1206 prior to
submission to Central Facility. Grants privileges to URs and associated key ordering privileges. Manages
modern key assets for a department, agency, or command
What type of accounts are Command Authorities responsible for establishing and managing? - Answer-
User Representatives
Who is responsible for managing traditional COMSEC material? - Answer-CONAUTH
Who manages Modern Key? - Answer-Command Authority
A CF Form 1205 is also known as a User Representative Partition Privilege Registration Request. -
Answer-True
What is a DAO code used to associate? - Answer-Ordering Privileges
When does a Modern Key expire? - Answer-One year from the date is was generated
How many spot check can CO delegate to XO? - Answer-Up to 2 of 4
How often should CO conduct spot checks? - Answer-Quarterly, at minimum
How often should Account Manager conduct spot checks? - Answer-Monthly, at minimum
, What are the guidelines for Account Manager? - Answer-Inspect/Spot Check each LE, annually
How often must a CO perform spot checks? - Answer-Quarterly
Self-assessments must be conducted at least quarterly. - Answer-True
An access list is the only method allowed for a CO to "grant access in writing to a COMSEC user." -
Answer-False (a Designation or Appointment Letter for each individual may also be used)
All COMSEC users must sign which document acknowledging access to COMSEC material? - Answer-SD-
572
What COMSEC component includes secure storage, limited access, life-cycle accountability, and
irretrievable destruction? - Answer-Physical Destruction
What type of information is needed by an adversary to develop measures or tactics to increase their
ability to exploit our vulnerabilities? - Answer-Mission Critical Information
Communications Security (COMSEC) is the prevention of unauthorized access to telecommunications
traffic, or to any written information that is transmitted or transferred. - Answer-True
What is the purpose of Tier 0? - Answer-Centralized key management for all forms of COMSEC key
Who is the end user that is responsible for the proper use, accountability, and destruction of material
assigned to their control by the COMSEC Manager? - Answer-LE
The CMCS consists of production facilities, COMSEC COR, distribution facilities (i.e., depots), and
COMSEC accounts - Answer-True