SFPC Test Questions and Correct Answers
Question 1
To provide access to Social Media sites, the DoD agency must provide all of the following, EXCEPT:
a. Protection against malware and advance threats.
b. Blocked access to prohibited sites and content.
c. Individual compliance with Joint Ethics Regulations and guidelines.
d. Constant monitoring to deter inappropriate site access.
Correct Answer
D
Question 2
What are the cybersecurity attributes?
Select all that apply.
A Confidentiality
B Integrity
C Availability
D Authentication
E Non-repudiation
Correct Answer
All of the above
Page 1 of 50
,Question 3
Select ALL of the correct responses. What activities occur during implementation of security
controls?
A Ensure consistency with DoD architectures
B Document security control implementation in the security plan
C Seek approvals from CIO
D Identify security controls available for inheritance
E Communicate updates to appropriate audiences
F Create appropriate training and communication plans
Correct Answer
A, B & D
Question 4
What are the components of the Risk Management System? (Select all that apply)
A Revision
B Analysis
C Evaluation
D Assessment
E Mitigation
Correct Answer
C, D & E
Page 2 of 50
,Question 5
Which of the following limitations is true regarding Limited Access Authorization (LAA) to non-U.S. citizens?
a. LAAs shall only be granted access at the Secret and Confidential levels.
b. A favorably completed and adjudicated Tier 3 or National Agency Check with Local Agency Check (NACLC). investigation
within the last five years is required.
c. An LAA is the same as a security clearance eligibility.
d. Access to classified information Is not limited to a specific program or project.
Correct Answer
A
Question 6
Which of the following describes a Special Access Program (SAP) that is established to protect sensitive research,
development, testing and evaluation, modification, and procurement activities?
a. Research and Technology SAP
b. Operations and Support SAP
c. Acquisition SAP
d. Intelligence SAP
Correct Answer
C
Page 3 of 50
, Question 7
What is the role of the Special Access Program Oversight Committee (SAPOC) during the maintenance phase
of the Special Access Program (SAP) lifecycle?
a. To ensure that the SAP has adequate Internal Review and Audit Compliance (IRAC) support, including accessed auditors
at supporting offices, to meet program audit needs.
b. To review existing programs annually to determine whether to revalidate them as SAPs.
c. To provide oversight of SAP program and budget accomplishments.
d. To provide oversight of SAP audits and inspections.
Correct Answer
B
Question 8
What evolving threats are attempts by hackers to damage or destroy a computer network or system?
A. Insider Threat
B. Social Media
C. Cyber Attack
D. Mobile Computing
Correct Answer
C
Page 4 of 50
Question 1
To provide access to Social Media sites, the DoD agency must provide all of the following, EXCEPT:
a. Protection against malware and advance threats.
b. Blocked access to prohibited sites and content.
c. Individual compliance with Joint Ethics Regulations and guidelines.
d. Constant monitoring to deter inappropriate site access.
Correct Answer
D
Question 2
What are the cybersecurity attributes?
Select all that apply.
A Confidentiality
B Integrity
C Availability
D Authentication
E Non-repudiation
Correct Answer
All of the above
Page 1 of 50
,Question 3
Select ALL of the correct responses. What activities occur during implementation of security
controls?
A Ensure consistency with DoD architectures
B Document security control implementation in the security plan
C Seek approvals from CIO
D Identify security controls available for inheritance
E Communicate updates to appropriate audiences
F Create appropriate training and communication plans
Correct Answer
A, B & D
Question 4
What are the components of the Risk Management System? (Select all that apply)
A Revision
B Analysis
C Evaluation
D Assessment
E Mitigation
Correct Answer
C, D & E
Page 2 of 50
,Question 5
Which of the following limitations is true regarding Limited Access Authorization (LAA) to non-U.S. citizens?
a. LAAs shall only be granted access at the Secret and Confidential levels.
b. A favorably completed and adjudicated Tier 3 or National Agency Check with Local Agency Check (NACLC). investigation
within the last five years is required.
c. An LAA is the same as a security clearance eligibility.
d. Access to classified information Is not limited to a specific program or project.
Correct Answer
A
Question 6
Which of the following describes a Special Access Program (SAP) that is established to protect sensitive research,
development, testing and evaluation, modification, and procurement activities?
a. Research and Technology SAP
b. Operations and Support SAP
c. Acquisition SAP
d. Intelligence SAP
Correct Answer
C
Page 3 of 50
, Question 7
What is the role of the Special Access Program Oversight Committee (SAPOC) during the maintenance phase
of the Special Access Program (SAP) lifecycle?
a. To ensure that the SAP has adequate Internal Review and Audit Compliance (IRAC) support, including accessed auditors
at supporting offices, to meet program audit needs.
b. To review existing programs annually to determine whether to revalidate them as SAPs.
c. To provide oversight of SAP program and budget accomplishments.
d. To provide oversight of SAP audits and inspections.
Correct Answer
B
Question 8
What evolving threats are attempts by hackers to damage or destroy a computer network or system?
A. Insider Threat
B. Social Media
C. Cyber Attack
D. Mobile Computing
Correct Answer
C
Page 4 of 50