COUNTERINTELLIGENCE AWARENESS
MASTER ASSESSMENT 150 MASTER Q and AS
WITH DETAILED CORRECT ANSWERS WITH
RATIONALES CORRECT VERIFIED ANSWERS
INCLUDED GRADE A+ INSTANT DOWNLOAD
Annual Security and Counterintelligence Awareness Master
Exam
1. A Department of Defense (DoD) civilian employee notices a
coworker frequently downloading massive quantities of
classified data to an unclassified external hard drive outside of
normal working hours. Which of the following actions
represents the correct protocol under federal
counterintelligence awareness guidelines?
A. Ignore the behavior because the coworker has a higher security
clearance level and is likely performing authorized troubleshooting.
B. Confront the coworker directly in the breakroom and demand an
immediate personal explanation for their unusual downloading patterns.
C. Report the suspicious behavior immediately to the facility Security
Specialist or the Insider Threat Program Officer for formal investigation.
D. Delete the user's network account permanently without consulting
management to prevent further potential unauthorized data exfiltration.
Correct Answer: C
Rationale: Federal counterintelligence guidelines mandate that
suspicious indicators of an insider threat—such as unauthorized
downloading of classified data or working anomalous hours—must be
reported immediately to designated security personnel or insider threat
channels rather than being handled through personal confrontation or
ignored. [1, 2, 3]
2. Foreign Intelligence Entities (FIE) frequently use social
engineering tactics on professional networking websites to
target cleared personnel. What is the most effective
preventative measure an employee can take to safeguard
sensitive information on these platforms?
,A. Accepting all incoming connection requests indiscriminately to build a
vast professional network that confuses foreign adversaries.
B. Listing precise project code names, specific classified contract
numbers, and detailed technical descriptions of sensitive work
assignments on public profiles.
C. Exercising extreme caution by vetting connections, avoiding the
publication of sensitive operational details, and reporting unsolicited
professional offers that seem suspicious.
D. Providing personal home addresses and private mobile phone
numbers to any online recruiter who claims to represent a global
consulting firm.
Correct Answer: C
Rationale: Counterintelligence awareness training emphasizes that
cleared individuals must maintain robust operational security (OPSEC)
on social media. This includes limiting the disclosure of sensitive
employment details and reporting unusual, unsolicited contacts from
foreign or ambiguous entities. [1, 2, 3, 4, 5]
3. During a routine business trip overseas, an employee is
approached at a hotel bar by an individual who expresses an
unusual and persistent interest in the employee's government-
funded research project. Which counterintelligence reporting
threshold does this encounter cross?
A. It is considered a casual social interaction that does not require any
administrative documentation or security reporting upon return.
B. It constitutes an attempt by a foreign national to obtain unauthorized
access to sensitive or classified information, which must be reported to
security officials.
C. It represents a standard marketing opportunity that the employee
should independently exploit to secure international venture capital.
D. It should only be reported if the individual explicitly states they are a
registered intelligence operative working for an adversarial government.
Correct Answer: B
Rationale: Federal security directives require all cleared personnel to
report any encounters with foreign nationals who demonstrate an
unusual, persistent, or targeted interest in sensitive, proprietary, or
classified government information or technology. [1]
4. Under the Controlled Unclassified Information (CUI)
federal program, how must CUI materials be handled when
,they are no longer needed by an agency or contractor?
A. Placed directly into standard public recycling bins located outside the
main facility gates to save administrative overhead costs.
B. Left unattended on common area conference room tables so other
unvetted employees can review the information at their convenience.
C. Destroyed using an approved method—such as cross-cut shredding,
burning, or pulverizing—that renders the information completely
unreadable and indecipherable.
D. Donated to local public libraries to foster open-source academic
research into historical government administration procedures.
Correct Answer: C
Rationale: The CUI Executive Order and 32 CFR Part 2002 dictate
that CUI must be destroyed utilizing methods specified by the National
Archives and Records Administration (NARA), ensuring the material is
destroyed beyond recognition to prevent unauthorized reconstruction.
[1, 2, 3]
5. An intelligence analyst receives an urgent email that
appears to originate from their agency's IT helpdesk,
demanding that they click a link to verify their network
credentials within one hour or face permanent account
termination. What type of security threat does this scenario
illustrate?
A. A routine system maintenance alert that requires immediate
compliance to prevent widespread network downtime.
B. A spear-phishing attack engineered to compromise user credentials
and gain unauthorized administrative access to secure networks.
C. A standard hardware malfunction that can be easily resolved by
restarting the local workstation three consecutive times.
D. An open-source intelligence gathering technique designed to catalog
the physical location of municipal office furniture.
Correct Answer: B
Rationale: Spear-phishing is a targeted form of social engineering
where attackers impersonate trusted entities (like an internal IT
helpdesk) to deceive specific individuals into revealing sensitive
credentials or executing malicious software. [1, 2, 3, 4, 5]
6. Which of the following indicators is considered a primary
behavioral red flag associated with a potential insider threat
within a secure government facility?
, A. Arriving precisely fifteen minutes before the official start of a
scheduled shift and consistently wearing the mandatory corporate
uniform.
B. Documented financial anomalies, such as sudden unexplained wealth,
combined with persistent attempts to access sensitive files outside the
scope of one's official duties.
C. Registering for voluntary evening professional development courses at
an accredited local community college or state university.
D. Submitting routine vacation requests to human resources at least six
months prior to the planned departure date.
Correct Answer: B
Rationale: Behavioral indicators of an insider threat frequently
include a combination of personal indicators (such as sudden,
unexplained financial prosperity) and technical indicators (such as
attempting to bypass access controls to view data unrelated to current
work assignments).
7. When transporting classified documents between two
approved secure facilities, what operational security protocol
must the cleared courier strictly observe?
A. Leaving the classified folder clearly visible on the passenger seat of an
unlocked vehicle while eating lunch at a commercial roadside restaurant.
B. Maintaining continuous personal custody of the double-wrapped
classified material and avoiding any unauthorized detours or personal
stops during transit.
C. Reviewing the classified documents out loud while utilizing public
public transportation networks to maximize travel productivity.
D. Posting real-time GPS coordinates and tracking updates of the courier
route on public personal social media feeds for family visibility.
Correct Answer: B
Rationale: Cleared couriers must ensure that classified material is
double-wrapped in approved packaging and remains under their
continuous, direct personal control at all times until it is successfully
delivered to an authorized recipient at the destination facility. [1, 2, 3]
8. An administrative assistant finds an unmarked USB flash
drive lying on the floor of a public hallway just outside the
facility’s secure compartmented information facility (SCIF).
What is the correct security response?
A. Insert the USB drive into a secure workstation immediately to