CERTIFICATION (SFPC) - EXAM 300 ACTUAL
QUESTION BANK AND CORRECT ANSWERS WITH
RATIONALE LATEST UPDATE ALREADY GRADED A+
ASSURED PASS
This comprehensive resource provides 300 unique, sectioned multiple-choice
questions tailored for the Security Fundamentals Professional Certification (SFPC)
exam. It covers essential security domains including Information Security,
Personnel Security (PERSEC), Physical Security, Industrial Security (INDUSEC),
Security Program Management and Operations, Operations Security (OPSEC),
Cybersecurity, Risk Management, Classification and Declassification, Access
Control, the National Industrial Security Program (NISP), and the SPeD
certification program. Each question includes the correct answer and a detailed
rationale designed to reinforce foundational security concepts and professional
competencies. The content emphasizes high-yield topics frequently tested on the
SFPC exam, making it an ideal tool for intensive review and mastery of security
fundamentals required for successful certification and professional security
practice.
SECTION 1: INFORMATION SECURITY AND
CLASSIFICATION MANAGEMENT
Question 1: Which Executive Order establishes the system for classifying,
safeguarding, and declassifying national security information?
A) Executive Order 12333
B) Executive Order 12829
C) Executive Order 13526
D) Executive Order 12968
Answer: C
Rationale: Executive Order 13526, "Classified National Security Information," is
the foundational directive that establishes the policies and procedures for
classifying, safeguarding, and declassifying national security information. EO
12333 addresses intelligence activities, EO 12829 establishes the National
Industrial Security Program, and EO 12968 addresses access to classified
,information. The Information Security Oversight Office (ISOO) issues regulations
implementing EO 13526 at 32 CFR Parts 2001 and 2003 .
Question 2: An Original Classification Authority (OCA) is best defined as:
A) Any individual who creates classified documents
B) An official designated with authority to make original classification decisions
C) Any security manager who reviews classified documents
D) A derivative classifier who applies classification markings
Answer: B
Rationale: An Original Classification Authority (OCA) is an official specifically
designated by the President, agency head, or other official with the authority to
make original classification decisions . OCAs determine whether information
meets the criteria for classification and assign the appropriate classification level .
Derivative classifiers, in contrast, apply classification markings based on guidance
from OCAs using a Security Classification Guide (SCG) .
Question 3: What are the three classification levels for national security
information?
A) Limited, Confidential, and Top Secret
B) Confidential, Secret, and Top Secret
C) Restricted, Confidential, and Top Secret
D) Unclassified, For Official Use Only, and Classified
Answer: B
Rationale: The three classification levels for national security information are
Confidential, Secret, and Top Secret. Confidential is the lowest level, indicating
that unauthorized disclosure could cause damage to national security. Secret
indicates serious damage, and Top Secret indicates exceptionally grave damage to
national security. These levels are established by Executive Order 13526 and
implemented through DoD Manual 5200.01 .
Question 4: Which of the following is required before an individual can be granted
access to classified information?
A) A signed SF 312 Nondisclosure Agreement
B) A valid security clearance investigation
C) A need to know the information
D) All of the above
Answer: D
Rationale: Before access to classified information is granted, an individual must
have: (1) a favorable determination of eligibility for access (security clearance), (2)
a need to know the information to perform official duties, and (3) a signed SF 312
,(Classified Information Nondisclosure Agreement). All three conditions must be
met. The "need-to-know" principle restricts access to information necessary to
perform official duties .
Question 5: An unauthorized disclosure is best defined as:
A) A technical error in document classification
B) Communication or physical transfer of classified information to an
unauthorized recipient
C) A security infraction with no potential for harm
D) Declassification of information without proper review
Answer: B
Rationale: An unauthorized disclosure is the communication or physical transfer of
classified or controlled unclassified information to an unauthorized recipient. This
includes verbal communication, written documents, electronic transmission, or any
other means of sharing classified information with someone who does not have the
appropriate clearance and need to know. Unauthorized disclosures may range from
security infractions to violations depending on the potential for loss or compromise
.
Question 6: What is the primary difference between a security infraction and a
security violation?
A) An infraction is intentional; a violation is accidental
B) An infraction cannot reasonably be expected to result in loss or compromise; a
violation does result or could be expected to result in loss or compromise
C) An infraction requires immediate reporting; a violation does not
D) An infraction occurs only in physical security; a violation occurs only in
information security
Answer: B
Rationale: A security infraction is an act or omission that cannot reasonably be
expected to and does not result in the loss, compromise, or suspected compromise
of classified information. A security violation is an act or omission that does result
in or could be expected to result in the loss or compromise of classified
information. Security violations must be reported and investigated through
administrative inquiries .
Question 7: Which authorities govern foreign disclosure of classified military
information?
A) Only Executive Order 13526
B) Arms Export Control Act, National Security Decision Memorandum 119, and
International Traffic in Arms Regulation (ITAR)
, C) Only the National Industrial Security Program Operating Manual
D) Only bilateral security agreements
Answer: B
Rationale: Foreign disclosure of classified military information is governed by
multiple authorities including the Arms Export Control Act, National Security
Decision Memorandum 119, the National Disclosure Policy-1, the International
Traffic in Arms Regulation (ITAR), EO 12829 and EO 13526, bilateral security
agreements, and DoD 5220.22-M (NISPOM). These authorities collectively ensure
that foreign disclosure is properly controlled and authorized .
Question 8: What must derivative classifiers do when applying classification
markings?
A) Make independent decisions without guidance
B) Follow the instructions in a Security Classification Guide (SCG)
C) Assign classification based on their own judgment
D) Consult with a legal advisor for every document
Answer: B
Rationale: Derivative classifiers must follow the instructions in a Security
Classification Guide (SCG) issued by an Original Classification Authority (OCA) .
The SCG provides specific guidance on what information is classified, at what
level, and for what duration. Derivative classifiers cannot make original
classification decisions and must apply markings exactly as specified in the SCG .
Question 9: Which classification consideration applies to nongovernment research
and development information?
A) Products are automatically classified
B) The government must acquire a proprietary interest before classification can be
applied
C) The government has an obligation to classify all R&D information
D) The non-government entity cannot request classification control
Answer: B
Rationale: For nongovernment research and development information, the
government must acquire a proprietary interest first before classification can be
applied . The government does not have an obligation to classify all R&D
information, and non-government entities may request controls under the
classification system. This ensures that proprietary rights are respected before
classification is imposed.
Question 10: What is the primary purpose of a Security Classification Guide
(SCG)?