Professional Certification Practice
Exam | Comprehensive 300-Question
Practice Examination | 2026 Latest
Version.
SECTION 1: SECURITY FUNDAMENTALS (Questions 1-45)
Q1: Which executive order establishes the National Industrial Security Program (NISP)?
A. Executive Order 13526
B. Executive Order 12968
C. Executive Order 12829 [CORRECT]
D. Executive Order 12333
Correct Answer: C
Rationale: Executive Order 12829, signed in 1993, established the National Industrial Security
Program (NISP) to safeguard classified information released to contractors, licensees, and
grantees. This EO created the framework for what is now implemented through 32 CFR Part 117
(NISPOM).
Q2: What is the primary purpose of a security program within the Department of Defense?
A. To eliminate all security risks completely
B. To provide reasonable assurance of protection through risk management [CORRECT]
C. To ensure absolute security of all classified information
D. To maximize convenience for personnel accessing classified materials
Correct Answer: B
Rationale: Security programs implement risk management principles to provide reasonable
assurance of protection. The goal is to balance security requirements with operational
effectiveness, recognizing that absolute security is unattainable while managing risks to
acceptable levels.
,Q3: Which document serves as the primary implementation guidance for the National Industrial
Security Program?
A. DoD Manual 5200.01
B. 32 CFR Part 117 (NISPOM) [CORRECT]
C. Executive Order 13526
D. DoD Instruction 5200.02
Correct Answer: B
Rationale: The NISPOM (32 CFR Part 117) provides the implementation guidance for the NISP,
establishing requirements for contractors to protect classified information. It covers all aspects
of industrial security including clearance requirements, marking, storage, and reporting.
Q4: A security specialist is reviewing the hierarchy of security policy documents. Which of the
following represents the correct order from highest to lowest authority?
A. Executive Order → Law → DoD Regulation → DoD Manual
B. Law → Executive Order → DoD Regulation → DoD Manual [CORRECT]
C. DoD Manual → DoD Regulation → Executive Order → Law
D. Law → DoD Regulation → Executive Order → DoD Manual
Correct Answer: B
Rationale: The hierarchy flows from laws (statutes passed by Congress), to Executive Orders
(presidential directives), to departmental regulations (DoD-level policies), to manuals
(implementation guidance). Each level must comply with those above it.
Q5: What is the fundamental principle that governs access to classified information?
A. Need-to-know and security clearance [CORRECT]
B. Rank and position title
C. Years of service and experience
D. Professional certifications held
Correct Answer: A
Rationale: Access to classified information requires both a valid security clearance at the
appropriate level AND a demonstrated need-to-know for the specific information. Both
elements are required—neither alone is sufficient for authorized access.
,Q6: Which organization is responsible for conducting background investigations for federal
personnel security clearances?
A. Federal Bureau of Investigation
B. Defense Counterintelligence and Security Agency (DCSA) [CORRECT]
C. Central Intelligence Agency
D. National Security Agency
Correct Answer: B
Rationale: The Defense Counterintelligence and Security Agency (DCSA), formerly the Defense
Security Service (DSS), conducts background investigations for federal personnel security
clearances. DCSA serves as the primary investigative service provider for DoD and other federal
agencies.
Q7: SCENARIO: A new security manager is reviewing the facility's security program and
discovers that security violations are not being reported in accordance with established
requirements. Employees appear unaware of their reporting responsibilities, and there is no
mechanism in place to track violations or corrective actions.
Q7: What is the primary security concern identified in this scenario?
A. Excessive security costs
B. Inadequate security education and awareness [CORRECT]
C. Too many security clearances
D. Improper classification of documents
Correct Answer: B
Rationale: The scenario describes a systemic failure in security education and awareness.
Security programs require trained personnel who understand their reporting responsibilities,
and organizations must have mechanisms to track violations and corrective actions as required
by DoD security policy.
Q8: Which of the following best describes the relationship between security violations and
security infractions?
A. Violations are less serious than infractions
B. Infractions are less serious than violations [CORRECT]
C. Both terms are interchangeable
D. Infractions only apply to cybersecurity incidents
, Correct Answer: B
Rationale: A security violation involves failure to comply with policy that could reasonably result
in the loss or compromise of classified information. An infraction is a lesser offense that does
not result in loss or compromise but is still a failure to comply with established requirements.
Q9: What is the primary purpose of the Security Professional Education Development (SPeD)
Program?
A. To standardize security training across the DoD [CORRECT]
B. To reduce the number of security clearances
C. To eliminate physical security requirements
D. To replace the NISPOM with new guidance
Correct Answer: A
Rationale: The SPeD Program standardizes security training and certification across the
Department of Defense. It ensures security professionals have consistent knowledge and
competencies regardless of their specific agency or component.
Q10: Which of the following is NOT a primary security discipline within the DoD security
framework?
A. Information security
B. Personnel security
C. Financial security [CORRECT]
D. Physical security
Correct Answer: C
Rationale: The primary security disciplines include information security, personnel security,
physical security, industrial security, and cybersecurity. Financial security is not a recognized
security discipline within the DoD framework.
Q11: A security manager discovers that classified information has been disclosed to an
unauthorized individual. What is the FIRST action that should be taken?
A. Conduct a full investigation immediately
B. Report the incident through established channels [CORRECT]
C. Terminate the responsible employee
D. Destroy the compromised information