100 VERIFIED Q&A | DETAILED
RATIONALES | NGN-ALIGNED | PASS
GUARANTEED – A+ GRADED
SECTION 1: INFORMATION SECURITY FUNDAMENTALS – Questions 1-25
Q1: Purpose of Marking Classified Materials
What is the purpose of marking classified materials?
A. To alert holders to the presence of classified information, how to properly protect it, and for
how long
B. To deter foreign adversaries from committing actions aimed at accessing such information
C. To provide guidance for interpretation and analysis of classified information
D. To alert holders to the methods used to collect classified information
Correct Answer: A
Rationale: Marking classified materials serves to alert holders to the presence of classified
information, instructs them on proper protection methods, and indicates the duration for which
the information must remain classified. This is a fundamental requirement of the DoD
Information Security Program.
Q2: Purpose of CAPCO Register
What is the purpose of the Controlled Access Program Coordination (CAPCO) register?
A. To identify the categories, types, and levels of Special Access Programs (SAPs)
B. To define the authorities for classifying, declassifying, and regrading sensitive documents
C. To identify the official classification and control markings, and their authorized abbreviations
and portion markings
D. To define the requirements, restrictions, and measures necessary to safeguard classified
information from unauthorized disclosure
Correct Answer: C
Rationale: The CAPCO register identifies official classification and control markings, along with
their authorized abbreviations and portion markings, ensuring standardized marking of classified
information across the DoD.
,Q3: Classified Data Spill Responsibility
When a classified data spill occurs, who is responsible for ensuring that policy requirements for
addressing an unauthorized disclosure are met?
A. Activity Security Manager
B. Information Assurance Staff
C. Information Assurance Manager
D. Information Assurance Officer
Correct Answer: A
Rationale: The Activity Security Manager is responsible for ensuring that policy requirements for
addressing an unauthorized disclosure (classified data spill) are met, including proper reporting,
investigation, and remediation actions.
Q4: Information Assurance – Non-Repudiation Loss
There are five information assurance attributes important to protect and defend DoD networks. If
there was a loss in non-repudiation, what would this cause?
A. Data is no longer reliable, accurate, nor trusted
B. Data may potentially be available to unauthorized users via electronic form
C. General communications are no longer trusted
D. Potential of unauthorized access to classified data
E. Data is no longer available to authorized users, and missions cannot be conducted
Correct Answer: C
Rationale: Non-repudiation ensures that a party in an electronic exchange cannot deny their
participation or the authenticity of the message. A loss of non-repudiation means general
communications are no longer trusted.
Q5: Security Violation vs. Infraction
Which of the following describes a security violation rather than a security infraction?
A. Karen printed classified documents in her open storage room and forgot them for an hour
B. Karen put a classified document in a folder she believed was marked for carrying classified
materials but was not
C. Karen took unclassified documents home and realized classified materials had slipped in
between them
D. Karen worked a mission-related task
,Correct Answer: C
Rationale: A security violation involves compromise or unauthorized disclosure of classified
information. Karen taking classified materials home inadvertently constitutes a violation because
classified information left a secure area without authorization.
Q6: Email Sender Denial
The inability to deny you are the sender of an email would be an indication of a lapse in:
A. Non-Repudiation
B. Confidentiality
C. Integrity
D. Availability
Correct Answer: A
Rationale: Non-repudiation ensures that a party cannot deny their participation in an electronic
exchange. The ability to deny being the sender of an email indicates a lapse in non-repudiation.
Q7: Unauthorized Disclosure and Privacy
Unauthorized disclosure and loss of privacy is a lapse in:
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Correct Answer: A
Rationale: Confidentiality preserves authorized restrictions on information disclosure and
protects personal privacy. Unauthorized disclosure is a direct breach of confidentiality.
Q8: First Action to Declassify
What is the first action taken to downgrade, declassify, or remove classification markings?
A. Through the appropriate chain of command, contact the original classification authority (OCA)
B. Remove all markings immediately
C. Notify the Activity Security Manager only
D. Destroy the document
Correct Answer: A
, Rationale: The first action is to contact the Original Classification Authority through the
appropriate chain of command to confirm that the information does not have an extended
classification duration.
Q9: Evolving Threat – Cyber Attack
What evolving threats are attempts by hackers to damage or destroy a computer network or
system?
A. Insider Threat
B. Social Media
C. Cyber Attack
D. Mobile Computing
Correct Answer: C
Rationale: Cyber attacks are attempts by hackers to damage, disrupt, or destroy computer
networks and systems, representing a significant evolving threat to DoD information systems.
Q10: Risk Management Framework – First Step
What is the first step in the Risk Management Framework (RMF)?
A. Categorize System
B. Authorize System
C. Implement Security Controls
D. Select Security Controls
E. Assess Security Controls
F. Monitor Security Controls
Correct Answer: A
Rationale: The first step in the RMF is to Categorize the System, which involves determining the
criticality and sensitivity of the information system based on the impact of a security breach.
Q11: Security Authorization Package
What is included in the security authorization package? (Select all that apply)
A. Security Assessment Report (SAR)
B. Plan of Action and Milestones (POA&M)
C. Security Plan
D. None of the above