SFPC Information Security CPT Exam
Questions and Answers
What are the names of the policies that provide guidance for the DoD Information Security Program? -
Answer-DoDI 5200.01, E.O. 13526 and E.O. 13556, and parts 2001 and 2002 of title 32, Code of Federal
Regulations
What are the purpose, scope, and goals of the DoD Information Security Program? - Answer-Identify
and protect national security information and CUI in accordance with national level policy issuances.
Promote information sharing, facilitate judicious use of resources, and simplify management through
implementation of uniform and standardized processes.
Classify and declassify national security information as required
What policies are associated with the classification, declassification, and reclassification of information?
- Answer-CLASSIFICATION - Information shall be classified only when necessary in the interests of
national security and shall be declassified as soon as is consistent with the requirements of national
security. Enclosure 4 to DoDM 5200.01 Volume 1
RECLASSIFICATION. - After information has been declassified and released to the public under proper
authority, it may be reclassified only in accordance with paragraph 17.b. of Enclosure 4 to DoDM
5200.01 Volume 1
DECLASSIFICATION - Information shall be declassified as soon as it no longer meets the standards for
classification. In some exceptional cases, the need to protect information still meeting these standards
may be outweighed by the public interest in disclosure of the information, and in these cases the
information should be declassified. Enclosure 5 to DoDM 5200.01 Volume 1
, What is the retention policy for classified and controlled unclassified information (CUI)? - Answer-
Classified information and CUI shall be maintained only when it is required for effective and efficient
operation of the organization or if law, treaty, international agreement, or regulation requires its
retention.
How do you coordinate security incidents with the appropriate Criminal Investigative Organization or
Defense Counterintelligence Component? - Answer-When information suggestive of a criminal or CI
nature is discovered, all actions associated with the inquiry or investigation shall cease pending
coordination with the cognizant DCIO or Defense CI component. If the DCIO or Defense CI component
accepts jurisdiction, the inquiry or investigation shall not be resumed without agreement of the
cognizant criminal investigative organization or CI component. All relevant information shall be released
with an annotation in the report that the matter was referred to the specific DCIO or Defense CI
component. Notify the OCA, originator, and others as appropriate, after coordination with the DCIO or
Defense CI component.
What are the requirements for reporting a potential or actual compromise? - Answer-Anyone finding
classified information out of proper control shall, if possible, take custody of and safeguard the material
and immediately notify the appropriate security authorities. Secure communications should be used for
notification whenever possible. Every civilian employee and Active, Reserve, and National Guard Military
member of the Department of Defense, and every DoD contractor or employee of a contractor working
with classified material, as provided by the terms of the contract, who becomes aware of the loss or
potential compromise of classified information shall immediately report it to the head of his or her local
activity and to the activity security manager. If the person believes that the head of the activity or the
security manager may have been involved in or responsible for the incident, he or she may report it to
the security authorities at the next higher level of command or supervision.
What is the process for handling incidents of potential or actual compromise (including Original
Classification Authority Actions and Damage Assessment)? - Answer-The head of the activity or activity
security manager having security cognizance shall initiate an inquiry into the actual or potential
compromise promptly to determine the facts and circumstances of the incident, and to characterize the
incident as an infraction or a violation.
If the circumstances of an incident require a more detailed or additional investigation, then an individual
shall be appointed by the activity head in writing, to conduct that investigation and, as appropriate,
provide recommendations for any corrective or disciplinary actions.
Questions and Answers
What are the names of the policies that provide guidance for the DoD Information Security Program? -
Answer-DoDI 5200.01, E.O. 13526 and E.O. 13556, and parts 2001 and 2002 of title 32, Code of Federal
Regulations
What are the purpose, scope, and goals of the DoD Information Security Program? - Answer-Identify
and protect national security information and CUI in accordance with national level policy issuances.
Promote information sharing, facilitate judicious use of resources, and simplify management through
implementation of uniform and standardized processes.
Classify and declassify national security information as required
What policies are associated with the classification, declassification, and reclassification of information?
- Answer-CLASSIFICATION - Information shall be classified only when necessary in the interests of
national security and shall be declassified as soon as is consistent with the requirements of national
security. Enclosure 4 to DoDM 5200.01 Volume 1
RECLASSIFICATION. - After information has been declassified and released to the public under proper
authority, it may be reclassified only in accordance with paragraph 17.b. of Enclosure 4 to DoDM
5200.01 Volume 1
DECLASSIFICATION - Information shall be declassified as soon as it no longer meets the standards for
classification. In some exceptional cases, the need to protect information still meeting these standards
may be outweighed by the public interest in disclosure of the information, and in these cases the
information should be declassified. Enclosure 5 to DoDM 5200.01 Volume 1
, What is the retention policy for classified and controlled unclassified information (CUI)? - Answer-
Classified information and CUI shall be maintained only when it is required for effective and efficient
operation of the organization or if law, treaty, international agreement, or regulation requires its
retention.
How do you coordinate security incidents with the appropriate Criminal Investigative Organization or
Defense Counterintelligence Component? - Answer-When information suggestive of a criminal or CI
nature is discovered, all actions associated with the inquiry or investigation shall cease pending
coordination with the cognizant DCIO or Defense CI component. If the DCIO or Defense CI component
accepts jurisdiction, the inquiry or investigation shall not be resumed without agreement of the
cognizant criminal investigative organization or CI component. All relevant information shall be released
with an annotation in the report that the matter was referred to the specific DCIO or Defense CI
component. Notify the OCA, originator, and others as appropriate, after coordination with the DCIO or
Defense CI component.
What are the requirements for reporting a potential or actual compromise? - Answer-Anyone finding
classified information out of proper control shall, if possible, take custody of and safeguard the material
and immediately notify the appropriate security authorities. Secure communications should be used for
notification whenever possible. Every civilian employee and Active, Reserve, and National Guard Military
member of the Department of Defense, and every DoD contractor or employee of a contractor working
with classified material, as provided by the terms of the contract, who becomes aware of the loss or
potential compromise of classified information shall immediately report it to the head of his or her local
activity and to the activity security manager. If the person believes that the head of the activity or the
security manager may have been involved in or responsible for the incident, he or she may report it to
the security authorities at the next higher level of command or supervision.
What is the process for handling incidents of potential or actual compromise (including Original
Classification Authority Actions and Damage Assessment)? - Answer-The head of the activity or activity
security manager having security cognizance shall initiate an inquiry into the actual or potential
compromise promptly to determine the facts and circumstances of the incident, and to characterize the
incident as an infraction or a violation.
If the circumstances of an incident require a more detailed or additional investigation, then an individual
shall be appointed by the activity head in writing, to conduct that investigation and, as appropriate,
provide recommendations for any corrective or disciplinary actions.