SFPC ACTUAL EXAM
Security Fundamentals Professional Certification
200 Questions with Correct Detailed Answers and Rationales
100% Correct and Verified Answers | Already Graded A
Aligned with 2026-2027 SFPC Exam Content
Defense Counterintelligence and Security Agency (DCSA) Standards
SPeD Security Professional Education Development Program Alignment
DoD Policy References: EO 13526 | EO 13556 | EO 13467 | NISPOM | DODM 5200.01
Exam Structure
Section Domain Questions
Section 1 Information Security Q1 - Q50
Section 2 Personnel Security Q51 - Q90
Section 3 Physical Security Q91 - Q120
Section 4 Industrial Security Q121 - Q145
Section 5 General Security Fundamentals Q146 - Q170
Section 6 Integrated Security Scenarios Q171 - Q200
Page 1
,SFPC Actual Exam | 200 Questions | 2026-2027 Security Fundamentals Professional Certification
SECTION 1: INFORMATION SECURITY (Q1-Q50)
Classification Systems and Executive Orders (Q1-Q8)
Q1: Under Executive Order 13526, which classification level applies to information whose unauthorized disclosure could
reasonably be expected to cause exceptionally grave damage to the national security?
A. Confidential
B. Secret
C. Top Secret [CORRECT]
D. For Official Use Only
Correct Answer: C
Rationale: Executive Order 13526 establishes three classification levels: Top Secret, Secret, and Confidential. Top Secret applies to
information whose unauthorized disclosure could reasonably be expected to cause exceptionally grave damage to national security,
which is a higher standard than 'serious' damage (Secret) or 'damage' (Confidential). For Official Use Only is not a classification
level under EO 13526.
Q2: A Security Classification Guide (SCG) serves which of the following primary purposes within a classified program?
A. It replaces the need for original classification authorities
B. It specifies classification levels, special requirements, and declassification instructions for classified
programs, projects, and plans [CORRECT]
C. It is used exclusively for marking unclassified materials
D. It governs physical security standards for SCIF construction
Correct Answer: B
Rationale: The Security Classification Guide (SCG) is the authoritative source document that specifies classification levels, special
handling requirements, and declassification instructions for classified programs, projects, and plans. SCGs do not replace OCAs, are
not used for unclassified marking, and do not govern physical security standards.
Q3: Who is authorized to serve as an Original Classification Authority (OCA) under Executive Order 13526?
A. Any federal employee with a security clearance
B. Only the President and agency heads or officials designated by the President in writing [CORRECT]
C. Any military officer above the rank of Colonel
D. The Director of National Intelligence exclusively
Correct Answer: B
Rationale: EO 13526 limits original classification authority to the President, Vice President, agency heads, and other officials
specifically designated by the President in writing. Not all cleared employees or military officers can be OCAs; the authority must be
formally delegated in writing.
Q4: What is the primary purpose of marking classified materials according to DoD security policy?
A. To increase the document processing time for security reviews
B. To alert holders to the presence of classified information, how to properly protect it, and for how long
[CORRECT]
C. To limit the number of copies that can be reproduced
D. To indicate the monetary value of the classified information
Page 2
,SFPC Actual Exam | 200 Questions | 2026-2027 Security Fundamentals Professional Certification
Correct Answer: B
Rationale: Classification markings serve to alert holders about the presence of classified information, communicate the level of
protection required, and specify the duration of classification. This is a fundamental information security principle ensuring proper
handling throughout the document lifecycle.
Q5: The CAPCO Register is best described as which of the following?
A. A list of all cleared personnel within the DoD
B. A registry that identifies official classification and control markings and their authorized abbreviations
and portion markings [CORRECT]
C. A database of all security incidents and violations
D. A catalog of approved storage containers for classified material
Correct Answer: B
Rationale: The CAPCO (Controlled Access Program Coordination Office) Register identifies official classification and control
markings, including their authorized abbreviations and portion markings. It is the authoritative reference for ensuring correct and
consistent marking practices across the government.
Q6: Derivative classification occurs when a person uses existing classified information to create new material. Which
source MUST derivative classifiers rely upon?
A. Verbal guidance from a supervisor
B. A Security Classification Guide (SCG) or source document containing classified information [CORRECT]
C. Personal judgment based on the subject matter
D. An unclassified reference document that discusses related topics
Correct Answer: B
Rationale: Derivative classification must be based exclusively on an existing Security Classification Guide (SCG) or a source document
that already contains classified information. Derivative classifiers cannot classify based on personal judgment, verbal guidance, or
unclassified reference materials.
Q7: Which Executive Order governs the Controlled Unclassified Information (CUI) program?
A. Executive Order 13526
B. Executive Order 13556 [CORRECT]
C. Executive Order 13467
D. Executive Order 12968
Correct Answer: B
Rationale: Executive Order 13556, 'Controlled Unclassified Information,' establishes the CUI program and defines CUI as
unclassified information that requires safeguarding and dissemination controls. EO 13526 governs classified national security
information, EO 13467 governs security clearances, and EO 12968 established the original personnel security framework.
Q8: Law Enforcement Sensitive (LES) Information is recognized under which information category?
A. Classified National Security Information under EO 13526
B. Controlled Unclassified Information (CUI) as a recognized CUI category [CORRECT]
C. Unclassified For Official Use Only (FOUO)
D. Restricted Data under the Atomic Energy Act
Correct Answer: B
Rationale: Law Enforcement Sensitive (LES) Information is a recognized category of Controlled Unclassified Information (CUI)
under Executive Order 13556. It is not classified national security information, nor is it simply FOUO, which was a legacy designation
that has been largely subsumed by the CUI program.
Page 3
, SFPC Actual Exam | 200 Questions | 2026-2027 Security Fundamentals Professional Certification
CUI, Safeguarding, and Storage (Q9-Q16)
Q9: Which of the following is an authorized method for transmitting Controlled Unclassified Information (CUI)?
A. Organizational wireless connections
B. Encrypted email via approved government systems [CORRECT]
C. Personal social media accounts
D. Unencrypted commercial cloud storage
Correct Answer: B
Rationale: CUI must be safeguarded, and organizational wireless connections are NOT an authorized method of transmission per
CUI policy. Encrypted email via approved government systems represents a proper safeguarding measure. Personal social media and
unencrypted commercial cloud storage are unauthorized for CUI.
Q10: Storage containers used for classified materials are primarily designed to perform which function?
A. Prevent all forms of unauthorized access regardless of circumstances
B. Delay unauthorized entry to protect valuable and/or sensitive assets [CORRECT]
C. Provide fire protection for all classified documents
D. Encrypt electronic media stored within them
Correct Answer: B
Rationale: Storage containers protect valuable and/or sensitive assets by delaying unauthorized entry; they are categorized by how
well they delay different types of threats. They do not prevent all unauthorized access, are not primarily fire protection devices, and
do not encrypt electronic media.
Q11: What is the required practice when safeguarding keys, locks, and combinations for storage containers holding
classified information?
A. They may be stored in any convenient location
B. They must be safeguarded at the same level of classified information being stored in the container
[CORRECT]
C. They should be shared with all personnel who have access to the facility
D. They must be changed only when a security violation occurs
Correct Answer: B
Rationale: Keys, locks, and combinations must be safeguarded at the same level of classification as the information stored in the
container. Storing them in any convenient location or sharing them broadly would create a significant vulnerability in the physical
security of classified material.
Q12: When must combinations for classified storage containers be changed?
A. Only when a container is relocated to a new room
B. When someone with knowledge of the combination no longer requires access to the container [CORRECT]
C. Annually on a fixed calendar date regardless of personnel changes
D. Only when directed by the Facility Security Officer during annual inspections
Correct Answer: B
Rationale: Container combinations must be changed when anyone with knowledge of the combination no longer requires access. This
is a mandatory physical security requirement. Waiting for annual inspections, relocations, or only when the FSO directs would create
unacceptable security gaps.
Q13: Foreign Government Information (FGI) received from an allied nation must be handled according to which principle?
Page 4