← All CFA Flashcard Decks

Counterintelligence Awareness & Threat Recognition Flashcards

7 cards from real CFA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Counterintelligence Awareness & Threat Recognition flashcards as text
  1. What is 'anomaly detection' as used in counterintelligence investigations?

    Answer: Identifying unusual patterns in data access, behavior, or communications that may indicate insider threat activity

    Anomaly detection in CI involves identifying deviations from established behavioral or technical baselines — such as unusual database queries, off-hours access, or unexplained foreign contacts — that may indicate hostile activity.

  2. Which of the following accurately describes a 'false flag' operation in counterintelligence?

    Answer: An operation designed to appear as though it originates from a nation or organization other than the one actually conducting it

    A false flag operation disguises the true sponsoring nation or organization, leading a target to believe they are working for or assisting a different entity than actually controls the operation.

  3. What is 'document sanitization' in intelligence operations, and when is it applied?

    Answer: The process of removing or redacting identifying information, sources, and methods from a document before it can be shared at a lower classification level

    Sanitization removes or obscures sensitive sourcing, methods, and identifying details from an intelligence product so it can be shared with partners or at lower classification levels without compromising the original collection source.

  4. In counterintelligence, what role does a 'dangle' serve?

    Answer: An agent who is deliberately revealed to an adversary as bait to assess whether the adversary will attempt recruitment

    A dangle is an individual — often a CI officer or controlled asset — who is deliberately made accessible to a foreign intelligence service to see whether the adversary makes a recruitment approach, revealing their targeting priorities and methods.

  5. Which of the following is a strong indicator that a covert communication channel or signal has been compromised?

    Answer: Adversary security forces appear at pre-planned meeting sites or intercept communications precisely timed to operational activity

    When hostile forces consistently appear at operationally sensitive locations or times with knowledge that could only come from the communications or plans themselves, this strongly indicates those channels have been intercepted or a human source has been compromised.

  6. What is the primary goal of a counterintelligence 'sting' operation?

    Answer: To lure a suspected insider threat or foreign agent into an overt illegal act that can support prosecution or controlled termination

    A CI sting presents a controlled opportunity for a suspected spy or insider threat to commit a prosecutable act — such as passing classified material — under monitored conditions that generate evidence and legal grounds for action.

  7. Which of the following best describes 'operational security' (OPSEC) and its relationship to counterintelligence?

    Answer: OPSEC is a process that identifies critical information, analyzes threats, and implements measures to deny adversaries indicators they could exploit

    OPSEC is a systematic process that identifies sensitive indicators of friendly activity, assesses adversary collection capabilities, and applies protective measures to deny useful intelligence to hostile services — directly supporting CI goals.