DOD DOD Information Assurance & Data Protection 2 — Questions and Answers
Question 1: What DoD policy mandates the use of encryption for data at rest on mobile devices and removable media containing CUI?
- DoD Instruction 8582.01 and FIPS 140-2 validated encryption (Correct answer)
- DoD Directive 5100.01 only
- NIST SP 800-61 incident handling guide
- FAR Part 12
Correct answer: DoD Instruction 8582.01 and FIPS 140-2 validated encryption
DoD Instruction 8582.01 requires FIPS 140-2 validated encryption for CUI stored on mobile devices and removable media to prevent unauthorized disclosure.
Question 2: Which process formally grants a DoD IT system authorization to operate (ATO)?
- The Risk Management Framework (RMF) Authorization process (Correct answer)
- The Defense Acquisition System (DAS) Milestone B review
- The Certification and Accreditation Legacy process only
- The Inspector General annual audit
Correct answer: The Risk Management Framework (RMF) Authorization process
The DoD Risk Management Framework (RMF) Authorization process, replacing DIACAP, is the formal process through which an Authorizing Official (AO) grants an ATO to a DoD IT system.
Question 3: What is the role of the Authorizing Official (AO) in the DoD RMF process?
- A senior official who accepts the residual risk of operating a system and grants or denies the Authorization to Operate (Correct answer)
- A technical engineer who implements security controls
- A contractor who writes the System Security Plan
- An auditor who reviews past incidents
Correct answer: A senior official who accepts the residual risk of operating a system and grants or denies the Authorization to Operate
The AO is a senior DoD official accountable for the mission risk associated with operating a system and is the only person with authority to grant or deny an ATO.
Question 4: Under DoD policy, which type of spillage occurs when classified information is placed on an information system accredited to handle only lower-classified or unclassified data?
- Classified data spillage (Correct answer)
- Data exfiltration
- Insider threat incident
- System compromise
Correct answer: Classified data spillage
Classified data spillage occurs when classified information is inadvertently or deliberately placed on a system not authorized to handle that classification level.
Question 5: What is the first step required when a classified data spillage is discovered on an unclassified DoD network?
- Isolate the affected system immediately and report to the ISSM/security officer (Correct answer)
- Delete the file and continue normal operations
- Email all users to warn them about the spillage
- Shut down the entire network segment permanently
Correct answer: Isolate the affected system immediately and report to the ISSM/security officer
The first action upon discovering classified spillage is to isolate the affected system to prevent further spread and immediately report to the ISSM or security officer for remediation.
Question 6: Which DoD program requires personnel to complete annual information assurance awareness training?
- Cyber Awareness Challenge (formerly Information Assurance Awareness Training) (Correct answer)
- Joint Staff Orientation Program
- Security Assistant Training Program
- Base Access Training Program
Correct answer: Cyber Awareness Challenge (formerly Information Assurance Awareness Training)
DoD requires all personnel with network access to annually complete the Cyber Awareness Challenge to maintain awareness of current threats, policies, and best practices.
What DoD policy mandates the use of encryption for data at rest on mobile devices and removable media containing CUI?