Security Fundamentals Professional Certification (SFPC) — Questions and Answers
Question 1: What is a 'carve-out' in the context of SAP security programs?
- When a cleared contractor excludes specific personnel from a security program for which they would otherwise be eligible (Correct answer)
- Removing classified information from documents
- Separating a program from its parent agency
- Reducing the classification level of information
Correct answer: When a cleared contractor excludes specific personnel from a security program for which they would otherwise be eligible
A carve-out occurs when a contractor excludes certain personnel, such as union members, from a security program, creating a separate workforce for sensitive activities.
Question 2: Which of the following BEST describes the primary role of the National Industrial Security Program (NISP)?
- To serve as a single, integrated program for the protection of classified information shared with U.S. industry. (Correct answer)
- To conduct background investigations for all federal employees.
- To exclusively manage the physical security of all Department of Defense facilities.
- To develop and publish all cybersecurity standards for the federal government.
Correct answer: To serve as a single, integrated program for the protection of classified information shared with U.S. industry.
The National Industrial Security Program (NISP), established by Executive Order 12829, is the single, integrated program that sets the standards for protecting classified information released to or generated by contractors, licensees, and grantees of the U.S. Government.
Question 3: What is the 'continuous monitoring' step in the NIST RMF designed to accomplish?
- Monitoring system performance metrics only
- Maintaining ongoing awareness of the security posture of a system to support risk management decisions (Correct answer)
- Conducting annual security assessments
- Continuously monitoring employee productivity
Correct answer: Maintaining ongoing awareness of the security posture of a system to support risk management decisions
Continuous monitoring maintains ongoing situational awareness of system security, enabling rapid detection of changes that may introduce new risks and supporting informed authorization decisions.
Question 4: A security manager is determining the appropriate level of investigation for a new federal position. What is the most critical factor in this determination?
- The geographic location of the position.
- The salary grade of the position.
- The designation of the position's sensitivity. (Correct answer)
- The number of applicants for the position.
Correct answer: The designation of the position's sensitivity.
The sensitivity level of a position (e.g., Non-Sensitive, Public Trust, or National Security) is the primary determinant for the type and scope of the required personnel security investigation. Higher sensitivity levels require more thorough investigations.
Question 5: What is a 'covert channel' in the context of information security?
- A communication path that transfers information in a manner that violates security policy (Correct answer)
- A classified communication system
- A standard network protocol
- An encrypted communication pathway
Correct answer: A communication path that transfers information in a manner that violates security policy
A covert channel is a communication path that allows information to be transferred in a manner that was not intended by the system designers and violates security policy.
Question 6: Which of the following examples describes a security violation rather than a security infraction?
- At the end of the day, Karen was leaving and taking with her unclassified documents she would review at home. When she began to review those documents that night, she realized that classified materials had slipped in between the unclassified materials. (Correct answer)
- On a busy day, Karen printed classified documents on the printer in her open storage/secure room. She forgot about the documents and they remained on the printer for about an hour before she retrieved them.
- Karen was working a mission related to Mexican Drug cartel operating out of Play a Carmen. Her husband planned a golf trip with friends to that area. She advised him not to go, and believing that it was a safety issue, she provided sensitive details about the cartel to make sure that he did not go.
- Karen was late for a meeting in a different area of her building. She put a classified document in a folder she believed was marked for carrying classified materials. When handing out the materials, Karen realized that the folder was not marked for carrying classified materials, she had put the documents in the wrong folder.
Correct answer: At the end of the day, Karen was leaving and taking with her unclassified documents she would review at home. When she began to review those documents that night, she realized that classified materials had slipped in between the unclassified materials.
Left ventricular hypertrophy (LVH) is the thickening of the left ventricular wall, often caused by increased workload on the heart. Aortic stenosis, a narrowing of the aortic valve, forces the left ventricle to pump harder against higher resistance, leading to chronic pressure overload and compensatory myocardial thickening, making it a common cause of LVH.
Question 7: Under EO 13526, what is the standard maximum duration for most originally classified information before automatic declassification?
- 25 years (Correct answer)
- 50 years
- 10 years
- 75 years
Correct answer: 25 years
EO 13526 establishes 25 years as the standard maximum classification period, after which information must be automatically declassified unless a specific exemption applies.
Question 8: What is 'original classification authority' (OCA)?
- A type of security clearance investigation
- A clearance level for senior government officials
- A committee that reviews classified information
- The authority vested in certain officials to determine that specific information requires protection in the national security interest (Correct answer)
Correct answer: The authority vested in certain officials to determine that specific information requires protection in the national security interest
Original Classification Authority (OCA) is the official authority vested in certain government officials to make initial determinations that information warrants classification protection.
Question 9: What is a 'security lighting' requirement and how does it contribute to physical security?
- Lighting used only during emergencies
- Illumination that deters unauthorized activity by reducing concealment opportunities and enabling surveillance cameras to capture clear images (Correct answer)
- Decorative lighting for facility aesthetics
- Lighting that automatically activates during fire alarms
Correct answer: Illumination that deters unauthorized activity by reducing concealment opportunities and enabling surveillance cameras to capture clear images
Security lighting deters unauthorized access by eliminating dark areas where intruders could conceal themselves and improving visibility for security patrols and surveillance cameras.
Question 10: What is the role of the 'Authorizing Official' (AO) in the NIST RMF?
- An external auditor who certifies system security
- A technical specialist who implements security controls
- A senior official who has the authority and accountability to accept risk on behalf of the organization and grant ATOs (Correct answer)
- A contractor who manages system operations
Correct answer: A senior official who has the authority and accountability to accept risk on behalf of the organization and grant ATOs
The AO is a senior official with the authority and accountability to authorize a system to operate by accepting the risk associated with its operation.
Question 11: What is 'biometric authentication' and what advantage does it provide over traditional access cards?
- A type of electronic keypad
- A backup authentication method
- A method using multiple keys to open a lock
- Authentication using unique physical or behavioral characteristics that cannot easily be stolen, lost, or shared (Correct answer)
Correct answer: Authentication using unique physical or behavioral characteristics that cannot easily be stolen, lost, or shared
Biometric authentication uses unique physical traits (fingerprints, iris patterns, facial features) that are much harder to steal, duplicate, or share than access cards, providing stronger authentication.
Question 12: A senior management official is presented with an authorization package that includes the System Security Plan (SSP), the Security Assessment Report (SAR), and a Plan of Action and Milestones (POA&M). By signing the Authorization to Operate (ATO), what is this official formally doing?
- Confirming that all items in the POA&M have been fully remediated.
- Certifying that all security controls have been implemented perfectly.
- Accepting the remaining residual risk of operating the information system. (Correct answer)
- Approving the budget for the next three years of security operations.
Correct answer: Accepting the remaining residual risk of operating the information system.
The 'Authorize' step of the RMF culminates in a senior official, the Authorizing Official (AO), making a formal decision. By granting an Authorization to Operate (ATO), the AO is formally accepting the security and privacy risk to the organization based on the implementation of controls and the plan to address remaining weaknesses, which is known as residual risk.
Question 13: A security manager is implementing Crime Prevention Through Environmental Design (CPTED) principles for a new corporate campus. Which of the following measures BEST exemplifies the principle of 'Natural Surveillance'?
- Issuing key cards to all employees to restrict access to specific buildings.
- Installing a high-perimeter fence with a single, guarded entry point.
- Posting signs that clearly define the property line and designate private areas.
- Using thorny bushes below ground-floor windows and ensuring building entrances are well-lit and visible from the street. (Correct answer)
Correct answer: Using thorny bushes below ground-floor windows and ensuring building entrances are well-lit and visible from the street.
Natural Surveillance, a core principle of CPTED, focuses on designing the environment to maximize visibility and the perception that people can be seen. Placing thorny bushes makes it difficult for potential intruders to hide near windows, and ensuring entrances are well-lit and visible from public areas increases the chances that illicit activities will be observed by employees, visitors, or passersby.
Question 14: What is the role of 'physical security surveys' in a security program?
- Reviews of access badge issuance procedures
- Annual inspections of fire safety equipment only
- Systematic assessments of a facility's physical security measures to identify vulnerabilities and recommend improvements (Correct answer)
- Interviewing employees about job satisfaction
Correct answer: Systematic assessments of a facility's physical security measures to identify vulnerabilities and recommend improvements
Physical security surveys systematically evaluate all aspects of a facility's physical security program to identify vulnerabilities and recommend countermeasures to reduce security risks.
Question 15: What does 'mitigating information' mean in the context of security clearance adjudication?
- A formal statement from the clearance applicant
- Information that automatically approves a clearance
- Information that addresses potentially disqualifying concerns by providing context, explanation, or evidence of rehabilitation (Correct answer)
- Information that increases the severity of security concerns
Correct answer: Information that addresses potentially disqualifying concerns by providing context, explanation, or evidence of rehabilitation
Mitigating information is information that reduces the significance of potentially disqualifying concerns by providing context, demonstrating rehabilitation, or showing the concern is not likely to recur.
Question 16: Under what circumstances may classified information be discussed over a standard non-secure telephone line?
- When the conversation is brief and no specific operational details are mentioned
- Never — classified information must not be discussed over non-secure telephone lines (Correct answer)
- When both parties hold appropriate clearances for the information being discussed
- When the call is made from within an approved government facility
Correct answer: Never — classified information must not be discussed over non-secure telephone lines
Classified information must never be discussed over standard non-secure telephone lines regardless of the parties' clearance levels, because unsecured communications channels are vulnerable to interception.
Question 17: What is the primary goal of personal security measures for a security professional?
- To prevent all contact with the public
- To avoid traveling abroad
- To identify and reduce personal vulnerabilities while enabling professional effectiveness (Correct answer)
- To limit social media use entirely
Correct answer: To identify and reduce personal vulnerabilities while enabling professional effectiveness
Personal security aims to reduce vulnerabilities and risks to the individual while still allowing them to perform their professional duties effectively.
Question 18: Which of the following describes the 'Availability' component of the CIA triad?
- The assurance that information is not disclosed to unauthorized individuals.
- The process of verifying the identity of a user.
- The guarantee that data is accurate and has not been tampered with.
- The assurance that authorized users can access information and systems when required. (Correct answer)
Correct answer: The assurance that authorized users can access information and systems when required.
Availability ensures that systems, applications, and data are accessible to authorized users when they need them. It involves protecting against downtime caused by hardware failures, software bugs, or malicious attacks like Denial of Service (DoS).
Question 19: When a classified data spill occurs, who is responsible for ensuring that policy requirements for addressing an unauthorized disclosure are met?
- Information Assurance Officer
- Activity Security Manager (Correct answer)
- Information Assurance Manager
- Information Assurance Staff
Correct answer: Activity Security Manager
Security Classification Guides (SCGs) are authoritative documents that provide specific instructions on the classification levels, downgrading, declassification, and special handling requirements for programs, projects, or plans. They serve as the preferred method for communicating classification determinations, ensuring consistent and proper protection of classified information across an organization.
Question 20: Why is social media a significant OPSEC concern?
- Social media allows inadvertent disclosure of critical information through posts, photos, and location data that adversaries can collect and analyze (Correct answer)
- Social media concerns only apply to personal accounts, not work activities
- Social media only matters for personal privacy
- Social media is a distraction from work
Correct answer: Social media allows inadvertent disclosure of critical information through posts, photos, and location data that adversaries can collect and analyze
Social media platforms allow people to unknowingly disclose sensitive information through posts, photographs (which may reveal sensitive locations or activities), and location data that adversaries can collect.
Question 21: What does 'sanitization' of classified materials mean?
- Updating classification markings
- Physically cleaning classified documents
- Sending documents to an archive
- Removing all classified information or references from a document so it can be handled as unclassified (Correct answer)
Correct answer: Removing all classified information or references from a document so it can be handled as unclassified
Sanitization involves the removal or modification of all classified information from a document or system, rendering it suitable for release or use at a lower classification level or as unclassified.
Question 22: What is the consequence of a security violation in an industrial security program?
- No consequence if classified information was not compromised
- Loss of facility clearance, administrative action, or criminal prosecution depending on severity (Correct answer)
- Automatic contract termination only
- Only a written warning
Correct answer: Loss of facility clearance, administrative action, or criminal prosecution depending on severity
Security violations can result in a range of consequences from counseling and retraining to loss of clearance, administrative action, or criminal prosecution depending on the nature and severity.
Question 23: What is the purpose of 'security seals' on equipment and containers?
- To attach shipping labels
- To provide tamper evidence, indicating whether a container or piece of equipment has been accessed or modified without authorization (Correct answer)
- Decorative purposes only
- To identify ownership of equipment
Correct answer: To provide tamper evidence, indicating whether a container or piece of equipment has been accessed or modified without authorization
Security seals provide tamper evidence on equipment, containers, and access points, making it apparent if someone has accessed or modified what is sealed without authorization.
Question 24: According to the principle of least privilege, how should access to information and resources be granted?
- All users should be granted administrator-level access to ensure they can perform their duties.
- Users should be granted the minimum level of access and permissions necessary to perform their job functions. (Correct answer)
- Users should be granted access based on their job title and seniority within the company.
- Access should be granted to groups of users rather than individuals to simplify management.
Correct answer: Users should be granted the minimum level of access and permissions necessary to perform their job functions.
The principle of least privilege is a fundamental concept in information security that states a user should only have the minimum set of permissions required to perform their specific job responsibilities, and nothing more. This helps to limit the damage that can be caused by an accident, error, or a compromised user account.
Question 25: What is the primary document used to establish and manage a Special Access Program?
- Standard Operating Procedures (SOPs)
- Program Protection Plan (PPP)
- Special Access Program Nomination Package (SAPNP) (Correct answer)
- Security Classification Guide (SCG)
Correct answer: Special Access Program Nomination Package (SAPNP)
The statement accurately defines biometrics. Biometrics are measurable physical characteristics (e.g., fingerprints, iris patterns) or personal behavioral traits (e.g., voice, handwriting) used to recognize or verify an individual's identity. This technology is widely employed in security systems for authentication and access control.
Question 26: What is the purpose of the Personnel Security Investigation (PSI) process?
- To investigate criminal activity
- To determine whether an individual is eligible for a security clearance (Correct answer)
- To assess job performance
- To evaluate candidates for promotions
Correct answer: To determine whether an individual is eligible for a security clearance
A PSI is conducted to gather information about an individual's background to determine their eligibility and suitability for a security clearance.
Question 27: What is the purpose of the industrial security inspection program?
- To conduct financial audits of contractors
- To review contract deliverables
- To evaluate employee job performance
- To verify compliance with NISPOM requirements and assess the effectiveness of security measures (Correct answer)
Correct answer: To verify compliance with NISPOM requirements and assess the effectiveness of security measures
Industrial security inspections are conducted by the cognizant security agency to verify contractor compliance with NISPOM requirements and the effectiveness of their security programs.
Question 28: What is the primary subject matter of Executive Order 13526?
- Cybersecurity requirements for classified networks
- Physical security requirements for classified facilities
- Classified national security information policy (Correct answer)
- Personnel security investigation standards
Correct answer: Classified national security information policy
EO 13526, signed in 2009, establishes U.S. government policy for classifying, safeguarding, and declassifying national security information, replacing EO 12958.
Question 29: A facility uses a physical access control system (PACS) where employees present a key fob to a reader to unlock a door. Which components are essential for this system to function?
- Surveillance camera, turnstile, and a visitor log.
- Biometric scanner, server, and a security guard.
- Motion detector, alarm, and a keypad.
- Credential, reader, and a control panel. (Correct answer)
Correct answer: Credential, reader, and a control panel.
A basic electronic physical access control system requires a credential (the key fob), a reader to interpret the credential's data, and a control panel that makes the access decision and signals the lock to open. The server stores the access rules and logs, and the control panel communicates with it, but the core interaction at the access point involves the credential, reader, and controller.
Question 30: What is required when a contractor discovers a potential loss or compromise of classified information?
- Wait to see if the information reappears
- Notify only the company's legal department
- Only document the incident internally
- Immediately conduct an inquiry and report the incident to the contracting agency and cognizant security authority (Correct answer)
Correct answer: Immediately conduct an inquiry and report the incident to the contracting agency and cognizant security authority
When classified information may be lost or compromised, immediate action is required to conduct a preliminary inquiry and report the incident to the government contracting activity and cognizant security authority.
Question 31: What is 'security information and event management' (SIEM)?
- A system that collects and analyzes security events from across an organization to identify threats (Correct answer)
- A method for organizing security training events
- A type of physical security alarm system
- A performance management system for security staff
Correct answer: A system that collects and analyzes security events from across an organization to identify threats
SIEM systems collect and correlate security events and logs from across an organization's IT infrastructure to provide real-time threat detection and compliance reporting.
Question 32: Where must the overall classification level marking appear on every page of a classified document?
- Only on the document cover sheet
- On the first and last pages only
- At the top and bottom of every page (Correct answer)
- Only on the first page as a banner
Correct answer: At the top and bottom of every page
The overall classification level must appear as a banner line at both the top and bottom of every page to ensure all readers are aware of the document's classification regardless of how pages are handled.
Question 33: What is the primary purpose of the NIST Risk Management Framework (RMF)?
- To provide a structured process for integrating security and privacy risk management into the system development lifecycle (Correct answer)
- To manage financial investment risk
- To certify software products
- To train cybersecurity professionals
Correct answer: To provide a structured process for integrating security and privacy risk management into the system development lifecycle
The NIST RMF provides a comprehensive process for managing information security and privacy risk throughout the system development lifecycle, from design through decommission.
Question 34: Which of the following activities is the primary focus of the 'Monitor' step in the Risk Management Framework?
- Performing the initial authorization of the system.
- Developing the initial System Security Plan (SSP).
- Continuously tracking changes to the system and assessing control effectiveness over time. (Correct answer)
- Selecting the initial baseline of security controls.
Correct answer: Continuously tracking changes to the system and assessing control effectiveness over time.
The 'Monitor' step is the final, ongoing phase of the RMF. Its purpose is to maintain security posture by continuously monitoring control implementation, assessing for changes, and understanding the ongoing risk to the system. This ensures that security remains effective throughout the system's lifecycle.
Question 35: What is 'data exfiltration' in the context of insider threats?
- Importing data from external sources
- Encrypting organizational data
- Backing up organizational data
- The unauthorized transfer of sensitive data from an organization by an insider (Correct answer)
Correct answer: The unauthorized transfer of sensitive data from an organization by an insider
Data exfiltration by an insider refers to the unauthorized transfer of sensitive organizational information to external parties, typically for financial gain, to benefit a foreign intelligence service, or for competitive advantage.
Question 36: What is 'social engineering' in the context of personal security?
- Managing social media accounts
- Building professional networks
- Manipulating individuals into revealing confidential information or performing actions (Correct answer)
- Organizing community events
Correct answer: Manipulating individuals into revealing confidential information or performing actions
Social engineering involves psychologically manipulating individuals to divulge confidential information or perform actions that may compromise security.
Question 37: What is an 'insider threat' in the security context?
- A threat that only affects insider trading
- A security risk posed by individuals within an organization who have authorized access but misuse it (Correct answer)
- A risk from contractors who have never been cleared
- A threat from someone outside the organization
Correct answer: A security risk posed by individuals within an organization who have authorized access but misuse it
An insider threat is a security risk posed by persons who have authorized access to organizational resources and who use that access—wittingly or unwittingly—in a way that harms the organization.
Question 38: What is 'two-factor authentication' (2FA)?
- Having two passwords for a single account
- Logging in twice to confirm identity
- A security process requiring two different types of verification before granting access (Correct answer)
- Using two separate computers to access a system
Correct answer: A security process requiring two different types of verification before granting access
2FA requires users to provide two different types of verification factors — something they know, something they have, or something they are — to access a system.
Question 39: A data center is located in an area prone to power outages. To ensure its physical security systems, including access controls and surveillance, remain operational at all times, which of the following is the MOST critical supporting measure?
- A contract with a local security guard service.
- A loud, audible alarm system.
- Motion-activated security cameras.
- An uninterruptible power supply (UPS) and backup generator. (Correct answer)
Correct answer: An uninterruptible power supply (UPS) and backup generator.
Physical security systems like access controls and surveillance cameras rely on electricity. During a power outage, these systems will fail. An uninterruptible power supply (UPS) provides immediate, short-term power, while a backup generator can sustain power for an extended period. This ensures continuous operation of critical security measures. The other options are valuable but do not address the fundamental issue of power loss.
Question 40: During a background investigation, an investigator discovers that the applicant deliberately omitted information about a prior arrest on their SF-86, Questionnaire for National Security Positions. Under which adjudicative guideline would this be a primary concern?
- Guideline F: Financial Considerations
- Guideline I: Psychological Conditions
- Guideline E: Personal Conduct (Correct answer)
- Guideline B: Foreign Influence
Correct answer: Guideline E: Personal Conduct
Guideline E, Personal Conduct, addresses issues of questionable judgment, lack of candor, dishonesty, and unwillingness to comply with rules and regulations. Deliberately falsifying information on a security questionnaire is a significant issue under this guideline.
Question 41: When a cleared employee must hand-carry Secret documents outside a controlled facility, what is required?
- A courier authorization letter and appropriate protective packaging or container (Correct answer)
- No special requirements beyond possessing an active Secret clearance
- Documents must be placed in a sealed envelope marked with the classification level
- Only a signed receipt from the destination facility is required
Correct answer: A courier authorization letter and appropriate protective packaging or container
Hand-carrying Secret materials outside controlled facilities requires a courier authorization letter and the documents must be properly packaged to prevent unauthorized access or disclosure during transit.
Question 42: An organization is implementing a risk management program. After identifying potential threats and vulnerabilities, what is the logical next step in the risk management process?
- Monitor and review the risks.
- Conduct a risk analysis. (Correct answer)
- Create an incident response plan.
- Implement security controls.
Correct answer: Conduct a risk analysis.
The standard risk management process involves identifying assets, threats, and vulnerabilities, and then analyzing the risk. Risk analysis involves evaluating the likelihood of a threat exploiting a vulnerability and the potential impact it would have on the organization. This analysis is crucial before deciding which controls to implement.
Question 43: What is 'technical surveillance countermeasures' (TSCM) and why are they important for SAPs?
- Methods for conducting electronic surveillance
- Physical security inspections only
- Specialized examinations of SAP facilities to detect clandestine listening devices or technical collection capabilities (Correct answer)
- Standard IT security audits
Correct answer: Specialized examinations of SAP facilities to detect clandestine listening devices or technical collection capabilities
TSCM involves specialized inspections of SAP facilities to detect and neutralize clandestine electronic surveillance devices or collection capabilities that could compromise program information.
Question 44: What is the purpose of 'crime prevention through environmental design' (CPTED)?
- Using security cameras in all areas (Correct answer)
- Placing security guards at every entrance
- Designing or modifying the physical environment to reduce the opportunities for crime and unauthorized access
- Installing alarm systems in all locations
Correct answer: Using security cameras in all areas
CPTED uses environmental design principles to reduce opportunities for criminal activity, including natural surveillance, natural access control, territorial reinforcement, and maintenance.
Question 45: Which of the following is a key component of the Trusted Workforce 2.0 initiative, designed to modernize the personnel security process?
- Periodic reinvestigations conducted every ten years for all clearance levels.
- Continuous Vetting/Evaluation to monitor for new risk information in near real-time. (Correct answer)
- Elimination of self-reporting requirements for security clearance holders.
- A one-time, comprehensive background investigation with no follow-up.
Correct answer: Continuous Vetting/Evaluation to monitor for new risk information in near real-time.
Continuous Vetting (CV) or Continuous Evaluation (CE) is a cornerstone of the Trusted Workforce 2.0 reform. It replaces the traditional periodic reinvestigation model with ongoing, automated checks of various data sources to identify potential security risks as they arise.
Question 46: Under Executive Order 13526, who is authorized to make original classification decisions?
- All cleared contractors working on classified programs
- The President, Vice President, and officials designated by the President (Correct answer)
- Any government employee holding an active security clearance
- The Director of National Intelligence exclusively
Correct answer: The President, Vice President, and officials designated by the President
EO 13526 designates the President, Vice President, and agency heads or officials specifically designated by the President as Original Classification Authorities (OCAs).
Question 47: What are the 'Adjudicative Guidelines' used for?
- Evaluating personnel security investigation results to determine eligibility for access to classified information (Correct answer)
- Determining salary levels for security positions
- Evaluating contractor performance
- Establishing security clearance processing timelines
Correct answer: Evaluating personnel security investigation results to determine eligibility for access to classified information
The Adjudicative Guidelines provide the criteria used to evaluate investigation results and determine whether granting or continuing a security clearance is consistent with national security interests.
Question 48: What is 'pattern analysis' in the context of OPSEC threats?
- A method for creating security policies
- The adversary technique of identifying regularities in behavior that can be used to predict activities or reveal critical information (Correct answer)
- Analyzing fabric patterns for security badges
- Statistical analysis of security incidents
Correct answer: The adversary technique of identifying regularities in behavior that can be used to predict activities or reveal critical information
Pattern analysis involves an adversary identifying recurring patterns in an organization's activities, schedules, or behaviors that can reveal sensitive information about planned operations.
Question 49: Which of the following security programs areas would you find practitioners involved with processes that monitor employees for new information that could affect their security clearance eligibility status?
- Foreign Disclosure
- Information Assurance
- Physical Security
- International Security
- Personnel Security (Correct answer)
- Information Security
- Operations Security
- Research and Technology Protection
Correct answer: Personnel Security
Executive Order 13556 established the Controlled Unclassified Information (CUI) program to standardize the handling of unclassified information that requires safeguarding or dissemination controls. Law Enforcement Sensitive (LES) information is specifically identified as a category of CUI, meaning it requires specific protections and handling procedures despite not being classified.
Question 50: What is a 'Letter of Interrogatory' (LOI) in the personnel security process?
- A search warrant
- A formal criminal charge
- An employment termination notice
- A written list of questions sent to a security clearance applicant to clarify potentially disqualifying information (Correct answer)
Correct answer: A written list of questions sent to a security clearance applicant to clarify potentially disqualifying information
A LOI is sent to a clearance applicant when an investigation reveals potentially disqualifying information, asking the individual to provide written responses to clarify the information.
Question 51: A security analyst is reviewing access logs for a sensitive database server. The analyst is primarily concerned with ensuring that the data has not been altered or deleted by unauthorized individuals. Which principle of the CIA triad is the analyst's main focus?
- Non-repudiation
- Integrity (Correct answer)
- Availability
- Confidentiality
Correct answer: Integrity
Integrity is the principle that ensures data is trustworthy and has not been subject to unauthorized modification or destruction. The analyst's focus on preventing alteration or deletion directly relates to maintaining the integrity of the data.
Question 52: What is a 'penetration test' in information security?
- A method for recovering deleted files
- Testing network cable connections
- A type of malware
- An authorized simulated attack to evaluate the security of a system (Correct answer)
Correct answer: An authorized simulated attack to evaluate the security of a system
A penetration test is an authorized, simulated attack against a system to identify vulnerabilities that could be exploited by real attackers.
Security Fundamentals Professional Certification (SFPC)
The SFPC exam validates foundational knowledge of DoD security disciplines including personnel security, information security, physical security, industrial security, and operations security.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds