IFPC Counterintelligence & Threat Awareness 2 — Questions and Answers
Question 1: What is the primary goal of Operations Security (OPSEC) as it relates to CI threat awareness?
- To encrypt all classified communications
- To deny adversaries access to critical information about plans and capabilities (Correct answer)
- To identify and arrest foreign intelligence officers
- To conduct background investigations on all personnel
Correct answer: To deny adversaries access to critical information about plans and capabilities
OPSEC is a process that denies adversaries critical information about friendly intentions, capabilities, and activities by identifying and protecting exploitable information.
Question 2: Which of the following behaviors is a recognized potential indicator of an insider threat?
- Requesting additional training on security protocols
- Working late hours consistently without explanation and accessing files outside normal duties (Correct answer)
- Reporting a colleague's suspicious behavior to security
- Taking approved leave during a high-tempo operation
Correct answer: Working late hours consistently without explanation and accessing files outside normal duties
Accessing systems or files outside one's normal duties, especially combined with unexplained after-hours activity, is a recognized behavioral indicator that may suggest insider threat activity.
Question 3: What is a 'honeypot' as used in counterintelligence operations?
- A safe house used to debrief returning agents
- A false target or decoy designed to attract and expose hostile intelligence activity (Correct answer)
- A classified database of known foreign intelligence officers
- An encrypted channel for communicating with assets
Correct answer: A false target or decoy designed to attract and expose hostile intelligence activity
A honeypot is a deliberately planted lure — such as fake documents, systems, or opportunities — designed to attract adversary intelligence activity so it can be identified and countered.
Question 4: What is 'compartmentation' as a counterintelligence and security principle?
- Organizing intelligence reports by geographic region
- Limiting access to sensitive information to only those with a need-to-know (Correct answer)
- Storing classified documents in separate physical locations
- Dividing a CI investigation team into specialized units
Correct answer: Limiting access to sensitive information to only those with a need-to-know
Compartmentation limits access to sensitive information strictly to those who have both the proper clearance and a verified need-to-know, reducing the damage any single breach or mole can cause.
Question 5: In CI terminology, what is a 'false flag' operation?
- An operation conducted under the wrong intelligence authority
- Misattributing an operation to a different country or organization to mislead the target (Correct answer)
- Flying an unauthorized aircraft over restricted airspace
- Reporting false threat assessments to deceive leadership
Correct answer: Misattributing an operation to a different country or organization to mislead the target
A false flag operation is one in which the true sponsor disguises itself by making the activity appear to originate from a different nation, group, or entity to mislead the target.
Question 6: What does surveillance detection refer to in operational security?
- Installing cameras to monitor a foreign embassy
- Techniques used to identify whether one is being watched or followed by adversaries (Correct answer)
- Technical methods to intercept hostile communications
- The process of auditing computer logs for unauthorized access
Correct answer: Techniques used to identify whether one is being watched or followed by adversaries
Surveillance detection involves techniques and patterns of behavior used by intelligence officers to determine if they are being observed or followed by a hostile surveillance team.
Question 7: What is the term for an individual who volunteers to provide information to an intelligence service without being formally recruited?
- Asset
- Handler
- Walk-in (Correct answer)
- Provocateur
Correct answer: Walk-in
A walk-in is an individual who approaches an intelligence service of their own volition to offer information, access, or services, rather than being identified and recruited through normal CI or collection means.
What is the primary goal of Operations Security (OPSEC) as it relates to CI threat awareness?