NSA NSA Operations Security (OPSEC) 2 — Questions and Answers
Question 1: In OPSEC, how is a 'threat' defined?
- Any natural disaster that disrupts operations
- An adversary with both the capability and intent to exploit critical information (Correct answer)
- A technical system failure
- A budget constraint limiting security programs
Correct answer: An adversary with both the capability and intent to exploit critical information
An OPSEC threat is an adversary with both the capability to collect information and the intent to use it against your mission or organization.
Question 2: What is a Critical Information List (CIL)?
- A list of all classified documents in an organization
- A prioritized list of information requiring protection from adversary exploitation (Correct answer)
- A list of cleared NSA personnel
- A list of known network vulnerabilities
Correct answer: A prioritized list of information requiring protection from adversary exploitation
A Critical Information List is a prioritized list of specific information whose compromise could damage national security or degrade mission success.
Question 3: In the OPSEC process, 'risk' is defined as a combination of which two factors?
- Cost and time to implement countermeasures
- Probability of exploitation and the impact of the resulting information loss (Correct answer)
- Personnel assigned and equipment available
- Classification level and data sensitivity rating
Correct answer: Probability of exploitation and the impact of the resulting information loss
OPSEC risk is calculated as the combination of the probability an adversary will successfully exploit a vulnerability and the resulting impact of that information loss.
Question 4: Which OPSEC step involves identifying potential adversaries and their collection capabilities?
- Identification of critical information
- Analysis of threats (Correct answer)
- Analysis of vulnerabilities
- Application of countermeasures
Correct answer: Analysis of threats
The analysis of threats step involves identifying potential adversaries, assessing their capabilities, and determining what information they are likely targeting.
Question 5: What is the role of an OPSEC Program Manager within a government agency?
- To issue and renew security clearances
- To oversee and coordinate all OPSEC activities to protect the organization's critical information (Correct answer)
- To conduct counterintelligence investigations
- To manage classified database access permissions
Correct answer: To oversee and coordinate all OPSEC activities to protect the organization's critical information
An OPSEC Program Manager is responsible for overseeing and coordinating all OPSEC activities to ensure the organization consistently protects its critical information.
Question 6: What does 'aggregation' mean in the context of OPSEC?
- Combining multiple data sources for statistical reporting
- Combining multiple pieces of individually unclassified information to reveal sensitive or classified details (Correct answer)
- Grouping security clearance levels for access control
- Collecting classified materials for archival purposes
Correct answer: Combining multiple pieces of individually unclassified information to reveal sensitive or classified details
Aggregation in OPSEC refers to combining multiple pieces of individually harmless unclassified information that together reveal sensitive or classified information.
In OPSEC, how is a 'threat' defined?