OSINT Operational Security and Counterintelligence 2 — Questions and Answers
Question 1: Which OPSEC step involves determining what information an adversary would need to successfully attack your operations?
- Risk assessment
- Threat analysis
- Critical information identification (Correct answer)
- Vulnerability analysis
Correct answer: Critical information identification
Identifying critical information is the first step in OPSEC, defining what data, if compromised, could harm the mission.
Question 2: A counterintelligence analyst notices a pattern of targeted phishing emails sent only to personnel who attended a specific classified briefing. This is best described as:
- Opportunistic spear-phishing
- Indicator of insider threat only
- Adversary intelligence collection against a specific group (Correct answer)
- Routine spam campaign
Correct answer: Adversary intelligence collection against a specific group
Targeted phishing correlated to a specific briefing's attendees suggests an adversary is actively collecting against that group.
Question 3: What is the primary purpose of a 'legend' in undercover OSINT operations?
- A map key for geospatial data
- A fabricated backstory supporting a cover identity (Correct answer)
- A legal document authorizing covert activity
- A classified code name for an operation
Correct answer: A fabricated backstory supporting a cover identity
A legend is a detailed, consistent false backstory constructed to make a cover identity believable under scrutiny.
Question 4: Which technique is used by adversaries to detect covert OSINT collectors by planting unique, trackable information in documents or databases?
- Data poisoning
- Canary trapping (honeypot data) (Correct answer)
- Steganography
- Traffic analysis
Correct answer: Canary trapping (honeypot data)
Canary trapping embeds unique bait information per suspected leaker so that when the data surfaces, the source is identified.
Question 5: When conducting OSINT research, using a VPN alone is considered insufficient for full anonymization primarily because:
- VPNs slow down searches
- Browser fingerprinting and behavior patterns can still identify the user (Correct answer)
- VPNs are illegal for intelligence work
- VPN providers always log traffic
Correct answer: Browser fingerprinting and behavior patterns can still identify the user
Browser fingerprints, cookies, and behavioral patterns can re-identify a researcher even when IP address is masked by a VPN.
Question 6: The concept of 'need-to-know' in classified environments directly supports OPSEC by:
- Ensuring all team members are fully informed
- Limiting exposure of sensitive information to only those who require it for their role (Correct answer)
- Speeding up decision-making processes
- Eliminating the need for encryption
Correct answer: Limiting exposure of sensitive information to only those who require it for their role
Need-to-know restricts information access, reducing the number of potential disclosure points and limiting adversary exploitation opportunities.
Question 7: An OSINT analyst observes that a foreign intelligence service is consistently acquiring job postings from a defense contractor to map internal structure. This collection method is called:
- Social engineering
- Open source exploitation of publicly available information (Correct answer)
- Cyber espionage
- Human intelligence (HUMINT)
Correct answer: Open source exploitation of publicly available information
Systematically mining publicly available job postings to map organizational structure is a classic open source exploitation technique.
Which OPSEC step involves determining what information an adversary would need to successfully attack your operations?