OSINT Operational Security and Counterintelligence 3 — Questions and Answers
Question 1: Which counterintelligence measure involves deliberately feeding false information to a suspected adversary contact to assess their loyalty or trace leaks?
- Deception operation (feed operation) (Correct answer)
- Double-blind testing
- Passive surveillance
- Signal jamming
Correct answer: Deception operation (feed operation)
A feed operation provides controlled false or misleading data to a suspected asset to track where it resurfaces and confirm the leak pathway.
Question 2: Metadata in digital photographs, such as GPS coordinates and device model, poses an OPSEC risk primarily because:
- It degrades image quality
- Adversaries can extract location and identity information without viewing the image content (Correct answer)
- It slows down file transfers
- It prevents images from being shared
Correct answer: Adversaries can extract location and identity information without viewing the image content
EXIF metadata embedded in images can reveal precise GPS location, timestamp, and device details that expose the operator's identity and position.
Question 3: In OPSEC terminology, a 'vulnerability' is best defined as:
- A weakness in a system that could be exploited by a threat (Correct answer)
- Any publicly available information
- An adversary's known capability
- A risk that has already been exploited
Correct answer: A weakness in a system that could be exploited by a threat
A vulnerability is a gap or weakness in protective measures that could allow an adversary to collect on or exploit critical information.
Question 4: A researcher discovers that a subject's morning running route is visible across multiple fitness tracking app public profiles. This represents which type of OPSEC failure?
- Single-source compromise
- Pattern of life aggregation from open sources (Correct answer)
- Cryptographic weakness
- Social engineering
Correct answer: Pattern of life aggregation from open sources
Aggregating individually innocuous public data points—like fitness app routes—creates a detailed pattern of life that is an OPSEC vulnerability.
Question 5: Which security principle involves separating operations into compartments so that compromise of one element does not expose the entire program?
- Defense in depth
- Compartmentalization (Correct answer)
- Zero trust architecture
- Redundancy planning
Correct answer: Compartmentalization
Compartmentalization limits information flow between segments so that a single breach cannot cascade into full program exposure.
Question 6: When an adversary monitors the timing, volume, and routing of communications—without reading the content—to infer operational activity, this is known as:
- Content analysis
- Traffic analysis (Correct answer)
- Signals intelligence (SIGINT) decryption
- Social network analysis
Correct answer: Traffic analysis
Traffic analysis derives intelligence from communication patterns, frequency, and routing rather than the encrypted content itself.
Question 7: An analyst uses a dedicated, air-gapped research laptop exclusively for sensitive OSINT work. This practice primarily mitigates which risk?
- Physical theft only
- Cross-contamination of sensitive data with personal or networked systems (Correct answer)
- Hardware failure
- Legal liability
Correct answer: Cross-contamination of sensitive data with personal or networked systems
An air-gapped dedicated device prevents sensitive research data from mixing with personal accounts, tracked browsers, or networked systems that could expose the analyst.
Which counterintelligence measure involves deliberately feeding false information to a suspected adversary contact to assess their loyalty or trace leaks?