Security Fundamentals Professional Certification (SFPC) — Questions and Answers
Question 1: What is a 'vehicle barrier system' and when is it used?
- Vehicle registration checkpoints
- Physical barriers (bollards, walls, vehicle traps) designed to prevent vehicle-borne attacks against facilities (Correct answer)
- Tire deflation devices for unauthorized vehicles
- Speed bumps for employee parking lots
Correct answer: Physical barriers (bollards, walls, vehicle traps) designed to prevent vehicle-borne attacks against facilities
Vehicle barrier systems prevent vehicle-borne threats (such as car bombs or ramming attacks) from reaching critical facilities by using passive or active physical barriers.
Question 2: Which of the following is a key component of the Trusted Workforce 2.0 initiative, designed to modernize the personnel security process?
- Elimination of self-reporting requirements for security clearance holders.
- Continuous Vetting/Evaluation to monitor for new risk information in near real-time. (Correct answer)
- Periodic reinvestigations conducted every ten years for all clearance levels.
- A one-time, comprehensive background investigation with no follow-up.
Correct answer: Continuous Vetting/Evaluation to monitor for new risk information in near real-time.
Continuous Vetting (CV) or Continuous Evaluation (CE) is a cornerstone of the Trusted Workforce 2.0 reform. It replaces the traditional periodic reinvestigation model with ongoing, automated checks of various data sources to identify potential security risks as they arise.
Question 3: What is the purpose of a 'security badge' or 'access control card' in physical security?
- To control physical access by verifying identity and authorization, allowing entry only to appropriately authorized individuals (Correct answer)
- To identify employees for payroll purposes only
- To provide employee benefit information
- To track employee attendance for HR purposes
Correct answer: To control physical access by verifying identity and authorization, allowing entry only to appropriately authorized individuals
Security badges and access control cards serve to verify an individual's identity and authorization level, allowing electronic access systems to grant or deny entry to specific areas based on programmed permissions.
Question 4: A senior management official is presented with an authorization package that includes the System Security Plan (SSP), the Security Assessment Report (SAR), and a Plan of Action and Milestones (POA&M). By signing the Authorization to Operate (ATO), what is this official formally doing?
- Approving the budget for the next three years of security operations.
- Certifying that all security controls have been implemented perfectly.
- Accepting the remaining residual risk of operating the information system. (Correct answer)
- Confirming that all items in the POA&M have been fully remediated.
Correct answer: Accepting the remaining residual risk of operating the information system.
The 'Authorize' step of the RMF culminates in a senior official, the Authorizing Official (AO), making a formal decision. By granting an Authorization to Operate (ATO), the AO is formally accepting the security and privacy risk to the organization based on the implementation of controls and the plan to address remaining weaknesses, which is known as residual risk.
Question 5: What is the primary purpose of a Special Access Program (SAP)?
- To streamline standard security clearance processing
- To impose additional safeguarding measures beyond standard classification requirements for specific sensitive programs (Correct answer)
- To provide supplemental pay for security professionals
- To create publicly accessible databases
Correct answer: To impose additional safeguarding measures beyond standard classification requirements for specific sensitive programs
SAPs impose additional security measures and access controls beyond standard classification requirements to protect especially sensitive national security information and activities.
Question 6: What does 'compartmentalization' mean in the context of SAPs?
- Dividing a facility into physical sections
- Restricting access to specific information or programs only to those with a need-to-know, limiting unauthorized disclosure (Correct answer)
- Creating separate computer networks
- Organizing files alphabetically
Correct answer: Restricting access to specific information or programs only to those with a need-to-know, limiting unauthorized disclosure
Compartmentalization limits access to information to only those individuals who need it for their specific duties, preventing broad exposure and limiting the damage from any single compromise.
Question 7: What is Standard Form 312 (SF-312)?
- A classified document cover sheet required for Top Secret materials
- A security incident report form used to document violations
- A classified information nondisclosure agreement signed before access is granted (Correct answer)
- A security clearance application submitted to the personnel security office
Correct answer: A classified information nondisclosure agreement signed before access is granted
SF-312 is the Classified Information Nondisclosure Agreement that all personnel must sign prior to being granted access to classified national security information.
Question 8: What is the purpose of 'crime prevention through environmental design' (CPTED)?
- Placing security guards at every entrance
- Installing alarm systems in all locations
- Designing or modifying the physical environment to reduce the opportunities for crime and unauthorized access
- Using security cameras in all areas (Correct answer)
Correct answer: Using security cameras in all areas
CPTED uses environmental design principles to reduce opportunities for criminal activity, including natural surveillance, natural access control, territorial reinforcement, and maintenance.
Question 9: What is 'patch management' in information security?
- Tracking security awareness training completion
- The process of acquiring, testing, and deploying software updates to fix vulnerabilities and improve functionality (Correct answer)
- Managing software licenses
- Repairing physical damage to hardware
Correct answer: The process of acquiring, testing, and deploying software updates to fix vulnerabilities and improve functionality
Patch management is the systematic process of keeping software up to date by applying vendor-released updates that fix security vulnerabilities and improve functionality.
Question 10: What is a 'penetration test' in information security?
- Testing network cable connections
- An authorized simulated attack to evaluate the security of a system (Correct answer)
- A type of malware
- A method for recovering deleted files
Correct answer: An authorized simulated attack to evaluate the security of a system
A penetration test is an authorized, simulated attack against a system to identify vulnerabilities that could be exploited by real attackers.
Question 11: What is the purpose of a 'security classification guide' (SCG)?
- To describe facility security procedures
- To identify specific items, elements, or categories of information that are classified and their required classification levels (Correct answer)
- To outline employee security responsibilities
- To provide a list of cleared personnel
Correct answer: To identify specific items, elements, or categories of information that are classified and their required classification levels
A SCG identifies specific information elements related to a classified program and prescribes their classification levels, downgrading instructions, and declassification guidance.
Question 12: What is a 'security lighting' requirement and how does it contribute to physical security?
- Lighting used only during emergencies
- Illumination that deters unauthorized activity by reducing concealment opportunities and enabling surveillance cameras to capture clear images (Correct answer)
- Decorative lighting for facility aesthetics
- Lighting that automatically activates during fire alarms
Correct answer: Illumination that deters unauthorized activity by reducing concealment opportunities and enabling surveillance cameras to capture clear images
Security lighting deters unauthorized access by eliminating dark areas where intruders could conceal themselves and improving visibility for security patrols and surveillance cameras.
Question 13: What should a security professional do if they believe they are being surveilled?
- Immediately confront the suspected surveiller
- Follow established protocols, avoid revealing awareness, and report to security personnel (Correct answer)
- Ignore the surveillance and continue normal activities
- Post about it on social media
Correct answer: Follow established protocols, avoid revealing awareness, and report to security personnel
Established protocols typically include not revealing awareness of surveillance while covertly noting details and reporting to security personnel to assess the threat.
Question 14: What is the principle of 'least privilege' in information security?
- Granting users and systems only the minimum permissions necessary to perform their required functions (Correct answer)
- Giving all users the minimum possible system resources
- Providing the least amount of security training to employees
- Implementing the simplest security controls available
Correct answer: Granting users and systems only the minimum permissions necessary to perform their required functions
The principle of least privilege limits user and system permissions to only what is necessary for their specific job functions, reducing the potential damage from account compromise or insider threats.
Question 15: Bollards are a type of physical security barrier primarily designed to protect against which of the following threats?
- Unauthorized pedestrian access
- Vehicular impact and ram-raiding (Correct answer)
- Climbing over perimeter fences
- Covert surveillance attempts
Correct answer: Vehicular impact and ram-raiding
Bollards are robust vertical posts designed to act as protective barriers against vehicle intrusions, whether accidental or intentional (ram-raiding). They are strategically placed to protect buildings, pedestrian areas, and other sensitive locations from vehicular impact. They are not primarily designed to stop pedestrians, surveillance, or climbing.
Question 16: What is the difference between an 'acknowledged' and 'unacknowledged' SAP?
- Acknowledged SAPs can be confirmed to exist while unacknowledged SAPs cannot be publicly confirmed (Correct answer)
- Only the budget differs
- Only the classification level differs
- Only the number of personnel cleared differs
Correct answer: Acknowledged SAPs can be confirmed to exist while unacknowledged SAPs cannot be publicly confirmed
Acknowledged SAPs may be confirmed to exist when inquired about, while unacknowledged SAPs (sometimes called 'black programs') cannot be confirmed to exist through official channels.
Question 17: What is 'defense in depth' in information security?
- Defending only the perimeter of a network
- Using the most advanced security technology available
- Encrypting only the most sensitive data
- Using multiple layers of security controls so that if one fails, others still provide protection (Correct answer)
Correct answer: Using multiple layers of security controls so that if one fails, others still provide protection
Defense in depth is a security strategy that employs multiple layers of controls, ensuring that if one control fails, additional controls continue to provide protection.
Question 18: An information system has been through the 'Assess' step of the Risk Management Framework (RMF). The assessment found several non-compliant security controls. What is the primary purpose of the Plan of Action and Milestones (POA&M) document created at this stage?
- To serve as the formal authorization decision for the system to operate.
- To provide a detailed technical description of the system's architecture and boundaries.
- To track the tasks, resources, and timelines required to correct identified weaknesses. (Correct answer)
- To document the system's information categorization and impact levels.
Correct answer: To track the tasks, resources, and timelines required to correct identified weaknesses.
The Plan of Action and Milestones (POA&M) is a corrective action plan used to track and manage the remediation of security weaknesses and vulnerabilities identified during a security control assessment. It details the specific tasks, necessary resources, milestones, and completion dates for addressing non-compliant controls.
Question 19: What is a 'personnel security interview' conducted during a background investigation?
- An interview with a subject's supervisor only
- A standard annual performance review
- A formal interview with the security clearance applicant or subject to clarify potentially disqualifying or derogatory information (Correct answer)
- A job interview for a security position
Correct answer: A formal interview with the security clearance applicant or subject to clarify potentially disqualifying or derogatory information
A personnel security interview is conducted with the subject to clarify information identified during the investigation, particularly potentially disqualifying or derogatory information.
Question 20: What is a 'security clearance denial' and what recourse does an individual have?
- An action that requires immediate legal action
- A permanent bar from all government employment
- An official determination that an individual does not meet eligibility standards, with the right to appeal through established procedures (Correct answer)
- An automatic finding of criminal activity
Correct answer: An official determination that an individual does not meet eligibility standards, with the right to appeal through established procedures
A security clearance denial means an individual doesn't meet the current eligibility standards, but they have the right to appeal the decision through established administrative procedures.
Question 21: Under what circumstances may classified information be discussed over a standard non-secure telephone line?
- When both parties hold appropriate clearances for the information being discussed
- Never — classified information must not be discussed over non-secure telephone lines (Correct answer)
- When the conversation is brief and no specific operational details are mentioned
- When the call is made from within an approved government facility
Correct answer: Never — classified information must not be discussed over non-secure telephone lines
Classified information must never be discussed over standard non-secure telephone lines regardless of the parties' clearance levels, because unsecured communications channels are vulnerable to interception.
Question 22: What behavioral indicator may suggest an employee is becoming a potential insider threat?
- Participating in company social events
- Consistently arriving on time
- Expressing unexplained financial concerns or discussing financial difficulties (Correct answer)
- Requesting additional training opportunities
Correct answer: Expressing unexplained financial concerns or discussing financial difficulties
Unexplained or unusual financial concerns can be a behavioral indicator of potential insider threat, particularly if the individual has access to valuable information or assets.
Question 23: What is the primary purpose of conducting end-of-day security checks in a classified work area?
- To update security clearance records for all personnel assigned to the area
- To record and count all classified documents accessed during the workday
- To verify that all employees have logged their classified access for the day
- To ensure all classified materials are properly secured and no violations exist (Correct answer)
Correct answer: To ensure all classified materials are properly secured and no violations exist
End-of-day security checks ensure all classified materials are stored in approved containers, equipment is secured, and no classified materials have been inadvertently left accessible when the area is unoccupied.
Question 24: What is a 'derivative classifier' in industrial security?
- A security clearance investigator
- An individual who creates new classified documents using information from existing classified sources (Correct answer)
- A contractor who specializes in classification reviews
- A computer program that classifies data
Correct answer: An individual who creates new classified documents using information from existing classified sources
A derivative classifier is a person who extracts, paraphrases, restates, or generates new information from existing classified sources, applying the classification determinations of the original source.
Question 25: What is the purpose of a 'DD Form 254' in industrial security?
- The Contract Security Classification Specification that conveys security requirements to contractors (Correct answer)
- A personnel security clearance request
- A financial reporting form
- An employee evaluation form
Correct answer: The Contract Security Classification Specification that conveys security requirements to contractors
DD Form 254 is the Contract Security Classification Specification that communicates specific security requirements, classification guidance, and access requirements to contractors.
Question 26: Which of the following activities is the primary focus of the 'Monitor' step in the Risk Management Framework?
- Continuously tracking changes to the system and assessing control effectiveness over time. (Correct answer)
- Performing the initial authorization of the system.
- Developing the initial System Security Plan (SSP).
- Selecting the initial baseline of security controls.
Correct answer: Continuously tracking changes to the system and assessing control effectiveness over time.
The 'Monitor' step is the final, ongoing phase of the RMF. Its purpose is to maintain security posture by continuously monitoring control implementation, assessing for changes, and understanding the ongoing risk to the system. This ensures that security remains effective throughout the system's lifecycle.
Question 27: What is the highest level of national security classification used in the United States?
- Sensitive Compartmented Information
- Confidential
- Top Secret (Correct answer)
- Secret
Correct answer: Top Secret
Top Secret is the highest of the three standard classification levels (Confidential, Secret, Top Secret) and is applied when unauthorized disclosure could cause exceptionally grave damage to national security.
Question 28: What type of container is required for storing Secret information?
- Any fire-rated office safe with a key-operated locking mechanism
- A standard locked metal filing cabinet in any government office area
- Any commercially available safe with a combination lock mechanism
- A GSA-approved security container meeting specific federal standards (Correct answer)
Correct answer: A GSA-approved security container meeting specific federal standards
Secret information must be stored in a GSA-approved security container (typically an SF-700 series safe) or in a vault or strong room that meets applicable federal standards.
Question 29: An organization is implementing a risk management program. After identifying potential threats and vulnerabilities, what is the logical next step in the risk management process?
- Conduct a risk analysis. (Correct answer)
- Monitor and review the risks.
- Implement security controls.
- Create an incident response plan.
Correct answer: Conduct a risk analysis.
The standard risk management process involves identifying assets, threats, and vulnerabilities, and then analyzing the risk. Risk analysis involves evaluating the likelihood of a threat exploiting a vulnerability and the potential impact it would have on the organization. This analysis is crucial before deciding which controls to implement.
Question 30: What is the primary purpose of a personnel security program?
- To ensure that only loyal, trustworthy, and reliable individuals are granted access to classified information or assigned to sensitive duties. (Correct answer)
- To prosecute individuals who have violated security protocols and regulations.
- To conduct lifestyle monitoring on all government employees to prevent potential security risks.
- To guarantee employment for individuals who pass a background investigation.
Correct answer: To ensure that only loyal, trustworthy, and reliable individuals are granted access to classified information or assigned to sensitive duties.
The fundamental purpose of a personnel security program (PSP) is to ascertain that individuals granted access to sensitive information or positions are loyal, trustworthy, and reliable, thereby protecting national security.
Question 31: What is the primary subject matter of Executive Order 13526?
- Personnel security investigation standards
- Physical security requirements for classified facilities
- Cybersecurity requirements for classified networks
- Classified national security information policy (Correct answer)
Correct answer: Classified national security information policy
EO 13526, signed in 2009, establishes U.S. government policy for classifying, safeguarding, and declassifying national security information, replacing EO 12958.
Question 32: What is the purpose of the personnel security program?
- To manage employee benefits and compensation
- To conduct performance evaluations
- To assess whether individuals can be trusted with access to classified information and sensitive positions (Correct answer)
- To manage employee scheduling
Correct answer: To assess whether individuals can be trusted with access to classified information and sensitive positions
The personnel security program assesses individuals' trustworthiness, reliability, and loyalty to determine whether they are suitable for access to classified information or sensitive positions.
Question 33: A small company has developed a new proprietary manufacturing process. They are concerned about competitors stealing their trade secrets. Which of the following is the BEST control to mitigate this risk?
- Implementing a firewall to block external network traffic.
- Installing antivirus software on all company computers.
- Requiring all employees with access to the process documents to sign non-disclosure agreements (NDAs). (Correct answer)
- Enforcing a strong password policy for all employees.
Correct answer: Requiring all employees with access to the process documents to sign non-disclosure agreements (NDAs).
While technical controls like firewalls and passwords are important, the most direct control to protect trade secrets from being shared by authorized individuals (insiders) is a legal control like a non-disclosure agreement (NDA). It legally binds employees to protect the company's confidential information.
Question 34: Which type of physical intrusion detection system (PIDS) sensor is specifically designed to detect an unauthorized entry through a door or window?
- A microwave sensor
- A magnetic contact switch (Correct answer)
- A passive infrared (PIR) sensor
- A glass-break detector
Correct answer: A magnetic contact switch
A magnetic contact switch consists of two parts: a magnet attached to a door or window and a switch on the frame. When the door or window is opened, the magnetic field is broken, which triggers the alarm. This makes it a direct detector of an opening, whereas other sensors detect motion (PIR, microwave) or the sound of breaking glass.
Question 35: Which of the following is NOT a category of Information Technology (IT)?
- Information Technology Applications (Correct answer)
- Information Technology Services
- Information Technology Products
- Platform Information Technology (PIT)
Correct answer: Information Technology Applications
While the phrase 'sole authority' is generally inaccurate in security policy, the markings on classified information are crucial for the document holder to understand the information's classification level, handling caveats, and dissemination restrictions. These markings guide the document holder in making responsible determinations regarding the information's transfer and dissemination, ensuring compliance with established security policies and need-to-know principles.
Question 36: What is the primary justification for establishing a Special Access Program (SAP)?
- The program's budget exceeds a specific monetary threshold as defined by Congress.
- The program requires security measures and access controls that exceed those normally required for information at the same classification level. (Correct answer)
- The information is classified as Top Secret and involves foreign governments.
- The program involves collaboration between the Department of Defense and the Department of Energy.
Correct answer: The program requires security measures and access controls that exceed those normally required for information at the same classification level.
A Special Access Program is established when it's determined that the normal safeguarding and access requirements for a given classification level (e.g., Confidential, Secret, or Top Secret) are insufficient to protect the information from exceptional threats or vulnerabilities. [4, 8, 13]
Question 37: What is the difference between 'eligibility' and 'access' in the personnel security context?
- Eligibility applies only to government employees; access applies to contractors
- There is no practical difference
- Access is more comprehensive than eligibility
- Eligibility is the determination that an individual meets security standards; access is the formal granting of permission to specific classified information based on need-to-know (Correct answer)
Correct answer: Eligibility is the determination that an individual meets security standards; access is the formal granting of permission to specific classified information based on need-to-know
Eligibility is the determination that a person meets security standards; access is the actual permission to view specific classified information, which also requires a need-to-know determination.
Question 38: What document serves as the primary regulatory guidance for the National Industrial Security Program?
- Executive Order 13526
- DoD Instruction 5200.01
- Federal Acquisition Regulation
- NISPOM (32 CFR Part 117) (Correct answer)
Correct answer: NISPOM (32 CFR Part 117)
The NISPOM (32 CFR Part 117) is the primary regulatory framework governing the safeguarding of classified information by contractors.
Question 39: What is the 'all-hazards' approach in emergency management?
- Addressing only hazardous material incidents
- Planning only for natural disasters
- Focusing exclusively on terrorism
- Preparing for a wide range of potential emergencies regardless of cause (Correct answer)
Correct answer: Preparing for a wide range of potential emergencies regardless of cause
The all-hazards approach prepares for any type of emergency or disaster, recognizing that many response activities are common regardless of the specific hazard.
Question 40: What is a 'perimeter intrusion detection system' (PIDS) used for?
- Providing lighting for nighttime operations
- Managing vehicle access credentials
- Detecting unauthorized intrusions along a facility's perimeter using sensors, cameras, and alarms (Correct answer)
- Monitoring employee attendance
Correct answer: Detecting unauthorized intrusions along a facility's perimeter using sensors, cameras, and alarms
A PIDS detects unauthorized access attempts along a facility's perimeter through various sensor technologies, triggering alerts that allow security personnel to respond.
Question 41: Under EO 13526, what is the standard maximum duration for most originally classified information before automatic declassification?
- 10 years
- 25 years (Correct answer)
- 50 years
- 75 years
Correct answer: 25 years
EO 13526 establishes 25 years as the standard maximum classification period, after which information must be automatically declassified unless a specific exemption applies.
Question 42: How must classified documents be physically transmitted between cleared contractor facilities?
- Via regular postal mail
- Through approved methods such as cleared commercial carrier, hand carrying by cleared personnel, or secure electronic transmission (Correct answer)
- Through any courier service
- Via email with encryption only
Correct answer: Through approved methods such as cleared commercial carrier, hand carrying by cleared personnel, or secure electronic transmission
Classified documents must be transmitted through approved methods to maintain control, including cleared commercial carriers, hand-carrying by authorized cleared personnel, or secure electronic systems.
Question 43: What is the purpose of 'security containers' (safes) in industrial security?
- To secure administrative records only
- To store personal items of value
- To store computer equipment
- To provide approved storage for classified materials, preventing unauthorized access (Correct answer)
Correct answer: To provide approved storage for classified materials, preventing unauthorized access
GSA-approved security containers provide the required level of protection for classified materials, preventing unauthorized access while materials are not in use.
Question 44: What action should employees take when they observe suspicious behavior by a colleague?
- Post about it on the company intranet
- Report the behavior through established reporting mechanisms to the insider threat program or security officer (Correct answer)
- Ignore it unless they are certain it is a security violation
- Confront the colleague directly
Correct answer: Report the behavior through established reporting mechanisms to the insider threat program or security officer
Employees should report suspicious behavior through established channels, such as the insider threat reporting hotline or directly to the security officer, rather than confronting the colleague.
Question 45: What is the 'whole person concept' in personnel security adjudication?
- Evaluating only the most recent behavior of an applicant
- Only evaluating criminal background
- Considering all available information about an individual's life, character, and circumstances to make a fair and accurate eligibility determination (Correct answer)
- Focusing exclusively on financial history
Correct answer: Considering all available information about an individual's life, character, and circumstances to make a fair and accurate eligibility determination
The whole person concept requires adjudicators to consider all available information about an individual — not just isolated incidents — to make a complete and accurate eligibility determination.
Question 46: If someone accidentally gave a foreign entity access to classified information, which guideline would it fall under?
- Use of Classified Systems
- Use of Information Technology Systems (Correct answer)
- Use of Unclassified Systems
- Use of Information DoD Systems
Correct answer: Use of Information Technology Systems
Common categories of Information Technology (IT) typically include Platform Information Technology (PIT), Information Technology Services, and Information Technology Products. While 'Information Technology Applications' are components that run on IT systems, they are generally considered a *type* of software or service rather than a distinct *category* of IT infrastructure itself.
Question 47: An adjudicator is reviewing a case file for a security clearance. The individual has a history of significant, unresolved debt but is also a highly decorated veteran with numerous commendations for their service. Which principle should the adjudicator apply to make a final eligibility determination?
- The Reciprocity Principle
- The Whole-Person Concept (Correct answer)
- The Least Privilege Principle
- The Need-to-Know Principle
Correct answer: The Whole-Person Concept
The 'Whole-Person Concept' requires adjudicators to carefully weigh all available information, both favorable and unfavorable, past and present, to make an overall common-sense judgment about an individual's reliability, trustworthiness, and loyalty. This includes considering mitigating factors alongside potentially disqualifying information.
Question 48: What is a 'T5' investigation and when is it used?
- A preliminary screening investigation
- A Tier 5 investigation, the most comprehensive federal background investigation, used for Top Secret/SCI access (Correct answer)
- A periodic reinvestigation for lower-level clearances
- A standard employment background check
Correct answer: A Tier 5 investigation, the most comprehensive federal background investigation, used for Top Secret/SCI access
A T5 (Tier 5) investigation is the most comprehensive federal background investigation, required for positions needing Top Secret access or access to Sensitive Compartmented Information.
Question 49: What is a classified 'working paper' as defined in information security handling guidelines?
- A classified document approved for wide distribution within an authorized agency
- A temporary access authorization form issued for new employees pending full clearance
- A document generated during preparation of a classified product, such as notes or drafts (Correct answer)
- An unclassified summary of a classified program authorized for public release
Correct answer: A document generated during preparation of a classified product, such as notes or drafts
Working papers are documents such as notes, drafts, and supporting materials created during the preparation of classified finished products, and they require the same protection as classified documents if they contain classified information.
Question 50: Which of the following is considered the FIRST step in the traditional five-step OPSEC process?
- Apply Countermeasures
- Analyze Threats
- Assess Risks
- Identify Critical Information (Correct answer)
Correct answer: Identify Critical Information
The foundational first step of the OPSEC process is to identify the critical information. An organization cannot protect its sensitive information if it does not first determine what information, if compromised, would cause the most harm to its mission or operations.
Question 51: What is the purpose of 'mantrap' or 'airlock' entry systems in physical security?
- To create a buffer zone that prevents tailgating by requiring each person to be authenticated before the inner door opens (Correct answer)
- To trap insects and pests
- To improve air circulation in secure facilities
- To store hazardous materials safely
Correct answer: To create a buffer zone that prevents tailgating by requiring each person to be authenticated before the inner door opens
A mantrap or airlock entry system prevents tailgating by requiring that one door fully close and authenticate before the next door opens, ensuring each person entering is individually verified.
Question 52: A system owner is preparing the key documentation for a new information system undergoing the RMF process. Which document provides a detailed overview of the security requirements and describes the specific controls in place or planned to meet those requirements?
- Authorization to Operate (ATO)
- Plan of Action and Milestones (POA&M)
- System Security Plan (SSP) (Correct answer)
- Security Assessment Report (SAR)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) is the formal document that provides a comprehensive overview of a system's security requirements and details the security controls implemented or planned to meet them. It is a foundational document in the authorization package.
Security Fundamentals Professional Certification (SFPC)
The SFPC exam validates foundational knowledge of DoD security disciplines including personnel security, information security, physical security, industrial security, and operations security.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds