Browse all practice questions for the DSAC Annex F Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

DSAC Annex F Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • What is a primary goal of cybersecurity?
  • Social Engineering is defined as:
  • What is the primary security benefit of data minimization?
  • Which item is NOT one of the three primary information security principles?
  • PKI is important because:
  • What is the Security Control Assessment and Authorization (A&A) process?
  • How should security roles and responsibilities be documented to satisfy Annex F requirements?
  • A Certificate Authority is:
  • Integrity is defined as which of the following?
  • Cybersecurity is important because it protects all categories of data from theft and damage.
  • Cybersecurity works by safeguarding against threats to protect computers, servers, mobile devices, electronic systems, networks, and data from malicious attacks.
  • What is the importance of tabletop exercises in security readiness under Annex F?
  • Which steps comprise a basic incident response lifecycle?
  • What does the monitoring and review phase entail in the risk management process?
  • Operations Security is best described as which of the following?
  • What is information security?
  • Which description best defines the security authorization boundary?
  • Critical Infrastructure security focuses on the physical and cyber systems that are vital to which country?
  • Automatic Key Recertification is best described as:
  • What does retention of audit logs 'per policy' imply?
  • What describes tamper-evident logging?
  • What is SIEM and what is its role in Annex F monitoring?
  • In addressing supply chain security risk, which practice is standard?
  • What order dictates the usage of HBSS within the DoD?
  • In Annex F, which function grants access permissions after identity is verified?
  • Which unit is responsible for executing DODIN and DCO operations?
  • What is Network security?
  • PKI consists of hardware, software, people, processes, and policies.
  • Which statement best describes defense in depth?
  • Which set represents the three primary information security principles as an acronym order?
  • In DSAC contexts, what does non-repudiation mean and how can it be achieved?
  • Cyber Threats are attack that are mounted against users or digital devices by means of cyberspace.
  • What technique specifically helps limit lateral movement by isolating workloads in zero-trust architecture?
  • Which of the following is listed as a countermeasure?
  • HBSS are a ______ measure hosted on an individual _____ designed to provide _____ security against cyber___.
  • Phishing is a form of social engineering where fraudulent email or text messages are sent randomly in order to steal sensitive data.
  • HIDS stands for which term?
  • Why is cybersecurity implemented by users and enterprises?
  • What is the primary responsibility of Information Security?
  • Which statement correctly describes the Quality Report Tool (QRT)?
  • Explain how to perform a basic security control mapping to NIST SP 800-53 controls in the context of DSAC Annex F.
  • Which statement describes a secure Software Development Life Cycle (SDLC)?
  • The statement “Security functions by pairing one public with another to authenticate users” is:
  • Another name for asymmetric-key cryptography is:
  • DDoS attacks are Attacks that utilize multiple systems to disrupt the traffic of a targeted systems by flooding the target with too much information in order to slow or crash the intended target(s).
  • HBSS stands for which term?
  • End User security is primarily concerned with protecting which of the following?
  • What is described as a top cybersecurity challenge?
  • Data Loss Prevention (DLP) focuses on preventing unauthorized access to sensitive data.
  • Which item is NOT listed as a major component of HBSS?
  • Which unit is staffed by government employees and contractors and mandates support and sustain the DoD Cyber Exchange?
  • Which statement best describes the four main access control models: DAC, MAC, RBAC, and ABAC?
  • Explain the principle of least privilege and why it is important in DSAC contexts.
  • Key History refers to:
  • Critical Infrastructure security refers to which of the following?
  • In an incident communications plan, what is a key objective?
  • What is a Host Intrusion Prevention System (HIPS)?
  • Why is cybersecurity important?
  • Which statement best describes defense in depth in the context of Annex F controls?
  • Which factor is cited as a top cybersecurity challenge in the material?
  • What is the primary objective of Advanced Persistent Threats (APTs) as described?
  • Which HBSS component provides a secure communication channel to the ePO and manages all of the other modules?
  • HIPS can be implemented on servers workstations and computers.
  • What is a security authorization boundary and why is it important?
  • Which statement describes a DDoS attack?
  • Which of the following is a countermeasure?
  • What is the difference between physical security controls and environmental controls?
  • The HBSS major components include five items. Which system uses these five items as major components?
  • How does Annex F define roles and responsibilities for security testing and evaluations?
  • HBSS major components are listed as which of the following?
  • Which of the following is NOT a listed benefit of cybersecurity?
  • Which statement describes audit log characteristics required under Annex F?
  • Which are key components of a System Security Plan (SSP) for Annex F?
  • Which item is NOT typically part of a System Security Plan (SSP)?
  • Why is data integrity critical in DSAC operations and how is it ensured under Annex F?
  • Which statement correctly describes encryption in transit and at rest?
  • What does cryptographic key lifecycle management include?
  • What does a Host-Based Intrusion Detection System (HIDS) do?
  • Malware is a program or file intentionally designed to be harmful to a computer, network or server, such as viruses, worms, Trojan horses, ransomware and spyware.
  • What is the concept of risk acceptance and risk transference as described in Annex F?
  • PIA in Annex F focuses on which of the following?
  • What is the purpose of privacy impact assessments (PIA) in Annex F?
  • What are countermeasures?
  • How does Annex F treat logging retention and secure storage?
  • The statement “PKI is commonly used to sign and/or encrypt data” is:
  • How should data retention and disposal be handled under Annex F?
  • SBOM stands for Software Bill of Materials. What is its primary purpose in supply chain security?
  • Virus Scan Enterprise (VSE) is an antivirus product that detects and protects computers from multiple types of digital threats.
  • Which of the following is a major component of HBSS?
  • MCCOG is the abbreviation for which unit?
  • Which is a major phase of a DSAC Annex F risk management process?
  • Which of the following is NOT a type of malware?
  • HBSS is designed to provide local security against cyber threats. Which option best represents this function?
  • What is the primary purpose of audit logs in Annex F?
  • Which statement best describes a SuperAgent's role?
  • Threat modeling is used to enhance security by which activity?
  • Which of the following is NOT listed as an element of cybersecurity?
  • Ransomware is a type of malware that involves an attacker locking the victim's computer system files until payment to decrypt and unlock them occurs.
  • HBSS is hosted on which of the following?
  • Which statement correctly differentiates preventive, detective, and corrective controls?
  • What is cybersecurity?
  • What is the role of management oversight in Annex F compliance?
  • What are common indicators of a security incident requiring escalation under Annex F?
  • Which of the following is a countermeasure related to access control?
  • Which description best defines a Certificate Repository?
  • SCAP files are generated in which format?
  • Which of the following is an element of cybersecurity?
  • In Annex F, which function verifies a user's identity?
  • Bulk Administration (BAT) is used for what aspect of IP phone management?
  • What is cryptographic key lifecycle management and why is it critical?
  • Which item is NOT listed as a PKI component in the description?
  • Insider threats are security breaches or losses caused by humans due to negligence.
  • Cybersecurity protects internet-connected systems from which of the following?
  • Which statement best describes the confidentiality aspect of the CIA triad?
  • Which statement best describes the purpose of a System Security Plan (SSP) in Annex F?
  • The technique that criminals use to attack users with targeted emails and fraudulent links is known as sphere fishing.
  • What is incident containment and which strategies help achieve it?
  • What term refers to the overall discipline that protects information assets, regardless of format or state?
  • What is a baseline configuration and why is it important in Annex F?
  • Which of the following is NOT listed as a method for IP phone configuration?
  • PKI is most commonly used for:
  • Which entity issues and signs digital certificates?
  • PII is commonly known as which of the following?
  • How should cryptographic algorithms be chosen and updated under Annex F?
  • Which statement about IP telephony authorization is correct?
  • What is the purpose of an incident communication plan?
  • What term describes voice features within IP technology such as voice calls and voicemail?
  • HBSS is a type of HIPS solution.
  • How do you perform a basic risk assessment using qualitative methods?
  • Which of the following describes Key Backup And Recovery?
  • What is the purpose of business continuity planning for ICT systems?
  • Describe the difference between vulnerability scanning and penetration testing.
  • Data Loss Prevention (DLP) is a set of tools and processes used to ensure that sensitive data is not lost, misused, or accessed by unauthorized users.
  • Which of the following is listed as a cybersecurity threat type in the material?
  • Physical security is defined as the protection of which elements from physical actions and events?
  • Digital certificates are typically issued and signed by:
  • What is the core principle of zero trust in DSAC Annex F?
  • Which approach is described as a way to enhance application security?
  • CTO is an acronym in DoD cyber policy. What does CTO stand for?
  • Spear Phishing targets a specific individual or organization.
  • HBSS is a type of HIPS solution.
  • Which tool is supported by Cisco Extended Functions Service?
  • Cyberspace is a virtual space that doesn't exist in physicality, but across servers, routers and switches.
  • Man-in-the-Middle (MitM) attacks are defined as:
  • What does HIDS do with detected intrusions?
  • What is Multi-Factor Authentication (MFA) and why is it recommended in Annex F guidelines?
  • What is a System Security Plan (SSP) and what Annex F requirements does it fulfill?
  • Which term describes measures that protect a computer network from intruders, including both wired and wireless connections?
  • Which statement best describes the principle of least privilege?
  • COOP vs DR: What is the relationship between continuity of operations and disaster recovery in Annex F?
  • What is data minimization and how is it applied in Annex F?
  • Spear Phishing is a type of attack that has an intended target user, organization or business.
  • What is the primary purpose of a risk treatment step?
  • PKI is a ________ that consists of hardware, _______, people, processes, and _______, that together helps identify and solve information security ____.
  • Why is time synchronization important for audit logs?
  • How is data typically managed under Annex F in terms classification and labeling?
  • Which of the following is NOT a recommended data disposal practice?
  • What does 'update path for deprecation' mean in cryptographic algorithm selection under Annex F?
  • In cloud deployments, which statement reflects the shared responsibility model?
  • The Security Center is:
  • End User security involves measures taken to protect which of the following?
  • In a qualitative risk assessment, which elements are typically identified to prioritize mitigations?
  • What does continuous verification imply in access control under Annex F?
  • Which access control model assigns permissions primarily by the owner?
  • Which of the following is NOT typically a phase in the DSAC Annex F risk management process?
  • Which of the following is a core component of a cryptographic key management lifecycle?
  • What is the overarching purpose of Annex F in DSAC practice exams?
  • PKI is described as a framework.
  • The primary purpose of PKI in IT is to establish trust by enabling:
  • Which term best describes voice communications over an IP network?
  • Which mechanism records user actions for auditing?
  • Describe RBAC and why it's preferred over DAC in DSAC contexts.
  • In multi-agent networks, what is a SuperAgent?
  • Advanced Persistent Threats (APTs) are best described as
  • How should patch management be implemented to align with Annex F?
  • Availability means that information is...
  • Which security domain focuses on protecting information and assets from physical actions and events?
  • What should the System Security Plan (SSP) include to satisfy Annex F requirements?
  • Key History functionality includes:
  • What is the difference between vulnerability assessment and threat model?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy