DoD Cyber Awareness Challenge Practice Quiz & Test Questions

Take a free practice quiz or snap a photo of any Cyber Awareness Challenge question for an instant, explained answer — finish your annual training without getting stuck.

Try it freeFree forever · no card required
Cambo
QUESTION
Which of the following is a best practice for protecting Controlled Unclassified Information (CUI)?
Answer — Store CUI only on authorized systems and encrypt it both at rest and in transit — never email it to a personal account or save it to removable media that isn't approved.
How it works

Three steps, a few seconds each.

01
Snap a photo
Point your phone at the question — on a screen, a printout, anywhere.
02
Get the answer
Cambo reads the question and answers it in a few seconds.
03
See the explanation
Read the reasoning behind the answer so it actually sticks.

Looking for the official training, not practice questions? cyber.mil — Cyber Awareness Challenge ↗

Why it works

Built for exactly this kind of question.

The Cyber Awareness Challenge covers a lot of ground fast — phishing, PII handling, spillage, insider threat, removable media — and it's easy to blank on a specific rule mid-question. Cambo reads the exact question on your screen and gives you the right answer plus the reasoning, so you finish the module instead of rereading the same slide twice.

Practice quiz

Test yourself with real practice questions.

Which of the following is a best practice for protecting Controlled Unclassified Information (CUI)?

  1. AEmail it to your personal account so you can work on it from home
  2. BSave it to any removable media so that a backup always exists
  3. CStore it only on authorized systems and encrypt it both at rest and in transit
  4. DPost it to a shared team folder with open permissions for convenience
Tap the card to reveal the answer
Answer
CStore it only on authorized systems and encrypt it both at rest and in transit
Store CUI only on authorized systems and encrypt it both at rest and in transit — never email it to a personal account or save it to removable media that isn't approved.

You receive an email from an unfamiliar sender asking you to verify your CAC PIN by clicking a link. What should you do?

  1. AClick the link but enter only the first two digits of your PIN
  2. BReply to the sender and ask them to confirm their identity first
  3. CForward it to your team so they know to expect the same request
  4. DDon't click the link — report it as suspected phishing, since DoD systems never ask for your PIN through an email link
Tap the card to reveal the answer
Answer
DDon't click the link — report it as suspected phishing, since DoD systems never ask for your PIN through an email link
Don't click the link. Report it as suspected phishing — legitimate DoD systems never ask you to enter your PIN through an email link.

You suspect classified information may have been introduced onto an unclassified system (a "spillage"). What should you do first?

  1. AImmediately report it to your security manager or the appropriate incident response channel
  2. BDelete the files right away to contain the exposure
  3. CKeep working normally and raise it at the next staff meeting
  4. DCopy the files to removable media so they can be reviewed later
Tap the card to reveal the answer
Answer
AImmediately report it to your security manager or the appropriate incident response channel
Immediately report it to your security manager or the appropriate incident response channel. Don't try to delete the files or keep working on the system — that can destroy evidence needed to contain the spillage.

You find a USB drive in the parking lot labeled "Salary Info FY26." What should you do?

  1. APlug it into an isolated personal laptop to identify the owner
  2. BLeave it where you found it in case the owner comes back
  3. CTurn it in to your security office without plugging it into any device
  4. DPlug it into a government workstation so antivirus can scan it
Tap the card to reveal the answer
Answer
CTurn it in to your security office without plugging it into any device
Don't plug it into any government or personal device. Turn it in to your security office — unknown removable media is a classic malware vector, and curiosity-driven plugging-in is exactly what this scenario tests.

Which of the following is a potential insider threat indicator?

  1. AAn employee who occasionally takes leave on short notice
  2. BAn employee who prefers to work from a quiet part of the office
  3. CAn employee who frequently asks questions about other teams' projects
  4. DUnexplained affluence combined with unusual work hours or attempts to access information outside their need-to-know
Tap the card to reveal the answer
Answer
DUnexplained affluence combined with unusual work hours or attempts to access information outside their need-to-know
Unexplained affluence combined with unusual work hours or attempts to access information outside their need-to-know — behavioral and financial red flags, not just technical ones, are what the training emphasizes.

Which social media practice creates the greatest security risk?

  1. APosting details about upcoming deployments, unit movements, or specific mission information
  2. BFollowing official DoD accounts from a personal profile
  3. CUsing a profile photo that was taken while in uniform
  4. DConnecting with former colleagues from a previous duty station
Tap the card to reveal the answer
Answer
APosting details about upcoming deployments, unit movements, or specific mission information
Posting details about upcoming deployments, unit movements, or specific mission information. Even seemingly harmless posts can aggregate into an OPSEC risk when combined with other public information.

A person you don't recognize asks you to hold the secure door open because their badge isn't working. What should you do?

  1. AHold the door — badge readers malfunction frequently
  2. BHold the door if the person is wearing a visible ID badge
  3. CPolitely decline and direct them to the visitor center or security desk to be verified
  4. DLet them in and report it to security afterward
Tap the card to reveal the answer
Answer
CPolitely decline and direct them to the visitor center or security desk to be verified
Politely decline and direct them to the visitor center or security desk to be verified — this is "tailgating," and holding the door bypasses the access control the badge system exists to enforce.

What is the best way to protect against malicious code?

  1. ADisable antivirus scanning so it doesn't interfere with system updates
  2. BKeep antivirus software and system patches up to date, and avoid links or attachments from unverified senders
  3. COnly open attachments that are in PDF format
  4. DRely on the network firewall, which blocks all malicious code
Tap the card to reveal the answer
Answer
BKeep antivirus software and system patches up to date, and avoid links or attachments from unverified senders
Keep antivirus software and system patches up to date, and avoid clicking links or opening attachments from unverified senders — most malicious code enters through phishing or unpatched vulnerabilities.
1 / 8
2 / 8
3 / 8
4 / 8
5 / 8
6 / 8
7 / 8
8 / 8
FAQ

Questions, answered.

How long does the DoD Cyber Awareness Challenge take?

Most people finish in 60-90 minutes, depending on how many modules your service branch requires and how quickly you move through the knowledge checks.

Do I have to retake it every year?

Yes — it's an annual requirement for anyone with access to DoD networks or systems, including contractors and service members.

Can I use Cambo during the actual training?

Yes. Cambo works on any question you can photograph, including the ones inside the official training portal — point your camera at the question and get an explained answer in seconds.

Is Cambo affiliated with the DoD or the official Cyber Awareness Challenge?

No. Cambo is an independent study tool. It's not produced, endorsed, or affiliated with the Department of Defense.

What topics does the Cyber Awareness Challenge cover?

Phishing and social engineering, handling of PII/PHI and CUI, spillage, malicious code, removable media, social networking risks, insider threat indicators, and physical and facility security.

What happens if I fail a knowledge check?

Most versions let you review the material and retake the check — there's usually no limit on attempts, just a requirement to pass before you get your completion certificate.
Practice resources

Browse questions for a specific test or training.

Cambo works on any question you can photograph — here are the ones tutors and students search for most.