OPSEC Training Quiz & Practice Questions

Take a free practice quiz or get instant, explained answers to OPSEC training questions — identify critical information, spot vulnerabilities, and finish your annual refresher without the guesswork.

Try it freeFree forever · no card required
Cambo
QUESTION
Which of the following is considered critical information under OPSEC?
Answer — Details that, if pieced together by an adversary, could reveal sensitive operations — for example, specific deployment dates, unit movements, or troop strength. General, publicly releasable information isn't critical information.
How it works

Three steps, a few seconds each.

01
Snap a photo
Point your phone at the question — on a screen, a printout, anywhere.
02
Get the answer
Cambo reads the question and answers it in a few seconds.
03
See the explanation
Read the reasoning behind the answer so it actually sticks.

Looking for the official training, not practice questions? cdse.edu — Operations Security ↗

Why it works

Built for exactly this kind of question.

OPSEC questions often hinge on judgment calls — is this detail critical information, is this a vulnerability, what's the right countermeasure — rather than pure recall. Cambo doesn't just give you an answer, it explains the reasoning so the training actually sticks instead of feeling like a box to check.

Practice quiz

Test yourself with real practice questions.

Which of the following is considered critical information under OPSEC?

  1. AAny information the unit has not yet published on its public website
  2. BDetails that, pieced together by an adversary, could reveal sensitive operations — such as deployment dates, unit movements, or troop strength
  3. CAll information marked Controlled Unclassified Information
  4. DPersonal contact details of unit members
Tap the card to reveal the answer
Answer
BDetails that, pieced together by an adversary, could reveal sensitive operations — such as deployment dates, unit movements, or troop strength
Details that, if pieced together by an adversary, could reveal sensitive operations — for example, specific deployment dates, unit movements, or troop strength. General, publicly releasable information isn't critical information.

A service member posts a photo on social media that includes a visible base identifier in the background. What OPSEC concern does this raise?

  1. ANo concern, since the photo contains no classified markings
  2. BA concern only if the post is set to public rather than friends-only
  3. CA potential indicator — a small detail that could help an adversary confirm location or activity when combined with other public information
  4. DA Privacy Act violation rather than an OPSEC issue
Tap the card to reveal the answer
Answer
CA potential indicator — a small detail that could help an adversary confirm location or activity when combined with other public information
It's a potential indicator — a small detail that seems harmless alone but could help an adversary confirm location or activity when combined with other public information.

What is a "countermeasure," in the OPSEC process?

  1. AA penalty imposed on personnel who disclose critical information
  2. BAn intelligence estimate of an adversary's likely next move
  3. CA formal request to declassify previously restricted information
  4. DAn action taken to eliminate an OPSEC vulnerability or reduce the risk of an adversary exploiting it
Tap the card to reveal the answer
Answer
DAn action taken to eliminate an OPSEC vulnerability or reduce the risk of an adversary exploiting it
An action taken to eliminate an OPSEC vulnerability or reduce the risk of an adversary exploiting it — such as limiting public discussion of an event's timing or restricting who has access to certain details.

Why does OPSEC training emphasize that "small" pieces of information can still be a risk?

  1. ABecause adversaries can aggregate multiple small, individually harmless details into a much larger picture
  2. BBecause small details are more likely to be classified than large ones
  3. CBecause reporting requirements apply only to minor disclosures
  4. DBecause small details are harder for friendly forces to track internally
Tap the card to reveal the answer
Answer
ABecause adversaries can aggregate multiple small, individually harmless details into a much larger picture
Because adversaries can piece together multiple small, individually harmless details into a much bigger picture — this is called "aggregation," and it's why OPSEC looks at cumulative risk, not just single facts.

Who is responsible for OPSEC within a unit or organization?

  1. AOnly the designated OPSEC officer or coordinator
  2. BEveryone — protecting critical information is every individual's responsibility, not just a specialist's
  3. COnly personnel holding a security clearance
  4. DOnly the unit commander and their immediate staff
Tap the card to reveal the answer
Answer
BEveryone — protecting critical information is every individual's responsibility, not just a specialist's
Everyone — while there's often a designated OPSEC officer or coordinator, protecting critical information is treated as every individual's responsibility, not just a specialist's job.

A spouse posts on social media about an upcoming "welcome home" event without specifying the date. Is this an OPSEC risk?

  1. ANo — without a specific date the post contains no useful information
  2. BNo — family members are not subject to OPSEC considerations
  3. CIt can be — vague timing hints combined with other public posts can help someone estimate deployment or return schedules
  4. DOnly if the post names the unit involved
Tap the card to reveal the answer
Answer
CIt can be — vague timing hints combined with other public posts can help someone estimate deployment or return schedules
It can be — even vague timing hints, combined with other public posts, can help someone estimate deployment or return schedules, which is why discretion matters even with indirect details.
1 / 6
2 / 6
3 / 6
4 / 6
5 / 6
6 / 6
FAQ

Questions, answered.

What does OPSEC stand for?

Operations Security — the process of identifying and protecting critical information that could be used against an organization or mission if it fell into the wrong hands.

Who has to complete OPSEC training?

Typically required annually for military service members, DoD civilians, and contractors, though specific requirements vary by command and role.

What are the five steps of the OPSEC process?

Identify critical information, analyze threats, analyze vulnerabilities, assess risk, and apply countermeasures.

Is Cambo affiliated with the DoD or any official OPSEC program?

No. Cambo is an independent study tool, not produced or endorsed by the Department of Defense.

How is OPSEC different from the Cyber Awareness Challenge?

Cyber Awareness focuses mainly on digital and cybersecurity risks like phishing and PII handling. OPSEC is broader — it covers protecting any critical information, digital or otherwise, from being pieced together by an adversary.

What's an OPSEC indicator?

A piece of information or behavior that, on its own or combined with others, could reveal something an adversary shouldn't know — like a pattern of activity, a visible location marker, or a schedule detail.
Practice resources

Browse questions for a specific test or training.

Cambo works on any question you can photograph — here are the ones tutors and students search for most.