PII Training Quiz & Practice Questions

Take a free practice quiz or get instant, explained answers to Personally Identifiable Information (PII) training questions — identify what counts as PII and how to protect it, without the guesswork.

Try it freeFree forever · no card required
Cambo
QUESTION
Which of the following, standing alone, is generally considered PII?
Answer — A Social Security Number — it can identify a specific individual on its own, unlike a first name or job title alone.
How it works

Three steps, a few seconds each.

01
Snap a photo
Point your phone at the question — on a screen, a printout, anywhere.
02
Get the answer
Cambo reads the question and answers it in a few seconds.
03
See the explanation
Read the reasoning behind the answer so it actually sticks.

Looking for the official training, not practice questions? securityawareness.dcsa.mil — PII Training ↗

Why it works

Built for exactly this kind of question.

PII questions often hinge on whether a specific piece of information counts as PII on its own or only in combination with other data — a distinction that's easy to second-guess. Cambo reads the exact scenario and explains the reasoning, not just the answer.

Practice quiz

Test yourself with real practice questions.

Which of the following, standing alone, is generally considered PII?

  1. AA job title
  2. BA ZIP code
  3. CA Social Security Number
  4. DA company department name
Tap the card to reveal the answer
Answer
CA Social Security Number
A Social Security Number — it can identify a specific individual on its own, unlike a first name or job title alone.

What should you do if you discover a PII breach?

  1. AReport it immediately through your organization's established breach reporting procedure, often within one hour
  2. BWait until you can confirm how many records were affected
  3. CDelete the affected records to limit the exposure
  4. DNotify the affected individuals directly before telling anyone else
Tap the card to reveal the answer
Answer
AReport it immediately through your organization's established breach reporting procedure, often within one hour
Report it immediately through your organization's established breach reporting procedure — most policies require reporting within a strict time window, often one hour.

Is a person's job title alone generally considered PII?

  1. AYes — any workplace attribute is PII on its own
  2. BNo — a job title alone usually doesn't identify a specific individual; it becomes a concern combined with other identifying details
  3. CYes — but only for personnel in supervisory roles
  4. DNo — job titles are never a PII concern in any combination
Tap the card to reveal the answer
Answer
BNo — a job title alone usually doesn't identify a specific individual; it becomes a concern combined with other identifying details
No — a job title by itself usually doesn't identify a specific individual. It becomes a PII concern only when combined with other identifying details, like a full name.

What is the difference between PII and "sensitive PII"?

  1. ASensitive PII refers only to medical information; PII covers everything else
  2. BSensitive PII is stored electronically, while PII is kept on paper
  3. CSensitive PII is a subset that could cause substantial harm if exposed — such as an SSN, financial account number, or biometric data — and requires stricter safeguards
  4. DThere is no practical difference; the terms are used interchangeably
Tap the card to reveal the answer
Answer
CSensitive PII is a subset that could cause substantial harm if exposed — such as an SSN, financial account number, or biometric data — and requires stricter safeguards
Sensitive PII is a subset that could cause substantial harm if exposed — like an SSN, financial account number, or biometric data — and typically requires stricter safeguards than PII in general.

What is the general rule for emailing PII to a personal email account?

  1. AIt is permitted if the file is password protected
  2. BIt is permitted when working remotely
  3. CIt is permitted if the employee deletes the message afterward
  4. DIt is prohibited — PII must stay within authorized government or organizational systems
Tap the card to reveal the answer
Answer
DIt is prohibited — PII must stay within authorized government or organizational systems
It's prohibited — PII should stay within authorized government or organizational systems, and sending it to a personal account is one of the most common PII-handling violations covered in training.

Why does PII training cover disposal procedures, not just storage and transmission?

  1. ABecause improperly discarded documents and unwiped devices are a real source of breaches, so protection must cover the entire data lifecycle
  2. BBecause disposal is the only stage regulated by federal law
  3. CBecause retention schedules require destroying all records annually
  4. DBecause disposal costs are a significant part of most agency budgets
Tap the card to reveal the answer
Answer
ABecause improperly discarded documents and unwiped devices are a real source of breaches, so protection must cover the entire data lifecycle
Because improperly discarded documents or devices (like an unshredded printout or an unwiped hard drive) are a real-world source of PII breaches — protection has to extend through the entire data lifecycle.
1 / 6
2 / 6
3 / 6
4 / 6
5 / 6
6 / 6
FAQ

Questions, answered.

How often is PII training required?

Annually for most DoD and federal personnel with access to systems or records containing PII.

What's the difference between PII and PHI?

PII is any information that can identify a specific individual. PHI (Protected Health Information) is a subset of PII specifically tied to health records and covered under HIPAA.

Who needs PII training?

Anyone who collects, accesses, maintains, or disposes of records containing personally identifiable information as part of their job.

Is Cambo affiliated with the DoD or any official PII program?

No. Cambo is an independent study tool, not produced or endorsed by the Department of Defense.

What are examples of PII?

Full name combined with SSN, date of birth, driver's license number, financial account numbers, or biometric records — generally anything that can identify or be traced to a specific individual.

What happens if PII is mishandled?

Consequences range from required breach reporting and mitigation to disciplinary action, depending on the severity and whether the mishandling was negligent or intentional.
Practice resources

Browse questions for a specific test or training.

Cambo works on any question you can photograph — here are the ones tutors and students search for most.