DOD Operations Security (OPSEC) 2 — Questions and Answers
Question 1: What is a 'vulnerability' in the context of the DOD OPSEC process?
- A software flaw in a classified information system
- A weakness that allows an adversary to collect critical information or prevent mission accomplishment (Correct answer)
- A personnel shortage that reduces unit combat effectiveness
- An unclassified document stored in a classified container
Correct answer: A weakness that allows an adversary to collect critical information or prevent mission accomplishment
An OPSEC vulnerability is a condition that allows an adversary to obtain critical information, exploit friendly activities, or compromise mission success.
Question 2: Which step of the OPSEC process involves weighing the potential impact of a loss of critical information against the cost of protective measures?
- Identify Critical Information
- Analyze Vulnerabilities
- Analyze Threats
- Assess Risk (Correct answer)
Correct answer: Assess Risk
Risk assessment compares the threat and vulnerability against the potential impact to determine the priority and cost-effectiveness of countermeasures.
Question 3: A unit publishes its training schedule on a public Facebook page. In OPSEC terms, this is an example of a(n):
- Authorized information release
- OPSEC indicator and potential vulnerability (Correct answer)
- Classified information spillage
- Required transparency measure under FOIA
Correct answer: OPSEC indicator and potential vulnerability
Posting operational schedules publicly creates observable indicators that adversaries can exploit to predict and counter unit activities.
Question 4: What does a Critical Information List (CIL) primarily help commanders do?
- Identify all personnel who require security clearances
- Focus OPSEC efforts by listing specific information that must be protected (Correct answer)
- Document security violations for disciplinary action
- Classify and mark all sensitive documents within a command
Correct answer: Focus OPSEC efforts by listing specific information that must be protected
A CIL focuses an organization's OPSEC efforts by specifically listing which information, if acquired by an adversary, would degrade mission success.
Question 5: In OPSEC, the term 'friendly force information requirements' (FFIR) refers to:
- Intelligence reports requested from allied nations
- Information the commander needs about friendly forces to plan and execute operations (Correct answer)
- Data submitted to OPSEC officers after mission completion
- Communications protocols between coalition partners
Correct answer: Information the commander needs about friendly forces to plan and execute operations
FFIR is information a commander needs about friendly forces, and it helps identify what an adversary would also want to know about those same forces.
Question 6: Which of the following best describes the relationship between OPSEC and classification?
- OPSEC only applies to classified information and systems
- OPSEC protects unclassified information that could be exploited when combined with other data (Correct answer)
- OPSEC and classification are the same process with different names
- Classification supersedes OPSEC in all cases where both apply
Correct answer: OPSEC protects unclassified information that could be exploited when combined with other data
OPSEC protects sensitive unclassified information that, when aggregated or combined, could reveal critical information to adversaries.
Question 7: What is 'aggregation' in the context of OPSEC?
- The process of consolidating classified documents into one secure location
- Combining multiple pieces of unclassified information to deduce sensitive or critical information (Correct answer)
- Grouping personnel by security clearance level for briefing purposes
- The collection of after-action reports from multiple operations
Correct answer: Combining multiple pieces of unclassified information to deduce sensitive or critical information
Aggregation occurs when individually harmless pieces of information are combined to reveal critical details that would otherwise remain protected.
What is a 'vulnerability' in the context of the DOD OPSEC process?