SFPC - Security Fundamentals Professional Special Access Program Basics Questions and Answers 1 — Questions and Answers
Question 1: What is the primary justification for establishing a Special Access Program (SAP)?
- The information is classified as Top Secret and involves foreign governments.
- The program requires security measures and access controls that exceed those normally required for information at the same classification level. (Correct answer)
- The program's budget exceeds a specific monetary threshold as defined by Congress.
- The program involves collaboration between the Department of Defense and the Department of Energy.
Correct answer: The program requires security measures and access controls that exceed those normally required for information at the same classification level.
A Special Access Program is established when it's determined that the normal safeguarding and access requirements for a given classification level (e.g., Confidential, Secret, or Top Secret) are insufficient to protect the information from exceptional threats or vulnerabilities. [4, 8, 13]
Question 2: An individual with a Top Secret clearance is assigned to a new project and is told they must be formally 'indoctrinated' before they can begin work. This process is a key indicator that the project is managed as what?
- A standard Sensitive Compartmented Information (SCI) program
- A Foreign Military Sales (FMS) case
- A Special Access Program (SAP) (Correct answer)
- A Research, Development, Test, and Evaluation (RDT&E) effort
Correct answer: A Special Access Program (SAP)
The term 'indoctrination,' often used interchangeably with being 'read-in,' is the formal process of granting an individual access to a specific Special Access Program after they have met all prerequisites, such as having the appropriate clearance and a validated need-to-know. [19]
Question 3: Which of the following are the three recognized categories of Special Access Programs within the Department of Defense?
- Acknowledged, Unacknowledged, and Waived
- Operational, Technological, and Strategic
- Counterintelligence, Counter-terrorism, and Counter-proliferation
- Acquisition, Intelligence, and Operations & Support (Correct answer)
Correct answer: Acquisition, Intelligence, and Operations & Support
DoD policy categorizes SAPs based on their primary function. The three categories are Acquisition (AQ) for sensitive research and development; Intelligence (IN) for sensitive intelligence operations; and Operations and Support (OS) for sensitive military activities. [2, 5]
Question 4: Who holds the ultimate authority within a U.S. government department to establish a new Special Access Program?
- The Program Security Officer (PSO)
- The Director of the Defense Counterintelligence and Security Agency (DCSA)
- The head of the department or agency (e.g., Secretary of Defense) (Correct answer)
- The Chairman of the Joint Chiefs of Staff
Correct answer: The head of the department or agency (e.g., Secretary of Defense)
The authority to create a SAP rests at the highest level of a department or agency. For example, the Secretary of Defense, Secretary of State, or the Director of National Intelligence (or their principal deputies) are the officials who can establish a SAP. [2, 6, 23]
Question 5: Which of the following are the two universal prerequisites for an individual to be considered for access to any Special Access Program?
- Possession of a Top Secret clearance and successful completion of a polygraph.
- U.S. citizenship and a minimum of 10 years of federal service.
- A validated need-to-know and the appropriate level of security clearance. (Correct answer)
- A technical degree and a favorable insider threat risk assessment.
Correct answer: A validated need-to-know and the appropriate level of security clearance.
Before any other requirements (like a polygraph, which is not required for all SAPs) are considered, an individual must have a favorably adjudicated security clearance at the level required by the program and a formally validated need-to-know the information to perform their duties. [9, 16]
Question 6: An employee working in a SAP discusses multiple unclassified details about their project's timeline and testing locations with a colleague who is not indoctrinated into the program. Why does this represent a significant security risk?
- This is a violation of the employee's signed Non-Disclosure Agreement (NDA).
- The aggregation of unclassified indicators could reveal sensitive or classified program information. (Correct answer)
- It demonstrates poor professional judgment and is grounds for a human resources complaint.
- The non-indoctrinated colleague is now considered an insider threat.
Correct answer: The aggregation of unclassified indicators could reveal sensitive or classified program information.
A core principle of protecting SAPs is Operations Security (OPSEC). Seemingly harmless, unclassified pieces of information (indicators) can be collected and pieced together by an adversary to reveal sensitive or even classified aspects of a program. This is known as aggregation or the mosaic effect. [4]
What is the primary justification for establishing a Special Access Program (SAP)?