Browse all practice questions for the DOD Instruction 5200.48 Controlled Unclassified Information (CUI) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

DOD Instruction 5200.48 Controlled Unclassified Information (CUI) Practice Exam course image
All questions

These questions are part of the practice quiz. Start practicing

  • What steps are taken during personnel turnover or departure to protect CUI?
  • What is the policy on using unofficial or personal email for official business involving CUI?
  • What is the main purpose of verification steps before sharing CUI?
  • Which roles are primarily responsible for CUI oversight?
  • Where can readers access the official list of DoD CUI indexes and categories?
  • What is the purpose of maintaining CUI training records?
  • What step is essential before disposing of removable media containing CUI?
  • Is there a specific timeline to decontrol CUI?
  • Do derivative documents shared outside DoD need to be marked if the information qualifies as CUI?
  • During initial phased implementation, how is DoD information protected regarding Basic vs Specified?
  • Which activities are included in the CUI lifecycle as standardized by DoDI 5200.48?
  • Under what conditions can CUI be shared with foreign nationals?
  • What happens if CUI is disclosed in a FOIA request?
  • What constitutes proper labeling for CUI in a physical environment?
  • CUI cannot be designated to do which of the following?
  • What is the purpose of the DoD CUI Registry?
  • Which topics should CUI personnel training cover?
  • Which statement best characterizes CUI within the DoD context?
  • Which framework serves as the baseline for protecting CDI where applicable?
  • If a CUI incident or breach occurs, what action is required?
  • Flow-down safeguarding requirements to subcontractors: what does it entail?
  • Which domains are addressed in safeguarding CUI protections?
  • How is CUI defined relative to classification levels?
  • When must DoD CUI be controlled?
  • What is the concept of 'need to know' when several agencies share CUI?
  • Which item is NOT listed as a CUI compliance document?
  • What are potential consequences for noncompliance with CUI policies?
  • How does CUI Specified differ from CUI Basic?
  • What does 'dissemination controls' mean in CUI handling?
  • What confidentiality impact level applies to DoD systems processing, storing, or transmitting CUI?
  • How is CUI defined in DoDI 5200.48?
  • Where are DoD CUI registry categories accessible?
  • What determines whether legacy information meets CUI requirements?
  • How is CUI defined in the general sense?
  • When data containing CUI is shared with external collaborators, which document is required to specify protection against CUI?
  • If a new document is created from legacy material and the information qualifies as CUI, what must be done with the new document?
  • What is the high-level message about information sharing versus controls in the CUI program?
  • Which statement best describes external recipients' agreements before receiving CUI?
  • What is "REL TO" used for (in this instruction's context)?
  • How should training records for CUI awareness be maintained?
  • Does legacy information automatically become CUI?
  • What is the minimum 'Controlled by' information needed on the CUI designation indicator?
  • Which statement best describes how CUI is identified in a classified document?
  • What is the primary purpose of DoD Instruction 5200.48?
  • What must happen before CUI is approved for public release (including posting to a public website)?
  • What is the primary purpose of DoDI 5200.48?
  • Does CUI generally require 'need-to-know' like classified information?
  • Which statement best defines need-to-know in the context of CUI sharing?
  • Which document does DoDI 5200.48 cancel or replace?
  • Which core access principle restricts who may view CUI?
  • What is required for retention of CUI records?
  • Which backup practice best ensures continued protection of CUI during storage?
  • Is the DoD CUI Registry aligned with DoD issuances?
  • The second line of the designation indicator must identify?
  • How should backups and snapshots containing CUI be handled?
  • How should CUI be transmitted electronically?
  • What does “flow-down” mean in CUI contracts?
  • Which marking indicates export control/licensing requirements exist for a foreign release?
  • Under what circumstance is a preliminary inquiry appropriate in response to a CUI incident?
  • Which elements are required for accreditation and authorization to operate (ATO) for CUI-storing systems?
  • When a CUI container is lost, who should be notified immediately?
  • What training is required for personnel handling CUI?
  • How should CUI be protected during electronic transmission?
  • How should CUI be managed in email communications?
  • What documentation is required for CUI training records?
  • If a paragraph contains only CUI content, how should that paragraph be marked?
  • What is the key driver for the DoD CUI Program in this instruction?
  • How should CUI be managed in cloud computing environments?
  • What is the role of risk assessment in CUI protection?
  • How should backups containing CUI be safeguarded?
  • Who shares duties for establishing and maintaining the CUI program besides the senior DoD official?
  • Under what conditions may CUI be stored on personal devices?
  • If a DoD Component uses a standard letterhead or origination indicator, which element of the designation indicator may be omitted?
  • What training is required for personnel who handle CUI?
  • What verification steps confirm a recipient's need-to-know before sharing CUI?
  • What penalties or sanctions exist for failing to protect CUI?
  • Which statement best describes the flow-down obligations in data-sharing agreements for CUI?
  • Which core component focuses on reporting security incidents involving CUI?
  • What must the designation banner and category/handling markings convey on a CUI document?
  • The fourth line must contain?
  • When should CUI be decontrolled?
  • Where should safeguards for an electronic CUI file be reflected?
  • Do legacy markings have to be redacted or re-marked as CUI?
  • What are general physical storage requirements for CUI?
  • How should a DoD electronic file containing CUI be marked?
  • How is CUI incident response integrated with the broader incident handling process?
  • Who determines whether an individual has an authorized government purpose to access CUI?
  • Which registry is established by DoDI 5200.48?
  • Which line contains the distribution statement or dissemination controls?
  • What does “decontrol” of CUI mean?
  • Which elements best describe access control for CUI in information systems?
  • How does CUI relate to FOIA?
  • Which action reflects the governance approach to dissemination and decontrol of CUI?
  • What is the purpose of inventories of CUI holdings?
  • What is the role of the Information System Security Officer (ISSO) in CUI?
  • The third line must identify?
  • How is CUI marked in classified documents?
  • Which documents demonstrate CUI compliance?
  • DoDI 5200.48 policies apply to CUI within which organization?
  • What kinds of information may get NOFORN/NF applied (examples listed)?
  • To whom should a CUI incident be reported?
  • Which is an allowed exception to using unofficial email for official CUI business?
  • Which statement best describes mobile device protection for CUI?
  • How soon must a CUI incident be reported after discovery?
  • Which item best illustrates a CUI compliance documentation element?
  • In CUI, what do Basic and Specified refer to?
  • How should CUI be disposed of when no longer needed?
  • Who is responsible for implementing policy, providing guidance, and ensuring oversight of the CUI program?
  • How should CUI be handled in email?
  • How should CUI be stored in DoD information systems?
  • Where on a paper CUI document should the designation, category, and dissemination restrictions be displayed?
  • Which elements must a DoD contract require for CUI protection?
  • Which action should be taken to handle a suspected CUI mishandling incident?
  • The fifth line must contain?
  • Within a CUI document, what portion marking is required for unclassified information?
  • CUI handling must be guided by which authorities?
  • Which statement best describes required training refreshers for CUI handling personnel?
  • What does CUI stand for in this context?
  • What is the primary purpose of inventories including access details?
  • How does DoD 5200.48 align with NIST or other standards?
  • How should CUI be destroyed?
  • What is the CUI Registry and its purpose?
  • Which element constitutes the CUI designation indicator on documents?
  • Which statement describes the purpose of the REL TO marking?
  • How does DoD Instruction 5200.48 relate to contractor systems and NIST SP 800-171?
  • Which core protection principle restricts how much access is granted to CUI?
  • What is the minimum security level referenced for DoD CUI systems and networks?
  • What are the requirements for remote access to CUI systems?
  • What is NOFORN/NF in this instruction's context?
  • What marking is required on each page of CUI documents?
  • When can CUI be disseminated within DoD and to contractors/consultants/grantees?
  • What action is required if a CUI container is lost or stolen?
  • What is the instruction's stance on unauthorized disclosure investigations for CUI?
  • When can CUI be disseminated to a foreign recipient?
  • What must accompany any sharing of CUI with contractors to ensure protection?
  • What is the purpose of CUI marking and labeling within handling processes?
  • What is the role of the CUI Policy Official or CUI Program Manager in a DoD component?
  • What are the two main designations used for CUI in DoDI 5200.48?
  • How does export control relate to CUI?
  • What is the primary purpose of CUI media sanitization?
  • Which statement describes Basic vs Specified handling during initial phased implementation?
  • What are the dissemination controls for CUI?
  • Who decontrols and releases CUI records (general rule in the instruction)?
  • What must DoD Component heads ensure regarding CUI training?
  • How should hotlines or reporting channels be used for CUI concerns?
  • When data contains both CUI and classified information, which safeguarding approach is recommended?
  • What notification is required for systems that contain CUI?
  • Which of the following statements correctly reflects the required confidentiality level for DoD CUI systems?
  • How often is CUI awareness training typically refreshed?
  • Which statement best describes the relationship between CUI and restricted data in an unclassified document?
  • When non-federal systems handle CUI under a contract, which security guideline is referenced?
  • Which statement about training measurement is supported by the material?
  • Which practice is not a standard component of contractor safeguarding when handling CUI?
  • Are DoD contractors required to protect CUI?
  • What must happen before marking unclassified intelligence CUI as NOFORN/NF?
  • Future guidance will address which aspects?
  • Do you have to put "U" in the banner/footer like the old "U//FOUO" format?
  • How should training and awareness be measured?
  • How should restricted data or formerly restricted data be treated when it appears in an unclassified document alongside CUI?
  • Which statement best describes CUI decontrol timing across the DoD?
  • Which elements are required when handling CUI by contractors?
  • Which statement best describes encryption requirements for CUI in transit and at rest?
  • How should CUI be marked on hard copy documents?
  • What is the purpose of reporting to leadership within a CUI program?
  • Which role is identified as part of CUI oversight?
  • DoD 5200.48 alignment with export-control?
  • If portion markings are used, how are portions containing CUI marked?
  • What is an example of CUI needing 'need-to-know'?
  • What marks should appear on CUI documents?
  • What are the two main CUI categories used under the policy?
  • What must be ensured before sharing CUI with contractors or external partners?
  • What are the main safeguarding controls in DoD 5200.48?
  • What is the difference between marking and labeling in the CUI context?
  • Hard copy CUI markings should include CUI and which additional information?
  • How should a CUI paper document be marked?
  • What is the role of the CUI Policy Official in enforcement across a DoD component?
  • Does the policy scope include contractor personnel who handle CUI?
  • Which of the following describes appropriate destruction methods for CUI?
  • Who is responsible for applying CUI markings and dissemination instructions?
  • How should CUI be treated when stored or processed outside DoD networks?
  • What is the role of ongoing risk management in CUI-storing systems?
  • How should removable media containing CUI be controlled?
  • Before disclosing CUI to another party, what must you verify?
  • How is access to CUI controlled in information systems?
  • What is the role of a CUI program manager or designated official?
  • Which statement best describes the difference between dissemination and disclosure of CUI?
  • How should mixed data containing CUI and classified information be handled?
  • What is the difference between "public release" and "authorized release" of CUI?
  • NOFORN/NF marking is applicable to which of the following information types?
  • What is the process for reporting potential noncompliance with CUI policy?
  • How should leadership reporting support governance in a CUI program?
  • Which statement describes what CUI refers to?
  • Which statement best describes the DoD CUI program's stance on information sharing and safeguarding?
  • Which approach is recommended when data contains both CUI and classified information regarding safeguarding and labeling?
  • What is a key inclusion of safeguarding controls in DoD 5200.48 beyond physical and technical measures?
  • How should portable media containing CUI be safeguarded?
  • The DoD CUI program standardizes processes per which framework?
  • Are DoD Components required to label CUI as 'Basic' or 'Specified' right now (per initial phased implementation)?
  • A CUI incident is defined as what?
  • What are the destruction requirements for CUI?
  • What is the scope of DoD Instruction 5200.48?
  • Which elements must be included in CUI labeling to ensure proper handling?
  • What level of safeguards must DoD Components apply at minimum?
  • On CUI documents, what information should accompany the designation?
  • Does CUI include information that is lawfully and publicly available without restrictions?
  • Are encryption requirements applicable to CUI at rest and in transit?
  • What information should a CUI marking include to indicate dissemination restrictions?
  • How should data-sharing agreements be used for CUI?
  • What is the difference between 'FOUO' and 'CUI' labeling?
  • How can compliance with the CUI program be verified?
  • Which item is explicitly part of the minimum CUI training standards?
  • What is decontrol of CUI?
  • What is the purpose of the splash screen for systems containing CUI?
  • Who has overall responsibility for establishing and maintaining a CUI program per DoD 5200.48?
  • What does the instruction say about future guidance on Basic vs Specified?
  • Which option best describes the content of the CUI designation banner related to dissemination restrictions?
  • How does DoD 5200.48 define CUI?
  • How should CUI containing PII be safeguarded?
  • Before accessing CUI, what must be determined?
  • How does DoD Instruction 5200.48 support governance of CUI across the DoD?
  • For unclassified material within a CUI document, which marking designates its status?
  • Who has the authority to designate CUI within a DoD program?
  • If a CUI misuse occurs and no disciplinary action is pursued, what type of inquiry is required?
  • What process governs the release of CUI records when a public disclosure is requested?
  • What additional step is used to alert readers to CUI inside a classified multi-page document?
  • What is the primary purpose of DoD Instruction 5200.48 regarding CUI within the DoD?
  • Who is responsible for determining at time of creation whether info falls into a CUI category?
  • Under DoD public release processes, when is DoD CUI considered controlled?
  • Which statement best describes the use of cross-domain solutions for CUI?
  • After CUI misuse or incidents that risk unauthorized disclosure, what is the primary focus?
  • What are the core components of an effective CUI program?
  • What practice helps prevent reconstruction of disposed CUI?
  • What is involved in CUI media sanitization?
  • If you create a new document from legacy material, what happens if the info qualifies as CUI?
  • Which items must be included (at minimum) in CUI training standards?
  • What is the purpose of a System Security Plan (SSP) in CUI handling?
  • Do legacy marked documents stored on a DoD access-controlled website need to be re-marked as CUI?
  • What is the minimum marking for unclassified DoD documents containing CUI?
  • What marking elements must appear on CUI documents?
  • What is the 'need to know' principle in CUI handling?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy