All questions

AFSC Cyberspace Operations Officer (17D) Block 5 Practice Exam

Browse all practice questions for the AFSC Cyberspace Operations Officer (17D) Block 5 Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

AFSC Cyberspace Operations Officer (17D) Block 5 Practice Exam course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which of the following is NOT a typical phase in the cyber kill chain?
  • What is a Joint Inspection (JI)?
  • What are the steps to perform a basic cyber risk assessment for a new mission system?
  • Which functional area is A3?
  • Which statement best describes the time-based data included in the TPFDD?
  • During redeployment, which statement best describes a key factor in readiness?
  • What's UTC tailoring?
  • RLD stands for what in the deployment context?
  • What's a packing list?
  • What are the five time-based data elements in the TPFDD?
  • What does LAD stand for in the deployment context?
  • Which order allocates cargo/PAX aircraft for movement based on DoD priorities?
  • In deployment planning, what does POD stand for?
  • What documentation is required for general cargo?
  • What is forensics readiness and why is it important in cyber incident response?
  • Who uses LOGMOD?
  • In cyber workforce roles, what best differentiates blue team and red team?
  • Describe the COMSEC Responsible Officer (CRO) of the COMSEC program.
  • Which statement best describes planning level 1 (CC's Estimate)?
  • Which brief provides an updated threat assessment, and which office delivers it?
  • Explain 'defense-in-depth' in cyberspace and give an example.
  • Which action is included in the Execute stage of PBED?
  • Which statement best contrasts symmetric and asymmetric cryptography and cites a representative use case?
  • Describe the Secure Voice Responsible Officer (SVRO) of the COMSEC program.
  • In a redeployment, which term best describes the steps taken to finalize personnel and equipment movement out of the unit?
  • What can your unit do if you cannot meet the tasking requirement?
  • What is the purpose of cross-domain data sharing controls, and name one risk if misconfigured?
  • What is MITRE ATT&CK for ICS and why is it relevant to 17D?
  • What is the primary purpose of analyzing an indicator of compromise (IOC)?
  • What is the classification level of Controlled Cryptographic Items (CCI)?
  • What steps are required for equipment handover?
  • Which statement best defines a packing list?
  • In cyberspace operations, what is an indicator of compromise (IOC) and how is it used?
  • Which of the following is NOT a primary phase of the Joint Planning Process (JPP) as applied to cyber operations?
  • Which option is best describes how to return equipment from a deployment?
  • What is a 'cyberspace domain commander' and how do they integrate with air or space operation centers?
  • During a TLS handshake, which sequence establishes a secure session?
  • Which action is included in the Debrief stage of PBED?
  • What is the purpose of a topographical map?
  • Describe the COMSEC Courier of the COMSEC program.
  • Which option correctly lists the levels of authority for the COMSEC program?
  • Who does IDO oversee management and control of?
  • What are the primary steps in cyber risk management for an enterprise network?
  • Name a common cyber threat actor and a typical tactic they employ.
  • Which functional area is A6?
  • What is the classification level of deployment TPFDD?
  • In a basic cyber risk assessment, which element is typically estimated to determine risk?
  • Explain the concept of cyber hygiene and name three practices for operators.
  • Data Loss Prevention (DLP) is best described as which?
  • Which actions are taken upon receipt of a warning order (WARNORD)?
  • Which statement describes planning level 4 - Operation Plans (OPLANs)?
  • What documentation is required for sensitive non-hazardous cargo?
  • Which functional area is A4?
  • Which functional area is A10?
  • Which coordinate systems are you likely to encounter/use?
  • LAD represents which concept?
  • What does ICAM stand for and what is its primary function in cyberspace operations?
  • Which statement best describes the difference between Defensive Cyberspace Operations (DCO) and Offensive Cyberspace Operations (OCO) in terms of objectives and authorization?
  • Which functional area is A5?
  • During redeployment, which statement about accountability is correct?
  • What is a primary objective of the CDM program in the U.S. government?
  • Which functional area is A2? (alternate wording)
  • Which functional area is A8? (alternate wording)
  • Identify three relevant offices/positions concerning readiness and deployments.
  • Who coordinates air travel for deployments? What about for exercises?
  • What best describes the purpose of an after-action report?
  • In coordinates such as 315000e 3365000n, what do the suffixes e and n denote?
  • What is the role of a Cyberspace Operations Officer in the Air Tasking Order (ATO) process?
  • What are the main components of a cyber incident playbook?
  • Which are the NIST SP 800-53 control families cited as examples under Security and Privacy Controls?
  • Which events are logged by the Master Station Log?
  • Which statement best defines threat modeling in the context of cyberspace operations?
  • Which documents are required for general cargo?
  • Which step is part of the equipment handover process?
  • Which of the following is not typically included in post-deployment actions?
  • Which term best defines the process of identifying assets and threats as the first step in cyber risk management?
  • Which statement best describes the MITRE ATT&CK framework?
  • What is a Project Letter of Agreement (PLA)?
  • Which is included in the Joint Inspection purpose?
  • Why is equipment handover important?
  • Which practice helps verify that a software component originated from a trusted source and was not altered?
  • Describe the UDM.
  • Which document area would you reference to verify if a site has power availability and on-site security?
  • ALD stands for what in the deployment context?
  • Identify methods of tracking and reporting deployment status updates.
  • Data Loss Prevention (DLP) techniques are typically applied to which areas?
  • Which term refers to protecting data, systems, and information by ensuring the CIA triad?
  • Which action adjusts a UTC for a deployment?
  • In the COA analysis phase, what is the purpose of war gaming?
  • LOGMOD report types — which option lists a valid set of report types LOGMOD can generate?
  • Which statement best describes a key factor in redeployment readiness?
  • In the Air Force, IA stands for Information Assurance; what does it protect?
  • What is a cyber tabletop exercise and its value?
  • Which information should be included in a site survey report?
  • R&R stands for which of the following?
  • Which of the following best describes when offensive cyber operations may be authorized?
  • Which documents are required for sensitive non-hazardous cargo beyond the base three?
  • Which statement describes planning level 3 - Concept Plans (CONPLANs)?
  • Which unit is responsible for overseeing deployment readiness and training for deployable personnel and/or cargo within their unit?
  • What pallet type is the mandatory standard shipping platform for developing UTCs?
  • When should the after-action report be completed?
  • ALD is defined as which description?
  • How many copies of the load list are required?
  • What is a Project Support Agreement (PSA)?
  • What is 'log correlation' and why is it important in detecting cyber incidents?
  • Which practice best supports mission assurance in cyberspace?
  • What is a network tap and why would a CyOps Officer deploy it in a defense-in-depth strategy?
  • What is the role of situational awareness in cyberspace operations?
  • Which sequence describes the typical hardening of a Windows workstation in a DCO context?
  • During redeployment, what is the team lead primarily accountable for?
  • What is a Master Station Log, and what is its purpose?
  • Which of the following lists the stages of PBED?
  • Which actions are taken upon receipt of an ALERTORD?
  • Which of the following is NOT one of the six steps in the Risk Management Framework (RMF) used to manage cyber risk for information systems?
  • Which form is added specifically for hazardous non-sensitive cargo?
  • How does a PLA differ from a PSA?
  • Which statement correctly differentiates cyber threat intelligence (CTI) from broader cyber intelligence (CI) as used in operations?
  • What is the primary purpose of the Cyberspace Operations Planning and Execution process in Air Force and joint operations?
  • What is the integrated cyber ecosystem doctrine and why is it important for 17D?
  • Which action is included in the Brief stage of PBED?
  • Which statement best describes the COMSEC User/Custodian role?
  • Which option NOT part of the formal levels of COMSEC program authority?
  • Explain the concept of 'Rules of Engagement' in cyber operations and provide a basic example.
  • Explain key OPSEC considerations for military cyber operations.
  • What describes the commander of the COMSEC program?
  • Which action is included in the Plan stage of PBED?
  • What is a SIEM and how is it used in a cyberspace operations environment?
  • Which planning level includes a Time-Phased Force and Deployment Data (TPFDD)?
  • Which reports can LOGMOD generate?
  • In RMF, which step involves implementing the security controls selected for the information system?
  • Which functional area is A8?
  • Which statement describes the malware threat landscape and defense risk balance?
  • What does planning level 2 Base Plans (BPLANs) describe?
  • What are the minimum items required to build a pallet for deployment?
  • Which sequence lists typical phases of patch management cycle?
  • PBED stands for?
  • What best describes a cyber tabletop exercise?
  • Which functional area is A3? (alternate wording)
  • Describe the COMSEC User/Custodian of the COMSEC program.
  • Latitude North of the Equator can be written in which of the following ways?
  • Which statement best describes the purpose of an after-action report?
  • Which statement correctly describes the packing list item detail?
  • What are some of the events logged by the Master Station Log?
  • Which document establishes the requirement for COMSEC material?
  • Which functional area is A1?
  • What are the time requirements for assigning a name to a deployment tasking?
  • RLD is defined as which description?
  • Which component is the focal point for deployment and execution operations?
  • Which functional area is A4? (alternate wording)
  • Which DATUM do we use?
  • What does the acronym RDD stand for in required delivery terminology?
  • Describe the IDRC.
  • Which action best describes returning equipment from an exercise?
  • Who acts as the CC's point of contact?
  • What is LOGMOD used for?
  • Which functional area is A7?
  • Which option represents NOT typically considered a cyber threat actor?
  • What is an 'attack surface' and name two methods to reduce it in an enterprise network?
  • Which coordinate system are these coordinates pertaining to? 16R 315000e 3365000n
  • What documentation is required for hazardous(sensitive) cargo?
  • Which functional area is A9?
  • Which datum is commonly used for GPS maps?
  • Which description correctly defines the COMSEC Courier?
  • Which planning level corresponds to Concept Plans (CONPLANs)?
  • Which statement best describes blue team role in cyber workforce?
  • Who in the COMSEC program is responsible for creating SOPs and COMSEC training?
  • What does the '16R' designation indicate in a coordinate reference?
  • Which statement about the 463L pallet is true?
  • EAD stands for what in the deployment context?
  • Which statement best describes the Master Station Log?
  • What are the PBED stages?
  • How would you return equipment from a deployment?
  • What does the 'Stow & Go' plan relate to in the COMSEC program?
  • Which of the following lists the six physical infrastructure concerns mentioned?
  • Which of the following is a typical component of an after-action report?
  • In the Joint Planning Process, what is the purpose of Plan/Order development?
  • What distinguishes a supply chain compromise from a direct network intrusion, and name one mitigation?
  • What is Continuous Diagnostics and Mitigation (CDM) and its role in U.S. government cyber defense?
  • Which action best aligns with post-deployment recognition?
  • How many copies of the packing list are required?
  • Which statement accurately describes governance for DCO and OCO in terms of authorization?
  • Which of the following best describes actions to take post-deployment?
  • Why are Joint Inspections (JI) performed?
  • Which components are typically included in post-incident activities within a playbook?
  • Which statement best describes resilience in a cyber system?
  • The coordinates '16R CJ 15000 65000' pertain to which coordinate system?
  • Describe the concept of resilience in cyberspace operations and give one example of a resilience capability.
  • Which statement best defines a TPFDD (Time Phased Force and Deployment Data)?
  • Describe the IDO function.
  • Which function best describes the role of SIEM in real-time cyber defense?
  • What is a log retention policy and why is it critical for incident detection and forensics?
  • What actions are taken upon receipt of an EXORD?
  • What must not be changed about the UTC?
  • Which of the following is a correct set of tools used to track deployment status updates (MSL, COMSTAT, COMSPOT)?
  • What do the 'e' and 'n' suffixes in coordinate notation indicate?
  • In deployment planning, what does POE stand for?
  • What documentation is required for hazardous non-sensitive cargo?
  • In the cyber kill chain model, which of the following is NOT a typical phase?
  • Which measures protect against unauthorized access to network devices and services?
  • What does MGRS stand for?
  • Define DATUM, as it pertains to maps.
  • What is data integrity and why is it critical in cyberspace operations? Provide one common method to ensure it.
  • Defensive Cyberspace Operations (DCO) is comprised of four primary activities. Which of the following lists those activities?
  • In patch management, which phase involves testing patches in a controlled environment before deployment?
  • Which functional area is A10? (alternate wording)
  • Which statement best describes the IDRC's role in deployment operations?
  • Which NIST SP 800-53 control family is most directly associated with cyber defense?
  • Which statement about copy requirements for load and packing lists is correct?
  • Usually when does JI occur?
  • In addition to the base documents, which forms are required for hazardous cargo that is also sensitive?
  • What is the difference between incident response and incident handling in cyberspace operations?
  • For a Joint Inspection who is the POC?
  • Which statement best describes the integration between a cyberspace domain commander and air/space operation centers?
  • What is Red Teaming and how does it contribute to mission readiness?
  • In the post-deployment cycle, reintegration refers to what?
  • Which functional area is A2?
  • What is the only acceptable automated system for completing air load plans?
  • What's a load list?
  • Name three types of deployments.
  • In a Joint operation, how do cyberspace operations support air superiority?
  • Who creates a project package?
  • Which practice is part of hardening a Windows workstation?
  • What is a cross-domain solution and why is it essential in Cyberspace Operations?
  • How does a zero-trust architecture improve cyberspace resilience?
  • Define 'mission assurance' in cyberspace and identify one key practice to improve it.
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy