Certified Counter-Insider Threat Professional - Fundamentals Exam Prep
Free practice questions

Free CCITP-F Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The CCITP-F exam has 110 questions and runs 2.1667 hours.

These 10 free CCITP-F questions are organized by exam domain, so you can see how each part of the Certified Counter-Insider Threat Professional - Fundamentals blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Policy and Directives 25% of exam

Question 1

A federal insider threat analyst requests an employee's reassignment dates from the agency's personnel system. The analyst is an employee of the same agency and needs the dates for an authorized duty. The Privacy Act applies, and no other restriction bars disclosure. HR objects because the employee has not consented. Which response correctly applies 5 U.S.C. 552a(b)(1)?

Show answer & explanation

Correct answer: D - The dates may be disclosed because the analyst needs them to perform assigned agency duties.

Question 2

An employee reports that an overseas contact offered payment for classified program information and asked that the exchange be concealed. The employee preserved the messages and reports making no disclosure. The insider threat hub has no investigative authority. Which assignment respects the participating organizations' roles?

Show answer & explanation

Correct answer: B - Refer the approach to counterintelligence; the hub integrates relevant, authorized security and personnel information.

Question 3

A cleared contractor accidentally sends a classified file through an approved system to a recipient who lacks authorized access, then immediately reports the error. No harmful intent is found. How does the National Insider Threat Policy apply to this incident?

Show answer & explanation

Correct answer: D - The incident remains within insider threat scope because authorized access can cause harm unwittingly.

Domain 2: Social and Behavioral Science 10% of exam

Question 4

What should the hub recommend when an employee's request for counseling and financial-assistance resources after a poor performance review is the sole basis for a proposed elevated insider threat designation? The supervisor reports no threats, safeguard violations, or changes in work behavior.

Show answer & explanation

Correct answer: C - Facilitate appropriate support without elevating threat concern solely because the employee seeks counseling.

Domain 3: Researching 30% of exam

Question 5

'Three independent sources corroborate that a technician photographed a restricted drawing,' states a referral. Its sources are a supervisor's email, HR's forwarding of that email, and a security memorandum quoting the forwarded email. No additional observations were collected. The referral's evidentiary claim fails because:

Show answer & explanation

Correct answer: A - It counts derivative reports of one originating allegation as independent corroboration.

Question 6

An unauthorized upload used a researcher's valid account. Two explanations remain: the researcher operated the account, or another person used compromised credentials. The upload time, destination, and file list are already verified. Which additional collection would best help distinguish those explanations?

Show answer & explanation

Correct answer: B - Endpoint and session records showing the activity that initiated the upload.

Question 7

Account disabled: June 8, 23:50 (UTC-4). Successful authentication: June 9, 03:35 UTC. Alert received: June 9, 04:10 UTC. Both source clocks are accurate. What does this chronology establish about an allegation that the recorded authentication succeeded after disablement?

Show answer & explanation

Correct answer: C - Authentication occurred 15 minutes before disablement; delayed alert delivery does not establish a post-disable login.

Domain 4: Synthesis & Tools and Methods 35% of exam

Question 8

An engineer's file-transfer alert fires after a move to the migration team. The project owner confirms that the destination, file set, and transfer window were approved. Endpoint and network records match that approval, and the volume increase is the alert's only trigger. How should this alert be resolved?

Show answer & explanation

Correct answer: B - Close it as authorized activity, retaining the records that support the disposition.

Question 9

An independent evaluation finds 18 unauthorized transfers that triggered alerts, 102 authorized transfers that triggered alerts, and 12 unauthorized transfers that were missed. A briefing calls 60% of the alerts confirmed unauthorized transfers. Which correction belongs in the briefing?

Show answer & explanation

Correct answer: D - 15% of alerts identified unauthorized transfers; 60% is sensitivity, not alert precision.

Question 10

At 14:05, a worker tells the hub that a colleague sent a message saying he is coming to the office that afternoon to shoot his supervisor. A security officer independently reports that the colleague is approaching the occupied building with a visible firearm. The analyst is in a secure location, and emergency responders have not been notified. What takes precedence?

Show answer & explanation

Correct answer: A - Notify emergency responders now and activate the site's protective procedures.

That's 10 of 1,030

The full bank has 1,020 more CCITP-F questions with explanations.

Continue in the free practice test →

View plans