Question 1
Two ethical/legal constraints in surveillance are privacy rights and oversight. Which statements describe these constraints?
Correct Answer:
Both of the above
Explanation:
Two essential factors guide surveillance ethics and legality: protecting privacy rights and ensuring proper oversight. Privacy rights limit what information is collected and how it’s used, preserving individuals’ expectations of privacy. Oversight provides accountability and governance over surveillance activities, including guidelines that law enforcement follow to keep actions justified and within bounds. Proportionality fits under oversight, requiring that intrusion be no more extensive than necessary to achieve a legitimate objective. The paired descriptions show how privacy protection and governance constraints shape surveillance, and together they capture both ethical and legal safeguards. Economic considerations aren’t part of these two constraints.
Question 2
Which statement correctly distinguishes active defense measures from passive defense measures, and which examples illustrate each?
Correct Answer:
Active defense reduces risk by design (segmentation, encryption); passive defense detects and disrupts attackers (IPS, deception technologies)
Explanation:
Active defense is about reducing risk by design, embedding protections into how a system is built so that even if an attacker breaches outer layers, the impact is limited. Segmentation isolates parts of the network to halt movement, and encryption protects data so it remains unreadable even if accessed. Passive defense, by contrast, focuses on seeing and slowing or stopping attackers as they try to operate—using measures that monitor and respond to activity, such as intrusion prevention systems that can block malicious traffic and deception technologies that mislead and slow down attackers. This pairing fits the idea that proactive, architectural protections aim to minimize risk up front, while detection and disruption measures respond to attacker activity. Other statements stray from that distinction: backups are about recovering from incidents after the fact rather than reducing risk by design, and IDS is a detection tool rather than a primary active defense control. The notion that active defense is for military use or that passive defense is the one that disrupts attackers also misaligns with how these concepts are applied in modern security.
Question 3
Which term identifies the area outside the base perimeter from which the base may be vulnerable to standoff threats?
Correct Answer:
Base Security Zone (BSZ)
Explanation:
The concept being tested is how security planners name the area beyond a base’s fence line where threats can launch or threaten from a distance. The Base Security Zone is the term used to describe that outward area outside the base perimeter where standoff threats can affect the base, guiding how early warning, sensors, barriers, and response forces are positioned to deter or detect attacks before they reach the perimeter. It focuses on the external threat environment that shapes protective posture, rather than the inner or perimeter-specific aspects of security. Other terms don’t fit as neatly. A Base Perimeter Zone suggests something tied to the inside-to-perimeter boundary rather than the outside threat area. An External Defense Area is vague and not a standard designation for the outer threat zone. An Outer Security Ring is a descriptive phrase but not the commonly used, formal label for the area outside the base perimeter that governs standoff threat planning.
Question 4
Which practices are essential for secure communications in contested environments?
Correct Answer:
End-to-end encryption, mutual authentication, and robust key management.
Explanation:
In contested environments, secure communications rely on three pillars: confidentiality, authentication, and robust key management. End-to-end encryption ensures that the content remains unreadable to anyone except the intended recipient, even if the message passes through untrusted or compromised networks. Mutual authentication verifies both parties’ identities, preventing impersonation and man-in-the-middle attacks where an adversary could otherwise insert themselves into the communication. Robust key management covers how keys are created, distributed, stored, rotated, revoked, and destroyed, so a compromised key doesn’t compromise long-term security and new keys can be issued securely. Without authentication, encryption alone can be dangerous because you might be encrypted to an impostor, so you could be sharing secrets with a bad actor. Relying only on perimeter defenses or assuming external networks are trusted leaves internal communications exposed if attackers breach the network or bypass borders. Using plain text removes any confidentiality and makes interception trivial, exposing sensitive information to anyone who can observe the channel.
Question 5
Which statements are true descriptions of need-to-know and least privilege?
Correct Answer:
Need-to-know restricts access to information essential for a role; least privilege grants only necessary rights.
Explanation:
Controlling who can see information and what they can do with it is the essential idea here. Need-to-know means access to particular information is granted only to people who truly need it to perform their duties, not to everyone who might have a general interest. Least privilege means that once someone has access, they receive only the minimum permissions necessary to carry out their tasks, no more. Together, these principles reduce exposure and limit potential damage from mistakes, misuse, or malicious actions. The described statement captures this accurately: access to information is restricted to what a role requires, and permissions are kept to the minimum needed to perform the job. The other options don’t fit because they imply universal access, broad permissions, or no effect on insider threats, which contradict the purpose of need-to-know and least privilege. For example, in practice, a nurse would only access patient records needed for care, and a user account would avoid unnecessary admin rights.
Question 1
Exam overview

About this Exam

Prepare with the Integrated Defense Test 1 Practice practice quiz. This question bank includes 10 questions covering defense, measures, integrated, constraints, and base. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

Integrated Defense Test 1 Practice

This practice set contains 10 questions from the matching question bank and focuses on defense, measures, integrated, constraints, and base. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions