SAPPC Certification Study Guide
2026- Comprehensive Q&A For
Certification Success
List three factors for determining whether U.S. companies are under Foreign
Ownership, Control, or Influence (FOCI)? - correct-answer -Record of economic
and government espionage against the U.S. targets
Record of enforcement/engagement in unauthorized technology transfer
Type and sensitivity of the information that shall be accessed
The source, nature and extent of FOCI
Record of compliance with pertinent U.S. laws, regulations and contracts
Define the purpose and function of the Militarily Critical Technologies List (MCTL)?
- correct-answer -Serves as a technical reference for the development and
implementation of DoD technology, security policies on international transfers of
defense-related goods, services, and technologies as administered by the Director,
Defense Technology Security Administration (DTSA). Formulation of export control
proposals and export license review.
List three primary authorities governing foreign disclosure of classified military
information? - correct-answer -Arms Export Control Act
,2|Page
National Security Decision Memorandum 119
National Disclosure Policy-1
International Traffic in Arms Regulation (ITAR)
E.O.s 12829, 13526
Bilateral Security Agreements
DoD 5220.22-M, "NISPOM,"
Briefly describe the purpose of the DD Form 254? - correct-answer -Convey
security requirements and classification guidance, and provide handling
procedures for classified material received and/or generated on a classified
contract.
List the three main policies that govern the DoD Information Security Program? -
correct-answer -E.O. 13526
Information Security Oversight Office (ISOO) 32 CFR Parts 2001 & 2003
Classified National Security Information; Final Rule"
DoD Manual 5200.01, Volumes 1-4
What must an "authorized person" have before being granted access to classified
information? - correct-answer -Favorable determination of eligibility for access
Need to know the information
Signed SF 312 Nondisclosure Agreement
, 3|Page
List three classification duration options for originally classified information? -
correct-answer -less than 10 years
at 10 years
up to 25 years
50X1-HUM (with no date or event)
50X2-WMD (with no date or event
25X (with a date or event)
List three authorized sources of security classification guidance that could be used
in the derivative classification process? - correct-answer -Security Classification
Guide
Properly Marked Source Document
Contract Security Classification Specification (DD Form 254)
Define derivative classification? - correct-answer -Incorporating, paraphrasing,
restating, or generating in new form information that is already classified and
marking the newly developed material consistent with the markings that apply to
the source information.