Skip to content
StudyDex
IT & Cybersecurity

Which of the Following Is True of Spillage?

Quick answer

Spillage can be either inadvertent or intentional. It occurs when information moves from a higher classification or protection level to a lower, unauthorized one. It must be reported immediately to your security point of contact (POC) and never deleted or forwarded.

The answer

The statement that is true of spillage is this: spillage can be either inadvertent or intentional, it happens when classified or sensitive information reaches a system, network, or person not authorized to hold it, and it must be reported immediately. In the DoD Cyber Awareness framework, spillage is formally defined as the transfer of classified or sensitive information to an information system that is not accredited (approved) for that level of classification.

The key facts that make a statement "true of spillage":

  • It moves information from a higher protection level to a lower one (for example, Secret data landing on an unclassified network or an unencrypted email).
  • It can be accidental (attaching the wrong file, emailing the wrong recipient) or deliberate.
  • It requires immediate reporting to your security POC.
  • You should not delete the data, forward it, or try to "clean it up" yourself, because that can destroy evidence and spread the exposure further.

Why the other options are wrong

Typical distractors on this question fail for concrete reasons:

  • "Spillage is always intentional." False. The majority of real spillage events are honest mistakes, such as a mislabeled document or an autocomplete email address. Intent is not required.
  • "You should delete the spilled file to fix it." False and dangerous. Deleting destroys the audit trail and does not guarantee the data is gone from backups, caches, or the recipient's mailbox. The correct move is to secure the area and let security handle remediation.
  • "Spillage only involves classified government data." Incomplete. While the term is rooted in classified environments, the same principle applies to any sensitive or controlled unclassified information (CUI) reaching an unauthorized level.
  • "You don't need to report minor spillage." False. All spillage is reported to your security POC regardless of size.

The bigger picture

Spillage differs from a data breach: a breach implies an outside adversary gained access, whereas spillage is usually an internal handling error, information going somewhere it should not, even if no attacker is involved. Both are security incidents, but spillage is specifically about classification level mismatch.

Your response should follow a clear sequence: do not delete or forward anything, note what happened, physically or logically secure the affected system or area, and report immediately to your security point of contact. Security professionals then perform a formal cleanup, which may involve wiping drives, reviewing logs, and notifying data owners. Following the wrong steps, such as trying to erase the file yourself, can turn a contained mistake into a much larger exposure. Understanding that spillage is common, often unintentional, and always reportable is exactly what the exam is testing.

Walk the decision
  1. 1

    Do you suspect information reached an unauthorized level?

    Classified or sensitive data on a system not accredited for it counts as spillage, whether accidental or deliberate.

  2. 2

    Do NOT delete or forward the data

  3. 3

    Secure the area or system

  4. 4

    Report immediately to your security POC

Frequently asked

What should you do if a spillage occurs?

Do not delete or forward the information. Secure the affected system or area to prevent further access, then report the incident immediately to your security point of contact (POC), who will handle formal remediation.

What is the difference between spillage and a data breach?

Spillage is usually an internal handling error, where information ends up on a system or with a person not authorized for that classification level, often accidentally. A data breach implies an external adversary gained unauthorized access. Both are reportable security incidents.

Is spillage always intentional?

No. Spillage can be either inadvertent or intentional. Most real events are unintentional, such as emailing the wrong recipient or mislabeling a document. Intent is not required for something to count as spillage.

Who do you report a classified spillage to?

Report it immediately to your security point of contact (POC) or security officer. Do not attempt to remediate it yourself; trained security personnel will perform the cleanup and notify affected data owners.

Start freeLog in