Which of the Following Poses a Security Risk While Teleworking
All of these pose a security risk while teleworking: voice-enabled devices, unchanged default passwords, unknown Bluetooth connections, and personal devices brought into the work environment.
That is the direct answer used for the DoD Cyber Awareness-style question. The useful part is understanding why each choice creates a problem. These risks can give an unauthorized person access to information or create a path to a data breach.
The direct answer: all of these IoT-related behaviors pose a risk
Internet of Things devices, or IoT devices, are everyday items that connect to a network. Examples include smart speakers, watches, televisions, cameras, printers, and home assistants.
In a telework setting, these devices may be close to work systems or work conversations. A device doesn't have to be designed for business use to affect your security. If it has weak settings, an unknown connection, or access to your home network, it can add risk.
For the quiz question, remember the short answer:
> All of these choices can pose a security risk while teleworking.
That answer applies to the listed IoT-related behaviors. Broader remote-work risks include phishing, social engineering, weak passwords, poor encryption, and missing multi-factor authentication (MFA).
Why voice-enabled devices can create telework security concerns
Voice-enabled devices respond to spoken commands. Smart speakers and other assistants may be active in the same room where you discuss work or handle DoD information.
The concern is simple: the device creates another possible path for unauthorized access or exposure of information. If its settings or connected account are not secure, work-related conversations or commands could create a security problem.
That doesn't mean every smart speaker is automatically unsafe. It means you should treat voice-enabled devices as part of your telework environment. Keep them away from sensitive work discussions when required by your organization, and follow your agency's rules for using them near government work.
For a knowledge check, connect the device to the risk, not to a specific brand or model:
- A voice-enabled device may be present during work conversations.
- It may connect to accounts or other devices.
- Poor security settings can contribute to unauthorized access or a data breach.
The quiz is testing whether you recognize that these devices can create risk—not whether every voice assistant has already caused a breach.
The danger of leaving default passwords unchanged
A default password is the password set by the maker when a device is first supplied. Some devices come with a standard password or an initial login that the owner is expected to change.
Leaving that password in place is dangerous because it may be easy for someone else to guess or know. It also shows poor password hygiene, which is one of the broader security risks associated with working from home.
The same lesson applies beyond IoT devices. Don't reuse weak passwords for work accounts, home routers, smart devices, or personal email. A compromised personal account can make a remote-work environment harder to protect.
For the quiz, the key point is direct: unchanged default passwords can contribute to unauthorized access and data breaches.
Risks from unknown Bluetooth connections
Bluetooth lets nearby devices connect without a physical cable. You may use it with headphones, a keyboard, a smartwatch, or another accessory.
The problem is an unknown Bluetooth connection. If you don't recognize the device or know why it is connected, you can't be sure what it is or what access it may have. That uncertainty can create a security risk in a telework setting.
Don't approve pairing requests just because they appear on screen. Check that the device belongs to you or is authorized for work use. Remove connections you don't recognize, and follow your organization's instructions for Bluetooth and other wireless features.
Again, the question does not require you to identify a particular attack. It asks whether an unknown connection can create risk. The answer is yes.
Other security risks associated with working from home
IoT devices are only one part of the problem. Remote workers also face common online threats that can expose accounts or work data.
Phishing and social engineering
Phishing uses deceptive messages to trick you into clicking a link, opening a file, or giving away login information. Social engineering is the broader use of manipulation or trust to get someone to take an unsafe action.
A message may appear to come from a coworker, manager, help desk, or service you use. Working away from the office can make it harder to check a request in person.
Pause before responding to unexpected requests. Check the sender, be careful with links and attachments, and use an approved way to confirm unusual instructions.
Weak passwords and missing MFA
Poor password practices include using simple passwords, reusing the same password, or failing to change a known default password.
Multi-factor authentication, or MFA, adds another check after you enter a password. Without it, a stolen password may be enough for someone to access an account. A lack of MFA is therefore another recognized remote-work security risk.
Insufficient encryption
Encryption changes data into a protected form so unauthorized people cannot easily read it. If data is not properly encrypted, information moving across a network or stored on a device may have less protection.
The study point is not that every home network is automatically unsafe. It is that insufficient encryption can leave work information exposed. Use only approved systems and follow DoD or organizational rules for handling data.
Protecting DoD data while teleworking
Workers must safeguard all DoD data while teleworking or working remotely. That responsibility does not disappear because you are using a home office, personal internet connection, or a device outside a government building.
Keep work information in approved locations and use authorized tools. Avoid moving DoD data to personal accounts, unapproved storage, or devices that are not allowed for work.
Also pay attention to who can see or hear your work. A screen visible from a shared area, an unlocked computer, or an open conversation can create a physical security risk even when no cyberattack is involved.
If you are unsure whether a device, app, connection, or storage location is approved, stop and check the relevant workplace guidance rather than guessing.
Classified documents and remote-work restrictions
Classified documents are prohibited while teleworking. This applies to both hard-copy and electronic classified information.
That rule is separate from ordinary home-office precautions. Locking a file cabinet or using a password does not make teleworking with classified material acceptable if the work arrangement is not approved for it.
For a knowledge check, keep the distinction clear:
- DoD data must be protected during telework.
- Classified documents, in paper or electronic form, are strictly prohibited while teleworking.
- Home-office security steps do not override restrictions on classified material.
What counts as a physical security risk?
The supplied quiz material does not identify a specific answer choice for a separate physical-security question. The safe principle is to protect work devices, documents, screens, and conversations from people who are not authorized to see or hear them.
Don't assume a risk is only “cyber” because a computer is involved. Someone gaining physical access to a device or document can also expose information.
Best practices for telework and remote work
A good best practice for telework and remote work is to review the whole setup, not just the work laptop. Use this quick check:
- Change default passwords on approved devices.
- Avoid unknown Bluetooth connections and pairing requests.
- Keep voice-enabled devices away from sensitive work when required.
- Use strong, unique passwords for work accounts.
- Turn on MFA wherever it is available and approved.
- Watch for phishing and social-engineering messages.
- Use approved tools and systems with proper encryption.
- Protect DoD data on every device and account.
- Never telework with classified documents, whether paper or electronic.
- Ask for guidance before using a personal device for work.
A smartwatch payment question cannot be answered safely from the supplied material alone. It does not provide enough evidence for a definite yes-or-no answer about that specific action. Treat separate quiz questions on their own facts instead of assuming every connected device activity has the same answer.
Before your next telework session, look around your workspace. Check for unsafe IoT devices, unchanged default passwords, unknown Bluetooth connections, and work data sitting where other people—or unapproved devices—can reach it.