Cyber Smart Quiz
Questions: 15 · 10 minutes
1. How would you recover important personal files if your device failed or was affected by malicious software?
I would try repair or recovery software because I do not keep a separate copy.
Some files exist on another device or cloud service, but coverage is inconsistent.
Important files are backed up regularly to one separate location.
Important files are backed up automatically, and at least one copy is separated from the main device or account.
2. How do software and operating-system updates usually happen on your main devices?
I often postpone them until an app or device stops working properly.
I install major updates after I have heard that they are stable.
I install updates reasonably soon, although some apps may be overlooked.
Automatic updates are enabled where practical, and I check devices or apps that require manual updates.
3. A website displays a padlock icon and uses HTTPS. What does that tell you?
The site has been checked and confirmed to be legitimate.
The connection is encrypted, but the site itself could still be deceptive.
The site's content is safe as long as the certificate has not expired.
The connection has some protection, though I would mainly judge the site by how polished it looks.
4. You need to access an account on a shared or borrowed computer. Which approach is closest to yours?
I sign in normally and rely on closing the browser when I finish.
I use a private browsing window but may allow the browser to remember some details.
I use private browsing, decline saved credentials, and sign out when finished.
I avoid signing in if possible; if necessary, I use private browsing, save nothing, sign out, and review the account afterward.
5. A message says your streaming account will close today unless you confirm payment details through its link. Which cue would matter most to you?
Whether the logo, colors, and formatting match the service.
Whether the message includes my name and part of my account information.
Whether the link text appears to mention the correct company.
Whether the alert also appears when I open the service through its official app or a saved address.
6. You receive an overdue-invoice email from a company you recognize, but you were not expecting it. What would you do first?
Open the attachment to identify the purchase before deciding what to do.
Check the sender's displayed name and open it if the company name looks correct.
Inspect the full sender address and message details before interacting with anything.
Avoid the attachment and contact the company through a known website, app, or phone number to verify the invoice.
7. A newly installed photo-editing app requests access to your contacts, microphone, precise location, and entire photo library. What would you do?
Allow everything so all of the app's features work as intended.
Allow the requests initially and remove access later if something seems wrong.
Allow only permissions that appear necessary for the features I plan to use.
Decline the least relevant permissions but allow broad photo access for convenience.
8. Your phone containing email, photos, and saved accounts goes missing. How prepared are you?
I would mainly retrace my steps and hope someone returns it.
The phone has a screen lock, but I am unsure whether I could locate or erase it remotely.
It has a strong screen lock and a location feature I know how to access.
It has a strong lock, remote location or erasure enabled, and important data backed up elsewhere.
9. A friend messages from their usual social account asking for money immediately because of an emergency. How would you respond?
Send a small amount because the request came from their familiar account.
Ask a personal question within the same chat before sending anything.
Pause and contact them using another method I already have.
Wait for more details and compare the writing style with their usual messages.
10. You need to check a sensitive account while using public Wi-Fi. What would you most likely do?
Use the network if it has the venue's name and does not show a warning.
Use it after confirming the network name with a sign or staff member.
Use the official network but avoid especially sensitive actions unless necessary.
Prefer mobile data or another trusted connection, especially for financial or similarly sensitive activity.
11. If you lost access to your main email account today, how prepared would you be to recover it?
I would have to rely on remembering old details or contacting support.
I have a recovery method set, though I am not sure it is current.
I have checked that at least one recovery email address or phone number is current.
My recovery details are current, protected, and supported by saved recovery codes or an equivalent backup method.
12. An unexpected sign-in approval request appears on your phone. You are not trying to sign in. What would you most likely do?
Approve it in case it came from one of my other devices.
Dismiss it and wait to see whether another request appears.
Deny it, then check the account's recent sign-in activity.
Deny it, review account activity through the official app or site, and secure the account if anything looks unfamiliar.
13. A poster in a public place has a QR code promising a discount. What is your typical approach?
Scan it and continue if the page looks professionally designed.
Scan it because printed QR codes are generally safer than emailed links.
Preview the destination and avoid entering sensitive information unless I can verify the site.
Find the organization's official site or app independently and look for the same offer there.
14. Which description best matches how you manage passwords across your accounts?
I use one familiar password, or a close variation of it, for most accounts.
I maintain several passwords, but some are reused across unrelated accounts.
My most important accounts have unique passwords, while lower-priority accounts may share one.
I use a password manager or another reliable system to give every account a strong, unique password.
15. A service you use offers a passkey or multi-factor authentication. How do you usually respond?
I usually skip it because a password feels sufficient.
I enable it only if the service requires me to do so.
I enable it on financial, email, or other high-value accounts.
I enable the strongest practical option on most accounts that support it.