Information Security Quiz
Questions: 16 · 10 minutes
1. Which backup arrangement best protects important files from device failure and ransomware?
A second folder on the same computer that synchronizes immediately
Multiple backup copies, including one isolated or offline copy, with restoration tested periodically
A single cloud folder that remains continuously connected to every device
An archive created only after unusual computer activity is noticed
2. A website uses HTTPS and displays a padlock. What can you reasonably conclude?
The connection is encrypted, but the site itself could still be deceptive or malicious
Files downloaded from the site cannot contain malware
The site’s claims and business identity have been independently verified
The site cannot collect or retain information you submit
3. Why should security updates for operating systems and applications be installed promptly?
They guarantee that phishing messages will be blocked
They often fix known vulnerabilities that attackers could exploit
They automatically replace reused passwords with unique ones
They prevent authorized users from accidentally deleting files
4. Someone you do not recognize follows closely behind you toward a badge-controlled office door and says they forgot their access card. What should you do?
Let them enter if they can name an employee who works there
Hold the door but ask them to show a business card
Direct them to the approved visitor or access-verification process instead of letting them follow you in
Allow entry and notify reception afterward if their behavior seems unusual
5. You find an unlabelled USB drive in your office parking area. What should you do?
Do not connect it; follow your organization’s process for reporting or safely handing in unknown devices
Connect it to a spare computer that does not contain important documents
Open only the top-level folder without running any visible programs
Scan it after copying its contents to your computer
6. A colleague asks you to send a customer file to their personal email because the approved sharing system is temporarily inconvenient. What is the best response?
Send a password-protected copy and include the password in a second personal email
Remove the filename and send the file as an unnamed attachment
Send only part of the file now and the remainder later
Keep the file within approved systems and seek an authorized alternative if access is blocked
7. A senior executive emails an employee requesting an urgent transfer to a new supplier account. The wording and timing are unusual. What is the best response?
Process a smaller transfer first to test whether the account works
Reply to the email asking the executive to type the request again
Verify the request through a separate, trusted channel and follow the organization’s payment controls
Proceed if the message includes the executive’s normal signature block
8. You receive a genuine notification of a successful login to your email account from an unfamiliar device. You did not log in. What should you do first?
Delete the notification so an attacker cannot interact with it
Wait for another alert to confirm that the activity is continuing
Use the provider’s official site or app to secure the account, review sessions, and report the incident as appropriate
Reply to the notification with a request to close the session
9. You discover that the same password protects your email, shopping, and streaming accounts. What change most directly limits damage if one service is breached?
Change the shared password every month while continuing to use it everywhere
Give every account a unique, strong password, preferably generated and stored by a password manager
Add personal details to the password so it is harder for strangers to guess
Save the shared password in your browser and remove it from written notes
10. Which description best matches ransomware?
Software that records browsing activity mainly to select advertisements
A fraudulent message designed to collect login details
A flood of network traffic intended to make a service unavailable
Malware that blocks access to data or systems and demands payment for restoration
11. Which statement best defines social engineering in information security?
Manipulating people into revealing information or taking actions that weaken security
Testing software code to find performance bottlenecks
Using encryption to protect messages sent through social platforms
Monitoring public posts to measure customer sentiment
12. Which type of malware is designed to appear legitimate while concealing harmful behavior?
A distributed denial-of-service attack
A firewall
A security patch
A Trojan
13. A temporary contractor needs to view one project folder but does not need editing or access to other projects. Which approach follows the principle of least privilege?
Give the contractor the same access as the project manager to avoid delays
Grant time-limited, read-only access to the required folder
Share a permanent team account that already has access
Provide access to all folders but ask the contractor not to open unrelated files
14. While using public Wi-Fi at an airport, you need to review a sensitive work document. What is the most appropriate choice?
Connect to the network with the strongest signal because it is likely the official one
Turn off Bluetooth, which makes all activity on the Wi-Fi connection private
Use a trusted mobile connection or an organization-approved VPN, following workplace policy
Use private-browsing mode before opening the document
15. What is the main security benefit of multi-factor authentication?
It requires another form of proof, so a stolen password alone may not grant access
It prevents a service provider from experiencing a data breach
It makes a short password equivalent to a long, unique password
It encrypts every file stored in an account
16. An email says your work account will be disabled in 30 minutes unless you use its link to confirm your password. What is the best response?
Forward the message to a personal account so you can inspect it later
Use the link if the sender’s display name matches the organization
Reply to the email and ask whether the warning is genuine
Open the organization’s site through a known bookmark or contact IT through an established channel to verify the request