Phishing Quiz
Questions: 16 · 10 minutes
1. An unexpected email says your payroll access expires in 30 minutes and provides a sign-in button. What is the safest response?
Use the button but leave immediately if the page looks unusual
Reply to the email and ask whether the warning is genuine
Open the payroll portal independently through a known bookmark or official site
Forward the message to a coworker and follow whatever they decide
2. Consider the link https://accounts.example.com.security-check.net/login. Which organization controls the key registered domain shown here?
example.com
accounts.example.com
The organization named on the email's logo
security-check.net
3. A link uses “micros0ft-support.com,” replacing the letter “o” with a zero. Which tactic is this?
Transport encryption
Email list tracking
Use of a legitimate corporate subdomain
Typosquatting with a look-alike domain
4. On a desktop computer, how can you inspect a linked destination without opening the page?
Click it and check the address bar before the page finishes loading
Hover the pointer over the link and review the displayed destination
Copy it into a private browsing window
Forward it to a personal email account and open it there
5. An email appearing to come from a senior executive urgently asks an employee to buy gift cards and send the codes. Which threat best fits this scenario?
Credential stuffing
Business email compromise or executive impersonation
A software update notification
An ordinary marketing campaign
6. An email displays your bank's name, but the From address uses an unrelated domain. What does this demonstrate?
The bank has necessarily outsourced its email service
The message is encrypted because two identities are shown
The email definitely contains a malicious attachment
A familiar display name does not prove who sent the message
7. When deciding where a link in an email will actually take you, which detail matters most?
The destination URL associated with the link
The wording displayed as the clickable text
The sender's displayed name
The company logo beside the link
8. Which request is most characteristic of a credential-phishing email?
An expected receipt listing a completed purchase without requesting action
An urgent link leading to a page that asks you to sign in
A newsletter offering a standard unsubscribe preference
A security notice telling you to check activity by opening the official app yourself
9. A supplier unexpectedly emails a macro-enabled spreadsheet labeled “Overdue Invoice.” What should you do first?
Reply to the message asking the sender whether the attachment is safe
Enable macros briefly so you can check whether the invoice is relevant
Verify the file and request through a known contact method before opening it
Upload the document to a personal cloud account and preview it there
10. You receive several unexpected multifactor authentication approval prompts. What should you do?
Deny them, secure the account through an official route, and notify appropriate support
Approve one prompt, then change the password after you gain access
Ignore the prompts without checking the account or reporting them
Uninstall the authentication app so the prompts stop
11. You entered your password on a page reached through a phishing email. What is the strongest immediate response?
Use a trusted device and official site to change the password, review account access, and report the incident
Delete the email and continue using the account normally
Reply to the sender and demand that the password be deleted
Wait to see whether the account behaves unusually before acting
12. An email security banner says, “No threats found.” How should that affect your judgment?
It proves every link and attachment in the message is safe
It confirms that the sender's identity was personally verified
It is one useful signal, but it does not guarantee that the message is legitimate
It makes independent verification unnecessary
13. A familiar colleague sends an unusual shared-document link with no explanation. What is the soundest conclusion?
The link is trustworthy because it came from a known address
The message must be fake because colleagues never share documents by email
The message must be harmless if it contains no attachment
The colleague's account could be compromised, so the request should be verified separately
14. What does HTTPS and a padlock icon establish about a website?
The connection to that domain is encrypted, but the site itself may still be deceptive
The website has been reviewed and approved as trustworthy
The domain belongs to the company whose brand appears on the page
Any information entered on the site cannot be stolen
15. A message's Reply-To address differs from its From address. What is the best interpretation?
The message is certainly phishing and needs no further assessment
It is a warning sign that calls for verification, though legitimate systems can also use different addresses
The visible From address cannot have been spoofed
The difference is harmless because email systems always rewrite replies
16. An email says your streaming account will close today unless you scan a QR code. What is the safest way to check the claim?
Scan the code because phones automatically block fraudulent websites
Reply and ask the sender to provide the destination as a normal link
Open the service's official app or manually enter its known website address
Forward the QR code to someone else to see whether it works for them