Security Awareness Training Quiz
Questions: 16 · 10 minutes
1. Which password practice best limits the damage if one website suffers a data breach?
Use a complex base password with a different number added for each site.
Maintain a few strong passwords and assign them according to each account's importance.
Change one memorable password regularly and use it across important accounts.
Use a strong, unique password for every account, preferably generated and stored by an approved password manager.
2. You find an unknown USB drive in a meeting room. What should you do?
Connect it to a spare computer that does not contain sensitive files.
Do not connect it; give it to security, IT, or another designated contact under your organization's procedure.
Keep it until someone sends a message asking whether it was found.
Ask nearby coworkers to connect it and identify its owner.
3. An unexpected email says your account will be closed today unless you open a link and confirm your password. What is the best response?
Avoid the link and report the message through the organization's approved security channel.
Open the link, but leave immediately if the page looks unusual.
Reply to the sender and ask whether the warning is genuine.
Forward the email to a colleague to see whether they received it too.
4. Which feature makes a backup most useful after ransomware or major data loss?
It is stored on the same device so files can be restored quickly.
It runs frequently, even if restoration has never been tested.
It synchronizes every file change immediately, including unwanted encryption.
It is appropriately isolated or protected, maintained, and tested to confirm that restoration works.
5. What is the main security benefit of multifactor authentication?
It encrypts every file stored in the account.
It prevents the account provider from experiencing a breach.
It makes a stolen password alone less likely to be enough for account access.
It automatically identifies and removes phishing messages.
6. Which approach best protects a password manager account?
Reuse its master password on another important account so it is easier to remember.
Use a strong, unique master passphrase and enable multifactor authentication when available.
Disable automatic locking so passwords remain available throughout the day.
Keep an unprotected export of the stored passwords in email as an emergency copy.
7. As you enter a restricted office area, an unfamiliar person tries to follow you through the door without using their own access credential. What is the best response?
Follow the organization's visitor or access procedure rather than allowing them to enter on your access.
Let them enter if they appear to be carrying work equipment.
Ask their name and allow entry if they mention someone you recognize.
Allow entry, then send a message to security later if their behavior seems unusual.
8. You need to share a spreadsheet containing sensitive customer information with a project team. Which approach best protects the data?
Use an approved location and grant access only to authorized people who need it.
Place it on a broadly accessible shared drive so the team can work without access delays.
Send it to the entire department so someone can provide access if you are unavailable.
Remove the filename's reference to customers before attaching it to an email.
9. Which email detail is the strongest specific sign that a message may be impersonating a trusted organization?
The email arrives outside the recipient's normal working hours.
The sender's domain contains a subtle misspelling that resembles the organization's real domain.
The message uses a logo and formal signature.
The email discusses an account or service the recipient uses.
10. A company-managed laptop displays an approved notice that a critical security update is ready. What should you do?
Delay it until the computer begins showing signs of a problem.
Install it promptly through the approved update process, following organizational instructions.
Wait until several coworkers confirm that they installed it successfully.
Search online for an unofficial copy that installs more quickly.
11. A poster in a public area has a QR code promising a free work-related resource. Before using it, what is the most security-aware action?
Scan it because QR codes cannot reveal the scanner's account credentials.
Open it on a personal device because personal devices are not exposed to security threats.
Scan it only after another person says the poster looks legitimate.
Consider the source and context, inspect the destination when possible, and avoid continuing if the link or request is unexpected.
12. A familiar supplier unexpectedly emails you a document that asks you to enable macros. What is the safest next step?
Verify the request with the supplier through a known, separate contact method before opening or enabling anything.
Open the document in preview mode because previews cannot contain threats.
Enable macros if the email includes the supplier's usual signature block.
Upload the document to a personal cloud account and open it there.
13. A workstation suddenly displays a ransomware note and files begin becoming unavailable. What should the user do first?
Pay the requested amount quickly to prevent further disruption.
Delete the ransom note and continue working to determine which files remain accessible.
Disconnect or isolate the device as instructed by policy and immediately report the incident to the designated security or IT team.
Contact coworkers and ask them to open the same files to check whether their devices are affected.
14. What does the principle of least privilege mean?
All employees receive the same access so responsibilities can be reassigned easily.
Administrative access is permitted whenever standard access feels inconvenient.
People and systems receive only the access needed for their authorized tasks, for only as long as needed.
Access is based mainly on seniority rather than specific job responsibilities.
15. A message that appears to come from an executive requests an urgent change to a vendor's bank details. What is the strongest verification step?
Check whether the message uses the executive's usual writing style.
Reply to the message and ask the sender to confirm the request.
Confirm the request through a known contact method and follow the established payment-change procedure.
Proceed if the email address and signature block appear familiar.
16. You must complete an authorized work task while connected to hotel Wi-Fi. Which measure most directly helps protect the connection?
Use a private browsing window so the network cannot observe traffic.
Rename the device so it does not include your name or employer.
Disable Bluetooth while leaving all other connection settings unchanged.
Confirm the correct network and use the organization's approved secure connection, such as its VPN, according to policy.