wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cyber Security Assessment for Bank Officials

Total questions: 100

Worksheet time: 50mins

Name
Class
Date
1.

What is the current version of Dutch-Bangla Bank ICT Operation and Security Policy?

a)

Seventh Revision: April 2022

b)

Eighth Revision: June 2022

c)

First Version: November 2021

d)

Tenth Revision: September 2022

2.

Which of the following attacks requires a carrier file to self-replicate?

a)

Trojan

b)

Virus

c)

Worm

d)

Spam

3.

Someone who is posing as an IT tech requests information about your computer configuration. What kind of attack is this?

a)

Insider threat

b)

Phishing

c)

Social engineering

d)

Whaling

4.

You are allowed to share or print full card number, PIN, password, expiry date with everyone. True or False?

a)

True

b)

False

5.

Which of the following describes monitoring software installed without your consent?

a)

Malware

b)

Adware

c)

Spyware

d)

Ransomware

6.

Cyber criminals only target large companies. True or False?

a)

True

b)

False

7.

Which of the following should you do to restrict access to business application?

a)

Update your software once a year.

b)

Share passwords only with colleagues you trust.

c)

Have your staff members access information via an open Wi-Fi network.

d)

Use multi-factor authentication.

8.

Business application users are not disabled after 90 days of inactivity. True or False?

a)

True

b)

False

9.

Backing up important files offline, on an external hard drive, will help protect your business in the event of a cyber-attack. True or False?

a)

True

b)

False

10.

Which is the best answer for which people in a business should be responsible for cybersecurity?

a)

Business owners. They run the business, so they need to know cybersecurity basics and put them in practice to reduce the risk of cyberattacks.

b)

IT specialists, because they are in the best position to know about and promote cybersecurity within a business.

c)

Managers, because they are responsible for making sure that staff members are following the right practices.

d)

All Bank officials are responsible and should know about cybersecurity best practices

11.

Branch and Divisional officials are allowed use removeable media. True or False

a)

True

b)

False

12.

Which one of these statements is correct?

a)

If you get an email that looks like it’s from someone you know, you can click on any links as long as you have a spam blocker and anti-virus protection.

b)

You can trust an email really comes from a client if it uses the client’s logo and contains at least one fact about the client that you know to be true.

c)

If you get a message from a colleague who needs your network password, you should never give it out unless the colleague says it’s an emergency.

d)

If you get an email from HRD asking you to provide personal information right away, you should check it out first andbe sure of their identity.

13.

Saving and sharing passwords is the best option to reduce hassles in everyday work. True or False?

a)

True

b)

False

14.

An email from your boss asks for the name, addresses, and credit card information of the company’s top clients. The email says it’s urgent and to please reply right away. You should reply right away. True or False?

a)

True

b)

False

15.

Dutch-Bangla Bank has an IT Operation and Security Policy. Is it True or False?

a)

True

b)

False

16.

You get a text message from an IT personnel who asks you to click on a link to renew your password so that you can log in to its website. You should:

a)

Reply to the text to confirm that you really need to renew your password.

b)

Pick up the phone and call the person, using a phone number you know to be correct, to confirm that the request is real.

c)

Click on the link. If it takes you to the website, then you’ll know it’s not a scam.

d)

None of the above

17.

If you fall for a phishing scam, what should you do to limit the damage?

a)

Delete the phishing email.

b)

Unplug the computer. This will get rid of any malware.

c)

Change the password / PIN or block the account /Card immediately .

d)

Nothing to do

18.

You should respond very fast if someone calling from an unknown number claims to be the MD/ DMD/ CXO of the bank and asks you for some customer confidential information. There is no need to verify the caller.

a)

True

b)

False

19.

Where should you write down your passwords?

a)

Some place that can be easily seen from your desk.

b)

Some place that is out of sight, like beneath your keyboard or a nearby drawer

c)

On a diary in a secure locked cabinet

d)

You should never write down your password

20.

What is ransomware?

a)

Malware that infects computer networks and mobile devices to hold your data hostage until you send the attackers money.

b)

Computer equipment that criminals steal from you and won’t return until you pay them.

c)

Software used to protect your computer or mobile device from harmful viruses.

d)

A form of cryptocurrency.

21.

Which of these best describes how criminals start ransomware attacks?

a)

Sending a scam email with links or attachments that put your data and network at risk.

b)

Getting into PC / Server through known vulnerabilities of the operating system / application and installing malware.

c)

Using infected websites that automatically download malicious software to your computer / Server or mobile device.

d)

All of the above.

22.

If you encounter a ransomware attack, the first thing you should do is pay the ransom. True or False?

a)

True

b)

False

23.

Paper files that have sensitive information should be disposed of in a locked trash bin. True or False?

a)

True

b)

False

24.

Which one of the following is the best password?

a)

TonyStark

b)

qwertyui

c)

12345678

d)

AG&m4$J7

25.

All branch and Division officials must ensure that all the PCs are covered by Antivirus /Antimalware Software. True or False?

a)

True

b)

False

26.

Which one of these statements is true?

a)

It’s best to use multi-factor authentication to access the business application with sensitive information.

b)

You should use the same password for key business devices to guarantee that high-level employees can access them in an emergency.

c)

The best way to protect business data is to make sure no one loses any device.

d)

You shouldn’t limit login attempts on key business devices, because getting locked out for having too many incorrect attempts would leave you unable to access your accounts.

27.

Dutch-Bangla Bank is currently PCI DSS certified. True or False?

a)

True

b)

False

28.

Bank has published two versions of Dutch-Bangla Bank ICT Operation and Security Policy: the complete one and a shorter one. True or False?

a)

True

b)

False

29.

Which of the following is the best answer for how to secure your password?

a)

Change the default password

b)

Make the password with upper & lower case, number and special character

c)

Password must be eight characters

d)

Don’t save the password on browser

e)

All of the above

30.

When receiving an email from an unknown contact that has a link, you should:

a)

Open the link to view its contents

b)

Report the suspicious email to IT Operation

c)

Forward the email to your co-workers to allow them to open the link first

d)

Forward the email to your personal email account so you can open it at home

31.

There is a rumor going around that if you can upload the most amount of customer information in a day on a site through a link, the management will grant you an attractive reward. What will be the appropriate action for you?

a)

You should inform all your colleagues and engage in a competition to win the reward

b)

You should immediately report the matter to your reporting manager

c)

Contact IT support and take their help.

d)

Both B & C.

32.

Which of the following circumstances should you treat as suspicious?

a)

Flight information attachment from airline when no travel is planned

b)

Request from Bank with a link to update information

c)

Email from unknown sender with an urgent message requiring action like changing your password immediately

d)

All of the above

33.

An act to cripple, corrupt or threaten a system or network is characterized as which of the below?

a)

Digital crime

b)

Threats

c)

System hijacking

d)

Cyber Attack

34.

What is a Trojan Horse?

a)

Malfunction of the software that makes it difficult to navigate the Internet. Bottom of Form

b)

Malicious software that allows other programs to control your computer by misleading users of its true intent

c)

A web browser with advanced capability

d)

Next generation antivirus

35.

Who is responsible for Cyber Security?

a)

ITSD

b)

ITOD

c)

Management

d)

Everyone

36.

The other day you were watching the news and you heard a journalist talking about a formof cyber-threat. Essentially criminals seem to be able to use malicious software to restrict users from accessing their computer system or personal files. Later criminals demand a payment in order for the restriction to be removed. What is the name of this threat?

a)

Ransomware

b)

Virus

c)

Botnet

d)

Trojan

37.

When visiting your favorite website, a pop-up appears that reads "You have won a free Apple iPod!" What should you do?

a)

Click the pop-up, enter your information and claim the prize

b)

Share the link with all your friends and family so that they too can get free stuff

c)

Do not click the pop-up - close it, and if possible, report it to IT Operation

d)

Contact on the page you were on

39.

Bank management have allowed the use of common name users (e.g., DBBL, ITOD) in special cases for accessing any business applications. True or False?

a)

True

b)

False

40.

Mr. Jamal was referred to an online shopping site by a friend that was offering a luxury brand watch at a very lucrative price with exceptional discount with limited sale period. Mr. Jamal has been wanting to purchase the brand of watch since a long time and was quite eager to grab the offer. What are the aspects that Mr. Jamal should keep in mind and duly verify, before proceeding to make the online purchase?

a)

He should verify - if the site is secured/trusted/original one(https/original URL); reviews about the site; customer reviews for product ; check for refund/return policy; whether COD option is given.

b)

He should verify the brand , quality, color and size of the watch displayed on the site.

c)

He should take the advice from his friends before he places the order for the watch.

d)

None of the above.

41.

You should never click on .exe files that you don’t recognize.

a)

True

b)

False

42.

You receive an email from a co-worker with an attachment.The subject line reads "Please See Attached Document". The mail contains no further information. What should you do?

a)

Open the attachment to get more information

b)

Delete the email

c)

Contact the apparent sender by phone or separate email to confirm the validity of the message

d)

Both B&C

43.

“Remember me” function of the web browsers or other applications are unsafe and should be avoided.

a)

True

b)

False

44.

You receive a text message warning you that your bank account has been suspended. It says that you must click on the link in the SMS and update your credentials within the next 24 hours. Is this message safe or unsafe?

a)

Safe

b)

Unsafe

45.

Dutch-Bangla Bank is currently not a Payment Card Industry Data Security Standard (PCI DSS) compliant Bank

a)

True

b)

False

46.

How Does Temperature Affect The Performance of Computer Components?

a)

High temperature may damage the hardware components of computer

b)

High temperature may damage the hardware and software of the computer

c)

I don’t think temperature will affect the performance of computer

d)

Both A & B

47.

You should leave your 2-FA token in an unlocked drawer in the office and share your password so that your colleague can continue your work in case of emergency.

a)

True

b)

False

48.

Which of the following is NOT a smart way to test a suspicious link?

a)

Use a free online tool to expand a shortened link and view the actual destination URL

b)

Click on it

c)

Use a link scanner tool

d)

Hover over the link and view the destination URL that is displayed

49.

Mr. Hossain received a message from his colleague Ms. Salma, saying she transferred an amount of Tk.3000/- upon his request over Facebook. Mr. Hossain was taken by surprise as he had not asked for any amount from Ms. Salma. How do you think Ms. Salma received that message and what action do you suggest Mr. Hossain from his end?

a)

Ms. Salma must have mistakenly taken some other friends request for money transfer, to be from Mr. Hossain. Ms. Salma can ask Mr. Hossain to cross verify properly and inform the other friend.

b)

It is a mystery how Ms. Salma got the message. Mr. Hossain can check his Facebook account and accordingly reply Ms. Salma.

c)

It is possible as Mr. Hossain’s Facebook account has been taken over by a fraudster somehow. He should immediately check his account and if it is accessible, change his password. Otherwise, he should report to the Facebook helpdesk to try and regain access to his account. He should also inform his friends, colleagues, family members about the possible fraud.

d)

Both A & B.

50.

Using two-factor authentication is not an effective tool for securing your accounts.

a)

True

b)

False

51.

What will you recommend your colleague who has been using one unique password for all his accounts for many years, but still no security breach has happened?

a)

Will not recommend anything as no security breach has happened.

b)

Tell your colleague to change the password regularly and use same password for all his account.

c)

Tell your colleague to change the password regularly and use different passwords for different accounts.

d)

Both A & B

52.

It is not necessary to lock your PC if you are leaving your desk for only two minutes.

a)

True

b)

False

53.

What is the only true guarantee against data loss due to a cyberattack such as ransomware?

a)

My business is small - this isn't something I need to worry about

b)

Having enough money to pay the ransom

c)

Having my data backed up and accessible

d)

Restricting internet access for my employees

54.

Your password should be changed _

a)

Never

b)

Daily

c)

Regularly

d)

Hourly

55.

You should try to install and uninstall software as per your requirement if you think you can do a better job than the people in ITOD.

a)

True

b)

False

56.

You have received an email from your Manager with a zip file attached. What will you do?

a)

Simply open the attachment and download the zip file and the unzip it since it is sent from a known person.

b)

Look for the sender’s email ID, confirm from your manager/friend if they have sent the zip attachment and then open the file.

c)

Both A & B.

d)

None of the above.

57.

Which of these is a possible cause of a data disaster?

a)

A lost or stolen device or laptop

b)

A Cyber-attack

c)

The sprinkler system in the office malfunctioning

d)

Equipment failure

e)

All of the above

58.

Cybersecurity is IT's responsibility. The everyday end-users in the office don't need to worry about this topic.

a)

True

b)

False

59.

Make sure your computer’s ____________ is up-to-date to protect your system from malware, ransomware attacks.

a)

Operating system

b)

Hardware

c)

Both

d)

None of above

60.

Software, Application and Antivirus / Anti-Malware updates are not important and can just be ignored.

a)

True

b)

False

61.

You must write down your passwords on a paper and stick it to your PC monitor so that you don’t forget and get locked out of your PC.

a)

True

b)

False

62.

Bank can take actions against you if you violate the IT security policies in place.

a)

True

b)

False

63.

Which of the following is not an advantage of cyber security?

a)

Makes the system a bit slower

b)

Minimizes computer freezing and crashes

c)

Gives privacy to users

d)

Protects system against viruses

64.

What is the difference between Vishing and Phishing?

a)

Phishing is an online attempt to grab private information through mails, messages, links, attachments, while Vishing makes use of phone calls/VoIP

b)

Phishing deals with of debit/credit card frauds, while Vishing deals with theft of online banking related frauds

c)

A & B

d)

None of the above

65.

Which of the following usually observe each activity on the internet of the victim, gather all information in the background, and send it to someone else?

a)

Malware

b)

Spyware

c)

Adware

d)

All of the above

66.

_______ is a type of software designed to help the user's computer detect viruses and avoid them.

a)

Malware

b)

Adware

c)

Antivirus

d)

Both B and C

67.

What security threats do employee-owned devices pose by storing bank’s data and then accessing public networks?

a)

Data loss

b)

Potential customer privacy violation

c)

Potential for noncompliance

d)

All of the above

68.

Which of the following types of attacks do hackers use to gain information from you without the use of specialized computer programs?

a)

Cross site scripting

b)

Social engineering

c)

SQL Injection

d)

DDoS Attack

69.

You can use your official external email for personal purposes.

a)

True

b)

False

70.

Which of the following refers to the violation of the principle if a computer is no more accessible?

a)

Access control

b)

Confidentiality

c)

Availability

d)

All of the above

71.

How do you block your phone when stolen?

a)

If your phone is stolen or lost, you may report your IMEI number to the Police and block it.

b)

If your phone is stolen or lost, you may report to your network service provider

c)

Both A & B

d)

None of the above

72.

To protect the computer system against the hacker and different kind of viruses, one must always keep _________ on in the computer system.

a)

Antivirus

b)

Firewall

c)

VLC player

d)

Script

73.

What is the most common delivery method for viruses?

a)

Internet download

b)

Infected disk

c)

Instant messenger software

d)

Email

74.

hat do you think is a social engineering threat?

a)

Manipulation by fraudsters to get access to your private and sensitive information for committing frauds.

b)

Fraudsters making a scheme or plan to commit financial frauds.

c)

Fraudsters socially cheating general public by stealing their money.

d)

All of the above

75.

Hackers usually used the computer virus for ______ purpose.

a)

To log, monitor each and every user's stroke

b)

To gain access the sensitive information like user's Id and Passwords

c)

To corrupt the user's data stored in the computer system

d)

All of the above

76.

Which of the following is not an appropriate measure for securing your accounts?

a)

Using Strong passwords

b)

Link your account with a phone number

c)

Never write your password anywhere

d)

Always maintain a soft copy of all your passwords in your PC

77.

Which of the file types should never be opened when received through email?

a)

.EXE - executable file

b)

.BAT - batch file

c)

.VBS - VB Script file

d)

All of the above

78.

When was the first computer virus created?

a)

1970

b)

1971

c)

1972

d)

1969

79.

Mr. Anwar was travelling with his family, when he received an OTP for successful payment authentication through his credit card. Mr. Anwar was surprised as he had not used his credit card for any payment processing. Why do you think Mr. Anwar had received the OTP though he had not used his credit card andwhat can be done to safeguard himself from possible financial fraud?

a)

A fraudster might have got hold of his CVV and card number and is attempting to use it. Mr. Anwar should immediately call up the bank authorities to block his card and get a new card.

b)

A family/ friend might have used his card details for online purchase. He can ignore it.

c)

He might have mistakenly saved his credit card details in some website and must have auto saved it further use, which might be misused. He can block the card and get it reissued, and henceforth not auto save any details.

d)

Both A & C

80.

Which of the following is used to identify a website user and can be a vulnerability to your privacy if not cleared regularly?

a)

Pop-ups

b)

Plug-ins

c)

Cookies

d)

Scripts

81.

It is okay to input your official email address on any website, this won’t lead to spamming.

a)

True

b)

False

82.

What is the most COMMON method of social engineering?

a)

Phishing

b)

Pretexting

c)

Baiting

d)

Tailgating

83.

If your boss orders you to open your pc and log into your email so that he can send an email from your PC, you should just let him do it.

a)

True

b)

False

84.

A type of program that demands payment after launching a successful cyber-attack and encrypting necessary files.

a)

Virus

b)

Malware

c)

Ransomware

d)

Trojan

85.

Let IT people access your computer only if they are calling from an office IP phone.

a)

True

b)

Flase

86.

What are the ways in which the identity theft can be committed by the fraudsters?

a)

Through application fraud or account take over.

b)

By stealing the password of the user.

c)

By stealing the PIN/ OTP details

d)

All the above

87.

Which is the best way to protect the sensitive data in your computer when you leave your desk for lunch?

a)

Turn the monitor off

b)

Activate the screen saver

c)

Lock your computer with password

d)

Close all programs

88.

What are the possible effects of downloading files from links that offer you free games/ music/ screen savers etc.?

a)

Allowing malware, spyware, and other objectionable files to be downloaded on to your computer

b)

The device getting corrupted

c)

Breach of firewall. Also allow culprits to obtain private information/data from system

d)

All the above

89.

What is a recommended way of having a safe password?

a)

Choose a password that you can easily remember

b)

Use same password for all accounts

c)

Use a combination of letters, numbers and specials characters.

d)

Both A & B

90.

It is okay to open a fake online ID in the name of your boss who dumps too much work on you just to have some fun and teach him a lesson.

a)

True

b)

False

91.

What are the measures recommended in case you either doubt or find yourself to be victim of social engineering technique of fraudsters?

a)

Immediately change the passwords / OTP /PIN & report to the concerned authorities & keep track of any unusual or unknown financial operations.

b)

Change your SIM card and mobile phone.

c)

Inform your family members and ask them to be aware of any calls from fraudsters.

d)

All of the above

92.

Strong passwords can be difficult to remember. What can you do to avoid forgetting them?

a)

Use mnemonics (acronyms or phrases that are easy for you to remember)

b)

Develop a password strategy

c)

Write down the passwords in a notebook and store it in a safe place

d)

Both A & B.

93.

HTTPS websites are more secure than HTTP website.

a)

True

b)

False

94.

The E-mail attachments should not be opened in the following situation:

a)

When the e-mail is from someone you know who always forwards you jokes.

b)

The e-mail attachment is from somebody you do not know, but is an executable file as attachment.

c)

The e-mail attachment has “.doc, .exe, or .pdf” in the file name extension.

d)

None of the above.

95.

Mr. Adnan received an external mail that seemed to be from a counterpart from another branchof the bank. He was asking Mr. Adnan to allow him access through VNC as he needed to gather some information on the technical details to prepare for an important presentation required by the board of directors. He was claiming that it was the Head of the division who had provided him with Mr. Adnan’s mail ID. Could it be a social engineering tactic?If so, what isthis kind of social engineering technique called and what should Mr. Adnan do?

a)

Yes, it could be Pretexting and he should immediately cross verify with the Head of the Division.

b)

Yes, it could be Phishing and he should verify if the mail id is genuine or not.

c)

Yes, it could be Persuasion and he should simply delete the mail.

d)

No, it is not a social engineering tactic.

96.

If you’re working in your organization’s system/desktop/laptop and suddenly a window pops up asking you to restart your PC to update your security application, you should ignore it.

a)

True

b)

False

97.

I have a really strong password, so I should be able to use it for years.

a)

True

b)

False

98.

What is the private information you should never share over social media platforms?

a)

Financial information like details of debit card, credit card, bank account etc.

b)

Address, mobile number, date and place of birth, employee ID.

c)

Favorite food, music, movies, hobbies etc.

d)

Both A & B.

99.

How should you report a cyber-crime in the bank environment?

a)

You should immediately inform the management and if required, ITOD.

b)

You should post a warning message on the social media platforms.

c)

You should destroy the PC that has been attack.

d)

All of the above

100.

The informal code of positive conduct that is used whenever someone is connected to the Internet is called:

a)

Cyber Security

b)

Cyber Safety

c)

Cyber Ethics

d)

Cyber Hygiene