Font size
WorksheetsCyber Security Assessment for Bank Officials
Total questions: 100
Worksheet time: 50mins
What is the current version of Dutch-Bangla Bank ICT Operation and Security Policy?
Seventh Revision: April 2022
Eighth Revision: June 2022
First Version: November 2021
Tenth Revision: September 2022
Which of the following attacks requires a carrier file to self-replicate?
Trojan
Virus
Worm
Spam
Someone who is posing as an IT tech requests information about your computer configuration. What kind of attack is this?
Insider threat
Phishing
Social engineering
Whaling
You are allowed to share or print full card number, PIN, password, expiry date with everyone. True or False?
True
False
Which of the following describes monitoring software installed without your consent?
Malware
Adware
Spyware
Ransomware
Cyber criminals only target large companies. True or False?
True
False
Which of the following should you do to restrict access to business application?
Update your software once a year.
Share passwords only with colleagues you trust.
Have your staff members access information via an open Wi-Fi network.
Use multi-factor authentication.
Business application users are not disabled after 90 days of inactivity. True or False?
True
False
Backing up important files offline, on an external hard drive, will help protect your business in the event of a cyber-attack. True or False?
True
False
Which is the best answer for which people in a business should be responsible for cybersecurity?
Business owners. They run the business, so they need to know cybersecurity basics and put them in practice to reduce the risk of cyberattacks.
IT specialists, because they are in the best position to know about and promote cybersecurity within a business.
Managers, because they are responsible for making sure that staff members are following the right practices.
All Bank officials are responsible and should know about cybersecurity best practices
Branch and Divisional officials are allowed use removeable media. True or False
True
False
Which one of these statements is correct?
If you get an email that looks like it’s from someone you know, you can click on any links as long as you have a spam blocker and anti-virus protection.
You can trust an email really comes from a client if it uses the client’s logo and contains at least one fact about the client that you know to be true.
If you get a message from a colleague who needs your network password, you should never give it out unless the colleague says it’s an emergency.
If you get an email from HRD asking you to provide personal information right away, you should check it out first andbe sure of their identity.
Saving and sharing passwords is the best option to reduce hassles in everyday work. True or False?
True
False
An email from your boss asks for the name, addresses, and credit card information of the company’s top clients. The email says it’s urgent and to please reply right away. You should reply right away. True or False?
True
False
Dutch-Bangla Bank has an IT Operation and Security Policy. Is it True or False?
True
False
You get a text message from an IT personnel who asks you to click on a link to renew your password so that you can log in to its website. You should:
Reply to the text to confirm that you really need to renew your password.
Pick up the phone and call the person, using a phone number you know to be correct, to confirm that the request is real.
Click on the link. If it takes you to the website, then you’ll know it’s not a scam.
None of the above
If you fall for a phishing scam, what should you do to limit the damage?
Delete the phishing email.
Unplug the computer. This will get rid of any malware.
Change the password / PIN or block the account /Card immediately .
Nothing to do
You should respond very fast if someone calling from an unknown number claims to be the MD/ DMD/ CXO of the bank and asks you for some customer confidential information. There is no need to verify the caller.
True
False
Where should you write down your passwords?
Some place that can be easily seen from your desk.
Some place that is out of sight, like beneath your keyboard or a nearby drawer
On a diary in a secure locked cabinet
You should never write down your password
What is ransomware?
Malware that infects computer networks and mobile devices to hold your data hostage until you send the attackers money.
Computer equipment that criminals steal from you and won’t return until you pay them.
Software used to protect your computer or mobile device from harmful viruses.
A form of cryptocurrency.
Which of these best describes how criminals start ransomware attacks?
Sending a scam email with links or attachments that put your data and network at risk.
Getting into PC / Server through known vulnerabilities of the operating system / application and installing malware.
Using infected websites that automatically download malicious software to your computer / Server or mobile device.
All of the above.
If you encounter a ransomware attack, the first thing you should do is pay the ransom. True or False?
True
False
Paper files that have sensitive information should be disposed of in a locked trash bin. True or False?
True
False
Which one of the following is the best password?
TonyStark
qwertyui
12345678
AG&m4$J7
All branch and Division officials must ensure that all the PCs are covered by Antivirus /Antimalware Software. True or False?
True
False
Which one of these statements is true?
It’s best to use multi-factor authentication to access the business application with sensitive information.
You should use the same password for key business devices to guarantee that high-level employees can access them in an emergency.
The best way to protect business data is to make sure no one loses any device.
You shouldn’t limit login attempts on key business devices, because getting locked out for having too many incorrect attempts would leave you unable to access your accounts.
Dutch-Bangla Bank is currently PCI DSS certified. True or False?
True
False
Bank has published two versions of Dutch-Bangla Bank ICT Operation and Security Policy: the complete one and a shorter one. True or False?
True
False
Which of the following is the best answer for how to secure your password?
Change the default password
Make the password with upper & lower case, number and special character
Password must be eight characters
Don’t save the password on browser
All of the above
When receiving an email from an unknown contact that has a link, you should:
Open the link to view its contents
Report the suspicious email to IT Operation
Forward the email to your co-workers to allow them to open the link first
Forward the email to your personal email account so you can open it at home
There is a rumor going around that if you can upload the most amount of customer information in a day on a site through a link, the management will grant you an attractive reward. What will be the appropriate action for you?
You should inform all your colleagues and engage in a competition to win the reward
You should immediately report the matter to your reporting manager
Contact IT support and take their help.
Both B & C.
Which of the following circumstances should you treat as suspicious?
Flight information attachment from airline when no travel is planned
Request from Bank with a link to update information
Email from unknown sender with an urgent message requiring action like changing your password immediately
All of the above
An act to cripple, corrupt or threaten a system or network is characterized as which of the below?
Digital crime
Threats
System hijacking
Cyber Attack
What is a Trojan Horse?
Malfunction of the software that makes it difficult to navigate the Internet. Bottom of Form
Malicious software that allows other programs to control your computer by misleading users of its true intent
A web browser with advanced capability
Next generation antivirus
Who is responsible for Cyber Security?
ITSD
ITOD
Management
Everyone
The other day you were watching the news and you heard a journalist talking about a formof cyber-threat. Essentially criminals seem to be able to use malicious software to restrict users from accessing their computer system or personal files. Later criminals demand a payment in order for the restriction to be removed. What is the name of this threat?
Ransomware
Virus
Botnet
Trojan
When visiting your favorite website, a pop-up appears that reads "You have won a free Apple iPod!" What should you do?
Click the pop-up, enter your information and claim the prize
Share the link with all your friends and family so that they too can get free stuff
Do not click the pop-up - close it, and if possible, report it to IT Operation
Contact on the page you were on
Which website URL is legitimate?
Bank management have allowed the use of common name users (e.g., DBBL, ITOD) in special cases for accessing any business applications. True or False?
True
False
Mr. Jamal was referred to an online shopping site by a friend that was offering a luxury brand watch at a very lucrative price with exceptional discount with limited sale period. Mr. Jamal has been wanting to purchase the brand of watch since a long time and was quite eager to grab the offer. What are the aspects that Mr. Jamal should keep in mind and duly verify, before proceeding to make the online purchase?
He should verify - if the site is secured/trusted/original one(https/original URL); reviews about the site; customer reviews for product ; check for refund/return policy; whether COD option is given.
He should verify the brand , quality, color and size of the watch displayed on the site.
He should take the advice from his friends before he places the order for the watch.
None of the above.
You should never click on .exe files that you don’t recognize.
True
False
You receive an email from a co-worker with an attachment.The subject line reads "Please See Attached Document". The mail contains no further information. What should you do?
Open the attachment to get more information
Delete the email
Contact the apparent sender by phone or separate email to confirm the validity of the message
Both B&C
“Remember me” function of the web browsers or other applications are unsafe and should be avoided.
True
False
You receive a text message warning you that your bank account has been suspended. It says that you must click on the link in the SMS and update your credentials within the next 24 hours. Is this message safe or unsafe?
Safe
Unsafe
Dutch-Bangla Bank is currently not a Payment Card Industry Data Security Standard (PCI DSS) compliant Bank
True
False
How Does Temperature Affect The Performance of Computer Components?
High temperature may damage the hardware components of computer
High temperature may damage the hardware and software of the computer
I don’t think temperature will affect the performance of computer
Both A & B
You should leave your 2-FA token in an unlocked drawer in the office and share your password so that your colleague can continue your work in case of emergency.
True
False
Which of the following is NOT a smart way to test a suspicious link?
Use a free online tool to expand a shortened link and view the actual destination URL
Click on it
Use a link scanner tool
Hover over the link and view the destination URL that is displayed
Mr. Hossain received a message from his colleague Ms. Salma, saying she transferred an amount of Tk.3000/- upon his request over Facebook. Mr. Hossain was taken by surprise as he had not asked for any amount from Ms. Salma. How do you think Ms. Salma received that message and what action do you suggest Mr. Hossain from his end?
Ms. Salma must have mistakenly taken some other friends request for money transfer, to be from Mr. Hossain. Ms. Salma can ask Mr. Hossain to cross verify properly and inform the other friend.
It is a mystery how Ms. Salma got the message. Mr. Hossain can check his Facebook account and accordingly reply Ms. Salma.
It is possible as Mr. Hossain’s Facebook account has been taken over by a fraudster somehow. He should immediately check his account and if it is accessible, change his password. Otherwise, he should report to the Facebook helpdesk to try and regain access to his account. He should also inform his friends, colleagues, family members about the possible fraud.
Both A & B.
Using two-factor authentication is not an effective tool for securing your accounts.
True
False
What will you recommend your colleague who has been using one unique password for all his accounts for many years, but still no security breach has happened?
Will not recommend anything as no security breach has happened.
Tell your colleague to change the password regularly and use same password for all his account.
Tell your colleague to change the password regularly and use different passwords for different accounts.
Both A & B
It is not necessary to lock your PC if you are leaving your desk for only two minutes.
True
False
What is the only true guarantee against data loss due to a cyberattack such as ransomware?
My business is small - this isn't something I need to worry about
Having enough money to pay the ransom
Having my data backed up and accessible
Restricting internet access for my employees
Your password should be changed _
Never
Daily
Regularly
Hourly
You should try to install and uninstall software as per your requirement if you think you can do a better job than the people in ITOD.
True
False
You have received an email from your Manager with a zip file attached. What will you do?
Simply open the attachment and download the zip file and the unzip it since it is sent from a known person.
Look for the sender’s email ID, confirm from your manager/friend if they have sent the zip attachment and then open the file.
Both A & B.
None of the above.
Which of these is a possible cause of a data disaster?
A lost or stolen device or laptop
A Cyber-attack
The sprinkler system in the office malfunctioning
Equipment failure
All of the above
Cybersecurity is IT's responsibility. The everyday end-users in the office don't need to worry about this topic.
True
False
Make sure your computer’s ____________ is up-to-date to protect your system from malware, ransomware attacks.
Operating system
Hardware
Both
None of above
Software, Application and Antivirus / Anti-Malware updates are not important and can just be ignored.
True
False
You must write down your passwords on a paper and stick it to your PC monitor so that you don’t forget and get locked out of your PC.
True
False
Bank can take actions against you if you violate the IT security policies in place.
True
False
Which of the following is not an advantage of cyber security?
Makes the system a bit slower
Minimizes computer freezing and crashes
Gives privacy to users
Protects system against viruses
What is the difference between Vishing and Phishing?
Phishing is an online attempt to grab private information through mails, messages, links, attachments, while Vishing makes use of phone calls/VoIP
Phishing deals with of debit/credit card frauds, while Vishing deals with theft of online banking related frauds
A & B
None of the above
Which of the following usually observe each activity on the internet of the victim, gather all information in the background, and send it to someone else?
Malware
Spyware
Adware
All of the above
_______ is a type of software designed to help the user's computer detect viruses and avoid them.
Malware
Adware
Antivirus
Both B and C
What security threats do employee-owned devices pose by storing bank’s data and then accessing public networks?
Data loss
Potential customer privacy violation
Potential for noncompliance
All of the above
Which of the following types of attacks do hackers use to gain information from you without the use of specialized computer programs?
Cross site scripting
Social engineering
SQL Injection
DDoS Attack
You can use your official external email for personal purposes.
True
False
Which of the following refers to the violation of the principle if a computer is no more accessible?
Access control
Confidentiality
Availability
All of the above
How do you block your phone when stolen?
If your phone is stolen or lost, you may report your IMEI number to the Police and block it.
If your phone is stolen or lost, you may report to your network service provider
Both A & B
None of the above
To protect the computer system against the hacker and different kind of viruses, one must always keep _________ on in the computer system.
Antivirus
Firewall
VLC player
Script
What is the most common delivery method for viruses?
Internet download
Infected disk
Instant messenger software
hat do you think is a social engineering threat?
Manipulation by fraudsters to get access to your private and sensitive information for committing frauds.
Fraudsters making a scheme or plan to commit financial frauds.
Fraudsters socially cheating general public by stealing their money.
All of the above
Hackers usually used the computer virus for ______ purpose.
To log, monitor each and every user's stroke
To gain access the sensitive information like user's Id and Passwords
To corrupt the user's data stored in the computer system
All of the above
Which of the following is not an appropriate measure for securing your accounts?
Using Strong passwords
Link your account with a phone number
Never write your password anywhere
Always maintain a soft copy of all your passwords in your PC
Which of the file types should never be opened when received through email?
.EXE - executable file
.BAT - batch file
.VBS - VB Script file
All of the above
When was the first computer virus created?
1970
1971
1972
1969
Mr. Anwar was travelling with his family, when he received an OTP for successful payment authentication through his credit card. Mr. Anwar was surprised as he had not used his credit card for any payment processing. Why do you think Mr. Anwar had received the OTP though he had not used his credit card andwhat can be done to safeguard himself from possible financial fraud?
A fraudster might have got hold of his CVV and card number and is attempting to use it. Mr. Anwar should immediately call up the bank authorities to block his card and get a new card.
A family/ friend might have used his card details for online purchase. He can ignore it.
He might have mistakenly saved his credit card details in some website and must have auto saved it further use, which might be misused. He can block the card and get it reissued, and henceforth not auto save any details.
Both A & C
Which of the following is used to identify a website user and can be a vulnerability to your privacy if not cleared regularly?
Pop-ups
Plug-ins
Cookies
Scripts
It is okay to input your official email address on any website, this won’t lead to spamming.
True
False
What is the most COMMON method of social engineering?
Phishing
Pretexting
Baiting
Tailgating
If your boss orders you to open your pc and log into your email so that he can send an email from your PC, you should just let him do it.
True
False
A type of program that demands payment after launching a successful cyber-attack and encrypting necessary files.
Virus
Malware
Ransomware
Trojan
Let IT people access your computer only if they are calling from an office IP phone.
True
Flase
What are the ways in which the identity theft can be committed by the fraudsters?
Through application fraud or account take over.
By stealing the password of the user.
By stealing the PIN/ OTP details
All the above
Which is the best way to protect the sensitive data in your computer when you leave your desk for lunch?
Turn the monitor off
Activate the screen saver
Lock your computer with password
Close all programs
What are the possible effects of downloading files from links that offer you free games/ music/ screen savers etc.?
Allowing malware, spyware, and other objectionable files to be downloaded on to your computer
The device getting corrupted
Breach of firewall. Also allow culprits to obtain private information/data from system
All the above
What is a recommended way of having a safe password?
Choose a password that you can easily remember
Use same password for all accounts
Use a combination of letters, numbers and specials characters.
Both A & B
It is okay to open a fake online ID in the name of your boss who dumps too much work on you just to have some fun and teach him a lesson.
True
False
What are the measures recommended in case you either doubt or find yourself to be victim of social engineering technique of fraudsters?
Immediately change the passwords / OTP /PIN & report to the concerned authorities & keep track of any unusual or unknown financial operations.
Change your SIM card and mobile phone.
Inform your family members and ask them to be aware of any calls from fraudsters.
All of the above
Strong passwords can be difficult to remember. What can you do to avoid forgetting them?
Use mnemonics (acronyms or phrases that are easy for you to remember)
Develop a password strategy
Write down the passwords in a notebook and store it in a safe place
Both A & B.
HTTPS websites are more secure than HTTP website.
True
False
The E-mail attachments should not be opened in the following situation:
When the e-mail is from someone you know who always forwards you jokes.
The e-mail attachment is from somebody you do not know, but is an executable file as attachment.
The e-mail attachment has “.doc, .exe, or .pdf” in the file name extension.
None of the above.
Mr. Adnan received an external mail that seemed to be from a counterpart from another branchof the bank. He was asking Mr. Adnan to allow him access through VNC as he needed to gather some information on the technical details to prepare for an important presentation required by the board of directors. He was claiming that it was the Head of the division who had provided him with Mr. Adnan’s mail ID. Could it be a social engineering tactic?If so, what isthis kind of social engineering technique called and what should Mr. Adnan do?
Yes, it could be Pretexting and he should immediately cross verify with the Head of the Division.
Yes, it could be Phishing and he should verify if the mail id is genuine or not.
Yes, it could be Persuasion and he should simply delete the mail.
No, it is not a social engineering tactic.
If you’re working in your organization’s system/desktop/laptop and suddenly a window pops up asking you to restart your PC to update your security application, you should ignore it.
True
False
I have a really strong password, so I should be able to use it for years.
True
False
What is the private information you should never share over social media platforms?
Financial information like details of debit card, credit card, bank account etc.
Address, mobile number, date and place of birth, employee ID.
Favorite food, music, movies, hobbies etc.
Both A & B.
How should you report a cyber-crime in the bank environment?
You should immediately inform the management and if required, ITOD.
You should post a warning message on the social media platforms.
You should destroy the PC that has been attack.
All of the above
The informal code of positive conduct that is used whenever someone is connected to the Internet is called:
Cyber Security
Cyber Safety
Cyber Ethics
Cyber Hygiene
