NEW
Font size
WorksheetsCraft Silicon IT Security Awareness Test
Total questions: 18
Worksheet time: 9mins
What is phishing, and how does it differ from other cyber threats?
A computer virus
Social media manipulation
Deceptive attempts to trick individuals into revealing sensitive information
What are some common tactics used by phishers to manipulate individuals?
Urgency and fear
Positive reinforcement
Entertainment and humour
What are some safe email habits that individuals can adopt to avoid falling victim to phishing?
Click on links from known senders
Download attachments from unfamiliar emails
Verify email sender addresses and avoid clicking on suspicious links
How can you identify a phishing URL, and why is it crucial to verify website addresses?
Ignore website addresses
Click on any link and assess the website later
Verify URLs by checking for spelling mistakes and using HTTPS
Attackers often use email attachments as a method for phishing. What is the risk associated with opening attachments from unknown or suspicious emails?
No risk, as email attachments are always safe to open
Risk of spreading positive content
Risk of downloading malware or viruses onto your device
You receive an email from the group CEO, which email would you respond to?
kamal@craftsi1icon.com
kamal@craftsilicon.com
kama1@craftsiIicon.com
kamaI@craftsiIicon.com
Define social engineering and provide examples of how it can be used in cyber attacks.
A type of computer programming that helps protect from cyber attacks
Manipulating individuals to gain confidential information
A form of networking and socialisation
Why is impersonation a common social engineering tactic, and how can individuals verify someone's identity?
Impersonation is rarely used in social engineering
By not questioning anyone's identity
Verifying identity through multiple channels
How can oversharing on social media contribute to social engineering attacks?
It has no impact on security
Enhances online privacy
Provides attackers with personal information
Why is it essential to verify unexpected requests for sensitive information, even if they seem to come from trusted sources?
It's not necessary to verify such requests
To avoid inconvenience
To prevent falling victim to phishing attacks
Discuss the importance of physical security in preventing unauthorized access to facilities and devices.
Physical security is irrelevant in cybersecurity
It prevents tailgating
It only applies to online activities
Why is IT security awareness training important for individuals in an organization?
It saves the company on cost
Enhances job performance only
Helps protect against cyber threats and promotes a secure work environment
In the context of incident response, what is the significance of promptly reporting security incidents?
Allows for a timely and effective response to mitigate potential damage
It helps to cover up the incident
Reporting is not necessary
It protects you from being blamed
As part of IT security best practices, what is recommended for creating strong passwords?
Using the same password for multiple accounts
Including personal information in passwords
Using a combination of uppercase, lowercase, numbers, and symbols
Using password managers
What does Two-Factor Authentication (2FA) add to the security of online accounts?
Provides an additional layer of security beyond passwords
Slows down the login process
It makes accounts more vulnerable
It makes harder to login
Whose responsibility is it to maintain a security-conscious culture within an organization?
The IT department
Everyone in the organization
senior management
Developers and Accounts
What is a recommended practice for enhancing security on mobile devices?
Disable all security features
Install apps from unofficial sources
Enable device passcodes or biometric authentication
In the context of social engineering, what is the primary defense against manipulation tactics?
Always trust unsolicited messages
Vigilance and verifying requests through trusted channels
Regularly update personal information online
