WorksheetsINFORMATION SECURITY POLICY
Total questions: 3
Worksheet time: 2mins
Case 1: Phishing Attack
An employee receives an email asking them to reset their password using a suspicious link. The employee is unsure whether to click on it. What should the employee do?
A) Click on the link to see if it is legitimate.
B) Report the email to the security team.
C) Ignore the email and delete it without doing anything.
D) Reply to the sender asking for more information.
Case 2: Unauthorized Access
A team member notices that someone has attempted to log into the company’s systems with an unauthorized user account.
What should the security team do first?
A) Block all user accounts.
B) Investigate and confirm if there was a security breach.
C) Immediately inform the management team.
D) Restart all the servers.
Case 3: Data Leak
Sensitive company information was accidentally shared via email with a client who is not authorized to view it.
What should the IT team do to resolve the issue?
A) Contact the client and ask them to delete the email.
B) Immediately notify the security team and follow the data breach protocol.
C) Temporarily shut down the email server.
D) Do nothing, as it was a small mistake.
