wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cyber Security Awareness 2025

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

1. What is phishing?

a)

a) A method of catching fish

b)

b) A tactic to distribute malware or steal personal information

c)

c) A process of encrypting data

d)

d) A type of software for email filtering

2.

2. What is the main difference between phishing and spear phishing?

a)

a) Phishing is targeted, while spear phishing is random

b)

b) Spear phishing targets specific individuals, while phishing is broad

c)

c) Phishing requires social media, spear phishing does not

d)

d) Spear phishing is more common than phishing

3.

3. Which of the following is a common sign of a phishing email?

a)

a) Perfect grammar and spelling

b)

b) A familiar sender name with an unfamiliar email address

c)

c) Random emojis in the email

d)

d) No links in the email

4.

4. What should you do if you receive a suspicious email with a link?

a)

a) Click it to check if it's real

b)

b) Forward it to everyone in your office

c)

c) Delete it immediately without checking

d)

d) Manually type the website’s URL in your browser

5.

5. Which of the following is NOT a best practice to avoid phishing?

a)

a) Checking the email sender's domain

b)

b) Mouse-hovering over links before clicking

c)

c) Immediately downloading all attachments

d)

d) Contacting IT security if unsure

6.

6. Why are email attachments a common way for malware to spread?

a)

a) They often look like harmless files but contain malicious code

b)

b) They can automatically execute malware upon opening

c)

c) Attackers can use them to steal information

d)

d) All of the above

7.

7. What should you do if you receive an unexpected email attachment?

a)

a) Open it immediately to check its contents

b)

b) Verify with the sender if they sent it

c)

c) Delete it without checking

d)

d) Save it for later

8.

8. What is a possible sign that an email attachment is malicious?

a)

a) The sender has an official company email

b)

b) It has an urgent message asking you to open it

c)

c) It’s in PDF format

d)

d) It comes from a co-worker

9.

9. What happens when you open a spam email?

a)

a) It confirms your email address is active to spammers

b)

b) It immediately infects your computer with a virus

c)

c) It deletes your inbox messages

d)

d) It encrypts your files

10.

10. Which is the best way to handle spam emails?

a)

a) Respond and ask to be removed from the mailing list

b)

b) Mark them as spam and delete them

c)

c) Forward them to your friends

d)

d) Click any links to check their content

11.

11. Why is using real answers for security questions risky?

a)

a) They are too easy to remember

b)

b) They are often available on social media

c)

c) They are required for password recovery

d)

d) They make accounts more secure

12.

12. What is the best practice when answering security questions?

a)

a) Use your real information

b)

b) Choose unique, false answers

c)

c) Always use the same answer

d)

d) Leave them blank

13.

13. Which of the following is an example of poor password hygiene?

a)

a) Using a unique password for each account

b)

b) Writing passwords on a sticky note under your keyboard

c)

c) Using a password manager

d)

d) Enabling two-factor authentication

14.

14. Why is changing passwords every 90 days important?

a)

a) It improves typing speed

b)

b) It helps prevent unauthorized access if a password is stolen

c)

c) It confuses hackers

d)

d) It makes passwords easier to remember

15.

15. What does two-factor authentication (2FA) require?

a)

a) Two different passwords

b)

b) A password plus a second verification method

c)

c) A backup email

d)

d) A physical token

16.

16. Why is SMS-based 2FA less secure than app-based 2FA?

a)

a) Text messages can be intercepted

b)

b) Apps are harder to install

c)

c) Texts are more convenient

d)

d) SMS messages cost money

17.

17. Which of the following is NOT a type of malware?

a)

a) Ransomware

b)

b) Trojan

c)

c) Firewall

d)

d) Spyware

18.

18. What is ransomware?

a)

a) A virus that steals banking information

b)

b) Malware that locks files and demands payment

c)

c) Software that speeds up your computer

d)

d) A security tool

19.

19. Why is public Wi-Fi considered dangerous?

a)

a) Hackers can set up fake networks

b)

b) Data sent over public Wi-Fi can be intercepted

c)

c) Attackers can steal login credentials

d)

d) All of the above

20.

20. How can you securely use the internet in public places?

a)

a) Use a VPN

b)

b) Connect to any available Wi-Fi

c)

c) Disable your antivirus

d)

d) Click on all pop-ups

21.

21. What is an IoT device?

a)

a) A traditional desktop computer

b)

b) A device like a smart thermostat or doorbell

c)

c) A USB drive

d)

d) A regular landline phone

22.

22. Why should you change the default password on IoT devices?

a)

a) The default password is often known to hackers

b)

b) It makes logging in easier

c)

c) It prevents software updates

d)

d) It helps share access with others

23.

23. What does HTTPS ensure?

a)

a) The website is safe to use

b)

b) The connection between you and the website is encrypted

c)

c) The website is free from malware

d)

d) Your device is updated

24.

24. Where should you check if a website is secure?

a)

a) The website’s footer

b)

b) The browser’s address bar

c)

c) The website’s background color

d)

d) The webpage’s text

25.

25. What is social engineering?

a)

a) A social networking feature

b)

b) A tactic used to manipulate people into giving out information

c)

c) A cybersecurity tool

d)

d) A type of firewall

26.

26. How can you prevent social engineering attacks?

a)

a) Verify caller identities before sharing information

b)

b) Always trust emails from your CEO

c)

c) Give out information if someone insists

d)

d) Ignore security policies

27.

27. What is an insider threat?

a)

a) An attack from a hacker

b)

b) A threat from someone within an organization

c)

c) A phishing attempt

d)

d) A spam email

28.

28. What is the primary goal of a firewall?

a)

a) To physically block unauthorized users

b)

b) To filter incoming and outgoing network traffic

c)

c) To create strong passwords

d)

d) To back up your data

29.

29. What should you do if your device is infected with malware?

a)

a) Ignore it and keep working

b)

b) Immediately inform your IT department

c)

c) Click on random pop-ups offering a solution

d)

d) Disable antivirus software

30.

30. How can you protect your personal and work devices from malware?

a)

a) Install antivirus and update software regularly

b)

b) Click on all pop-up advertisements

c)

c) Use public Wi-Fi whenever possible

d)

d) Disable security updates

31.

31. What is the best way to create a strong password?

a)

a) Use a mix of letters, numbers, and symbols

b)

b) Use your name and birthdate for easy recall

c)

c) Use "password123" as it is commonly accepted

d)

d) Use the same password for all accounts

32.

32. Which of the following is NOT a sign of a phishing attempt?

a)

a) Urgent language demanding immediate action

b)

b) Links to a website that looks slightly different from a real one

c)

c) A personal email from a colleague you regularly communicate with

d)

d) Unexpected attachments from unknown senders

33.

33. Why should employees follow the company’s Acceptable Use Policy (AUP)?

a)

a) To ensure compliance with cybersecurity best practices

b)

b) To avoid workplace productivity

c)

c) To freely share information with third parties

d)

d) To use personal social media on company devices

34.

34. What is an effective way to protect sensitive company data?

a)

a) Use encrypted communication and access controls

b)

b) Share passwords with trusted coworkers

c)

c) Print out all sensitive documents for safekeeping

d)

d) Keep confidential data stored on USB drives without encryption

35.

35. How can you recognize a fake website?

a)

a) It contains poor spelling and grammar

b)

b) The URL is slightly misspelled

c)

c) It lacks HTTPS in the address bar

d)

d) All of the above

36.

36. Why should you avoid downloading software from unknown sources?

a)

a) It may contain hidden malware

b)

b) It will always be expensive

c)

c) It requires a fast internet connection

d)

d) It may not install correctly

37.

37. What is one major risk of using weak passwords?

a)

a) They can be easily guessed by attackers

b)

b) They help you log in faster

c)

c) They are easy to remember

d)

d) They improve cybersecurity

38.

38. How can employees contribute to reducing cybersecurity risks?

a)

a) Ignoring IT security updates

b)

b) Following security policies and reporting suspicious activity

c)

c) Using the same password for all work accounts

d)

d) Clicking on unknown links in emails

39.

39. What is the safest way to store passwords?

a)

a) Writing them in a notebook

b)

b) Saving them in a password manager

c)

c) Keeping them on a sticky note under your keyboard

d)

d) Sharing them with a trusted colleague

40.

40. What should you do if you suspect your company is experiencing a cybersecurity breach?

a)

a) Keep working and wait for someone else to report it

b)

b) Inform the IT security team immediately

c)

c) Ignore the issue if your computer is working fine

d)

d) Post about it on social media to warn others