NEW
Font size
Worksheets2nd Quarter Security Training Quiz
Total questions: 40
Worksheet time: 20mins
Which of the following best explains why AI-enhanced scams are more dangerous than traditional scams?
They are only focused on stealing passwords.
They rely solely on malware and hacking software.
They can mimic trusted voices, create realistic content, and exploit emotions in real time.
They are limited to phishing emails with grammar mistakes.
A member insists on wiring funds immediately but appears nervous, won’t explain why, and says it’s for a “private emergency.” What should you do first as a teller or MSR?
Complete the transaction as quickly as possible.
Flag your supervisor and ask clarifying questions.
Call the recipient to verify the emergency.
Refuse the transaction and close the member’s account.
What is an example of a procedural gap that scammers might exploit at a financial institution?
A member is unfamiliar with how phishing scams work.
A teller does not know the correct steps to take when a transaction seems suspicious.
A voice scam uses an AI-generated impersonation.
A member panics due to a fake police threat.
Which of the following would most likely indicate synthetic identity fraud?
A member withdraws large cash amounts frequently.
A check is returned unpaid after three business days.
A member asks to add a joint owner to an existing loan.
A new account has a Social Security number tied to multiple addresses and no verified employment history.
What is the most accurate definition of “exploiting the gap” in the context of financial scams?
Scammers are looking for faster internet access to complete transactions.
Scammers act during non-business hours to avoid being caught.
Scammers take advantage of what victims or institutions don’t yet know, understand, or expect.
Scammers target only rural institutions with fewer fraud resources.
What makes elder financial abuse particularly difficult to detect?
Staff are not required to engage with elder members
Most cases involve international banking
It always involves physical threats
Members often feel embarrassed or afraid to report it
A member who never used online banking suddenly makes several large Zelle payments. What should staff do first?
Disable their online banking access
Accuse the member of violating fraud policy
Observe and document the behavior
Freeze the account immediately
Which transaction request should raise a red flag for possible exploitation?
Paying a utility bill
Transferring to a linked account
Cashing a check payable to a family member with no explanation
Making a loan payment
What is the correct way to begin asking clarifying questions when concerned about a transaction?
“This seems suspicious, can you prove it’s not?”
“Who told you to do this?”
“Why are you giving away your money?”
“Can you help me understand what this transaction is for?”
What is a key reason for documenting suspected financial exploitation?
For internal compliance and potential reporting
For marketing analysis
To protect the teller from legal liability
So all branches know about the situation
Which scam typically includes requests for remote access to a member’s computer?
Romance Scam
Lottery Scam
Government Impersonator
Tech Support Scam
How should staff handle a situation where a controlling individual refuses to let a member speak during a transaction?
Ignore it to avoid confrontation
Process the transaction to avoid delay
Ask the member to step aside for a private verification
Ask the member to fill out a complaint form
Why are repeated requests for the same transaction a red flag?
It means the member wants to do the same transaction over and over
It indicates the member lacks technical knowledge
It shows potential memory issues or outside pressure
It’s usually an error with the system
If you suspect fraud but the member is unwilling to speak, which of the following is a recommended action?
Flag their account
Report to a supervisor or compliance officer immediately
Call law enforcement without internal review
Alert the accompanying person of your concerns
A member’s savings balance is $3. What must be done before disbursing check funds?
Disburse only the remaining balance
Add $2 to meet minimum and proceed
Offer a partial check cashing service
Deposit funds to restore the $5 membership minimum
What must always occur when cashing an On Us check over $1,000 for a non-member?
Apply a non-member fee
Complete a Member Contact entry
Verify check details directly with the issuing member
Have the check notarized
Which red flag behavior could indicate a romance scam?
Member discusses buying property with their spouse
Member purchases a new car in cash
Member applies for a HELOC with a family member
Member sends money to someone they’ve never met in person
If a member has been negative for over 30 days and doesn’t have ODP, what is required?
Allow partial payment
Refer to Collections and require full payment
Refuse all transactions
Suspend mobile banking access
When processing a HELOC advance at a branch (not the Main Office), what is required if the member doesn’t have a check?
Refer the member to the Main Office
Offer a Line of Credit Add-On through Sharetec on the tellerline
Involve a loan officer or branch manager for documentation
Refuse the transaction
What is one appropriate way to offer discreet help to a potentially exploited elder member?
Suggest they visit another branch
Call a family member without the member’s permission
Provide them with a printed brochure about common scams
Inform the media
What is the teller’s role if a non-member brings in a $3,000 On Us check?
Process the item quickly to avoid delays
Refuse the item without further review
Refer the non-member to their own financial institution
Get their supervisor immediately
What is the best follow-up step after verifying an On Us check with the issuing member?
Print a receipt and send them to Lending
Document the verification in Sharetec using Member Contact
Archive the check and shred the copy
Escalate it to the branch manager only
A member walks in visibly frustrated about a declined card. What is the best way to use the S.E.R.V.I.C.E. Skill "Enthusiasm" to de-escalate?
Remind them of card limits in a flat tone
Smile, listen attentively, and offer help with a positive attitude
Smile and offer to help them but let them know it isn't LorMet's fault
Tell them to come back when they’re calmer
Why is verifying Overdraft Privilege (ODP) status important before discussing payments with members?
It determines if partial payments are allowed
It helps track transaction limits
It is required for all new account setups
It prevents internal audit reviews
A senior member who has always done in-person banking begins initiating large online transfers and appears increasingly anxious during branch visits. A younger companion now accompanies them and answers most of the questions. As a frontline employee, what is the most appropriate sequence of actions to take, following credit union best practices?
Escalate immediately to Adult Protective Services and freeze the member’s account
Refuse the transaction, separate the member, and contact law enforcement
Observe and document behaviors, attempt private clarification with the member, then escalate internally
Complete the transaction normally to avoid member conflict, but notify your supervisor after the member leaves
What is the most common method cybercriminals use to deliver ransomware to a target’s system?
Physical USB drops
Social media posts
Phishing emails with malicious attachments or links
Drive-by downloads from antivirus websites
What is one reason ransomware has become a preferred tool for cybercriminals?
It’s easy for the victim to reverse
It allows for immediate visibility and psychological pressure
It requires physical access to the victim’s system
It can only target outdated operating systems
Which of the following behaviors would most likely prevent falling victim to ransomware?
Relying on your firewall for all protection
Backing up files once a month
Installing a VPN on your mobile device
Verifying links before clicking and avoiding unknown attachments
During a ransomware infection, which of the following is not a best practice?
Immediately disconnect the device from the network
Report the incident to Stephen/Upper management
Preserve evidence for forensic analysis
Attempt to pay the ransom through Bitcoin
Which attack vector would be most consistent with the concept of social engineering in Security Awareness Foundations?
A fake software update on a website
A person calling IT support while impersonating an employee
A brute-force attack using password software
An attacker disabling antivirus via terminal
What is a key difference between phishing and vishing?
Phishing uses texts, vishing uses email
Phishing targets software, vishing targets hardware
Vishing is done via voice calls, phishing is typically email-based
Vishing attacks always involve ransom
Ava in Cyberspace Mars gave up her login information during a vishing attack. Which cybersecurity principle did she fail to follow?
Multi-factor authentication
Physical device encryption
Password reuse
Verifying identity before sharing personal information
What type of data is commonly targeted in ransomware attacks?
Personal files, financial records, and proprietary business data
Browser history and cookies
System fonts and audio drivers
Screen resolution settings
Which of the following is not considered personally identifiable information (PII)?
Social Security Number
IP address range
Employee ID badge photo
Home address
Which of the following could be an indicator of a vishing attempt?
The caller rushes you and asks you to verify private account info
The caller is friendly and offers you a discount
The caller sends a follow-up email
The caller calls from a familiar area code
What is one way cybercriminals increase success rates in ransomware campaigns?
Using highly technical scripts
Embedding malware in browser bookmarks
Targeting only CEOs and executives
Targeting users with personalized or believable emails
Why is having up-to-date backups crucial in protecting against ransomware?
It prevents social engineering attempts
It avoids needing to contact IT
It allows data recovery without paying ransom
It reduces phishing success
What does Sergeant Vasquez emphasize as a major ransomware risk in the training on Knowbe4?
Weak encryption tools
Human error and untrained users
Internal fraud
USB flash drives left in parking lots
Which of the following would be a poor response to a suspected vishing call?
Hang up and call the official number on file
Take notes on the caller and report it to IT
Ask the caller for more personal details to verify them
Refuse to provide any personal information
Which combination of actions would best protect a user from ransomware, phishing, and vishing threats?
Use incognito mode and update your wallpaper
Ignore spam folders and auto-click URLs
Use public Wi-Fi to avoid detection
Be cautious with unknown links, calls, and keep backups
