wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

2nd Quarter Security Training Quiz

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

Which of the following best explains why AI-enhanced scams are more dangerous than traditional scams?

a)

They are only focused on stealing passwords.

b)

They rely solely on malware and hacking software.

c)

They can mimic trusted voices, create realistic content, and exploit emotions in real time.

d)

They are limited to phishing emails with grammar mistakes.

2.

A member insists on wiring funds immediately but appears nervous, won’t explain why, and says it’s for a “private emergency.” What should you do first as a teller or MSR?

a)

Complete the transaction as quickly as possible.

b)

Flag your supervisor and ask clarifying questions.

c)

Call the recipient to verify the emergency.

d)

Refuse the transaction and close the member’s account.

3.

What is an example of a procedural gap that scammers might exploit at a financial institution?

a)

A member is unfamiliar with how phishing scams work.

b)

A teller does not know the correct steps to take when a transaction seems suspicious.

c)

A voice scam uses an AI-generated impersonation.

d)

A member panics due to a fake police threat.

4.

Which of the following would most likely indicate synthetic identity fraud?

a)

A member withdraws large cash amounts frequently.

b)

A check is returned unpaid after three business days.

c)

A member asks to add a joint owner to an existing loan.

d)

A new account has a Social Security number tied to multiple addresses and no verified employment history.

5.

What is the most accurate definition of “exploiting the gap” in the context of financial scams?

a)

Scammers are looking for faster internet access to complete transactions.

b)

Scammers act during non-business hours to avoid being caught.

c)

Scammers take advantage of what victims or institutions don’t yet know, understand, or expect.

d)

Scammers target only rural institutions with fewer fraud resources.

6.

What makes elder financial abuse particularly difficult to detect?

a)

Staff are not required to engage with elder members

b)

Most cases involve international banking

c)

It always involves physical threats

d)

Members often feel embarrassed or afraid to report it

7.

A member who never used online banking suddenly makes several large Zelle payments. What should staff do first?

a)

Disable their online banking access

b)

Accuse the member of violating fraud policy

c)

Observe and document the behavior

d)

Freeze the account immediately

8.

Which transaction request should raise a red flag for possible exploitation?

a)

Paying a utility bill

b)

Transferring to a linked account

c)

Cashing a check payable to a family member with no explanation

d)

Making a loan payment

9.

What is the correct way to begin asking clarifying questions when concerned about a transaction?

a)

“This seems suspicious, can you prove it’s not?”

b)

“Who told you to do this?”

c)

“Why are you giving away your money?”

d)

“Can you help me understand what this transaction is for?”

10.

What is a key reason for documenting suspected financial exploitation?

a)

For internal compliance and potential reporting

b)

For marketing analysis

c)

To protect the teller from legal liability

d)

So all branches know about the situation

11.

Which scam typically includes requests for remote access to a member’s computer?

a)

Romance Scam

b)

Lottery Scam

c)

Government Impersonator

d)

Tech Support Scam

12.

How should staff handle a situation where a controlling individual refuses to let a member speak during a transaction?

a)

Ignore it to avoid confrontation

b)

Process the transaction to avoid delay

c)

Ask the member to step aside for a private verification

d)

Ask the member to fill out a complaint form

13.

Why are repeated requests for the same transaction a red flag?

a)

It means the member wants to do the same transaction over and over

b)

It indicates the member lacks technical knowledge

c)

It shows potential memory issues or outside pressure

d)

It’s usually an error with the system

14.

If you suspect fraud but the member is unwilling to speak, which of the following is a recommended action?

a)

Flag their account

b)

Report to a supervisor or compliance officer immediately

c)

Call law enforcement without internal review

d)

Alert the accompanying person of your concerns

15.

A member’s savings balance is $3. What must be done before disbursing check funds?

a)

Disburse only the remaining balance

b)

Add $2 to meet minimum and proceed

c)

Offer a partial check cashing service

d)

Deposit funds to restore the $5 membership minimum

16.

What must always occur when cashing an On Us check over $1,000 for a non-member?

a)

Apply a non-member fee

b)

Complete a Member Contact entry

c)

Verify check details directly with the issuing member

d)

Have the check notarized

17.

Which red flag behavior could indicate a romance scam?

a)

Member discusses buying property with their spouse

b)

Member purchases a new car in cash

c)

Member applies for a HELOC with a family member

d)

Member sends money to someone they’ve never met in person

18.

If a member has been negative for over 30 days and doesn’t have ODP, what is required?

a)

Allow partial payment

b)

Refer to Collections and require full payment

c)

Refuse all transactions

d)

Suspend mobile banking access

19.

When processing a HELOC advance at a branch (not the Main Office), what is required if the member doesn’t have a check?

a)

Refer the member to the Main Office

b)

Offer a Line of Credit Add-On through Sharetec on the tellerline

c)

Involve a loan officer or branch manager for documentation

d)

Refuse the transaction

20.

What is one appropriate way to offer discreet help to a potentially exploited elder member?

a)

Suggest they visit another branch

b)

Call a family member without the member’s permission

c)

Provide them with a printed brochure about common scams

d)

Inform the media

21.

What is the teller’s role if a non-member brings in a $3,000 On Us check?

a)

Process the item quickly to avoid delays

b)

Refuse the item without further review

c)

Refer the non-member to their own financial institution

d)

Get their supervisor immediately

22.

What is the best follow-up step after verifying an On Us check with the issuing member?

a)

Print a receipt and send them to Lending

b)

Document the verification in Sharetec using Member Contact

c)

Archive the check and shred the copy

d)

Escalate it to the branch manager only

23.

A member walks in visibly frustrated about a declined card. What is the best way to use the S.E.R.V.I.C.E. Skill "Enthusiasm" to de-escalate?

a)

Remind them of card limits in a flat tone

b)

Smile, listen attentively, and offer help with a positive attitude

c)

Smile and offer to help them but let them know it isn't LorMet's fault

d)

Tell them to come back when they’re calmer

24.

Why is verifying Overdraft Privilege (ODP) status important before discussing payments with members?

a)

It determines if partial payments are allowed

b)

It helps track transaction limits

c)

It is required for all new account setups

d)

It prevents internal audit reviews

25.

A senior member who has always done in-person banking begins initiating large online transfers and appears increasingly anxious during branch visits. A younger companion now accompanies them and answers most of the questions. As a frontline employee, what is the most appropriate sequence of actions to take, following credit union best practices?

a)

Escalate immediately to Adult Protective Services and freeze the member’s account

b)

Refuse the transaction, separate the member, and contact law enforcement

c)

Observe and document behaviors, attempt private clarification with the member, then escalate internally

d)

Complete the transaction normally to avoid member conflict, but notify your supervisor after the member leaves

26.

What is the most common method cybercriminals use to deliver ransomware to a target’s system?

a)

Physical USB drops

b)

Social media posts

c)

Phishing emails with malicious attachments or links

d)

Drive-by downloads from antivirus websites

27.

What is one reason ransomware has become a preferred tool for cybercriminals?

a)

It’s easy for the victim to reverse

b)

It allows for immediate visibility and psychological pressure

c)

It requires physical access to the victim’s system

d)

It can only target outdated operating systems

28.

Which of the following behaviors would most likely prevent falling victim to ransomware?

a)

Relying on your firewall for all protection

b)

Backing up files once a month

c)

Installing a VPN on your mobile device

d)

Verifying links before clicking and avoiding unknown attachments

29.

During a ransomware infection, which of the following is not a best practice?

a)

Immediately disconnect the device from the network

b)

Report the incident to Stephen/Upper management

c)

Preserve evidence for forensic analysis

d)

Attempt to pay the ransom through Bitcoin

30.

Which attack vector would be most consistent with the concept of social engineering in Security Awareness Foundations?

a)

A fake software update on a website

b)

A person calling IT support while impersonating an employee

c)

A brute-force attack using password software

d)

An attacker disabling antivirus via terminal

31.

What is a key difference between phishing and vishing?

a)

Phishing uses texts, vishing uses email

b)

Phishing targets software, vishing targets hardware

c)

Vishing is done via voice calls, phishing is typically email-based

d)

Vishing attacks always involve ransom

32.

Ava in Cyberspace Mars gave up her login information during a vishing attack. Which cybersecurity principle did she fail to follow?

a)

Multi-factor authentication

b)

Physical device encryption

c)

Password reuse

d)

Verifying identity before sharing personal information

33.

What type of data is commonly targeted in ransomware attacks?

a)

Personal files, financial records, and proprietary business data

b)

Browser history and cookies

c)

System fonts and audio drivers

d)

Screen resolution settings

34.

Which of the following is not considered personally identifiable information (PII)?

a)

Social Security Number

b)

IP address range

c)

Employee ID badge photo

d)

Home address

35.

Which of the following could be an indicator of a vishing attempt?

a)

The caller rushes you and asks you to verify private account info

b)

The caller is friendly and offers you a discount

c)

The caller sends a follow-up email

d)

The caller calls from a familiar area code

36.

What is one way cybercriminals increase success rates in ransomware campaigns?

a)

Using highly technical scripts

b)

Embedding malware in browser bookmarks

c)

Targeting only CEOs and executives

d)

Targeting users with personalized or believable emails

37.

Why is having up-to-date backups crucial in protecting against ransomware?

a)

It prevents social engineering attempts

b)

It avoids needing to contact IT

c)

It allows data recovery without paying ransom

d)

It reduces phishing success

38.

What does Sergeant Vasquez emphasize as a major ransomware risk in the training on Knowbe4?

a)

Weak encryption tools

b)

Human error and untrained users

c)

Internal fraud

d)

USB flash drives left in parking lots

39.

Which of the following would be a poor response to a suspected vishing call?

a)

Hang up and call the official number on file

b)

Take notes on the caller and report it to IT

c)

Ask the caller for more personal details to verify them

d)

Refuse to provide any personal information

40.

Which combination of actions would best protect a user from ransomware, phishing, and vishing threats?

a)

Use incognito mode and update your wallpaper

b)

Ignore spam folders and auto-click URLs

c)

Use public Wi-Fi to avoid detection

d)

Be cautious with unknown links, calls, and keep backups