wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Module 02: Personal Cybersecurity

Total questions: 52

Worksheet time: 26hrs 0mins

Name
Class
Date
1.

Indicate whether the statement is true or false. 1. Security questions should be answered with a fictious answer instead of the accurate answer.

a)

True

b)

False

2.

Indicate whether the statement is true or false. 2. Virtually anyone could type in a person's username and pretend to be that person.

a)

True

b)

False

3.

Indicate whether the statement is true or false. 3. Passwords are still considered a strong defense against attackers.

a)

True

b)

False

4.

Indicate whether the statement is true or false. 4. FACTA grants consumers the right to request one free credit report from each of the three national credit-reporting firms every 12 months.

a)

True

b)

False

5.

Indicate whether the statement is true or false. 5. The weakness of passwords centers on human memory.

a)

True

b)

False

6.

Indicate whether the statement is true or false. 6. When creating passwords, the most important principle is that length is more important than complexity.

a)

True

b)

False

7.

Indicate whether the statement is true or false. 7. Impersonation is a technique used in social engineering.

a)

True

b)

False

8.

What is it called if a user misspells the URL or uses the incorrect domain and is sent to a fake look-alike site?

a)

pharming

b)

phishing

c)

polling

d)

typo squatting

9.

Which security technique requires an authorization by what the user knows and what the user has?

a)

special email account

b)

two-factor authorization

c)

biometrics

d)

social networking

10.

What type of attack continuously enters different passwords against the same account?

a)

Brute force attack

b)

Phishing attack

c)

Man-in-the-middle attack

d)

Denial of Service attack

11.

What popular online activity involves allowing users to stay connected with friends, family, and peers?

a)

affiliate marketing

b)

affiliate networking

c)

social networking

d)

social marketing

12.

With which type of social engineering attack are users asked to respond to an email or are directed to a website where they are requested to update personal information, such as passwords or credit card numbers?

a)

pharming

b)

typo squatting

c)

phishing

d)

pretexting

13.

The built-in security function of all password managers is known as ____________________?

a)

two-factor authentication

b)

biometrics

c)

vault

d)

random password generator

14.

Using which social engineering principle might an attacker impersonate a CEO of a company?

a)

scarcity

b)

authority

c)

urgency

d)

trust

15.

What law contains rules regarding consumer privacy?

a)

Credit and Transactions Act

b)

Fair and Accurate Credit Transactions Act

c)

Fair Credit Reporting Act

d)

Accurate Transactions Act

16.

In the United States, if a consumer finds a problem on their credit report, they must first send a letter to the credit-reporting agency. Under federal law, how many days does the agency have to investigate and respond to the alleged inaccuracy and issue a corrected report?

a)

15

b)

30

c)

45

d)

60

17.

What type of attack is when a small number of common passwords are used to attempt to log in to multiple user accounts?

a)

password cracking

b)

typo squatting

c)

password spraying

d)

social networking

18.

Which of the following is an alternate method instead of passwords for authentication?

a)

biometrics

b)

special email account

c)

anonymous user id

d)

fictitious security answer

19.

What type of program lets a user create and store multiple strong passwords in a single user database file that is protected by one strong master password?

a)

password manager

b)

password generator

c)

password fault program

d)

password vault program

20.

What type of attack is a false warning, often contained in an email message claiming to come from the information technology (IT) department?

a)

impersonation

b)

authentication

c)

hoax

d)

revalidation

21.

What is the special algorithm that creates a scrambled password from a user entered password?

a)

modification

b)

brute force

c)

scrambled

d)

hash

22.

The “Consensus” principle of social engineering is exemplified by which of the following examples?

a)

I’m the CEO calling

b)

You know who I am

c)

If you don’t reset my password, I’ll call your supervisor

d)

I called last week and your colleague reset my password

23.

How often does FACTA grant consumers the right to request one free credit report from each of the three national credit-reporting firms?

a)

every 2 months

b)

every 6 months

c)

every 12 months

d)

every 18 months

24.

What is the best approach to establishing strong security with passwords?

a)

Keep passwords short so you can remember them.

b)

Use the same password for many sites.

c)

Keep a written log of your passwords.

d)

Use technology for managing passwords.

25.

What type of attacker is most likely to use information you have posted about yourself on a social networking site?

a)

identity thief

b)

phisher

c)

cracker

d)

hoaxer

26.

Which of the following involves using someone’s personal information, such as a Social Security number, to fraudulently establish bank or credit card accounts?

a)

identity borrowing

b)

identity theft

c)

information theft

d)

property theft

27.

The most frequently attacked sector of the market by phishing schemes and attacks is ____________________?

a)

financial

b)

manufacturing

c)

retail

d)

marketing

28.

28. Technically speaking, the process for creating a password digital representation is based on a hash algorithm, which creates a(n) _________________?

a)

digest

b)

encryption key

c)

digital certificate

d)

public key

29.

29. ________________ may involve the use of a PC and smartphone to login to a secure system.

a)

Two-factor authentication

b)

Single sign-on

c)

Password hint

d)

Guest login

30.

30. A(n) ________________ is a false warning, often contained in an email message claiming to come from the IT department.

a)

hoax

b)

phishing

c)

malware

d)

spam

31.

31. One of the best tools to put people at ease for social engineering and obtaining information is ________________.

a)

pretexting

b)

humor

c)

dumpster diving

d)

shoulder surfing

32.

32. A(n) ________________ is a unique name used for identification.

a)

username

b)

password

c)

address

d)

email

33.

The steps that ensure that the individual is who they claim to be.

a)

h. Identity fraud

b)

a. Authentication

c)

b. Authorization

d)

c. Password

34.

A password attack in which every possible combination of letters, numbers, and characters is used to match passwords in a stolen password file.

a)

e. brute force attack

b)

a. Phishing

c)

b. Shoulder surfing

d)

c. Keylogging

35.

A secret combination of letters, numbers, and/or symbols that serves to authenticate a user by what they know.

a)

d. Password

b)

a. Username

c)

b. Email address

d)

c. Security question

36.

Software designed to find passwords based on digests known as 'candidates'.

a)

e. Password cracking

b)

a. Firewall configuration

c)

b. Data compression

d)

c. Network sniffing

37.

Some of the characteristics of weak passwords are:

a)

They are short and easy to guess.

b)

They use a mix of uppercase, lowercase, numbers, and symbols.

c)

They are unique for every account.

d)

They are regularly updated.

38.

General recommendations for creating passwords include:

a)

Using a mix of letters, numbers, and symbols

b)

Using only your birthdate

c)

Using the word 'password'

d)

Using the same password for all accounts

39.

Password cracking is accomplished by:

a)

using various techniques to guess or decrypt passwords

b)

creating strong passwords for users

c)

encrypting passwords to protect them

d)

storing passwords in a secure database

40.

The psychological approaches used by attackers in person-to-person contact to gain the trust of the person include:

a)

Building rapport and using social engineering techniques

b)

Using technical hacking tools only

c)

Relying solely on physical intimidation

d)

Ignoring the target's emotions and behaviors

41.

Phishing is:

a)

a method used to trick people into giving away personal information online.

b)

a way to improve internet speed.

c)

a technique for creating strong passwords.

d)

a process for encrypting emails.

42.

Do not use passwords that consist of dictionary words or phonetic words. Do not repeat characters (xxx) or use sequences (abc, 123, qwerty). Do not use birthdays, family member names, pet names, addresses, or any personal information. Do not use short passwords. A strong password should be a minimum of 18 characters in length.

a)

Do not use passwords that consist of dictionary words or phonetic words. Do not repeat characters (xxx) or use sequences (abc, 123, qwerty). Do not use birthdays, family member names, pet names, addresses, or any personal information. Do not use short passwords. A strong password should be a minimum of 18 characters in length.

b)

Use passwords that are easy to remember, such as your name or birthday, and keep them short for convenience.

c)

Repeat characters and use simple sequences like 123 or abc to make your password easier to recall.

d)

A strong password should be a common word or phrase that you use frequently.

43.

Password cracking works by:

a)

Trying different combinations to guess the correct password.

b)

Encrypting passwords to make them secure.

c)

Storing passwords in a database.

d)

Sending passwords over a secure connection.

44.

Phishing is a form of social engineering that involves:

a)

Tricking individuals into revealing sensitive information through deceptive emails or websites.

b)

Physically stealing someone's computer to access their data.

c)

Using strong encryption to protect sensitive information.

d)

Developing antivirus software to prevent malware attacks.

45.

Pretending to be somebody else in order to gain something(like money) is called:

a)

Identity theft

b)

Hacking

c)

Digital asset

d)

Malware

46.

Which of the following is LEAST likely to indicate a phishing attack?

a)

An email from your bank asks you to call the number on your card to verify a transaction.

b)

An email from a merchant asks that you click on a link to reset your password.

c)

An email from a utility company asks you to enter your date of birth and social security number for verification purposes.

d)

An email that indicates you have won a large sum of money and asks you to enter your bank account number so that money can be transferred to you.

47.
What is the most common way to receive a phishing scam?
a)
Text message
b)
Email
c)
Downloading films
d)
Unsafe wesbites
48.
Select the Phishing Schemes that apply to the following email:
From:  no_reply@emailinternet.chase.com
Subject:  Account Status
Attention US Bank Customer,
Due to a recent security check on your account, we require you to confirm your details.  Failure to do so within 24 hours will lead to account suspension.  Sorry for the inconveenince.
Click here to confirm your account

Regards,
US Bank Online Customer Service
This email has been sent by US Bank.
                                                         
a)
Generic greeting & Link to email
b)
Sense of urgency & Spelling errors
c)
Need to verify account info
d)
ALL of the previous choices are in the email.
49.
What's the name given to the attempt to obtain sensitive information such as usernames and passwords, by disguising as a trustworthy entity in an electronic communication (e.g. creating a fake website)?
a)
Trojan
b)
Virus
c)
Ransomware
d)
Phishing
50.

Which of these is the best definition of Phishing?

a)

Calling someone to create an invented situation that increases the chance they will share sensitive information with you.

b)

Sending an email that pretends to be from a reputable company which usually has a link to click that takes you to a website that looks real but is not.

c)

A cyber attack that redirects a user from a real URL to a website that looks real but is not.

d)

Looking at someone entering their personal data into a system and copying what you see.

51.
What is spam?
a)
unsolicited messages sent to you
b)
Send Programs And Machine code
c)
untitled messages
d)
A Virus
52.
Phishing is...
a)
when people send email and social media messages to say how much they like you
b)
the thing with a pole and water
c)
super fun
d)
when people send you phony emails, pop-up messages and social media messages, text or calls to hook you into giving out personal information