NEW
Font size
WorksheetsCyber Security and Digital Awareness - Assessment 2
Total questions: 50
Worksheet time: 38mins
Riya receives a WhatsApp message from a “UPI Refund Team” asking her to approve a collect request to get ₹1,200 refund. What is the red flag?
Refunds are always instant
Refunds never come through collect requests
Collect requests are used only by merchants
Refunds require OTP
A video of a celebrity endorsing a free crypto scheme goes viral. His lips don’t match perfectly with the audio. What is most likely happening?
Screen recording
Deepfake manipulation
Video compression
AI captioning
A student gets an SMS saying “Your bank KYC is expiring tonight. Click to update: sbi-kycverify.info”. What should they check first?
SMS sender name
Website domain authenticity
Their account balance
Whether the link opens quickly
A fake university exam timetable is circulated. It has wrong fonts, no official seal, and a strange URL at the bottom. What is this?
Data scraping
Misinformation
Cache error
Session timeout
Aman uses the same password for Facebook, Gmail, and Instagram. After one breach, all accounts get hacked. What attack is this?
Brute force
Credential stuffing
SQL Injection
Reverse hashing
A caller pretending to be “Bank Verification Officer” asks for UPI PIN to confirm identity. What’s the intention?
Account activation
Loan approval
Money theft
KYC process
Priya scans a QR code stuck outside a shop that says “Free Recharge ₹50”. What type of attack is likely?
Smishing
QR Phishing (Quishing)
Malware email
SIM swap
A message from “Income Tax Refund Notice” asks students to login with Aadhaar number and PAN. What is being targeted?
Academic data
Financial identity
Browser cookies
SIM details
A student downloads a free movie app. It asks for SMS, Contacts, and Microphone access. What is happening?
Normal Android permissions
Excessive permission harvesting
Cache management
VPN tunneling
Rahul gets a pop-up saying “Your device has 13 viruses! Click fix now.” What scam is this?
Browser hijack
Fake virus alert malware
Antivirus update
RAM booster
A thief clones a student's SIM and receives all OTPs. What attack is this?
MITM
SIM Swap
Phishing bypass
Credential reuse
A job offer email promises ₹50,000 monthly for “2 hours work”. It has no company website and asks for registration fees. What scam?
Insider trading
Advance-fee scam
Phishing
Profile scraping
Shivani uploads her resume on multiple job portals. Later she gets fake HR calls asking for “ID verification”. What data leakage occurred?
Browser cookies
Career data harvesting
VPN tunneling
Cloud backup failure
A deepfake audio copies a father’s voice asking daughter for urgent UPI payment. What red flag reveals danger?
Sender typing speed
No call-back allowed
Voice tone mismatch
Both B and C
Student clicks a link “Check your Aadhaar status” from an unknown Telegram group. What attack is this?
Pharming
Social engineering
Browser caching
SSL spoofing
A laptop webcam light turns on randomly. What does this indicate?
Auto-update
Malware or remote access
Low RAM
VPN disconnection
A student receives “Your Instagram will be deleted in 24 hrs. Login now.” What is this?
Terms update
Phishing login page
IG Moderator Warning
AI-generated alert
A PDF from unknown email asks to “Enable Macros” to view content. What might happen?
Faster download
Malware execution
File compression
Text formatting
You try to visit a website and browser shows “Not Secure” icon. What is missing?
RAM
VPN
HTTPS certificate
Antivirus
A stranger sends WhatsApp message: “Forward this to 20 people or your account will be locked.” This is:
Cyber extortion
Chain hoax
Spoofing
KYC alert
“support@paytm-securee.com” is asking for wallet login. What’s wrong?
Domain misspelling
Wrong grammar
No logo
Short email
An app asks for “Display over other apps” permission. What attack may follow?
Overlay attack
Clipboard cloning
CAPTCHA bypass
IP spoofing
When UPI transaction fails, which information should NEVER be shared with a support agent?
UPI ID
Bank name
Last 6 digits of account
UPI PIN
A student joins a fake Telegram group “Govt. Internship 2024” asking ₹999 registration. What is this?
Internship indexing
Scam job funnel
Data entry job
Govt form processing
Your social media password appears on HaveIBeenPwned. What should you do first?
Ignore
Change password + enable 2FA
Restart phone
Use different browser
Which DPDPA section is violated when fraudsters collect data without informing purpose?
Section 7
Section 4
Section 3
Section 11
A student receives an AI-generated newspaper headline about a fake earthquake. What is this?
Disinformation
Cache error
News archiving
Push notification
OTP is required for:
Verifying identity
Blocking account
Changing ATM PIN
Completing UPI transfer
A popup asks student to login through Google to download question paper. Risk?
Profile phishing
Device wipe
VPN block
Cloud sync
A malware turns phone screen black and demands money. What is this?
Spyware
Ransomware
Botnet
Keylogger
A website wants “Location Access Always”. But it's a wallpaper website. What’s happening?
Cache bypass
Unnecessary permission harvesting
High accuracy tracking
VR mode
A phishing email uses official logos but wrong URL. Why do students fall for it?
Logo trust bias
Limited data
Slow internet
DNS block
Who is responsible for protecting personal data under DPDPA?
Only Government
Only Apps
Only Banks
Both User & Data Fiduciary
A cloned voice message says “Pay fast, battery dying, can't talk.” Which red flag?
Urgency
Background noise
Auto-correction
Text length
Which browser habit makes students MOST unsafe?
Opening new tabs
Saving passwords in public computers
Using dark mode
Using bookmarks
A student receives a PDF titled “Exam Results”, but file size is only 8 KB. What could this be?
High compression
Malware loader
Screenshot PDF
Document preview
Fake UPI handles often contain:
Bank names
Extra letters or numbers
Emojis
Dashes
A friend asks on WhatsApp for money urgently, but refuses video call. This is:
Friendship test
SIM damage
Deepfake voice scam
OTP block
A suspicious website asks user to disable 2FA. Why?
More convenience
Marketing
Easier account takeover
Battery saving
“Forward your PAN/Aadhaar for discount.” Which principle is violated?
Purpose limitation
User duty
Accuracy
Retention
Students click a link that secretly installs screen-sharing malware. What attack begins?
Cookie stuffing
Remote takeover
Cache poisoning
Drive-by attack
Keyboard lag right after installing unknown APK indicates:
Low storage
Keylogger infection
Auto-correct bug
VPN connection
A student’s friend sends a video that asks “Enable Accessibility Services”. Why dangerous?
Slow phone
Reads all screen data
Cache clean
Screenshot block
Which UPI request is always fake?
Payment request
Collect request for refund
Merchant request
Billing request
A fake news article ends with “Share before they delete it!”. Which red flag?
Fear appeal
Time constraint
Forward pressure
All of the above
Bank calls NEVER ask for:
Last transaction
Registered name
Full debit card number
Complaint ID
A random link captured your cookie session and logged into your account. What is this attack?
Session hijacking
DNS tunneling
Packet flooding
Credential caching
“Your WhatsApp is expiring. Renew here.” What to check?
App version
WhatsApp never expires
SIM balance
PlayStore rating
A student receives “You won ₹1 lakh”. Which principle is used?
Reciprocity
Authority
Scarcity
Social proof
A deepfake image is analyzed and face edges show blurry halos. What does it indicate?
Overexposure
AI blending artifacts
Low camera quality
Watermark removal
