wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cyber Security and Digital Awareness - Assessment 2

Total questions: 50

Worksheet time: 38mins

Name
Class
Date
1.

Riya receives a WhatsApp message from a “UPI Refund Team” asking her to approve a collect request to get ₹1,200 refund. What is the red flag?

a)

Refunds are always instant

b)

Refunds never come through collect requests

c)

Collect requests are used only by merchants

d)

Refunds require OTP

2.

A video of a celebrity endorsing a free crypto scheme goes viral. His lips don’t match perfectly with the audio. What is most likely happening?

a)

Screen recording

b)

Deepfake manipulation

c)

Video compression

d)

AI captioning

3.

A student gets an SMS saying “Your bank KYC is expiring tonight. Click to update: sbi-kycverify.info”. What should they check first?

a)

SMS sender name

b)

Website domain authenticity

c)

Their account balance

d)

Whether the link opens quickly

4.

A fake university exam timetable is circulated. It has wrong fonts, no official seal, and a strange URL at the bottom. What is this?

a)

Data scraping

b)

Misinformation

c)

Cache error

d)

Session timeout

5.

Aman uses the same password for Facebook, Gmail, and Instagram. After one breach, all accounts get hacked. What attack is this?

a)

Brute force

b)

Credential stuffing

c)

SQL Injection

d)

Reverse hashing

6.

A caller pretending to be “Bank Verification Officer” asks for UPI PIN to confirm identity. What’s the intention?

a)

Account activation

b)

Loan approval

c)

Money theft

d)

KYC process

7.

Priya scans a QR code stuck outside a shop that says “Free Recharge ₹50”. What type of attack is likely?

a)

Smishing

b)

QR Phishing (Quishing)

c)

Malware email

d)

SIM swap

8.

A message from “Income Tax Refund Notice” asks students to login with Aadhaar number and PAN. What is being targeted?

a)

Academic data

b)

Financial identity

c)

Browser cookies

d)

SIM details

9.

A student downloads a free movie app. It asks for SMS, Contacts, and Microphone access. What is happening?

a)

Normal Android permissions

b)

Excessive permission harvesting

c)

Cache management

d)

VPN tunneling

10.

Rahul gets a pop-up saying “Your device has 13 viruses! Click fix now.” What scam is this?

a)

Browser hijack

b)

Fake virus alert malware

c)

Antivirus update

d)

RAM booster

11.

A thief clones a student's SIM and receives all OTPs. What attack is this?

a)

MITM

b)

SIM Swap

c)

Phishing bypass

d)

Credential reuse

12.

A job offer email promises ₹50,000 monthly for “2 hours work”. It has no company website and asks for registration fees. What scam?

a)

Insider trading

b)

Advance-fee scam

c)

Phishing

d)

Profile scraping

13.

Shivani uploads her resume on multiple job portals. Later she gets fake HR calls asking for “ID verification”. What data leakage occurred?

a)

Browser cookies

b)

Career data harvesting

c)

VPN tunneling

d)

Cloud backup failure

14.

A deepfake audio copies a father’s voice asking daughter for urgent UPI payment. What red flag reveals danger?

a)

Sender typing speed

b)

No call-back allowed

c)

Voice tone mismatch

d)

Both B and C

15.

Student clicks a link “Check your Aadhaar status” from an unknown Telegram group. What attack is this?

a)

Pharming

b)

Social engineering

c)

Browser caching

d)

SSL spoofing

16.

A laptop webcam light turns on randomly. What does this indicate?

a)

Auto-update

b)

Malware or remote access

c)

Low RAM

d)

VPN disconnection

17.

A student receives “Your Instagram will be deleted in 24 hrs. Login now.” What is this?

a)

Terms update

b)

Phishing login page

c)

IG Moderator Warning

d)

AI-generated alert

18.

A PDF from unknown email asks to “Enable Macros” to view content. What might happen?

a)

Faster download

b)

Malware execution

c)

File compression

d)

Text formatting

19.

You try to visit a website and browser shows “Not Secure” icon. What is missing?

a)

RAM

b)

VPN

c)

HTTPS certificate

d)

Antivirus

20.

A stranger sends WhatsApp message: “Forward this to 20 people or your account will be locked.” This is:

a)

Cyber extortion

b)

Chain hoax

c)

Spoofing

d)

KYC alert

21.

“support@paytm-securee.com” is asking for wallet login. What’s wrong?

a)

Domain misspelling

b)

Wrong grammar

c)

No logo

d)

Short email

22.

An app asks for “Display over other apps” permission. What attack may follow?

a)

Overlay attack

b)

Clipboard cloning

c)

CAPTCHA bypass

d)

IP spoofing

23.

When UPI transaction fails, which information should NEVER be shared with a support agent?

a)

UPI ID

b)

Bank name

c)

Last 6 digits of account

d)

UPI PIN

24.

A student joins a fake Telegram group “Govt. Internship 2024” asking ₹999 registration. What is this?

a)

Internship indexing

b)

Scam job funnel

c)

Data entry job

d)

Govt form processing

25.

Your social media password appears on HaveIBeenPwned. What should you do first?

a)

Ignore

b)

Change password + enable 2FA

c)

Restart phone

d)

Use different browser

26.

Which DPDPA section is violated when fraudsters collect data without informing purpose?

a)

Section 7

b)

Section 4

c)

Section 3

d)

Section 11

27.

A student receives an AI-generated newspaper headline about a fake earthquake. What is this?

a)

Disinformation

b)

Cache error

c)

News archiving

d)

Push notification

28.

OTP is required for:

a)

Verifying identity

b)

Blocking account

c)

Changing ATM PIN

d)

Completing UPI transfer

29.

A popup asks student to login through Google to download question paper. Risk?

a)

Profile phishing

b)

Device wipe

c)

VPN block

d)

Cloud sync

30.

A malware turns phone screen black and demands money. What is this?

a)

Spyware

b)

Ransomware

c)

Botnet

d)

Keylogger

31.

A website wants “Location Access Always”. But it's a wallpaper website. What’s happening?

a)

Cache bypass

b)

Unnecessary permission harvesting

c)

High accuracy tracking

d)

VR mode

32.

A phishing email uses official logos but wrong URL. Why do students fall for it?

a)

Logo trust bias

b)

Limited data

c)

Slow internet

d)

DNS block

33.

Who is responsible for protecting personal data under DPDPA?

a)

Only Government

b)

Only Apps

c)

Only Banks

d)

Both User & Data Fiduciary

34.

A cloned voice message says “Pay fast, battery dying, can't talk.” Which red flag?

a)

Urgency

b)

Background noise

c)

Auto-correction

d)

Text length

35.

Which browser habit makes students MOST unsafe?

a)

Opening new tabs

b)

Saving passwords in public computers

c)

Using dark mode

d)

Using bookmarks

36.

A student receives a PDF titled “Exam Results”, but file size is only 8 KB. What could this be?

a)

High compression

b)

Malware loader

c)

Screenshot PDF

d)

Document preview

37.

Fake UPI handles often contain:

a)

Bank names

b)

Extra letters or numbers

c)

Emojis

d)

Dashes

38.

A friend asks on WhatsApp for money urgently, but refuses video call. This is:

a)

Friendship test

b)

SIM damage

c)

Deepfake voice scam

d)

OTP block

39.

A suspicious website asks user to disable 2FA. Why?

a)

More convenience

b)

Marketing

c)

Easier account takeover

d)

Battery saving

40.

“Forward your PAN/Aadhaar for discount.” Which principle is violated?

a)

Purpose limitation

b)

User duty

c)

Accuracy

d)

Retention

41.

Students click a link that secretly installs screen-sharing malware. What attack begins?

a)

Cookie stuffing

b)

Remote takeover

c)

Cache poisoning

d)

Drive-by attack

42.

Keyboard lag right after installing unknown APK indicates:

a)

Low storage

b)

Keylogger infection

c)

Auto-correct bug

d)

VPN connection

43.

A student’s friend sends a video that asks “Enable Accessibility Services”. Why dangerous?

a)

Slow phone

b)

Reads all screen data

c)

Cache clean

d)

Screenshot block

44.

Which UPI request is always fake?

a)

Payment request

b)

Collect request for refund

c)

Merchant request

d)

Billing request

45.

A fake news article ends with “Share before they delete it!”. Which red flag?

a)

Fear appeal

b)

Time constraint

c)

Forward pressure

d)

All of the above

46.

Bank calls NEVER ask for:

a)

Last transaction

b)

Registered name

c)

Full debit card number

d)

Complaint ID

47.

A random link captured your cookie session and logged into your account. What is this attack?

a)

Session hijacking

b)

DNS tunneling

c)

Packet flooding

d)

Credential caching

48.

“Your WhatsApp is expiring. Renew here.” What to check?

a)

App version

b)

WhatsApp never expires

c)

SIM balance

d)

PlayStore rating

49.

A student receives “You won ₹1 lakh”. Which principle is used?

a)

Reciprocity

b)

Authority

c)

Scarcity

d)

Social proof

50.

A deepfake image is analyzed and face edges show blurry halos. What does it indicate?

a)

Overexposure

b)

AI blending artifacts

c)

Low camera quality

d)

Watermark removal