NEW
Font size
Worksheets1-2-4 Securing Your Browser
Total questions: 78
Worksheet time: 1hrs 18mins
Which URL component primarily identifies who you are connecting to on the internet?
Protocol
Subdomain
Domain name
File path
In the URL https://portal.school.org/login/home, which part is the file path?
https://
portal.
school.org
/login/home
What does the “S” in HTTPS most accurately represent?
Secure, meaning the page is password protected
Secure, meaning HTTP is running over TLS/SSL encryption
Safe, meaning the site cannot host malware
Signed, meaning the page is digitally signed by the user
Which statement best describes typosquatting?
Overloading a server with traffic until it fails
Registering domains with deliberate spelling errors of popular sites
Capturing network packets to read passwords
Using a VPN to hide browser activity
Which browser feature stores a record of all sites you have visited?
Cookies
Cache only
Browsing history
Incognito mode
What is the primary risk of allowing all pop-ups and redirects globally?
Slower DNS resolution
Increased CPU temperature
Higher chance of malicious or deceptive windows appearing
Loss of saved bookmarks
Which statement about Incognito mode is TRUE?
It hides browsing from your school’s network logs
It prevents the ISP from seeing which sites you visit
It blocks all tracking cookies by default
It does not save local history after the session is closed
Which organization typically issues and validates website certificates for HTTPS?
Internet Service Providers
Network Address Translators
Certificate Authorities
Domain Name Registrars
What is the main purpose of a browser cookie?
To execute JavaScript on the client
To store small pieces of data such as session IDs or preferences
To filter malicious traffic
To encrypt all HTTP traffic
Which browser setting most directly controls whether a site can know your physical location?
Cookies
Cache settings
Location services
Incognito mode
What governs access to geolocation in a browser?
Notifications
Pop-ups and redirects
Location services
Downloads
What is one common consequence of clearing “Cookies and other site data”?
All cached images are preserved
You are signed out of most websites
The browser disables HTTPS
All bookmarks are deleted
Which of the following is the BEST reason a browser warns about an expired certificate?
It always indicates malware
The site has exceeded its bandwidth limit
The identity or integrity of the site can no longer be trusted with confidence
The DNS record is missing
In Chrome, what does the “Always use secure connections” option attempt to do?
Block all HTTP traffic
Automatically upgrade HTTP requests to HTTPS when possible
Turn off DNS
Force VPN usage
Which file type is MOST likely to be dangerous if downloaded from an unknown site?
.jpg
.exe
.txt
What is the primary security advantage of downloading files only from official vendor websites?
Files are always free of malware
Files are guaranteed to be compatible with your system
Files are less likely to be tampered with or malicious
Files are automatically updated
Which description best fits a browser cache?
A list of passwords
Local copies of pages and content to speed up revisits
A list of DNS servers
A collection of installed plug-ins
Which setting is MOST directly related to preventing websites from silently listening to conversations?
Location
Pop-ups and redirects
Microphone
Notifications
What does a padlock icon next to a URL generally indicate?
The site has no ads
The site is government-owned
The connection is encrypted and a valid certificate was verified
The site is free of malware
Which of the following BEST defines “illegal content sites” in a browser security context?
Sites that block cookies
Sites hosting pirated movies, software, or music
Sites that require strong passwords
Sites using HTTPS
Which action directly reveals where a downloaded file was stored in Chrome?
Checking the browser history
Selecting “Show in folder” from the Downloads page
Clearing cookies
Opening Task Manager
Which Chrome feature lets you review and remove cookies for individual sites?
Extensions panel
Site info (lock menu)
“See all cookies and site data” in Settings
Browser history
What is the main purpose of requiring sites to “Ask before accessing” the camera and microphone?
To speed up streaming
To reduce disk usage
To prevent silent use of audio/video hardware without user consent
To disable all browser plug-ins
Which of the following is LEAST likely to be changed when clearing only “Browsing history”?
The list of visited URLs
Cached copies of pages
Saved passwords
Auto-completion suggestions in the address bar
Which two indicators together give the strongest sign that a site is using secure communication?
HTTP and pop-ups
HTTPS and a valid lock icon
DNS and proxy settings
Cookies and cached pages
Why is having a browser plug-in set to “Ask first” generally safer than “Allow always”?
It stops all network traffic
It ensures the plug-in runs in incognito only
It forces user interaction before potentially risky code executes
It hides your IP address
A student types disenyplus.com instead of disneyplus.com and lands on a site that looks identical to the real one. The login form appears normal. Which threat is this MOST likely an example of?
DNS poisoning
Typosquatting
ARP spoofing
URL shortening
You are on public Wi-Fi and notice a site is using http:// instead of https:// when asking for a password. What is the MOST likely risk?
Cookies will be deleted
Your traffic may be read or altered by anyone on the path
The site will fail to load
Your browser will automatically block the page
A user complains that ads and suspicious download prompts appear every time they visit a streaming site. Pop-ups are currently allowed for all sites. What is the BEST first mitigation step?
Disable all cookies
Block pop-ups and redirects by default and add exceptions only for trusted sites
Turn off browsing history
Change the system time
Your organization shares a single workstation for printing pay stubs. The browser is configured to save user names and passwords automatically. What is the MOST likely security issue?
Increased VPN usage
Other users may log in as someone else without knowing their credentials
HTTPS will not work
DNS resolution will fail
While visiting a banking site, your browser shows “Your connection is not private” and displays an expired certificate. No urgent transactions are required. What should you do FIRST?
Proceed anyway and complete the login quickly
Ignore the warning and reload repeatedly
Close the tab and contact the bank using a known-good phone number or bookmarked link
Clear cookies and retry on the same URL
A student uses Incognito mode on a school laptop and believes the school cannot see what websites they visit. Which statement is MOST accurate?
The school can still see network traffic in its logs
Incognito hides all traffic from the network
Only the ISP can see traffic, not the school
No one can see traffic in Incognito mode
While doing a lab, you download a document from https://sites.google.com/view/pltw-sec-demo. You forget where it saved. Which action helps you locate it?
Clearing browser data
Opening “Show in folder” from the Downloads page
Restarting the computer
Flushing DNS cache
A user notices Chrome is set to “Sites can ask for your location.” They are comfortable sharing their location only with a few map services. What is the safest way to use this setting?
Change it to “Allow” for all sites
Change it to “Block” globally
Keep “Ask,” then approve location only for specific trusted sites
Disable HTTPS
You are investigating a malware incident and see that the user downloaded an .exe file from a pirated game site. Which factor MOST likely contributed to the infection?
Using HTTPS
Downloading from an untrusted, illegal content site
Clearing cookies
Using bookmarks
A user reports: “When I type http://google.com, it automatically changes to https://www.google.com.” What security feature is responsible for this behavior?
Browser cache
DNS cache
Automatic HTTP→HTTPS redirection
Ad-blocking extension
You’re configuring a lab computer for students. They must be able to join Meet/Zoom calls but you want to prevent random sites from turning on the camera. Which configuration is MOST appropriate?
Camera: Allow; Microphone: Block
Camera: Ask; Microphone: Ask
Camera: Block; Microphone: Allow
Camera: Allow; Microphone: Allow
During an investigation, you see a long list of suspicious adult sites in a computer’s browser history. Which security risk does this MOST directly create?
Increased VPN efficiency
Evidence of potential exposure to drive-by downloads and phishing
Loss of all cached images
Automatic HTTPS upgrades
A user insists, “I use HTTPS so I’m perfectly safe.” Which situation shows they may still be at risk?
They clear cookies weekly
They ignore certificate errors and proceed on warning pages
They block pop-ups
They never save passwords
On a shared family PC, a teenager uses Incognito mode to log in to a game account. Later, a sibling opens the browser in normal mode and can’t see any of those visited sites. What has Incognito successfully protected in this case?
ISP logs
School firewall logs
Local browsing history and some cookies
DNS queries
A user downloads a file that claims to be a PDF, but Windows shows it as report.pdf.exe. What is the BEST interpretation?
It is a harmless text document
It is likely an executable file disguised as a document
It is a browser cache file
It is encrypted with HTTPS
A class is using a virtual machine for the security lab, and the Chrome language defaults to another language. Students type “change language” and follow prompts to switch to English. What security principle is being followed by keeping the VM separate from the host computer?
Obfuscation
Least privilege
Segmentation/isolation of risky activity
Single sign-on
You notice that Chrome suggests enabling updates, but the lab instructions say not to update Chrome so the lab behavior stays consistent. In a real production environment, what is the MOST security-conscious action?
Ignore update prompts permanently
Regularly update the browser to the latest stable version
Uninstall the browser
Disable HTTPS
A phishing page copies your bank’s logo but uses the URL https://secure-banking.banknow-verify.com/login. Which detail is MOST suspicious?
Use of HTTPS
Use of the word “secure”
The real bank domain appears as a sub-string, not the registered domain
The presence of a login form
A user clears only “Cookies and other site data” but not history. What will they MOST likely experience next time they revisit a site that previously “remembered” them?
The site loads faster
The site no longer recognizes them and asks them to log in again
All bookmarks are gone
Their ISP can’t see their traffic
You are asked to verify that downloaded lab resources are stored on the Desktop instead of the default Downloads folder. Which browser setting must you review?
Default search engine
Download location
Cookie policy
Proxy settings
A user wants to quickly check whether a suspicious website has already stored cookies on their system. Which is the MOST direct method?
Open browser history
Check extension list
Open “See all cookies and site data” and search for the site
Clear cache
The system time on a workstation is accidentally set one year in the future. When the user visits common HTTPS sites, they see certificate errors. What is the MOST likely reason?
The root CA is compromised
The certificates appear expired relative to the incorrect system date
DNS servers are offline
HTTPS was disabled
A teacher asks students to document each step of a browser-security lab with screenshots and explanations of “what” and “why.” From a security operations perspective, what does this MOST closely resemble?
Casual texting
Forensic-quality evidence documentation
Malware reverse engineering
Bug bounty reporting
A student opens many shady streaming sites and later asks why their system is slow and full of pop-ups. Which is the MOST likely cause?
Heavy RAM usage by bookmarks
Malware or adware installed via drive-by downloads and pop-ups
Too many HTTPS connections
Browser cache being empty
A user wants to open a “New incognito window” to research a sensitive medical topic at home. What privacy benefit do they MOST likely gain?
Their ISP cannot log their traffic
Their home router stops seeing DNS requests
Other family members won’t see the visited sites in local history
Websites cannot track them
You are defining a standard browser configuration for student laptops. Which combination BEST balances privacy and usability?
Location: Allow; Pop-ups: Allow; Downloads: Auto to Downloads
Location: Ask; Camera/Mic: Ask; Pop-ups: Block; Downloads: Ask location
Location: Block; Camera/Mic: Block; Pop-ups: Allow; Downloads: Auto
Location: Allow; Camera/Mic: Allow; Pop-ups: Block; Downloads: Auto
An entry-level sysadmin is reviewing several possible responses to frequent “Your connection is not private” warnings on staff machines. Which action is MOST appropriate?
Train users to click through if they recognize the site
Disable certificate validation in the browser
Investigate certificate issues on the affected sites or proxies and fix the root cause
Turn off HTTPS inspection in all situations
You must configure one shared library computer used by many patrons. Which password-related approach is BEST?
Allow the browser to save passwords but clear them weekly
Permit password saving only for HTTPS sites
Disable browser password saving entirely on the shared device
Use the same admin account password for all users
You are analyzing two download behaviors: - User A downloads software only from official vendor sites. - User B downloads “cracked” versions from random forums. From a risk perspective, which statement is MOST accurate?
Both users face the same risk if they use HTTPS
User A faces higher risk because vendors are targeted more
User B faces higher risk due to untrusted sources and possible tampering
Risk cannot be evaluated without knowing file size
A small business wants employees to access location-based features (maps, delivery services) while minimizing unnecessary tracking. Which policy is MOST appropriate?
Location: Allow for all sites
Location: Block for all sites
Location: Ask, and instruct users to allow only for approved business apps
Location: Allow in Incognito only
You are choosing a policy for pop-ups and redirects on corporate browsers. Which option BEST supports security while allowing necessary business sites to function?
Allow pop-ups from all sites
Block pop-ups globally, with an approved exception list
Block pop-ups only on HTTPS sites
Allow pop-ups only when Incognito is used
A security team is debating how often users should clear browsing data. Which practice BEST balances privacy and productivity for typical knowledge workers?
Clear all data after every browsing session
Clear cookies and cache weekly
Clear browsing history monthly
Never clear browsing data
You must choose between two browser settings for downloads: Auto-save all files to a shared Downloads folder or ask for the save location each time. For a security-sensitive environment where users handle confidential documents, which is BETTER and why?
Option 1, because it is simpler
Option 1, because it uses less disk space
Option 2, because it forces users to think about where sensitive data is stored
They are equivalent
An administrator is deciding whether to allow third-party browser extensions. Which policy BEST reflects a secure mindset?
Allow all extensions; users know their needs
Block all extensions, even from trusted vendors
Allow only vetted, necessary extensions from official stores
Allow extensions only in Incognito mode
You see a user habitually relying on the address bar auto-complete for banking and school sites rather than typing URLs from memory. From a typosquatting defense perspective, how should you evaluate this behavior?
Positive, because it reduces mistyped URLs
Negative, because it always uses HTTP
Neutral, because it doesn’t matter
Negative, because bookmarks cannot be trusted
A help desk technician proposes allowing 'Sites can use JavaScript' for all domains without restriction. What is the MOST appropriate response?
Allow JavaScript for all domains; it improves functionality
Restrict JavaScript usage to trusted domains only
Block JavaScript entirely; it poses security risks
Allow JavaScript only for Incognito mode
What is the most practical approach to handling JavaScript in modern browsers?
Approve it immediately; JavaScript is always safe
Reject it; JavaScript should be disabled globally in modern browsers
Allow JavaScript but pair it with strong anti-malware controls and user training
Disable all browsers that use JavaScript
When evaluating which sites should "always use HTTPS," which category should be considered the HIGHEST priority?
News blogs without logins
Public weather sites
Banking, e-commerce, and grade/portal systems
Meme sites
You are comparing two approaches to handling suspicious certificate warnings for a critical internal app. From a security architecture perspective, which approach is BETTER and why?
Approach A, because it avoids downtime
Approach A, because users learn to recognize warnings
Approach B, because it preserves user trust in browser warnings and removes the root cause
They are equivalent
You’re designing a training exercise on Incognito mode. Which learning objective BEST reflects a correct understanding?
Students will use Incognito to bypass school content filters.
Students will explain that Incognito hides local history but not traffic from the school or ISP.
Students will show that Incognito encrypts all HTTP traffic.
Students will prove that Incognito blocks all cookies.
A new sysadmin suggests that employees use pirated software to save licensing costs, claiming that “as long as we scan downloads, it’s safe.” How should you evaluate this recommendation?
Accept it; antivirus eliminates the risk
Reject it; using pirated software is illegal and high-risk even with scanning
Accept it only for non-critical systems
Accept it if run in Incognito mode
When choosing default browser settings for a high school lab environment, which policy for notification prompts is MOST appropriate?
Allow notifications from all sites
Block notifications globally
Ask for notifications on all sites
Turn off the browser’s notification feature
You are comparing three policies for shared school computers: 1. Leave all cookies and history between users 2. Clear cookies and history at logoff 3. Disable browsing entirely Which option BEST balances usability and privacy?
Policy 1
Policy 2
Policy 3
None; all are equivalent
A security analyst reviews logs and sees many outbound connections to domains like google-support.com and google-media.net. What is the BEST conclusion?
Normal browser prefetching
Malware infection
Unauthorized data exfiltration
Misconfigured proxy settings
An admin wants to reduce risk from users installing random Chrome extensions. Which control is MOST effective?
Telling users “don’t install bad extensions” in an email
Implementing a group policy that only allows approved extensions from a curated list
Requiring users to use Incognito
Clearing cache weekly
An organization must decide how to handle shared kiosk machines used for quick web access in a lobby. Which browser configuration is MOST appropriate?
Enable password saving and keep history for 90 days
Disable password saving, clear history on each session, and keep pop-ups blocked
Allow pop-ups from all sites and enable notifications
Leave all settings at home-user defaults
A student often downloads lab files and leaves them mixed with personal downloads, making incident response harder. Which change would MOST improve traceability of lab materials?
Turn off HTTPS
Use a dedicated “LabDownloads” folder and configure the browser to save lab files there
Disable all downloads
Save everything on the desktop without organization
When evaluating whether to rely on the padlock icon alone to judge website safety, which statement is MOST accurate?
The padlock proves the site is legitimate and safe
The padlock only confirms an encrypted connection and a valid certificate, not the legitimacy of the site
The padlock ensures the website is free from malware
The padlock guarantees the website is trustworthy
What does the padlock symbol in a browser indicate about a website?
The site is trustworthy and secure.
HTTPS protects the channel, not necessarily the site's intentions.
The padlock guarantees no malware is present.
The padlock means the site is government-approved.
A policy proposal suggests forcing 'Block all cookies' across every browser in the company. How should security leadership evaluate this?
Fully adopt it; blocking all cookies has no downside.
Reject it; many modern web apps break without cookies, and the policy will hurt usability.
Adopt it only for home users.
Adopt it only for developers.
From a security perspective, which evaluation is MOST accurate regarding anti-phishing habits? Student A: 'I'll always check the domain name slowly before entering credentials.' Student B: 'I'll rely on how professional the website's graphics look.'
Student A's approach is stronger because domain verification is harder to fake than page design.
Student B's approach is stronger.
Both are equally strong.
Neither is useful.
You are drafting a browser-security 'action plan' for new employees. Which item would be the MOST valuable to include?
Always accept any certificate warning so you can finish work quickly.
Use bookmarks or password-manager links for important sites instead of retyping URLs.
Disable HTTPS on all internal sites to speed them up.
Allow all pop-ups; blocking them is unnecessary.
