wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

1-2-4 Securing Your Browser

Total questions: 78

Worksheet time: 1hrs 18mins

Name
Class
Date
1.

Which URL component primarily identifies who you are connecting to on the internet?

a)

Protocol

b)

Subdomain

c)

Domain name

d)

File path

2.

In the URL https://portal.school.org/login/home, which part is the file path?

a)

https://

b)

portal.

c)

school.org

d)

/login/home

3.

What does the “S” in HTTPS most accurately represent?

a)

Secure, meaning the page is password protected

b)

Secure, meaning HTTP is running over TLS/SSL encryption

c)

Safe, meaning the site cannot host malware

d)

Signed, meaning the page is digitally signed by the user

4.

Which statement best describes typosquatting?

a)

Overloading a server with traffic until it fails

b)

Registering domains with deliberate spelling errors of popular sites

c)

Capturing network packets to read passwords

d)

Using a VPN to hide browser activity

5.

Which browser feature stores a record of all sites you have visited?

a)

Cookies

b)

Cache only

c)

Browsing history

d)

Incognito mode

6.

What is the primary risk of allowing all pop-ups and redirects globally?

a)

Slower DNS resolution

b)

Increased CPU temperature

c)

Higher chance of malicious or deceptive windows appearing

d)

Loss of saved bookmarks

7.

Which statement about Incognito mode is TRUE?

a)

It hides browsing from your school’s network logs

b)

It prevents the ISP from seeing which sites you visit

c)

It blocks all tracking cookies by default

d)

It does not save local history after the session is closed

8.

Which organization typically issues and validates website certificates for HTTPS?

a)

Internet Service Providers

b)

Network Address Translators

c)

Certificate Authorities

d)

Domain Name Registrars

9.

What is the main purpose of a browser cookie?

a)

To execute JavaScript on the client

b)

To store small pieces of data such as session IDs or preferences

c)

To filter malicious traffic

d)

To encrypt all HTTP traffic

10.

Which browser setting most directly controls whether a site can know your physical location?

a)

Cookies

b)

Cache settings

c)

Location services

d)

Incognito mode

11.

What governs access to geolocation in a browser?

a)

Notifications

b)

Pop-ups and redirects

c)

Location services

d)

Downloads

12.

What is one common consequence of clearing “Cookies and other site data”?

a)

All cached images are preserved

b)

You are signed out of most websites

c)

The browser disables HTTPS

d)

All bookmarks are deleted

13.

Which of the following is the BEST reason a browser warns about an expired certificate?

a)

It always indicates malware

b)

The site has exceeded its bandwidth limit

c)

The identity or integrity of the site can no longer be trusted with confidence

d)

The DNS record is missing

14.

In Chrome, what does the “Always use secure connections” option attempt to do?

a)

Block all HTTP traffic

b)

Automatically upgrade HTTP requests to HTTPS when possible

c)

Turn off DNS

d)

Force VPN usage

15.

Which file type is MOST likely to be dangerous if downloaded from an unknown site?

a)

.pdf

b)

.jpg

c)

.exe

d)

.txt

16.

What is the primary security advantage of downloading files only from official vendor websites?

a)

Files are always free of malware

b)

Files are guaranteed to be compatible with your system

c)

Files are less likely to be tampered with or malicious

d)

Files are automatically updated

17.

Which description best fits a browser cache?

a)

A list of passwords

b)

Local copies of pages and content to speed up revisits

c)

A list of DNS servers

d)

A collection of installed plug-ins

18.

Which setting is MOST directly related to preventing websites from silently listening to conversations?

a)

Location

b)

Pop-ups and redirects

c)

Microphone

d)

Notifications

19.

What does a padlock icon next to a URL generally indicate?

a)

The site has no ads

b)

The site is government-owned

c)

The connection is encrypted and a valid certificate was verified

d)

The site is free of malware

20.

Which of the following BEST defines “illegal content sites” in a browser security context?

a)

Sites that block cookies

b)

Sites hosting pirated movies, software, or music

c)

Sites that require strong passwords

d)

Sites using HTTPS

21.

Which action directly reveals where a downloaded file was stored in Chrome?

a)

Checking the browser history

b)

Selecting “Show in folder” from the Downloads page

c)

Clearing cookies

d)

Opening Task Manager

22.

Which Chrome feature lets you review and remove cookies for individual sites?

a)

Extensions panel

b)

Site info (lock menu)

c)

“See all cookies and site data” in Settings

d)

Browser history

23.

What is the main purpose of requiring sites to “Ask before accessing” the camera and microphone?

a)

To speed up streaming

b)

To reduce disk usage

c)

To prevent silent use of audio/video hardware without user consent

d)

To disable all browser plug-ins

24.

Which of the following is LEAST likely to be changed when clearing only “Browsing history”?

a)

The list of visited URLs

b)

Cached copies of pages

c)

Saved passwords

d)

Auto-completion suggestions in the address bar

25.

Which two indicators together give the strongest sign that a site is using secure communication?

a)

HTTP and pop-ups

b)

HTTPS and a valid lock icon

c)

DNS and proxy settings

d)

Cookies and cached pages

26.

Why is having a browser plug-in set to “Ask first” generally safer than “Allow always”?

a)

It stops all network traffic

b)

It ensures the plug-in runs in incognito only

c)

It forces user interaction before potentially risky code executes

d)

It hides your IP address

27.

A student types disenyplus.com instead of disneyplus.com and lands on a site that looks identical to the real one. The login form appears normal. Which threat is this MOST likely an example of?

a)

DNS poisoning

b)

Typosquatting

c)

ARP spoofing

d)

URL shortening

28.

You are on public Wi-Fi and notice a site is using http:// instead of https:// when asking for a password. What is the MOST likely risk?

a)

Cookies will be deleted

b)

Your traffic may be read or altered by anyone on the path

c)

The site will fail to load

d)

Your browser will automatically block the page

29.

A user complains that ads and suspicious download prompts appear every time they visit a streaming site. Pop-ups are currently allowed for all sites. What is the BEST first mitigation step?

a)

Disable all cookies

b)

Block pop-ups and redirects by default and add exceptions only for trusted sites

c)

Turn off browsing history

d)

Change the system time

30.

Your organization shares a single workstation for printing pay stubs. The browser is configured to save user names and passwords automatically. What is the MOST likely security issue?

a)

Increased VPN usage

b)

Other users may log in as someone else without knowing their credentials

c)

HTTPS will not work

d)

DNS resolution will fail

31.

While visiting a banking site, your browser shows “Your connection is not private” and displays an expired certificate. No urgent transactions are required. What should you do FIRST?

a)

Proceed anyway and complete the login quickly

b)

Ignore the warning and reload repeatedly

c)

Close the tab and contact the bank using a known-good phone number or bookmarked link

d)

Clear cookies and retry on the same URL

32.

A student uses Incognito mode on a school laptop and believes the school cannot see what websites they visit. Which statement is MOST accurate?

a)

The school can still see network traffic in its logs

b)

Incognito hides all traffic from the network

c)

Only the ISP can see traffic, not the school

d)

No one can see traffic in Incognito mode

33.

While doing a lab, you download a document from https://sites.google.com/view/pltw-sec-demo. You forget where it saved. Which action helps you locate it?

a)

Clearing browser data

b)

Opening “Show in folder” from the Downloads page

c)

Restarting the computer

d)

Flushing DNS cache

34.

A user notices Chrome is set to “Sites can ask for your location.” They are comfortable sharing their location only with a few map services. What is the safest way to use this setting?

a)

Change it to “Allow” for all sites

b)

Change it to “Block” globally

c)

Keep “Ask,” then approve location only for specific trusted sites

d)

Disable HTTPS

35.

You are investigating a malware incident and see that the user downloaded an .exe file from a pirated game site. Which factor MOST likely contributed to the infection?

a)

Using HTTPS

b)

Downloading from an untrusted, illegal content site

c)

Clearing cookies

d)

Using bookmarks

36.

A user reports: “When I type http://google.com, it automatically changes to https://www.google.com.” What security feature is responsible for this behavior?

a)

Browser cache

b)

DNS cache

c)

Automatic HTTP→HTTPS redirection

d)

Ad-blocking extension

37.

You’re configuring a lab computer for students. They must be able to join Meet/Zoom calls but you want to prevent random sites from turning on the camera. Which configuration is MOST appropriate?

a)

Camera: Allow; Microphone: Block

b)

Camera: Ask; Microphone: Ask

c)

Camera: Block; Microphone: Allow

d)

Camera: Allow; Microphone: Allow

38.

During an investigation, you see a long list of suspicious adult sites in a computer’s browser history. Which security risk does this MOST directly create?

a)

Increased VPN efficiency

b)

Evidence of potential exposure to drive-by downloads and phishing

c)

Loss of all cached images

d)

Automatic HTTPS upgrades

39.

A user insists, “I use HTTPS so I’m perfectly safe.” Which situation shows they may still be at risk?

a)

They clear cookies weekly

b)

They ignore certificate errors and proceed on warning pages

c)

They block pop-ups

d)

They never save passwords

40.

On a shared family PC, a teenager uses Incognito mode to log in to a game account. Later, a sibling opens the browser in normal mode and can’t see any of those visited sites. What has Incognito successfully protected in this case?

a)

ISP logs

b)

School firewall logs

c)

Local browsing history and some cookies

d)

DNS queries

41.

A user downloads a file that claims to be a PDF, but Windows shows it as report.pdf.exe. What is the BEST interpretation?

a)

It is a harmless text document

b)

It is likely an executable file disguised as a document

c)

It is a browser cache file

d)

It is encrypted with HTTPS

42.

A class is using a virtual machine for the security lab, and the Chrome language defaults to another language. Students type “change language” and follow prompts to switch to English. What security principle is being followed by keeping the VM separate from the host computer?

a)

Obfuscation

b)

Least privilege

c)

Segmentation/isolation of risky activity

d)

Single sign-on

43.

You notice that Chrome suggests enabling updates, but the lab instructions say not to update Chrome so the lab behavior stays consistent. In a real production environment, what is the MOST security-conscious action?

a)

Ignore update prompts permanently

b)

Regularly update the browser to the latest stable version

c)

Uninstall the browser

d)

Disable HTTPS

44.

A phishing page copies your bank’s logo but uses the URL https://secure-banking.banknow-verify.com/login. Which detail is MOST suspicious?

a)

Use of HTTPS

b)

Use of the word “secure”

c)

The real bank domain appears as a sub-string, not the registered domain

d)

The presence of a login form

45.

A user clears only “Cookies and other site data” but not history. What will they MOST likely experience next time they revisit a site that previously “remembered” them?

a)

The site loads faster

b)

The site no longer recognizes them and asks them to log in again

c)

All bookmarks are gone

d)

Their ISP can’t see their traffic

46.

You are asked to verify that downloaded lab resources are stored on the Desktop instead of the default Downloads folder. Which browser setting must you review?

a)

Default search engine

b)

Download location

c)

Cookie policy

d)

Proxy settings

47.

A user wants to quickly check whether a suspicious website has already stored cookies on their system. Which is the MOST direct method?

a)

Open browser history

b)

Check extension list

c)

Open “See all cookies and site data” and search for the site

d)

Clear cache

48.

The system time on a workstation is accidentally set one year in the future. When the user visits common HTTPS sites, they see certificate errors. What is the MOST likely reason?

a)

The root CA is compromised

b)

The certificates appear expired relative to the incorrect system date

c)

DNS servers are offline

d)

HTTPS was disabled

49.

A teacher asks students to document each step of a browser-security lab with screenshots and explanations of “what” and “why.” From a security operations perspective, what does this MOST closely resemble?

a)

Casual texting

b)

Forensic-quality evidence documentation

c)

Malware reverse engineering

d)

Bug bounty reporting

50.

A student opens many shady streaming sites and later asks why their system is slow and full of pop-ups. Which is the MOST likely cause?

a)

Heavy RAM usage by bookmarks

b)

Malware or adware installed via drive-by downloads and pop-ups

c)

Too many HTTPS connections

d)

Browser cache being empty

51.

A user wants to open a “New incognito window” to research a sensitive medical topic at home. What privacy benefit do they MOST likely gain?

a)

Their ISP cannot log their traffic

b)

Their home router stops seeing DNS requests

c)

Other family members won’t see the visited sites in local history

d)

Websites cannot track them

52.

You are defining a standard browser configuration for student laptops. Which combination BEST balances privacy and usability?

a)

Location: Allow; Pop-ups: Allow; Downloads: Auto to Downloads

b)

Location: Ask; Camera/Mic: Ask; Pop-ups: Block; Downloads: Ask location

c)

Location: Block; Camera/Mic: Block; Pop-ups: Allow; Downloads: Auto

d)

Location: Allow; Camera/Mic: Allow; Pop-ups: Block; Downloads: Auto

53.

An entry-level sysadmin is reviewing several possible responses to frequent “Your connection is not private” warnings on staff machines. Which action is MOST appropriate?

a)

Train users to click through if they recognize the site

b)

Disable certificate validation in the browser

c)

Investigate certificate issues on the affected sites or proxies and fix the root cause

d)

Turn off HTTPS inspection in all situations

54.

You must configure one shared library computer used by many patrons. Which password-related approach is BEST?

a)

Allow the browser to save passwords but clear them weekly

b)

Permit password saving only for HTTPS sites

c)

Disable browser password saving entirely on the shared device

d)

Use the same admin account password for all users

55.

You are analyzing two download behaviors: - User A downloads software only from official vendor sites. - User B downloads “cracked” versions from random forums. From a risk perspective, which statement is MOST accurate?

a)

Both users face the same risk if they use HTTPS

b)

User A faces higher risk because vendors are targeted more

c)

User B faces higher risk due to untrusted sources and possible tampering

d)

Risk cannot be evaluated without knowing file size

56.

A small business wants employees to access location-based features (maps, delivery services) while minimizing unnecessary tracking. Which policy is MOST appropriate?

a)

Location: Allow for all sites

b)

Location: Block for all sites

c)

Location: Ask, and instruct users to allow only for approved business apps

d)

Location: Allow in Incognito only

57.

You are choosing a policy for pop-ups and redirects on corporate browsers. Which option BEST supports security while allowing necessary business sites to function?

a)

Allow pop-ups from all sites

b)

Block pop-ups globally, with an approved exception list

c)

Block pop-ups only on HTTPS sites

d)

Allow pop-ups only when Incognito is used

58.

A security team is debating how often users should clear browsing data. Which practice BEST balances privacy and productivity for typical knowledge workers?

a)

Clear all data after every browsing session

b)

Clear cookies and cache weekly

c)

Clear browsing history monthly

d)

Never clear browsing data

59.

You must choose between two browser settings for downloads: Auto-save all files to a shared Downloads folder or ask for the save location each time. For a security-sensitive environment where users handle confidential documents, which is BETTER and why?

a)

Option 1, because it is simpler

b)

Option 1, because it uses less disk space

c)

Option 2, because it forces users to think about where sensitive data is stored

d)

They are equivalent

60.

An administrator is deciding whether to allow third-party browser extensions. Which policy BEST reflects a secure mindset?

a)

Allow all extensions; users know their needs

b)

Block all extensions, even from trusted vendors

c)

Allow only vetted, necessary extensions from official stores

d)

Allow extensions only in Incognito mode

61.

You see a user habitually relying on the address bar auto-complete for banking and school sites rather than typing URLs from memory. From a typosquatting defense perspective, how should you evaluate this behavior?

a)

Positive, because it reduces mistyped URLs

b)

Negative, because it always uses HTTP

c)

Neutral, because it doesn’t matter

d)

Negative, because bookmarks cannot be trusted

62.

A help desk technician proposes allowing 'Sites can use JavaScript' for all domains without restriction. What is the MOST appropriate response?

a)

Allow JavaScript for all domains; it improves functionality

b)

Restrict JavaScript usage to trusted domains only

c)

Block JavaScript entirely; it poses security risks

d)

Allow JavaScript only for Incognito mode

63.

What is the most practical approach to handling JavaScript in modern browsers?

a)

Approve it immediately; JavaScript is always safe

b)

Reject it; JavaScript should be disabled globally in modern browsers

c)

Allow JavaScript but pair it with strong anti-malware controls and user training

d)

Disable all browsers that use JavaScript

64.

When evaluating which sites should "always use HTTPS," which category should be considered the HIGHEST priority?

a)

News blogs without logins

b)

Public weather sites

c)

Banking, e-commerce, and grade/portal systems

d)

Meme sites

65.

You are comparing two approaches to handling suspicious certificate warnings for a critical internal app. From a security architecture perspective, which approach is BETTER and why?

a)

Approach A, because it avoids downtime

b)

Approach A, because users learn to recognize warnings

c)

Approach B, because it preserves user trust in browser warnings and removes the root cause

d)

They are equivalent

66.

You’re designing a training exercise on Incognito mode. Which learning objective BEST reflects a correct understanding?

a)

Students will use Incognito to bypass school content filters.

b)

Students will explain that Incognito hides local history but not traffic from the school or ISP.

c)

Students will show that Incognito encrypts all HTTP traffic.

d)

Students will prove that Incognito blocks all cookies.

67.

A new sysadmin suggests that employees use pirated software to save licensing costs, claiming that “as long as we scan downloads, it’s safe.” How should you evaluate this recommendation?

a)

Accept it; antivirus eliminates the risk

b)

Reject it; using pirated software is illegal and high-risk even with scanning

c)

Accept it only for non-critical systems

d)

Accept it if run in Incognito mode

68.

When choosing default browser settings for a high school lab environment, which policy for notification prompts is MOST appropriate?

a)

Allow notifications from all sites

b)

Block notifications globally

c)

Ask for notifications on all sites

d)

Turn off the browser’s notification feature

69.

You are comparing three policies for shared school computers: 1. Leave all cookies and history between users 2. Clear cookies and history at logoff 3. Disable browsing entirely Which option BEST balances usability and privacy?

a)

Policy 1

b)

Policy 2

c)

Policy 3

d)

None; all are equivalent

70.

A security analyst reviews logs and sees many outbound connections to domains like google-support.com and google-media.net. What is the BEST conclusion?

a)

Normal browser prefetching

b)

Malware infection

c)

Unauthorized data exfiltration

d)

Misconfigured proxy settings

71.

An admin wants to reduce risk from users installing random Chrome extensions. Which control is MOST effective?

a)

Telling users “don’t install bad extensions” in an email

b)

Implementing a group policy that only allows approved extensions from a curated list

c)

Requiring users to use Incognito

d)

Clearing cache weekly

72.

An organization must decide how to handle shared kiosk machines used for quick web access in a lobby. Which browser configuration is MOST appropriate?

a)

Enable password saving and keep history for 90 days

b)

Disable password saving, clear history on each session, and keep pop-ups blocked

c)

Allow pop-ups from all sites and enable notifications

d)

Leave all settings at home-user defaults

73.

A student often downloads lab files and leaves them mixed with personal downloads, making incident response harder. Which change would MOST improve traceability of lab materials?

a)

Turn off HTTPS

b)

Use a dedicated “LabDownloads” folder and configure the browser to save lab files there

c)

Disable all downloads

d)

Save everything on the desktop without organization

74.

When evaluating whether to rely on the padlock icon alone to judge website safety, which statement is MOST accurate?

a)

The padlock proves the site is legitimate and safe

b)

The padlock only confirms an encrypted connection and a valid certificate, not the legitimacy of the site

c)

The padlock ensures the website is free from malware

d)

The padlock guarantees the website is trustworthy

75.

What does the padlock symbol in a browser indicate about a website?

a)

The site is trustworthy and secure.

b)

HTTPS protects the channel, not necessarily the site's intentions.

c)

The padlock guarantees no malware is present.

d)

The padlock means the site is government-approved.

76.

A policy proposal suggests forcing 'Block all cookies' across every browser in the company. How should security leadership evaluate this?

a)

Fully adopt it; blocking all cookies has no downside.

b)

Reject it; many modern web apps break without cookies, and the policy will hurt usability.

c)

Adopt it only for home users.

d)

Adopt it only for developers.

77.

From a security perspective, which evaluation is MOST accurate regarding anti-phishing habits? Student A: 'I'll always check the domain name slowly before entering credentials.' Student B: 'I'll rely on how professional the website's graphics look.'

a)

Student A's approach is stronger because domain verification is harder to fake than page design.

b)

Student B's approach is stronger.

c)

Both are equally strong.

d)

Neither is useful.

78.

You are drafting a browser-security 'action plan' for new employees. Which item would be the MOST valuable to include?

a)

Always accept any certificate warning so you can finish work quickly.

b)

Use bookmarks or password-manager links for important sites instead of retyping URLs.

c)

Disable HTTPS on all internal sites to speed them up.

d)

Allow all pop-ups; blocking them is unnecessary.