MFA
Business Email Compromise
VISHING
Impersonation Attacks
Security Incident Reporting
200

What is the main purpose of Multi-Factor Authentication (MFA)?

a. To increase internet speed
b. To provide an extra layer of security for accounts
c. To store files online
d. To replace usernames Correct

b. To provide an extra layer of security for accounts

200

What is Business Email Compromise (BEC)?

A. A software bug that crashes email systems
B. A type of social engineering where attackers impersonate a trusted sender  
C. A computer virus hidden in email attachments
D. A method for encrypting emails

B. A type of social engineering where attackers impersonate a trusted sender  

200

Which of the following is a common warning sign of a vishing attack?

A. The caller provides clear verification procedures
B. The caller pressures you to act immediately
C. The caller sends official documentation first
D. The caller uses the company directory

B. The caller pressures you to act immediately

200

What should you do before sharing sensitive information?

A. Share immediately
B. Verify the person's identity
C. Post it in Teams
D. Save it for later

B. Verify the person's identity

200

Why is timely incident reporting important?

A.To increase workload for security teams
B.To help contain and mitigate potential security risks quickly
C. To delay business operations
D. To generate additional reports

B. To help contain and mitigate potential security risks quickly

400

If you are not attempting to sign in but receive an MFA prompt, what should you do first?

a. Approve the request
b. Retry the sign-in
c. Deny the request and report it to SIR
d. Turn off your phone

c. Deny the request and report it to SIR

400

Which of the following should be considered a warning sign of a potential BEC attack?

A. An email newsletter from a subscribed vendor
B. A meeting invitation from your manager's calendar
C. An urgent request to update payment details using a new bank account
D. A reminder to complete mandatory training

C. An urgent request to update payment details using a new bank account

400

An attacker claims your corporate account will be disabled within an hour unless you verify your login credentials over the phone. What tactic is being used?

A. Curiosity
B. Urgency
C. Reward
D. Social networking

B. Urgency

400

Which scenario is an impersonation attack?

A. Official HR communication
B. Colleague requesting a meeting room
C. Fake vendor requesting urgent payment
D. Software update notification

C. Fake vendor requesting urgent payment

400

Which information is most useful when reporting a security incident?

A. Accurate details about what happened, when it occurred, and affected systems
B. Personal opinions only
C. Information unrelated to the incident
D. Assumptions without evidence

A. Accurate details about what happened, when it occurred, and affected systems

600

What does MFA require?

a. Two or more verification factors
b. Two passwords
c. Two email accounts
d. Two devices

a. Two or more verification factors

600

Which request is LEAST likely to be associated with a BEC attack?

A. "Please keep this confidential and act immediately."
B. "Update the supplier's banking details today."
C. "Buy gift cards and send photos of the codes."
D. "Review the monthly team newsletter when you have time."

D. "Review the monthly team newsletter when you have time."

600

A caller asks you to install remote-access software to "fix" an urgent issue on your computer. What should you do?

A. Follow the instructions immediately
B. Install the software but monitor activity
C. Verify the request with IT through approved channels before taking action
D. Give temporary access

C. Verify the request with IT through approved channels before taking action

600

How can MFA help reduce impersonation risks?

A. It provides an extra verification layer
B. It increases storage
C. It blocks Teams meetings
D. It speeds up networks

A. It provides an extra verification layer

600

Why should employees avoid investigating suspected incidents on their own?

A. It may destroy evidence or interfere with official investigations
B. It makes reporting easier
C. It guarantees faster recovery
D. It prevents security teams from working Correct

A. It may destroy evidence or interfere with official investigations

800

Why do cybercriminals use MFA fatigue attacks?

a. To improve account security
b. To pressure users into approving an authentication request
c. To improve system performance
d. To synchronize devices

b. To pressure users into approving an authentication request

800

Which of the following is the strongest indicator of a Business Email Compromise (BEC) attack?

A. Email contains an attachment
B. Email requests urgent action involving money or sensitive information
C. Email is sent during office hours
D. Email has a company logo

B. Email requests urgent action involving money or sensitive information

800

A vishing caller accurately knows your name, department, and manager. What should you conclude?

A. The caller is legitimate
B. The information proves the caller works for your company
C. Publicly available or previously compromised information may have been used to build credibility D. The caller must be from Human Resources

C. Publicly available or previously compromised information may have been used to build credibility

800

Which control most effectively mitigates impersonation attacks?

A. Dual monitors
B. Verification and approval procedures
C. Screen brightness
D. Browser bookmarks

B. Verification and approval procedures

800

Why is preserving evidence important during an information security incident?

A. It helps support investigation, containment, and corrective actions
B. It improves system performance
C. It eliminates the need for reporting
D. It prevents future software updates

A. It helps support investigation, containment, and corrective actions

1000

After clicking a suspicious link, you start receiving MFA prompts. What is the most likely explanation?

a. Your device needs an update
b. A cybercriminal may be attempting to access your account using stolen credentials
c. Your mailbox is full
d. Your internet connection is unstable

b. A cybercriminal may be attempting to access your account using stolen credentials

1000

Which of the following makes BEC attacks more difficult to detect than traditional phishing?

A. They use large malware attachments
B. They target random employees
C. They often contain no malicious links or attachments
D. They always originate externally

C. They often contain no malicious links or attachments

1000

Which of the following scenarios best demonstrates a sophisticated vishing attack?

A. A caller asks for directions to the office
B. A caller requests publicly available company information
C. A caller impersonates IT support, references a recent ticket, and requests credential verification
D. A caller invites employees to a company event

C. A caller impersonates IT support, references a recent ticket, and requests credential verification

1000

What should employees do when uncertain about a request's legitimacy?

A. Proceed carefully
B. Independently validate before acting
C. Share with coworkers
D. Ignore security concerns

B. Independently validate before acting

1000

Which of the following incidents should be reported even if no immediate impact is observed?

A. Suspicious account activity detected on a company system
B. Completion of annual training
C. Routine password change
D. Office relocation announcement

A. Suspicious account activity detected on a company system

M
e
n
u