CAPTCHA
Voice Cloning
Smishing
Extortion ware vs Ransomware
Information Security policies and expected employee actions
200
Which of the following is a common type of CAPTCHA?
A. Multi-Factor Authentication (MFA)
B. Firewall Authentication
C. Checkbox with "I am not a robot"
D. VPN Verification

C. Checkbox with "I am not a robot"

200

What is voice cloning? 

A. AI-generated copy of a person's voice
B. Voice recording backup
C. Call forwarding
D. Device synchronization

A. AI-generated copy of a person's voice

200
Which of the following is a common sign of a smishing message?
A. It comes from a trusted colleague
B. It contains urgent language demanding immediate action
C. It is sent during office hours

D. It contains your email signature

B. It contains urgent language demanding immediate action

200
Which description best explains ransomware?
A. Malware that secretly monitors user activity
B. Malware that blocks access to data and demands payment 
C. Malware that displays unwanted advertisements 

D. Malware that uses a device to mine cryptocurrency

B. Malware that blocks access to data and demands payment

200
What principle ensures users receive only the access required to perform their job
A. Open Access 
B. Least Privilege 
C. Unlimited Access 

D. Shared Access

B. Least Privilege

400
What is the biggest limitation of CAPTCHA as a security control?
A. It requires an internet connection
B. It can be bypassed and should not replace strong authentication controls
C. It only works on mobile devices
D. It prevents legitimate users from accessing systems​​​​​

B. It can be bypassed and should not replace strong authentication controls 

400

How can employees validate suspicious phone requests? 

A. Call back using an official directory number
B. Use speaker mode
C. Increase volume
D. Record the call

A. Call back using an official directory number

400
You clicked a suspicious SMS link but did not enter any information. What should you do next?
A. Do nothing
B. Report the incident and follow organizational security procedures 
C. Send the link to others for confirmation 

D. Continue using the site

B. Report the incident and follow organizational security procedures

400
Several networked devices become infected without users installing the same program. What most likely caused this?
A. A worm exploiting vulnerable devices 
B. Spyware monitoring one workstation
C. A keylogger recording keystrokes 

D. Adware displaying advertisements

A. A worm exploiting vulnerable devices

400
Which statement about software licensing is correct?
A. Employees may share licensed software with friends
B. Licensed software can be duplicated freely
C. All software must be properly licensed

D. License agreements are optional

C. All software must be properly licensed

600
A healthcare portal records thousands of account registration attempts from a single IP address. Why might CAPTCHA be triggered?
A. To improve website appearance
B. To detect and slow potential bot activity
C. To increase database size
D. To reduce network encryption​​​​​

B. To detect and slow potential bot activity 

600

Which department is often impersonated in voice-cloning attacks? 

A. Leadership and IT Support
B. Facilities
C. Cafeteria
D. Reception

A. Leadership and IT Support

600
Which statement about OTPs is correct?
A. They can be shared with bank representatives
B. They may be shared with IT support
C. They should never be shared with anyone

D. They can be shared if the sender sounds urgent

C. They should never be shared with anyone

600
An employee installs a free, unapproved utility that appears to work normally. In the background, it secretly gives an attacker access to the device. Which type of malware is most likely involved?
A. Ransomware
B. Computer worm
C. Trojan

D. Adware

C. Trojan

600
Why should employees avoid installing unauthorized software?
A. It may introduce security, legal, or operational risks  
B. It uses battery power  
C. It changes desktop icons  

D. It increases printing costs

A. It may introduce security, legal, or operational risks

800
Advances in Generative AI have created which challenge for traditional CAPTCHA systems?
A. AI models can increasingly solve visual and text-based CAPTCHAs with high accuracy 
B. AI permanently disables CAPTCHAs
C. AI automatically grants administrative privileges 

D. AI removes website encryption

A. AI models can increasingly solve visual and text-based CAPTCHAs with high accuracy

800

Why are voice-cloning attacks becoming more common? 

A. Easier access to AI tools and public voice samples
B. Better phone batteries
C. More video meetings
D. Lower network costs

A. Easier access to AI tools and public voice samples

800
Which combination of indicators most strongly suggests a smishing attempt?
A. Personalized greeting and official branding
B. Urgency, suspicious link, and request for sensitive information 
C. Company logo and generic text 

D. Message received during working hours

B. Urgency, suspicious link, and request for sensitive information

800
What is “persistence” in a malware attack?
A. Malware repeatedly displaying alerts
B. An attacker retaining access after remediation
C. A device remaining disconnected 

D. A backup taking longer than expected

B. An attacker retaining access after remediation

800
You are working remotely and receive an unexpected MFA approval prompt on your mobile device. What should you do?
A. Approve it quickly to stop the notifications  
B. Ignore it and continue working  
C. Deny the request and report it if you did not initiate a login  

D. Ask a coworker to approve it

C. Deny the request and report it if you did not initiate a login

1000
A security team notices that CAPTCHA completion rates by bots have significantly increased over the past year. What is the most appropriate response?
A. Remove CAPTCHA entirely 
B. Adopt layered defenses such as MFA, device reputation, behavioral analytics, and bot detection 
C. Disable monitoring controls 

D. Increase password sharing

B. Adopt layered defenses such as MFA, device reputation, behavioral analytics, and bot detection

1000

What is the BEST defense against advanced voice-cloning attacks? 

A. Relying on recognition alone
B. Independent verification and approval controls
C. Speaking slowly
D. Recording calls

B. Independent verification and approval controls

1000
A text message claims that unusual activity was detected on your account and asks you to call a number immediately. What is the most secure response?
A. Call the number provided in the message
B. Reply to confirm your identity
C. Contact the organization using official contact details from trusted sources

D. Share your account details during the call

C. Contact the organization using official contact details from trusted sources

1000
What is the first priority when ransomware is actively spreading?
A. Restore the latest backup 
B. Restart all affected devices
C. Isolate affected systems from the network

D. Delete the ransom note

C. Isolate affected systems from the network

1000
What factors should be considered for granting Access?
A. User role, location, Manager Approval
B. Manager Approval
C. User Preference 

D. User role, location, data classification, risk level

D. User role, location, data classification, risk level