AuthenticationQuestion 1 of 25
1. What is the main purpose of authentication?
AuthenticationQuestion 2 of 25
2. Which statement correctly separates authentication from authorization?
CredentialsQuestion 3 of 25
3. Which item is the best example of a credential?
PassphrasesQuestion 4 of 25
4. Which change usually makes a login secret stronger?
PassphrasesQuestion 5 of 25
5. Which fake credential is most predictable?
Password ReuseQuestion 6 of 25
6. Why is password reuse dangerous?
Password ManagersQuestion 7 of 25
7. What is the main benefit of a password manager?
Password ManagersQuestion 8 of 25
8. What should be true about a password manager master password?
Autofill SafetyQuestion 9 of 25
9. A password manager does not autofill on a page that looks like the school portal. What is the safest response?
MFAQuestion 10 of 25
10. What makes authentication truly multi-factor?
MFAQuestion 11 of 25
11. Which pair represents two different authentication factors?
MFA PromptsQuestion 12 of 25
12. What should a user do with an unexpected MFA approval prompt?
Verification CodesQuestion 13 of 25
13. Why should one-time verification codes never be shared?
MFA FatigueQuestion 14 of 25
14. What is MFA fatigue?
RecoveryQuestion 15 of 25
15. What is the safest way to begin account recovery?
RecoveryQuestion 16 of 25
16. Why should recovery information be reviewed before an emergency?
Backup CodesQuestion 17 of 25
17. How should backup recovery codes be handled?
Login AlertsQuestion 18 of 25
18. What makes a login alert most useful?
Active SessionsQuestion 19 of 25
19. What is the safest response to an unknown active browser session?
Layered SecurityQuestion 20 of 25
20. What does layered account security mean?
Security ChecklistQuestion 21 of 25
21. Which group belongs in a complete account security checklist?
Shared DevicesQuestion 22 of 25
22. A student finds another person’s school account still open on a shared computer. What is the safest response?
Incident ResponseQuestion 23 of 25
23. Which action is an example of containment?
Risk PrioritizationQuestion 24 of 25
24. A fictional account has an unknown active session, an old recovery email, and a strong unique password. What should usually be addressed first?
Safe ResponseQuestion 25 of 25
25. A message demands a recovery code and says the account will be deleted in five minutes. What is the safest response?