Multiple-choice and scenario-based phishing-defense questions.
Answers stay hidden
Scores and explanations appear only after submission.
Fake examples only
Do not use real suspicious links, files, credentials, codes, payment details, phone numbers, or private information.
Questions answered0/25
Social EngineeringQuestion 1 of 25
1. What is social engineering?
Manipulation TacticsQuestion 2 of 25
2. Which message uses urgency as a manipulation tactic?
Manipulation TacticsQuestion 3 of 25
3. Why is a demand for secrecy suspicious?
Email AnalysisQuestion 4 of 25
4. Why is an email display name not enough to prove who sent the message?
Email AnalysisQuestion 5 of 25
5. Which sender detail is the strongest warning sign?
Email AnalysisQuestion 6 of 25
6. What is the safest response to an urgent account-warning email?
SmishingQuestion 7 of 25
7. What is smishing?
VishingQuestion 8 of 25
8. What is vishing?
Phone SafetyQuestion 9 of 25
9. Why should caller ID not be trusted by itself?
Social Media ScamsQuestion 10 of 25
10. A familiar social profile asks for emergency money and says not to call. What is the safest response?
ImpersonationQuestion 11 of 25
11. What is impersonation?
Fake SupportQuestion 12 of 25
12. What should happen when a support message requests an MFA code?
Fake SupportQuestion 13 of 25
13. Why is an unexpected remote-access request dangerous?
Recovery SecretsQuestion 14 of 25
14. What should a student do if a caller requests a recovery code?
Link JudgmentQuestion 15 of 25
15. Why can a shortened link be risky?
Link JudgmentQuestion 16 of 25
16. What is the safest response to a suspicious login link?
Attachment JudgmentQuestion 17 of 25
17. Which filename is the strongest warning sign?
Attachment JudgmentQuestion 18 of 25
18. What should a student do with an unexpected attachment from a familiar display name?
Safe UpdatesQuestion 19 of 25
19. Where should software updates normally come from?
ReportingQuestion 20 of 25
20. What should a useful phishing report include?
ReportingQuestion 21 of 25
21. Why should suspicious files not be forwarded with a report?
Incident ResponseQuestion 22 of 25
22. What should happen if a student clicked a suspicious link?
Account ContainmentQuestion 23 of 25
23. What should happen after an unexpected MFA prompt?
Account ContainmentQuestion 24 of 25
24. A suspicious link is followed by an unknown active browser session. What should happen first?
Phishing Defense LabQuestion 25 of 25
25. A fictional student receives an urgent teacher-style email, enters a password on a look-alike page, denies an MFA prompt, sees an unknown session, and gets a fake support call. What is the safest response order?
Submit Module Test
25 questions remaining
Your score and answer explanations will appear only after you submit the complete test.