Study sets
English

IT and Internet Literacy Quiz | Spotting Phishing Emails, Fake Sites, and QR Code Scams

1 / 100.0s

Problem 1

An unexpected email claiming to be from your cloud storage service says all your data will be deleted unless you confirm within five minutes. The linked page asks for your password and card number. Which combination is the most important phishing warning sign?

View explanation

A short deadline or threatened loss is used to rush your judgment, while a linked page unexpectedly requests login and financial information. Logos, names, and company details can be copied, so their presence does not prove legitimacy.

Problem 2

An online interview invitation displays the name of a recruiter from a major company, but it asks for bank details before you have formally applied. What should you examine first when checking the sender?

View explanation

Display names and logos are easy to copy. Reveal the full sender address and compare its domain with the company's legitimate domain. Even if it appears correct, an unusual request for bank details before an application should be verified separately with the company.

Problem 3

An email displays the link text “Check at account.example.com,” but previewing the destination without opening it shows “account-example.secure-login.example.” What is the most appropriate response?

View explanation

Visible link text and the actual destination can be different. Here, the registered domain also differs from the stated site, so use an independent route such as a saved official address or app. Page colors and appearance do not verify the destination.

Problem 4

A close friend's account unexpectedly sends you a file named “travel-photos.zip” with no explanation. This friend normally contacts you before sending files. What is the best action before opening it?

View explanation

A friend's account can be compromised, so verify an unexpected attachment through a separate channel you already know. Checking only within the received conversation may allow the attacker controlling the account to answer.

Problem 5

At a public parking lot, a new QR code sticker appears to cover the original payment instructions. Scanning it begins to open a page asking for card details. What is the most appropriate response?

View explanation

Someone can replace a QR code, and its destination is not visible from the image alone. If a sticker looks altered, do not make even a test payment. Confirm the official payment method using the facility's established instructions or operator.

Problem 6

A page on a domain resembling a well-known shopping site shows HTTPS and a padlock in the address bar. What can you conclude with certainty from that indicator?

View explanation

HTTPS and the padlock indicate encryption between the browser and the current destination. A fake site can also use HTTPS, so the indicator does not verify the operator, the products, or the absence of malware. Check the domain separately.

Problem 7

Your email service has a “Report phishing” feature. You receive a suspicious promotional message that also contains an “unsubscribe” link. What is the most appropriate handling?

View explanation

Report a suspicious message through the available reporting feature or designated channel, then delete it without using links, including unsubscribe. An attacker-controlled link may lead to a fake site or confirm that your address is active.

Problem 8

Right after entering your shopping-site username and password on a page opened from a delivery-notice QR code, you notice that the domain is fake. What is the most appropriate first response?

View explanation

The submitted credentials may already have reached the attacker. Change the password immediately through the legitimate service, not through the fake page, and enable two-factor authentication. If the password was reused elsewhere, replace it there with a different password as well.

Problem 9

You opened an unexpected attachment on your personally owned computer and may have downloaded malicious software. Nothing obvious has changed on screen. Which safety check is most appropriate?

View explanation

Malicious activity may not produce a visible change. On a personal device, update trusted security software, scan the system, and follow the results. For an employer- or school-managed device, follow the organization's reporting procedure instead of acting independently.

Problem 10

A billing email uses your video service's logo and contains no spelling errors, but it asks you to re-enter card details for a charge you do not recognize. What is the most appropriate judgment?

View explanation

Attackers can reproduce a real company's logo and write polished messages. Because the charge is unfamiliar and the message requests card details, avoid its links and contact information and verify the account through a known official route.