CHAPTER QUIZ

Final Assessment

20 questions covering this module.

You can practise anonymously. Sign in to grade and save your attempt.

Sign in to track progress

Final Assessment

0/20 answered

1. A finance employee receives an emailed payment request that seems suspicious, so they ask to verify. The requester immediately offers a video call, on which a recognised senior colleague repeats the request. What should the employee do?

2. Which four elements form the skeleton of a manipulation attempt? Select all that apply.

3. Why is enforced secrecy the strongest single signal in that skeleton?

4. An attacker signs in using credentials stolen through a phishing page. Why is this difficult to detect?

5. What makes a passkey resistant to phishing, where an authenticator app code is not?

6. Why does changing a password often fail to evict an attacker?

7. What is the root cause of prompt injection?

8. Which change most reduces the severity of a successful prompt injection?

9. A chatbot answers staff questions from an internal wiki any employee can edit. What is the principal risk?

10. How should output produced by a language model be treated before it is used by another system?

11. Which property is shared by patching, passkeys, least privilege, tested backups and dual authorisation?

12. An organisation stores backups on a share reachable with the same administrative credentials as the servers they protect. What is this an example of?

13. Which are common causes of privilege creep? Select all that apply.

14. An attacker quietly alters the bank details on one supplier record. Which property has been broken, and why is it dangerous?

15. A supplier emails from their correct address to notify a change of bank details. What is the correct response?

16. Why is "check for spelling and grammar mistakes" now considered harmful advice?

17. An engineer pastes proprietary source code into a public chatbot to debug it. What is the most accurate description?

18. Which of these actions should follow a suspected phishing compromise? Select all that apply.

19. Money has been transferred to a fraudulent account. Why does speed matter more here than in most incidents?

20. What is the through line of this course regarding where defensive effort should go?