1. Why is "check for spelling and grammar mistakes" now described as harmful rather than simply outdated?
2. What are the four structural components of a manipulation attempt? Select all that apply.
3. Which component should be weighted most heavily, and why?
4. What is the "circle test" for distinguishing genuine confidentiality from fraudulent secrecy?
5. In the verification ritual, why must you use a contact detail you already had?
6. A supplier emails from their correct address to say their bank details have changed. What is the appropriate response?
7. Why is a change to stored supplier bank details higher risk than a single payment request?
8. Why should training move away from teaching people to detect synthetic audio and video?
9. Which of these are reasons an attacker may choose chat, text or a phone call over email? Select all that apply.
10. What is the argument for always verifying, even when the request is probably genuine?