Cyber Security
Introduction to Financial Literacy · 20 lessons
What is cyber security?
Why A is correct:
Cybersecurity is about defending digital systems, data, and networks from threats like hacking, malware, and theft. It's the core definition of the field.
Why the others are wrong:
- B (physical assets): That's physical security, not cyber security—different field entirely.
- C (hacking): Hacking is what cybersecurity *defends against*, not what cybersecurity is.
- D (sharing personal info): That's actually the *opposite* of cybersecurity; sharing info recklessly creates security risks.
Why is cyber security important?
A is correct: Cybersecurity protects personal and financial data from criminals, reducing the real risks of fraud and identity theft.
B is wrong: No security system can guarantee "absolute" protection—threats constantly evolve, so cybersecurity reduces risk but doesn't eliminate it completely.
C is wrong: Cybersecurity doesn't eliminate online transactions; it makes them *safer* so people can use them confidently.
D is wrong: Cybersecurity doesn't restrict internet access—it protects users *while* they use digital tools and the internet.
What are some common cyber threats?
Why A is correct:
Phishing and malware are classic cyber threats—they're digital attacks that exploit software vulnerabilities or trick users into compromising their own security.
Why the others are wrong:
- B (Physical theft): This is a physical security threat, not a cyber threat. Cyber threats are digital attacks over networks.
- C (Physical attacks on networks): Again, this is physical security. Cyber threats happen digitally, not with physical force.
- D (Shopping and social media): These are normal online activities, not threats themselves—though they can *involve* cyber threats like phishing or malware.
What is the purpose of strong and unique passwords?
A is correct: Strong, unique passwords act as a barrier that makes it extremely difficult for hackers to guess or crack your account, keeping your personal information and accounts secure.
B is wrong: This is the opposite of what passwords do—hackers *want* to guess passwords, but strong ones prevent that.
C is wrong: While you should memorize passwords, that's a side benefit, not the main purpose of making them strong and unique.
D is wrong: Easy access is actually a security risk; passwords should be hard to access *for others*, not easy for everyone.
What is two-factor authentication (2FA)?
Why A is correct:
2FA requires two separate verification methods (like a password plus a code from your phone) to log in, making it much harder for hackers to access your account even if they steal your password.
Why the others are wrong:
- B: Using two devices at once has nothing to do with authentication or security verification.
- C: That describes encryption, not authentication—it's about protecting data that's already stored, not verifying identity.
- D: Two passwords are just variations of the same verification method; 2FA requires *different types* of verification (something you know + something you have/are).
What is phishing?
A is correct: Phishing is a cybercrime where attackers trick people into revealing sensitive information (passwords, credit card numbers, etc.) by pretending to be legitimate companies through fake emails or websites.
B is wrong: While it uses the word "phishing," this describes a video game activity, not a real security threat.
C is wrong: Encryption protects data by scrambling it—the opposite of phishing, which exposes data through deception.
D is wrong: That describes networking or connectivity, which has nothing to do with stealing information or deception.
What is malware?
Why A is correct:
Malware stands for "malicious software"—it's specifically designed to harm, infiltrate, or damage computers and systems without the user's permission.
Why the others are wrong:
- B describes performance-enhancing software (legitimate utilities), the opposite of malware
- C describes security software for transactions (like encryption tools), which protects rather than damages
- D describes secure storage/sharing apps (like cloud services), which are protective, not harmful
What is a firewall?
Why A is correct:
A firewall is software or hardware that monitors incoming and outgoing network traffic, blocking unauthorized access while allowing legitimate communication. It's the primary gatekeeper for computer networks.
Why the others are wrong:
- B (physical barrier): While firewalls can be physical devices, their main job is digital security, not physical protection from damage.
- C (secure communication): Firewalls don't enable communication—they control and filter it. VPNs or encryption tools do secure communication.
- D (encryption tool): Firewalls don't encrypt data; they filter traffic. Encryption tools like SSL certificates handle that separately.
What is a VPN (Virtual Private Network)?
A is correct: A VPN encrypts your internet traffic and routes it through a secure server, hiding your IP address and protecting your data from hackers on public networks. This is the core function of VPNs.
B is wrong: While VPNs can be used on public networks, they don't just "access the internet through" them—they *secure* that connection, which is the whole point.
C is wrong: That describes a physical LAN (Local Area Network), not a virtual private network. VPNs are software-based, not physical infrastructure.
D is wrong: That's a backup tool or external storage function, completely unrelated to VPN technology.
What is encryption?
A is correct: Encryption scrambles readable data into unreadable code using a special key—only someone with the right key can decode it back into readable information.
Why the others are wrong:
- B (backups): That's data protection through copies, not conversion to secret code.
- C (deleting): That's data removal, the opposite of encryption.
- D (databases): That's data organization and storage, not conversion to secret code.
What is the purpose of software updates and patches?
A is correct: Security vulnerabilities and bug fixes are the primary purpose of patches and updates—they protect your device from attacks and make software work properly.
B is wrong: Updates may occasionally affect performance, but slowing down your computer is never the intended goal.
C is partially true but incomplete: While some updates add features, the core purpose of patches is fixing problems, not adding new capabilities.
D is wrong: Updates don't restrict your access to websites or apps; that would be a parental control or firewall feature, not an update.
What is a secure website?
Why A is correct:
Encryption scrambles your data (like passwords or credit card numbers) so only authorized parties can read it. This protects your information while traveling between your device and the website's server—the core definition of a secure website.
Why the others are wrong:
- B: Ads and pop-ups are annoying but don't relate to security or data protection.
- C: Asking for personal information doesn't make a site secure; it might actually indicate poor security if that information isn't encrypted.
- D: Restricting user access is about privacy control, not about protecting data from being intercepted or stolen during transmission.
What is a data breach?
Why A is correct:
A data breach happens when someone gains unauthorized access to sensitive information (like passwords, personal data, or financial records) and exposes it. This is the defining characteristic of a breach.
Why the others are wrong:
- B describes normal data transfer, which is legal and intentional—not a breach
- C is about data deletion, which is the opposite of exposure
- D describes malware distribution, which is a separate cybercrime (though malware can *cause* a breach)
What is a strong indicator of a phishing email?
Correct Answer (A): Legitimate organizations almost never ask for passwords or personal information via email. Phishers use this tactic to steal credentials and commit identity theft, making it a primary red flag.
Why others are wrong:
- B: Emails from trusted sources are actually *safe*—phishing involves deception, so a genuinely known sender isn't phishing.
- C: While many phishing emails do have poor grammar, some are well-written. It's a *common* indicator but not as reliable as A.
- D: Attachments and links aren't inherently suspicious—legitimate emails use them regularly. You need other warning signs to confirm phishing.
What is the importance of regularly backing up data?
A is correct because backups create copies of your data stored separately, so if your original files are lost, damaged, corrupted, or stolen, you can restore them from the backup.
B is wrong — backups actually *reduce* risk by protecting against loss; they don't increase it.
C is wrong — backups preserve data rather than delete it. You'd use other methods (like archive tools) to permanently remove unwanted files.
D is wrong — backups and security measures like passwords/encryption serve different purposes. Backups don't replace the need for strong security; you need both.
What is a digital footprint?
A is correct: Your digital footprint is everything you do online—posts, searches, logins, purchases, comments—that creates a record about you on the internet.
B is wrong: Physical location of a device has nothing to do with a digital footprint; that's just hardware placement.
C is wrong: Deleting files is an action you can take, but it's not what a digital footprint *is*.
D is wrong: While tracking transactions might be *part* of your footprint, this definition is too narrow and specific—a digital footprint includes much more than just financial activity.
What is the purpose of regular antivirus scans?
A is correct: Regular antivirus scans search your system for viruses, malware, and other threats, then remove them to keep your computer safe and secure.
B is wrong: While scans may temporarily use system resources, slowing performance is a *side effect*, not the purpose.
C is wrong: That's what parental controls or firewalls do, not antivirus software.
D is wrong: That's the job of disk cleanup tools, not antivirus programs—antivirus targets malicious code specifically, not just any unnecessary files.
What is the role of user awareness in cyber security?
A is correct: User awareness is foundational to cyber security—when people understand phishing scams, password safety, and suspicious links, they become the first line of defense against attacks.
B is wrong: User behavior is actually one of the biggest factors in security. Many breaches happen because people click malicious links or use weak passwords, so awareness directly impacts security.
C is wrong: While awareness is powerful, it's not a guarantee. No single measure can block *all* threats—you still need firewalls, updates, and other technical protections working together.
D is wrong: User awareness doesn't restrict internet access; it teaches safer *ways* to use the internet and technology responsibly.
What should you do if you suspect a cyber security incident?
A is correct: Reporting to authorities or IT immediately allows professionals to contain the threat, investigate, and protect other systems before damage spreads.
B is wrong: Ignoring incidents lets attackers operate undetected, making the breach worse and harder to fix later.
C is wrong: Posting on social media alerts attackers that you're aware of the breach, gives them time to cover tracks, and may panic other users without helpful information.
D is wrong: Paying ransoms funds criminal operations, doesn't guarantee your data back, and often violates laws—IT professionals have better recovery options.
Practise any of these free
Make an account in under a minute, or try it as a guest first.
Start learning free