Cyber Security

Introduction to Financial Literacy · 20 lessons

What is cyber security?

  • The protection of digital assets from unauthorized access or attacks
  • The protection of physical assets
  • The process of hacking into computer systems
  • The practice of sharing personal information online
Why:

Why A is correct:
Cybersecurity is about defending digital systems, data, and networks from threats like hacking, malware, and theft. It's the core definition of the field.

Why the others are wrong:
- B (physical assets): That's physical security, not cyber security—different field entirely.
- C (hacking): Hacking is what cybersecurity *defends against*, not what cybersecurity is.
- D (sharing personal info): That's actually the *opposite* of cybersecurity; sharing info recklessly creates security risks.

Why is cyber security important?

  • It helps prevent financial fraud and identity theft
  • It guarantees absolute protection against all cyber threats
  • It eliminates the need for online transactions and digital communication
  • It restricts access to the internet and digital technologies
Why:

A is correct: Cybersecurity protects personal and financial data from criminals, reducing the real risks of fraud and identity theft.

B is wrong: No security system can guarantee "absolute" protection—threats constantly evolve, so cybersecurity reduces risk but doesn't eliminate it completely.

C is wrong: Cybersecurity doesn't eliminate online transactions; it makes them *safer* so people can use them confidently.

D is wrong: Cybersecurity doesn't restrict internet access—it protects users *while* they use digital tools and the internet.

What are some common cyber threats?

  • Phishing attacks and malware infections
  • Physical theft of digital devices
  • Physical attacks on computer networks
  • Online shopping and social media usage
Why:

Why A is correct:
Phishing and malware are classic cyber threats—they're digital attacks that exploit software vulnerabilities or trick users into compromising their own security.

Why the others are wrong:
- B (Physical theft): This is a physical security threat, not a cyber threat. Cyber threats are digital attacks over networks.
- C (Physical attacks on networks): Again, this is physical security. Cyber threats happen digitally, not with physical force.
- D (Shopping and social media): These are normal online activities, not threats themselves—though they can *involve* cyber threats like phishing or malware.

What is the purpose of strong and unique passwords?

  • To protect accounts from unauthorized access
  • To make it easier for hackers to guess passwords
  • To remember passwords without writing them down
  • To provide easy access to online accounts
Why:

A is correct: Strong, unique passwords act as a barrier that makes it extremely difficult for hackers to guess or crack your account, keeping your personal information and accounts secure.

B is wrong: This is the opposite of what passwords do—hackers *want* to guess passwords, but strong ones prevent that.

C is wrong: While you should memorize passwords, that's a side benefit, not the main purpose of making them strong and unique.

D is wrong: Easy access is actually a security risk; passwords should be hard to access *for others*, not easy for everyone.

What is two-factor authentication (2FA)?

  • A method of adding an additional layer of security to online accounts
  • A method of using two different digital devices simultaneously
  • A method of encrypting data for secure storage
  • A method of using two different passwords for online accounts
Why:

Why A is correct:
2FA requires two separate verification methods (like a password plus a code from your phone) to log in, making it much harder for hackers to access your account even if they steal your password.

Why the others are wrong:
- B: Using two devices at once has nothing to do with authentication or security verification.
- C: That describes encryption, not authentication—it's about protecting data that's already stored, not verifying identity.
- D: Two passwords are just variations of the same verification method; 2FA requires *different types* of verification (something you know + something you have/are).

What is phishing?

  • A method of stealing personal information through deceptive emails or websites
  • A method of catching fish in a virtual environment
  • A method of encrypting files for secure storage
  • A method of connecting computers and devices to a network
Why:

A is correct: Phishing is a cybercrime where attackers trick people into revealing sensitive information (passwords, credit card numbers, etc.) by pretending to be legitimate companies through fake emails or websites.

B is wrong: While it uses the word "phishing," this describes a video game activity, not a real security threat.

C is wrong: Encryption protects data by scrambling it—the opposite of phishing, which exposes data through deception.

D is wrong: That describes networking or connectivity, which has nothing to do with stealing information or deception.

What is malware?

  • Software that infects and damages computer systems
  • Software that enhances computer performance
  • Software used for secure online transactions
  • Software used for secure file storage and sharing
Why:

Why A is correct:
Malware stands for "malicious software"—it's specifically designed to harm, infiltrate, or damage computers and systems without the user's permission.

Why the others are wrong:
- B describes performance-enhancing software (legitimate utilities), the opposite of malware
- C describes security software for transactions (like encryption tools), which protects rather than damages
- D describes secure storage/sharing apps (like cloud services), which are protective, not harmful

What is a firewall?

  • A security measure that prevents unauthorized access to computer networks
  • A physical barrier to protect computers from physical threats
  • A device used for secure online communication
  • A tool for encrypting and decrypting data
Why:

Why A is correct:
A firewall is software or hardware that monitors incoming and outgoing network traffic, blocking unauthorized access while allowing legitimate communication. It's the primary gatekeeper for computer networks.

Why the others are wrong:
- B (physical barrier): While firewalls can be physical devices, their main job is digital security, not physical protection from damage.
- C (secure communication): Firewalls don't enable communication—they control and filter it. VPNs or encryption tools do secure communication.
- D (encryption tool): Firewalls don't encrypt data; they filter traffic. Encryption tools like SSL certificates handle that separately.

What is a VPN (Virtual Private Network)?

  • A method of securely connecting to the internet and protecting online privacy
  • A method of accessing the internet through a public network
  • A physical network of interconnected computers
  • A tool for backing up data to external storage devices
Why:

A is correct: A VPN encrypts your internet traffic and routes it through a secure server, hiding your IP address and protecting your data from hackers on public networks. This is the core function of VPNs.

B is wrong: While VPNs can be used on public networks, they don't just "access the internet through" them—they *secure* that connection, which is the whole point.

C is wrong: That describes a physical LAN (Local Area Network), not a virtual private network. VPNs are software-based, not physical infrastructure.

D is wrong: That's a backup tool or external storage function, completely unrelated to VPN technology.

What is social engineering?

  • A method of manipulating individuals to gain unauthorized access to information
  • A method of manipulating social media platforms
  • A method of building strong social connections online
  • A method of using advanced search techniques on the internet
Why:

Why A is correct:
Social engineering is a security threat where attackers trick or manipulate people (not systems) into revealing confidential information or granting access. It exploits human psychology rather than technical vulnerabilities.

Why the others are wrong:
- B - While attackers might use social media as a tool, social engineering isn't specifically about manipulating platforms themselves
- C - This describes healthy relationship-building, not the deceptive manipulation that defines social engineering
- D - This is just internet research; it has nothing to do with manipulation or security threats

What is encryption?

  • The process of converting digital information into a secret code
  • The process of creating backups of important files and documents
  • The process of permanently deleting digital data
  • The process of organizing and structuring data in a database
Why:

A is correct: Encryption scrambles readable data into unreadable code using a special key—only someone with the right key can decode it back into readable information.

Why the others are wrong:
- B (backups): That's data protection through copies, not conversion to secret code.
- C (deleting): That's data removal, the opposite of encryption.
- D (databases): That's data organization and storage, not conversion to secret code.

What is the purpose of software updates and patches?

  • To fix security vulnerabilities and bugs
  • To slow down computer performance
  • To introduce new features and functionality
  • To restrict access to certain websites and applications
Why:

A is correct: Security vulnerabilities and bug fixes are the primary purpose of patches and updates—they protect your device from attacks and make software work properly.

B is wrong: Updates may occasionally affect performance, but slowing down your computer is never the intended goal.

C is partially true but incomplete: While some updates add features, the core purpose of patches is fixing problems, not adding new capabilities.

D is wrong: Updates don't restrict your access to websites or apps; that would be a parental control or firewall feature, not an update.

What is a secure website?

  • A website that uses encryption to protect data during transmission
  • A website with a lot of advertisements and pop-ups
  • A website that requires a lot of personal information to access
  • A website that restricts access to certain users
Why:

Why A is correct:
Encryption scrambles your data (like passwords or credit card numbers) so only authorized parties can read it. This protects your information while traveling between your device and the website's server—the core definition of a secure website.

Why the others are wrong:
- B: Ads and pop-ups are annoying but don't relate to security or data protection.
- C: Asking for personal information doesn't make a site secure; it might actually indicate poor security if that information isn't encrypted.
- D: Restricting user access is about privacy control, not about protecting data from being intercepted or stolen during transmission.

What is a data breach?

  • The unauthorized access and exposure of sensitive information
  • A method of transferring data from one device to another
  • A method of permanently deleting digital data
  • The intentional spreading of computer viruses and malware
Why:

Why A is correct:
A data breach happens when someone gains unauthorized access to sensitive information (like passwords, personal data, or financial records) and exposes it. This is the defining characteristic of a breach.

Why the others are wrong:
- B describes normal data transfer, which is legal and intentional—not a breach
- C is about data deletion, which is the opposite of exposure
- D describes malware distribution, which is a separate cybercrime (though malware can *cause* a breach)

What is a strong indicator of a phishing email?

  • An email asking for personal information or login credentials
  • An email from a known and trusted source
  • An email with grammatical errors and typos
  • An email with a lot of attachments and links
Why:

Correct Answer (A): Legitimate organizations almost never ask for passwords or personal information via email. Phishers use this tactic to steal credentials and commit identity theft, making it a primary red flag.

Why others are wrong:
- B: Emails from trusted sources are actually *safe*—phishing involves deception, so a genuinely known sender isn't phishing.
- C: While many phishing emails do have poor grammar, some are well-written. It's a *common* indicator but not as reliable as A.
- D: Attachments and links aren't inherently suspicious—legitimate emails use them regularly. You need other warning signs to confirm phishing.

What is the importance of regularly backing up data?

  • It ensures the availability of data in case of loss or damage
  • It increases the risk of data loss and cyber attacks
  • It guarantees the permanent deletion of unnecessary files
  • It reduces the need for strong passwords and encryption
Why:

A is correct because backups create copies of your data stored separately, so if your original files are lost, damaged, corrupted, or stolen, you can restore them from the backup.

B is wrong — backups actually *reduce* risk by protecting against loss; they don't increase it.

C is wrong — backups preserve data rather than delete it. You'd use other methods (like archive tools) to permanently remove unwanted files.

D is wrong — backups and security measures like passwords/encryption serve different purposes. Backups don't replace the need for strong security; you need both.

What is a digital footprint?

  • The trail of online activities and information left behind by an individual
  • The physical location of a digital device
  • The process of securely deleting digital files and data
  • The method of tracking and recording online transactions
Why:

A is correct: Your digital footprint is everything you do online—posts, searches, logins, purchases, comments—that creates a record about you on the internet.

B is wrong: Physical location of a device has nothing to do with a digital footprint; that's just hardware placement.

C is wrong: Deleting files is an action you can take, but it's not what a digital footprint *is*.

D is wrong: While tracking transactions might be *part* of your footprint, this definition is too narrow and specific—a digital footprint includes much more than just financial activity.

What is the purpose of regular antivirus scans?

  • To identify and remove viruses and malware
  • To slow down computer performance
  • To restrict access to certain websites and applications
  • To delete unnecessary files and data
Why:

A is correct: Regular antivirus scans search your system for viruses, malware, and other threats, then remove them to keep your computer safe and secure.

B is wrong: While scans may temporarily use system resources, slowing performance is a *side effect*, not the purpose.

C is wrong: That's what parental controls or firewalls do, not antivirus software.

D is wrong: That's the job of disk cleanup tools, not antivirus programs—antivirus targets malicious code specifically, not just any unnecessary files.

What is the role of user awareness in cyber security?

  • User awareness helps prevent cyber threats and attacks
  • User awareness has no impact on cyber security
  • User awareness guarantees immediate protection from all cyber threats
  • User awareness restricts access to the internet and digital technologies
Why:

A is correct: User awareness is foundational to cyber security—when people understand phishing scams, password safety, and suspicious links, they become the first line of defense against attacks.

B is wrong: User behavior is actually one of the biggest factors in security. Many breaches happen because people click malicious links or use weak passwords, so awareness directly impacts security.

C is wrong: While awareness is powerful, it's not a guarantee. No single measure can block *all* threats—you still need firewalls, updates, and other technical protections working together.

D is wrong: User awareness doesn't restrict internet access; it teaches safer *ways* to use the internet and technology responsibly.

What should you do if you suspect a cyber security incident?

  • Report it to the appropriate authorities or IT department
  • Ignore it and hope it goes away
  • Share your suspicions on social media
  • Pay the requested ransom in case of a ransomware attack
Why:

A is correct: Reporting to authorities or IT immediately allows professionals to contain the threat, investigate, and protect other systems before damage spreads.

B is wrong: Ignoring incidents lets attackers operate undetected, making the breach worse and harder to fix later.

C is wrong: Posting on social media alerts attackers that you're aware of the breach, gives them time to cover tracks, and may panic other users without helpful information.

D is wrong: Paying ransoms funds criminal operations, doesn't guarantee your data back, and often violates laws—IT professionals have better recovery options.

Practise any of these free

Make an account in under a minute, or try it as a guest first.

Start learning free