Security Awareness Quiz
Test Your Information Security Awareness
A Security Awareness Quiz helps employees, contractors, and other personnel test their understanding of basic information-security responsibilities.
Security awareness training should not end when an employee completes a presentation or video. A short assessment can help determine whether people understand important security practices such as phishing detection, password security, MFA, information classification, incident reporting, remote working, and acceptable use.
The quiz can be used after security awareness training, during employee onboarding, as part of annual refresher training, or following a security incident or significant policy change.
Training → Understand → Test → Identify Gaps → Reinforce → Improve
1. Purpose of a Security Awareness Quiz
The purpose of the quiz is to assess whether personnel understand the security responsibilities relevant to their work.
A quiz can help the organization:
- Validate employee understanding
- Identify knowledge gaps
- Reinforce important security practices
- Support new-employee onboarding
- Support annual security awareness training
- Measure training effectiveness
- Identify topics requiring additional training
- Provide evidence of security awareness activities
- Support continual improvement of the security-awareness program
The quiz should be considered one component of the overall awareness program rather than the only measure of security competence.
2. Who Should Complete the Quiz?
The quiz may be assigned to:
☐ Employees
☐ New employees
☐ Contractors
☐ Interns
☐ Temporary personnel
☐ Remote workers
☐ Privileged users
☐ Personnel handling customer information
☐ Personnel handling personal data
☐ Other relevant third parties
Additional role-specific assessments may be required for employees with higher-risk responsibilities.
3. When Should the Quiz Be Used?
A security awareness quiz may be conducted:
New Employee Onboarding
After initial security awareness training.
Annual Awareness Training
As part of the organization’s annual security-awareness program.
Refresher Training
Following repeated awareness weaknesses or changes in threats.
After a Security Incident
When an incident identifies a knowledge gap.
After an Audit Finding
When training is an appropriate corrective action.
After a Policy Change
When employees need to understand new security requirements.
After a Technology Change
For example, introduction of a new cloud platform, authentication method, AI tool, or security system.
4. Recommended Quiz Topics
A general security awareness quiz can cover:
| Topic | Example Knowledge Area |
|---|---|
| Phishing | Identifying suspicious messages |
| Passwords | Secure password practices |
| MFA | Authentication security |
| Incident Reporting | When and how to report |
| Information Classification | Handling sensitive information |
| Remote Working | Secure remote access |
| Malware | Recognizing malicious activity |
| Social Engineering | Manipulation and impersonation |
| Physical Security | Protecting devices and information |
| Acceptable Use | Appropriate use of organizational resources |
| Privacy | Protecting personal information |
| AI Security | Safe use of AI tools |
| Cloud Security | Secure use of cloud services |
5. Quiz Format
A typical employee awareness quiz may contain:
- 10–20 questions
- Multiple-choice questions
- True/False questions
- Scenario-based questions
- Multiple-answer questions where appropriate
- A defined passing score
- Feedback for incorrect answers
- Additional training where required
The number and difficulty of questions should be appropriate for the audience.
6. Security Awareness Quiz
Question 1 — Phishing
You receive an unexpected email asking you to urgently sign in to your company account using a link.
What is the safest first action?
A. Click the link and check whether the page looks genuine.
B. Report the message using the approved reporting mechanism.
C. Forward it to several coworkers for advice.
D. Reply to the sender asking whether it is legitimate.
Correct Answer
B. Report the message using the approved reporting mechanism.
Suspicious messages should be reported through the organization’s approved process rather than interacting with potentially malicious links or attachments.
7. Question 2 — Passwords and MFA
Which actions help protect an organizational account from phishing and credential theft?
A. Use MFA where provided.
B. Approve unexpected MFA prompts to make them stop.
C. Independently verify unusual login or password-reset requests.
D. Share an MFA code with IT if requested by email.
Correct Answers
A and C
MFA provides an additional authentication factor, while independent verification helps prevent attackers from using impersonation or urgency to obtain credentials.
Unexpected MFA requests should never simply be approved, and authentication codes should not be disclosed to unverified requesters.
8. Question 3 — Phishing Messages
True or False?
A phishing message can still be dangerous even if it has perfect grammar and professional-looking branding.
Correct Answer
True
Modern phishing attacks can be highly convincing and professionally written.
Employees should not rely only on:
- Spelling mistakes
- Poor grammar
- Obvious formatting errors
They should also consider:
- Sender identity
- Domain
- Context
- Unexpected requests
- Links
- Attachments
- Urgency
- Requests for credentials
- Requests for confidential information
- Independent verification
9. Question 4 — Accidental Credential Disclosure
An employee accidentally enters their company password into a suspicious website.
What should they do?
A. Keep it secret unless an account is actually compromised.
B. Report the event immediately and follow security instructions.
C. Delete browser history and continue working.
D. Send the password to the security team.
Correct Answer
B. Report the event immediately and follow security instructions.
Prompt reporting gives the organization an opportunity to:
- Reset credentials
- Revoke sessions
- Investigate activity
- Protect the account
- Identify other affected users
- Contain the incident
Employees should never be discouraged from reporting mistakes.
10. Question 5 — Information Classification
An organization uses four information classifications:
- Public
- Internal
- Confidential
- Restricted
Which classification normally requires the strongest protection?
A. Public
B. Internal
C. Confidential
D. Restricted
Correct Answer
D. Restricted
Restricted information is normally the highest classification in this example and should receive the strongest applicable access, protection, and handling controls.
The organization’s approved information-classification policy should always be followed.
11. Question 6 — Incident Reporting
Which situations should normally be reported through the organization’s security or incident-reporting process?
A. A suspicious phishing email
B. An unexpected MFA approval request
C. Suspected loss of confidential customer information
D. A routine meeting invitation from a known colleague
Correct Answers
A, B and C
Suspicious activity, potential account compromise, and possible information exposure should be reported promptly.
A routine meeting invitation from a known colleague does not normally represent a security incident.
12. Question 7 — MFA Fatigue
True or False?
Employees should approve an MFA notification when it appears repeatedly because repeated prompts usually indicate that the system is malfunctioning.
Correct Answer
False
Repeated unexpected MFA requests may indicate an attempted account compromise or MFA-fatigue attack.
Employees should:
- Deny or ignore unexpected requests.
- Avoid approving authentication they did not initiate.
- Report suspicious activity.
- Follow the organization’s security instructions.
13. Question 8 — Business Email Compromise
You receive an urgent request from a senior executive asking you to change a supplier’s bank account immediately.
What should you do?
A. Process it immediately because the request is from an executive.
B. Verify the request using an independent approved channel.
C. Forward the request to the supplier and ask them to confirm.
D. Ignore the request permanently.
Correct Answer
B. Verify the request using an independent approved channel.
Financial and other high-risk requests should follow the organization’s approved authorization and verification process.
Executive impersonation is a common business-email-compromise technique.
Urgency does not replace verification.
14. Question 9 — Remote Working
Which practices help protect information when working remotely?
A. Use approved organizational devices and services.
B. Share confidential files through any convenient personal file-sharing service.
C. Use secure authentication and MFA.
D. Report a lost organizational device promptly.
Correct Answers
A, C and D
Remote working does not reduce the organization’s information-security responsibilities.
Personnel should continue to:
- Use approved systems
- Protect credentials
- Use MFA
- Protect organizational devices
- Secure confidential information
- Report incidents promptly
15. Question 10 — Purpose of Security Awareness Training
What is the primary purpose of security awareness training?
A. Make employees responsible for all cybersecurity controls.
B. Ensure employees understand and apply security responsibilities relevant to their work.
C. Eliminate the need for technical security controls.
D. Demonstrate that every employee attended a presentation.
Correct Answer
B. Ensure employees understand and apply security responsibilities relevant to their work.
Security awareness is intended to influence secure behavior and help personnel understand their responsibilities.
Training does not replace technical, administrative, or physical security controls.
16. Suggested Scoring
A simple scoring model can be used:
| Score | Suggested Result |
|---|---|
| 90–100% | Excellent |
| 80–89% | Satisfactory |
| 70–79% | Needs Reinforcement |
| Below 70% | Additional Training Recommended |
The organization may define its own passing threshold based on risk and training requirements.
For higher-risk roles, a higher passing threshold may be appropriate.
17. Failed Quiz Process
If an employee does not achieve the required score:
Identify → Notify → Reinforce → Retest → Record
Possible actions include:
☐ Review incorrect topics
☐ Complete refresher training
☐ Receive targeted awareness material
☐ Complete another assessment
☐ Complete a practical exercise
☐ Manager follow-up where appropriate
☐ Security-team follow-up for high-risk roles
The response should be proportionate to the risk.
18. Quiz Effectiveness
The organization should not rely only on quiz scores.
Additional indicators may include:
- Phishing simulation results
- Phishing reporting rate
- Security incidents
- Repeat mistakes
- Policy violations
- Incident-reporting behavior
- Employee feedback
- Audit findings
- Security awareness campaign results
Important Principle
A high quiz score does not automatically prove secure behavior.
The organization should combine knowledge testing with practical and behavioral indicators.
19. Quiz Evidence
Maintain appropriate evidence such as:
- Quiz version
- Training topic
- Employee or audience
- Date assigned
- Completion date
- Score
- Pass/fail result
- Retest result
- Additional training
- Evidence reference
- Training material version
Avoid retaining unnecessary personal information.
20. Security Awareness Quiz Register
| Quiz ID | Employee/Team | Training | Date | Score | Passing Score | Result | Retest | Evidence |
|---|---|---|---|---|---|---|---|---|
21. Role-Based Security Quizzes
Not every employee needs the same quiz.
General Employees
Focus on:
- Phishing
- Passwords
- MFA
- Incident reporting
- Classification
- Acceptable use
- Remote working
- Physical security
Developers
Add:
- Secure coding
- Secrets
- Source-code protection
- Dependency security
- Vulnerability management
- AI-assisted development
Cloud Administrators
Add:
- IAM
- Privileged access
- Cloud configuration
- Logging
- Monitoring
- Cloud incident response
Finance
Add:
- Payment fraud
- Invoice fraud
- Business-email compromise
- Supplier verification
Security Team
Add:
- Incident response
- Threat detection
- Evidence handling
- Security monitoring
- Vulnerability management
22. AWS SaaS Startup Example
Consider a SaaS startup operating:
- AWS
- GitHub
- Microsoft 365 or Google Workspace
- Customer data
- Remote workforce
General Employee Quiz
10 questions covering:
Phishing → Passwords → MFA → Information Classification → Incident Reporting → Remote Working
Developer Quiz
Additional questions covering:
Source Code → Secrets → Dependencies → Secure Development → AI-Assisted Coding
Cloud Administrator Quiz
Additional questions covering:
AWS IAM → Privileged Access → Cloud Configuration → Logging → Incident Response
This approach makes the awareness program risk-based rather than one-size-fits-all.
23. Startup-Friendly Implementation
A startup does not need a complex learning-management platform to begin.
A simple process can be:
Step 1 — Train
Provide security awareness material.
Step 2 — Test
Give employees a short quiz.
Step 3 — Record
Record completion and score.
Step 4 — Identify Gaps
Review commonly missed topics.
Step 5 — Reinforce
Provide targeted training.
Step 6 — Retest
Test employees where necessary.
Step 7 — Improve
Update awareness content based on results.
24. Common Mistakes
Avoid:
- Making the quiz unnecessarily difficult.
- Testing obscure security knowledge unrelated to employee responsibilities.
- Using the same quiz for every role.
- Treating quiz completion as proof of security competence.
- Not providing feedback.
- Ignoring failed assessments.
- Not tracking retests.
- Not updating questions when threats change.
- Revealing answers before employees complete the quiz.
- Collecting unnecessary personal information.
- Using the quiz as a punitive employee-performance tool.
- Failing to connect quiz results to the training program.
25. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Awareness Policy | Defines awareness requirements |
| Security Awareness and Training Procedure | Defines training process |
| Security Awareness Training Register | Records training |
| Annual Security Awareness Plan | Defines annual activities |
| Role-Based Security Training Matrix | Defines role-specific requirements |
| Employee Security Training Checklist | Tracks individual training |
| Phishing Awareness Procedure | Provides phishing-specific awareness |
| Phishing Simulation Register | Records phishing exercises |
| Incident Response Procedure | Supports incident-driven training |
| Corrective Action Tracker | Tracks training-related actions |
| Policy Compliance Review Checklist | Supports verification of policy awareness |
26. ISO 27001 Connection
A security awareness quiz can provide supporting evidence that personnel have received and understood relevant information-security awareness training.
The quiz can support activities related to:
- Information-security awareness
- Competence
- Security responsibilities
- Access security
- Incident reporting
- Information protection
- Secure use of organizational resources
The Security Awareness Quiz is not itself a universally prescribed ISO 27001 document or mandatory form. The organization should determine whether quizzes are appropriate based on its risks, roles, training requirements, contractual obligations, applicable controls, and other compliance requirements.
27. Final Audit Checklist
☐ Quiz owner assigned
☐ Target audience defined
☐ Training topics identified
☐ Questions approved
☐ Role-specific questions considered
☐ Passing score defined
☐ Quiz completed
☐ Results recorded
☐ Failed assessments identified
☐ Retesting performed where required
☐ Additional training provided where required
☐ Evidence retained
☐ Quiz content reviewed
☐ Questions updated when risks change
☐ Results analyzed
☐ Training effectiveness evaluated
☐ Management reporting performed where appropriate
28. Final Audit Trail
For the security awareness quiz, the organization should be able to demonstrate:
What training was provided?
Who was required to complete the quiz?
What security topics were tested?
When was the quiz completed?
What score was achieved?
Was the required threshold met?
What happened when the employee failed?
Was additional training provided?
Was the employee retested?
What knowledge gaps were identified?
Were awareness materials improved based on the results?
Final Principle
A Security Awareness Quiz should not simply measure whether an employee remembers security terminology. It should help the organization determine whether personnel understand the security decisions they are expected to make in their daily work.
Security Awareness Assessment Lifecycle:
Train → Test → Measure → Identify Gaps → Reinforce → Retest → Analyze → Improve
