ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Security Awareness Quiz

Security Awareness Quiz

Security Awareness Quiz

Test Your Information Security Awareness

A Security Awareness Quiz helps employees, contractors, and other personnel test their understanding of basic information-security responsibilities.

Security awareness training should not end when an employee completes a presentation or video. A short assessment can help determine whether people understand important security practices such as phishing detection, password security, MFA, information classification, incident reporting, remote working, and acceptable use.

The quiz can be used after security awareness training, during employee onboarding, as part of annual refresher training, or following a security incident or significant policy change.

Training → Understand → Test → Identify Gaps → Reinforce → Improve


1. Purpose of a Security Awareness Quiz

The purpose of the quiz is to assess whether personnel understand the security responsibilities relevant to their work.

A quiz can help the organization:

  • Validate employee understanding
  • Identify knowledge gaps
  • Reinforce important security practices
  • Support new-employee onboarding
  • Support annual security awareness training
  • Measure training effectiveness
  • Identify topics requiring additional training
  • Provide evidence of security awareness activities
  • Support continual improvement of the security-awareness program

The quiz should be considered one component of the overall awareness program rather than the only measure of security competence.


2. Who Should Complete the Quiz?

The quiz may be assigned to:

☐ Employees

☐ New employees

☐ Contractors

☐ Interns

☐ Temporary personnel

☐ Remote workers

☐ Privileged users

☐ Personnel handling customer information

☐ Personnel handling personal data

☐ Other relevant third parties

Additional role-specific assessments may be required for employees with higher-risk responsibilities.


3. When Should the Quiz Be Used?

A security awareness quiz may be conducted:

New Employee Onboarding

After initial security awareness training.

Annual Awareness Training

As part of the organization’s annual security-awareness program.

Refresher Training

Following repeated awareness weaknesses or changes in threats.

After a Security Incident

When an incident identifies a knowledge gap.

After an Audit Finding

When training is an appropriate corrective action.

After a Policy Change

When employees need to understand new security requirements.

After a Technology Change

For example, introduction of a new cloud platform, authentication method, AI tool, or security system.


4. Recommended Quiz Topics

A general security awareness quiz can cover:

TopicExample Knowledge Area
PhishingIdentifying suspicious messages
PasswordsSecure password practices
MFAAuthentication security
Incident ReportingWhen and how to report
Information ClassificationHandling sensitive information
Remote WorkingSecure remote access
MalwareRecognizing malicious activity
Social EngineeringManipulation and impersonation
Physical SecurityProtecting devices and information
Acceptable UseAppropriate use of organizational resources
PrivacyProtecting personal information
AI SecuritySafe use of AI tools
Cloud SecuritySecure use of cloud services

5. Quiz Format

A typical employee awareness quiz may contain:

  • 10–20 questions
  • Multiple-choice questions
  • True/False questions
  • Scenario-based questions
  • Multiple-answer questions where appropriate
  • A defined passing score
  • Feedback for incorrect answers
  • Additional training where required

The number and difficulty of questions should be appropriate for the audience.


6. Security Awareness Quiz

Question 1 — Phishing

You receive an unexpected email asking you to urgently sign in to your company account using a link.

What is the safest first action?

A. Click the link and check whether the page looks genuine.

B. Report the message using the approved reporting mechanism.

C. Forward it to several coworkers for advice.

D. Reply to the sender asking whether it is legitimate.

Correct Answer

B. Report the message using the approved reporting mechanism.

Suspicious messages should be reported through the organization’s approved process rather than interacting with potentially malicious links or attachments.


7. Question 2 — Passwords and MFA

Which actions help protect an organizational account from phishing and credential theft?

A. Use MFA where provided.

B. Approve unexpected MFA prompts to make them stop.

C. Independently verify unusual login or password-reset requests.

D. Share an MFA code with IT if requested by email.

Correct Answers

A and C

MFA provides an additional authentication factor, while independent verification helps prevent attackers from using impersonation or urgency to obtain credentials.

Unexpected MFA requests should never simply be approved, and authentication codes should not be disclosed to unverified requesters.


8. Question 3 — Phishing Messages

True or False?

A phishing message can still be dangerous even if it has perfect grammar and professional-looking branding.

Correct Answer

True

Modern phishing attacks can be highly convincing and professionally written.

Employees should not rely only on:

  • Spelling mistakes
  • Poor grammar
  • Obvious formatting errors

They should also consider:

  • Sender identity
  • Domain
  • Context
  • Unexpected requests
  • Links
  • Attachments
  • Urgency
  • Requests for credentials
  • Requests for confidential information
  • Independent verification

9. Question 4 — Accidental Credential Disclosure

An employee accidentally enters their company password into a suspicious website.

What should they do?

A. Keep it secret unless an account is actually compromised.

B. Report the event immediately and follow security instructions.

C. Delete browser history and continue working.

D. Send the password to the security team.

Correct Answer

B. Report the event immediately and follow security instructions.

Prompt reporting gives the organization an opportunity to:

  • Reset credentials
  • Revoke sessions
  • Investigate activity
  • Protect the account
  • Identify other affected users
  • Contain the incident

Employees should never be discouraged from reporting mistakes.


10. Question 5 — Information Classification

An organization uses four information classifications:

  • Public
  • Internal
  • Confidential
  • Restricted

Which classification normally requires the strongest protection?

A. Public

B. Internal

C. Confidential

D. Restricted

Correct Answer

D. Restricted

Restricted information is normally the highest classification in this example and should receive the strongest applicable access, protection, and handling controls.

The organization’s approved information-classification policy should always be followed.


11. Question 6 — Incident Reporting

Which situations should normally be reported through the organization’s security or incident-reporting process?

A. A suspicious phishing email

B. An unexpected MFA approval request

C. Suspected loss of confidential customer information

D. A routine meeting invitation from a known colleague

Correct Answers

A, B and C

Suspicious activity, potential account compromise, and possible information exposure should be reported promptly.

A routine meeting invitation from a known colleague does not normally represent a security incident.


12. Question 7 — MFA Fatigue

True or False?

Employees should approve an MFA notification when it appears repeatedly because repeated prompts usually indicate that the system is malfunctioning.

Correct Answer

False

Repeated unexpected MFA requests may indicate an attempted account compromise or MFA-fatigue attack.

Employees should:

  1. Deny or ignore unexpected requests.
  2. Avoid approving authentication they did not initiate.
  3. Report suspicious activity.
  4. Follow the organization’s security instructions.

13. Question 8 — Business Email Compromise

You receive an urgent request from a senior executive asking you to change a supplier’s bank account immediately.

What should you do?

A. Process it immediately because the request is from an executive.

B. Verify the request using an independent approved channel.

C. Forward the request to the supplier and ask them to confirm.

D. Ignore the request permanently.

Correct Answer

B. Verify the request using an independent approved channel.

Financial and other high-risk requests should follow the organization’s approved authorization and verification process.

Executive impersonation is a common business-email-compromise technique.

Urgency does not replace verification.


14. Question 9 — Remote Working

Which practices help protect information when working remotely?

A. Use approved organizational devices and services.

B. Share confidential files through any convenient personal file-sharing service.

C. Use secure authentication and MFA.

D. Report a lost organizational device promptly.

Correct Answers

A, C and D

Remote working does not reduce the organization’s information-security responsibilities.

Personnel should continue to:

  • Use approved systems
  • Protect credentials
  • Use MFA
  • Protect organizational devices
  • Secure confidential information
  • Report incidents promptly

15. Question 10 — Purpose of Security Awareness Training

What is the primary purpose of security awareness training?

A. Make employees responsible for all cybersecurity controls.

B. Ensure employees understand and apply security responsibilities relevant to their work.

C. Eliminate the need for technical security controls.

D. Demonstrate that every employee attended a presentation.

Correct Answer

B. Ensure employees understand and apply security responsibilities relevant to their work.

Security awareness is intended to influence secure behavior and help personnel understand their responsibilities.

Training does not replace technical, administrative, or physical security controls.


16. Suggested Scoring

A simple scoring model can be used:

ScoreSuggested Result
90–100%Excellent
80–89%Satisfactory
70–79%Needs Reinforcement
Below 70%Additional Training Recommended

The organization may define its own passing threshold based on risk and training requirements.

For higher-risk roles, a higher passing threshold may be appropriate.


17. Failed Quiz Process

If an employee does not achieve the required score:

Identify → Notify → Reinforce → Retest → Record

Possible actions include:

☐ Review incorrect topics

☐ Complete refresher training

☐ Receive targeted awareness material

☐ Complete another assessment

☐ Complete a practical exercise

☐ Manager follow-up where appropriate

☐ Security-team follow-up for high-risk roles

The response should be proportionate to the risk.


18. Quiz Effectiveness

The organization should not rely only on quiz scores.

Additional indicators may include:

  • Phishing simulation results
  • Phishing reporting rate
  • Security incidents
  • Repeat mistakes
  • Policy violations
  • Incident-reporting behavior
  • Employee feedback
  • Audit findings
  • Security awareness campaign results

Important Principle

A high quiz score does not automatically prove secure behavior.

The organization should combine knowledge testing with practical and behavioral indicators.


19. Quiz Evidence

Maintain appropriate evidence such as:

  • Quiz version
  • Training topic
  • Employee or audience
  • Date assigned
  • Completion date
  • Score
  • Pass/fail result
  • Retest result
  • Additional training
  • Evidence reference
  • Training material version

Avoid retaining unnecessary personal information.


20. Security Awareness Quiz Register

Quiz IDEmployee/TeamTrainingDateScorePassing ScoreResultRetestEvidence

21. Role-Based Security Quizzes

Not every employee needs the same quiz.

General Employees

Focus on:

  • Phishing
  • Passwords
  • MFA
  • Incident reporting
  • Classification
  • Acceptable use
  • Remote working
  • Physical security

Developers

Add:

  • Secure coding
  • Secrets
  • Source-code protection
  • Dependency security
  • Vulnerability management
  • AI-assisted development

Cloud Administrators

Add:

  • IAM
  • Privileged access
  • Cloud configuration
  • Logging
  • Monitoring
  • Cloud incident response

Finance

Add:

  • Payment fraud
  • Invoice fraud
  • Business-email compromise
  • Supplier verification

Security Team

Add:

  • Incident response
  • Threat detection
  • Evidence handling
  • Security monitoring
  • Vulnerability management

22. AWS SaaS Startup Example

Consider a SaaS startup operating:

  • AWS
  • GitHub
  • Microsoft 365 or Google Workspace
  • Customer data
  • Remote workforce

General Employee Quiz

10 questions covering:

Phishing → Passwords → MFA → Information Classification → Incident Reporting → Remote Working

Developer Quiz

Additional questions covering:

Source Code → Secrets → Dependencies → Secure Development → AI-Assisted Coding

Cloud Administrator Quiz

Additional questions covering:

AWS IAM → Privileged Access → Cloud Configuration → Logging → Incident Response

This approach makes the awareness program risk-based rather than one-size-fits-all.


23. Startup-Friendly Implementation

A startup does not need a complex learning-management platform to begin.

A simple process can be:

Step 1 — Train

Provide security awareness material.

Step 2 — Test

Give employees a short quiz.

Step 3 — Record

Record completion and score.

Step 4 — Identify Gaps

Review commonly missed topics.

Step 5 — Reinforce

Provide targeted training.

Step 6 — Retest

Test employees where necessary.

Step 7 — Improve

Update awareness content based on results.


24. Common Mistakes

Avoid:

  • Making the quiz unnecessarily difficult.
  • Testing obscure security knowledge unrelated to employee responsibilities.
  • Using the same quiz for every role.
  • Treating quiz completion as proof of security competence.
  • Not providing feedback.
  • Ignoring failed assessments.
  • Not tracking retests.
  • Not updating questions when threats change.
  • Revealing answers before employees complete the quiz.
  • Collecting unnecessary personal information.
  • Using the quiz as a punitive employee-performance tool.
  • Failing to connect quiz results to the training program.

25. Relationship With Other ISMS Documents

DocumentRelationship
Information Security Awareness PolicyDefines awareness requirements
Security Awareness and Training ProcedureDefines training process
Security Awareness Training RegisterRecords training
Annual Security Awareness PlanDefines annual activities
Role-Based Security Training MatrixDefines role-specific requirements
Employee Security Training ChecklistTracks individual training
Phishing Awareness ProcedureProvides phishing-specific awareness
Phishing Simulation RegisterRecords phishing exercises
Incident Response ProcedureSupports incident-driven training
Corrective Action TrackerTracks training-related actions
Policy Compliance Review ChecklistSupports verification of policy awareness

26. ISO 27001 Connection

A security awareness quiz can provide supporting evidence that personnel have received and understood relevant information-security awareness training.

The quiz can support activities related to:

  • Information-security awareness
  • Competence
  • Security responsibilities
  • Access security
  • Incident reporting
  • Information protection
  • Secure use of organizational resources

The Security Awareness Quiz is not itself a universally prescribed ISO 27001 document or mandatory form. The organization should determine whether quizzes are appropriate based on its risks, roles, training requirements, contractual obligations, applicable controls, and other compliance requirements.


27. Final Audit Checklist

☐ Quiz owner assigned

☐ Target audience defined

☐ Training topics identified

☐ Questions approved

☐ Role-specific questions considered

☐ Passing score defined

☐ Quiz completed

☐ Results recorded

☐ Failed assessments identified

☐ Retesting performed where required

☐ Additional training provided where required

☐ Evidence retained

☐ Quiz content reviewed

☐ Questions updated when risks change

☐ Results analyzed

☐ Training effectiveness evaluated

☐ Management reporting performed where appropriate


28. Final Audit Trail

For the security awareness quiz, the organization should be able to demonstrate:

What training was provided?
Who was required to complete the quiz?
What security topics were tested?
When was the quiz completed?
What score was achieved?
Was the required threshold met?
What happened when the employee failed?
Was additional training provided?
Was the employee retested?
What knowledge gaps were identified?
Were awareness materials improved based on the results?

Final Principle

A Security Awareness Quiz should not simply measure whether an employee remembers security terminology. It should help the organization determine whether personnel understand the security decisions they are expected to make in their daily work.

Security Awareness Assessment Lifecycle:

Train → Test → Measure → Identify Gaps → Reinforce → Retest → Analyze → Improve