Beyond basic password safety, understanding cyber security means knowing about common threats and protections. Multi-factor authentication (MFA) adds an extra layer of security beyond just a password — like a code sent to your phone — so that even if your password is stolen, an attacker still can't access your account without that second step. Phishing is a common attack where scammers impersonate a trustworthy source (like a bank or a well-known company) to trick people into giving away personal information or clicking dangerous links. Your digital footprint is the trail of data you leave behind through your online activity — posts, searches, app usage, and more — and it's worth regularly considering what data is actually necessary for a service to collect, and being thoughtful about what you share.
Example
If you receive an email claiming to be from your bank asking you to "urgently verify your account" by clicking a link and entering your password, this is a classic phishing attempt — a legitimate bank would never ask for your password this way, and multi-factor authentication would still protect your account even if you accidentally gave away your password.
Key terms
Multi-factor authentication (MFA):
A security method requiring more than just a password to log in, like a code sent to your phone.
Phishing:
A scam where someone impersonates a trustworthy source to trick people into giving away information.
Digital footprint:
The trail of data left behind by a person's online activity.
Questions
1. Multi-factor authentication adds:
Nothing extra
An extra layer of security beyond just a password
A weaker password
No real protection
2. Phishing is:
A safe online activity
A scam impersonating a trustworthy source to steal information
A type of strong password
A type of encryption
3. A digital footprint is:
Unrelated to the internet
The trail of data left behind by online activity
Only your physical footprints
A type of computer hardware
4. MFA might include:
Only a password
A password plus a code sent to your phone
No security at all
A public username
5. A phishing email might:
Always be from a trusted source
Impersonate a bank or company to trick you
Never ask for personal information
Always be completely safe
6. Being thoughtful about your digital footprint means:
Sharing everything without thought
Considering what data you share and why
Ignoring online privacy
Avoiding the internet completely
7. Even if a password is stolen, MFA can:
Do nothing to help
Still protect the account by requiring a second verification step
Automatically delete the account
Make the account less secure
8. An email claiming to be from your bank asking you to "urgently click here and enter your password" is likely:
A safe, legitimate request
A phishing attempt
A type of encryption
Always harmless
9. Why would a legitimate bank be unlikely to ask for your password via email?
Banks always ask this way
Legitimate organisations typically don't request passwords directly like this, since it's a common scam tactic
This is standard, safe practice
Email is always secure
10. Your digital footprint might include:
Nothing at all
Your social media posts, searches and app usage
Only your name
Unrelated physical information
11. Why might it be worth considering whether an app's data collection is "essential to its purpose"?
Data collection is always necessary and should never be questioned
Some apps may collect more data than needed, so it's worth being thoughtful about privacy
Apps never collect unnecessary data
This consideration is irrelevant
12. If you receive a suspicious message asking for personal information, a safe response is to:
Immediately provide the information
Be cautious, verify the source independently, and avoid clicking suspicious links
Ignore all safety concerns
Share it with strangers online
13. MFA typically requires:
Only one single factor
Something you know (password) plus something else, like a code
Nothing at all
Only a username
14. Why might your digital footprint matter even years after you created it?
Old digital footprints have no lasting relevance
Digital information can persist and potentially be found or used well into the future
Digital footprints disappear automatically after a short time
This has no real-world relevance
15. A user reuses the same password across many accounts and has no MFA enabled. If one account is compromised, what risk does this create?
No risk at all
Other accounts using the same password could also become vulnerable
Reusing passwords always improves security
MFA would make no difference in this situation
16. Why might phishing attacks often create a sense of urgency (like "your account will be closed in 24 hours")?
Urgency has no effect on people's decisions
Urgency can pressure people into acting quickly without carefully verifying the request first
Legitimate requests always create urgency
Urgency makes messages more trustworthy
17. A student is asked by a game app for access to their entire contact list, though the game has no obvious need for it. What should they consider?
Access requests never need scrutiny
Whether this data access is actually necessary for the app's stated purpose, and the privacy implications if not
All access requests should always be granted immediately
Contact list access is always essential for games
18. Why does enabling MFA significantly reduce the risk from a stolen password, compared to relying on a password alone?
MFA has no effect on security
An attacker would also need the second factor (e.g. a phone-based code), which they're unlikely to have even with the password
MFA makes accounts less secure
Passwords alone are always sufficient protection
19. Why might regularly reviewing your digital footprint (like old posts or account permissions) be a useful habit?
Old digital footprint data is never worth reviewing
It helps identify and manage what information about you is still accessible or being collected
Reviewing has no real benefit
Digital footprints cannot be managed once created
20. Understanding cyber security threats and digital footprints mainly helps students:
Ignore online risks entirely
Make safer, more informed decisions about their own online security and privacy
Assume all online interactions are automatically safe
Avoid using any online services
Answer key (parent copy)
1. An extra layer of security beyond just a password
2. A scam impersonating a trustworthy source to steal information
3. The trail of data left behind by online activity
4. A password plus a code sent to your phone
5. Impersonate a bank or company to trick you
6. Considering what data you share and why
7. Still protect the account by requiring a second verification step
8. A phishing attempt
9. Legitimate organisations typically don't request passwords directly like this, since it's a common scam tactic
10. Your social media posts, searches and app usage
11. Some apps may collect more data than needed, so it's worth being thoughtful about privacy
12. Be cautious, verify the source independently, and avoid clicking suspicious links
13. Something you know (password) plus something else, like a code
14. Digital information can persist and potentially be found or used well into the future
15. Other accounts using the same password could also become vulnerable
16. Urgency can pressure people into acting quickly without carefully verifying the request first
17. Whether this data access is actually necessary for the app's stated purpose, and the privacy implications if not
18. An attacker would also need the second factor (e.g. a phone-based code), which they're unlikely to have even with the password
19. It helps identify and manage what information about you is still accessible or being collected
20. Make safer, more informed decisions about their own online security and privacy