Cybersecurity protects devices, networks and data from unauthorised access or damage. Malware is malicious software designed to harm or exploit a system — including viruses (which spread by attaching to files), worms (which spread on their own across networks), and ransomware (which locks your files and demands payment). Phishing uses fake messages pretending to be from a trusted source to trick people into giving up sensitive information.
Example
An email claiming to be from your bank, asking you to "verify your account" by clicking a link and entering your password, is a classic phishing attempt — the real bank would never ask for your password this way.
Key terms
Malware:
Malicious software designed to harm or exploit a system.
Phishing:
Fake messages designed to trick people into giving up sensitive information.
Ransomware:
Malware that locks a victim's files and demands payment to unlock them.
Questions
1. Malware is:
Malicious software designed to harm a system
A type of helpful app
A password manager
A type of hardware
2. Phishing tries to trick people into:
Giving up sensitive information
Winning a prize legitimately
Improving their computer's speed
Nothing at all
3. Ransomware:
Locks files and demands payment
Speeds up your computer
Is always harmless
Only affects printers
4. A computer virus spreads by:
Attaching to files
Only appearing in printed documents
Being completely harmless
Never spreading at all
5. Cybersecurity protects:
Devices, networks and data
Only physical locks on doors
Only paper documents
Nothing digital
6. A worm is a type of malware that:
Spreads on its own across networks
Only affects paper files
Cannot spread at all
Is always harmless
7. An email pretending to be your bank asking for your password is likely:
A phishing attempt
Always legitimate
A type of hardware
Required by banks
8. Why would a real bank rarely ask for your password via email?
It's a major security risk and a common phishing tactic
Banks always ask for passwords by email
Email is the most secure way to share passwords
Passwords are not sensitive information
9. Which is a red flag suggesting an email might be a phishing attempt?
Urgent language demanding immediate action and a suspicious link
A calm, professional tone with no links
An email from a known, verified contact
Perfect grammar and spelling only
10. Antivirus software helps by:
Detecting and removing malicious software
Making your computer more vulnerable
Deleting all your files automatically
Having no real function
11. Ransomware attacks are dangerous mainly because they can:
Make important files completely inaccessible until a ransom is paid
Only affect old computers
Improve your computer's performance
Have no real consequences
12. A trojan is malware disguised as:
Legitimate, harmless-looking software
A visible warning message
A physical computer part
An antivirus program only
13. Two-factor authentication adds security by:
Requiring a second form of verification beyond just a password
Removing the need for any password
Making login completely optional
Having no effect on account security
14. Keeping software updated helps cybersecurity because updates often:
Fix security vulnerabilities that malware could exploit
Always make software less secure
Have no relationship to security
Only change the software's appearance
15. Why do cybercriminals often use urgency ("Act now or lose access!") in phishing messages?
It pressures victims to act quickly without carefully checking if the message is legitimate
Urgency has no effect on how people respond
It proves the message is definitely genuine
Legitimate companies always use extreme urgency
16. A company backing up its data regularly is a defence specifically against:
Ransomware, since backups let you restore files without paying
Only viruses, never other malware
Nothing related to cybersecurity
Only physical theft of computers
17. Why might a cyberattack on a hospital or power grid be considered especially dangerous compared to one on a small personal blog?
Critical infrastructure attacks can directly endanger lives and essential services
All cyberattacks have identical consequences regardless of target
Hospitals and power grids have no digital systems to attack
Personal blogs are always more valuable targets
18. A "zero-day" vulnerability refers to:
A previously unknown security flaw that hasn't yet been patched
A vulnerability that has existed for zero days, meaning it never existed
A type of antivirus software
A password requirement
19. Why is employee training often considered as important as technical tools in preventing cyberattacks like phishing?
Many attacks rely on tricking a person, not just breaking through technical defences
Humans are never involved in cybersecurity risks
Technical tools alone are always 100% effective
Training has no impact on security outcomes
20. Why do cybersecurity experts recommend using different, unique passwords for different accounts?
If one account's password is leaked, it won't compromise your other accounts too
Using the same password everywhere is always safest
Unique passwords are harder for you but have no security benefit
Password reuse has no relationship to security risk
21. A firewall helps protect a network mainly by:
Monitoring and controlling incoming and outgoing traffic based on security rules
Physically blocking a computer from turning on
Deleting all files on a device automatically
Having no actual security function
Answer key (parent copy)
1. Malicious software designed to harm a system
2. Giving up sensitive information
3. Locks files and demands payment
4. Attaching to files
5. Devices, networks and data
6. Spreads on its own across networks
7. A phishing attempt
8. It's a major security risk and a common phishing tactic
9. Urgent language demanding immediate action and a suspicious link
10. Detecting and removing malicious software
11. Make important files completely inaccessible until a ransom is paid
12. Legitimate, harmless-looking software
13. Requiring a second form of verification beyond just a password
14. Fix security vulnerabilities that malware could exploit
15. It pressures victims to act quickly without carefully checking if the message is legitimate
16. Ransomware, since backups let you restore files without paying
17. Critical infrastructure attacks can directly endanger lives and essential services
18. A previously unknown security flaw that hasn't yet been patched
19. Many attacks rely on tricking a person, not just breaking through technical defences
20. If one account's password is leaked, it won't compromise your other accounts too
21. Monitoring and controlling incoming and outgoing traffic based on security rules