Phishing Awareness Training Video
Rating
0
0
There are no comments for now.
Join this Course
to be the first to leave a comment.
1.
Which of the following characteristics is UNIQUE to phishing emails and NOT present in legitimate BG communications?
They are sent by email, WhatsApp, or SMS
They include BG branding such as logos, colour schemes, or staff names
They combine a request for action with an element designed to override the recipient's judgement — urgency, fear, reward, or isolation
They arrive during working hours and reference current BG operations
2.
Which of the following BEST explains why attackers use urgency and deadlines in phishing emails?
To give recipients enough time to verify the request through official channels
To trigger the fight-or-flight response, bypassing rational thinking and pushing the recipient to act before verifying
Because legitimate requests from finance and HR teams are always time-sensitive
To ensure the phishing link does not expire before the recipient clicks it
3.
Why is it dangerous to enter your BG portal password on a page you reached by clicking an email link, even if the page looks identical to the real BG portal?
Because your password may be too short to be accepted by the real portal
Because the visual appearance of a webpage does not confirm its authenticity — attackers can replicate any login page pixel-perfectly, while the URL remains under their control
Because BG's portal does not accept passwords entered via email links for security reasons
Because your browser will automatically block credential entry on unsafe pages
4.
A BG staff member receives a phishing email, recognises it immediately, does NOT click anything, and then deletes it without reporting. What is the consequence of this action?
No consequence — the correct action is to delete phishing emails without engaging with them
The InfoSec team loses visibility of the threat and cannot warn colleagues who may receive the same lure or block the malicious domain
The email may auto-forward to the attacker's server once deleted
HR will flag the deletion as suspicious behaviour
5.
A colleague messages you on Zoho Cliq claiming to be from IT Support: 'We detected unusual activity on your account. Please confirm your BG portal password immediately so we can secure it.' What should you do?
6.
In a Business Email Compromise (BEC) attack targeting BG's Finance team, what is the attacker's PRIMARY method of making the email appear legitimate?
Sending the email from a BG-registered domain after hacking BG's mail server
Spoofing or closely mimicking a senior executive's display name and using a lookalike domain, combined with urgency and confidentiality to prevent verification
Including the Finance team's internal budget figures to prove they have access to BG's systems
Sending the email at exactly the same time every week to match a predictable payment schedule
7.
A BG staff member changes their BG portal password immediately after suspecting they entered it on a fake page. They tell no one. Which risk remains UNADDRESSED?
No risk remains — changing the password fully revokes the attacker's access
The attacker may have already accessed the account, exfiltrated data, or implanted persistent access during the window before the password change
The password change may not take effect for 24 hours on BG's system
The staff member's browser may have cached the old password and will submit it automatically next time
8.
Why are BG field agents at elevated phishing risk during disbursement season (January–March) and harvest season (September–November) specifically?
Because phishing infrastructure is more active during Nigerian agricultural seasons
Because agents receive more emails from BG Head Office during those months
Because operational pressure and time constraints reduce the cognitive space to pause, verify, and check suspicious communications
Because BG issues new login credentials at the start of each season, making agents unfamiliar with the new system
9.
You clicked a link in a suspicious email and typed your BG password on the page before realising the URL looked wrong. You close the browser. What is your FIRST action?
Run an antivirus scan and monitor your account for unusual activity
Change your BG password immediately and tell no one — it was probably fine
Contact IT Cybersecurity Lead on Zoho Cliq immediately and forward the email to [email protected]. Change your password from a different trusted device.
Report it to your line manager at the end of the day
10.
Which of the following most accurately describes the relationship between a convincing email and the need to verify it before acting?
A convincing, well-written email with no spelling errors is safe to act on without verification
The more convincing and legitimate an email looks, the more important verification becomes — sophistication is a sign of effort, not authenticity
Verification is only necessary when the email asks for money or a password
An email that passes the sender address check does not require further verification