NEDP Digital Literacy and Internet Safety 1 — Questions and Answers
Question 1: What does 'phishing' mean in cybersecurity?
- A fraudulent attempt to obtain sensitive information (passwords, credit card numbers) by disguising as a trustworthy entity via email or messages (Correct answer)
- A method of catching computer viruses using security software
- Unauthorized access to another person's computer files
- The process of recovering deleted files from a hard drive
Correct answer: A fraudulent attempt to obtain sensitive information (passwords, credit card numbers) by disguising as a trustworthy entity via email or messages
Phishing scams impersonate trusted organizations via email or text to trick users into revealing sensitive information.
Phishing attacks use fake emails, texts, or websites that appear to come from legitimate sources (banks, the IRS, Amazon, etc.) to trick victims into entering login credentials, credit card numbers, or Social Security numbers. Red flags: urgent language, mismatched sender email domains, suspicious links, and requests for sensitive information. Never click links in suspicious emails — go directly to the official website.
Question 2: What is a 'strong password' according to cybersecurity best practices?
- A long combination of uppercase letters, lowercase letters, numbers, and symbols that is unique to each account (Correct answer)
- Your pet's name followed by your birth year
- A single long word that is easy to remember
- The same complex password used for all accounts to remember it easily
Correct answer: A long combination of uppercase letters, lowercase letters, numbers, and symbols that is unique to each account
Strong passwords are long, complex, unique per account, and difficult to guess — especially important for email, banking, and social media.
Best practices for strong passwords: at least 12 characters, mix of uppercase, lowercase, numbers, and symbols; avoid personal information (name, birthday); use a unique password for every account. Reusing passwords means one breach compromises all accounts. Use a reputable password manager (LastPass, Bitwarden) to generate and store complex unique passwords. Enable two-factor authentication (2FA) for critical accounts.
Question 3: What is 'two-factor authentication' (2FA)?
- A security method requiring two forms of verification (password + a code sent to your phone) to access an account (Correct answer)
- Having two different email accounts for added security
- Logging into an account from two different devices simultaneously
- A security question in addition to your regular password
Correct answer: A security method requiring two forms of verification (password + a code sent to your phone) to access an account
2FA requires something you know (password) plus something you have (phone with code) — making accounts far harder for hackers to access.
Two-factor authentication (2FA) adds a second verification layer beyond your password. Common 2FA methods: a one-time code sent via SMS, an authenticator app (Google Authenticator, Authy), biometrics (fingerprint, face recognition), or a physical security key. Even if a hacker steals your password, they cannot access your account without the second factor. Enable 2FA on all critical accounts — especially email and banking.
Question 4: What should you do before clicking a link in an email that claims to be from your bank?
- Hover over the link to see the actual URL, and if suspicious, go directly to the bank's website by typing the address yourself. (Correct answer)
- Click the link only if the email looks professional.
- Reply to the email to confirm it is legitimate.
- Forward the email to friends to see if they received the same one.
Correct answer: Hover over the link to see the actual URL, and if suspicious, go directly to the bank's website by typing the address yourself.
Hovering over links reveals their true destination. Typing the bank's URL directly bypasses potential phishing traps entirely.
Before clicking any link in an email claiming to be from a financial institution: hover over the link to see the actual URL in your browser's status bar (e.g., a 'Bank of America' email leading to 'bankofamerica.fake-login.ru' is phishing). Better yet, never click email links — open your browser and type the bank's official URL directly. Banks will never ask for your password via email.
Question 5: What is 'malware'?
- Malicious software designed to damage, disrupt, or gain unauthorized access to computer systems (Correct answer)
- Software that runs in the background to update your operating system
- A type of hardware failure in older computers
- Online advertisements that appear as pop-ups
Correct answer: Malicious software designed to damage, disrupt, or gain unauthorized access to computer systems
Malware (malicious software) includes viruses, ransomware, spyware, and trojans — all designed to harm systems or steal data.
Malware is a broad category of malicious software: viruses (spread by infecting files), worms (self-replicating, spread across networks), ransomware (encrypts your files and demands payment), spyware (secretly monitors your activity), trojans (disguised as legitimate software), and adware (bombards you with ads). Protect yourself: keep software updated, use reputable antivirus software, avoid suspicious downloads, and don't click unknown links.
Question 6: Why is it important to read an app's 'privacy policy' or 'terms of service' before installing it?
- It explains what personal data the app collects, how it is used, and who it may be shared with. (Correct answer)
- It is required by law to read before using any digital service.
- It tells you the exact price you will pay for the app.
- It proves the app is safe and free of malware.
Correct answer: It explains what personal data the app collects, how it is used, and who it may be shared with.
Privacy policies disclose data collection practices — knowing what an app does with your data helps you make informed decisions about using it.
Privacy policies (and Terms of Service) are legal documents disclosing what data an app collects (location, contacts, browsing history), how it's used, and whether it's sold to third parties. While lengthy and technical, understanding key points protects your privacy. If a free app's privacy policy reveals it sells your data to advertisers, you can make an informed choice about whether to use it. Resources like Terms of Service; Didn't Read (tosdr.org) summarize key points.
What does 'phishing' mean in cybersecurity?