LLN Digital Literacy Skills — Questions and Answers
Question 1: Which of these is the strongest sign that an email may be a phishing attempt?
- It urgently asks you to click a link and enter your password (Correct answer)
- It comes from a known colleague with no attachments
- It has a company logo in the signature
- It was sent during business hours
Correct answer: It urgently asks you to click a link and enter your password
Urgent requests to click a link and enter credentials are a classic phishing tactic designed to create pressure and bypass caution.
Phishing emails commonly use urgency ('your account will be locked') combined with a request to click a link and enter sensitive information like a password. Legitimate organizations rarely ask for passwords via email. A logo or normal sending time doesn't guarantee legitimacy, since these are easy to fake, whereas urgent credential requests are a recognized red flag taught in digital literacy and cybersecurity awareness training.
Question 2: What is the safest way to create a strong password?
- Use a long, unique combination of words, numbers, and symbols not reused elsewhere (Correct answer)
- Use your birthdate for easy memory
- Reuse the same password across all accounts
- Use a short, simple word like 'password123'
Correct answer: Use a long, unique combination of words, numbers, and symbols not reused elsewhere
Long, unique passwords that aren't reused across accounts significantly reduce the risk of a breach spreading to other accounts.
Password strength depends on length, unpredictability, and uniqueness. A long passphrase combining unrelated words, numbers, and symbols is far harder to guess or crack than a short common word or a personal date. Reusing passwords is especially risky because if one account is breached, attackers can try the same password on other accounts — a technique called 'credential stuffing'.
Question 3: When searching online for information, which of these best indicates a source may be more reliable?
- The information is backed by verifiable evidence and a reputable, identifiable author or organization (Correct answer)
- The website has a colorful design
- It appears at the top of search results
- It matches what you already believed
Correct answer: The information is backed by verifiable evidence and a reputable, identifiable author or organization
Reliability is best judged by verifiable evidence and an identifiable, reputable source — not by design, ranking, or personal bias.
Evaluating online information critically is a core digital literacy skill. Search ranking, visual design, or confirmation of existing beliefs are not reliable indicators of accuracy. Instead, learners are taught to check for verifiable evidence, identifiable authorship, and the reputation or credentials of the source, and to cross-check claims against other reputable sources.
Question 4: What is the main purpose of two-factor authentication (2FA)?
- It adds a second verification step, making it harder for someone to access your account with just a stolen password (Correct answer)
- It replaces the need for a password entirely
- It slows down login for no security benefit
- It is only used for banking apps
Correct answer: It adds a second verification step, making it harder for someone to access your account with just a stolen password
Two-factor authentication requires a second proof of identity, such as a code sent to your phone, in addition to the password.
Two-factor authentication (2FA) requires a second piece of evidence beyond the password — typically a one-time code, biometric scan, or authentication app approval. This means that even if a password is stolen, an attacker generally cannot access the account without also having the second factor. It is widely used across email, banking, and workplace systems, not only banking apps.
Question 5: Which practice best protects personal information when using public Wi-Fi?
- Avoiding logging into sensitive accounts, or using a trusted VPN (Correct answer)
- Turning off your device's firewall for faster speeds
- Sharing your files openly on the network
- Using the same password you use everywhere else
Correct answer: Avoiding logging into sensitive accounts, or using a trusted VPN
Public Wi-Fi networks are often unsecured, so avoiding sensitive logins or using a trusted VPN reduces the risk of data interception.
Public Wi-Fi networks often lack strong encryption, making it easier for others on the same network to intercept data. Best practice is to avoid logging into sensitive accounts (banking, email) on public Wi-Fi unless using a trusted VPN that encrypts the connection. Disabling security features or reusing passwords would increase risk rather than reduce it.
Question 6: A file attachment arrives from an unknown sender with an unusual file extension. What is the safest action?
- Do not open it, and report or delete the email (Correct answer)
- Open it to see what it contains
- Forward it to coworkers to check if they recognize it
- Download it and scan it after opening
Correct answer: Do not open it, and report or delete the email
Unrecognized attachments from unknown senders are a common malware delivery method — the safest action is not to open them at all.
Unexpected attachments, especially with unusual file extensions, are a common vector for malware. The safest practice is to avoid opening the file altogether and instead report it to IT/security or delete it. Scanning a file only after opening it may be too late, since some malware executes immediately upon opening, and forwarding it risks spreading the same threat to others.
Which of these is the strongest sign that an email may be a phishing attempt?