Skip to main content
Templates/Quizzes/Cybersecurity Awareness Training
Pass/Fail AssessmentBusiness

Phishing Quiz: Can Your Team Spot a Fake Sender?

Free 8 question phishing quiz for employees: spot fake sender domains, vishing calls, and ransomware. Pass mark 80 of 100, explanations included.

8questions
10-15 min
Medium
Pass/FailExplanationsCertificate Ready
Browse More Templates
uplup.com/p/3jfcms8w

Live interactive preview - try it out!

A pass mark of 80 out of 100, eight questions, and roughly 10 to 15 minutes per employee. That is the entire footprint of the Cybersecurity Awareness Training quiz, a scored assessment that checks whether staff can recognize phishing emails, vishing calls, weak passwords, ransomware, and the risks of public Wi-Fi before an attacker tests them for real.

It runs as a pass or fail test, so the outcome is a clean compliance record rather than a vague score, and every answer carries a written explanation of why it is right or wrong.

An email from rnicrosoft.com just hit the finance inbox

Picture the scenario the opening question is built around. A message arrives carrying a familiar logo, sent during business hours, formatted like every other internal email. The only tell is the sender's domain, which does not match the organisation it claims to represent. The quiz's own explanation cites the classic trick of registering rnicrosoft.com to impersonate microsoft.com, a swap most people miss at a glance.

That is the judgment this assessment measures. Not whether someone can define a firewall, but whether they pause on the small details that separate a legitimate request from a trap.

Lookalike domains, ransom notes, and a fake IT caller

The quiz mixes single choice, select all that apply, and true or false formats across its eight items. Alongside the phishing indicator question, staff work through a strong password checklist, a definition of social engineering, and a scenario quoted here in full: "You receive a phone call from someone claiming to be from IT support asking for your password to fix an urgent issue. What should you do?" The correct move, refusing and reporting through official channels, earns the points. Handing over even part of the password does not.

Later questions cover ransomware, safe handling of sensitive data, whether MFA matters beyond financial accounts, and a true or false statement about whether a password makes public Wi-Fi. Each answer is worth 12.5 points, skipping is permitted, and takers can revisit anything they answered earlier before submitting.

What a score of 80 actually certifies

Scoring is pass or fail against a 100 point total, with 80 needed to clear the bar. In practice, an employee can miss one question and still pass, but not two. There is no instant feedback during the attempt; explanations appear after submission, so the quiz measures knowledge first and teaches second.

Retakes are switched on in this template's settings, meaning anyone who falls short can study the explanations, close the gaps, and sit the test again. On your side, response analytics reveal how each individual question performed across the team, so if half the company stumbles on the public Wi-Fi item, you know exactly what the next security briefing should cover.

From the security team to every employee without a ticket queue

Everything here runs on Uplup's free plan, so the first company wide round costs nothing. Send the quiz by direct link in an announcement email, print its QR code into onboarding packets, or paste the embed snippet into the intranet. If the internal portal happens to run on WordPress, a shortcode from the Uplup plugin places the quiz on any page without touching a template file.

Results export to CSV for the compliance folder, and webhooks or Zapier can push each completed attempt into your HR system as it lands. All eight questions, their answer choices, their explanations, and the 80 point threshold are editable before you send a single invite, and applying your company's logo and colors makes the quiz read as an internal document rather than a third party test.

Who Is This Template For?

This template works for a wide range of goals and industries.

New hire security onboarding

Add the quiz to week one paperwork so every new employee proves they can spot a mismatched sender domain and a fake IT support call before they get inbox access. The 10 to 15 minute run time fits neatly between longer onboarding sessions.

Annual compliance certification

Run the assessment once a year as the knowledge check behind your security policy. The 80 point pass mark and CSV export give auditors a dated, per employee record, and retakes let anyone who misses the bar certify after reviewing the explanations.

Follow-up after a phishing incident

If a real or simulated phishing email caught people out, assign this quiz as the retraining step. Question level analytics then show whether the weak spot was lookalike domains, password habits, or public Wi-Fi assumptions, so the next briefing targets the actual gap.

What's Included in This Template

8 Questions

Professionally written questions with detailed explanations.

Pass/Fail Scoring

Participants need 80% to pass, with detailed feedback on each answer.

Fully Customizable

Edit questions, change colors, add your logo, set up integrations, and publish on your own domain.

Questions in This Quiz

1

Which of the following is the strongest indicator that an email is a phishing attempt?

Multiple Choice4 options12.5 pts
2

Which of the following are characteristics of a strong password? (Select all that apply)

Select All That Apply4 options12.5 pts
3

Multi-factor authentication (MFA) only provides security benefits when used on financial accounts.

True / False12.5 pts
4

What is 'social engineering' in the context of cybersecurity?

Multiple Choice4 options12.5 pts
5

You receive a phone call from someone claiming to be from IT support asking for your password to fix an urgent issue. What should you do?

Dropdown4 options12.5 pts
6

Which of the following are safe practices for handling sensitive data? (Select all that apply)

Select All That Apply4 options12.5 pts
7

What type of attack involves encrypting a victim's files and demanding payment for the decryption key?

Multiple Choice4 options12.5 pts
8

Using public Wi-Fi to access company resources is safe as long as the Wi-Fi network has a password.

True / False12.5 pts

Key Features

Pass or fail scoring at 80 points

Eight questions worth 12.5 points each roll up to a 100 point total with an 80 point pass line, giving you a binary certified-or-not outcome for every employee. The threshold is editable if your policy demands a stricter bar.

Explanations after every attempt

Instant feedback is off, so answers stay hidden during the test, then each question reveals a written explanation, like why a mismatched sender domain outweighs a convincing logo. Failed attempts double as training material.

Question level response analytics

The results dashboard shows how the whole team scored on each of the eight questions, making it obvious whether people struggle with ransomware, MFA, or data handling. Export the full response set to CSV or push attempts out through webhooks and Zapier.

Fully editable questions and branding

Rewrite any question, option, or explanation to match your internal policies, adjust the pass mark, and apply your organisation's logo and colors so the assessment looks like it came from your own security team.

How It Works

1

Choose This Template

Click "Use This Template Free" to get started. You will get a full copy of this quiz in your account, ready to edit.

2

Customize It

Edit the questions, update the results, change the design, and add your branding. Everything is editable from the visual builder.

3

Share & Collect Results

Publish your quiz and share it with a link, embed it on your website, or post it on social media. View responses in real time.

Frequently Asked Questions

Does this quiz include real phishing questions?
Yes. The opening question asks which sign most strongly marks an email as a phishing attempt, and the correct answer is a sender domain that does not match the organisation it claims to represent. A later scenario covers vishing, the phone based variant, where a caller posing as IT support asks for a password. Both come with explanations that spell out the tactic.
What score do employees need to pass?
80 out of 100. Each of the 8 questions is worth 12.5 points, so a taker can get one wrong and still pass, but two misses put them under the line. Scoring is strictly pass or fail, which keeps the compliance record unambiguous.
Can someone retake the quiz if they fail?
Yes. This template ships with retakes enabled, so an employee who scores under 80 can read the explanations shown after submission and make another attempt. If your process requires a single sitting, you can disable retakes in the quiz settings.
Do I need a paid plan to run this phishing quiz?
No. It runs on Uplup's free plan. Editing questions, sharing the link or QR code, embedding it, collecting responses, and exporting results to CSV all work without upgrading.

Ready to Use This Quiz Template?

Customize the questions, add your branding, and share with your audience in minutes.