Certified Security Awareness 1 Exam Prep
Free practice questions

Free C)SA1 Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

These 10 free C)SA1 questions are organized by exam domain, so you can see how each part of the Certified Security Awareness 1 blueprint is tested. Reveal the answer and explanation under each question.

Domain 2: 2025 Cyberthreat Trends

Question 1

'The backup has undone the damage,' says a manager after a ransomware incident. Responders have restored accurate records to clean systems and normal service has resumed. They have also confirmed that the attackers copied customer records before encrypting them. What should the manager understand about the restoration?

Show answer & explanation

Correct answer: C - Availability has been restored; the disclosure has not been reversed.

Domain 3: The Human Factor

Question 2

At a badge-controlled entrance, a familiar delivery driver asks an employee to hold the door because his hands are full. The delivery is expected, but visitors must sign in at reception before entering the work area. How should the employee handle the request?

Show answer & explanation

Correct answer: B - Direct him to reception for the required visitor check-in.

Domain 4: Phishing & Social Engineering

Question 3

A supplier's usual email account replies within an existing invoice thread, asking for payment to a new bank account. The amount and invoice number match your records, and the message contains no link or attachment. Which verification would best protect the payment?

Show answer & explanation

Correct answer: B - Call the supplier using the number already held in the vendor record.

Question 4

The known payroll address is payroll.alder.example. A QR code in an unexpected email opens this address: https://payroll.alder.example.login-review.example/signin The browser shows no certificate warning. Which reading of the address is correct?

Show answer & explanation

Correct answer: D - The host is under login-review.example, not alder.example.

Domain 5: Credentials, Passwords, and Access Security

Question 5

An investigation finds that attempted work-email logins used exact username-password pairs stolen from an unrelated shopping website. The affected employees had reused those passwords. Which attack-control pairing fits these findings?

Show answer & explanation

Correct answer: D - Credential stuffing; use a unique password for every service.

Question 6

Why would FIDO/WebAuthn passkeys help against a fake sign-in page that captures a password and one-time code, then immediately relays both to the genuine service?

Show answer & explanation

Correct answer: A - Authentication is cryptographically bound to the legitimate service.

Domain 6: Data Protection & Handling Sensitive Information

Question 7

Dispatch is authorized to send an approved courier today's customer names and delivery addresses. Its spreadsheet export also contains birth dates and payment details. The approved transfer portal encrypts uploaded files, and the courier's recipient account has been verified. What should dispatch send?

Show answer & explanation

Correct answer: A - An export limited to customer names and delivery addresses.

Question 8

Full-disk encryption is enabled on a payroll laptop. An employee needs to step away while a spreadsheet is open, and visitors are nearby. Which control addresses the exposure that disk encryption does not?

Show answer & explanation

Correct answer: B - Lock the session before leaving the laptop.

Domain 7: Communication Security & Collaboration Tools

Question 9

Approved request: two named external auditors may read one confidential report. Editing and access to other project files are not authorized. The platform supports file-level sharing with verified recipients. Which arrangement gives the auditors the access they need?

Show answer & explanation

Correct answer: C - Share that report with the two auditors using view permission.

Domain 8: Incident Response, Security Culture, and Wrap-Up

Question 10

Files on an office laptop are being renamed and a ransom demand appears. Ethernet and Wi-Fi are both active. The incident procedure authorizes immediate user-initiated isolation, both network connections can be disconnected, and a separate phone is available for contacting security. What should happen first?

Show answer & explanation

Correct answer: D - Disconnect Ethernet and Wi-Fi, leave power on, and call security.

The rest of the C)SA1 blueprint

The C)SA1 exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more C)SA1 questions with explanations.

Continue in the free practice test →

View plans