Online Safety Test

Online Safety Test

Almost nobody gets scammed because they are careless. They get scammed because a message arrived at a believable moment, sounded urgent, and looked exactly like something real.

This free online safety test walks you through 20 of those moments. A package text you did not expect. A pop up warning about a virus. A boss asking you to wire money before a deadline. You pick what you would do, and every answer explains itself immediately.

You get a Cyber Smart score out of 100, a level, and a free certificate with your name on it. It takes about five minutes. No sign up, no email, and nothing you answer leaves your browser.

How the Online Safety Test Is Scored

Twenty questions, five points each. Every answer reveals the explanation straight away, so the test teaches as much as it measures.

Correct answersScoreLevel
18 to 2090 to 100Cyber Guardian
15 to 1775 to 85Cyber Smart
12 to 1460 to 70Cyber Aware
8 to 1140 to 55Safety Learner
7 or fewerBelow 40Safety Starter

Worth saying plainly: scoring well here means you recognize scams when you are calm, sitting down, and expecting a test. Real scams arrive when you are distracted, rushed, or already worried about something. Knowing the patterns is the point, not the number.

The Scams This Test Covers

NameHow it works
PhishingAn email pretending to be a company you use, pushing you to log in through their link so they capture your password.
SmishingThe same trick by text message. Delivery notices and toll charges are the most common covers.
VishingA phone call impersonating your bank, a government office, or tech support.
Tech support scamA pop up claims your device is infected and gives a number to call. The goal is remote access to your computer and your money.
Romance scamAffection built fast over weeks or months, then an emergency that needs money. Often the most financially devastating type.
Business email compromiseA message that appears to be from your boss, a supplier, or a relative, asking for an urgent transfer.
RansomwareSoftware that encrypts your files and demands payment to unlock them.
TyposquattingFake sites at addresses one character off from the real one, waiting for a mistyped domain or a hasty glance.
Credential stuffingPasswords stolen from one breached site tried automatically against hundreds of others. This is why reuse is dangerous.

Five Habits That Prevent Most Attacks

You do not need to become a security expert. A small number of changes block the overwhelming majority of what actually happens to ordinary people.

1. Use a password manager

This is the highest value change available to most people, because it fixes reuse permanently. One breached site stops being able to unlock your email, your bank, and your shopping accounts.

Guidance has shifted in recent years, and it is worth knowing the current thinking. Length matters more than special characters, so a long passphrase beats a short jumble of symbols. Forcing yourself to change passwords every few months is no longer recommended, because it pushes people toward small predictable edits. Change a password when there is a reason, such as a breach or a suspicion, rather than on a schedule.

You also do not have to memorize anything except one strong master password and the passwords for your phone and computer.

2. Turn on two factor, and know that not all of it is equal

Any second factor is far better than none. That said, there is a real hierarchy, and it matters because modern phishing pages can sit between you and the real site and pass your code straight through.

MethodStrength
Text message codesBetter than nothing, but vulnerable to phone number takeover and to phishing pages that relay the code in real time.
Authenticator app codesStronger. Not tied to your phone number, though a convincing fake login page can still capture the code.
Push approval promptsConvenient, but people do approve prompts they did not trigger when they are spammed with them. Never approve one you did not start.
Passkeys and hardware security keysStrongest. They are tied to the real website address, so a lookalike site simply cannot use them.

If a service offers passkeys, turning them on for your email account is one of the most protective things you can do. Email is the master key, since it is where every password reset lands.

3. Install updates

Most successful attacks use weaknesses that were already patched. Turning on automatic updates for your phone, computer, and browser closes those doors without you having to think about it.

4. Verify money requests on a number you already have

Any urgent request to move money deserves a phone call to a number you look up yourself, never the one in the message. This single habit defeats business email compromise, grandparent scams, and most impersonation fraud at once.

Deepfaked voices have made this more important, not less. Hearing a familiar voice on the phone is no longer proof of who you are speaking to, which is why some families agree on a private code word for emergencies.

5. Back up so ransomware is an inconvenience

The rule of thumb is three copies of anything you would hate to lose, on two different kinds of storage, with one of them kept somewhere separate. The separate copy is the part that matters, because ransomware encrypts every drive it can reach, including the backup drive plugged into your desk.

Red Flags That Show Up in Almost Every Scam

The specific story changes constantly. The underlying pressure tactics barely change at all.

  • Urgency. Act now, your account closes today, the warrant is being issued. Rush is the whole technique, because it stops you from checking.
  • Secrecy. Do not tell anyone, do not hang up, this is confidential. Real organizations never need you isolated.
  • Unusual payment. Gift cards, wire transfers, cryptocurrency, or payment apps. These are chosen because they are hard to reverse.
  • Contact you did not initiate. They called you. They emailed you. The safe response is always to hang up and reach out through a channel you found yourself.
  • A story that explains why the rules are different. A special one time exception, a reason the normal process does not apply.
  • Too good to be true. Free luxury items, guaranteed returns, a prize from a contest you never entered.
The one habit worth building

When something creates urgency about money or account access, stop and use a different channel. Hang up and call the number on your bank card. Close the email and type the website address yourself. Scams rely almost entirely on you staying inside the channel they control, and stepping outside it breaks nearly all of them.

What the Lock Icon Does and Does Not Mean

This one catches people who consider themselves careful.

The padlock and the https in your browser mean the connection between you and that site is encrypted, so nobody in between can read it. That is all it means. It says nothing about whether the site is honest.

Certificates are free and easy to obtain, so fraudulent sites have them too. A perfect looking padlock on a page at a lookalike address is a padlock on a fraud. The address bar is where the truth lives, not the icon next to it.

About Public Wi-Fi

The old warning was that anyone on café Wi-Fi could read your banking session. That specific risk is much smaller now, because almost all websites are encrypted by default.

The risks that remain are worth understanding. You cannot tell who actually runs a network, and a hotspot named after the café may not belong to the café. A malicious network can push fake login pages and redirect traffic. Open networks also expose devices to each other, which matters if anything you own is out of date.

So the advice still stands, just for updated reasons. Use your phone's own connection for anything sensitive, keep file sharing off, and be suspicious of any login page that appears unprompted after joining a network.

If You Think You Have Been Scammed

Speed matters more than anything else here, and so does setting shame aside. These schemes are professionally built and they catch careful, intelligent people every day.

  1. Stop all contact and send nothing further. Do not send one more payment, even if they say it will release the rest.
  2. Call your bank or card issuer immediately. Reversal windows are short, and hours can decide the outcome.
  3. Change your email password first, then anywhere you reused it. Email controls every password reset you own.
  4. Turn on two factor on email, banking, and anything financial.
  5. Run a security check if anyone had remote access to your device, and consider having it professionally cleaned.
  6. Report it. In the United States, the Federal Trade Commission takes reports at reportfraud.ftc.gov, the FBI's Internet Crime Complaint Center at ic3.gov, and identity theft is handled at identitytheft.gov. Other countries have equivalent agencies.
  7. Consider freezing your credit if personal details were exposed. It is free in the US and can be lifted whenever you need it.
Watch out for the second scam

People who have been defrauded once are frequently targeted again by someone claiming they can recover the lost money for an upfront fee. These recovery scams are often run by the same networks, using lists of known victims. Nobody legitimate asks for payment in advance to get your money back. If someone contacts you out of the blue offering to recover funds, that is the scam continuing.

Helping an Older Relative Stay Safer

Older adults are targeted heavily, and the most common mistake families make is leading with criticism. Someone who fears being told they were foolish, or that they will lose their independence, simply stops mentioning the strange phone calls.

A few things that tend to work better than warnings.

  • Agree that any request for money gets discussed with you first, framed as a rule you both follow rather than supervision.
  • Set up a family code word for emergency calls, which defeats voice impersonation.
  • Help them turn on two factor on email and banking while you are visiting.
  • Tell them plainly that no real agency ever asks for gift cards, so that single rule can be applied without judgment calls.
  • Make it safe to say they nearly fell for something. People who feel they can talk about a close call are far more likely to ask before acting next time.

Frequently Asked Questions

What is phishing?

A message pretending to come from an organization you trust, designed to get you to enter your login details on a fake page or open a harmful attachment. Email phishing is the most common, with text message versions called smishing and phone versions called vishing.

How do I make a strong password?

Make it long and unique to that account. A passphrase of several unrelated words beats a short complicated string. The practical answer for most people is a password manager, which generates and stores unique passwords so you never reuse one.

Should I change my passwords regularly?

Current guidance says no, not on a fixed schedule. Routine forced changes lead people to make small predictable edits. Change a password when there is a reason, such as a breach notice or any suspicion of compromise.

Is two factor authentication worth it?

Yes, and it is one of the most effective protections available. Text message codes are the weakest form but still much better than nothing. Authenticator apps are stronger, and passkeys or hardware keys are strongest because they cannot be used on a fake site.

Does the padlock icon mean a website is safe?

No. It means the connection is encrypted, not that the site is trustworthy. Scam sites can and do have padlocks. Check the address itself.

What should I do if I clicked a phishing link?

If you only opened the page and entered nothing, the risk is low. If you entered a password, change it immediately and anywhere you reused it, starting with your email account, then turn on two factor. If you downloaded anything, run a security scan.

Why do scammers ask for gift cards?

Because the money moves instantly, is nearly impossible to reverse, and is hard to trace. No legitimate business, utility, or government agency accepts gift cards as payment. That request alone is enough to end the conversation.

Is this test free, and are my answers stored?

Free, with no sign up or email. Everything runs in your browser and nothing you select is saved or transmitted.

This page is general safety education, not personalized security, legal, or financial advice. Threats and best practices change, so treat this as a starting point. If you have suffered a significant financial loss or believe your identity has been stolen, contact your bank and the relevant authorities in your country rather than relying on general guidance.

More Free Tests

  • Online Safety TestYou are here. Twenty scam and security scenarios with instant explanations and a free certificate.
  • AI Literacy TestHow AI really works, including deepfakes and why AI generated scams are getting harder to spot.
  • Money IQ QuizCheck your grasp of interest, credit, and everyday financial decisions.
  • Critical Thinking ExerciseTwelve scenarios that train you to spot weak reasoning and manipulation.

Other Free Tools