15 quick questions to check your everyday security instincts.
Your answers and score are calculated entirely in your browser and never sent anywhere. This tool runs entirely in your browser. You can disconnect from the internet after the page loads and it will keep working — proof that nothing is being transmitted. No accounts, no cookies, no analytics tracking what you type.
Most successful attacks don't rely on breaking encryption or exploiting obscure software bugs — they rely on everyday browsing habits: reusing passwords, ignoring browser warnings, clicking unexpected links, or downloading files from untrusted sources. This quiz checks your instincts against 15 common real-world scenarios.
No — the whole quiz runs in your browser using JavaScript. Nothing about your answers or score is sent to a server or stored anywhere.
That's exactly what this quiz is for — a low score just means there's room to tighten up a few habits. Check the explanation after each question for the reasoning behind the safer choice.
Security software catches a lot, but the last line of defence is always a human decision: click or don’t click, connect or don’t connect. This quiz tests the everyday judgement calls — public Wi-Fi, unexpected attachments, “urgent” login requests — that no antivirus can make for you.
A low score is not a failure; it is a map. Each wrong answer comes with the reasoning, so treat the results page as a personal lesson plan. Re-take the quiz after a month — research on security habits shows that spaced repetition is what turns one-off knowledge into default behaviour.
Safe browsing is less about knowing many things and more about doing a few things consistently. The list below is short on purpose — these are the habits that account for most real-world protection.
Browser, operating system, and phone apps. The overwhelming majority of drive-by attacks exploit flaws that were fixed months earlier. Turning on automatic updates is the single highest-value security action most people can take, and it requires no ongoing effort.
A convincing copy of a login page is easy to build; a convincing copy of a domain name is not. Before typing a password, look at the address bar and check the two labels immediately before the first slash. Better still, reach important sites through bookmarks or the official app rather than through links.
Download software from the maker's own site or an official app store, never from a search advert, which is a common malware delivery route. Browser extensions deserve particular care: they can read everything you do in the browser, and popular extensions are sometimes sold to new owners who add tracking or malicious code. Keep the number you have installed small and review them occasionally.
Browser password stores are a primary target for information-stealing malware, which can extract them in seconds. A dedicated password manager keeps the vault encrypted and locked behind a master passphrase.
Almost all web traffic is encrypted now, so the old warnings are overstated, but the network operator can still see which sites you visit and captive portals are sometimes used to push fake update prompts. Avoid connecting automatically to open networks, and be suspicious of any prompt to install something in order to get online.
None of this takes long, and together it removes most of the realistic risk. Perfect security is not the target; being a harder target than the automated attacks expect is.
Less than it used to be, because almost all web traffic is now encrypted. The realistic risks are the network operator seeing which sites you visit, and fake login portals or update prompts. Avoid installing anything a network asks you to install.
It depends what you want from it. A VPN hides your traffic from your network provider and changes your apparent location. It does not protect against phishing, malware or account takeover, which cause most actual harm.
Some are, and all of them can read what you do in the browser. Install few, install from the official store, check the developer, and review them periodically. Popular extensions have been sold and turned malicious after the fact.
A dedicated password manager is safer. Browser password stores are a primary target for information-stealing malware and can often be extracted quickly if a device is compromised.
No. It stops your own device recording the history. Your network provider, your employer and the websites themselves can still see the activity.