Phishing and verification
Test the pause before the click.
Use email, chat, QR-code, and payment scenarios. Ask what to inspect and how to verify an unusual request.
- Unexpected links
- Domain differences
- Independent verification
Describe your workforce and priority risks. Makeform turns the brief into a practical security awareness survey with scenario questions, role context, and follow-up prompts.
Send survey responses to Slack, Google Sheets, and Zapier.
Sample prompts for the builder
Choose a prompt, tailor it to your policies, or send it to the Makeform builder.
Audience
Employees across departments and seniority levels
Format
Ten-question scenario survey with topic tags
Prompt size
302 chars
Example survey structure
Ten-question scenario survey with topic tags
A supplier sends a new sign-in link. What do you do first?
How should you handle an unexpected approval prompt?
How do you report a suspected incident?
Your department
Topics needing more guidance
Suggested routing tags
Strong awareness
Review recommended
Training follow-up
Use believable workplace situations. Scenarios reveal whether someone recognizes the safe action when details compete for attention.
Step 1
Define
audience, risks, policies, and reporting path
Step 2
Test
short scenarios that require a safe decision
Step 3
Review
topic patterns, confidence, and missed concepts
Step 4
Respond
targeted guidance and a later follow-up survey
Measure practical judgment
Completion records show attendance. A security awareness survey shows how employees respond to suspicious messages, lost devices, and unexpected access requests.
Frame questions around decisions employees face, with enough context to choose the next action.
Tag questions by phishing, passwords, data, devices, or reporting to identify weak subjects.
Show specialized questions for finance, managers, remote staff, or administrators after a common baseline.
Survey design choices
Assess judgment without inviting passwords, confidential records, incident details, or sensitive screenshots.
Route managers, finance staff, and IT to relevant scenarios after a shared core.
Use plausible choices and make the preferred action specific.
Pair answers with confidence to distinguish uncertainty from misconceptions.
Tell respondents not to enter passwords, recovery codes, confidential data, or incident evidence.
Build the survey
Start with required decisions, then structure results to reveal training priorities without collecting unnecessary data.
Tell the builder who will respond, which threats matter, what employees have already learned, and the exact internal reporting route that answer explanations should reference.
Replace generic policy assumptions with your own guidance. Check that one option is clearly preferred, distractors remain believable, and no question asks for sensitive information.
Show role-specific sections only when relevant, then label each question by subject so exported responses can support a phishing, password, device, or reporting breakdown.
Distribute the survey, review patterns by topic and role, offer focused guidance, and use a later version with fresh scenarios to see where understanding has changed.
Choose the right measurement
These activities answer different questions. Use the security awareness survey for knowledge and judgment, and interpret its findings alongside behavior and training feedback rather than treating one score as a complete risk measure.
Field guide
Use these six sections to balance core knowledge, workplace decisions, response confidence, and training needs. Edit every recommended action to match your organization before sharing.
Phishing and verification
Use email, chat, QR-code, and payment scenarios. Ask what to inspect and how to verify an unusual request.
Authentication
Test password reuse, recovery information, and unexpected multifactor prompts without asking for real credentials.
Data handling
Present choices about sharing, storage, printing, and disposal. Keep examples fictional so no confidential data is copied.
Devices and workplaces
Ask about lost devices, screens, updates, removable media, public networks, and visitors. Tailor the mix to employee work patterns.
Incident reporting
Test what warrants a report and which internal channel to use. Put your real process in the reviewed guidance.
Context and follow-up
Role, confidence, and requested topics can guide education. Explain how results will be used and avoid identifying small groups.
Related tools
Build a focused quiz, collect training feedback, survey employees, document completion, assess business risks, and standardize incident intake with these live Makeform tools.
Create a focused knowledge quiz for cybersecurity concepts and safe workplace decisions.
Open toolAsk participants which training examples were clear and what needs improvement.
Open toolCollect broader employee opinions and workplace context in a separate survey.
Open toolRecord completion acknowledgments separately from knowledge and confidence responses.
Open toolCapture and prioritize operational risks that may shape future awareness topics.
Open toolGive employees a structured intake path when a suspicious event needs reporting.
Open toolFAQ
Practical answers for security and IT managers planning an employee knowledge check.
It gauges how employees understand and apply safe practices. Useful versions present workplace scenarios about phishing, authentication, data, devices, access, and reporting instead of testing vocabulary alone.
Cover suspicious messages, multifactor prompts, password reuse, file sharing, lost devices, visitors, remote work, and incident reporting. Adapt preferred answers to your policies and roles.
Collect names only when individual follow-up is necessary. A broad role may be enough. Explain how results will be used and avoid small-group reports that identify respondents.
Define preferred answers and ask for scoring or topic labels, then review the logic. Topic patterns and confidence can be more actionable than one overall score.
Run it when results support a decision, such as before training or after time to apply it. Use fresh scenarios in follow-ups while measuring the same topics.
Yes. Makeform provides unlimited free forms and responses, so you can generate, edit, share, and repeat the survey without a response cap. The paid tier removes the Makeform badge.
Yes. Use conditional paths for finance, people teams, managers, or IT after a broad role question. Keep some core questions common for a shared baseline.
Review missed topics and confidence patterns by broad role. Turn clear gaps into focused guidance, reinforce the reporting path, and later check the same topics with new scenarios.
Turn awareness into a measurable baseline.