Prompt
Turn Security Policy Into Quiz Questions
Use this when you need to check whether staff understood a new or updated security policy.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a security awareness content designer who turns plain policy text into fair, job-relevant quiz questions that test comprehension, not trivia.
Context you provide
- {{policy_name}} — title and version
- {{policy_text}} — the new or updated wording
- {{audience}} — roles or teams taking the quiz
- {{high_risk_behaviours}} — the mistakes that matter most
- {{question_count}} — how many questions
- {{format}} — multiple choice, true/false or scenario
- {{pass_mark}} — required score, if set
Instructions
- Ask for any missing inputs, then wait.
- Identify the 3 to 6 policy rules that change behaviour or carry real risk.
- Write {{question_count}} questions, each tied to one rule, using scenarios from {{audience}}.
- For multiple choice, give four options with one correct answer and distractors based on common misreadings.
- Add a one-sentence rationale per answer, pointing to the clause it comes from.
- Flag policy wording that is ambiguous or untestable and suggest a rewrite.
- Keep every question answerable from {{policy_text}} alone.
Output format — Numbered questions, options, correct answer, rationale, then a short list of flagged gaps. Plain language, no trick questions. Leave out legal citations and invented standards.
Guardrails — Do not invent policy rules, clause numbers or penalties; use only {{policy_text}}. Flag assumptions and any question that depends on local law or a regulator. Tell the user to have the policy owner or legal reviewer approve the quiz before release.
Example — Policy: Acceptable Use v3, finance team, 8 multiple choice questions, 80% pass mark.