wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Online data security | Internet safety

Total questions: 36

Worksheet time: 1hrs 12mins

Name
Class
Date
1.

In 2014, Yahoo suffered a data breach that exposed details of at least 500 million user accounts, giving attackers access to real names, email addresses, dates of birth, and telephone numbers. With access to that information, which of these actions can be taken by an attacker? 👁️ Note that there are 2 answers to this question.

a)

They could email a user with a threat to reveal private information.

b)

The could hack into a user's computer and access their file systems.

c)

They could sell the user's Social Security numbers to another attacker on the Internet.

d)

They could post the users' home addresses on a public social media account.

e)

They could send spam messages to a user's mobile phone.

2.

Jairo is shopping for a new pair of shoes and has found four online stores that sell the shoes. He opens them all up in different browser tabs and begins the checkout process so that he can find out what the final price (with shipping and taxes) will be and decide if any of the websites aren't legitimate. Which of these online stores seems the most suspicious?

a)

The store that asks for his name, drivers licence number, credit card number, and address in the checkout form.

b)

The store that asks for his name, phone number, credit card number, and address in the checkout form.

c)

The store that asks for his email, age range, credit card number, and address in the checkout form.

d)

The store that asks for his credit card number and address in the checkout form.

3.

A software engineer for a university is creating a system to keep track of students. They need to decide which data should be considered PII so that they can store it in a more secure database. Which of the pieces of data is most likely to be considered PII?

a)

GPA (Grade Point Average)

b)

Grade level

c)

Declared major

d)

Home address

4.

Gene writes an article for his town's local newspaper about the spread of viruses in a warmer climate. In what ways could this article reveal PII?

a)

The illustrations accompanying the article indicate Gene's favorite colors.

b)

The vocabulary in the article could be analyzed to estimate the educational level of the author (high school, college, graduate, etc.).

c)

The author name could be looked up in the town's property tax records to identify Gene's address.

d)

The topic of the article suggests that Gene is a virology expert.

5.

Lana visits a news website she's never visited before. She notices a section called "Recommended for you" with a list of articles that are related to articles she'd been reading on other news sites. Which technology was most likely responsible for the recommended articles?

a)

Web cookies

b)

Rogue access points

c)

Keylogging software

d)

IP-based geolocation

6.

Daxton reads the privacy policy of his browser and realizes he is uncomfortable with the browser's default privacy practices. What would be a good next step?

a)

There is nothing he can do; all web browsers have the same privacy practices, per international standards.

b)

He can ask their Internet Service Provider for more privacy when using that browser.

c)

He can change the privacy settings in his browser to a level is comfortable with.

d)

He can switch browsers to a browser that has different privacy practices.

7.

A user doesn't want a website to know which of the web site's web pages they visit. Which actions can the user take to prevent the website from recording their browsing history along with any form of user identifier?

a)

Logging out of their account on the site is sufficient.

b)

Logging out of their account on the site and disabling cookies on their browser is sufficient.

c)

Logging out of their account on the site, disabling cookies on their browser, and restarting the browser for each webpage they visit is sufficient.

d)

No combinations of those actions is completely sufficient.

8.

An advertisement company builds a profile of a user based on their browsing history across many websites and uses that profile to create more targeted advertisements. Which technology enables the company to aggregate the user's browsing history across multiple sites?

a)

Geolocation

b)

Encryption

c)

Cookies

d)

Search engines

9.

A privacy-concerned citizen wants to introduce local regulations to restrict companies that collect the geolocation data of their users. They would like every company to present users with a warning and explanation before collecting the data. Which table identifies the types of companies that would be affected by those regulations? Each table lists four types of companies in the same order.

a)
b)
c)
d)
10.

In 2018, more than a thousand data breaches were reported and over 500 million data records were exposed in those breaches. In one particular breach, a video-making website discovered unauthorized access to their database. The attackers were able to access the following user details: first name, last name, username, geolocation, gender, and date of birth. Which of the following is an immediate risk of that data breach?

a)

A hacker could install keylogging software on the machine of one of the website users.

b)

A stalker could go to the house of one of the website users.

c)

A cybercriminal could use the credit card information of one of the website users to make an online purchase.

d)

A cybercriminal could take control of the access point of one of the website users, turning it into a rogue access point.

11.

A company develops a mobile app designed for parents to monitor what their children are doing. The parents install the app on the phone, and it can record details like who the child is conversing with and what apps they're using. It can also record and store the geolocation of the child. Which of these questions from parents could not be answered by the recorded geolocation data?

a)

Did my child hang out in the park in a group of more than 20 people?

b)

Did my child travel to another city today?

c)

Did my child spend more than an hour outside of the school campus in the middle of the day?

d)

Did my child break their curfew by staying outside of the home past 21:00?

12.

Billy receives a message from a stranger on a social media website that simply says "I know where you live." Billy tried to think about his online activities, and whether or not those activities could have revealed his location. Which of these online activities is least likely to have revealed his location to the stranger?

a)

Uploading a photo of their house, as taken from the street.

b)

Looking up driving instructions to their house on a mapping site over an unsecured HTTP connection.

c)

Uploading a photo of their cat sleeping in the garden (with no house visible).

d)

Reading news sites in a browser with third-party cookies enabled.

e)

Granting the social media site access to their geolocation while searching for nearby posts.

13.

Sahed works for admissions at a university. One day, she receives an email about a new admissions tool that she needs to start using ASAP. The email links to a webpage with a registration form. She decides to re-use her password from the old administration tool, and signs up with her email and that password. Unfortunately, she then receives a message from her manager that the email is a phishing scam targeting everyone in the department, and that she should ignore it. What are the effects of revealing that password to the cyber criminals? 👁️ Note that there are 2 answers to this equation.

a)

The cyber criminals can disable her ability to access her university computer and ask her to pay a ransom.

b)

The cyber criminals could use the password to login as any user of the actual admissions tool.

c)

The cyber criminals can infect the servers of the actual admissions tool with malware.

d)

The cyber criminals can try that password on the actual admissions tool and successfully gain access.

e)

The cyber criminals can sell her email and password combination to other attackers.

14.

Karlee receives this email that claims to be from Instagram, the social media site. Which aspect of the email is least indicative of a phishing attack?

a)

The text of the email contains alarming information about their account security.

b)

The sending email address is from a non-Instagram domain.

c)

The email footer includes the company's mailing address.

d)

The subject line uses multiple exclamation marks.

e)

The text of the email suggests clicking on a link.

15.

Evelyn receives an email that claims to be from the IRS, the United States Internal Revenue Service. The email states that their tax refund is ready and includes an attachment labeled "taxrefund.doc". Evelyn is eager for their refund but worried the email is a phishing scam. What is the safest next step?

a)

Evelyn can open the attachment from their mobile phone instead of from their personal computer, since the mobile phone is more malware-proof.

b)

Evelyn can search the Web to see if the ".doc" file type can every contain malware. If it is always safe, then they can open it.

c)

Evelyn can find the official IRS website by searching the Web and contact IRS through a listed email address to inquire about the email.

d)

Evelyn can download the attachment, send it through their antivirus software, and confirm that is has no malware inside it. Then they can safely open it.

16.

Sacha uses a payment app called Circle cash and typically logs on to his merchant account at "circle.com". He receives an email that claims to be from Circle cash and contains a link to a webpage. He clicks the link but then realizes that the email may be a phishing attack, as he didn't request a password reset recently. Once the webpage loads, he checks the URL in the browser to see if it's a legitimate Circle cash URL. Which of these URLs is most likely owned by CircleCash?

17.

Emilia arrived to work at there company's office at 9:00. She connected her laptop to the WiFi hotspot labeled "OfficeWiFi5thFl". After a meeting ended at 10:30, she connected to a different hotspot labeled "OfficeSpace5thFl". After lunch ended at 12:00, her laptop lost that signal and reconnected to "OfficeWiFi5thFl". If "OfficeSpace5thFl" was a actually a rogue access point, which website visits could it have intercepted?

a)

A visit to an analytics website at 9:20 where she downloaded the weekly analytics data.

b)

A visit to an online spreadsheets website at 9:50 where she filled out several rows of information about internal team deadlines.

c)

A visit to a tax software website at 10:45 where she filled out part of her tax form for this year.

d)

A visit to an expense management website at 12:15 where she submitted a receipt for reimbursement.

e)

A visit to an analytics website at 9:20 where she downloaded the weekly analytics data, a visit to an online spreadsheets website at 9:50 where she filled out several rows of information about internal team deadlines, a visit to a tax software website at 10:45 where she filled out part of her tax form for this year, and a visit to an expense management website at 12:15 where she submitted a receipt for reimbursement.

18.

Which of the following could not occur if your computer is connected to the Internet over a rogue access point?

a)

The rogue access point could modify the contents of your connection to a website.

b)

The rogue access point could analyze the types of websites you visit.

c)

The rogue access point could see what keywords you're searching for on a web search engine.

d)

The rogue access point could read the files on your device.

19.

An investigative journalist connects to the Internet over a wired Ethernet connection in a government building. They don't want anyone else to see which websites they're visiting. Which entities might be able to see the websites visited in that browsing session?

a)

A rogue access point and the building's Internet Service Provider (ISP) only.

b)

The building's Internet Service Provider (ISP) and their computer's web browser only.

c)

A rogue access point and their computer's web browser only.

d)

A rogue access point, the building's Internet Service Provider (ISP), and their computer's web browser.

20.

Süyenne is buying a subscription from an Internet Service Provider (ISP) for her new apartment so that she can have wireless Internet access in each room. She already has a laptop that can connect to WiFi networks. Does Süyenne need to purchase any additional hardware to have wireless Internet access?

a)

No, the laptop can connect wirelessly to the Internet as long as the apartment has a working wired connection to the Internet.

b)

She only needs to purchase more hardware if she wants a fast wireless connection. She can connect wirelessly to a slow connection without additional hardware.

c)

She only needs to purchase more hardware if she wants a secure wireless connection. She can connect wirelessly to an insecure connection without additional hardware.

d)

Yes, she needs a wireless router that will send an receive packets from the apartment's wired Internet connection.

21.

Which of these statements about malware are true. 👁️ Note that there are 2 answers to this question.

a)

Malware is a term that means the same thing as computer virus.

b)

Malware is a type of computer virus, but there are other types of viruses.

c)

A virus is a type of computer malware that only affects web servers.

d)

A virus is a type of computer malware, but there are other toes of malware.

e)

Malware can affect desktops, laptops, phones, servers.

22.

Which of the following algorithms is most likely to be found in a computer virus?

a)

An algorithm that copies the virus program into a different file.

b)

An algorithm that records all of the keys typed by a user.

c)

An algorithm that monitors the data sent over the Internet from the user.

d)

An algorithm that sends emails to all of the user's contacts.

23.

BBC News wrote an article with this headline: "HP laptops found have hidden keylogger". After reading that headline, what should HP laptop owners be most concerned about?

a)

The keylogger could be using up their computing power to mine for cryptocurrency.

b)

The keylogger could be overwriting their files with random generated text.

c)

The keylogger could be recording what they type and sending the logs to a server.

d)

The keylogger could be sending emails to all of their contacts with malware attached.

24.

ZeuS is malware that is typically used to steal banking data from a computer's users by installing a key logger and sending the logged data to the attacker. What best describes how antivirus software can protect against ZeuS?

a)

Antivirus software can prevent the user from ever downloading any malware.

b)

Antivirus software can warn the user not to use banking websites.

c)

Antivirus software can block network requests that are coming from a known ZeuS botnet.

d)

Antivirus software can scan the files on the drive and notify the users of files that look like the ZeuS malware.

25.

Which of the following is the best description of the process of decryption?

a)

Encoding data to prevent unauthorized access.

b)

Decoding data reveal the original message.

c)

Generating a public key.

d)

Verifying the authenticity of a message sender.

26.

Which of the following situations is made possible thanks to public key encryption?

a)

A company with medical data stores the health records securely in an internal database, such that engineers need a specific password to unlock them.

b)

A social media user posts an update and marks it as "friends only", enabling only their friends to see the update.

c)

A customer enters their credit card number on a website, and the server securely receives the number without the possibility of cybercriminal seeing the credit card number.

d)

A user browses a shopping website using the incognito mode of their browser, preventing the shopping website from tracking their usage and using that for future advertising.

27.

Which of the following best describes symmetric encryption?

a)

An encryption scheme where the sender encrypts data with the receiver's public key and the receiver decrypts the data with their own private key.

b)

An encryption scheme where the sender and receiver use the same shared key for encrypting and decrypting data.

c)

An encryption scheme where the sender and receiver each have their own key for encrypting and decrypting data.

d)

An encryption scheme where the sender encrypts data with the sender's public key and the receiver decrypts the data with the sender's private key.

28.

Computer A is sending data securely to Computer B using public key encryption. In order for Computer A to encrypt the data, they need to use information from Computer B in a mathematical operation. What information from Computer B is used in that operation?

a)

Computer B's IP address

b)

Computer B's public key

c)

Computer B's administrative password

d)

Computer B's private key

29.

Madden connected securely with HTTPS to this website: https://www.football-gamers.com/teams/tigers. His browser validated the digital certificate of the website before loading the page. The digital certificate contained this encryption key. What type of key is that and who does it belong to?

a)

It's the private key of football-gamers.com

b)

It's the public key of football-gamers.com

c)

It's the private key of Madden's browser

d)

It's the public key of Madden's browser

30.

On September 11, 2017, the Google Chrome security team announced a plan to stop trusting certificates issued from the Symantec certificate authority. The Chrome team announced the plan after reports that some of Symantec's certificate issuing organizations were issuing certificates to domains that weren't properly verified. Why is it so important that the Google Chrome team monitors the trustworthiness of certificates?

a)

A certificate indicates a domain is following best practices for securing user data. If a certificate isn't properly verified, then Chrome users might accidentally use websites that don't handle their data well.

b)

If a cybercriminal can register a domain for a certificate without verifying it, then they can register domains for activities that are illegal in some countries.

c)

If a cybercriminal acquires a certificate for a domain they don't own, they can use that to secretly steal private data from that domain's website users.

d)

If a domain doesn't go through the proper verification steps for the certificate, then their domain ➝ IP mapping may not work correctly, and users won't be able to load the domain in Chrome.

31.

Aliza visited a website over HTTPS and saw a lock icon on the URL bar, indicating a secure connection with a valid digital certificate. Which of these statements describes the trust model in this scenario.

a)

Aliza trusts the browser, the browser trusts the certificate authority, and the certificate authority trusts the website.

b)

Aliza trusts the certificate authority, the certificate authority trusts the browser, and the browser trusts the website.

c)

The certificate authority trusts Aliza, Aliza trusts the browser, and the browser trusts the website.

d)

The browser trusts Aliza, Aliza trusts the certificate authority, and the certificate authority trusts the website.

32.

Paula is creating a journalism organization to do investigative reporting. She registers the domain "whistleblowerz.org" and signs up with a hosting company to provide an email server, so that journalists can easily communicate with each other. She's debating whether to acquire a digital certificate for her domain from a certificate authorit. What benefit would the certificate bring?

a)

The certificate would notify the domain name servers that "mail.whistleblowerz.org" maps to the associated IP address for the email server.

b)

The certificate for "whistleblowerz.org" would ensure that the journalists using the email server all use strong passwords.

c)

The certificate for "whistleblowerz.org" would verify to users that the associated news stories are not "fake news".

d)

The certificate for "whistleblowerz.org" would associate a public key with the domain, and enable the server to use TLS for secure email sending.

33.

A popular blogger is worried about their video streaming account being broken into by attackers. The video streaming site offers them two options for authentication: a password or multi-factor authentication (with a password and SMS code). Which of these pieces of advice is accurate?

a)

It doesn't matter if they use MFA or password; both protect equally against account break-ins.

b)

If they use MFA, then their account can't be broken into.

c)

MFA will offer more security than a passwords but they still need to be vigilant to protect their account from attackers.

d)

If they use MFA and a strong password, then their account can't be broken into.

34.

A website is setting up a multi-factor authentication system and considering which evidence to ask for. Which of the following combinations would not count as a multi-factor authentication system?

a)

The user's voice saying "Hello" & a code sent to the user's cell phone.

b)

The user's voice saying "Hello" & the user's favorite song.

c)

The user's favorite song & a password set by the user.

d)

A code sent to the user's cell phone & a password set by the user.

35.

Which statements are true about multi-factor authentication? 👁️ Note that there are 2 answers to this question.

a)

MFA requires the user to reveal PII in order to authenticate.

b)

MFA adds a layer of encryption to online authentication.

c)

MFA requires evidence from at least two authentication factors.

d)

MFA adds an additional level of security to the authentication process.

36.

Amos decides to use a password manager to store their passwords, and is currently coming up with a master password. Which of these is the strongest master password?

a)

"aiwwdts1d&dd,Icub&m2md", an initialism based on song lyrics ("As I was walking down the street one dark and dreary day, I came upon a billboard and much to my dismay..")

b)

"3141592653589793", the first 16 digits of PI.

c)

"1943_spruce_ave", which is based on their address.

d)

"M@sterp@ssw0rd!"