wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Professional Ethics in Information Systems

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

What is the primary focus of professional ethics?

a)

Technical skill development

b)

Legal compliance only

c)

Relationships and responsibilities to clients and society

d)

Marketing and sales strategies

2.

Which of the following is a general moral imperative under the ACM Code?

a)

Increase software costs

b)

Avoid harm to others

c)

Promote software sales

d)

Encourage software piracy

3.

Which principle states that software engineers must act consistently with the public interest?

a)

Principle 2: Client and Employer

b)

Principle 4: Judgment

c)

Principle 1: Public

d)

Principle 6: Profession

4.

If a software engineer discovers a serious security vulnerability, what is their ethical responsibility?

a)

Sell the information to competitors

b)

Keep it confidential forever

c)

Disclose it to the appropriate persons or authorities

d)

Post it on social media for awareness

5.

A left-handed user tests a handwriting system and finds it unusable. What guideline was overlooked?

a)

Avoiding intellectual property conflicts

b)

Honoring confidentiality

c)

Designing for real users

d)

Prioritizing cost over safety

6.

A developer is assigned to a high-risk AI system affecting public safety. How should ethical guidelines shape their decision-making?

a)

Deliver the product as quickly as possible

b)

Focus only on technical specifications

c)

Evaluate safety, involve stakeholders, and delay if risks are unclear

d)

Let clients make all decisions

7.

A software engineer wants to report unethical conduct by their employer, but fears job loss. Which ethical principle should guide them?

a)

Remain silent unless asked

b)

Prioritize loyalty over integrity

c)

Report significant violations if other methods are ineffective or dangerous

d)

Delete all evidence for self-protection

8.

What is the purpose of professional codes of ethics?

a)

To increase company revenue

b)

To provide ethical guidelines and support for professionals

c)

To manage software updates

d)

To promote political agendas

9.

According to the ACM Code, programmers should:

a)

Always follow client instructions regardless of ethics

b)

Share personal passwords with coworkers

c)

Respect the privacy of others

d)

Avoid reporting software bugs

10.

Who can be affected by a computer professional's work?

a)

Only the client

b)

Just coworkers

c)

Only programmers

d)

Clients and the general public

11.

Which principle emphasizes lifelong learning for software engineers?

a)

Principle 5: Management

b)

Principle 8: Self

c)

Principle 2: Client and Employer

d)

Principle 7: Colleagues

12.

A software engineer reviews a colleague's work and finds major issues. What is the best ethical action?

a)

Keep it private to avoid conflict

b)

Report it only if the colleague agrees

c)

Provide a candid, objective, and documented review

d)

Ignore the problem entirely

13.

A manager assigns a project without considering an employee's experience. What ethical guideline does this violate?

a)

Ensure fair wages

b)

Prioritize company profit

c)

Assign work based on qualifications and educational background

d)

Encourage competition among staff

14.

How should a professional respond to pressure from management to hide known security flaws in software?

a)

Comply without question

b)

Publicly release the flaws immediately

c)

Refuse to comply and raise the issue ethically

d)

Blame others in the team

15.

What best demonstrates ethical leadership in software engineering?

a)

Promoting one's own interest over team needs

b)

Ignoring outdated software documentation

c)

Encouraging ethical behavior, fair management, and transparent practices

d)

Keeping technical standards secret from staff

16.

Which of the following defines cybersecurity?

a)

Designing gaming software

b)

Protecting systems, networks, and data from digital attacks

c)

Creating social media platforms

d)

Developing hardware components

17.

The CIA triad in cybersecurity stands for:

a)

Control, Inspect, Authenticate

b)

Confidentiality, Integrity, Availability

c)

Confidentiality, Intrusion, Analysis

d)

Control, Integration, Access

18.

Which term describes software that secretly installs itself and can control a computer?

a)

Firewall

b)

Phishing

c)

Malware

d)

Encryption

19.

If a user receives an email claiming to be from their bank but asking to verify login credentials, this is likely:

a)

A firewall alert

b)

A phishing attack

c)

A malware installation

d)

A DoS attack

20.

Which action helps maintain system availability during an attack?

a)

Deleting system logs

b)

Using redundancy and backups

c)

Disabling firewalls

d)

Ignoring packet filtering

21.

A company suffers repeated data corruption after a breach. As a cybersecurity analyst, what best combines integrity and availability protections?

a)

Install encryption and delete backups

b)

Deploy checksums for data integrity and redundant backup servers

c)

Remove access controls and save logs

d)

Swap out all software immediately

22.

A hacker uses spoofed IP addresses in a DoS attack. To mitigate this, you might:

a)

Allow all IP traffic

b)

Implement packet-filtering and source validation

c)

Share all logs publicly

d)

Disable logging

23.

What is a vulnerability?

a)

An attack type

b)

A weakness in a system that can be exploited

c)

A security policy

d)

A type of encryption

24.

What does a firewall do?

a)

Encrypts network traffic

b)

Monitors and filters incoming/outgoing traffic based on rules

c)

Detects phishing emails

d)

Physically destroys storage media

25.

Which actor is most likely to launch a hacktivist attack?

a)

State-sponsored intelligence agency

b)

Criminal organization

c)

Activist group using hacking for social or political causes

d)

Individual trying to steal data for personal gain

26.

A denial-of-service (DoS) attack aims to:

a)

Corrupt data silently

b)

Prevent legitimate users from accessing services

c)

Steal credentials via email

d)

Modify firewall settings

27.

During a vulnerability assessment, which step assesses network weaknesses?

a)

Writing user manuals

b)

Port scanning to find open services

c)

Training staff on phishing

d)

Encrypting backups

28.

To protect against malware inserted via USB devices, a company should:

a)

Block all USB ports

b)

Allow unrestricted USB use

c)

Install antivirus and restrict USB functionality

d)

Disable all file scanning

29.

A targeted phishing email bypasses traditional spam filters using employee-specific data. What defense best counters this?

a)

Only use email text-based filters

b)

Implement user training, multi-factor authentication, and behavior analytics

c)

Disable email altogether

d)

Block all attachments permanently

30.

A network experiences IP spoofing and amplification attacks. What layered defense strategy should be used?

a)

Only install antivirus

b)

Combine packet filtering, ingress/egress filtering, and network monitoring

c)

Remove all security controls

d)

Only rely on user education

31.

Which type of malware replicates itself to spread across networks?

a)

Trojan

b)

Worm

c)

Rootkit

d)

Spyware

32.

What is the primary goal of confidentiality in cybersecurity?

a)

Ensure system uptime

b)

Prevent unauthorized access to data

c)

Encrypt data after a breach

d)

Allow public access to systems

33.

Which one is an example of social engineering?

a)

Exploiting a software vulnerability

b)

Guessing a password using brute force

c)

Tricking a user into revealing their password

d)

Installing a firewall

34.

What should a company do if an employee receives a suspicious link in an email?

a)

Click the link to investigate

b)

Delete it immediately

c)

Report it to IT/security team and avoid clicking

d)

Reply asking for clarification

35.

Which scenario best applies the principle of least privilege?

a)

Giving admin access to all users

b)

Allowing access only to the data needed for a specific role

c)

Sharing all passwords with the team

d)

Disabling all security controls

36.

Which is the best practice to prevent brute-force attacks on login portals?

a)

Allow unlimited login attempts

b)

Use single-factor authentication only

c)

Implement account lockout after failed attempts and use CAPTCHA

d)

Avoid passwords altogether

37.

A company wants to prevent both internal and external unauthorized access. What layered approach should they use?

a)

Only use antivirus

b)

Use firewalls, access controls, monitoring, and employee training

c)

Disable internet access

d)

Block all outbound traffic

38.

During a cybersecurity audit, inconsistent data logs are discovered. What does this most likely indicate?

a)

Good data encryption

b)

Data breach or log tampering

c)

Redundant backups

d)

System uptime

39.

A phishing campaign uses email subject lines tailored to a specific company's operations. This is an example of:

a)

Random spam

b)

Generic email spoofing

c)

Spear phishing

d)

Malware injection

40.

An attacker uses a compromised machine to launch attacks on others. What is this machine called?

a)

Worm

b)

Host

c)

Bot

d)

Payload