NEW
Font size
WorksheetsProfessional Ethics in Information Systems
Total questions: 40
Worksheet time: 20mins
What is the primary focus of professional ethics?
Technical skill development
Legal compliance only
Relationships and responsibilities to clients and society
Marketing and sales strategies
Which of the following is a general moral imperative under the ACM Code?
Increase software costs
Avoid harm to others
Promote software sales
Encourage software piracy
Which principle states that software engineers must act consistently with the public interest?
Principle 2: Client and Employer
Principle 4: Judgment
Principle 1: Public
Principle 6: Profession
If a software engineer discovers a serious security vulnerability, what is their ethical responsibility?
Sell the information to competitors
Keep it confidential forever
Disclose it to the appropriate persons or authorities
Post it on social media for awareness
A left-handed user tests a handwriting system and finds it unusable. What guideline was overlooked?
Avoiding intellectual property conflicts
Honoring confidentiality
Designing for real users
Prioritizing cost over safety
A developer is assigned to a high-risk AI system affecting public safety. How should ethical guidelines shape their decision-making?
Deliver the product as quickly as possible
Focus only on technical specifications
Evaluate safety, involve stakeholders, and delay if risks are unclear
Let clients make all decisions
A software engineer wants to report unethical conduct by their employer, but fears job loss. Which ethical principle should guide them?
Remain silent unless asked
Prioritize loyalty over integrity
Report significant violations if other methods are ineffective or dangerous
Delete all evidence for self-protection
What is the purpose of professional codes of ethics?
To increase company revenue
To provide ethical guidelines and support for professionals
To manage software updates
To promote political agendas
According to the ACM Code, programmers should:
Always follow client instructions regardless of ethics
Share personal passwords with coworkers
Respect the privacy of others
Avoid reporting software bugs
Who can be affected by a computer professional's work?
Only the client
Just coworkers
Only programmers
Clients and the general public
Which principle emphasizes lifelong learning for software engineers?
Principle 5: Management
Principle 8: Self
Principle 2: Client and Employer
Principle 7: Colleagues
A software engineer reviews a colleague's work and finds major issues. What is the best ethical action?
Keep it private to avoid conflict
Report it only if the colleague agrees
Provide a candid, objective, and documented review
Ignore the problem entirely
A manager assigns a project without considering an employee's experience. What ethical guideline does this violate?
Ensure fair wages
Prioritize company profit
Assign work based on qualifications and educational background
Encourage competition among staff
How should a professional respond to pressure from management to hide known security flaws in software?
Comply without question
Publicly release the flaws immediately
Refuse to comply and raise the issue ethically
Blame others in the team
What best demonstrates ethical leadership in software engineering?
Promoting one's own interest over team needs
Ignoring outdated software documentation
Encouraging ethical behavior, fair management, and transparent practices
Keeping technical standards secret from staff
Which of the following defines cybersecurity?
Designing gaming software
Protecting systems, networks, and data from digital attacks
Creating social media platforms
Developing hardware components
The CIA triad in cybersecurity stands for:
Control, Inspect, Authenticate
Confidentiality, Integrity, Availability
Confidentiality, Intrusion, Analysis
Control, Integration, Access
Which term describes software that secretly installs itself and can control a computer?
Firewall
Phishing
Malware
Encryption
If a user receives an email claiming to be from their bank but asking to verify login credentials, this is likely:
A firewall alert
A phishing attack
A malware installation
A DoS attack
Which action helps maintain system availability during an attack?
Deleting system logs
Using redundancy and backups
Disabling firewalls
Ignoring packet filtering
A company suffers repeated data corruption after a breach. As a cybersecurity analyst, what best combines integrity and availability protections?
Install encryption and delete backups
Deploy checksums for data integrity and redundant backup servers
Remove access controls and save logs
Swap out all software immediately
A hacker uses spoofed IP addresses in a DoS attack. To mitigate this, you might:
Allow all IP traffic
Implement packet-filtering and source validation
Share all logs publicly
Disable logging
What is a vulnerability?
An attack type
A weakness in a system that can be exploited
A security policy
A type of encryption
What does a firewall do?
Encrypts network traffic
Monitors and filters incoming/outgoing traffic based on rules
Detects phishing emails
Physically destroys storage media
Which actor is most likely to launch a hacktivist attack?
State-sponsored intelligence agency
Criminal organization
Activist group using hacking for social or political causes
Individual trying to steal data for personal gain
A denial-of-service (DoS) attack aims to:
Corrupt data silently
Prevent legitimate users from accessing services
Steal credentials via email
Modify firewall settings
During a vulnerability assessment, which step assesses network weaknesses?
Writing user manuals
Port scanning to find open services
Training staff on phishing
Encrypting backups
To protect against malware inserted via USB devices, a company should:
Block all USB ports
Allow unrestricted USB use
Install antivirus and restrict USB functionality
Disable all file scanning
A targeted phishing email bypasses traditional spam filters using employee-specific data. What defense best counters this?
Only use email text-based filters
Implement user training, multi-factor authentication, and behavior analytics
Disable email altogether
Block all attachments permanently
A network experiences IP spoofing and amplification attacks. What layered defense strategy should be used?
Only install antivirus
Combine packet filtering, ingress/egress filtering, and network monitoring
Remove all security controls
Only rely on user education
Which type of malware replicates itself to spread across networks?
Trojan
Worm
Rootkit
Spyware
What is the primary goal of confidentiality in cybersecurity?
Ensure system uptime
Prevent unauthorized access to data
Encrypt data after a breach
Allow public access to systems
Which one is an example of social engineering?
Exploiting a software vulnerability
Guessing a password using brute force
Tricking a user into revealing their password
Installing a firewall
What should a company do if an employee receives a suspicious link in an email?
Click the link to investigate
Delete it immediately
Report it to IT/security team and avoid clicking
Reply asking for clarification
Which scenario best applies the principle of least privilege?
Giving admin access to all users
Allowing access only to the data needed for a specific role
Sharing all passwords with the team
Disabling all security controls
Which is the best practice to prevent brute-force attacks on login portals?
Allow unlimited login attempts
Use single-factor authentication only
Implement account lockout after failed attempts and use CAPTCHA
Avoid passwords altogether
A company wants to prevent both internal and external unauthorized access. What layered approach should they use?
Only use antivirus
Use firewalls, access controls, monitoring, and employee training
Disable internet access
Block all outbound traffic
During a cybersecurity audit, inconsistent data logs are discovered. What does this most likely indicate?
Good data encryption
Data breach or log tampering
Redundant backups
System uptime
A phishing campaign uses email subject lines tailored to a specific company's operations. This is an example of:
Random spam
Generic email spoofing
Spear phishing
Malware injection
An attacker uses a compromised machine to launch attacks on others. What is this machine called?
Worm
Host
Bot
Payload
