wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

COMSEC-FINALS

Total questions: 100

Worksheet time: 50mins

Name
Class
Date
1.

Which of the following best describes the main function of a firewall?

a)

It filters access to a protected network.

b)

It stores frequently used files for faster access.

c)

It provides internet connectivity to devices.

d)

It encrypts all outgoing emails.

2.

What is a proxy server primarily used for?

a)

Acting as a middleman between users and websites.

b)

Encrypting all network traffic.

c)

Generating random passwords for users.

d)

Managing user accounts on a network.

3.

Which of the following is NOT an objective of a firewall?

a)

Keep out intruders and unwanted traffic.

b)

Protect private information from leaking.

c)

Provide a secure boundary between networks.

d)

Increase internet speed for all users.

4.

Firewalls require both hardware and software to function. What is the role of software in a firewall?

a)

Filters and proxies that allow or block traffic.

b)

Physical devices that connect to the network.

c)

Cables that transmit data.

d)

Power supply for the firewall.

5.

Which of the following is a limitation of firewalls?

a)

They can't stop attacks that bypass the firewall.

b)

They can block unauthorized access.

c)

They monitor suspicious activity.

d)

They provide secure communication using IPsec.

6.

Why is it more practical to place a firewall at one central point in a network?

a)

It creates a single checkpoint where all traffic is controlled and monitored.

b)

It allows every device to have its own firewall.

c)

It increases the number of security policies.

d)

It eliminates the need for network passwords.

7.

Which of the following is NOT a use of proxy servers?

a)

Encrypting all emails sent from the network.

b)

Improving security by blocking harmful sites.

c)

Hiding location for private browsing.

d)

Saving bandwidth by caching files.

8.

Malware is best defined as:

a)

Software designed to harm or steal without the user's consent.

b)

A tool for improving network speed.

c)

A device that filters network traffic.

d)

A program for creating secure passwords.

9.

Which capability does a firewall provide to a network?

a)

Blocks unauthorized access.

b)

Automatically repairs damaged files.

c)

Increases bandwidth for all users.

d)

Provides free antivirus software.

10.

What is a characteristic of all network traffic in relation to firewalls?

a)

All network traffic must pass through the firewall.

b)

All network traffic is encrypted by default.

c)

All network traffic is stored for future use.

d)

All network traffic is automatically compressed.

11.

A company wants to prevent employees from accessing certain websites. Which solution is most appropriate?

a)

Use proxy servers to control access.

b)

Increase the network bandwidth.

c)

Install more physical devices.

d)

Remove all firewalls from the network.

12.

Which of the following is a limitation of firewalls regarding internal threats?

a)

Firewalls do not protect against internal threats such as a malicious employee.

b)

Firewalls can block all viruses.

c)

Firewalls encrypt all internal communications.

d)

Firewalls automatically detect all suspicious emails.

13.

A network administrator wants to balance network traffic to avoid crashes. Which tool should they use?

a)

Proxy server

b)

Malware

c)

Firewall hardware only

d)

Antivirus software

14.

Which of the following is a design principle for firewalls in organizations?

a)

Place the firewall at one central point for all traffic.

b)

Install a firewall on every device separately.

c)

Use only software firewalls.

d)

Allow all traffic without monitoring.

15.

What is a possible effect of malware on a computer system?

a)

Slow down performance and steal sensitive data.

b)

Increase network speed.

c)

Block all unauthorized access.

d)

Encrypt all files for security.

16.

Which type of malware displays unwanted ads, pop-ups, or redirects and is often financially supported by companies advertising products?

a)

Adware

b)

Spyware

c)

Worms

d)

Trojan Horse

17.

What is the main function of spyware?

a)

Secretly steals information such as browsing history or banking details

b)

Changes browser settings

c)

Spreads automatically without user action

d)

Pretends to be useful software

18.

Which type of malware can change your browser settings and redirect you to malicious or unwanted websites?

a)

Browser Hijackers

b)

Virus

c)

Worms

d)

Scareware

19.

What is the correct order of the virus lifecycle stages?

a)

Dormant, Propagation, Triggering, Execution

b)

Propagation, Dormant, Execution, Triggering

c)

Execution, Dormant, Propagation, Triggering

d)

Triggering, Execution, Dormant, Propagation

20.

How do worms differ from viruses?

a)

Worms spread automatically without user action

b)

Worms require human action to activate

c)

Worms only display ads

d)

Worms steal banking information

21.

Which of the following is a sign of Trojan infection?

a)

Slower performance and frequent crashes

b)

Displaying unwanted ads

c)

Spreading through USB drives

d)

Changing browser settings

22.

Which type of Trojan locks your files until a ransom is paid?

a)

Ransomware Trojans

b)

DDoS Trojans

c)

Exploit Trojans

d)

Banking Trojans

23.

Scareware tricks users with fake warnings and may force them to download fake software or pay money. What is an example of scareware?

a)

Fake tech support pop-ups

b)

Keylogger

c)

Botnet

d)

USB virus

24.

A botnet is best described as:

a)

A group of hacked computers controlled by hackers

b)

A type of virus that spreads through emails

c)

A fake antivirus alert

d)

A browser redirect to unwanted sites

25.

Why is clicking "close" on a scareware pop-up potentially dangerous?

a)

It can secretly download malware

b)

It disables your antivirus

c)

It changes your browser settings

d)

It spreads through USB drives

26.

Which of the following is a key element for improving security according to the document?

a)

A flexible strategy that adapts to new risks

b)

Having only one security policy

c)

Ignoring new technologies

d)

Never updating procedures

27.

What is the main purpose of administrative security guidelines?

a)

To set rules based on strategy and policy

b)

To create encryption keys

c)

To monitor network traffic

d)

To design user interfaces

28.

Which prevention tool is used to find weaknesses like weak passwords and malware?

a)

Vulnerability analysis tools

b)

Antivirus software

c)

Firewalls

d)

One-time passwords (OTPs)

29.

Why is it important to use a website with 'https://' and a padlock icon for safe browsing?

a)

It protects personal information and credit card details

b)

It loads pages faster

c)

It allows access to more content

d)

It blocks advertisements

30.

Which of the following is NOT a recommended tip for buying online?

a)

Ignore privacy and share all your information

b)

Pay securely on https:// sites

c)

Check the product for warranty and compatibility

d)

Keep records of receipts and order forms

31.

What is the main reason for clearing your browser cache?

a)

To remove stored webpage data for faster loading

b)

To delete your browsing history

c)

To block pop-up ads

d)

To update your passwords

32.

Why should you be cautious when posting personal details on social networking sites?

a)

It can lead to identity theft, monitoring, or misuse

b)

It increases your popularity

c)

It improves your account security

d)

It makes your profile more attractive

33.

Which technological security tool isolates suspicious programs to prevent harm?

a)

Malware sandbox

b)

Firewall

c)

One-time password (OTP)

d)

Cryptography

34.

How can you enhance your safety on social networks according to the document?

a)

Use strong, regularly changed passwords

b)

Share your passwords with friends

c)

Post all your personal details publicly

d)

Never adjust privacy settings

35.

If you are planning an event to promote information security awareness, which strategy should you use?

a)

Strengthening promotion through a variety of events

b)

Ignoring employee training

c)

Disabling security software

d)

Posting all company data online

36.

Which of the following is a recommended practice when connecting with people online?

a)

Connect with everyone who sends you a request

b)

Only connect with people you know and trust

c)

Accept requests from strangers to expand your network

d)

Ignore privacy settings when adding contacts

37.

Why is it important to check your privacy settings on social media?

a)

To make your profile look attractive

b)

To control who sees your updates

c)

To increase the number of followers

d)

To automatically delete old posts

38.

What can happen if you post status updates carelessly on social media?

a)

You will get more likes

b)

You may lose your job

c)

Your account will be deleted

d)

You will receive free gifts

39.

Which information can social networks reveal through your online content?

a)

Your favorite color

b)

Your location via GPS or photo data

c)

Your password

d)

Your bank account number

40.

Why should you always get consent before posting photos or videos of others online?

a)

To avoid copyright issues

b)

To respect their privacy

c)

To increase your followers

d)

To make your posts more popular

41.

What is a safer way to communicate using instant chats?

a)

Use built-in chat features

b)

Use encrypted apps

c)

Share your password

d)

Post your messages publicly

42.

How can joining or creating online groups put you at risk?

a)

It makes you popular

b)

It reveals your interests and beliefs

c)

It increases your followers

d)

It improves your computer security

43.

A worker lost their job because of a post about their employer. What does this example illustrate about social media use?

a)

Social media posts are always private

b)

Posts can be used against you

c)

Employers do not monitor social media

d)

Status updates are harmless

44.

If you want to share a photo online, what should you do to protect the privacy of others?

a)

Post it without asking anyone

b)

Always get consent from the people in the photo

c)

Edit the photo to remove everyone

d)

Only share it with your close friends

45.

Why might governments monitor your social media posts?

a)

To help you gain followers

b)

If your posts go against their stance

c)

To give you job opportunities

d)

To send you advertisements

46.

How can photos and videos shared online reveal hidden details?

a)

They only show what is visible

b)

They can reveal time, place, and camera info

c)

They erase all metadata automatically

d)

They are always anonymous

47.

What is a potential risk of joining political or sensitive groups online?

a)

You will get free merchandise

b)

You may be put at risk due to your association

c)

You will receive more friend requests

d)

Your account will be upgraded

48.

Why is it recommended to use encrypted apps for instant chats instead of built-in chat features?

a)

Encrypted apps are easier to use

b)

Built-in chat features are often insecure and easy to trace, while encrypted apps provide safer communication

c)

Encrypted apps are more popular

d)

Built-in chat features have better graphics

49.

Not checking location settings on photos could lead to which privacy issue?

a)

Your photo will look blurry

b)

Your exact location could be revealed to strangers, putting you at risk

c)

Your friends will not see your photo

d)

Your phone will run out of battery

50.

One risk of others assuming you agree with everything a group stands for when you join an online community is:

a)

It can lead to misunderstandings and may put you at risk if the group is political or sensitive

b)

It will make you more popular

c)

It will increase your job opportunities

d)

It will improve your computer security

51.

Which of the following is considered "Illegal Access" under cybercrime law?

a)

Accessing a computer without permission

b)

Accessing a computer with permission

c)

Creating a backup of your own data

d)

Using a computer for gaming

52.

What is the penalty range for "Hacking/Data Crimes" according to the cybercrime law?

a)

6–12 years or fine ₱200k+

b)

1–6 months or fine ₱50k+

c)

20–40 years or fine ₱1M+

d)

12–20 years or fine ₱500k+

53.

Which act involves secretly listening or recording private data transmissions?

a)

Illegal Interception

b)

Data Interference

c)

System Interference

d)

Forgery

54.

If a crime is committed using technology, how does the penalty change?

a)

Punishment is heavier

b)

Punishment is lighter

c)

No change in punishment

d)

Punishment is removed

55.

Which of the following is NOT a computer-related offense under cybercrime law?

a)

Libel

b)

Forgery

c)

Fraud

d)

Identity Theft

56.

A company can be fined up to how much if crimes are committed on their behalf?

a)

₱10M

b)

₱1M

c)

₱500k

d)

₱250k

57.

What is the main purpose of the State in recognizing the role of ICT in national development?

a)

To create an environment for safe ICT use and protect systems, networks, and data

b)

To ban the use of computers in business

c)

To encourage illegal access to data

d)

To promote only entertainment uses of ICT

58.

Which offense involves registering a domain name in bad faith to profit, mislead, or damage others?

a)

Cyber-squatting

b)

Identity Theft

c)

Libel

d)

Forgery

59.

What must service providers do according to Sec. 13 of the cybercrime law?

a)

Preserve data for 6 months (extendable)

b)

Delete all user data immediately

c)

Share data without a court order

d)

Encrypt all data transmissions

60.

Which of the following is an example of a content-related offense?

a)

Cybersex

b)

Illegal Interception

c)

System Interference

d)

Forgery

61.

Why is aiding or abetting someone in committing cybercrime punishable?

a)

Because even helping or attempting cybercrime is illegal

b)

Because only the main offender is punished

c)

Because it is not considered a crime

d)

Because it is allowed under cybercrime law

62.

Which of the following requires a court order according to Sec. 12 of the cybercrime law?

a)

Accessing data content

b)

Accessing traffic data (origin, time, size)

c)

Accessing public websites

d)

Accessing social media profiles

63.

According to Sec. 17, what must happen to data after the case or period ends?

a)

Data must be archived for future reference.

b)

Data must be destroyed.

c)

Data must be published online.

d)

Data must be transferred to another agency.

64.

What is the consequence for evidence collected without a warrant, as stated in Sec. 18?

a)

It is admissible in court.

b)

It is considered valid.

c)

It is inadmissible.

d)

It is automatically destroyed.

65.

Which government agency may block illegal content or sites according to Sec. 19?

a)

Department of Education (DepEd)

b)

Department of Justice (DOJ)

c)

Department of Health (DOH)

d)

Department of Finance (DOF)

66.

What is the penalty for non-compliance as stated in Sec. 20?

a)

1 month imprisonment or ₱10k fine

b)

6 months–6 years imprisonment or ₱100k fine

c)

10 years imprisonment or ₱1M fine

d)

No penalty

67.

Law enforcers can collect, preserve, and analyze data, but what must they follow to ensure evidence is valid?

a)

Their own procedures

b)

Court orders

c)

Public opinion

d)

Media guidelines

68.

What is the yearly budget allocated for implementation according to Sec. 27?

a)

₱10M

b)

₱100M

c)

₱50M

d)

₱1M

69.

Which agencies are responsible for making implementing rules within 90 days as per Sec. 28?

a)

DOJ, DOST-ICTO, DILG

b)

DOH, DepEd, DOF

c)

DTI, DA, DENR

d)

NBI, PNP, AFP

70.

(DoK Level 2) Why is it important for law enforcers to follow court orders when collecting, preserving, and analyzing data?

a)

To ensure evidence is legal and valid in court

b)

To speed up investigations

c)

To avoid paperwork

d)

To increase public awareness

71.

(DoK Level 2) How does the allocation of a yearly budget (Sec. 27) contribute to the proper implementation of the law?

a)

It allows for regular training of law enforcers

b)

It ensures there are sufficient resources for enforcement

c)

It increases the number of cases prosecuted

d)

It reduces the need for government oversight

72.

(DoK Level 3) If the DOJ fails to block illegal content/sites as stated in Sec. 19, what potential risks could arise for computer security and information assurance?

a)

Increased access to illegal content and cyber threats

b)

Improved internet speed

c)

Reduced government spending

d)

Enhanced privacy for users

73.

(DoK Level 3) Imagine a scenario where evidence is collected without a warrant and used in court. What could be the legal and ethical implications based on Sec. 18?

a)

The evidence would be inadmissible, potentially leading to dismissal of the case and violation of rights

b)

The evidence would strengthen the prosecution’s case

c)

The evidence would be ignored by the judge

d)

The evidence would be used for public awareness campaigns

74.

Which Republic Act is known as the Data Privacy Act of 2012 in the Philippines?

a)

Republic Act No. 10173

b)

Republic Act No. 9003

c)

Republic Act No. 9165

d)

Republic Act No. 8792

75.

According to the Data Privacy Act, what is the main reason the state protects privacy and communication?

a)

To ensure free flow of information and promote innovation and growth

b)

To restrict access to information

c)

To encourage data breaches

d)

To eliminate communication between citizens

76.

Which of the following is NOT a general data privacy principle under the Data Privacy Act?

a)

Data must be kept longer than needed

b)

Data must be collected for a clear purpose

c)

Data must be processed fairly and lawfully

d)

Data must be accurate and updated

77.

Under what condition can journalists be forced to reveal confidential sources according to the Data Privacy Act?

a)

They cannot be forced to reveal confidential sources

b)

If the government requests it

c)

If the information is about public safety

d)

If the source is a criminal

78.

Which of the following is a criterion for lawful processing of personal data?

a)

With consent

b)

Without any reason

c)

Only for entertainment

d)

For personal curiosity

79.

If a company outsources data processing, who is responsible for ensuring safeguards?

a)

The main controller

b)

The subcontractor only

c)

The government

d)

The data subject

80.

Which right allows you to correct errors in your personal data?

a)

Rights of the Data Subject

b)

Right to Data Portability

c)

Non-Applicability

d)

Security Measures

81.

What can heirs do after the data subject’s death or incapacity according to the Data Privacy Act?

a)

Invoke rights over the data

b)

Delete all data immediately

c)

Sell the data to third parties

d)

Ignore the data

82.

Which section of the Data Privacy Act allows you to get a copy of your data in electronic format for reuse?

a)

Right to Data Portability

b)

Security Measures

c)

Subcontracting Personal Information

d)

Protection for Journalists

83.

Rights under the Data Privacy Act do NOT apply if data is used only for which of the following?

a)

Research or investigations

b)

Commercial purposes

c)

Marketing

d)

Social media sharing

84.

What is one organizational safeguard that companies must implement to protect personal information?

a)

Have a security policy

b)

Ignore breaches

c)

Share passwords

d)

Allow unauthorized access

85.

If a breach happens, what must companies do according to the Data Privacy Act?

a)

Notify the Commission and affected people

b)

Hide the breach from everyone

c)

Delete all data immediately

d)

Ignore the incident

86.

A company stores personal data longer than necessary. Which principle of the Data Privacy Act is being violated?

a)

Data should be kept only as long as needed

b)

Data should be processed fairly

c)

Data should be accurate

d)

Data should be stored in a way that protects identity

87.

Why is it important for data controllers to monitor for breaches?

a)

To detect unauthorized access and prevent misuse

b)

To allow more data leaks

c)

To avoid following the law

d)

To increase data collection

88.

How does the Data Privacy Act protect journalists and their sources?

a)

Journalists are protected and do not have to reveal their news sources

b)

Journalists must always reveal their sources

c)

Journalists can only protect sources in criminal cases

d)

Journalists are not mentioned in the Act

89.

Which of the following is a responsibility of controllers under the Accountability Principle in computer security?

a)

They must ensure all employees have encryption software.

b)

They are responsible for all personal data under them, even if outsourced.

c)

They must dispose of data every year.

d)

They are required to create new data protection laws.

90.

What is required for whoever collects data according to the Accountability Principle?

a)

Must have a data protection officer (DPO).

b)

Must encrypt all data immediately.

c)

Must share data with contractors.

d)

Must delete data after one year.

91.

Which of the following is NOT a requirement for government handling of sensitive data?

a)

Employees need clearance for access.

b)

Only 1,000 records can be accessed at a time for off-site use.

c)

Off-site access must use encryption.

d)

All data must be made public.

92.

Why must government agencies apply strict security, clearance, and encryption rules to contractors?

a)

To ensure contractors can access all data freely.

b)

To maintain the same level of data protection as within the agency.

c)

To allow contractors to bypass security protocols.

d)

To reduce the cost of data management.

93.

What is the penalty for unauthorized processing of sensitive data?

a)

1–3 years imprisonment + ₱500k–₱2M fine

b)

3–6 years imprisonment + ₱500k–₱4M fine

c)

6 months–2 years imprisonment + ₱100k–₱500k fine

d)

1–5 years imprisonment + ₱500k–₱1M fine

94.

Which act carries a higher penalty if the data involved is sensitive?

a)

Negligent access

b)

Unauthorized purpose use

c)

Improper disposal

d)

All of the above

95.

If a public official is found guilty of a crime under these provisions, what is one possible consequence?

a)

They are promoted to a higher office.

b)

They are disqualified from office if guilty.

c)

They receive a bonus.

d)

They are given more data access.

96.

What happens if a crime affects more than 100 people?

a)

The penalty is reduced.

b)

The maximum penalty is applied.

c)

The crime is ignored.

d)

Only a warning is given.

97.

Strategic Thinking: What penalties might apply if a contractor fails to comply with government data protection standards and unauthorized access occurs, and why would the punishment be heavier if sensitive data is involved?

a)

Penalties could include fines and imprisonment, with heavier punishment for sensitive data due to increased risk and impact.

b)

Only a warning would be issued, regardless of data sensitivity.

c)

The contractor would be promoted for honesty.

d)

No penalties would apply if the contractor was unaware of the rules.

98.

Skill/Concept: Why is encryption required for off-site access to government data?

a)

To make data easier to share with the public.

b)

To protect sensitive information from unauthorized access.

c)

To reduce the cost of data storage.

d)

To allow employees to access data without clearance.

99.

What is the first step in creating an information security policy?

a)

Conducting a penetration test

b)

Setting a budget

c)

Creating an organization

d)

Information gathering

100.

Which of the following is NOT typically collected during information gathering from other countries?

a)

Security organizations and their operations

b)

Policies, laws, and regulations

c)

International methodologies and best practices

d)

Personal financial records