wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Network Security Quiz

Total questions: 98

Worksheet time: 49mins

Name
Class
Date
1.

Which of the following is the best way to secure a LAN (Local Area Network)?

a)

Increase external access

b)

Minimize external access

c)

Allow all incoming traffic

d)

Disable firewalls

2.

What is the primary function of a firewall in a network?

a)

To increase network speed

b)

To filter access to a protected network

c)

To store frequently used files

d)

To bypass security rules

3.

Which of the following is NOT a use of proxy servers?

a)

Improve security by blocking harmful sites

b)

Hide location for private browsing

c)

Increase malware on the network

d)

Save bandwidth by caching files

4.

Firewalls need both hardware and software to work. What does the hardware component refer to?

a)

Filters and proxies

b)

Physical devices

c)

Network traffic

d)

Security policies

5.

Which of the following is a limitation of firewalls?

a)

They block unauthorized access

b)

They can’t stop attacks that bypass the firewall

c)

They monitor suspicious activity

d)

They provide secure communication using IPsec

6.

What is the main objective of a firewall?

a)

To allow all traffic through the network

b)

To keep out intruders, malicious code, and unwanted traffic

c)

To slow down network performance

d)

To store user passwords

7.

Which of the following is a capability of firewalls?

a)

Allow risky services

b)

Block unauthorized access

c)

Ignore suspicious activity

d)

Disable secure communication

8.

Why might an organization place a firewall at one central point rather than protecting each device separately?

a)

It is less practical

b)

It creates a single checkpoint for monitoring all traffic

c)

It increases the risk of attacks

d)

It slows down the network

9.

Which of the following best describes malware?

a)

Software designed to improve network speed

b)

Software designed to harm or steal without the user’s consent

c)

Software that filters network traffic

d)

Software that blocks unauthorized access

10.

How do proxy servers help balance network traffic?

a)

By allowing all traffic through

b)

By avoiding crashes

c)

By blocking all websites

d)

By disabling firewalls

11.

Which of the following is NOT a characteristic of firewalls?

a)

All network traffic must pass through the firewall

b)

Only traffic that follows security rules is allowed

c)

Firewalls themselves must be weak and insecure

d)

Different types of firewalls can be configured for different security policies

12.

A proxy server acts as an intermediary between:

a)

The firewall and the internet

b)

The user and the websites they visit

c)

The hardware and the software

d)

The LAN and the WAN

13.

Which of the following is a strategic reason for using a firewall perimeter in a network?

a)

To protect each device separately

b)

To create a security boundary between the local network and the internet

c)

To allow all traffic without monitoring

d)

To disable all security policies

14.

What is one function that firewalls can provide in addition to blocking unauthorized access?

a)

Increase malware

b)

Provide extra internet functions like IPsec for secure communication

c)

Allow risky services

d)

Ignore suspicious activity

15.

Which of the following is NOT a limitation of firewalls?

a)

Can’t stop attacks that bypass the firewall

b)

Doesn’t protect against internal threats

c)

Can scan every file for viruses

d)

Some infected files may still pass through

16.

Which type of malware displays unwanted ads, pop-ups, or redirects and is often financially supported by companies advertising products?

a)

Adware

b)

Spyware

c)

Worms

d)

Trojan Horse

17.

What is the main function of spyware?

a)

Secretly steals information like browsing history or banking details

b)

Changes your browser settings

c)

Spreads automatically without user action

d)

Pretends to be useful software but is actually harmful

18.

Which type of malware can change your browser settings and redirect you to malicious or unwanted websites?

a)

Browser Hijackers

b)

Virus

c)

Worms

d)

Scareware

19.

What is the correct order of the virus lifecycle stages?

a)

Dormant, Propagation, Triggering, Execution

b)

Propagation, Dormant, Execution, Triggering

c)

Execution, Triggering, Dormant, Propagation

d)

Triggering, Execution, Propagation, Dormant

20.

How do worms differ from viruses?

a)

Worms spread automatically without user action, while viruses need human action to activate

b)

Worms only display ads, while viruses steal information

c)

Worms are always harmless, while viruses are harmful

d)

Worms can only infect browsers, while viruses infect files

21.

Which of the following is a sign of Trojan infection?

a)

Slower performance and frequent crashes

b)

Increased battery life

c)

Faster internet speed

d)

Improved system security

22.

Which type of Trojan locks your files until a ransom is paid?

a)

Ransomware Trojans

b)

DDoS Trojans

c)

Exploit Trojans

d)

Banking Trojans

23.

Scareware tricks users with fake warnings and forces them to do what?

a)

Download fake software or pay money

b)

Update their browser

c)

Change their password

d)

Buy new hardware

24.

A Trojan horse can make your PC part of a botnet by:

a)

Creating a backdoor for hackers, allowing them to control your system and connect it to a botnet.

b)

Only displaying ads, resulting in faster internet speed.

c)

Improving system security, leading to more pop-ups.

d)

Disabling antivirus, causing increased battery life.

25.

Which statement best compares the activation methods of viruses and worms?

a)

Viruses require human action to activate, such as clicking a file, while worms spread automatically without user action.

b)

Both viruses and worms require human action to activate.

c)

Worms require clicking a file, while viruses spread automatically.

d)

Viruses and worms both only infect browsers.

26.

Which of the following is a key element for improving security according to the document?

a)

A flexible strategy that adapts to new risks

b)

A single, unchanging policy

c)

Ignoring new technologies

d)

Minimal vigilance

27.

What is the main purpose of administrative security guidelines?

a)

To set rules based on strategy and policy

b)

To provide technical details for security

c)

To ignore government regulations

d)

To focus only on short-term security

28.

Which prevention tool is used to find weaknesses like weak passwords and malware?

a)

Vulnerability analysis tools

b)

Antivirus software

c)

Firewalls

d)

Malware sandbox

29.

Why is it important to use https:// and a padlock icon when browsing?

a)

It protects personal information and credit card details

b)

It makes the website load faster

c)

It allows access to more content

d)

It disables advertisements

30.

When buying online, why should you check the full cost?

a)

To consider taxes, shipping, and conversion fees

b)

To get a discount

c)

To avoid reading terms and conditions

d)

To skip warranty information

31.

What is a risk of sharing too much personal information on social networking sites?

a)

Identity theft, monitoring, or misuse

b)

Faster internet speed

c)

Better privacy protection

d)

More friends online

32.

Which of the following is a recommended safety tip for social networks?

a)

Use strong, regularly changed passwords

b)

Share your passwords with friends

c)

Never change your privacy settings

d)

Post all your personal details online

33.

Why is ongoing vigilance important in security?

a)

Because security threats are always changing

b)

Because policies never change

c)

Because technology is always outdated

d)

Because guidelines are unnecessary

34.

If you are using a public computer, what should you do to protect your information?

a)

Clear your history and passwords

b)

Leave your accounts logged in

c)

Share your passwords with others

d)

Ignore privacy settings

35.

Which of the following is a recommended practice when connecting with people online?

a)

Only connect with people you know and trust.

b)

Connect with as many people as possible.

c)

Accept all friend requests without checking.

d)

Share personal information with strangers.

36.

Why is it important to check your privacy settings on social media?

a)

To control who sees your updates.

b)

To increase the number of followers.

c)

To make your profile public.

d)

To automatically delete old posts.

37.

What can social networks reveal about you when you share online content?

a)

Your location via GPS or photo data.

b)

Your favorite color.

c)

Your bank account number.

d)

Your school grades.

38.

Why should you always get consent before posting photos or videos of others online?

a)

To respect their privacy and rights.

b)

To increase your popularity.

c)

To avoid losing followers.

d)

To make your posts more interesting.

39.

Which type of app is recommended for safer communication in instant chats?

a)

Encrypted apps

b)

Free apps

c)

Social media apps

d)

Gaming apps

40.

What is a potential risk of joining or creating online groups and communities?

a)

Revealing your interests and beliefs.

b)

Getting more likes on your posts.

c)

Receiving free gifts.

d)

Automatically becoming an admin.

41.

A worker lost their job because of a post about their employer. What does this example illustrate about posting status updates online?

a)

Posts can be used against you.

b)

Posts always help you get a job.

c)

Posts are always private.

d)

Posts cannot affect your career.

42.

Sharing photos or videos online can reveal which of the following hidden details about you?

a)

Time and place information, camera info

b)

Your favorite food and music

c)

Your password and username

d)

Your shopping history and bank balance

43.

The risks of using insecure instant chat features can be reduced by:

a)

Using encrypted apps to improve security.

b)

Using more emojis to improve security.

c)

Using free apps to improve security.

d)

Using faster internet to improve security.

44.

Joining political or sensitive groups online can put you at risk because:

a)

It can reveal your interests and beliefs, and others may assume you agree with everything the group stands for; consider privacy and potential consequences before joining.

b)

It can make you popular, and you should join as many groups as possible.

c)

It can help you get discounts, and you should share your personal information freely.

d)

It can increase your followers, and you should post frequently in these groups.

45.

Which of the following is considered "Illegal Access" under cybercrime law?

a)

Accessing a computer without permission

b)

Changing computer passwords with permission

c)

Sending unsolicited emails

d)

Registering a domain name for a business

46.

What is the penalty range for "Hacking/Data Crimes" according to the cybercrime law?

a)

6–12 years or fine ₱200k+

b)

1–6 months or fine ₱50k

c)

20–40 years or fine ₱1M

d)

12–20 years or fine ₱500k+

47.

Which offense involves secretly listening or recording private data transmissions?

a)

Illegal Interception

b)

Data Interference

c)

System Interference

d)

Identity Theft

48.

If a company’s employee commits a cybercrime, what is the maximum fine the company can face under corporate liability?

a)

₱10M

b)

₱1M

c)

₱500k

d)

₱200k

49.

Which of the following is NOT a computer-related offense under the cybercrime law?

a)

Forgery

b)

Fraud

c)

Identity Theft

d)

System Interference

50.

What is the penalty for child pornography committed using computers under RA 9775?

a)

Penalty under RA 9775 + 1 degree higher

b)

6–12 years or fine up to ₱500k

c)

1–6 months or fine ₱50k–₱250k

d)

12–20 years or fine ₱500k+

51.

Which of the following is an example of a content-related cybercrime offense?

a)

Cybersex

b)

Data Interference

c)

Fraud

d)

Illegal Interception

52.

What must service providers do with data according to Sec. 13 of the cybercrime law?

a)

Preserve data for 6 months (extendable)

b)

Delete data immediately

c)

Share data without a warrant

d)

Encrypt all data transmissions

53.

Which of the following is true about penalties for cybercrime when ICT is used?

a)

Penalties are usually 1 degree higher

b)

Penalties are always 1 degree lower

c)

Penalties do not change

d)

Penalties are only fines, not imprisonment

54.

Why does the State recognize the vital role of ICT in national development?

a)

It supports telecom, e-commerce, and data processing

b)

It increases unemployment

c)

It reduces the need for education

d)

It encourages illegal activities

55.

A student is planning to register a domain name similar to a popular brand to mislead users. Which cybercrime offense does this act fall under?

a)

Cyber-squatting

b)

Identity Theft

c)

Fraud

d)

System Interference

56.

If authorities need to collect traffic data (origin, time, size) but not content, what is required according to Sec. 12?

a)

No warrant is needed

b)

A court order is required

c)

Data must be deleted

d)

Data must be encrypted

57.

Which of the following is a strategic way to prevent cybercrime in organizations?

a)

Creating an environment for safe ICT use and protecting systems, networks, and data

b)

Ignoring security updates

c)

Allowing unrestricted access to all data

d)

Sharing passwords with colleagues

58.

A company is found guilty of aiding and abetting cybercrime. What is true about the liability of individuals involved?

a)

Individuals are still liable even if the company is fined

b)

Individuals are not liable if the company is fined

c)

Only the company is punished

d)

No one is punished

59.

If a person attempts but fails to commit a cybercrime, what is the legal consequence?

a)

Attempting is still punishable

b)

No penalty is given

c)

Only a warning is issued

d)

The person is rewarded

60.

According to Sec. 17, what must happen to data after the case or period ends?

a)

Data must be archived for future reference.

b)

Data must be destroyed.

c)

Data must be transferred to another agency.

d)

Data must be published online.

61.

What does Sec. 18 state about evidence obtained without a warrant?

a)

It is admissible in court.

b)

It is inadmissible.

c)

It can be used for investigation only.

d)

It must be destroyed immediately.

62.

Which authority may block illegal content or sites according to Sec. 19?

a)

Department of Education (DepEd)

b)

Department of Justice (DOJ)

c)

Department of Health (DOH)

d)

Department of Finance (DOF)

63.

What is the penalty for non-compliance as stated in Sec. 20?

a)

1 year imprisonment or P50k fine

b)

6 months–6 years imprisonment or P100k fine

c)

10 years imprisonment or P500k fine

d)

3 months imprisonment or P10k fine

64.

Law enforcers can collect, preserve, and analyze data, but what must they follow to ensure evidence is valid?

a)

Agency guidelines

b)

Court orders

c)

Personal judgment

d)

Public opinion

65.

What is the yearly budget allocated for implementation according to Sec. 27?

a)

P10M

b)

P100M

c)

P50M

d)

P500M

66.

Which agencies are responsible for making implementing rules within 90 days as per Sec. 28?

a)

DOJ, DOST-ICTO, DILG

b)

DOH, DepEd, DOF

c)

DTI, DA, DENR

d)

DFA, DOT, DSWD

67.

Why is it important for government funds and agencies to ensure the law is properly implemented?

a)

To increase public awareness

b)

To ensure compliance and effectiveness of the law

c)

To reduce government spending

d)

To promote international relations

68.

Which law is discussed in Lesson 9 of the provided material?

a)

Republic Act No. 10173 (Data Privacy Act of 2012)

b)

Republic Act No. 9003 (Ecological Solid Waste Management Act)

c)

Republic Act No. 9165 (Comprehensive Dangerous Drugs Act)

d)

Republic Act No. 8792 (E-Commerce Act)

69.

According to the Data Privacy Act, what does the government value alongside privacy rights?

a)

Information flow

b)

Economic growth

c)

Environmental protection

d)

Social equality

70.

Which of the following is NOT a general data privacy principle under Section 11?

a)

Data must be stored in a way that protects identity

b)

Data must be collected for a clear purpose

c)

Data must be shared with everyone

d)

Data must be accurate and updated

71.

Under Section 12, which of the following is a valid criterion for lawful processing of personal data?

a)

With consent

b)

For entertainment purposes

c)

Without any reason

d)

For personal curiosity

72.

Journalists are protected under the Data Privacy Act. What does this protection mean?

a)

Journalists do not have to reveal their news sources

b)

Journalists must share all confidential information

c)

Journalists are exempt from all laws

d)

Journalists cannot report on privacy issues

73.

If a company outsources data processing, who is responsible for ensuring safeguards?

a)

The main controller

b)

The subcontractor only

c)

The government

d)

The data subject

74.

Which right allows individuals to correct errors in their personal data?

a)

Right to data subject

b)

Right to portability

c)

Right to non-applicability

d)

Right to security

75.

What can heirs do after the data subject’s death or incapacity according to Section 17?

a)

Invoke rights over the data

b)

Delete all data

c)

Sell the data

d)

Ignore the data

76.

Which section allows you to download or transfer your data in a usable format?

a)

Section 18: Right to Data Portability

b)

Section 14: Subcontracting Personal Information

c)

Section 5: Protection for Journalists

d)

Section 20: Security Measures

77.

Rights under the Data Privacy Act do NOT apply if data is used only for which purpose?

a)

Research or investigations

b)

Marketing

c)

Personal use

d)

Social media sharing

78.

What is one organizational measure companies must take to secure personal information?

a)

Have a security policy

b)

Ignore breaches

c)

Share passwords

d)

Disable all security systems

79.

Why must companies notify the Commission and affected people?

a)

In case of breaches

b)

When hiring new staff

c)

When launching a product

d)

When updating their website

80.

(DoK Level 2) If a company stores personal data longer than needed, which data privacy principle is being violated?

a)

Data must be kept only as long as needed

b)

Data must be accurate and updated

c)

Data must be collected for a clear purpose

d)

Data must be stored in a way that protects identity

81.

(DoK Level 2) How can a data subject exercise control over their data according to Section 16?

a)

By knowing, accessing, correcting, deleting, blocking, and getting compensation if misused

b)

By ignoring all data requests

c)

By sharing data with everyone

d)

By refusing to use any technology

82.

(DoK Level 3) Imagine a scenario where a company fails to update personal data, resulting in outdated information being used. What right can the data subject exercise to address this issue?

a)

Block/remove outdated/false/illegal data

b)

Right to data portability

c)

Right to non-applicability

d)

Right to subcontracting

83.

(DoK Level 3) A hospital needs to process patient data during a national emergency. Which lawful processing criterion justifies this action?

a)

For national emergency, public safety, or authority functions

b)

For entertainment purposes

c)

For marketing campaigns

d)

For personal curiosity

84.

Who is responsible for all personal data under their control, even if the data is outsourced?

a)

Controllers

b)

Employees

c)

Contractors

d)

Aliens

85.

What must government agencies use when handling sensitive data?

a)

Industry-standard protection

b)

Basic password protection

c)

No protection required

d)

Physical locks only

86.

Which of the following is a requirement for off-site access to sensitive government data?

a)

Encryption must be used

b)

No encryption needed

c)

Physical access only

d)

Unlimited records can be accessed

87.

What is the maximum number of records that can be accessed at a time for off-site use according to the document?

a)

1,000

b)

10,000

c)

100

d)

5,000

88.

Which penalty applies to unauthorized processing of sensitive data?

a)

3-6 years imprisonment and ₱500k–₱4M fine

b)

6 months imprisonment and ₱100k fine

c)

1-3 years imprisonment and ₱500k–₱2M fine

d)

1-5 years imprisonment and ₱500k–₱1M fine

89.

If a public official is found guilty of a crime under these provisions, what is one possible consequence?

a)

Disqualification from office

b)

Promotion

c)

No penalty

d)

Transfer to another department

90.

Which of the following crimes carries the maximum penalty?

a)

Crimes affecting 100+ people

b)

Unauthorized access by a single person

c)

Negligent access

d)

Improper disposal

91.

A contractor wants to access sensitive government data off-site. What must they ensure according to the rules?

a)

They must comply with encryption and clearance requirements

b)

They can access without restrictions

c)

They only need verbal permission

d)

They do not need to comply with any rules

92.

What is the role of a Data Protection Officer (DPO) in an organization?

a)

To ensure compliance and accountability for data collection

b)

To process payroll

c)

To manage physical security

d)

To supervise marketing campaigns

93.

What is the first step in creating an information security policy?

a)

Conducting a penetration test

b)

Creating an organization

c)

Information gathering

d)

Allocating budget

94.

Which of the following is NOT typically collected during information gathering from other countries?

a)

Security organizations and their operations

b)

Policies, laws, and regulations

c)

International methodologies and best practices

d)

Personal financial records

95.

According to Sun Tzu’s principle in gap analysis, what should policymakers know?

a)

Only the strengths of their country

b)

Only the weaknesses of their country

c)

Both strengths and weaknesses of their country

d)

Only the laws of their country

96.

Which phase is NOT part of gap analysis?

a)

Assessing the country’s capabilities

b)

Identifying external threats

c)

Allocating budget

d)

Legislative inquiry

97.

Why is it important for policymakers to avoid duplicating structures in security organizations?

a)

It increases efficiency and reduces confusion

b)

It makes the system more complex

c)

It encourages more attacks

d)

It reduces the need for laws

98.

Which of the following is a key component of setting a policy framework for information security?

a)

Ignoring privacy protection

b)

Acquisition & Implementation

c)

Avoiding monitoring and assessment

d)

Focusing only on physical security