WorksheetsNetwork Security Quiz
Total questions: 98
Worksheet time: 49mins
Which of the following is the best way to secure a LAN (Local Area Network)?
Increase external access
Minimize external access
Allow all incoming traffic
Disable firewalls
What is the primary function of a firewall in a network?
To increase network speed
To filter access to a protected network
To store frequently used files
To bypass security rules
Which of the following is NOT a use of proxy servers?
Improve security by blocking harmful sites
Hide location for private browsing
Increase malware on the network
Save bandwidth by caching files
Firewalls need both hardware and software to work. What does the hardware component refer to?
Filters and proxies
Physical devices
Network traffic
Security policies
Which of the following is a limitation of firewalls?
They block unauthorized access
They can’t stop attacks that bypass the firewall
They monitor suspicious activity
They provide secure communication using IPsec
What is the main objective of a firewall?
To allow all traffic through the network
To keep out intruders, malicious code, and unwanted traffic
To slow down network performance
To store user passwords
Which of the following is a capability of firewalls?
Allow risky services
Block unauthorized access
Ignore suspicious activity
Disable secure communication
Why might an organization place a firewall at one central point rather than protecting each device separately?
It is less practical
It creates a single checkpoint for monitoring all traffic
It increases the risk of attacks
It slows down the network
Which of the following best describes malware?
Software designed to improve network speed
Software designed to harm or steal without the user’s consent
Software that filters network traffic
Software that blocks unauthorized access
How do proxy servers help balance network traffic?
By allowing all traffic through
By avoiding crashes
By blocking all websites
By disabling firewalls
Which of the following is NOT a characteristic of firewalls?
All network traffic must pass through the firewall
Only traffic that follows security rules is allowed
Firewalls themselves must be weak and insecure
Different types of firewalls can be configured for different security policies
A proxy server acts as an intermediary between:
The firewall and the internet
The user and the websites they visit
The hardware and the software
The LAN and the WAN
Which of the following is a strategic reason for using a firewall perimeter in a network?
To protect each device separately
To create a security boundary between the local network and the internet
To allow all traffic without monitoring
To disable all security policies
What is one function that firewalls can provide in addition to blocking unauthorized access?
Increase malware
Provide extra internet functions like IPsec for secure communication
Allow risky services
Ignore suspicious activity
Which of the following is NOT a limitation of firewalls?
Can’t stop attacks that bypass the firewall
Doesn’t protect against internal threats
Can scan every file for viruses
Some infected files may still pass through
Which type of malware displays unwanted ads, pop-ups, or redirects and is often financially supported by companies advertising products?
Adware
Spyware
Worms
Trojan Horse
What is the main function of spyware?
Secretly steals information like browsing history or banking details
Changes your browser settings
Spreads automatically without user action
Pretends to be useful software but is actually harmful
Which type of malware can change your browser settings and redirect you to malicious or unwanted websites?
Browser Hijackers
Virus
Worms
Scareware
What is the correct order of the virus lifecycle stages?
Dormant, Propagation, Triggering, Execution
Propagation, Dormant, Execution, Triggering
Execution, Triggering, Dormant, Propagation
Triggering, Execution, Propagation, Dormant
How do worms differ from viruses?
Worms spread automatically without user action, while viruses need human action to activate
Worms only display ads, while viruses steal information
Worms are always harmless, while viruses are harmful
Worms can only infect browsers, while viruses infect files
Which of the following is a sign of Trojan infection?
Slower performance and frequent crashes
Increased battery life
Faster internet speed
Improved system security
Which type of Trojan locks your files until a ransom is paid?
Ransomware Trojans
DDoS Trojans
Exploit Trojans
Banking Trojans
Scareware tricks users with fake warnings and forces them to do what?
Download fake software or pay money
Update their browser
Change their password
Buy new hardware
A Trojan horse can make your PC part of a botnet by:
Creating a backdoor for hackers, allowing them to control your system and connect it to a botnet.
Only displaying ads, resulting in faster internet speed.
Improving system security, leading to more pop-ups.
Disabling antivirus, causing increased battery life.
Which statement best compares the activation methods of viruses and worms?
Viruses require human action to activate, such as clicking a file, while worms spread automatically without user action.
Both viruses and worms require human action to activate.
Worms require clicking a file, while viruses spread automatically.
Viruses and worms both only infect browsers.
Which of the following is a key element for improving security according to the document?
A flexible strategy that adapts to new risks
A single, unchanging policy
Ignoring new technologies
Minimal vigilance
What is the main purpose of administrative security guidelines?
To set rules based on strategy and policy
To provide technical details for security
To ignore government regulations
To focus only on short-term security
Which prevention tool is used to find weaknesses like weak passwords and malware?
Vulnerability analysis tools
Antivirus software
Firewalls
Malware sandbox
Why is it important to use https:// and a padlock icon when browsing?
It protects personal information and credit card details
It makes the website load faster
It allows access to more content
It disables advertisements
When buying online, why should you check the full cost?
To consider taxes, shipping, and conversion fees
To get a discount
To avoid reading terms and conditions
To skip warranty information
What is a risk of sharing too much personal information on social networking sites?
Identity theft, monitoring, or misuse
Faster internet speed
Better privacy protection
More friends online
Which of the following is a recommended safety tip for social networks?
Use strong, regularly changed passwords
Share your passwords with friends
Never change your privacy settings
Post all your personal details online
Why is ongoing vigilance important in security?
Because security threats are always changing
Because policies never change
Because technology is always outdated
Because guidelines are unnecessary
If you are using a public computer, what should you do to protect your information?
Clear your history and passwords
Leave your accounts logged in
Share your passwords with others
Ignore privacy settings
Which of the following is a recommended practice when connecting with people online?
Only connect with people you know and trust.
Connect with as many people as possible.
Accept all friend requests without checking.
Share personal information with strangers.
Why is it important to check your privacy settings on social media?
To control who sees your updates.
To increase the number of followers.
To make your profile public.
To automatically delete old posts.
What can social networks reveal about you when you share online content?
Your location via GPS or photo data.
Your favorite color.
Your bank account number.
Your school grades.
Why should you always get consent before posting photos or videos of others online?
To respect their privacy and rights.
To increase your popularity.
To avoid losing followers.
To make your posts more interesting.
Which type of app is recommended for safer communication in instant chats?
Encrypted apps
Free apps
Social media apps
Gaming apps
What is a potential risk of joining or creating online groups and communities?
Revealing your interests and beliefs.
Getting more likes on your posts.
Receiving free gifts.
Automatically becoming an admin.
A worker lost their job because of a post about their employer. What does this example illustrate about posting status updates online?
Posts can be used against you.
Posts always help you get a job.
Posts are always private.
Posts cannot affect your career.
Sharing photos or videos online can reveal which of the following hidden details about you?
Time and place information, camera info
Your favorite food and music
Your password and username
Your shopping history and bank balance
The risks of using insecure instant chat features can be reduced by:
Using encrypted apps to improve security.
Using more emojis to improve security.
Using free apps to improve security.
Using faster internet to improve security.
Joining political or sensitive groups online can put you at risk because:
It can reveal your interests and beliefs, and others may assume you agree with everything the group stands for; consider privacy and potential consequences before joining.
It can make you popular, and you should join as many groups as possible.
It can help you get discounts, and you should share your personal information freely.
It can increase your followers, and you should post frequently in these groups.
Which of the following is considered "Illegal Access" under cybercrime law?
Accessing a computer without permission
Changing computer passwords with permission
Sending unsolicited emails
Registering a domain name for a business
What is the penalty range for "Hacking/Data Crimes" according to the cybercrime law?
6–12 years or fine ₱200k+
1–6 months or fine ₱50k
20–40 years or fine ₱1M
12–20 years or fine ₱500k+
Which offense involves secretly listening or recording private data transmissions?
Illegal Interception
Data Interference
System Interference
Identity Theft
If a company’s employee commits a cybercrime, what is the maximum fine the company can face under corporate liability?
₱10M
₱1M
₱500k
₱200k
Which of the following is NOT a computer-related offense under the cybercrime law?
Forgery
Fraud
Identity Theft
System Interference
What is the penalty for child pornography committed using computers under RA 9775?
Penalty under RA 9775 + 1 degree higher
6–12 years or fine up to ₱500k
1–6 months or fine ₱50k–₱250k
12–20 years or fine ₱500k+
Which of the following is an example of a content-related cybercrime offense?
Cybersex
Data Interference
Fraud
Illegal Interception
What must service providers do with data according to Sec. 13 of the cybercrime law?
Preserve data for 6 months (extendable)
Delete data immediately
Share data without a warrant
Encrypt all data transmissions
Which of the following is true about penalties for cybercrime when ICT is used?
Penalties are usually 1 degree higher
Penalties are always 1 degree lower
Penalties do not change
Penalties are only fines, not imprisonment
Why does the State recognize the vital role of ICT in national development?
It supports telecom, e-commerce, and data processing
It increases unemployment
It reduces the need for education
It encourages illegal activities
A student is planning to register a domain name similar to a popular brand to mislead users. Which cybercrime offense does this act fall under?
Cyber-squatting
Identity Theft
Fraud
System Interference
If authorities need to collect traffic data (origin, time, size) but not content, what is required according to Sec. 12?
No warrant is needed
A court order is required
Data must be deleted
Data must be encrypted
Which of the following is a strategic way to prevent cybercrime in organizations?
Creating an environment for safe ICT use and protecting systems, networks, and data
Ignoring security updates
Allowing unrestricted access to all data
Sharing passwords with colleagues
A company is found guilty of aiding and abetting cybercrime. What is true about the liability of individuals involved?
Individuals are still liable even if the company is fined
Individuals are not liable if the company is fined
Only the company is punished
No one is punished
If a person attempts but fails to commit a cybercrime, what is the legal consequence?
Attempting is still punishable
No penalty is given
Only a warning is issued
The person is rewarded
According to Sec. 17, what must happen to data after the case or period ends?
Data must be archived for future reference.
Data must be destroyed.
Data must be transferred to another agency.
Data must be published online.
What does Sec. 18 state about evidence obtained without a warrant?
It is admissible in court.
It is inadmissible.
It can be used for investigation only.
It must be destroyed immediately.
Which authority may block illegal content or sites according to Sec. 19?
Department of Education (DepEd)
Department of Justice (DOJ)
Department of Health (DOH)
Department of Finance (DOF)
What is the penalty for non-compliance as stated in Sec. 20?
1 year imprisonment or P50k fine
6 months–6 years imprisonment or P100k fine
10 years imprisonment or P500k fine
3 months imprisonment or P10k fine
Law enforcers can collect, preserve, and analyze data, but what must they follow to ensure evidence is valid?
Agency guidelines
Court orders
Personal judgment
Public opinion
What is the yearly budget allocated for implementation according to Sec. 27?
P10M
P100M
P50M
P500M
Which agencies are responsible for making implementing rules within 90 days as per Sec. 28?
DOJ, DOST-ICTO, DILG
DOH, DepEd, DOF
DTI, DA, DENR
DFA, DOT, DSWD
Why is it important for government funds and agencies to ensure the law is properly implemented?
To increase public awareness
To ensure compliance and effectiveness of the law
To reduce government spending
To promote international relations
Which law is discussed in Lesson 9 of the provided material?
Republic Act No. 10173 (Data Privacy Act of 2012)
Republic Act No. 9003 (Ecological Solid Waste Management Act)
Republic Act No. 9165 (Comprehensive Dangerous Drugs Act)
Republic Act No. 8792 (E-Commerce Act)
According to the Data Privacy Act, what does the government value alongside privacy rights?
Information flow
Economic growth
Environmental protection
Social equality
Which of the following is NOT a general data privacy principle under Section 11?
Data must be stored in a way that protects identity
Data must be collected for a clear purpose
Data must be shared with everyone
Data must be accurate and updated
Under Section 12, which of the following is a valid criterion for lawful processing of personal data?
With consent
For entertainment purposes
Without any reason
For personal curiosity
Journalists are protected under the Data Privacy Act. What does this protection mean?
Journalists do not have to reveal their news sources
Journalists must share all confidential information
Journalists are exempt from all laws
Journalists cannot report on privacy issues
If a company outsources data processing, who is responsible for ensuring safeguards?
The main controller
The subcontractor only
The government
The data subject
Which right allows individuals to correct errors in their personal data?
Right to data subject
Right to portability
Right to non-applicability
Right to security
What can heirs do after the data subject’s death or incapacity according to Section 17?
Invoke rights over the data
Delete all data
Sell the data
Ignore the data
Which section allows you to download or transfer your data in a usable format?
Section 18: Right to Data Portability
Section 14: Subcontracting Personal Information
Section 5: Protection for Journalists
Section 20: Security Measures
Rights under the Data Privacy Act do NOT apply if data is used only for which purpose?
Research or investigations
Marketing
Personal use
Social media sharing
What is one organizational measure companies must take to secure personal information?
Have a security policy
Ignore breaches
Share passwords
Disable all security systems
Why must companies notify the Commission and affected people?
In case of breaches
When hiring new staff
When launching a product
When updating their website
(DoK Level 2) If a company stores personal data longer than needed, which data privacy principle is being violated?
Data must be kept only as long as needed
Data must be accurate and updated
Data must be collected for a clear purpose
Data must be stored in a way that protects identity
(DoK Level 2) How can a data subject exercise control over their data according to Section 16?
By knowing, accessing, correcting, deleting, blocking, and getting compensation if misused
By ignoring all data requests
By sharing data with everyone
By refusing to use any technology
(DoK Level 3) Imagine a scenario where a company fails to update personal data, resulting in outdated information being used. What right can the data subject exercise to address this issue?
Block/remove outdated/false/illegal data
Right to data portability
Right to non-applicability
Right to subcontracting
(DoK Level 3) A hospital needs to process patient data during a national emergency. Which lawful processing criterion justifies this action?
For national emergency, public safety, or authority functions
For entertainment purposes
For marketing campaigns
For personal curiosity
Who is responsible for all personal data under their control, even if the data is outsourced?
Controllers
Employees
Contractors
Aliens
What must government agencies use when handling sensitive data?
Industry-standard protection
Basic password protection
No protection required
Physical locks only
Which of the following is a requirement for off-site access to sensitive government data?
Encryption must be used
No encryption needed
Physical access only
Unlimited records can be accessed
What is the maximum number of records that can be accessed at a time for off-site use according to the document?
1,000
10,000
100
5,000
Which penalty applies to unauthorized processing of sensitive data?
3-6 years imprisonment and ₱500k–₱4M fine
6 months imprisonment and ₱100k fine
1-3 years imprisonment and ₱500k–₱2M fine
1-5 years imprisonment and ₱500k–₱1M fine
If a public official is found guilty of a crime under these provisions, what is one possible consequence?
Disqualification from office
Promotion
No penalty
Transfer to another department
Which of the following crimes carries the maximum penalty?
Crimes affecting 100+ people
Unauthorized access by a single person
Negligent access
Improper disposal
A contractor wants to access sensitive government data off-site. What must they ensure according to the rules?
They must comply with encryption and clearance requirements
They can access without restrictions
They only need verbal permission
They do not need to comply with any rules
What is the role of a Data Protection Officer (DPO) in an organization?
To ensure compliance and accountability for data collection
To process payroll
To manage physical security
To supervise marketing campaigns
What is the first step in creating an information security policy?
Conducting a penetration test
Creating an organization
Information gathering
Allocating budget
Which of the following is NOT typically collected during information gathering from other countries?
Security organizations and their operations
Policies, laws, and regulations
International methodologies and best practices
Personal financial records
According to Sun Tzu’s principle in gap analysis, what should policymakers know?
Only the strengths of their country
Only the weaknesses of their country
Both strengths and weaknesses of their country
Only the laws of their country
Which phase is NOT part of gap analysis?
Assessing the country’s capabilities
Identifying external threats
Allocating budget
Legislative inquiry
Why is it important for policymakers to avoid duplicating structures in security organizations?
It increases efficiency and reduces confusion
It makes the system more complex
It encourages more attacks
It reduces the need for laws
Which of the following is a key component of setting a policy framework for information security?
Ignoring privacy protection
Acquisition & Implementation
Avoiding monitoring and assessment
Focusing only on physical security
