wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cybercrime Investigation

Total questions: 45

Worksheet time: 23mins

Name
Class
Date
1.

What does the term "cyber" primarily relate to?

a)

Physical infrastructure

b)

Agricultural systems

c)

Computers and information technology

d)

Manual labor

2.

Which domain is recognized as a new theater of war when IT infrastructure is a concern?

a)

Land

b)

Sea

c)

Air

d)

Cyberspace

3.

How is cyberspace best defined in this context?

a)

A physical location for data storage

b)

A virtual network for global communication

c)

A government surveillance tool

d)

A local area network

4.

Which Philippine law first addressed electronic commerce?

a)

RA 10175

b)

RA 8792

c)

RA 9995

d)

RA 4200

5.

RA 10175 primarily addresses which area?

a)

Child labor

b)

Wiretapping

c)

Cybercrime prevention

d)

Data privacy

6.

Which of the following is classified as a content-related cybercrime offense?

a)

Illegal access

b)

Cybersex

c)

Data interference

d)

System interference

7.

Which law mandates SIM card registration in the Philippines?

a)

RA 10173

b)

RA 11934

c)

RA 8792

d)

RA 9995

8.

Which rule governs the use of electronic evidence in the Philippines?

a)

RA 10175

b)

RA 8792

c)

A.M. No. 01-7-01-SC

d)

RA 4200

9.

Which cybercrime involves the unauthorized acquisition or assumption of another person’s identity?

a)

Cyber-squatting

b)

Computer-related identity theft

c)

Data interference

d)

System interference

10.

What best describes cyber-squatting?

a)

Hacking into protected systems

b)

Selling illegal devices online

c)

Acquiring domain names in bad faith

d)

Spreading malware via email

11.

What is the primary purpose of cyber intelligence in investigations?

a)

To monitor physical and conventional crimes

b)

To gather data on cyber threats

c)

To regulate internet bandwidth and speed

d)

To enforce traffic laws

12.

Which offense refers to unauthorized listening to or recording of data transmissions?

a)

Illegal access

b)

Data interference

c)

Illegal interception

d)

System interference

13.

Which law is the Data Privacy Act of 2012 in the Philippines?

a)

RA 10175

b)

RA 10173

c)

RA 8792

d)

RA 4200

14.

Altering digital data to create false information is best categorized as which offense?

a)

Computer-related fraud

b)

Computer-related forgery

c)

Cybersex

d)

Libel

15.

What is the role of digital evidence in cybercrime cases?

a)

It replaces physical evidence entirely

b)

It is inadmissible in court

c)

It supports legal claims in electronic form

d)

It is used only for civil cases

16.

Which element distinguishes cyberspace from physical domains like land or sea?

a)

Use of electromagnetic spectrum

b)

Presence of military bases

c)

Natural boundaries such as bodies of water

d)

Reliance on physical infrastructure

17.

How does RA 10175 differ from RA 8792 in legal scope?

a)

RA 8792 focuses on child protection

b)

RA 10175 criminalizes specific cyber offenses

c)

RA 8792 regulates SIM cards

d)

RA 10175 legalizes e-commerce

18.

Why is cyber-squatting considered a misuse of cyberspace?

a)

It promotes free speech

b)

It enables secure transactions

c)

It exploits domain names for malicious intent

d)

It enhances brand visibility

19.

What does the inclusion of corporate liability in RA 10175 imply about cybercrime?

a)

Only individuals commit cybercrime

b)

Corporations are immune to cyber laws

c)

Cybercrime is limited to government entities

d)

Organizations can be held accountable

20.

How does illegal interception differ from illegal access under cybercrime laws?

a)

Interception involves physical theft

b)

Access is passive; interception is active monitoring

c)

Access is legal; interception is not

d)

Interception is limited to emails

21.

Why is digital evidence governed by A.M. No. 01-7-01-SC (Rules on Electronic Evidence)?

a)

To exclude electronic data from trials

b)

To promote physical evidence

c)

To ensure admissibility and integrity

d)

To simplify court procedures

22.

What does the penalty enhancement for crimes against critical infrastructure suggest?

a)

Infrastructure-related crimes are more severe

b)

All cybercrimes are treated equally

c)

Penalties are reduced for juridical and corporate entities

d)

Infrastructure crimes are civil offenses

23.

Which cybercrime involves unauthorized use of another’s credentials and personal information?

a)

Cybersex

b)

Identity theft

c)

Libel

d)

Data interference

24.

Why is cybercrime often considered transnational?

a)

It only affects limited and local users

b)

It requires physical presence

c)

It is limited to one country only

d)

It crosses borders via networks

25.

How does cyberspace facilitate espionage activities?

a)

Through physical infiltration and manual surveillance

b)

Via electromagnetic surveillance and data theft

c)

By disabling satellites

d)

Through land-based operations

26.

What should investigators do when encountering encrypted data during a lawful seizure?

a)

Ignore it

b)

Delete it

c)

Share it publicly

d)

Attempt to decrypt using forensic tools

27.

Which Philippine law governs the confidentiality of personal data during investigations?

a)

RA 10175

b)

RA 8792

c)

RA 10173

d)

RA 9995

28.

What is the primary role of the Rules on Electronic Evidence in court proceedings?

a)

To exclude digital files

b)

To define admissibility standards

c)

To promote manual documentation

d)

To regulate internet use

29.

Which action best demonstrates ethical handling of digital evidence by an investigator?

a)

Editing irrelevant files to save space

b)

Sharing evidence with media for transparency

c)

Preserving original data and documenting all access

d)

Encrypting evidence without logging the password

30.

When prioritizing cybercrime cases, which factor should weigh most heavily for investigators?

a)

Media attention and case sensationalization

b)

Severity of potential harm to victims

c)

Number of social media shares

d)

Political implications

31.

Which incident response approach is most appropriate for a suspected phishing attack on a government agency?

a)

Immediately shut down all IT infrastructure

b)

Notify the media to warn the public

c)

Isolate affected systems and initiate forensic analysis

d)

Delete all suspicious emails

32.

An intelligence officer receives a credible tip about a planned ransomware attack. What is the most effective next step?

a)

Wait for the attack to occur

b)

Publicly announce the threat to avoid panic

c)

Ignore the tip unless confirmed by the media

d)

Coordinate with cybersecurity teams and initiate threat monitoring

33.

How should a cybercrime investigator evaluate the credibility of a digital witness statement?

a)

Base it on the witness’s social media following

b)

By verifying metadata and corroborating with other evidence

c)

By trusting the witness’s reputation

d)

By checking grammar and spelling

34.

Which action reflects sound judgment in handling a cross-border cybercrime case?

a)

Conduct surveillance without informing foreign counterparts

b)

Post suspect details online to crowdsource leads

c)

Ignore jurisdictional boundaries to speed up the case

d)

Collaborate with international law enforcement through proper channels

35.

What is the most appropriate response when a cyber-warrant request is denied due to insufficient evidence?

a)

Proceed with the search anyway because technicalities may allow it

b)

Fabricate supporting documents to strengthen the case

c)

Reassess and strengthen the application with additional evidence

d)

Leak the case to the press

36.

Which action most directly supports cyber threat pattern recognition during investigations?

a)

Counting the number of emails received

b)

Identifying patterns in malware behavior across multiple incidents

c)

Reading online forums for general information without analyzing threats

d)

Monitoring social media trends

37.

What is the most effective way to evaluate the success of a cybercrime investigation?

a)

Recovery of stolen data and successful prosecution

b)

Number of arrests made due to conventional crimes

c)

Media coverage received

d)

Number of likes on social media posts

38.

Which response best reflects a responder’s situational awareness during a live cyber-attack?

a)

Focusing only on the affected system

b)

Monitoring network-wide activity and coordinating with IT teams

c)

Waiting for instructions from superiors since the attack is not serious

d)

Shutting down all systems immediately to delay the attack

39.

How should an investigator assess whether to pursue a cyber-libel case?

a)

By evaluating the content’s intent, truthfulness, and public interest

b)

Based on the number of views and likes the victim received

c)

By checking the suspect’s political affiliation

d)

By comparing with similar cases on social media

40.

What is the most responsible way to handle a whistleblower’s digital tip?

a)

Publicly reveal the source on radio and television to alert everyone

b)

Ignore anonymous tips as they may come from a disgruntled employee

c)

Protect the source’s identity and verify the information

d)

Use the tip without verification

41.

Which of the following best demonstrates critical evaluation of a cybercrime suspect’s digital footprint?

a)

Counting the number of devices owned by the suspect and its network

b)

Analyzing login patterns, IP addresses, and communication logs

c)

Checking their social media followers

d)

Reading their emails without a warrant

42.

How should an investigator evaluate the reliability of a cybersecurity tool used in evidence collection?

a)

Based on cost

b)

Based on user reviews and economic impact on the investigator

c)

Based on forensic validation and legal admissibility

d)

Based on popularity

43.

What is the most effective way to assess a cybercrime unit’s readiness?

a)

Number of personnel and the size of the cybercrime unit

b)

Budget allocation and the number of investigative personnel

c)

Size of office space

d)

Frequency of training and successful case resolution

44.

How should a responder evaluate the urgency of a reported cyber incident?

a)

Based on the time of day

b)

Based on the number of emails received

c)

Based on potential data loss, system impact, and threat persistence

d)

Based on the reporter’s tone

45.

A team is selecting between two forensic imaging tools. Both meet budget and have positive user reviews. Which criterion should most strongly guide their choice to ensure court use?

a)

Choose the more popular tool in industry forums

b)

Select the tool with the lowest training overhead

c)

Prefer the tool with documented forensic validation and legal admissibility

d)

Pick the tool recommended by a senior investigator