NEW
Font size
WorksheetsCybercrime Investigation
Total questions: 45
Worksheet time: 23mins
What does the term "cyber" primarily relate to?
Physical infrastructure
Agricultural systems
Computers and information technology
Manual labor
Which domain is recognized as a new theater of war when IT infrastructure is a concern?
Land
Sea
Air
Cyberspace
How is cyberspace best defined in this context?
A physical location for data storage
A virtual network for global communication
A government surveillance tool
A local area network
Which Philippine law first addressed electronic commerce?
RA 10175
RA 8792
RA 9995
RA 4200
RA 10175 primarily addresses which area?
Child labor
Wiretapping
Cybercrime prevention
Data privacy
Which of the following is classified as a content-related cybercrime offense?
Illegal access
Cybersex
Data interference
System interference
Which law mandates SIM card registration in the Philippines?
RA 10173
RA 11934
RA 8792
RA 9995
Which rule governs the use of electronic evidence in the Philippines?
RA 10175
RA 8792
A.M. No. 01-7-01-SC
RA 4200
Which cybercrime involves the unauthorized acquisition or assumption of another person’s identity?
Cyber-squatting
Computer-related identity theft
Data interference
System interference
What best describes cyber-squatting?
Hacking into protected systems
Selling illegal devices online
Acquiring domain names in bad faith
Spreading malware via email
What is the primary purpose of cyber intelligence in investigations?
To monitor physical and conventional crimes
To gather data on cyber threats
To regulate internet bandwidth and speed
To enforce traffic laws
Which offense refers to unauthorized listening to or recording of data transmissions?
Illegal access
Data interference
Illegal interception
System interference
Which law is the Data Privacy Act of 2012 in the Philippines?
RA 10175
RA 10173
RA 8792
RA 4200
Altering digital data to create false information is best categorized as which offense?
Computer-related fraud
Computer-related forgery
Cybersex
Libel
What is the role of digital evidence in cybercrime cases?
It replaces physical evidence entirely
It is inadmissible in court
It supports legal claims in electronic form
It is used only for civil cases
Which element distinguishes cyberspace from physical domains like land or sea?
Use of electromagnetic spectrum
Presence of military bases
Natural boundaries such as bodies of water
Reliance on physical infrastructure
How does RA 10175 differ from RA 8792 in legal scope?
RA 8792 focuses on child protection
RA 10175 criminalizes specific cyber offenses
RA 8792 regulates SIM cards
RA 10175 legalizes e-commerce
Why is cyber-squatting considered a misuse of cyberspace?
It promotes free speech
It enables secure transactions
It exploits domain names for malicious intent
It enhances brand visibility
What does the inclusion of corporate liability in RA 10175 imply about cybercrime?
Only individuals commit cybercrime
Corporations are immune to cyber laws
Cybercrime is limited to government entities
Organizations can be held accountable
How does illegal interception differ from illegal access under cybercrime laws?
Interception involves physical theft
Access is passive; interception is active monitoring
Access is legal; interception is not
Interception is limited to emails
Why is digital evidence governed by A.M. No. 01-7-01-SC (Rules on Electronic Evidence)?
To exclude electronic data from trials
To promote physical evidence
To ensure admissibility and integrity
To simplify court procedures
What does the penalty enhancement for crimes against critical infrastructure suggest?
Infrastructure-related crimes are more severe
All cybercrimes are treated equally
Penalties are reduced for juridical and corporate entities
Infrastructure crimes are civil offenses
Which cybercrime involves unauthorized use of another’s credentials and personal information?
Cybersex
Identity theft
Libel
Data interference
Why is cybercrime often considered transnational?
It only affects limited and local users
It requires physical presence
It is limited to one country only
It crosses borders via networks
How does cyberspace facilitate espionage activities?
Through physical infiltration and manual surveillance
Via electromagnetic surveillance and data theft
By disabling satellites
Through land-based operations
What should investigators do when encountering encrypted data during a lawful seizure?
Ignore it
Delete it
Share it publicly
Attempt to decrypt using forensic tools
Which Philippine law governs the confidentiality of personal data during investigations?
RA 10175
RA 8792
RA 10173
RA 9995
What is the primary role of the Rules on Electronic Evidence in court proceedings?
To exclude digital files
To define admissibility standards
To promote manual documentation
To regulate internet use
Which action best demonstrates ethical handling of digital evidence by an investigator?
Editing irrelevant files to save space
Sharing evidence with media for transparency
Preserving original data and documenting all access
Encrypting evidence without logging the password
When prioritizing cybercrime cases, which factor should weigh most heavily for investigators?
Media attention and case sensationalization
Severity of potential harm to victims
Number of social media shares
Political implications
Which incident response approach is most appropriate for a suspected phishing attack on a government agency?
Immediately shut down all IT infrastructure
Notify the media to warn the public
Isolate affected systems and initiate forensic analysis
Delete all suspicious emails
An intelligence officer receives a credible tip about a planned ransomware attack. What is the most effective next step?
Wait for the attack to occur
Publicly announce the threat to avoid panic
Ignore the tip unless confirmed by the media
Coordinate with cybersecurity teams and initiate threat monitoring
How should a cybercrime investigator evaluate the credibility of a digital witness statement?
Base it on the witness’s social media following
By verifying metadata and corroborating with other evidence
By trusting the witness’s reputation
By checking grammar and spelling
Which action reflects sound judgment in handling a cross-border cybercrime case?
Conduct surveillance without informing foreign counterparts
Post suspect details online to crowdsource leads
Ignore jurisdictional boundaries to speed up the case
Collaborate with international law enforcement through proper channels
What is the most appropriate response when a cyber-warrant request is denied due to insufficient evidence?
Proceed with the search anyway because technicalities may allow it
Fabricate supporting documents to strengthen the case
Reassess and strengthen the application with additional evidence
Leak the case to the press
Which action most directly supports cyber threat pattern recognition during investigations?
Counting the number of emails received
Identifying patterns in malware behavior across multiple incidents
Reading online forums for general information without analyzing threats
Monitoring social media trends
What is the most effective way to evaluate the success of a cybercrime investigation?
Recovery of stolen data and successful prosecution
Number of arrests made due to conventional crimes
Media coverage received
Number of likes on social media posts
Which response best reflects a responder’s situational awareness during a live cyber-attack?
Focusing only on the affected system
Monitoring network-wide activity and coordinating with IT teams
Waiting for instructions from superiors since the attack is not serious
Shutting down all systems immediately to delay the attack
How should an investigator assess whether to pursue a cyber-libel case?
By evaluating the content’s intent, truthfulness, and public interest
Based on the number of views and likes the victim received
By checking the suspect’s political affiliation
By comparing with similar cases on social media
What is the most responsible way to handle a whistleblower’s digital tip?
Publicly reveal the source on radio and television to alert everyone
Ignore anonymous tips as they may come from a disgruntled employee
Protect the source’s identity and verify the information
Use the tip without verification
Which of the following best demonstrates critical evaluation of a cybercrime suspect’s digital footprint?
Counting the number of devices owned by the suspect and its network
Analyzing login patterns, IP addresses, and communication logs
Checking their social media followers
Reading their emails without a warrant
How should an investigator evaluate the reliability of a cybersecurity tool used in evidence collection?
Based on cost
Based on user reviews and economic impact on the investigator
Based on forensic validation and legal admissibility
Based on popularity
What is the most effective way to assess a cybercrime unit’s readiness?
Number of personnel and the size of the cybercrime unit
Budget allocation and the number of investigative personnel
Size of office space
Frequency of training and successful case resolution
How should a responder evaluate the urgency of a reported cyber incident?
Based on the time of day
Based on the number of emails received
Based on potential data loss, system impact, and threat persistence
Based on the reporter’s tone
A team is selecting between two forensic imaging tools. Both meet budget and have positive user reviews. Which criterion should most strongly guide their choice to ensure court use?
Choose the more popular tool in industry forums
Select the tool with the lowest training overhead
Prefer the tool with documented forensic validation and legal admissibility
Pick the tool recommended by a senior investigator
