wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Chapter 5 Learning Objectives

Total questions: 67

Worksheet time: 34mins

Name
Class
Date
1.

Which scenario best illustrates an ethical issue commonly raised by information systems?

a)

Automating backups to reduce data loss

b)

Compressing files to save storage space

c)

Tracking employee keystrokes without consent

d)

Upgrading servers for better performance

2.

Which principles are most appropriate to guide ethical decision-making in information systems?

a)

Maximizing data collection for analytics

b)

Respect for privacy and informed consent

c)

Unrestricted sharing of proprietary code

d)

Transparency and accountability of processes

3.

Which challenge to individual privacy is amplified by contemporary IS and the Internet?

a)

Local-only storage of paper records

b)

Anonymized aggregate statistics reporting

c)

Wide-scale data profiling across platforms

d)

Manual entry errors in spreadsheets

4.

In the context of information systems, what does accountability and liability primarily concern?

a)

Ensuring high uptime of servers

b)

Assigning responsibility for harm caused

c)

Reducing costs of cloud services

d)

Increasing speed of database queries

5.

Which statement best defines ethics in the context of individual decision-making?

a)

Legal statutes governments enact to regulate behavior

b)

Rules of compliance organizations impose on employees

c)

Cultural norms communities use to enforce traditions

d)

Principles of right and wrong guiding free moral agents

6.

Information systems can trigger intense social change. What is a likely impact of such change?

a)

Reducing opportunities for innovation across industries

b)

Stabilizing existing distributions of power and rights

c)

Threatening existing distributions of power and obligations

d)

Eliminating the need for ethical reasoning in workplaces

7.

Which scenario illustrates an ethical dilemma introduced by information systems?

a)

Comparing prices of cloud storage subscriptions

b)

Selecting an ergonomic keyboard for office comfort

c)

Deciding whether to collect user data beyond consent

d)

Choosing the fastest internet provider for home use

8.

Which options represent new opportunities for crime arising from information systems? Select all that apply.

a)

Identity theft using breached databases

b)

Public posting of open-source tools

c)

Phishing campaigns targeting employees

d)

Routine software patch management

e)

Unauthorized access to cloud resources

9.

What distinguishes new kinds of crimes enabled by information systems from traditional crimes?

a)

They depend on digital technologies and networks

b)

They are prosecuted under civil law exclusively

c)

They always occur in physical locations only

d)

They require no intent or malicious motivation

10.

An IT manager introduces a system that shifts control of customer data from users to the firm. Which ethical principle is most directly challenged?

a)

Promotion of industry-standard encryption suites

b)

Respect for individual autonomy and informed choice

c)

Adherence to legacy data retention schedules

d)

Maximization of organizational efficiency metrics

11.

Which set best captures why information systems raise new ethical questions?

a)

Faster processors and larger storage capacity

b)

Opportunities for social change and new crimes

c)

Higher hardware costs and licensing fees

d)

Improved user interfaces and accessibility features

12.

Which option best describes the moral dimension focused on rules for collecting, using, and sharing personal data?

a)

Quality of life

b)

Accountability and control

c)

Information rights and obligations

d)

Property rights and obligations

13.

Which moral dimension deals primarily with intellectual property, licensing, and ownership of digital assets?

a)

System quality

b)

Information rights and obligations

c)

Property rights and obligations

d)

Accountability and control

14.

A fintech app incorrectly charges fees and no one can trace who is responsible. Which moral dimension is most violated?

a)

Property rights and obligations

b)

Accountability and control

c)

System quality

d)

Quality of life

15.

An online service ships with frequent crashes and security bugs that harm users. Which moral dimension is directly implicated?

a)

Accountability and control

b)

Quality of life

c)

System quality

d)

Information rights and obligations

16.

A social network’s addictive design reduces sleep and increases anxiety for teens. Which moral dimension is highlighted?

a)

Property rights and obligations

b)

Accountability and control

c)

System quality

d)

Quality of life

17.

Which trends intensify privacy risks by enabling cheaper retention of massive datasets? Select all that apply.

a)

Computing power impact

b)

Mobile device growth

c)

Data analysis advances

d)

Data storage cost decline

e)

Networking advances

18.

Which statement best captures the impact of computing power doubling every 18 months on ethical issues?

a)

It slows the spread of mobile devices worldwide

b)

It eliminates the need for accountability controls

c)

It enables more complex surveillance algorithms

d)

It reduces data collection incentives overall

19.

Which combination of trends most expands real-time tracking and profiling at scale?

a)

System quality improvements

b)

Property rights expansion

c)

Computing power increases

d)

Networking advances

e)

Mobile device growth

20.

Which best describes profiling in advanced data analysis?

a)

Aggregating multi-source data into individual dossiers

b)

Encrypting sensitive records to prevent unauthorized access

c)

Automating data entry workflows across enterprise systems

d)

Detecting anomalies in real-time streaming telemetry

21.

What is the primary goal of Nonobvious Relationship Awareness (NORA)?

a)

Classify images using deep neural networks

b)

Summarize public reports for executive dashboards

c)

Reveal obscure hidden connections among entities

d)

Measure system performance under variable loads

22.

Which statements are accurate about combining data from multiple sources in advanced analysis? Select all that apply.

a)

Primarily reduces storage costs across data centers

b)

Ensures datasets are anonymized by default

c)

Finds hidden links that aid identifying criminals

d)

Creates detailed dossiers on individuals

23.

In the diagram, which step occurs immediately before NORA generates alerts?

a)

Name standardization, match, merge

b)

Data encryption and archival

c)

Policy approval by compliance team

d)

Risk scoring and visualization

24.

Which data sources are shown feeding into the NORA system in the diagram? Select all that apply.

a)

Human resources systems

b)

Social media profiles

c)

Customer transaction systems

d)

Incident and arrest systems

e)

Watch lists

25.

What is the primary purpose of combining data from telephone records and HR systems in NORA?

a)

To anonymize employee identities across systems

b)

To enforce password complexity policies

c)

To replace legacy payroll applications

d)

To reveal nonobvious relationships for alerts

26.

Which statement best defines responsibility in IT decision-making?

a)

Appealing decisions to higher authorities

b)

Recovering damages through legal claims

c)

Tracking actions with audit mechanisms

d)

Accepting potential costs, duties, and obligations

27.

In an information system, accountability primarily refers to:

a)

Publicly posting organizational policies

b)

Acceptance of duties and obligations

c)

Legal rights to claim compensation

d)

Mechanisms for identifying responsible parties

28.

Which option correctly matches the concept of liability in IT governance?

a)

Ensures decisions can be appealed

b)

Permits individuals to recover damages

c)

Accepts duties and obligations

d)

Identifies responsible parties

29.

Choose all statements that describe due process in the context of IT and law.

a)

There is an ability to appeal to higher authorities

b)

Laws are well-known and understood

c)

Mechanisms exist for identifying responsible parties

d)

Individuals can recover damages for harm

30.

Which action best represents the first step in an ethical analysis for an IT scenario?

a)

Evaluate potential legal penalties first

b)

Survey public opinion on the issue

c)

Select the most convenient option available

d)

Identify and clearly describe the facts

31.

In an ethical analysis, what is the primary purpose of defining the conflict or dilemma?

a)

To list all technical constraints

b)

To choose stakeholders to prioritize

c)

To identify higher-order values involved

d)

To draft a communication plan

32.

Which combination lists steps that occur before deciding on an action in the five-step ethical analysis process?

a)

Draft implementation timelines

b)

Identify potential consequences

c)

Identify stakeholders affected

d)

Define the conflict or dilemma

33.

A security engineer faces a dilemma about disclosing a vulnerability. Which stakeholders should be identified during analysis?

a)

Competitors with unrelated products

b)

Regulators overseeing compliance

c)

The engineer's pet and family

d)

End users relying on the system

34.

Professional codes of conduct from ACM and IEEE primarily serve which role within the IT profession?

a)

Technical standards for hardware connectors

b)

Promises to self-regulate for society's interest

c)

Marketing strategies to attract new members

d)

Legal statutes enforced by government courts

35.

Which statement best distinguishes ACM and IEEE codes from personal moral preferences?

a)

They are crowd-sourced social media polls

b)

They are criminal laws with punishments

c)

They are private beliefs kept confidential

d)

They are promulgated by professional associations

36.

Which scenario best illustrates conflicting interests in employee monitoring within an IT workplace?

a)

Company tracks keystrokes to boost output

b)

Workers use breaks for lengthy gaming sessions

c)

Employees block ads with personal browser plugins

d)

Team adopts agile to improve sprint velocity

37.

In social media platforms, which practices raise privacy and data monetization concerns? Select all that apply.

a)

Selling aggregated user data to partners

b)

Restricting third-party app access via audits

c)

Encrypting messages end-to-end by default

d)

Profiling behavior to target advertisements

38.

A company argues it must monitor internet usage to maximize productivity, while employees want limited oversight for short personal tasks. What is the core ethical tension?

a)

Data accuracy versus system availability

b)

Market competition versus open-source collaboration

c)

Legal compliance versus technical feasibility

d)

Organizational efficiency versus individual autonomy

39.

Which statement best defines privacy in the context of information rights?

a)

Right to be left alone and control information

b)

Right to unrestricted access to all public data

c)

Right to anonymity for all online activities

d)

Right to government-provided cybersecurity services

40.

Which U.S. Constitutional amendment primarily protects against unreasonable searches and seizures, supporting privacy?

a)

Fifth Amendment due process protections

b)

Fourth Amendment protections against unreasonable searches

c)

First Amendment protections of speech and association

d)

Tenth Amendment reserving powers to the states

41.

Which combination correctly lists federal measures that protect privacy in the United States?

a)

Privacy Act of 1974

b)

Fourth Amendment constraints

c)

First Amendment freedoms

d)

Sherman Antitrust Act

42.

Fair Information Practices (FIP) are best described as what?

a)

Set of principles for collecting and using information

b)

Federal agency enforcing consumer protection laws

c)

Statute exclusively governing children’s online privacy

d)

Technical standard for encrypting personal data

43.

Which laws are commonly associated with implementing FIP in the United States?

a)

Gramm–Leach–Bliley Act (GLBA)

b)

Children’s Online Privacy Protection Act (COPPA)

c)

Digital Millennium Copyright Act (DMCA)

d)

Health Insurance Portability and Accountability Act (HIPAA)

44.

Which statement about FIP’s influence is accurate?

a)

Focuses solely on data security and breach notification

b)

Applies only to paper records in government agencies

c)

Forms the basis for most U.S. and European privacy laws

d)

Eliminates the need for sector-specific privacy statutes

45.

Which are core FTC FIP principles focused on consumer control and transparency?

a)

Choice and consent

b)

Data monetization

c)

Notice and awareness

d)

Access and participation

46.

Which principle emphasizes allowing individuals to review and correct their personal information held by an organization?

a)

Notice/awareness describing collection practices

b)

Security safeguarding data against unauthorized access

c)

Choice/consent selecting data sharing preferences

d)

Access/participation correcting personal information

47.

Which element of the FTC FIP framework is most directly concerned with technical and administrative safeguards for personal data?

a)

Notice/awareness explaining data practices

b)

Choice/consent enabling opt-in or opt-out

c)

Security protecting data from unauthorized access

d)

Enforcement through accountability mechanisms

48.

An online service posts a clear privacy notice, allows opt-in for sharing, lets users edit profiles, encrypts data, and undergoes audits. Which FTC FIP elements does this scenario illustrate?

a)

Data exclusivity and ownership

b)

Enforcement through audits

c)

Access/participation and security

d)

Notice/awareness and choice/consent

49.

Which statement best describes GDPR consent for processing personal data?

a)

Unambiguous explicit informed consent by the individual

b)

Implied consent through continued website use

c)

Consent granted permanently unless revoked by the regulator

d)

Automatic consent for EU residents using online services

50.

A company in an EU member state wants to transfer customer data to a foreign partner. Under GDPR, when is this permitted?

a)

When customers have accounts in both jurisdictions

b)

Only if the partner offers similar privacy protection

c)

Whenever the partner is a multinational corporation

d)

If the data are anonymized for marketing analytics

51.

Which entities must comply with GDPR requirements?

a)

Only EU-headquartered firms processing EU data

b)

Any firm operating in the EU or processing EU residents' data

c)

Only data processors that store data within EU borders

d)

Government agencies within EU member states only

52.

Select all measures strengthened or mandated by GDPR.

a)

Privacy Shield conformity for processing EU data

b)

Right to be forgotten

c)

Mandatory data transfers to non-EU partners

d)

Maximum fines set at 4% of global daily revenue

53.

What is a potential penalty under GDPR for serious violations?

a)

Mandatory public apology to affected users

b)

A fixed fine of €10,000 per incident

c)

Revocation of EU operating licenses only

d)

Fines up to 4% of global annual revenue

54.

Which statement best describes cookies in web browsing?

a)

Small files identifying a browser for site visits

b)

Standalone programs that replace operating systems

c)

Encrypted emails protecting messages from interception

d)

Large images improving website loading speed

55.

What is the primary purpose of web beacons (web bugs)?

a)

Track who reads emails or visits pages

b)

Store user passwords on the device

c)

Block pop-up advertisements automatically

d)

Provide end-to-end message encryption

56.

Which behavior is most characteristic of spyware?

a)

Only improves graphics performance

b)

Secretly installs and transmits keystrokes

c)

Requires explicit consent before installation

d)

Deletes all tracking cookies automatically

57.

Which practice exemplifies behavioral targeting by online services?

a)

Personalized ads based on browsing history

b)

Randomized ads regardless of past activity

c)

Blocking all ads at the network perimeter

d)

Ads chosen solely by page color scheme

58.

In an opt-out model, what must a user do to stop data collection for marketing?

a)

Actively decline participation

b)

Enable anonymous browsing mode

c)

Install a hardware firewall

d)

Explicitly grant permission

59.

Which statements are accurate about online privacy approaches in the United States?

a)

Privacy statements can be complex or ambiguous

b)

Opt-in models are more commonly selected than opt-out

c)

Industry often favors self-regulation over legislation

d)

Businesses may use transaction data for marketing

60.

What is a common criticism of online privacy statements and seals?

a)

They primarily describe encryption algorithms

b)

They guarantee strict government enforcement

c)

They are complex and ambiguous for users

d)

They eliminate all tracking technologies

61.

According to the diagram, what is the server’s first action when a user visits a site?

a)

Sends targeted ads immediately

b)

Creates a user account automatically

c)

Reads browser and system details

d)

Downloads files to the user’s device

62.

Which sequence correctly describes the cookie lifecycle shown: creation, storage, retrieval, and use?

a)

Server requests cookie, browser creates, server stores, browser identifies

b)

Browser creates cookie, server stores, browser requests, server identifies

c)

Browser stores cookie, server sends ads, browser retrieves, server deletes

d)

Server sends cookie, browser stores, server requests, server identifies

63.

When a returning visitor arrives, what does the server request to recognize the user?

a)

Contents of previously deposited cookies

b)

Encrypted session logs from browser

c)

User’s email inbox messages

d)

Operating system license information

64.

Which statements are true about the role of cookies in visitor identification in the diagram?

a)

Cookies are tiny text files stored by the browser

b)

Servers read cookies to call up user data

c)

Cookies are created only by the browser itself

d)

Cookies replace authentication for every website

65.

Which option best describes the main goal of email encryption in privacy protection?

a)

Prevent malware from installing on devices

b)

Hide message contents from unintended readers

c)

Block all tracking across unrelated websites

d)

Mask a user’s IP address on the network

66.

Select ALL solutions that primarily aim to limit web tracking across sites rather than encrypt content.

a)

Private browsing mode in browsers

b)

Browser “Do Not Track” signals

c)

Email end-to-end encryption

d)

Anonymity tools like Tor routing

67.

Which statement is most accurate about the effectiveness of technical solutions in stopping cross-site tracking?

a)

Overall, they have not fully prevented tracking

b)

They completely block all third-party trackers

c)

They eliminate the need for organizational policies

d)

They make tracking illegal in all countries