wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Chapter 7 Security, Ethics and Privacy – 30 MCQs

Total questions: 90

Worksheet time: 45mins

Name
Class
Date
1.

Which of the following is a common sign of a phishing email?

a)

A personal greeting

b)

A message asking for login details

c)

An email from your friend

d)

A normal company update

2.

What is the main purpose of a password?

a)

To make the device run faster

b)

To control who can access a system

c)

To save storage space

d)

To update the software

3.

Which is an example of malware?

a)

Antivirus

b)

Worm

c)

Router

d)

Keyboard

4.

When a computer becomes very slow because a program is copying itself repeatedly, this is likely caused by a:

a)

Firewall

b)

Virus

c)

Monitor

d)

Backup file

5.

What does encryption do?

a)

Deletes old files

b)

Turns readable data into unreadable form

c)

Speeds up the Internet

d)

Makes graphics clearer

6.

Which of the following is a good security practice?

a)

Sharing passwords

b)

Using easy passwords

c)

Updating software

d)

Clicking unknown links

7.

Which device is used to verify a fingerprint?

a)

Scanner

b)

Biometric reader

c)

Printer

d)

Mouse

8.

Which attack tries to overload a website so it becomes unavailable?

a)

Spoofing

b)

DDoS

c)

Backup

d)

Logging

9.

What is the main purpose of a firewall?

a)

Printing documents

b)

Blocking unauthorized access

c)

Saving battery power

d)

Playing media

10.

Social engineering mainly targets:

a)

System hardware

b)

Human weakness

c)

Internet speed

d)

Backup files

11.

What is an example of personal data?

a)

Movie rating

b)

Weather report

c)

Your IC number

d)

File size

12.

Cookies on a website are used to:

a)

Steal credit cards

b)

Improve user experience

c)

Delete viruses

d)

Increase RAM

13.

Unauthorized access means:

a)

Entering a system without permission

b)

Printing documents

c)

Closing an application

d)

Restarting a computer

14.

Which action helps protect your privacy online?

a)

Posting personal details publicly

b)

Using strong passwords

c)

Connecting to any free WiFi

d)

Turning off antivirus

15.

If your files suddenly become encrypted and you are asked to pay money, this is:

a)

Firewall update

b)

Ransomware attack

c)

System maintenance

d)

Normal backup process

16.

Information ethics mainly deals with:

a)

How people use technology responsibly

b)

How to design hardware

c)

How screens display colours

d)

How fast data transfers occur

17.

A backup is used when:

a)

You need to open YouTube

b)

Data is lost or damaged

c)

CPU is overheating

d)

Internet is lagging

18.

Which is a safe behaviour online?

a)

Downloading unknown attachments

b)

Ignoring updates

c)

Using two-factor authentication

d)

Clicking random ads

19.

A digital certificate is used to:

a)

Speed up websites

b)

Confirm a website is real

c)

Slow down cyberattacks

d)

Change screen settings

20.

Which of the following is a security threat?

a)

Healthy posture

b)

Malware infection

c)

Keyboard cleaning

d)

Screen brightness

21.

Carpal Tunnel Syndrome is related to:

a)

Network speed

b)

Repetitive wrist movement

c)

Antivirus updates

d)

Keyboard colour

22.

Which of the following is a privacy concern?

a)

Sharing your location publicly

b)

Charging your laptop

c)

Installing updates

d)

Changing wallpaper

23.

What is the first thing you should do when receiving a suspicious message?

a)

Click the link to check

b)

Reply immediately

c)

Delete or report it

d)

Forward it to friends

24.

Why do companies use access control?

a)

To manage who can see or use data

b)

To reduce electricity bills

c)

To speed up downloads

d)

To change app colours

25.

What is an example of ethical behaviour in IT?

a)

Using cracked software

b)

Respecting user privacy

c)

Ignoring copyrights

d)

Sharing confidential data

26.

A password like “12345” is considered:

a)

Strong

b)

Very secure

c)

Weak

d)

Encrypted

27.

Which action helps avoid malware?

a)

Downloading from unsafe sites

b)

Installing antivirus

c)

Disabling updates

d)

Turning off the firewall

28.

Why is two-factor authentication safer?

a)

It removes the need for passwords

b)

It requires two forms of verification

c)

It increases Internet speed

d)

It shortens login time

29.

Which is an example of information theft?

a)

Losing your water bottle

b)

Someone stealing your data

c)

Watching a video

d)

Resetting your account

30.

What is the main goal of cybersecurity?

a)

Make computers faster

b)

Protect systems and data from threats

c)

Increase screen brightness

d)

Create more apps

31.

An organization implements an advanced firewall and intrusion detection system, yet attackers still manage to access sensitive files by obtaining the login details of a long-time employee through subtle psychological manipulation. Which statement BEST explains the deeper systemic vulnerability?

a)

Technical systems lacked encryption

b)

Human element remains the weakest point in security

c)

Network segmentation was not properly tested

d)

Firewall rules were too permissive

32.

An IT department notices that despite strong security tools, employees continue to ignore software update notifications, increasing vulnerability windows. Which concept BEST describes this behavioural risk?

a)

System downtime tolerance

b)

Compliance fatigue

c)

Access privilege misuse

d)

Redundancy misalignment

33.

A company encrypts all stored data using strong cryptographic algorithms, yet attackers still manage to read the data by exploiting a memory dump after a program crash. Which theoretical security limitation does this illustrate?

a)

Encryption is obsolete against modern attackers

b)

Data in use remains vulnerable even if stored data is encrypted

c)

Encryption increases system memory usage

d)

Attackers can always bypass encryption if they use brute force

34.

Two organizations adopt identical antivirus software. One suffers frequent malware outbreaks, while the other experiences almost none. Both have similar hardware. Which factor MOST likely explains the difference?

a)

Antivirus update schedule and user behaviour

b)

Brand of RAM installed

c)

SSD fragmentation

d)

Background processes with high priority

35.

A multinational company creates a privacy policy but provides it only in English, leaving non-English speaking workers unaware of its conditions. Which ethical problem arises?

a)

Lack of technical redundancy

b)

Inequitable access to information

c)

Overuse of encryption keys

d)

Poorly implemented DNS records

36.

An employee discovers a flaw allowing access to confidential data but does not report it, believing “no harm was done.” Which ethical framework does the employee violate MOST?

a)

Legal compliance law

b)

Professional duty of care

c)

Encryption assurance

d)

Network segmentation policy

37.

An organization uses a rule requiring employees to “handle all personal data minimally.” Which principle is being enforced?

a)

Data minimization

b)

Network throttling

c)

Multi-layer caching

d)

Zero-trust encryption bursting

38.

A company redesigns its security architecture to assume everyone, including internal employees, is a potential threat. Which model is being adopted?

a)

Open-access computing

b)

Zero-trust security

c)

Public-key federation

d)

Hierarchical privilege indexing

39.

A CEO demands full monitoring of all employees’ digital activity “to maximize productivity,” but employees express strong discomfort, citing privacy concerns. What fundamental ethical tension arises?

a)

Integrity vs. redundancy

b)

Organizational oversight vs. individual privacy

c)

Firewall throughput vs. encryption

d)

Data mining vs. firmware updates

40.

A company refuses to update its Acceptable Use Policy despite new security threats emerging. Which issue does this create over time?

a)

Reduced cache consistency

b)

Policy obsolescence and weakened governance

c)

More efficient load balancing

d)

Guaranteed user compliance

41.

Remote employees frequently access corporate systems through personal devices. What theoretical risk does this environment exemplify?

a)

Controlled integration

b)

Expanded attack surface

c)

Physical redundancy

d)

Fibre-optic signal decay

42.

A machine-learning fraud detection system locks valid users out during peak hours. The company argues, “false positives are acceptable for high security.” Which ethical concern is raised?

a)

Cognitive load imbalance

b)

Fairness and proportionality in security controls

c)

Excessive data compression

d)

Inconsistent DNS handshakes

43.

During an audit, it was found that only administrators understand how logs are generated and stored, making fraud detection difficult for the rest of the team. Which issue does this represent?

a)

Excessive privilege distribution

b)

Knowledge centralization and lack of transparency

c)

Faulty data replication

d)

Low virtual memory allocation

44.

An organization encrypts all data, trains employees thoroughly, installs firewalls, and monitors internal behaviour, yet still suffers data leakage through screenshots taken on phones. What security reality does this illustrate?

a)

Perfect security is achievable with the right tools

b)

Technological controls cannot eliminate all human workarounds

c)

Screenshots cannot be considered data breaches

d)

Encryption prevents screenshots from being harmful

45.

A privacy officer argues that “data collection should always match the purpose it was gathered for.” Which privacy framework supports this argument?

a)

Data lifecycle depletion

b)

Purpose limitation

c)

Audit recursion

d)

Least-frequency replication

46.

An IT director insists on using extremely long, complex passwords without implementing password managers. Staff begin storing passwords on paper. Which unintended risk is introduced?

a)

Higher network speed

b)

Increased physical security vulnerabilities

c)

More efficient encryption

d)

Reduced malware risk

47.

A company provides cybersecurity awareness training once a year. Research indicates most employees forget key information within weeks. Which theoretical weakness does this show?

a)

Training frequency misalignment

b)

Algorithmic decay

c)

Hyper-threading confusion

d)

Virtualization overhead

48.

Two-factor authentication is implemented across an organization. However, attackers still gain access using compromised session tokens. Which vulnerability does this highlight?

a)

Token hijacking bypasses identity verification

b)

Password strength must be doubled

c)

Users reused their PINs frequently

d)

Tokens prevent all forms of unauthorized access

49.

A critical server stores logs but overwrites old entries every 24 hours due to storage limitations. How does this undermine security?

a)

Logs lose aesthetic clarity

b)

Incident investigation becomes incomplete

c)

Password hashing becomes impossible

d)

CPU cooling becomes inefficient

50.

Employees become overly reliant on biometric authentication and stop creating strong passwords. Which security risk emerges?

a)

Credential fallback weakness

b)

Elevated GPU temperature

c)

Excessive browser caching

d)

DNS failover loops

51.

The board of directors requests minimal encryption to maintain performance levels. The security team disagrees, warning this may violate laws protecting user data. Which principle is in conflict?

a)

Efficiency vs. compliance

b)

Redundancy vs. caching

c)

VLAN purity

d)

System acceleration

52.

A malware variant disables antivirus services before executing its payload. Which defence principle was MOST critically compromised?

a)

Fail-open architecture

b)

Defence in depth

c)

Fibre attenuation

d)

Adaptive frequency hopping

53.

A phishing campaign targets employees with personalized details collected from social media. Which concept explains why the attack is convincing?

a)

High bandwidth

b)

Contextual specificity

c)

Random noise injection

d)

DNS balancing

54.

A system restricts employees to viewing data relevant only to their tasks, preventing curiosity-driven browsing of confidential records. What key security idea does this follow?

a)

Principle of least privilege

b)

Redundant directory mapping

c)

Universal access control

d)

Recursive encryption

55.

A cybersecurity officer states that “every breach is also a failure of organizational culture.” What does this imply theoretically?

a)

Cybersecurity is solely technical

b)

Behaviour and governance shape security posture

c)

Encryption speed determines culture

d)

Culture has no measurable impact on breaches

56.

A company automates encryption but leaves key management to manual processes handled by one employee. What major risk exists?

a)

Lack of redundancy in key control

b)

Faster encryption speed

c)

Reduced access latency

d)

High-quality password caching

57.

A privacy assessment finds that a company collects more data than needed “just in case it becomes useful later.” Which theoretical risk does this create?

a)

Storage overflow

b)

Unnecessary exposure due to excessive retention

c)

Reduced CPU threads

d)

Duplicate packet flows

58.

A cyberattack exploits the fact that users often click quickly without thinking. Which psychological factor is MOST relevant?

a)

Time pressure and cognitive shortcuts

b)

Increased working memory capacity

c)

Rational evaluation processes

d)

Passive information filtering

59.

An organization depends heavily on automated monitoring but rarely verifies alerts manually. What vulnerability does this create?

a)

Overreliance on automation may mask false negatives

b)

Excessive DNS records

c)

Slow packet transmission

d)

Misleading GUI theming

60.

A data center practices disaster recovery by running simulations without informing employees beforehand. What important benefit does this provide?

a)

Accurate measurement of real-world response behaviour

b)

Increased system cooling

c)

Improved text rendering on dashboards

d)

Elevated system cache lifetime

61.

An organization implements an advanced firewall and intrusion detection system, yet attackers still manage to access sensitive files by obtaining the login details of a long-time employee through subtle psychological manipulation. Which statement BEST explains the deeper systemic vulnerability?

a)

Technical systems lacked encryption

b)

Human element remains the weakest point in security

c)

Network segmentation was not properly tested

d)

Firewall rules were too permissive

62.

An IT department notices that despite strong security tools, employees continue to ignore software update notifications, increasing vulnerability windows. Which concept BEST describes this behavioural risk?

a)

System downtime tolerance

b)

Compliance fatigue

c)

Access privilege misuse

d)

Redundancy misalignment

63.

A company encrypts all stored data using strong cryptographic algorithms, yet attackers still manage to read the data by exploiting a memory dump after a program crash. Which theoretical security limitation does this illustrate?

a)

Encryption is obsolete against modern attackers

b)

Data in use remains vulnerable even if stored data is encrypted

c)

Encryption increases system memory usage

d)

Attackers can always bypass encryption if they use brute force

64.

Two organizations adopt identical antivirus software. One suffers frequent malware outbreaks, while the other experiences almost none. Both have similar hardware. Which factor MOST likely explains the difference?

a)

Antivirus update schedule and user behaviour

b)

Brand of RAM installed

c)

SSD fragmentation

d)

Background processes with high priority

65.

A multinational company creates a privacy policy but provides it only in English, leaving non-English speaking workers unaware of its conditions. Which ethical problem arises?

a)

Lack of technical redundancy

b)

Inequitable access to information

c)

Overuse of encryption keys

d)

Poorly implemented DNS records

66.

An employee discovers a flaw allowing access to confidential data but does not report it, believing “no harm was done.” Which ethical framework does the employee violate MOST?

a)

Legal compliance law

b)

Professional duty of care

c)

Encryption assurance

d)

Network segmentation policy

67.

An organization uses a rule requiring employees to “handle all personal data minimally.” Which principle is being enforced?

a)

Data minimization

b)

Network throttling

c)

Multi-layer caching

d)

Zero-trust encryption bursting

68.

A company redesigns its security architecture to assume everyone, including internal employees, is a potential threat. Which model is being adopted?

a)

Open-access computing

b)

Zero-trust security

c)

Public-key federation

d)

Hierarchical privilege indexing

69.

A CEO demands full monitoring of all employees’ digital activity “to maximize productivity,” but employees express strong discomfort, citing privacy concerns. What fundamental ethical tension arises?

a)

Integrity vs. redundancy

b)

Organizational oversight vs. individual privacy

c)

Firewall throughput vs. encryption

d)

Data mining vs. firmware updates

70.

A company refuses to update its Acceptable Use Policy despite new security threats emerging. Which issue does this create over time?

a)

Reduced cache consistency

b)

Policy obsolescence and weakened governance

c)

More efficient load balancing

d)

Guaranteed user compliance

71.

Remote employees frequently access corporate systems through personal devices. What theoretical risk does this environment exemplify?

a)

Controlled integration

b)

Expanded attack surface

c)

Physical redundancy

d)

Fibre-optic signal decay

72.

A machine-learning fraud detection system locks valid users out during peak hours. The company argues, “false positives are acceptable for high security.” Which ethical concern is raised?

a)

Cognitive load imbalance

b)

Fairness and proportionality in security controls

c)

Excessive data compression

d)

Inconsistent DNS handshakes

73.

During an audit, it was found that only administrators understand how logs are generated and stored, making fraud detection difficult for the rest of the team. Which issue does this represent?

a)

Excessive privilege distribution

b)

Knowledge centralization and lack of transparency

c)

Faulty data replication

d)

Low virtual memory allocation

74.

An organization encrypts all data, trains employees thoroughly, installs firewalls, and monitors internal behaviour, yet still suffers data leakage through screenshots taken on phones. What security reality does this illustrate?

a)

Perfect security is achievable with the right tools

b)

Technological controls cannot eliminate all human workarounds

c)

Screenshots cannot be considered data breaches

d)

Encryption prevents screenshots from being harmful

75.

A privacy officer argues that “data collection should always match the purpose it was gathered for.” Which privacy framework supports this argument?

a)

Data lifecycle depletion

b)

Purpose limitation

c)

Audit recursion

d)

Least-frequency replication

76.

A IT director insists on using extremely long, complex passwords without implementing password managers. Staff begin storing passwords on paper. Which unintended risk is introduced?

a)

Higher network speed

b)

Increased physical security vulnerabilities

c)

More efficient encryption

d)

Reduced malware risk

77.

A company provides cybersecurity awareness training once a year. Research indicates most employees forget key information within weeks. Which theoretical weakness does this show?

a)

Training frequency misalignment

b)

Algorithmic decay

c)

Hyper-threading confusion

d)

Virtualization overhead

78.

Two-factor authentication is implemented across an organization. However, attackers still gain access using compromised session tokens. Which vulnerability does this highlight?

a)

Token hijacking bypasses identity verification

b)

Password strength must be doubled

c)

Users reused their PINs frequently

d)

Tokens prevent all forms of unauthorized access

79.

A critical server stores logs but overwrites old entries every 24 hours due to storage limitations. How does this undermine security?

a)

Logs lose aesthetic clarity

b)

Incident investigation becomes incomplete

c)

Password hashing becomes impossible

d)

CPU cooling becomes inefficient

80.

Employees become overly reliant on biometric authentication and stop creating strong passwords. Which security risk emerges?

a)

Credential fallback weakness

b)

Elevated GPU temperature

c)

Excessive browser caching

d)

DNS failover loops

81.

The board of directors requests minimal encryption to maintain performance levels. The security team disagrees, warning this may violate laws protecting user data. Which principle is in conflict?

a)

Efficiency vs. compliance

b)

Redundancy vs. caching

c)

VLAN purity

d)

System acceleration

82.

A malware variant disables antivirus services before executing its payload. Which defence principle was MOST critically compromised?

a)

Fail-open architecture

b)

Defence in depth

c)

Fibre attenuation

d)

Adaptive frequency hopping

83.

A phishing campaign targets employees with personalized details collected from social media. Which concept explains why the attack is convincing?

a)

High bandwidth

b)

Contextual specificity

c)

Random noise injection

d)

DNS balancing

84.

A system restricts employees to viewing data relevant only to their tasks, preventing curiosity-driven browsing of confidential records. What key security idea does this follow?

a)

Principle of least privilege

b)

Redundant directory mapping

c)

Universal access control

d)

Recursive encryption

85.

A cybersecurity officer states that “every breach is also a failure of organizational culture.” What does this imply theoretically?

a)

Cybersecurity is solely technical

b)

Behaviour and governance shape security posture

c)

Encryption speed determines culture

d)

Culture has no measurable impact on breaches

86.

A company automates encryption but leaves key management to manual processes handled by one employee. What major risk exists?

a)

Lack of redundancy in key control

b)

Faster encryption speed

c)

Reduced access latency

d)

High-quality password caching

87.

A privacy assessment finds that a company collects more data than needed “just in case it becomes useful later.” Which theoretical risk does this create?

a)

Storage overflow

b)

Unnecessary exposure due to excessive retention

c)

Reduced CPU threads

d)

Duplicate packet flows

88.

A cyberattack exploits the fact that users often click quickly without thinking. Which psychological factor is MOST relevant?

a)

Time pressure and cognitive shortcuts

b)

Increased working memory capacity

c)

Rational evaluation processes

d)

Passive information filtering

89.

An organization depends heavily on automated monitoring but rarely verifies alerts manually. What vulnerability does this create?

a)

Overreliance on automation may mask false negatives

b)

Excessive DNS records

c)

Slow packet transmission

d)

Misleading GUI theming

90.

A data center practices disaster recovery by running simulations without informing employees beforehand. What important benefit does this provide?

a)

Accurate measurement of real-world response behaviour

b)

Increased system cooling

c)

Improved text rendering on dashboards

d)

Elevated system cache lifetime