Font size
WorksheetsChapter 7 Security, Ethics and Privacy – 30 MCQs
Total questions: 90
Worksheet time: 45mins
Which of the following is a common sign of a phishing email?
A personal greeting
A message asking for login details
An email from your friend
A normal company update
What is the main purpose of a password?
To make the device run faster
To control who can access a system
To save storage space
To update the software
Which is an example of malware?
Antivirus
Worm
Router
Keyboard
When a computer becomes very slow because a program is copying itself repeatedly, this is likely caused by a:
Firewall
Virus
Monitor
Backup file
What does encryption do?
Deletes old files
Turns readable data into unreadable form
Speeds up the Internet
Makes graphics clearer
Which of the following is a good security practice?
Sharing passwords
Using easy passwords
Updating software
Clicking unknown links
Which device is used to verify a fingerprint?
Scanner
Biometric reader
Printer
Mouse
Which attack tries to overload a website so it becomes unavailable?
Spoofing
DDoS
Backup
Logging
What is the main purpose of a firewall?
Printing documents
Blocking unauthorized access
Saving battery power
Playing media
Social engineering mainly targets:
System hardware
Human weakness
Internet speed
Backup files
What is an example of personal data?
Movie rating
Weather report
Your IC number
File size
Cookies on a website are used to:
Steal credit cards
Improve user experience
Delete viruses
Increase RAM
Unauthorized access means:
Entering a system without permission
Printing documents
Closing an application
Restarting a computer
Which action helps protect your privacy online?
Posting personal details publicly
Using strong passwords
Connecting to any free WiFi
Turning off antivirus
If your files suddenly become encrypted and you are asked to pay money, this is:
Firewall update
Ransomware attack
System maintenance
Normal backup process
Information ethics mainly deals with:
How people use technology responsibly
How to design hardware
How screens display colours
How fast data transfers occur
A backup is used when:
You need to open YouTube
Data is lost or damaged
CPU is overheating
Internet is lagging
Which is a safe behaviour online?
Downloading unknown attachments
Ignoring updates
Using two-factor authentication
Clicking random ads
A digital certificate is used to:
Speed up websites
Confirm a website is real
Slow down cyberattacks
Change screen settings
Which of the following is a security threat?
Healthy posture
Malware infection
Keyboard cleaning
Screen brightness
Carpal Tunnel Syndrome is related to:
Network speed
Repetitive wrist movement
Antivirus updates
Keyboard colour
Which of the following is a privacy concern?
Sharing your location publicly
Charging your laptop
Installing updates
Changing wallpaper
What is the first thing you should do when receiving a suspicious message?
Click the link to check
Reply immediately
Delete or report it
Forward it to friends
Why do companies use access control?
To manage who can see or use data
To reduce electricity bills
To speed up downloads
To change app colours
What is an example of ethical behaviour in IT?
Using cracked software
Respecting user privacy
Ignoring copyrights
Sharing confidential data
A password like “12345” is considered:
Strong
Very secure
Weak
Encrypted
Which action helps avoid malware?
Downloading from unsafe sites
Installing antivirus
Disabling updates
Turning off the firewall
Why is two-factor authentication safer?
It removes the need for passwords
It requires two forms of verification
It increases Internet speed
It shortens login time
Which is an example of information theft?
Losing your water bottle
Someone stealing your data
Watching a video
Resetting your account
What is the main goal of cybersecurity?
Make computers faster
Protect systems and data from threats
Increase screen brightness
Create more apps
An organization implements an advanced firewall and intrusion detection system, yet attackers still manage to access sensitive files by obtaining the login details of a long-time employee through subtle psychological manipulation. Which statement BEST explains the deeper systemic vulnerability?
Technical systems lacked encryption
Human element remains the weakest point in security
Network segmentation was not properly tested
Firewall rules were too permissive
An IT department notices that despite strong security tools, employees continue to ignore software update notifications, increasing vulnerability windows. Which concept BEST describes this behavioural risk?
System downtime tolerance
Compliance fatigue
Access privilege misuse
Redundancy misalignment
A company encrypts all stored data using strong cryptographic algorithms, yet attackers still manage to read the data by exploiting a memory dump after a program crash. Which theoretical security limitation does this illustrate?
Encryption is obsolete against modern attackers
Data in use remains vulnerable even if stored data is encrypted
Encryption increases system memory usage
Attackers can always bypass encryption if they use brute force
Two organizations adopt identical antivirus software. One suffers frequent malware outbreaks, while the other experiences almost none. Both have similar hardware. Which factor MOST likely explains the difference?
Antivirus update schedule and user behaviour
Brand of RAM installed
SSD fragmentation
Background processes with high priority
A multinational company creates a privacy policy but provides it only in English, leaving non-English speaking workers unaware of its conditions. Which ethical problem arises?
Lack of technical redundancy
Inequitable access to information
Overuse of encryption keys
Poorly implemented DNS records
An employee discovers a flaw allowing access to confidential data but does not report it, believing “no harm was done.” Which ethical framework does the employee violate MOST?
Legal compliance law
Professional duty of care
Encryption assurance
Network segmentation policy
An organization uses a rule requiring employees to “handle all personal data minimally.” Which principle is being enforced?
Data minimization
Network throttling
Multi-layer caching
Zero-trust encryption bursting
A company redesigns its security architecture to assume everyone, including internal employees, is a potential threat. Which model is being adopted?
Open-access computing
Zero-trust security
Public-key federation
Hierarchical privilege indexing
A CEO demands full monitoring of all employees’ digital activity “to maximize productivity,” but employees express strong discomfort, citing privacy concerns. What fundamental ethical tension arises?
Integrity vs. redundancy
Organizational oversight vs. individual privacy
Firewall throughput vs. encryption
Data mining vs. firmware updates
A company refuses to update its Acceptable Use Policy despite new security threats emerging. Which issue does this create over time?
Reduced cache consistency
Policy obsolescence and weakened governance
More efficient load balancing
Guaranteed user compliance
Remote employees frequently access corporate systems through personal devices. What theoretical risk does this environment exemplify?
Controlled integration
Expanded attack surface
Physical redundancy
Fibre-optic signal decay
A machine-learning fraud detection system locks valid users out during peak hours. The company argues, “false positives are acceptable for high security.” Which ethical concern is raised?
Cognitive load imbalance
Fairness and proportionality in security controls
Excessive data compression
Inconsistent DNS handshakes
During an audit, it was found that only administrators understand how logs are generated and stored, making fraud detection difficult for the rest of the team. Which issue does this represent?
Excessive privilege distribution
Knowledge centralization and lack of transparency
Faulty data replication
Low virtual memory allocation
An organization encrypts all data, trains employees thoroughly, installs firewalls, and monitors internal behaviour, yet still suffers data leakage through screenshots taken on phones. What security reality does this illustrate?
Perfect security is achievable with the right tools
Technological controls cannot eliminate all human workarounds
Screenshots cannot be considered data breaches
Encryption prevents screenshots from being harmful
A privacy officer argues that “data collection should always match the purpose it was gathered for.” Which privacy framework supports this argument?
Data lifecycle depletion
Purpose limitation
Audit recursion
Least-frequency replication
An IT director insists on using extremely long, complex passwords without implementing password managers. Staff begin storing passwords on paper. Which unintended risk is introduced?
Higher network speed
Increased physical security vulnerabilities
More efficient encryption
Reduced malware risk
A company provides cybersecurity awareness training once a year. Research indicates most employees forget key information within weeks. Which theoretical weakness does this show?
Training frequency misalignment
Algorithmic decay
Hyper-threading confusion
Virtualization overhead
Two-factor authentication is implemented across an organization. However, attackers still gain access using compromised session tokens. Which vulnerability does this highlight?
Token hijacking bypasses identity verification
Password strength must be doubled
Users reused their PINs frequently
Tokens prevent all forms of unauthorized access
A critical server stores logs but overwrites old entries every 24 hours due to storage limitations. How does this undermine security?
Logs lose aesthetic clarity
Incident investigation becomes incomplete
Password hashing becomes impossible
CPU cooling becomes inefficient
Employees become overly reliant on biometric authentication and stop creating strong passwords. Which security risk emerges?
Credential fallback weakness
Elevated GPU temperature
Excessive browser caching
DNS failover loops
The board of directors requests minimal encryption to maintain performance levels. The security team disagrees, warning this may violate laws protecting user data. Which principle is in conflict?
Efficiency vs. compliance
Redundancy vs. caching
VLAN purity
System acceleration
A malware variant disables antivirus services before executing its payload. Which defence principle was MOST critically compromised?
Fail-open architecture
Defence in depth
Fibre attenuation
Adaptive frequency hopping
A phishing campaign targets employees with personalized details collected from social media. Which concept explains why the attack is convincing?
High bandwidth
Contextual specificity
Random noise injection
DNS balancing
A system restricts employees to viewing data relevant only to their tasks, preventing curiosity-driven browsing of confidential records. What key security idea does this follow?
Principle of least privilege
Redundant directory mapping
Universal access control
Recursive encryption
A cybersecurity officer states that “every breach is also a failure of organizational culture.” What does this imply theoretically?
Cybersecurity is solely technical
Behaviour and governance shape security posture
Encryption speed determines culture
Culture has no measurable impact on breaches
A company automates encryption but leaves key management to manual processes handled by one employee. What major risk exists?
Lack of redundancy in key control
Faster encryption speed
Reduced access latency
High-quality password caching
A privacy assessment finds that a company collects more data than needed “just in case it becomes useful later.” Which theoretical risk does this create?
Storage overflow
Unnecessary exposure due to excessive retention
Reduced CPU threads
Duplicate packet flows
A cyberattack exploits the fact that users often click quickly without thinking. Which psychological factor is MOST relevant?
Time pressure and cognitive shortcuts
Increased working memory capacity
Rational evaluation processes
Passive information filtering
An organization depends heavily on automated monitoring but rarely verifies alerts manually. What vulnerability does this create?
Overreliance on automation may mask false negatives
Excessive DNS records
Slow packet transmission
Misleading GUI theming
A data center practices disaster recovery by running simulations without informing employees beforehand. What important benefit does this provide?
Accurate measurement of real-world response behaviour
Increased system cooling
Improved text rendering on dashboards
Elevated system cache lifetime
An organization implements an advanced firewall and intrusion detection system, yet attackers still manage to access sensitive files by obtaining the login details of a long-time employee through subtle psychological manipulation. Which statement BEST explains the deeper systemic vulnerability?
Technical systems lacked encryption
Human element remains the weakest point in security
Network segmentation was not properly tested
Firewall rules were too permissive
An IT department notices that despite strong security tools, employees continue to ignore software update notifications, increasing vulnerability windows. Which concept BEST describes this behavioural risk?
System downtime tolerance
Compliance fatigue
Access privilege misuse
Redundancy misalignment
A company encrypts all stored data using strong cryptographic algorithms, yet attackers still manage to read the data by exploiting a memory dump after a program crash. Which theoretical security limitation does this illustrate?
Encryption is obsolete against modern attackers
Data in use remains vulnerable even if stored data is encrypted
Encryption increases system memory usage
Attackers can always bypass encryption if they use brute force
Two organizations adopt identical antivirus software. One suffers frequent malware outbreaks, while the other experiences almost none. Both have similar hardware. Which factor MOST likely explains the difference?
Antivirus update schedule and user behaviour
Brand of RAM installed
SSD fragmentation
Background processes with high priority
A multinational company creates a privacy policy but provides it only in English, leaving non-English speaking workers unaware of its conditions. Which ethical problem arises?
Lack of technical redundancy
Inequitable access to information
Overuse of encryption keys
Poorly implemented DNS records
An employee discovers a flaw allowing access to confidential data but does not report it, believing “no harm was done.” Which ethical framework does the employee violate MOST?
Legal compliance law
Professional duty of care
Encryption assurance
Network segmentation policy
An organization uses a rule requiring employees to “handle all personal data minimally.” Which principle is being enforced?
Data minimization
Network throttling
Multi-layer caching
Zero-trust encryption bursting
A company redesigns its security architecture to assume everyone, including internal employees, is a potential threat. Which model is being adopted?
Open-access computing
Zero-trust security
Public-key federation
Hierarchical privilege indexing
A CEO demands full monitoring of all employees’ digital activity “to maximize productivity,” but employees express strong discomfort, citing privacy concerns. What fundamental ethical tension arises?
Integrity vs. redundancy
Organizational oversight vs. individual privacy
Firewall throughput vs. encryption
Data mining vs. firmware updates
A company refuses to update its Acceptable Use Policy despite new security threats emerging. Which issue does this create over time?
Reduced cache consistency
Policy obsolescence and weakened governance
More efficient load balancing
Guaranteed user compliance
Remote employees frequently access corporate systems through personal devices. What theoretical risk does this environment exemplify?
Controlled integration
Expanded attack surface
Physical redundancy
Fibre-optic signal decay
A machine-learning fraud detection system locks valid users out during peak hours. The company argues, “false positives are acceptable for high security.” Which ethical concern is raised?
Cognitive load imbalance
Fairness and proportionality in security controls
Excessive data compression
Inconsistent DNS handshakes
During an audit, it was found that only administrators understand how logs are generated and stored, making fraud detection difficult for the rest of the team. Which issue does this represent?
Excessive privilege distribution
Knowledge centralization and lack of transparency
Faulty data replication
Low virtual memory allocation
An organization encrypts all data, trains employees thoroughly, installs firewalls, and monitors internal behaviour, yet still suffers data leakage through screenshots taken on phones. What security reality does this illustrate?
Perfect security is achievable with the right tools
Technological controls cannot eliminate all human workarounds
Screenshots cannot be considered data breaches
Encryption prevents screenshots from being harmful
A privacy officer argues that “data collection should always match the purpose it was gathered for.” Which privacy framework supports this argument?
Data lifecycle depletion
Purpose limitation
Audit recursion
Least-frequency replication
A IT director insists on using extremely long, complex passwords without implementing password managers. Staff begin storing passwords on paper. Which unintended risk is introduced?
Higher network speed
Increased physical security vulnerabilities
More efficient encryption
Reduced malware risk
A company provides cybersecurity awareness training once a year. Research indicates most employees forget key information within weeks. Which theoretical weakness does this show?
Training frequency misalignment
Algorithmic decay
Hyper-threading confusion
Virtualization overhead
Two-factor authentication is implemented across an organization. However, attackers still gain access using compromised session tokens. Which vulnerability does this highlight?
Token hijacking bypasses identity verification
Password strength must be doubled
Users reused their PINs frequently
Tokens prevent all forms of unauthorized access
A critical server stores logs but overwrites old entries every 24 hours due to storage limitations. How does this undermine security?
Logs lose aesthetic clarity
Incident investigation becomes incomplete
Password hashing becomes impossible
CPU cooling becomes inefficient
Employees become overly reliant on biometric authentication and stop creating strong passwords. Which security risk emerges?
Credential fallback weakness
Elevated GPU temperature
Excessive browser caching
DNS failover loops
The board of directors requests minimal encryption to maintain performance levels. The security team disagrees, warning this may violate laws protecting user data. Which principle is in conflict?
Efficiency vs. compliance
Redundancy vs. caching
VLAN purity
System acceleration
A malware variant disables antivirus services before executing its payload. Which defence principle was MOST critically compromised?
Fail-open architecture
Defence in depth
Fibre attenuation
Adaptive frequency hopping
A phishing campaign targets employees with personalized details collected from social media. Which concept explains why the attack is convincing?
High bandwidth
Contextual specificity
Random noise injection
DNS balancing
A system restricts employees to viewing data relevant only to their tasks, preventing curiosity-driven browsing of confidential records. What key security idea does this follow?
Principle of least privilege
Redundant directory mapping
Universal access control
Recursive encryption
A cybersecurity officer states that “every breach is also a failure of organizational culture.” What does this imply theoretically?
Cybersecurity is solely technical
Behaviour and governance shape security posture
Encryption speed determines culture
Culture has no measurable impact on breaches
A company automates encryption but leaves key management to manual processes handled by one employee. What major risk exists?
Lack of redundancy in key control
Faster encryption speed
Reduced access latency
High-quality password caching
A privacy assessment finds that a company collects more data than needed “just in case it becomes useful later.” Which theoretical risk does this create?
Storage overflow
Unnecessary exposure due to excessive retention
Reduced CPU threads
Duplicate packet flows
A cyberattack exploits the fact that users often click quickly without thinking. Which psychological factor is MOST relevant?
Time pressure and cognitive shortcuts
Increased working memory capacity
Rational evaluation processes
Passive information filtering
An organization depends heavily on automated monitoring but rarely verifies alerts manually. What vulnerability does this create?
Overreliance on automation may mask false negatives
Excessive DNS records
Slow packet transmission
Misleading GUI theming
A data center practices disaster recovery by running simulations without informing employees beforehand. What important benefit does this provide?
Accurate measurement of real-world response behaviour
Increased system cooling
Improved text rendering on dashboards
Elevated system cache lifetime
