wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

GEC9 Final Exam SY25-26

Total questions: 80

Worksheet time: 40mins

Name
Class
Date
1.

A pharmaceutical company generates billions of data points daily from laboratory sensors, clinical trials, and patient feedback. The complexity of managing this massive, constantly updating data stream highlights the importance of which two "Vs" of Big Data?

a)

Volume and Variety

b)

Variety and Value

c)

Volume and Velocity

d)

Velocity and Value

2.

A company creates a proprietary statistical model that accurately predicts market shifts. They sell the model’s predictions to hundreds of clients simultaneously without diminishing the model’s value to the original purchaser. This economic characteristic of the model (information) is best described as:

a)

Intangible

b)

Scalable

c)

Non-Rivalrous

d)

Processed and Organized

3.

An IT firm develops software robots (bots) to automatically extract data from incoming customer application forms and inputs the data into the main database system, replacing manual keystrokes. This specific automation method is known as:

a)

IT Automation

b)

Customer Support Automation

c)

Home Automation

d)

Robotics Process Automation (RPA)

4.

A manufacturing plant installs IoT sensors to collect machine performance data (the hardware part), which is sent wirelessly to a centralized dashboard (the software part). This capability ensures executives can quickly identify and fix production bottlenecks, primarily demonstrating:

a)

Security and Service enhancement

b)

Data Analysis and Synchronization

c)

Connectivity management

d)

System requirements definition

5.

A historical analysis of IT evolution reveals that the period characterized by the invention of the telephone in 1876 and the development of the first radio in 1894 marked the beginnings of telecommunication. This period is classified as the:

a)

Pre-Mechanical Age

b)

Mechanical Age

c)

Electromechanical Age

d)

Electronic Age

6.

An individual suffering from Decision Paralysis is unable to make investment choices because they are overwhelmed by constant real-time updates and notifications across dozens of financial platforms. This situation is a direct consequence of:

a)

Asymmetric Information

b)

Market Efficiency

c)

Information Overload

d)

Information Costs

7.

To combat the problem described in Q6, a company implements a knowledge management system to store and retrieve only the most relevant information needed for core tasks. This aligns with which strategy for managing Information Overload?

a)

Automation

b)

Personalization

c)

Effective Data Management

d)

Utilizing the Velocity of Data

8.

A city implements smart networks focused on renewable energy distribution and infrastructure upgrades, optimizing resource usage across neighborhoods. This specific deployment falls under the IoT application of:

a)

Connected Industries

b)

Connected Buildings

c)

Connected Cars

d)

Smart Energy

9.

A corporation spends significant capital and human resources hiring analysts to acquire and process proprietary consumer behavior data from social media and sales figures. This expenditure is fundamentally categorized as:

a)

Asymmetric Information

b)

Market Efficiency

10.

Which scenario best demonstrates the concept of Technological Unemployment as a negative impact of ICT?

a)

A factory worker suffers low self-esteem due to online comparisons.

b)

A computer system emits gases like carbon dioxide.

c)

A data entry job is eliminated because a new AI system automates data processing.

d)

An unauthorized user commits identity fraud.

11.

Why is Cloud Computing recognized as a crucial tool for managing Big Data?

a)

It simplifies the integration of structured and unstructured data.

b)

It strictly follows the rules of Netiquette.

c)

It provides scalable infrastructure and resources necessary for data storage, processing, and on-demand computing for enormous, complex datasets.

d)

It reduces the physical cost of acquiring information.

12.

The most critical challenge facing the widespread deployment of highly mobile IoT sensors used in remote disaster management is often related to:

a)

System Requirements definitions.

b)

Connectivity protocols.

c)

Power Requirements, specifically extending battery life.

d)

Development capabilities of the smart things.

13.

The integration of IT with media broadcasting technologies and audio/video processing and transmission is specifically known as:

a)

Information Technology (IT).

b)

IT Automation.

c)

Information and Communication Technology (ICT)

d)

Data Management.

14.

A salesperson knows that a product has critical flaws that they actively conceal from the customer, maintaining an informational advantage during the sale. This relationship is a defining example of:

a)

Information Costs.

b)

Asymmetric Information.

c)

Information Overload.

d)

Market Efficiency.

15.

If a historian studies Charles Babbage inventing his engines and Blaise Pascal inventing the Pascaline mechanical computer, they are analyzing the developments that characterized the:

a)

Pre-Mechanical Age.

b)

Mechanical Age.

c)

Electromechanical Age.

d)

Electronic Age.

16.

A company uses educational technology to provide online resources, digital support materials, and monitor student progress to enhance learning. This activity aligns with which positive impact of ICT?

a)

Improved Communication.

b)

Mechanized Agriculture.

c)

Improved Education and Learning Process

d)

Easy Access Information.

17.

If data is merely acquired and stored (raw data), why is it not yet considered an Information Resource?

a)

It must be intangible to be a resource.

b)

It must be scalable and non-rivalrous.

c)

Information is defined as data that has been processed, organized, and made valuable for decision-making.

d)

Raw data only exists in the Mechanical Age.

18.

A data scientist works with massive datasets containing structured, semi-structured, and unstructured data formats (e.g., database tables, sensor logs, and social media text). Managing this variety is defined as the Big Data Management challenge of:

a)

Data Security.

b)

Data Quality.

c)

Data Integration.

d)

Data Velocity.

19.

If a large corporation uses IoT connectivity, including remote access to heavy equipment and machinery for manufacturing and production, they are operating within which specific application area?

a)

Smart Cities.

b)

Connected Buildings.

c)

Connected Industries.

d)

Smart Energy.

20.

A company implements policies to ensure data is properly acquired, organized, stored, and protected to maintain its accessibility and value. This fundamental organizational activity is known as:

a)

Information Economics.

b)

Big Data Technologies.

c)

Data Management.

d)

IT Automation.

21.

A system administrator configures the operating system to allocate temporary storage (RAM) to a graphics editing application and ensures that memory is freed up when the user closes the program. This activity falls under the OS core function of:

a)

Process Management.

b)

File System Management.

c)

Memory Management.

d)

Device Management.

22.

A company requires a network solution to connect multiple Local Area Networks (LANs) within its sprawling university campus, creating a unified internal environment restricted to the physical boundaries of the institution. This requirement best fits a:

a)

Metropolitan Area Network (MAN).

b)

Wide Area Network (WAN).

c)

Campus Area Network (CAN).

d)

Virtual Private Network (VPN).

23.

A developer is designing a system and spends a significant amount of time assessing the potential for the program to be used to spread disinformation or create harmful social biases. This adherence to foresight directly aligns with which Computer Ethics Commandment?

a)

8th (Appropriate Intellectual Output).

b)

5th (Bear False Witness).

c)

9th (Think about the social consequences).

d)

1st (Harm Other People).

24.

Which characteristic defines the fundamental difference between a Local Area Network (LAN) and a Wide Area Network (WAN)?

a)

The protocols used (e.g., TCP/IP).

b)

The requirement for a VPN.

c)

The geographical coverage area.

d)

The ability to share resources.

25.

A software engineer needs an operating system that is free to use and distribute, highly customizable, and known for robust security and stability for running high-demand servers. The most appropriate choice is:

a)

Windows OS

b)

Linux

c)

macOS

d)

Embedded OS

26.

An individual uses computer software to secretly gain access to a competitor’s proprietary client list, intending to copy the data and use it for personal gain. This action is categorized as a violation of the Commandment:

a)

Not to interfere with computer work.

b)

Not to use a computer to steal.

c)

Not to bear false witness.

d)

Not to snoop around in files.

27.

A company requires a network to have high reliability. If the network experiences frequent downtimes and failures, the administrator must work to reduce the:

a)

Transit Time.

b)

Response Time.

c)

Frequency at which network failures take place.

d)

Capability of Connected Hardware.

28.

An application developer copies the entire source code of a copyrighted financial modeling software and distributes it online for free. This violation primarily targets the 6th Commandment, which prohibits:

a)

Snooping in computer files.

b)

Appropriating intellectual output.

c)

Copying or using proprietary software for which you have not paid.

d)

Using computer resources without authorization.

29.

When discussing network quality, ensuring that shared data is protected from any unauthorized user or access pertains directly to the criterion of:

a)

Reliability.

b)

Performance.

c)

Security.

d)

Transit Time.

30.

A user attempts to print a document, but the operating system handles the spooling, communicates with the printer (an I/O device), and sends the print job. This interaction is managed by the OS function of:

a)

Networking.

b)

Process Management.

c)

Device Management.

d)

Error Detection and Handling.

31.

An individual posts deliberately false information about a public figure using social media to damage their reputation. This use of computer technology is a violation of the 5th Commandment:

a)

Thou shalt not interfere with other people’s work.

b)

Thou shalt not use a computer to harm other people.

c)

Thou shalt not use a computer to bear false witness.

d)

Thou shalt not appropriate intellectual output.

32.

The use of a Virtual Private Network (VPN) is critical for a company because it allows employees to securely:

a)

Manage internal physical hardware.

b)

Connect multiple LANs within a single campus.

c)

Create a private network over a public network (like the internet).

d)

Use an Embedded OS on mobile devices.

33.

A designer chooses macOS for its working environment. This choice is often motivated by the OS's advantages in superior graphics and multimedia capabilities and its:

a)

Open-source nature.

b)

Strong gaming support.

c)

Seamless experience across the Apple ecosystem.

d)

Ease of use for general users.

34.

The system requires a password entry and sometimes a fingerprint scan before granting access to files. This mechanism is provided by the OS function of:

a)

User Interface (UI).

b)

Networking.

c)

Security and Access Control.

d)

Memory Management.

35.

An employee attempts to covertly access and read sensitive files stored on a co-worker's computer. This act constitutes a breach of the Commandment:

a)

Not to interfere with computer work.

b)

Not to snoop around in other people's computer files.

c)

Not to use a computer to steal.

d)

To ensure consideration and respect.

36.

A complex industrial machine, such as heavy equipment used in the oil and gas industry, typically uses an operating system that is tailored for a specific, often minimal-resource, dedicated task. This is an example of a(n):

a)

Desktop OS (Windows).

b)

Server OS.

c)

Mobile OS.

d)

Embedded OS.

37.

If an application developer creates a program specifically designed to overload the server resources of a non-profit organization, slowing down their essential services, this action violates the Commandment:

a)

Thou shalt not use a computer to steal.

b)

Thou shalt not interfere with other people’s computer work.

c)

Thou shalt not use a computer to harm other people.

d)

Thou shalt not appropriate intellectual output.

38.

The rules governing how individuals should behave properly online and be respectful and courteous during communication are collectively known as:

a)

Computer Ethics.

b)

Access Control.

c)

Netiquette.

d)

Data Management.

39.

A network administrator measures the quality of the network based on the time elapsed between sending a request for data and receiving the resulting data. This metric is known as:

a)

Transit Time.

b)

Security.

c)

Reliability.

d)

Response Time.

40.

The primary role of the Operating System is described as acting as an intermediary between users and the:

a)

User Interface (UI).

b)

Processes.

c)

Hardware.

d)

Network connections.

41.

A security policy mandates that an employee must be limited to only the minimum access rights necessary to perform their specific job functions, thereby reducing potential damage from internal errors or breaches. This practice is known as the:

a)

Strong Authentication Method.

b)

Data Encryption principle.

c)

Least Privilege principle.

d)

Security Training Awareness.

42.

A company hosts its customer databases on a third-party server infrastructure accessible via the internet. Protecting this data specifically requires implementing techniques like Multi-factor Authentication (MFA) and encryption at this hosted location. This specialized protection falls under the domain of:

a)

Network Security.

b)

Application Security.

c)

Cloud Security.

d)

Endpoint Security.

43.

Which situation represents a vulnerability based on Lack of User Awareness?

a)

A bug in a newly released software update.

b)

Using an easily guessed password like "123456".

c)

A user clicking a deceptive email link that asks for their login credentials.

44.

A major utility company ensures that all industrial machinery and smart devices connected to its power grid are rigorously monitored and secured against unauthorized control and data theft. This specialized focus falls under:

a)

Application Security.

b)

Information Security.

c)

IoT Security.

d)

Data Governance.

45.

If a business wishes to restore its operations quickly following a successful ransomware attack, which strategy must be robust and regularly tested?

a)

Data Encryption.

b)

Backup and Recovery Planning.

c)

Network Segmentation.

d)

Strong Authentication Methods.

46.

An organization implements firewalls and Intrusion Detection Systems (IDS) to secure the network from outside intruders. This practice is the main goal of:

a)

Application Security.

b)

Endpoint Security.

c)

Network Security.

d)

Data Governance.

47.

A security team continuously monitors the source code of a proprietary application before deployment to prevent attacks that exploit inherent errors or flaws in the code. This effort is the primary concern of:

a)

Network Security.

b)

Application Security.

c)

IoT Security.

d)

Data Security.

48.

An attacker targets a popular news website by overwhelming its servers with traffic from thousands of compromised computers, making the website inaccessible to legitimate readers. This is a classic example of a:

a)

Ransomware attack.

b)

Trojan horse.

c)

Denial-of-Service Attack (DoS).

d)

Man-in-the-Middle Attack (MitM).

49.

Why are regular system and software updates crucial for maintaining cybersecurity?

a)

They ensure data is encrypted in transit.

b)

They enforce the Least Privilege principle.

c)

They fix known security weaknesses (vulnerabilities) promptly.

d)

They verify user identity using MFA.

50.

A finance department employee uses a common password for both their corporate email and their personal banking site, creating a severe security weakness. This is a vulnerability categorized as:

a)

Software Bugs.

b)

Weak Passwords.

c)

Lack of User Awareness.

d)

Outdated Software.

51.

An attacker sends a seemingly legitimate email from the "IT Department" instructing recipients to click a link to verify their account or face suspension, aiming to trick them into entering credentials on a fake site. This social engineering threat is a:

a)

Malware.

b)

Ransomware.

c)

Phishing Attack.

d)

Denial-of-Service Attack (DoS).

52.

The three fundamental pillars or goals that Information Security (Data Security) aims to maintain are:

a)

Encryption, Monitoring, and Authentication.

b)

Firewalls, Antivirus, and IDS.

c)

Confidentiality, Integrity, and Availability.

d)

Access Control, Least Privilege, and Data Backup.

53.

A company implements Multi-Factor Authentication (MFA) for all remote access points. The main goal of this strong authentication method is to:

a)

Encrypt data at rest.

b)

Segment the network infrastructure.

c)

Verify user identity to prevent unauthorized access.

d)

Educate users about phishing.

54.

To protect sensitive customer information, a manager dictates who can view, edit, or delete the data, managing permissions and access rights. This overall process of managing and protecting data assets and related decisions is called:

a)

Information Security.

b)

Cloud Security.

c)

Data Governance.

d)

Endpoint Security.

55.

If a security team uses Device Encryption and antivirus software to protect individual employee laptops from being compromised by malware or other threats, they are specifically engaged in:

a)

Application Security.

b)

Endpoint Security.

c)

Network Security.

d)

IoT Security.

56.

Why are organizations advised to implement Security Training Awareness for all personnel?

a)

To guarantee 100% data encryption.

b)

To maintain the least privilege principle.

c)

To educate users to recognize threats and use systems safely.

d)

To secure Wi‑Fi connections.

57.

An attacker successfully compromises a network, but instead of altering the data, they simply monitor all network traffic, intercepting login credentials and financial details being exchanged between two parties. This interception is characteristic of a:

a)

Ransomware attack.

b)

Denial-of-Service Attack (DoS).

c)

Trojan.

d)

Man-in-the-Middle Attack (MitM).

58.

A software application that appears harmless but is actually designed to carry a malicious payload into a system is known as a:

a)

Virus.

b)

Worm.

c)

Trojan.

d)

Spyware.

59.

A company continues to use an unsupported server operating system that is five years old, even though the manufacturer no longer releases security patches for it. This situation creates a severe vulnerability categorized as:

a)

Software Bugs.

b)

Outdated Software or Hardware.

c)

Weak Passwords.

d)

Unsecured Networks.

60.

When data must be protected by converting it into a coded format so that unauthorized persons cannot read it, the organization is prioritizing:

a)

Access Control.

b)

Network Segmentation.

c)

Data Encryption.

d)

Security Training Awareness.

61.

A citizen requests a copy of all the personal information a large online retailer holds about them, including how it was collected and processed. This request falls under the Data Subject’s Right to:

a)

Be informed.

b)

Access.

c)

Rectify.

d)

Object.

62.

A company based in Singapore that does not have an office in the Philippines uses Philippine-based cloud storage servers to process the personal information of its Southeast Asian clients. According to the DPA of 2012, this foreign entity:

a)

Is exempt because the data subjects are non-Filipino.

b)

Must only comply with Singaporean data privacy laws.

c)

Is covered by the DPA because it uses equipment located in the Philippines.

d)

Is covered only if the NPC grants specific authorization.

63.

A politician collects personal health records and religious beliefs from voters during a local campaign. The DPA classifies religious beliefs and health records as requiring the highest level of protection because they fall under the category of:

a)

Basic Personal Information.

b)

Financial Information.

c)

Sensitive Personal Information.

d)

Location Data.

64.

A digital media company hires an outsourcing firm to manage and run its customer mailing list campaigns. In this relationship, the media company is the entity that controls the collection and use, making them the:

a)

Data Subject.

b)

Personal Information Controller.

c)

Personal Information Processor.

d)

National Privacy Commission.

65.

A data subject discovers that a medical facility incorrectly recorded their blood type in their patient profile. They demand that the facility update the file immediately. This action is covered by the Right to:

a)

Be informed.

b)

Access.

c)

Object.

d)

Rectify.

66.

An employee who works for a Personal Information Controller intentionally processes customer phone numbers for an unauthorized personal business venture (unconsented telemarketing). This act constitutes:

a)

Unauthorized Access or Intentional Breach.

b)

Processing of Personal Information for Unauthorized Purposes.

c)

Improper Disposal.

d)

Concealment of Security Breaches.

67.

The maximum fine imposed under the DPA for a single act of Unauthorized Processing of sensitive personal information is:

a)

PHP 500,000.00.

b)

PHP 2,000,000.00.

c)

PHP 1,000,000.00.

d)

PHP 5,000,000.00.

68.

A Data Subject wants to leave their current online service provider and move all their Online Activity Data and stored files to a competitor. Which right allows them to request this information in a commonly used format for easy transfer?

a)

Right to access.

b)

Right to object.

c)

Right to data portability.

d)

Right to erasure or blocking.

69.

Which action is covered by the DPA's exemption clause?

a)

Storing personal usernames and passwords.

b)

Processing information about financial benefits granted by the government, including the name and details of the beneficiary.

c)

Collecting detailed biometric data.

d)

Unauthorized disclosure of financial information.

70.

A Data Controller learns of a massive, confirmed breach involving sensitive personal information but decides to keep the incident hidden from the authorities and the affected parties. This act of Concealment of Security Breaches is punishable by imprisonment ranging from 1 year and 6 months to 5 years and a minimum fine of:

a)

PHP 100,000.00.

b)

PHP 500,000.00.

c)

PHP 1,000,000.00.

d)

PHP 5,000,000.00.

71.

An individual intentionally and unlawfully gains access to a computer system storing personal information. This specific criminal offense is classified as:

a)

Malicious Disclosure.

b)

Processing for Unauthorized Purposes.

c)

Unauthorized Access or Intentional Breach.

d)

Accessing Information Due to Negligence.

72.

A security violation involved both Unauthorized Access (Section 29) and Unauthorized Disclosure (Section 32) committed by the same individual. Since this constitutes a Combination or Series of Acts, the perpetrator faces increased penalties, with imprisonment ranging from three (3) years to six (6) years and a maximum fine of:

a)

PHP 2,000,000.00.

b)

PHP 1,000,000.00.

c)

PHP 5,000,000.00.

d)

PHP 500,000.00.

73.

Big Data, characterized by its Volume, Variety, and Velocity, requires advanced technologies for processing because it:

a)

Is always subject to the Right to Rectify.

b)

Cannot be processed with traditional data-processing tools.

c)

Is exempt from Data Privacy laws.

d)

Must utilize IT Automation.

74.

The DPA aims to protect Financial Information. Which example below falls under this category?

a)

GPS coordinates.

b)

Social Security Number.

c)

Educational certificates.

d)

Credit card and bank account details.

75.

If a Data Subject suffers actual harm or injury due to a violation of their rights under the DPA, the Data Subject is entitled to exercise the Right to:

a)

File a complaint.

b)

Data portability.

c)

Object.

d)

Damages.

76.

A Personal Information Controller is transitioning from paper files to digital storage. If they fail to adequately shred the paper files, leaving them in an accessible area, they commit the offense of:

a)

Unauthorized Processing.

b)

Unauthorized Disclosure.

c)

Improper Disposal.

d)

Accessing Information Due to Negligence.

77.

To mitigate the risk of employees Accessing Personal Information Due to Negligence (Section 26), the Personal Information Controller should primarily enforce stronger:

a)

Compliance with foreign jurisdiction laws.

b)

Security Training Awareness and Access Control policies.

c)

Rights to Erasure or Blocking.

d)

Cloud Computing scalability.

78.

If a company uses Fingerprints or Facial Recognition Data for employee authentication, they are handling a specific type of protected information known as:

a)

Location Data.

b)

Biometric Data.

c)

Behavioral Data.

d)

Online Account Information.

79.

Which government body is designated to administer the DPA of 2012 and handle complaints related to data privacy violations?

a)

The Department of Justice.

b)

The Supreme Court.

c)

The National Privacy Commission.

d)

The Personal Information Controller.

80.

When Big Data is used in economic systems, it is essential because it is identified as a key asset driving new business models, innovation, and:

a)

Information Costs reduction.

b)

Asymmetric Information maximization.

c)

Economic growth.

d)

Decision Paralysis.