Heads up: opening this section reveals every question, every option, and the correct answer for this round. If you came here to play, scroll up and hit Play first.
Question 1: What is the primary goal of data minimization in a workplace?
- Collecting only necessary data
- Storing data for as long as possible
- Sharing data with all departments
- Reducing the file size of documents
Answer: A. Collecting only necessary data
Explanation: Data minimization ensures that organizations only collect and process the specific personal information required for a stated purpose, which reduces risk in the event of a data breach.
Question 2: Which of the following is a common sign of a phishing attempt?
- Links to official company portals
- Urgent requests for sensitive info
- Personalized professional greetings
- Correct spelling and grammar
Answer: B. Urgent requests for sensitive info
Explanation: Phishing emails often create a false sense of urgency or fear to pressure recipients into clicking malicious links or revealing credentials without verifying the sender's identity.
Question 3: What does the principle of 'least privilege' mean for access control?
- Restricting access to weekends only
- Giving users minimum necessary access
- Granting full admin rights to all
- Sharing passwords among team members
Answer: B. Giving users minimum necessary access
Explanation: The principle of least privilege dictates that employees should only have the specific access rights necessary to perform their job functions, limiting potential damage from compromised accounts.
Question 4: When should you report a suspected data security incident?
- Only if data was actually stolen
- Immediately upon discovery
- At the end of the business week
- After investigating it yourself
Answer: B. Immediately upon discovery
Explanation: Reporting incidents immediately allows security teams to contain threats quickly, minimizing potential impact and ensuring compliance with organizational incident response protocols.
Question 5: What is the safest way to share sensitive files externally?
- Posting to a public cloud folder
- Using an unencrypted USB drive
- Sending via standard email
- Encrypted file transfer services
Answer: D. Encrypted file transfer services
Explanation: Using encrypted transfer services ensures that data remains protected during transit, preventing unauthorized interception by third parties who might access the communication channel.
Question 6: Which of these is considered 'Personal Data'?
- An employee's home address
- General company revenue figures
- Publicly available product specs
- Office building floor plans
Answer: A. An employee's home address
Explanation: Personal data refers to any information that relates to an identified or identifiable individual, such as home addresses, personal phone numbers, or private email addresses.
Question 7: What is the best practice for managing workplace passwords?
- Sharing passwords via chat apps
- Using unique, complex passwords
- Writing passwords on sticky notes
- Using the same password for all
Answer: B. Using unique, complex passwords
Explanation: Using unique, complex passwords for every account prevents a single compromised password from granting attackers access to multiple systems across your professional digital environment.
Question 8: Why is 'consent' important when processing personal data?
- It removes all security risks
- It speeds up data entry tasks
- It is only required for marketing
- It validates legal processing
Answer: D. It validates legal processing
Explanation: Obtaining valid consent ensures that individuals are aware of how their data is being used and have agreed to that processing, which is a core requirement for privacy.
Question 9: What should you do before leaving your desk for a break?
- Close all browser tabs
- Turn off the office lights
- Lock your computer screen
- Log out of the company network
Answer: C. Lock your computer screen
Explanation: Locking your computer screen prevents unauthorized individuals from accessing your workstation, viewing sensitive information, or performing actions under your user account while you are away.
Question 10: What is the risk of using public Wi-Fi for work?
- Automatic software updates
- Incompatibility with office apps
- Data interception by attackers
- Slow internet connection speeds
Answer: C. Data interception by attackers
Explanation: Public Wi-Fi networks are often unsecured, making it easy for attackers to intercept data transmitted between your device and the network, potentially exposing sensitive information.