Q&A Study Guide
Every question & answer built from the "Connecting & Communicating Online" and "Digital
Security, Ethics & Privacy" chapter pages — plus difficult scenario-based questions
This study guide contains 67 questions and answers, organized into six topical sections (A–F) covering every
concept found in the source pages, followed by a set of 12 difficult, scenario-based questions that require
applying multiple concepts together.
A. The Internet & Connecting Online
10 questions
Q1. What is the Internet?
A: The Internet is a worldwide collection of networks that connects millions of businesses, government
agencies, educational institutions, and individuals. Each network on the Internet provides resources that add
to the abundance of goods, services, and information available.
Q2. What are the two general ways to connect a computer or mobile device to the Internet?
A: Wired connections, where a device physically attaches via a cable or wire to a communications device
such as a modem, and wireless connections, where a device uses built-in wireless capability or a wireless
modem to transmit data over the air.
Q3. What is a dongle?
A: A dongle is a small wireless modem that plugs into a computer (often via a USB port) and enables it to
connect wirelessly to the Internet.
Q4. What is an Internet service provider (ISP)?
A: A business that provides individuals and organizations access to the Internet, free or for a fee, often
bundled with additional services such as email and online storage.
Q5. Define bandwidth and explain how it relates to data transfer.
A: Bandwidth is the amount of data that travels over a network. A higher bandwidth means more data
transmits; data sizes are typically stated in megabytes (MB) and gigabytes (GB).
Q6. According to the Data Usage table, roughly how much data does one hour of HD streaming
video use compared to sending 100 text-only emails?
A: One hour of HD streaming video uses about 5–20 GB, while sending/receiving 100 text-only email
messages uses only about 3–6 MB — HD video can use over a thousand times more data.
Q7. What is a Wi-Fi hot spot?
A: A wireless network that provides Internet connections to mobile computers and devices, commonly found
in places such as coffee shops, malls, schools, hotels, and airports.
Q8. What does tethering mean?
Digital Security & Internet Fundamentals — Q&A Study Guide | Page 1
A: Tethering transforms a smartphone or Internet-capable tablet into a portable communications device (a
mobile hot spot) that shares its Internet access wirelessly with other computers and devices.
Q9. Name four precautions for using a public Wi-Fi hot spot safely.
A: Avoid typing passwords or financial information unless the site's address begins with "https"; sign out of
websites and close the window when finished; disable your wireless connection when you're done using it;
and never leave your computer or device unattended, including watching for over-the-shoulder snoopers.
Q10. What is dial-up access, and why might a home user still rely on it?
A: Dial-up access occurs when a modem in a computer connects to the Internet through a standard
telephone line using an analog signal. Some home users still rely on it because of its lower cost or because
broadband access isn't available where they live.
B. IP Addresses, Domain Names & Web Addresses
10 questions
Q11. What is an IP address?
A: A sequence of numbers that uniquely identifies the location of each computer or device connected to the
Internet.
Q12. Differentiate between IPv4 and IPv6.
A: IPv4 is the original IP addressing scheme; as the Internet grew, its available addresses began dwindling.
IPv6 is the newer scheme that increased the number of available IP addresses exponentially.
Q13. What is a domain name, and why does the Internet support them?
A: A domain name is a text-based name that corresponds to the IP address of a server that hosts a website.
Because IP addresses are difficult to remember, the Internet supports domain names as an easier
alternative.
Q14. What is the role of a DNS server?
A: A DNS server translates a domain name entered into a browser into its associated IP address so that the
request can be routed to the correct web server.
Q15. What is a top-level domain (TLD)? Give three examples.
A: The TLD is the suffix of a domain name that identifies the type of organization associated with the domain
— for example, .com for commercial businesses, .edu for educational institutions, and .gov for government
agencies.
Q16. What does ICANN stand for, and what does it do?
A: ICANN stands for the Internet Corporation for Assigned Names and Numbers; it is the organization that
approves and controls top-level domains.
Q17. What is cybersquatting, and what law addresses it?
A: Cybersquatting is buying up domain names — often ones containing another company's name or
trademark — with the intent to resell them to the rightful owner at a profit. The Anticybersquatting Consumer
Protection Act (ACPA) was enacted to protect trademark owners from this practice.
Q18. Break down the parts of the web address [Link]
Digital Security & Internet Fundamentals — Q&A Study Guide | Page 2
A: Protocol: http — Host name: www — Domain name: [Link] — Path: history — Webpage name:
[Link].
Q19. What does HTTP stand for, and what is its purpose?
A: HyperText Transfer Protocol; it is a set of rules that defines how webpages transfer across the Internet.
Q20. Differentiate between a static webpage and a dynamic webpage.
A: A static webpage displays the same fixed content to every visitor every time it is viewed, while a dynamic
webpage generates customized content each time a user displays it, such as personalized search results or
current stock quotes.
C. Digital Security Risks & Cybercriminals
10 questions
Q21. Define digital security risk.
A: Any event or action that could cause a loss of, or damage to, computer or mobile device hardware,
software, data, information, or processing capability.
Q22. List the common categories of digital security risk.
A: Internet and network attacks, unauthorized access and use, hardware theft, software theft, information
theft, and system failure.
Q23. What is the difference between a computer crime and cybercrime?
A: A computer crime is any illegal act involving the use of a computer or related device; cybercrime
specifically refers to online or Internet-based illegal acts, such as distributing malware or committing identity
theft.
Q24. Differentiate between a hacker and a cracker.
A: A hacker originally had a complimentary meaning for a computing enthusiast; today it commonly refers to
someone who accesses a computer or network illegally, though some hackers claim their intent is to
improve security. A cracker also accesses a computer or network illegally but has the intent of destroying
data, stealing information, or another malicious action.
Q25. What is a script kiddie, and how does it differ from a cracker?
A: A script kiddie has the same intent as a cracker but lacks the technical skill and knowledge, typically
relying on prewritten hacking and cracking programs to break into computers and networks.
Q26. What is a corporate spy, and what practice does this describe?
A: Someone hired for their computer and networking skills to break into a specific company's computer and
steal its proprietary data and information, or to identify security risks in their own organization — this practice
is known as corporate espionage.
Q27. What motivates an unethical employee to commit a digital security breach?
A: Some exploit a security weakness for personal financial gain, such as selling confidential information;
disgruntled employees may breach security to seek revenge.
Q28. Define cyberextortionist and cyberterrorist.
Digital Security & Internet Fundamentals — Q&A Study Guide | Page 3
A: A cyberextortionist demands payment to stop an attack on an organization's technology infrastructure,
threatening to expose confidential information, exploit a security flaw, or launch an attack if unpaid. A
cyberterrorist uses the Internet or a network to destroy or damage computers for political reasons,
potentially targeting infrastructure such as air traffic control or power-generating companies.
Q29. What is a hacktivist?
A: A type of hacker whose actions are politically or socially motivated; the hacktivist believes his or her
actions should be protected under the First Amendment.
Q30. Per the Ethics & Issues discussion, why is it difficult for legislators to prosecute
cybercrime across jurisdictions?
A: Cybercrime laws vary between states and countries, making it difficult to establish what is illegal and
which jurisdiction is responsible for prosecuting a crime — for example, determining whether the area
responsible is where the victim resides or where the criminal lives.
D. Malware
6 questions
Q31. Define malware and explain what a "payload" is.
A: Malware (malicious software) consists of programs that act without a user's knowledge and deliberately
alter the operations of computers and mobile devices. Its payload is the destructive event or prank it
delivers, which can trigger when a user opens an infected file, runs an infected program, connects an
unprotected device to a network, or when a specific condition (like a date) occurs.
Q32. Differentiate between a virus and a worm.
A: A virus is a potentially damaging program that affects a device negatively by altering how it works, without
the user's knowledge or permission, typically by attaching to a file or program. A worm copies itself
repeatedly — for example, in memory or over a network — using resources and possibly shutting down the
computer, device, or network.
Q33. How does a Trojan horse differ from a virus or a worm?
A: A Trojan horse hides within or looks like a legitimate program, but unlike a virus or a worm, it does not
replicate itself to other computers or devices.
Q34. What is a rootkit?
A: A program that hides in a computer or mobile device and allows someone from a remote location to take
full control of the computer or device.
Q35. Define spyware and adware.
A: Spyware is a program placed on a computer or mobile device without the user's knowledge that secretly
collects information about the user and communicates it to an outside source while the user is online.
Adware is a program that displays an online advertisement in a banner, pop-up window, or pop-under
window on webpages, email messages, or other Internet services.
Q36. Describe the three steps by which a virus can spread via an email message.
Digital Security & Internet Fundamentals — Q&A Study Guide | Page 4
A: Step 1: Unscrupulous programmers create a virus program, hide it in a document, and attach it to an
email message. Step 2: They send the infected email message to thousands of users worldwide. Step 3a:
Some users open the attachment and their computers become infected. Step 3b: Other users don't
recognize the sender, delete the message without opening it, and remain uninfected.
E. Internet & Network Attacks
9 questions
Q37. What is a denial of service (DoS) attack?
A: An assault whose purpose is to disrupt computer access to an Internet service, such as the web or email,
often carried out by using an unsuspecting computer to send an influx of confusing data messages or
useless traffic to a network until it slows down considerably or becomes unresponsive.
Q38. What is a DDoS attack, and how does it differ from a standard DoS attack?
A: A distributed DoS (DDoS) attack is a more devastating type of DoS attack in which a zombie army of
compromised computers is used to attack simultaneously; DDoS attacks have been able to stop operations
temporarily at powerhouse websites such as Yahoo!, eBay, [Link], and [Link].
Q39. What is a back door, and how do perpetrators typically exploit it?
A: A back door is a program or set of instructions in a program that allows users to bypass security controls
when accessing a program, computer, or network. After gaining access to an unsecured computer,
perpetrators often install a back door — or modify an existing program to include one — so they can
continue accessing the computer remotely without the user's knowledge.
Q40. Why might legitimate programmers build back doors into software?
A: Programmers often build back doors into programs during development to save development time, since
a back door lets them bypass security controls while writing and testing the program.
Q41. Define spoofing and its two common types.
A: Spoofing is a technique intruders use to make their network or Internet transmission appear legitimate to
a victim computer or network. The two common types are IP spoofing and email spoofing.
Q42. Explain IP spoofing.
A: IP spoofing occurs when an intruder computer fools a network into believing its IP address is associated
with a trusted source. Perpetrators trick victims into interacting with the phony website — for example, by
getting them to provide confidential information or download malware.
Q43. Explain email spoofing and one common use for it.
A: Email spoofing occurs when the sender's address or other components of an email header are altered so
that the message appears to have originated from a different sender. It is commonly used in virus hoaxes,
spam, and phishing scams.
Q44. List four warning signs that an email message may have been spoofed.
A: The message requests personal information such as account numbers, passwords, Social Security
numbers, or credit card numbers; it contains spelling or grammatical errors; it encourages you to tap or click
a link to another website; and the header shows a different domain than the supposed sender's, or the
"From"/"Reply-To" addresses don't match.
Q45. If you're unsure whether an email has been spoofed, what should you do?
Digital Security & Internet Fundamentals — Q&A Study Guide | Page 5
A: Contact the supposed sender either by phone or with a new email message — never by replying to the
original message — to verify the authenticity of the communication.
F. Safeguards, Firewalls & Unauthorized Access
10 questions
Q46. List the five general safeguards against Internet and network attacks.
A: Use antivirus software; be suspicious of unsolicited email attachments; scan removable media for
malware before using it; implement firewall solutions; and back up regularly.
Q47. What is a firewall?
A: Hardware and/or software that protects a network's resources from intrusion by users on another
network, such as the Internet.
Q48. Differentiate between a personal firewall and a hardware firewall.
A: A personal firewall is software that constantly monitors all transmissions to and from a computer to
protect it and its data from unauthorized intrusions. A hardware firewall is a physical device, such as a
router, with built-in firewall capability that stops malicious intrusions before they reach the computer or
network.
Q49. What is a proxy server, and what does it do?
A: A proxy server is typically a component of a firewall — a server outside an organization's network that
controls which communications pass in and out of the network, screening all incoming and outgoing
messages using techniques such as checking domain names or IP addresses, or requiring digital
signatures.
Q50. Before adjusting a personal firewall's incoming and outgoing rules, what should you do
first?
A: Back up or export your current list of incoming and outgoing rules, so that if the computer stops
functioning properly after the changes, you can restore the rules you backed up or exported.
Q51. Why should users be cautious when adjusting a personal firewall's settings?
A: Because adding or removing rules may hinder a legitimate program's ability to work properly, or could
unintentionally allow unwanted access to the computer.
Q52. Differentiate between unauthorized access and unauthorized use.
A: Unauthorized access is the use of a computer or network without permission. Unauthorized use is the
use of a computer or its data for unapproved or possibly illegal activities.
Q53. Give three examples of unauthorized use described in the reference material.
A: An employee using an organization's computer to send personal email messages; an employee using the
organization's word processing software to track a child's soccer league scores; and a perpetrator gaining
access to a bank computer to perform an unauthorized transfer.
Q54. What is an acceptable use policy (AUP), and what should it specify?
A: A written policy that outlines the activities for which a computer or network may and may not be used. It
should specify the acceptable use of technology by employees for personal reasons, and what personal
activities (if any) are allowed during company time.
Digital Security & Internet Fundamentals — Q&A Study Guide | Page 6
Q55. How does disabling file and printer sharing protect a personal computer?
A: It is a security measure that helps ensure others cannot access your files or printer over the network,
protecting your device from unauthorized intrusions.
G. Scenario-Based Questions (Applied & Difficult)
12 questions
These scenarios combine several concepts at once and ask you to identify the correct term, explain the reasoning,
and recommend a safeguard — the way an exam or real-world case study would.
Scenario 1. An employee opens an email attachment from an unfamiliar sender. Afterward, her computer
slows down, and IT discovers a hidden program is letting a remote attacker fully control her machine. What
malware is this most likely, and what safeguard could have prevented it?
A: This matches a rootkit (likely delivered inside a Trojan horse), since it hides in the device and allows a
remote user to take full control. It most likely arrived through the suspicious email attachment. Prevention:
never open unsolicited or suspicious email attachments, keep antivirus software running and up to date, and
scan attachments before opening them.
Scenario 2. A retail website becomes completely inaccessible to shoppers during its biggest sale, after
receiving a simultaneous flood of traffic from thousands of compromised computers worldwide. What attack is
this, and why is it harder to stop than a single-source attack?
A: This is a DDoS (distributed denial of service) attack. Because it uses a zombie army of many computers
attacking at once rather than a single source, it's far harder to block and can overwhelm even large,
well-resourced sites — DDoS attacks have temporarily shut down operations at companies such as Yahoo!,
eBay, [Link], and [Link], causing extensive financial and reputational damage.
Scenario 3. You get an email that looks like it's from your bank's real address, asking you to click a link and
re-enter your account number and password to "verify your account." It contains a couple of spelling mistakes
and urgent language. What should you suspect, and what should you do before responding?
A: This has the classic signs of a spoofed / phishing email: a request for personal or financial information,
spelling and grammatical errors, and a link urging you to another website. You should not click the link or
reply — instead, verify authenticity by contacting the bank directly by phone or by typing the bank's known
web address into your browser separately.
Scenario 4. A small business wants to protect both its network as a whole and each individual employee
computer, without relying on a single layer of defense. What combination of safeguards achieves this, and
how do the pieces differ in role?
A: The business should combine a hardware firewall (such as a router with built-in firewall capability) at the
point where the network connects to the Internet — stopping malicious intrusions before they reach any
device — with personal (software) firewalls on each individual computer, which monitor transmissions to and
from that specific device. A proxy server can add a further layer by screening all incoming and outgoing
organizational messages.
Scenario 5. A former IT employee, fired weeks earlier, still knows about a hidden entry point built into the
company's software during development and never removed. He uses it to access the network remotely
without triggering a normal login. What is this vulnerability, and what should the company have done
differently?
Digital Security & Internet Fundamentals — Q&A Study Guide | Page 7
A: This is a back door — instructions built into the software (often left over from development or testing) that
bypass normal security controls. The company should have ensured all back doors were removed before
deployment, immediately revoked the former employee's access credentials upon termination, and
reviewed/updated its firewall rules and account permissions.
Scenario 6. Company A publishes a written policy defining exactly what employees may and may not do with
company technology. Company B has no such policy, and later discovers an employee has been running a
side business using company computers. What is Company B missing, and what risk does that create?
A: Company B lacks an acceptable use policy (AUP). Without one, there's no documented standard defining
permitted technology use, making it harder to prevent, identify, or discipline unauthorized use — like an
employee's side business — and it increases the organization's legal and security exposure.
Scenario 7. A political activist group breaches a government website not to steal money, but to alter a page
and post a protest message about a controversial policy. How does this differ, ethically and by definition, from
a criminal who breaches the same website to steal citizens' financial data?
A: The activist group's actions fit the definition of hacktivism — hacking motivated by political or social belief,
where the hacktivist believes their actions are protected free speech. The criminal stealing financial data is
better described as a cracker (or a cyberextortionist if payment is demanded), since the intent is destructive
or theft-based rather than expressive. This raises the same open ethical questions the reference material
poses: whether hacktivism deserves First Amendment protection, and whether punishment should be based
on motive or purely on harm caused.
Scenario 8. A company discovers a competitor seems to know its confidential product designs. Investigation
reveals a contractor with advanced networking skills was paid by the competitor to break into the company's
servers. What category of cybercriminal is this, and what is this practice called?
A: This is a corporate spy, and the practice is called corporate espionage — hiring someone with advanced
computer and networking skills to illegally access a competitor's systems and steal proprietary data or
information for competitive advantage.
Scenario 9. You try to register your first-choice ".com" domain name for your new business, but discover
someone bought it years ago, never built a site on it, and is now offering to sell it to you for a large sum. What
is this practice called, and what options do you have?
A: This is cybersquatting. You may have recourse under the Anticybersquatting Consumer Protection Act
(ACPA), which protects trademark owners — but you would need to prove the cybersquatter acted in bad
faith, such as buying the domain specifically to profit from your trademarked name. Alternatively, you could
register a different TLD (such as .net or .org) or a modified version of the name.
Scenario 10. An IT administrator reviewing a personal firewall's rules is considering disabling several outgoing
rules to tighten security. What should he do first, and what trade-off does he need to weigh?
A: He should first back up or export the current list of incoming and outgoing rules so the previous
configuration can be restored if something breaks. The trade-off: restricting outgoing rules increases
security by limiting what can communicate out to the Internet, but may also prevent legitimate programs —
such as a browser or email client — from functioning properly.
Scenario 11. A user connects to a "Free WiFi" hot spot at a coffee shop and checks his bank balance and
answers emails with sensitive attachments, without checking whether the connection is secure. Identify at
least three mistakes, based on public Wi-Fi safety guidance, and what he should have done instead.
Digital Security & Internet Fundamentals — Q&A Study Guide | Page 8
A: Mistakes: (1) entering financial/password information without confirming the site's address began with
"https"; (2) not signing out of his accounts and closing the window immediately when finished; (3) risking
exposure to over-the-shoulder snoopers or leaving the device unattended. He should have avoided typing
sensitive information on an unsecured connection, signed out immediately after use, disabled his wireless
connection when done, and stayed alert to anyone who might view his screen.
Scenario 12. Antivirus software flags a downloaded program as one that "hides within a legitimate-looking
application but does not try to copy itself to other files or spread across the network." Which malware type is
this, and how would the situation differ if the program had instead been self-replicating across the network?
A: This matches a Trojan horse, since it hides within or resembles a legitimate program but does not
replicate itself. If it had been self-replicating across the network instead, it would be classified as a worm —
malware that copies itself repeatedly (for example, in memory or over a network), consuming resources and
potentially shutting down the computer, device, or network.
Source: Compiled and paraphrased from the uploaded textbook chapter pages ("Connecting and Communicating Online" & "Digital Security, Ethics,
and Privacy").
Digital Security & Internet Fundamentals — Q&A Study Guide | Page 9