HomeSubjectsUniversityBlogAbout

Cyber Laws & Ethics

Topic in Cyber Security

210 total MCQsShowing 30 with explanations10 Easy10 Medium10 Hard

About This Topic

Cyber laws and ethics are the legal rules and moral principles that govern the use of computers, networks and personal data, and the prosecution of cybercrime. For Pakistan, questions focus on the Prevention of Electronic Crimes Act (PECA) 2016, its offences such as unauthorized access, cyber terrorism and electronic fraud, the FIA's enforcement role, and the Personal Data Protection Bill. International items cover the Budapest Convention, the EU GDPR and its territorial scope, the US CFAA, HIPAA and the CLOUD Act. Privacy principles like consent, data minimization, PII and privacy by design appear alongside intellectual property, professional codes of ethics and responsible disclosure.

Below are 30 practice questions from a pool of 210 Cyber Laws & Ethics MCQs, one of 16 topics in Cyber Security. Each shows the correct answer with an explanation; when you are ready, take a timed quiz to test recall under exam conditions.

Practice Questions

Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.

Cyber Laws & EthicsEasy

Q1. What is intellectual property in the digital context?

  1. A.A physical hardware component used in computing infrastructure
  2. B.Creative works, inventions, designs, and software protected by law from unauthorized use✓ Correct
  3. C.Internet speed and bandwidth available for data transfers
  4. D.Physical property like land and buildings owned by individuals

Explanation

Digital IP includes software, content, patents, and copyrighted material legally protected from unauthorized use.

Report an error in this question

Cyber Laws & EthicsEasy

Q2. What is data privacy?

  1. A.Making data public and freely accessible for anyone across computing environments
  2. B.The right of individuals to control how their personal information is collected, used, and shared✓ Correct
  3. C.Hiding your computer from others by placing it out of sight
  4. D.Deleting all data from storage devices permanently across computing environments

Explanation

Data privacy is the right of individuals to control their personal information.

Report an error in this question

Cyber Laws & EthicsEasy

Q3. What is online harassment?

  1. A.Using digital communication to threaten, intimidate, or harm another person✓ Correct
  2. B.Social media marketing campaigns for brand awareness
  3. C.Sending friendly emails to colleagues for collaboration
  4. D.Online gaming with other players for entertainment purposes

Explanation

Online harassment is punishable under cybercrime laws including Pakistan's PECA.

Report an error in this question

Cyber Laws & EthicsEasy

Q4. What is cybercrime?

  1. A.Playing computer games for recreational entertainment and leisure purposes
  2. B.Criminal activity involving computers, networks, or digital devices as tools or targets✓ Correct
  3. C.Using computers for normal everyday work productivity and communications
  4. D.Building websites for establishing personal or commercial online presence

Explanation

Cybercrime encompasses any criminal activity that uses or targets computers and networks.

Report an error in this question

Cyber Laws & EthicsEasy

Q5. What is digital consent?

  1. A.A symmetric key data encryption algorithm applied to data protection workflows
  2. B.A computer command executed from the terminal or console used in enterprise computing environments
  3. C.A digital signature used for verifying message authenticity used in enterprise computing environments
  4. D.Permission given by an individual for their personal data to be collected, processed, or shared✓ Correct

Explanation

Digital consent is informed permission for organizations to handle personal data.

Report an error in this question

Cyber Laws & EthicsEasy

Q6. What is unauthorized access in cyber law?

  1. A.Logging into your own user account with correct credentials
  2. B.Downloading free software from authorized official sources
  3. C.Using public Wi-Fi for browsing the internet content
  4. D.Accessing a computer system or network without permission✓ Correct

Explanation

Unauthorized access is gaining entry to a system without permission, illegal under cybercrime laws.

Report an error in this question

Cyber Laws & EthicsEasy

Q7. What is PECA 2016 in Pakistan?

  1. A.An education policy for governing school curriculum standards
  2. B.Pakistan's primary legislation addressing cybercrimes, data protection, and electronic fraud✓ Correct
  3. C.A health regulation for managing public medical facilities used in enterprise computing environments
  4. D.A traffic law regulating vehicle movement on roads used in enterprise computing environments

Explanation

PECA 2016 is Pakistan's comprehensive cybercrime law.

Report an error in this question

Cyber Laws & EthicsEasy

Q8. What is software piracy?

  1. A.Software testing for validating application feature quality
  2. B.The unauthorized copying, distribution, or use of copyrighted software✓ Correct
  3. C.Open-source development contributing code to public projects
  4. D.Sailing ships equipped with computer navigation technology

Explanation

Software piracy violates intellectual property laws and copyright protections.

Report an error in this question

Cyber Laws & EthicsMedium

Q9. What is the difference between ethical and illegal hacking?

  1. A.There is no difference between ethical and illegal hacking or notable impact in any deployment scenario
  2. B.Ethical hacking is authorized security testing with permission; illegal hacking is unauthorized access✓ Correct
  3. C.Illegal hacking is faster than ethical hacking in all scenarios
  4. D.Ethical hacking uses better tools than illegal hacking methods

Explanation

Ethical hacking involves authorized, legal testing; illegal hacking is unauthorized access.

Report an error in this question

Cyber Laws & EthicsEasy

Q10. What is the purpose of acceptable use policies (AUP)?

  1. A.To deploy and install application software and management
  2. B.To restrict all computer use for security purposes and management
  3. C.To increase internet speed for improved operational efficiency
  4. D.To define rules and guidelines for responsible and secure use of IT resources✓ Correct

Explanation

An AUP establishes rules for acceptable use of organizational IT resources.

Report an error in this question

Cyber Laws & EthicsEasy

Q11. What is identity theft in the digital context?

  1. A.Creating a new email account for personal communication
  2. B.Changing your username on a social media platform account
  3. C.Forgetting your password and requesting an account reset
  4. D.Stealing personal information to impersonate someone for fraud or other crimes✓ Correct

Explanation

Digital identity theft involves stealing personal information for fraudulent purposes.

Report an error in this question

Cyber Laws & EthicsMedium

Q12. What are the main offenses covered under PECA 2016?

  1. A.Only hacking is covered as a cybercrime offense under PECA
  2. B.Unauthorized access, data damage, electronic fraud, cyber terrorism, spamming, and spoofing✓ Correct
  3. C.Only online shopping fraud is covered under PECA across computing environments
  4. D.Only spam emails are covered as offenses under the PECA act

Explanation

PECA 2016 covers unauthorized access, electronic fraud, system damage, cyber terrorism, and more.

Report an error in this question

Cyber Laws & EthicsMedium

Q13. What is the GDPR?

  1. A.A Pakistani law governing domestic trade and commerce
  2. B.An EU regulation providing comprehensive data protection rights for EU citizens✓ Correct
  3. C.A US trade law governing international commerce and tariffs
  4. D.A UN resolution addressing global peacekeeping and diplomacy

Explanation

GDPR gives individuals rights over their personal data with significant penalties for non-compliance.

Report an error in this question

Cyber Laws & EthicsMedium

Q14. What is FIA's role in cybercrime in Pakistan?

  1. A.FIA only handles immigration cases and border control
  2. B.The designated agency for investigating and prosecuting cybercrimes under PECA 2016✓ Correct
  3. C.FIA only handles customs and trade regulation enforcement
  4. D.FIA has no role in cybercrime investigation or prosecution

Explanation

FIA's Cyber Crime Wing investigates and prosecutes cybercrimes under PECA 2016.

Report an error in this question

Cyber Laws & EthicsMedium

Q15. What is computer forensics evidence admissibility?

  1. A.Digital evidence is never admissible in any court proceedings regardless of the deployment context or scenario
  2. B.Evidence must meet standards including authenticity, integrity, chain of custody, and relevance✓ Correct
  3. C.All digital evidence is automatically admissible without conditions
  4. D.Only email evidence is admissible while other digital evidence is excluded

Explanation

Digital evidence must be authentic, unaltered, properly documented, relevant, and legally collected.

Report an error in this question

Cyber Laws & EthicsHard

Q16. How does PECA 2016 address cyber terrorism?

  1. A.Only monetary fines are imposed for cyber terrorism under PECA across computing environments
  2. B.Only verbal warnings are issued for cyber terrorism under PECA across computing environments
  3. C.Section 10 criminalizes using information systems for terrorism with penalties up to 14 years and 50 million rupees✓ Correct
  4. D.PECA does not address terrorism in any of its provisions in any deployment scenario or context

Explanation

PECA Section 10 criminalizes cyber terrorism with imprisonment up to 14 years and fines up to 50 million rupees.

Report an error in this question

Cyber Laws & EthicsHard

Q17. What is the Budapest Convention on Cybercrime?

  1. A.A European trade agreement governing international commerce used in enterprise computing environments
  2. B.A military alliance treaty for coordinating national defense used in enterprise computing environments
  3. C.The first international treaty addressing cybercrime with a framework for international cooperation✓ Correct
  4. D.A climate agreement for addressing global environmental change used in enterprise computing environments

Explanation

The Budapest Convention (2001) is the first binding international instrument on cybercrime.

Report an error in this question

Cyber Laws & EthicsHard

Q18. What is the NIS2 Directive?

  1. A.A physical hardware component widely used in enterprise computing infrastructure systems
  2. B.A standard software application used for routine enterprise computing operations tasks
  3. C.A standard network communication protocol used for transmitting data across systems
  4. D.An EU directive expanding cybersecurity requirements with risk management and incident reporting mandates✓ Correct

Explanation

NIS2 broadens cybersecurity requirements across sectors with penalties up to 10 million euros.

Report an error in this question

Cyber Laws & EthicsMedium

Q19. What are the penalties for cybercrime under PECA 2016?

  1. A.No penalties exist under PECA for cybercrime offenses regardless of the deployment context or scenario
  2. B.Only verbal warnings are issued for cybercrime violations
  3. C.Penalties range from fines to imprisonment up to 14 years depending on offense severity✓ Correct
  4. D.Only monetary fines are imposed without imprisonment penalties

Explanation

PECA 2016 prescribes fines and imprisonment from 3 months to 14 years depending on the offense.

Report an error in this question

Cyber Laws & EthicsHard

Q20. What is 'duty of care' in cybersecurity?

  1. A.The legal obligation to implement reasonable security measures to protect stakeholders from foreseeable harm✓ Correct
  2. B.Only governments have a duty of care not private organizations regardless of the deployment context or scenario
  3. C.Duty of care is only a medical concept with no legal relevance regardless of the deployment context or scenario
  4. D.Having no responsibility for security is the accepted standard regardless of the deployment context or scenario

Explanation

Duty of care means organizations must implement reasonable security measures to protect data and systems.

Report an error in this question

Cyber Laws & EthicsHard

Q21. What is the legal framework for digital evidence in Pakistan?

  1. A.Qanun-e-Shahadat Order 1984, PECA 2016, and Electronic Transactions Ordinance 2002 collectively govern it✓ Correct
  2. B.Only criminal law applies without any specific legislation
  3. C.No legal framework exists for digital evidence in Pakistan regardless of the deployment context or scenario
  4. D.Only PECA applies without any other relevant legislation across computing environments

Explanation

Pakistan's digital evidence framework includes the Qanun-e-Shahadat Order, PECA 2016, and ETO 2002.

Report an error in this question

Cyber Laws & EthicsMedium

Q22. What is the concept of data sovereignty?

  1. A.The principle that data is subject to the laws of the country where it is stored or processed✓ Correct
  2. B.Data belongs to everyone equally and cannot be controlled by any single entity
  3. C.Data is always free and not subject to any jurisdictional laws or regulations at all
  4. D.Data has its own independent government and governance structure for management

Explanation

Data sovereignty means digital data is subject to the laws of the country where it is located.

Report an error in this question

Cyber Laws & EthicsHard

Q23. What are the challenges of cross-border cybercrime investigation?

  1. A.There are no challenges with this approach at all or notable impact in any deployment scenario
  2. B.Only language barriers present challenges for investigation
  3. C.Only time zone differences present challenges for investigation
  4. D.Jurisdictional conflicts, varying laws, evidence preservation across borders, and MLAT delays✓ Correct

Explanation

Cross-border investigation faces jurisdictional conflicts, differing laws, and evidence preservation challenges.

Report an error in this question

Cyber Laws & EthicsMedium

Q24. What is the right to be forgotten?

  1. A.Forgetting your password and requesting an account reset
  2. B.A memory improvement technique for better data recall used in enterprise computing environments
  3. C.An individual's right to request deletion of their personal data under certain conditions✓ Correct
  4. D.A data backup policy for creating redundant recovery copies

Explanation

The right to be forgotten allows individuals to request deletion of their personal data.

Report an error in this question

Cyber Laws & EthicsHard

Q25. What is the legal status of encryption in different jurisdictions?

  1. A.Encryption is mandatory everywhere in the world without exception
  2. B.Legality varies: some countries mandate it, others restrict or require key escrow✓ Correct
  3. C.There are no laws about encryption in any country worldwide
  4. D.Encryption is illegal everywhere in the world without exception

Explanation

Encryption regulations vary globally, creating compliance complexity for multinational organizations.

Report an error in this question

Cyber Laws & EthicsMedium

Q26. What is cyber defamation?

  1. A.Publishing false or damaging statements about a person through digital media✓ Correct
  2. B.A cryptographic algorithm used for protecting sensitive data
  3. C.A standard network communication protocol for data transfer
  4. D.Building a good reputation through positive online interactions

Explanation

Cyber defamation involves publishing false, damaging statements through digital platforms.

Report an error in this question

Cyber Laws & EthicsHard

Q27. What is the legal principle of proportionality in cyber security law?

  1. A.Minimum security is always sufficient regardless of threat across computing environments
  2. B.No security is needed because there are no significant threats regardless of the deployment context or scenario
  3. C.Maximum security should always be applied regardless of risk
  4. D.Security measures and penalties should be proportionate to the actual risk, balancing security with rights✓ Correct

Explanation

Proportionality requires security measures be proportionate to the threat, balancing security and individual rights.

Report an error in this question

Cyber Laws & EthicsMedium

Q28. What is responsible disclosure?

  1. A.Privately reporting vulnerabilities to the vendor and allowing time for patching before public disclosure✓ Correct
  2. B.Publishing vulnerabilities immediately for public disclosure
  3. C.Never reporting discovered vulnerabilities to anyone in any deployment scenario or context
  4. D.Selling discovered vulnerabilities to the highest bidder across computing environments

Explanation

Responsible disclosure privately reports vulnerabilities, providing time for patches before public disclosure.

Report an error in this question

Cyber Laws & EthicsHard

Q29. What are the implications of the Schrems II decision?

  1. A.There are no implications for this technology whatsoever regardless of the deployment context or scenario
  2. B.It invalidated EU-US Privacy Shield and requires assessment of destination country data protection adequacy✓ Correct
  3. C.It only affects social media platforms and no other services without impacting any other system components
  4. D.It only affects banking institutions and no other organizations without impacting any other system components

Explanation

Schrems II requires transfer impact assessments and supplementary measures for EU personal data transfers.

Report an error in this question

Cyber Laws & EthicsHard

Q30. What is Pakistan's Personal Data Protection Bill?

  1. A.An education policy for governing school curriculum standards used in enterprise computing environments
  2. B.It has been fully enacted and is currently in force as law across computing environments
  3. C.A banking regulation governing financial institution operations used in enterprise computing environments
  4. D.A proposed legislation establishing data protection rights, consent requirements, and a regulatory authority✓ Correct

Explanation

The bill proposes comprehensive data protection including consent requirements and data localization.

Report an error in this question

Ready to test yourself on Cyber Laws & Ethics?

Take a timed quiz drawn from 210+ questions on this topic. No signup required — your progress saves in your browser.

Start Cyber Laws & Ethics Quiz