← Course Hub← 课程主页 ← All Units← 返回单元列表
H I G H  S C H O O L  C O M P U T E R  S C I E N C E
Practice练习题

Cybersecurity, Ethics and Society网络安全、伦理与社会

Practice Questions · AP CSP-Feeder · US / ON / BC / AB Styles练习题集 · AP CSP 衔接 · 美 / 安 / 卑 / 阿省风格

EASY MEDIUM HARD 🇺🇸 US 🇨🇦 ON 🇨🇦 BC 🇨🇦 AB AP CSP-style MCQAP CSP 风格选择题 AP CSP-feeder FRQAP CSP 衔接简答题 ON Provincial-style安大略省考风格 BC Provincial-style卑诗省考风格 AB/Universal Applied阿省/通用应用题 Honors荣誉级


Name:姓名:Date:日期:
PART I  ·  SHORT RESPONSE第一部分  ·  短答题AP CSP-style MCQ + ON/BC short answer · 25 marksAP CSP 风格选择题 + 安/卑省考短答 · 共 25 分

Section A · Short ResponseA 部分 · 短答题

Questions mix multiple-choice and short-answer items. For MCQs, circle the letter of the best answer and briefly justify in the work space. For short-answer items, write in complete sentences. No code tracing required in this part.本部分包含选择题与短答题。选择题请圈出最佳答案字母并在答题空白处简要说明理由。短答题用完整句子作答。本部分无需追踪代码。

Q1 EASY 🇺🇸 US AP CSP-style MCQAP CSP 风格选择题 §1 Cybersecurity Threats网络安全威胁 · CSTA 3A-NI-05 [3 marks][3 分]

Which type of malware disguises itself as legitimate software to trick a user into installing it, but then performs harmful actions once installed?哪种类型的恶意软件将自己伪装成合法软件,诱使用户安装,但安装后执行有害操作?

  1. (A) Worm蠕虫
  2. (B) Trojan木马
  3. (C) Spyware间谍软件
  4. (D) Ransomware勒索软件
Q2 EASY 🇨🇦 BC BC Provincial-style卑诗省考风格 §2 Encryption and Authentication加密与身份验证 · CSTA 3A-NI-07 [4 marks][4 分]

Distinguish between symmetric and asymmetric encryption by completing the table below.通过完成下表区分对称加密和非对称加密。

Aspect方面Symmetric对称Asymmetric非对称
Number of keys used使用的密钥数量
Processing speed处理快慢
(a) Fill in the two rows of the table above.填写上表的两行。 [2]
(b) State which type is used to exchange a session key in HTTPS, and why.说明 HTTPS 使用哪种类型交换会话密钥,以及原因。 [2]
Q3 MEDIUM 🇨🇦 ON ON Provincial-style安大略省考风格 §3 Safe Computing Practices安全计算实践 · ICS3U D1 [5 marks][5 分]

A student uses the same password "soccer2010" on five different websites. One website is breached and its password hashes are cracked.一名学生在五个不同网站上使用相同的密码 "soccer2010"。其中一个网站遭到入侵,其密码哈希被破解。

(a) Name the attack that exploits reused passwords by trying stolen credentials on other sites.说明利用重复使用的密码在其他网站尝试窃取凭据的攻击名称。 [1]
(b) Explain why "soccer2010" is a weak password. State two specific improvements.解释为什么"soccer2010"是弱密码。说明两项具体改进措施。 [3]
(c) Name one tool that helps users maintain strong, unique passwords across many sites without memorising them all.说明一种帮助用户在多个网站保持强且唯一密码而无需全部记忆的工具名称。 [1]
Q4 MEDIUM 🇺🇸 US AP CSP-style MCQAP CSP 风格选择题 §4 Privacy and Data Ethics隐私与数据伦理 · CSTA 3A-IC-29 [6 marks][6 分]

A free navigation app requests the following permissions: location (always on), microphone, contacts, and camera. The app's only stated purpose is to give turn-by-turn directions.一款免费导航应用请求以下权限:位置(始终开启)、麦克风、联系人和摄像头。该应用声明的唯一目的是提供逐步导航。

(a) Which permission is strictly necessary for the app's stated purpose? Justify your choice.哪项权限对应用声明的目的是严格必要的?说明理由。 [2]
(b) State the data ethics principle that the unnecessary permissions violate. Define it in one sentence.说明不必要权限所违反的数据伦理原则。用一句话定义它。 [2]
(c) A user taps "Allow All" without reading the permissions. Explain why this does not constitute genuine informed consent.用户未阅读权限就点击了"全部允许"。解释为什么这不构成真正的知情同意。 [2]
Q5 MEDIUM 🇨🇦 AB AB/Universal Applied阿省/通用应用题 §5 Intellectual Property and Licensing知识产权与许可 · CSTA 3A-IC-28 [7 marks][7 分]

Match each scenario below to the most appropriate term from the box. Then answer the follow-up.将下列每个场景与方框中最合适的术语匹配。然后回答后续问题。

Terms:术语: copyright · software piracy · open-source (MIT licence) · fair use · GPL (copyleft)版权 · 软件盗版 · 开源(MIT 许可)· 合理使用 · GPL(著佐权)

(a) A teacher photocopies one chapter of a textbook for classroom discussion without selling copies.一位老师为课堂讨论复印了教材的一章内容,未出售副本。 [1]
(b) A student downloads and uses a paid software package without purchasing a licence.一名学生未购买许可就下载并使用了付费软件包。 [1]
(c) A developer uses a library released under this licence; their modified version must also be distributed as open-source.一名开发者使用了在此许可下发布的库;其修改版本也必须以开源方式分发。 [1]
(d) Explain, in two sentences, one beneficial effect and one harmful effect that strict copyright law can have on software innovation (CSTA 3A-IC-28).用两句话解释严格版权法对软件创新可能产生的一个有益影响和一个有害影响(CSTA 3A-IC-28)。 [4]
PART II  ·  EXTENDED RESPONSE第二部分  ·  简答题AP CSP-feeder FRQ + Honors · 30 marksAP CSP 衔接简答题 + 荣誉级 · 共 30 分

Section B · Extended ResponseB 部分 · 简答题

Write in complete sentences unless a specific format (table, list) is requested. For "evaluate" or "argue" questions, two sentences of reasoning earn full marks. Cite the relevant threat category, principle, or licence name in your answer.除非要求特定格式(表格、列表),否则用完整句子作答。"评估"或"论证"题,两句推理即可满分。在答案中引用相关的威胁类别、原则或许可名称。

Q6 EASY 🇺🇸 US 🇨🇦 ON AP CSP-feeder FRQAP CSP 衔接简答题 §1 Threat classification + defence威胁分类与防御 · CSTA 3A-NI-05 [6 marks][6 分]

Read each scenario. Identify the threat category (malware, phishing, or social engineering) and state one specific defence for each.阅读每个场景。识别威胁类别(恶意软件、钓鱼或社会工程学),并为每个场景说明一种具体防御措施。

(a) Scenario A: Emma receives an email that looks like it is from her school, asking her to click a link and reset her password. The link goes to a site that looks identical to her school's portal but has a slightly different URL.场景 A:Emma 收到一封看起来来自她学校的电子邮件,要求她点击链接重置密码。该链接指向一个看起来与学校门户相同但 URL 略有不同的网站。 [2]
(b) Scenario B: A pop-up message tells a user their computer is infected and urges them to call a phone number immediately. When they call, the "technician" asks for remote access and payment to "fix" the problem.场景 B:一个弹窗告诉用户他们的电脑已感染病毒,并催促他们立即拨打一个电话号码。当他们拨打时,"技术人员"要求远程访问权限和付款来"修复"问题。 [2]
(c) Scenario C: A worm spreads through a corporate network by exploiting an unpatched vulnerability in the operating system. No user interaction is required for the worm to spread.场景 C:一个蠕虫通过利用操作系统中未打补丁的漏洞在企业网络中传播。蠕虫传播不需要任何用户交互。 [2]
Q7 MEDIUM 🇨🇦 ON 🇨🇦 BC ON Provincial-style安大略省考风格 §2 + §3 Encryption basics + MFA加密基础 + 多因素认证 · ICS4U D2.1 [7 marks][7 分]

A student is studying simple ciphers. The Caesar cipher shifts each letter by a fixed number of positions in the alphabet. The pseudocode below implements a Caesar cipher with a shift of 3.一名学生正在研究简单密码。凯撒密码将每个字母在字母表中移动固定数量的位置。下面的伪代码实现了移位为 3 的凯撒密码。

FUNCTION caesar_encrypt(plaintext, shift):
    ciphertext = ""
    FOR EACH letter IN plaintext:
        IF letter is alphabetic THEN
            new_char = shift letter forward by shift positions (wrapping A-Z)
            ciphertext = ciphertext + new_char
        ELSE
            ciphertext = ciphertext + letter
        END IF
    END FOR
    RETURN ciphertext
(a) Apply the cipher to encrypt the word HACK using shift = 3. Show your working letter by letter.使用移位 = 3 的密码加密单词 HACK。逐字母展示过程。 [2]
(b) Explain one major weakness of the Caesar cipher that makes it unsuitable for protecting real data.解释凯撒密码使其不适合保护真实数据的一个主要弱点。 [2]
(c) After encrypting a file, a user wants to send it to a colleague over email. State which type of encryption (symmetric or asymmetric) they should use to share the decryption key securely, and why.加密文件后,用户想通过电子邮件将其发送给同事。说明他们应使用哪种类型的加密(对称或非对称)来安全共享解密密钥,以及原因。 [2]
(d) Name the three authentication factors. Give one example of each.说明三种身份验证因素。各举一个例子。 [1]
Q8 MEDIUM 🇺🇸 US 🇨🇦 AB AP CSP-feeder FRQAP CSP 衔接简答题 §4 + §5 PII + secondary use + IPPII + 二次使用 + 知识产权 · CSTA 3A-IC-29 / 3A-IC-28 [8 marks][8 分]

A loyalty rewards app for a grocery store collects the following data from users: name, email address, home postal code, and a full history of every item purchased. The company then sells anonymised purchase histories to a marketing data broker.一家杂货店的会员积分应用从用户收集以下数据:姓名、电子邮件地址、家庭邮政编码以及每件购买商品的完整历史记录。该公司随后将匿名化的购买历史出售给营销数据经纪人。

(a) Identify which pieces of data collected are PII. Justify each one in one sentence.识别收集的数据中哪些是 PII。每项用一句话说明理由。 [3]
(b) The company claims anonymisation removes all privacy concerns because individual names are stripped. Give one reason this claim may be false.公司声称匿名化消除了所有隐私问题,因为个人姓名已被删除。给出一个该说法可能是错误的理由。 [2]
(c) Selling the data to marketers without user knowledge violates which ethical principle? Name and define it.在用户不知情的情况下将数据出售给营销商违反了哪项伦理原则?命名并定义它。 [2]
(d) The app was built using an open-source library licenced under the GPL. The company modified the library. State what the GPL requires them to do with their modified version.该应用使用了 GPL 许可下的开源库构建。该公司修改了该库。说明 GPL 要求他们对其修改版本做什么。 [1]
Q9 HARD Honors荣誉级 🇺🇸 US AP CSP-feeder FRQAP CSP 衔接简答题 §6 + §7 Societal impact + bias + accessibility社会影响 + 偏见 + 可访问性 · CSTA 3A-IC-30 [9 marks][9 分]

A city uses an AI-powered hiring tool to screen job applications. The tool was trained on historical hiring data from the past 20 years.一个城市使用 AI 驱动的招聘工具筛选求职申请。该工具基于过去 20 年的历史招聘数据进行训练。

(a) If the historical data reflects past discriminatory hiring patterns, what problem will likely emerge in the AI tool's decisions? Name the term for this phenomenon.如果历史数据反映了过去的歧视性招聘模式,AI 工具的决策中可能会出现什么问题?说明这一现象的术语名称。 [2]
(b) The city argues the tool is fair because it treats all candidates identically. Evaluate this argument. Is identical treatment always equitable? Explain in two sentences.该城市认为该工具是公平的,因为它对所有候选人一视同仁。评估这一论点。同样的对待是否总是公平?用两句话解释。 [3]
(c) Propose two concrete steps the city could take to reduce the risk of biased outcomes before deploying the tool at scale.提出两项具体措施,城市可以在大规模部署该工具之前采取,以降低偏见结果的风险。 [2]
(d) The digital hiring portal has no screen-reader support. Name the computing principle this violates and explain why accessibility matters for equitable access to employment (CSTA 3A-IC-30).数字招聘门户没有屏幕阅读器支持。说明这违反了哪项计算原则,并解释为什么可访问性对于平等就业机会很重要(CSTA 3A-IC-30)。 [2]
PART III  ·  MODELING / APPLIED第三部分  ·  建模与应用Universal / multi-region applied · 25 marks通用/多地区应用题 · 共 25 分

Section C · Modeling and ApplicationsC 部分 · 建模与应用

Read each scenario carefully before writing. Argue your position clearly; marks are awarded for reasoning, not just conclusions. Use specific terminology from the unit. Each question has a multi-part structure; answer all parts.动笔前仔细阅读每个场景。清晰表达你的立场;分数来自推理,而不仅仅是结论。使用本单元的具体术语。每题均为多部分结构;作答所有部分。

Q10 MEDIUM 🇺🇸 US 🇨🇦 ON 🇨🇦 BC AP CSP-feeder FRQAP CSP 衔接简答题 §1 + §2 + §3 Security incident analysis安全事件分析 · CSTA 3A-NI-05 / 3A-NI-07 [8 marks][8 分]

A hospital suffers a ransomware attack. Investigation reveals the infection entered through a phishing email opened by a staff member. The ransomware encrypted all patient files, and the hospital had no recent backups. Patient care was disrupted for three days.一家医院遭受勒索软件攻击。调查显示,感染通过一名工作人员打开的钓鱼电子邮件进入。勒索软件加密了所有患者文件,医院没有近期备份。患者护理中断了三天。

(a) Trace the attack chain: identify the initial attack vector (how the attacker first gained a foothold), the payload type, and the impact category.追踪攻击链:识别初始攻击向量(攻击者如何首先获得立足点)、有效载荷类型和影响类别。 [3]
(b) The hospital argues the staff member is solely to blame. Evaluate this claim. Name two systemic security failures on the hospital's part that contributed to the severity of the outcome.医院认为工作人员负有全部责任。评估这一说法。说明医院方面导致后果严重的两个系统性安全失误。 [3]
(c) Recommend a three-measure prevention plan (one technical, one procedural, one cultural) that would have reduced the likelihood or severity of this attack. Justify each measure in one sentence.推荐一个三措施预防计划(一项技术性、一项程序性、一项文化性),这些措施本可降低此次攻击的可能性或严重性。每项措施用一句话说明理由。 [2]
Q11 MEDIUM 🇨🇦 ON 🇨🇦 BC 🇨🇦 AB ON Provincial-style安大略省考风格 §4 + §6 Privacy vs. public safety tradeoff隐私与公共安全的权衡 · ICS4U D2.1 / CSTA 3A-IC-30 [9 marks][9 分]

A city government proposes installing facial recognition cameras throughout its public transit system. The city claims this will reduce crime and improve safety. Civil liberties groups argue it threatens privacy and may produce biased outcomes for certain demographic groups.一个市政府提议在整个公共交通系统中安装人脸识别摄像头。该市声称这将减少犯罪并提高安全性。民权团体认为这威胁隐私,并可能对某些人口群体产生有偏见的结果。

(a) State two categories of PII that facial recognition systems collect or generate. For each, explain a potential harm if that data were breached or misused.说明人脸识别系统收集或生成的两类 PII。对每类,解释如果该数据遭到泄露或滥用可能造成的潜在危害。 [4]
(b) Argue, in three to four sentences, whether the city should be required to obtain explicit public consent before deploying the system. Reference the principle of informed consent in your argument.用三到四句话论证该市在部署系统之前是否应该被要求获得明确的公众同意。在论证中引用知情同意原则。 [3]
(c) Identify one computing professional ethics code (e.g., ACM Code of Ethics) and state one principle from it that is directly relevant to this scenario. Explain the connection in one sentence.识别一个计算专业伦理准则(如 ACM 伦理准则),并说明其中一条与本场景直接相关的原则。用一句话解释关联。 [2]
Q12 HARD 🇺🇸 US 🇨🇦 ON 🇨🇦 BC 🇨🇦 AB AB/Universal Applied阿省/通用应用题 All sections · Secure app design全节综合 · 安全应用设计 · CSTA 3A-NI-05 / 3A-IC-28 / ICS4U D2.2 [8 marks][8 分]

A student is designing a web app that allows users to store and share personal health records. The app stores usernames, passwords, date of birth, and all medical history for each user. The student wants the app to be free, so they plan to use an open-source framework (MIT licenced) and monetise by selling anonymised user data to health insurance companies.一名学生正在设计一个允许用户存储和共享个人健康记录的网络应用。该应用存储每个用户的用户名、密码、出生日期和全部病历。学生希望应用免费,因此计划使用开源框架(MIT 许可)并通过将匿名化用户数据出售给健康保险公司来盈利。

(a) The student stores passwords in plaintext in the database. Identify this security flaw and describe the correct approach (name the technique and briefly explain how it works).该学生以明文形式将密码存储在数据库中。识别这一安全缺陷并描述正确做法(命名该技术并简要解释其工作原理)。 [3]
(b) List two specific pieces of data in this app that are clearly PII. For each, describe one security measure the app should implement to protect it.列出该应用中两项明确属于 PII 的具体数据。对每项,描述应用应实施的一种安全措施来保护它。 [2]
(c) Evaluate the student's monetisation plan from a data ethics perspective. Identify the specific ethical violation and explain why anonymisation alone may not protect users' interests in this context.从数据伦理角度评估学生的盈利计划。识别具体的伦理违规,并解释为什么在此背景下单纯匿名化可能无法保护用户利益。 [3]

🇺🇸 US CSTA / AP CSP美国 CSTA / AP CSP3A-NI-05 · 3A-NI-07 · 3A-IC-28 · 3A-IC-29 · 3A-IC-30
🇨🇦 Ontario安大略ICS4U D2.1 · D2.2 · ICS3U D1
🇨🇦 British Columbia不列颠哥伦比亚CS10: security risks, copyright, fair use, software updatesCS10:安全风险、版权、合理使用、软件更新
🇨🇦 Alberta阿尔伯塔CTS: COM1005 digital citizenship, INF2020 privacy and securityCTS:COM1005 数字公民,INF2020 隐私与安全

Full Syllabus Map in Study Guide: ../Study Guides/Unit_12_Cybersecurity_Ethics_and_Society.html. CS has no AB standalone diploma exam; AB framing uses CTS computing course outcomes.完整大纲对照见学习指南:../Study Guides/Unit_12_Cybersecurity_Ethics_and_Society.html。CS 无独立 AB 毕业考;AB 题使用 CTS 课程成果框架。