Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
A customer places an order for a product on an e*commerce site after reviewing the quantity and pricing on the online form. The customer then receives an email confirmation that displays different pricing than the order form. The customer reports the discrepancy to customer service.
Which security practice is this customer addressing?
Computerized Provider Order Entry (CPOE) is a digital system that allows healthcare providers to enter medication orders electronically, reducing errors related to handwriting and incomplete prescriptions.
Why CPOE?
Eliminates handwriting misinterpretation errors.
Ensures complete medication details, reducing omissions.
Often integrates decision support tools, warning about drug interactions and incorrect dosages.
Why Not the Other Options?
B . Health Information Exchange (HIE): Shares patient records across providers but does not focus on medication ordering.
C . Electronic Medical Record (EMR): Digitizes patient records but does not prevent prescription errors directly.
D . Clinical Decision Support (CDS): Helps providers make better decisions but does not replace the ordering process like CPOE does.
Thus, the correct answer is A. Computerized Provider Order Entry (CPOE), as it directly addresses prescription errors.
Reference in Ethics in Technology:
Bates, D. W. et al. (1998). Effect of Computerized Physician Order Entry and a Team Intervention on Prevention of Serious Medication Errors.
Institute of Medicine (2000). To Err is Human: Building a Safer Health System.
A company is bidding on a website project for a prospective client. The company knows that the client is going to weigh the time to deliver the project as one of its primary decision factors. The client has advised all bidders that completion time should be no more than three months with a budget of S50.000.
The company knows that with its current resourcing, it cannot complete the project in less than four months. However, it is confident that it will be able to deliver within four months to a high-quality standard and 20% under the set budget. The company advises the client that it would need four months but would be able to complete the project under budget.
What is this behavior considered?
The company honestly discloses its realistic project timeline to the client without misleading or misrepresenting its capabilities.
Why is this ethical?
The company does not engage in deception; it clearly states that it requires four months rather than falsely promising three.
It offers added value by completing the project 20% under budget, which is beneficial for the client.
This aligns with ethical principles of honesty, transparency, and fairness.
Why is this legal?
There is no law requiring the company to meet the three-month deadline if it discloses its timeline honestly.
Misrepresentation would be illegal, but the company truthfully communicates its capabilities.
Why Not the Other Options?
A . Ethical and Illegal: There is no violation of any law.
B . Unethical and Illegal: The company does not engage in fraud or deception.
C . Unethical and Legal: The action is not unethical since it follows principles of honesty and integrity.
Thus, the correct answer is D. Ethical and Legal because the company acts transparently while complying with business ethics and legal standards.
Reference in Ethics in Technology:
ACM Code of Ethics (2022).
IEEE Code of Conduct (2020).
Brenkert, G. G. (2008). 'Marketing Ethics.' Blackwell Encyclopedia of Management.
What is a Gramm-Leach-BIiley Act (GLBA) financial privacy rule that presents a threat to data privacy?
The Financial Privacy Rule of the Gramm-Leach-Bliley Act (GLBA) allows consumers to control how their personal financial information is shared through an opt-out mechanism.
Why is 'Opt-Out' a Threat to Data Privacy?
The opt-out model assumes that consumers consent to having their data shared unless they take action to refuse.
Many consumers may not be aware of their right to opt-out, leading to widespread data sharing without explicit consent.
This is less privacy-protective than an opt-in model, where consumers must actively give permission before their data is shared.
Why Not the Other Options?
A . Opt-in -- This would enhance privacy, not threaten it.
B . Safeguard -- Refers to data security, not data-sharing policies.
D . Pretexting -- Involves fraudulent access to financial data, which is a different issue.
Thus, the correct answer is C. Opt-out, as it weakens consumer privacy protections by allowing data sharing unless the consumer takes action.
Reference in Ethics in Technology:
Gramm-Leach-Bliley Act (1999), 15 U.S.C. 6801-6809.
Federal Trade Commission (FTC) Guide to GLBA Opt-Out Provisions.
Nissenbaum, H. (2010). Privacy in Context: Technology, Policy, and the Integrity of Social Life.
A data scientist selects publicly available demographic data from a limited group of familiar zip codes when training an algorithm. What are two ethical concerns with this approach? Choose 2 answers.
The data scientist's approach raises two key ethical concerns:
Proxy Discrimination (C) -- Using demographic data from limited zip codes may create biased AI models that discriminate against certain racial, economic, or social groups. Zip codes often reflect historical segregation, leading to unfair predictions.
Small Sample Size (D) -- Training an AI model on a limited set of familiar zip codes introduces selection bias, reducing the model's ability to generalize across diverse populations. This affects fairness and accuracy.
Relevant Ethical Reference in Technology:
Algorithmic Fairness & Bias (FAT/ML Guidelines) -- AI models must avoid using biased proxies and ensure diverse training data.
Privacy & Ethical AI (GDPR, CCPA) -- AI decisions must not indirectly discriminate based on location, race, or socioeconomic status.
Utilitarian Ethics (Maximizing Fairness & Inclusivity) -- AI should benefit all groups equally, not just selected demographics.
IEEE & ACM AI Ethics Standards -- Encourage transparent, unbiased data selection to prevent discrimination.
Thus, the correct answers are C. Proxy discrimination and D. Small sample size, as both contribute to bias in AI models.
Which legislation provides a safe harbor for internet service providers (ISPs) whose customers violate intellectual property rights?
The Digital Millennium Copyright Act (DMCA) provides a safe harbor provision for internet service providers (ISPs) and online platforms that host user-generated content.
Why DMCA Applies?
Protects ISPs from liability if their users violate copyright laws, as long as they follow takedown procedures.
Establishes a notice-and-takedown system, allowing copyright holders to request removal of infringing content.
Why Not the Other Options?
B . Copyright Term Extension Act -- Extends copyright duration but does not provide ISP protection.
C . Digital Performance Right in Sound Recordings Act -- Focuses on music copyright protections, not ISP liability.
D . Leahy-Smith America Invents Act -- Governs patent law, not copyright infringement.
Thus, the correct answer is A. Digital Millennium Copyright Act (DMCA) as it provides safe harbor protections for ISPs.
Reference in Ethics in Technology:
Digital Millennium Copyright Act (DMCA), 17 U.S.C. 512.
Electronic Frontier Foundation (EFF) DMCA Guide.
Litman, J. (2001). Digital Copyright: Protecting Intellectual Property on the Internet.
66 questions covering all exam domains, starting from $20
5 domains from the WGU Ethics-In-Technology exam outline, with approximate weightings. Every sample question above is tagged with the domain it comes from
This section measures skills of IT Support Specialists and introduces ethical considerations connected to technology use in the modern world. Learners explore decision-making through ethical frameworks and review real examples involving surveillance, social media, hacking, data manipulation, plagiarism, piracy, artificial intelligence, responsible innovation, and the digital divide.
This section measures skills of IT Support Specialists and discusses how ethical codes help guide appropriate behavior in technology roles. Learners gain an understanding of the standards that support responsible actions and informed decision-making.
Sample question from this domain above: Q5
This section measures skills of IT Compliance Technicians and outlines major ethical concerns related to data handling. Learners understand the importance of protecting privacy, ensuring accuracy, managing access correctly, and maintaining strong security in both organizational and personal settings.
This section measures skills of IT Support Specialists and explains how learners apply ethical frameworks to make informed decisions in technology use. It introduces methods for approaching complex scenarios while considering moral and societal impacts.
Sample question from this domain above: Q2
This section measures skills of IT Compliance Technicians and focuses on recognizing personal biases and understanding their legal implications. Learners learn how to apply interventions to ensure ethical, fair, and lawful practices in technology use.
Sample question from this domain above: Q4
Common questions about the exam itself