Professional Ethics and Security Flashcards
7 cards from real Virtual Assistant practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Professional Ethics and Security flashcards as text
A client asks you to share login credentials for their bank account over email. What is the most secure response?
Answer: Use a dedicated password manager with shared vault access instead
A password manager with a shared vault transmits and stores credentials encrypted, avoiding plaintext exposure.
You discover a coworker VA is copying a client's customer list to use for a side business. What should you do first?
Answer: Report the breach to the client or your agency through proper channels
Misuse of a client's confidential data is a serious breach that must be reported through the proper channels.
Which practice best protects client data when working on public Wi-Fi at a cafe?
Answer: Connect through a VPN before accessing client systems
A VPN encrypts traffic on untrusted public networks, preventing interception of client data.
A client pressures you to leave fake positive reviews for their product. The ethical action is to:
Answer: Decline and explain that fake reviews violate platform policies and ethics
Posting fabricated reviews is deceptive and violates platform terms, so a VA should decline.
What is the safest way to handle a client's files once a contract ends?
Answer: Securely delete the files per the agreement after confirming with the client
Data should be securely deleted at contract end per agreement to honor confidentiality and privacy obligations.
Which of these is a sign of a phishing email targeting a VA?
Answer: Urgent request to reset a payment login via an unfamiliar link
Phishing emails typically create urgency and direct you to unfamiliar links to steal credentials.
Enabling two-factor authentication on client accounts primarily protects against:
Answer: Unauthorized access even if the password is stolen
Two-factor authentication adds a second verification step, blocking access even when a password is compromised.