Virtual Assistant Professional Ethics and Security 2 — Questions and Answers
Question 1: A client asks you to share login credentials for their bank account over email. What is the most secure response?
- Use a dedicated password manager with shared vault access instead (Correct answer)
- Email the credentials but split them across two messages
- Text the credentials to a personal phone number
- Store them in a shared Google Doc for convenience
Correct answer: Use a dedicated password manager with shared vault access instead
A password manager with a shared vault transmits and stores credentials encrypted, avoiding plaintext exposure.
Question 2: You discover a coworker VA is copying a client's customer list to use for a side business. What should you do first?
- Report the breach to the client or your agency through proper channels (Correct answer)
- Confront the coworker and ask for a share of the profit
- Ignore it since it is not your account
- Post about it on social media to warn others
Correct answer: Report the breach to the client or your agency through proper channels
Misuse of a client's confidential data is a serious breach that must be reported through the proper channels.
Question 3: Which practice best protects client data when working on public Wi-Fi at a cafe?
- Connect through a VPN before accessing client systems (Correct answer)
- Disable the password to load pages faster
- Use the cafe's shared computer instead of your own
- Turn off your firewall to avoid connection errors
Correct answer: Connect through a VPN before accessing client systems
A VPN encrypts traffic on untrusted public networks, preventing interception of client data.
Question 4: A client pressures you to leave fake positive reviews for their product. The ethical action is to:
- Decline and explain that fake reviews violate platform policies and ethics (Correct answer)
- Write the reviews using multiple fake accounts
- Hire someone cheaper to write them for you
- Write them but only give four stars to seem realistic
Correct answer: Decline and explain that fake reviews violate platform policies and ethics
Posting fabricated reviews is deceptive and violates platform terms, so a VA should decline.
Question 5: What is the safest way to handle a client's files once a contract ends?
- Securely delete the files per the agreement after confirming with the client (Correct answer)
- Keep copies indefinitely in case they return
- Forward everything to your personal cloud as backup
- Sell unused stock images you collected for them
Correct answer: Securely delete the files per the agreement after confirming with the client
Data should be securely deleted at contract end per agreement to honor confidentiality and privacy obligations.
Question 6: Which of these is a sign of a phishing email targeting a VA?
- Urgent request to reset a payment login via an unfamiliar link (Correct answer)
- A scheduled meeting invite from a known client
- A monthly newsletter you subscribed to
- A calendar reminder you set yourself
Correct answer: Urgent request to reset a payment login via an unfamiliar link
Phishing emails typically create urgency and direct you to unfamiliar links to steal credentials.
Question 7: Enabling two-factor authentication on client accounts primarily protects against:
- Unauthorized access even if the password is stolen (Correct answer)
- Slow internet speeds
- Email spam from newsletters
- Accidental file deletion
Correct answer: Unauthorized access even if the password is stolen
Two-factor authentication adds a second verification step, blocking access even when a password is compromised.
A client asks you to share login credentials for their bank account over email.
What is the most secure response?