Computer Knowledge · General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

What kind of link could be an illegitimate site?

Directions: Read the passage and answer the question that follows.

Don’t use passwords or user IDs that include personal information such as your birth date.
Don’t use your mother’s maiden name as a security question. Pick something more obscure, such as your childhood pet’s name.
Don’t leave passwords in plain view – on your monitor, for example.
Don’t use the same password for multiple sites. If crooks crack your Twitter account, they can access your bank account, too.
Do create passwords that are at least eight to 16 characters long, with a mix of capital letters, numbers and symbols. They’re harder to crack.
Do use random pattern codes to create passwords. For example, pick two computer keys – say, 4 and 7. Type straight down the keyboard from 4 until you reach the bottom (the letter V), then type one character to the left. Then do the same for 7, this time using all caps. You now have a meaningless password that reads 4rfvc7UJMN, but all you have to remember is 47. Or use the first letter of each word in a line from a favourite song or poem.
Do change passwords often, about once a month.
Do hold your cursor over an unknown link before clicking on it, and look at the bottom of your web browser. It will show where the link is actually taking you to. Do note the wording before the .com, .com.au, .org.au (or similar) part of the URL. It’s what counts. So while paypal.com is legitimate, paypal.1234.com is fake.
Do look out for links with the @ symbol. Browsers ignore everything to the left of it, so [email protected] is not a PayPal site.
Do watch for deliberate misspellings – such as paypol. com – designed to trick you into clicking.

  1. Do note the wording before the .com, .com. au, .org.au (or similar) part of the URL. It's what counts. So while paypal.com is legitimate, paypal.1234.com is fake.

  2. Do look out for links with the @ symbol. Browsers ignore everything to the left of it, so [email protected] is not a PayPal site.

  3. Do watch for deliberate misspellings - such as paypol.com - designed to trick you into clicking.

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

All the options are mentioned in the passage.

Multiple choice

What kind of a code is harder to crack?

Directions: Read the passage and answer the question that follows.

Don’t use passwords or user IDs that include personal information such as your birth date.
Don’t use your mother’s maiden name as a security question. Pick something more obscure, such as your childhood pet’s name.
Don’t leave passwords in plain view – on your monitor, for example.
Don’t use the same password for multiple sites. If crooks crack your Twitter account, they can access your bank account, too.
Do create passwords that are at least eight to 16 characters long, with a mix of capital letters, numbers and symbols. They’re harder to crack.
Do use random pattern codes to create passwords. For example, pick two computer keys – say, 4 and 7. Type straight down the keyboard from 4 until you reach the bottom (the letter V), then type one character to the left. Then do the same for 7, this time using all caps. You now have a meaningless password that reads 4rfvc7UJMN, but all you have to remember is 47. Or use the first letter of each word in a line from a favourite song or poem.
Do change passwords often, about once a month.
Do hold your cursor over an unknown link before clicking on it, and look at the bottom of your web browser. It will show where the link is actually taking you to. Do note the wording before the .com, .com.au, .org.au (or similar) part of the URL. It’s what counts. So while paypal.com is legitimate, paypal.1234.com is fake.
Do look out for links with the @ symbol. Browsers ignore everything to the left of it, so [email protected] is not a PayPal site.
Do watch for deliberate misspellings – such as paypol. com – designed to trick you into clicking.

  1. One that is a name of some family member

  2. One that is a mixture of capital, small alphabets and also of numbers and symbols

  3. One that is the name of your mother

  4. One that contains your bank account number and your vehicle number

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

[Do create passwords that are at least eight to 16 characters long, with a mix of capital letters, numbers and symbols. They’re harder to crack.]

Multiple choice

Using the first letter of each word in a line from a favourite song or poem, in a password makes it:

Directions: Read the passage and answer the question that follows.

Don’t use passwords or user IDs that include personal information such as your birth date.
Don’t use your mother’s maiden name as a security question. Pick something more obscure, such as your childhood pet’s name.
Don’t leave passwords in plain view – on your monitor, for example.
Don’t use the same password for multiple sites. If crooks crack your Twitter account, they can access your bank account, too.
Do create passwords that are at least eight to 16 characters long, with a mix of capital letters, numbers and symbols. They’re harder to crack.
Do use random pattern codes to create passwords. For example, pick two computer keys – say, 4 and 7. Type straight down the keyboard from 4 until you reach the bottom (the letter V), then type one character to the left. Then do the same for 7, this time using all caps. You now have a meaningless password that reads 4rfvc7UJMN, but all you have to remember is 47. Or use the first letter of each word in a line from a favourite song or poem.
Do change passwords often, about once a month.
Do hold your cursor over an unknown link before clicking on it, and look at the bottom of your web browser. It will show where the link is actually taking you to. Do note the wording before the .com, .com.au, .org.au (or similar) part of the URL. It’s what counts. So while paypal.com is legitimate, paypal.1234.com is fake.
Do look out for links with the @ symbol. Browsers ignore everything to the left of it, so [email protected] is not a PayPal site.
Do watch for deliberate misspellings – such as paypol. com – designed to trick you into clicking.

  1. Very easy

  2. Moderately difficult

  3. Quite difficult

  4. Very much hackable

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

It is mentioned in the passage as one of the ways to make the password difficult.

Multiple choice
  1. cyberstalking

  2. corporate cyberstalking

  3. spamming

  4. hacking

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Corporate cyberstalking is when a company harasses an individual online or an individual or group of individuals harass an organisation.

Multiple choice
  1. is an encryption mechanism that enforces network security

  2. helps prevent a single sender from monopolizing a shared communication link for an arbitrary amount of time

  3. is an algorithm for data encoding in the physical layer

  4. none of these

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

null

Multiple choice

Which of the following is/are true about security breaches according to the passage?

Directions: Read the following passage and answer the given question.

Security breaches and the compromise of sensitive information are very real concerns for any organisation today. Studies have shown that though the likelihood of the attack from insiders may be very low as compared to external threats, the magnitude of the impact is at least 10 times more than that of the total impact an external attacker can cause. This is because an insider attack is committed by people who know the organisation’s most sensitive secrets and vulnerabilities and have access to its systems. In most cases, breaches by insiders are committed by individuals who have no intention of doing anything wrong.
Data Security Council of India (DSCI) and Price waterhouse Coopers (PwC) have jointly conducted a study to understand the challenges and risks associated with insider threats. The study has been conducted to understand the security posture of the Indian IT/BPO industry from an insider threat perspective and the perceptions of the client organisations on the same.
Surprisingly, not even a single incident was attributed to the senior management of the organisation. This was in contrast to our findings from secondary research, where senior management was found to be involved in a number of such incidents.
The survey revealed that an insider can be motivated to commit a crime due to a number of reasons, viz. information gain, personal financial gain, a new job, unsatisfactory appraisal or unmet professional expectations, an urge to prove oneself, antagonism towards the management etc. As per 89% of the service provider organisations, behavioural motivation to break existing norms is the primary motive that leads to insider threat. This might be due to the predominant youth mix in the IT/BPO industry.
On the other hand, 75% of the respondents in the client organisations believe that personal financial gain is the prime motive for insiders at service provider organisations to carry out illicit activities.
Dissatisfaction with organisation policies was rated as the second most probable reason that leads to insider threat as 44% service provider organisations highlighted this as a concern. However, in contrast, 25% of client organisations believe this to be a reason for insider threat at service provider organisations.
It is encouraging to note that not even a single respondent in service provider organisations considers competition as a driving force for insider threat. This observation is supported by client organisations.
Interestingly, most of the factors such as dissatisfaction with organisational policy, dissatisfaction with immediate supervisor, feeling of entitlement, urge to prove oneself, breaking existing norms and unmet expectations, that lead to insider threats can be controlled. This means that by understanding such (controllable) motivational factors, an organisation can tune its policies to contain insider incidents.

  1. An insider is more likely to make such a breach.

  2. Inside attackers are a bigger risk factor.

  3. Security is compromised for no reason at all.

  4. Both (1) and (2)

  5. None of these

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

It is given that “though likelihood of the attack from insiders may be very low as compared to external threats, the magnitude of the impact is at least ten times more (bigger risk factor) than that of the total impact an external attacker can cause.” So, option (2) will be correct.

Multiple choice
  1. Providing protection against internal threats

  2. Implementation of audits and alarms

  3. Acting as a network address translator

  4. Performing network management functions

  5. Serving as a platform for IPSec

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A firewall cannot give protection against internal threats present within the system. It also cannot prevent transfer of virus-infected programs or files.

Multiple choice
  1. machine readable badges and electronic smart cards

  2. fingerprints

  3. vault cards

  4. Both 1 and 2

  5. Both 2 and 3

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Artifact-based authentication system refers to the use of machine readable badges which help in authentication of the user. Electronic smart cards also contain a magnetic strip which is read by the device to authentic its use.

Multiple choice
  1. Mandatory access control

  2. Role based access control

  3. Asymmetric key cryptography

  4. Symmetric key cryptography

  5. Identification system

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

It controls access based on the positions that users have within the system and on rules stating what accesses are allowed to users in given positions.