Computer Knowledge · General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
-
to facilitate access to external networks
-
to stop the target server from being able to handle requests
-
to scan the data on the target server
-
to obtain all addresses in the address book in the server
B
Correct answer
Explanation
A Denial of Service (DoS) attack aims to disrupt or completely shut down a network, service, or server, making it unavailable to its intended users. This is typically achieved by overwhelming the target with a flood of superfluous requests.
-
establishing personal firewalls on each computer
-
encrypting all sensitive data that is stored on the servers
-
employees must use a card key when entering a secure area
-
ensuring that all os and antivirus software is up to date
C
Correct answer
Explanation
Physical security involves measures designed to safeguard personnel, hardware, programs, networks, and data from physical circumstances and events. Requiring a card key to enter a secure area directly controls physical access to the facility, unlike firewalls, encryption, and software updates, which are logical or digital security measures.
-
Unseat and reconnect the hard drive connectors on the host.
-
Disconnect the host from the network
-
Check the host hard drive for errors and file system issues.
-
Examine the Device Manager on the host for device conflicts.
B
Correct answer
Explanation
Disconnecting the host from the network is an immediate way to isolate the device and observe if the network traffic flood stops. If the network performance improves immediately after disconnection, it confirms that the specific host was the source of the traffic.
-
An attack that uses TCP/IP messages to flood ports
-
An attack where computers use false IP and MAC addresses
-
A malicious software to
-
The use of personal information to trick users
B
Correct answer
Explanation
Spoofing is a technique where an attacker masquerades as another device or user on a network by falsifying data, such as IP or MAC addresses, to bypass access controls. This allows the attacker to intercept traffic or gain unauthorized access to systems.
-
watering-hole attack
-
whaling
-
pharming
-
spear phising
C
Correct answer
Explanation
Pharming redirects a user to a fraudulent website, often by corrupting DNS entries, even if the user types the correct URL.
-
botnet
-
zombies
-
bot herder
-
zombie herder
A
Correct answer
Explanation
A botnet is a network of computers infected with malware that allows an attacker to control them remotely. The infected computers are called 'zombies' or 'bots.' Bot herders are the attackers who control the botnet.
-
phising
-
pharming
-
hoax
-
vishing
C
Correct answer
Explanation
A hoax is a false warning designed to trick users into taking actions that compromise security, like changing settings or revealing credentials. Phishing steals data directly, pharming redirects to fake sites, and vishing uses phone calls - but hoaxes rely on false warnings.
-
Enable System Restore and create a restore point
-
Educate the user about how to avoid malware
-
Update the antivirus software and run a full system scan
-
Move the infected system to a lab with no network connectivity
D
Correct answer
Explanation
When malware is identified, the first priority is containing the threat by isolating the system from the network to prevent spread or data exfiltration. Moving to a lab with no network connectivity is the immediate containment step. Updates, scans, and user education come after containment.
-
Phising
-
Spear Phising
-
Spoofing
-
Impersonation
B
Correct answer
Explanation
Spear phishing uses personalized information about specific targets to make attacks more convincing. Unlike generic phishing which casts a wide net, spear phishing tailors messages using the victim's name, role, or other personal details. Spoofing fakes identities, and impersonation pretends to be someone else - but spear phishing is defined by its personalized approach.
-
Dumpster diving
-
Phising
-
Spear phising
-
Impersonation
A
Correct answer
Explanation
Dumpster diving involves searching through trash or recycling bins to find sensitive information like passwords, account numbers, or corporate documents. This physical social engineering attack exploits improper disposal practices. Phishing and spear phishing use electronic messages, while impersonation involves pretending to be someone else.
-
Give your information out
-
Put your password in your pocket
-
Share your password
-
Keep your Password as a secrect
D
Correct answer
Explanation
Keeping your password strictly confidential is fundamental to preventing unauthorized access and interception. Sharing your password or giving out personal information directly compromises your security.
-
Fake Messages
-
phishing
-
Fraudulent E-mails
-
fishing
C
Correct answer
Explanation
Phishing refers to the practice of sending fraudulent emails that mimic legitimate organizations to trick recipients into revealing sensitive information like passwords or credit card numbers. While it can involve other communication channels, fraudulent emails are the most common form.
-
Wall on fire in your house
-
To protect Your network from hackers
-
Burning wall
-
To protect your wall from fire
B
Correct answer
Explanation
A firewall is a security system designed to prevent unauthorized access to or from a private network. It acts as a barrier, filtering incoming and outgoing traffic based on established security rules to block potential threats.
-
cyber crime
-
hacking
-
coding
-
breakthrough
B
Correct answer
Explanation
Hacking refers to the practice of manipulating computer systems to gain unauthorized access to data or networks. While hacking is a type of cybercrime, the specific action of gaining unauthorized access is most directly defined as hacking.
-
theft
-
robbery
-
phishing
-
phising
C
Correct answer
Explanation
Phishing is a cybercrime where targets are contacted by email, telephone, or text message by someone posing as a legitimate institution to lure individuals into providing sensitive data. The spelling in option C is correct, while option D is a common misspelling.