Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice
  1. Enables transmission of sensitive data via encrypted connections.

  2. Allow database access from application servers

  3. Setting up DMZ networks

  4. Prevents unauthorized people from eavesdropping on traffic.

Reveal answer Fill a bubble to check yourself
A,D Correct answer
Explanation

VPNs are primarily used to provide secure, encrypted communication (A) and to protect traffic from unauthorized interception or eavesdropping (D).

Multiple choice organization of commerce and management management by objectives (mbo) and management by exception (mbe) meaning and definition of mbo meaning and definition of mbe controlling

When would "auditing around the computer" be appropriate?

  1. When controls over the computer system are strong.

  2. When controls over the computer system are non-existent.

  3. When controls over the computer system are adequate.

  4. It is never appropriate to audit around the computer.

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Auditing around the computer is one of the methods of evaluating a client's computer controls. It picks source documents randomly and verifies the outputs with the inputs. This method can only exist when controls over the computer system are non-existent.

Multiple choice

What is the role of the Indian Computer Emergency Response Team (CERT-In) in cybersecurity?

  1. To respond to and mitigate cyberattacks

  2. To provide cybersecurity advisories and alerts

  3. To conduct cybersecurity research and development

  4. To coordinate cybersecurity efforts with international partners

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The Indian Computer Emergency Response Team (CERT-In) is responsible for responding to and mitigating cyberattacks in India. CERT-In also provides cybersecurity advisories and alerts, conducts cybersecurity research and development, and coordinates cybersecurity efforts with international partners.

Multiple choice

Which of the following is a common penetration testing technique used to identify vulnerabilities in web applications?

  1. Social engineering

  2. Port scanning

  3. SQL injection

  4. Buffer overflow

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

SQL injection is a technique used to exploit vulnerabilities in web applications that allow attackers to execute arbitrary SQL queries. This can lead to unauthorized access to sensitive data, modification of data, or even complete compromise of the application.

Multiple choice

Which of the following is a common type of social engineering attack?

  1. Phishing

  2. Vishing

  3. Smishing

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Phishing, vishing, and smishing are all types of social engineering attacks that involve tricking users into revealing sensitive information or taking actions that compromise their security. Phishing attacks are conducted via email, vishing attacks are conducted via phone calls, and smishing attacks are conducted via text messages.

Multiple choice

Which of the following is a common type of vulnerability scanner?

  1. Nessus

  2. OpenVAS

  3. Qualys

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Nessus, OpenVAS, and Qualys are all popular vulnerability scanners used to identify vulnerabilities in systems and applications.

Multiple choice

Which of the following is a common type of penetration testing methodology?

  1. OSSTMM

  2. PTES

  3. OWASP

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

OSSTMM (Open Source Security Testing Methodology Manual), PTES (Penetration Testing Execution Standard), and OWASP (Open Web Application Security Project) are all popular penetration testing methodologies that provide a structured approach to conducting penetration tests.

Multiple choice

Which of the following is a common type of penetration testing tool?

  1. Metasploit

  2. Burp Suite

  3. Wireshark

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Metasploit, Burp Suite, and Wireshark are all popular penetration testing tools used to identify vulnerabilities, exploit vulnerabilities, and analyze network traffic.

Multiple choice

What is the importance of penetration testing in cybersecurity?

  1. It helps identify vulnerabilities in systems and applications.

  2. It helps improve the security of systems and applications.

  3. It helps prevent unauthorized access to systems and applications.

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Penetration testing is important in cybersecurity because it helps identify vulnerabilities in systems and applications, improve the security of systems and applications, and prevent unauthorized access to systems and applications.

Multiple choice

Which of the following is NOT a factor that can be considered in determining whether an individual is a national security risk?

  1. Criminal history

  2. Terrorist ties

  3. Political beliefs

  4. Religious beliefs

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Religious beliefs are not a factor that can be considered in determining whether an individual is a national security risk.

Multiple choice

Which of the following is NOT a common type of cyberattack that can target critical infrastructure?

  1. Malware attacks

  2. Phishing attacks

  3. Distributed Denial-of-Service (DDoS) attacks

  4. Physical attacks

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Physical attacks involve direct physical damage or disruption to critical infrastructure facilities, while malware attacks, phishing attacks, and DDoS attacks are all types of cyberattacks.

Multiple choice

What are some of the key security considerations for M2M communication?

  1. Authentication and authorization

  2. Data encryption

  3. Network security

  4. Device security

  5. All of the above

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

M2M communication requires robust security measures to protect against unauthorized access, data breaches, and other security threats.

Multiple choice

Which of the following is a common type of automotive cyberattack?

  1. Malware injection

  2. Vehicle immobilization

  3. Data manipulation

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Automotive cyberattacks can take various forms, including malware injection, vehicle immobilization, data manipulation, and more. These attacks can compromise vehicle safety, functionality, and privacy.

Multiple choice

Which of the following is a common type of automotive data security breach?

  1. Unauthorized access to vehicle location data

  2. Theft of personal information from infotainment systems

  3. Manipulation of vehicle diagnostic data

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Automotive data security breaches can take various forms, including unauthorized access to vehicle location data, theft of personal information from infotainment systems, manipulation of vehicle diagnostic data, and more. These breaches can compromise vehicle safety, functionality, and privacy.