Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
B
Correct answer
Explanation
The Tor browser is specifically designed to anonymize web traffic by routing it through multiple volunteer nodes, making it difficult for third parties to track user activity or intercept data.
-
Enables transmission of sensitive data via encrypted connections.
-
Allow database access from application servers
-
Setting up DMZ networks
-
Prevents unauthorized people from eavesdropping on traffic.
A,D
Correct answer
Explanation
VPNs are primarily used to provide secure, encrypted communication (A) and to protect traffic from unauthorized interception or eavesdropping (D).
When would "auditing around the computer" be appropriate?
-
When controls over the computer system are strong.
-
When controls over the computer system are non-existent.
-
When controls over the computer system are adequate.
-
It is never appropriate to audit around the computer.
B
Correct answer
Explanation
Auditing around the computer is one of the methods of evaluating a client's computer controls. It picks source documents randomly and verifies the outputs with the inputs. This method can only exist when controls over the computer system are non-existent.
What is the role of the Indian Computer Emergency Response Team (CERT-In) in cybersecurity?
-
To respond to and mitigate cyberattacks
-
To provide cybersecurity advisories and alerts
-
To conduct cybersecurity research and development
-
To coordinate cybersecurity efforts with international partners
A
Correct answer
Explanation
The Indian Computer Emergency Response Team (CERT-In) is responsible for responding to and mitigating cyberattacks in India. CERT-In also provides cybersecurity advisories and alerts, conducts cybersecurity research and development, and coordinates cybersecurity efforts with international partners.
Which of the following is a common penetration testing technique used to identify vulnerabilities in web applications?
-
Social engineering
-
Port scanning
-
SQL injection
-
Buffer overflow
C
Correct answer
Explanation
SQL injection is a technique used to exploit vulnerabilities in web applications that allow attackers to execute arbitrary SQL queries. This can lead to unauthorized access to sensitive data, modification of data, or even complete compromise of the application.
Which of the following is a common type of social engineering attack?
-
Phishing
-
Vishing
-
Smishing
-
All of the above
D
Correct answer
Explanation
Phishing, vishing, and smishing are all types of social engineering attacks that involve tricking users into revealing sensitive information or taking actions that compromise their security. Phishing attacks are conducted via email, vishing attacks are conducted via phone calls, and smishing attacks are conducted via text messages.
Which of the following is a common type of vulnerability scanner?
-
Nessus
-
OpenVAS
-
Qualys
-
All of the above
D
Correct answer
Explanation
Nessus, OpenVAS, and Qualys are all popular vulnerability scanners used to identify vulnerabilities in systems and applications.
Which of the following is a common type of penetration testing methodology?
-
OSSTMM
-
PTES
-
OWASP
-
All of the above
D
Correct answer
Explanation
OSSTMM (Open Source Security Testing Methodology Manual), PTES (Penetration Testing Execution Standard), and OWASP (Open Web Application Security Project) are all popular penetration testing methodologies that provide a structured approach to conducting penetration tests.
Which of the following is a common type of penetration testing tool?
-
Metasploit
-
Burp Suite
-
Wireshark
-
All of the above
D
Correct answer
Explanation
Metasploit, Burp Suite, and Wireshark are all popular penetration testing tools used to identify vulnerabilities, exploit vulnerabilities, and analyze network traffic.
What is the importance of penetration testing in cybersecurity?
-
It helps identify vulnerabilities in systems and applications.
-
It helps improve the security of systems and applications.
-
It helps prevent unauthorized access to systems and applications.
-
All of the above
D
Correct answer
Explanation
Penetration testing is important in cybersecurity because it helps identify vulnerabilities in systems and applications, improve the security of systems and applications, and prevent unauthorized access to systems and applications.
Which of the following is NOT a factor that can be considered in determining whether an individual is a national security risk?
-
Criminal history
-
Terrorist ties
-
Political beliefs
-
Religious beliefs
D
Correct answer
Explanation
Religious beliefs are not a factor that can be considered in determining whether an individual is a national security risk.
Which of the following is NOT a common type of cyberattack that can target critical infrastructure?
-
Malware attacks
-
Phishing attacks
-
Distributed Denial-of-Service (DDoS) attacks
-
Physical attacks
D
Correct answer
Explanation
Physical attacks involve direct physical damage or disruption to critical infrastructure facilities, while malware attacks, phishing attacks, and DDoS attacks are all types of cyberattacks.
What are some of the key security considerations for M2M communication?
-
Authentication and authorization
-
Data encryption
-
Network security
-
Device security
-
All of the above
E
Correct answer
Explanation
M2M communication requires robust security measures to protect against unauthorized access, data breaches, and other security threats.
Which of the following is a common type of automotive cyberattack?
-
Malware injection
-
Vehicle immobilization
-
Data manipulation
-
All of the above
D
Correct answer
Explanation
Automotive cyberattacks can take various forms, including malware injection, vehicle immobilization, data manipulation, and more. These attacks can compromise vehicle safety, functionality, and privacy.
Which of the following is a common type of automotive data security breach?
-
Unauthorized access to vehicle location data
-
Theft of personal information from infotainment systems
-
Manipulation of vehicle diagnostic data
-
All of the above
D
Correct answer
Explanation
Automotive data security breaches can take various forms, including unauthorized access to vehicle location data, theft of personal information from infotainment systems, manipulation of vehicle diagnostic data, and more. These breaches can compromise vehicle safety, functionality, and privacy.