Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

What is the process of encrypting data before transmitting it over a network called?

  1. Authentication

  2. Encryption

  3. Authorization

  4. Non-repudiation

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Encryption involves converting data into a form that cannot be easily understood by unauthorized parties, ensuring the confidentiality of the information.

Multiple choice

Which of the following is a common type of network security attack that involves exploiting vulnerabilities in software to gain unauthorized access to a system?

  1. Malware

  2. Buffer Overflow

  3. Cross-Site Scripting (XSS)

  4. Man-in-the-Middle Attack

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Buffer overflow attacks exploit weaknesses in software that allow attackers to overwrite memory buffers, potentially leading to unauthorized code execution.

Multiple choice

What is the process of verifying the identity of a user or device before granting access to a network or resource called?

  1. Authentication

  2. Authorization

  3. Encryption

  4. Non-repudiation

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Authentication involves verifying the identity of a user or device to ensure that only authorized individuals have access to specific resources.

Multiple choice

Which of the following is a common type of network security attack that involves injecting malicious code into a legitimate website or application?

  1. Cross-Site Scripting (XSS)

  2. SQL Injection

  3. Buffer Overflow

  4. Malware

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Cross-Site Scripting (XSS) attacks involve injecting malicious code into a legitimate website or application, allowing attackers to execute arbitrary code in a user's browser.

Multiple choice

What is the process of granting specific permissions or privileges to users or devices to access certain resources or perform certain actions called?

  1. Authentication

  2. Authorization

  3. Encryption

  4. Non-repudiation

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Authorization involves granting specific permissions or privileges to users or devices to access certain resources or perform certain actions based on their roles or attributes.

Multiple choice

Which of the following is a common type of network security attack that involves intercepting and modifying data in transit between two parties?

  1. Man-in-the-Middle Attack

  2. Cross-Site Scripting (XSS)

  3. Buffer Overflow

  4. SQL Injection

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Man-in-the-Middle attacks involve intercepting and modifying data in transit between two parties, allowing attackers to eavesdrop on communications or impersonate one of the parties.

Multiple choice

What is the process of ensuring that a message or transaction cannot be denied by the sender or receiver called?

  1. Authentication

  2. Authorization

  3. Encryption

  4. Non-repudiation

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Non-repudiation ensures that a message or transaction cannot be denied by the sender or receiver, providing accountability and preventing disputes.

Multiple choice

Which of the following is a common type of network security attack that involves exploiting vulnerabilities in web applications to gain unauthorized access to sensitive data?

  1. Cross-Site Scripting (XSS)

  2. SQL Injection

  3. Buffer Overflow

  4. Malware

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

SQL Injection attacks involve exploiting vulnerabilities in web applications that use SQL databases, allowing attackers to execute arbitrary SQL queries and potentially gain access to sensitive data.

Multiple choice

Which of the following is a common type of network security attack that involves sending malicious software or code to a victim's computer or device?

  1. Malware

  2. Buffer Overflow

  3. Cross-Site Scripting (XSS)

  4. SQL Injection

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Malware attacks involve sending malicious software or code to a victim's computer or device, allowing attackers to gain control of the system, steal sensitive data, or disrupt its operation.

Multiple choice

What is the process of identifying, assessing, and prioritizing security risks in a network or system called?

  1. Incident Response

  2. Risk Assessment

  3. Vulnerability Management

  4. Security Auditing

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Risk Assessment involves identifying, assessing, and prioritizing security risks in a network or system to determine the likelihood and potential impact of security threats.

Multiple choice

Which of the following is a common type of network security attack that involves exploiting vulnerabilities in network protocols or devices to gain unauthorized access or disrupt network operations?

  1. Malware

  2. Buffer Overflow

  3. Cross-Site Scripting (XSS)

  4. Network Attack

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Network attacks involve exploiting vulnerabilities in network protocols or devices to gain unauthorized access or disrupt network operations, such as denial-of-service attacks or man-in-the-middle attacks.

Multiple choice

Which of the following is NOT a common type of cyberattack targeting transportation systems?

  1. Ransomware attacks

  2. Malware infections

  3. Phishing attacks

  4. Physical attacks

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Physical attacks, such as sabotage or tampering with physical infrastructure, are not typically considered cyberattacks, although they can have similar consequences.

Multiple choice

What is the term used to describe the unauthorized access, use, disclosure, disruption, modification, or destruction of transportation systems or data?

  1. Cybersecurity breach

  2. Cybersecurity incident

  3. Cybersecurity attack

  4. Cybersecurity threat

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A cybersecurity breach refers to the unauthorized access, use, disclosure, disruption, modification, or destruction of transportation systems or data.

Multiple choice

Which of the following is NOT a common cybersecurity vulnerability in transportation systems?

  1. Weak passwords

  2. Unpatched software

  3. Lack of encryption

  4. Insufficient physical security

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Insufficient physical security, such as inadequate access control or lack of surveillance, is not typically considered a cybersecurity vulnerability, although it can contribute to cybersecurity risks.

Multiple choice

Which of the following is NOT a common cybersecurity best practice for transportation organizations?

  1. Regularly updating software and firmware

  2. Implementing strong access control measures

  3. Educating employees about cybersecurity risks

  4. Ignoring cybersecurity incidents

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Ignoring cybersecurity incidents is not a best practice and can lead to severe consequences. Organizations should promptly investigate and respond to cybersecurity incidents.