Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
What is the term used to describe the unauthorized access, use, or disclosure of sensitive personal information?
-
Data breach.
-
Cyber attack.
-
Cyber extortion.
-
Identity theft.
A
Correct answer
Explanation
A data breach is the unauthorized access, use, or disclosure of sensitive personal information, such as names, addresses, social security numbers, or credit card numbers.
What is the term used to describe a cyber attack in which an attacker threatens to release sensitive information unless a ransom is paid?
-
Phishing.
-
Malware.
-
DDoS attacks.
-
Cyber extortion.
D
Correct answer
Explanation
Cyber extortion is a type of cyber attack in which an attacker threatens to release sensitive information unless a ransom is paid.
What is the term used to describe a cyber attack in which an attacker floods a website or online service with traffic, making it unavailable to legitimate users?
-
Phishing.
-
Malware.
-
DDoS attacks.
-
Man-in-the-middle attacks.
C
Correct answer
Explanation
DDoS attacks (Distributed Denial of Service attacks) are cyber attacks in which an attacker floods a website or online service with traffic, making it unavailable to legitimate users.
What is the term used to describe a cyber attack in which an attacker intercepts communications between two parties and impersonates one of them?
-
Phishing.
-
Malware.
-
DDoS attacks.
-
Man-in-the-middle attacks.
D
Correct answer
Explanation
Man-in-the-middle attacks are cyber attacks in which an attacker intercepts communications between two parties and impersonates one of them.
What is the best way to protect against phishing attacks?
-
Use strong passwords and change them regularly.
-
Be cautious of emails and messages from unknown senders.
-
Never click on links or open attachments in suspicious emails or messages.
-
All of the above.
D
Correct answer
Explanation
The best way to protect against phishing attacks is to use strong passwords and change them regularly, be cautious of emails and messages from unknown senders, and never click on links or open attachments in suspicious emails or messages.
What is the best way to protect against malware attacks?
-
Install and update antivirus software.
-
Be cautious of downloading files from unknown sources.
-
Keep your operating system and software up to date.
-
All of the above.
D
Correct answer
Explanation
The best way to protect against malware attacks is to install and update antivirus software, be cautious of downloading files from unknown sources, and keep your operating system and software up to date.
What is the best way to protect against DDoS attacks?
-
Use a firewall.
-
Implement rate limiting.
-
Use a content delivery network (CDN).
-
All of the above.
D
Correct answer
Explanation
The best way to protect against DDoS attacks is to use a firewall, implement rate limiting, and use a content delivery network (CDN).
What is the best way to protect against man-in-the-middle attacks?
-
Use strong passwords and change them regularly.
-
Use a VPN when connecting to public Wi-Fi networks.
-
Be cautious of using public Wi-Fi networks.
-
All of the above.
D
Correct answer
Explanation
The best way to protect against man-in-the-middle attacks is to use strong passwords and change them regularly, use a VPN when connecting to public Wi-Fi networks, and be cautious of using public Wi-Fi networks.
What is the best way to prevent cyber attacks?
-
Implement a comprehensive cybersecurity program.
-
Educate employees about cybersecurity risks.
-
Use strong passwords and change them regularly.
-
All of the above.
D
Correct answer
Explanation
The best way to prevent cyber attacks is to implement a comprehensive cybersecurity program, educate employees about cybersecurity risks, and use strong passwords and change them regularly.
Which of the following is NOT a common MDM security feature?
-
Device encryption
-
Remote wipe
-
Two-factor authentication
-
Jailbreaking or rooting detection
D
Correct answer
Explanation
Jailbreaking or rooting detection is not a standard MDM security feature, as it specifically applies to unauthorized modifications of iOS and Android devices, respectively.
Which of the following is NOT a common MDM security best practice?
-
Enforcing strong passwords
-
Enabling two-factor authentication
-
Jailbreaking or rooting devices
-
Regularly updating software and applications
C
Correct answer
Explanation
Jailbreaking or rooting devices is not a recommended security practice in MDM, as it compromises the device's security and may lead to vulnerabilities.
Which of the following is NOT a common MDM compliance requirement?
-
HIPAA
-
PCI DSS
-
GDPR
-
ISO 9001
D
Correct answer
Explanation
ISO 9001 is a quality management standard, while HIPAA, PCI DSS, and GDPR are regulations and standards related to data protection and privacy.
Which of the following is a common method used in cybersecurity vulnerability assessment?
-
Penetration testing.
-
Risk assessment.
-
Security audits.
-
Vulnerability scanning.
D
Correct answer
Explanation
Vulnerability scanning is a widely used method in cybersecurity vulnerability assessment. It involves using automated tools to scan IT systems and networks for known vulnerabilities, such as outdated software, misconfigurations, and weak passwords.
Which of the following is a best practice for conducting a cybersecurity vulnerability assessment?
-
Regularly updating vulnerability assessment tools and techniques.
-
Involving multiple stakeholders, including IT, security, and business teams.
-
Focusing solely on external vulnerabilities.
-
Ignoring low-risk vulnerabilities.
A
Correct answer
Explanation
Regularly updating vulnerability assessment tools and techniques is a crucial best practice. As new vulnerabilities are discovered and exploited, it is essential to use up-to-date tools and techniques to ensure that the assessment accurately identifies the latest vulnerabilities in an organization's IT systems.
Which of the following is a common tool used for vulnerability scanning in cybersecurity vulnerability assessment?
-
Nessus.
-
Wireshark.
-
Metasploit.
-
Nmap.
A
Correct answer
Explanation
Nessus is a widely used tool for vulnerability scanning in cybersecurity vulnerability assessment. It is a comprehensive vulnerability scanner that can identify a wide range of vulnerabilities in IT systems, including operating systems, applications, and network devices.