Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
Which of the following is NOT a common e-commerce platform security measure?
-
SSL (Secure Sockets Layer) encryption
-
Two-factor authentication (2FA)
-
Regular software updates and patches
-
Physical security measures for warehouses
D
Correct answer
Explanation
Physical security measures for warehouses are not directly related to e-commerce platform security.
Which of the following is an example of a data security measure used in astronomy?
-
Encryption
-
Authentication
-
Authorization
-
All of the above
D
Correct answer
Explanation
Encryption, authentication, and authorization are all examples of data security measures used in astronomy.
Which of the following is a key component of cybersecurity risk management?
-
Risk assessment
-
Risk mitigation
-
Risk acceptance
-
Risk transfer
A
Correct answer
Explanation
Risk assessment is the process of identifying, analyzing, and evaluating cybersecurity risks to determine their likelihood and impact.
Which of the following is a key element of a cybersecurity risk management plan?
-
Risk assessment
-
Risk mitigation
-
Risk acceptance
-
Risk transfer
Correct answer
Explanation
A cybersecurity risk management plan should include elements such as risk assessment, risk mitigation, risk acceptance, and risk transfer.
Which of the following is a key component of a cybersecurity incident response plan?
-
Incident detection and analysis
-
Incident containment and eradication
-
Incident recovery and restoration
-
All of the above
D
Correct answer
Explanation
A cybersecurity incident response plan should include components such as incident detection and analysis, incident containment and eradication, and incident recovery and restoration.
Which of the following is a common cybersecurity monitoring tool?
-
Security information and event management (SIEM)
-
Intrusion detection system (IDS)
-
Vulnerability scanner
-
All of the above
D
Correct answer
Explanation
Common cybersecurity monitoring tools include SIEM, IDS, and vulnerability scanners.
Which of the following is a common cybersecurity training topic?
-
Social engineering attacks
-
Password security
-
Phishing scams
-
All of the above
D
Correct answer
Explanation
Common cybersecurity training topics include social engineering attacks, password security, phishing scams, and other cybersecurity best practices.
Which of the following is a common cybersecurity audit standard?
-
ISO 27001
-
NIST Cybersecurity Framework
-
PCI DSS
-
All of the above
D
Correct answer
Explanation
Common cybersecurity audit standards include ISO 27001, NIST Cybersecurity Framework, and PCI DSS.
-
The protection of personal information from unauthorized access, use, or disclosure.
-
The protection of personal information from being used for harmful purposes.
-
The protection of personal information from being used for commercial purposes.
-
The protection of personal information from being used for political purposes.
A
Correct answer
Explanation
Data protection is the protection of personal information from unauthorized access, use, or disclosure.
What are some of the best practices for data protection?
-
Implementing strong security measures.
-
Educating employees about data protection.
-
Having a data protection policy in place.
-
Regularly reviewing and updating data protection practices.
-
All of the above.
E
Correct answer
Explanation
Some of the best practices for data protection include implementing strong security measures, educating employees about data protection, having a data protection policy in place, and regularly reviewing and updating data protection practices.
What are some of the key data protection laws and regulations?
-
The General Data Protection Regulation (GDPR).
-
The California Consumer Privacy Act (CCPA).
-
The Personal Information Protection and Electronic Documents Act (PIPEDA).
-
All of the above.
D
Correct answer
Explanation
Some of the key data protection laws and regulations include the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Personal Information Protection and Electronic Documents Act (PIPEDA).
Which of the following is a common type of adversarial attack?
-
Poisoning attack
-
Evasion attack
-
Model extraction attack
-
Privacy attack
B
Correct answer
Explanation
Evasion attacks involve modifying the input data to cause the machine learning model to make incorrect predictions, while preserving the integrity of the data.
Which of the following techniques can be used to defend against data poisoning attacks?
-
Data sanitization
-
Model regularization
-
Adversarial training
-
Differential privacy
A
Correct answer
Explanation
Data sanitization involves removing or correcting errors and malicious data from the training dataset before training the machine learning model.
Which of the following techniques can be used to defend against model extraction attacks?
-
Obfuscation
-
Steganography
-
Differential privacy
-
Adversarial training
A
Correct answer
Explanation
Obfuscation involves modifying the model parameters or architecture to make it more difficult to extract or interpret.
What are some common test security procedures?
-
Requiring test takers to show their identification before entering the testing room
-
Prohibiting the use of electronic devices during the test
-
Collecting all test materials at the end of the test
-
All of the above
D
Correct answer
Explanation
Common test security procedures include requiring test takers to show their identification before entering the testing room, prohibiting the use of electronic devices during the test, collecting all test materials at the end of the test, and using secure testing environments.