Computer Knowledge · General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is NOT a type of hotel access control system?

  1. Key cards

  2. Facial recognition

  3. PIN codes

  4. Biometric scanners

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

PIN codes are not typically used as a form of hotel access control, although they may be used for other purposes, such as accessing Wi-Fi networks.

Multiple choice

What is the role of SSL certificates in securing e-commerce transactions?

  1. To encrypt data transmitted between the customer's browser and the merchant's website

  2. To verify the identity of the merchant's website

  3. To prevent unauthorized access to customer data

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

SSL certificates play a crucial role in securing e-commerce transactions by encrypting data transmitted between the customer's browser and the merchant's website, verifying the identity of the merchant's website, and preventing unauthorized access to customer data.

Multiple choice

Which of the following is a common type of fraud in e-commerce?

  1. Phishing

  2. Carding

  3. Identity theft

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Phishing, carding, and identity theft are all common types of fraud in e-commerce. Phishing is a type of online fraud where criminals attempt to obtain sensitive information such as passwords and credit card numbers by disguising themselves as legitimate businesses or organizations. Carding is a type of fraud where criminals use stolen or counterfeit credit card numbers to make purchases online. Identity theft is a type of fraud where criminals use someone else's personal information to make purchases or open accounts.

Multiple choice

Which of the following is a common type of 3D Secure authentication method?

  1. One-time password (OTP)

  2. Fingerprint scan

  3. Facial recognition

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

One-time password (OTP), fingerprint scan, and facial recognition are all common types of 3D Secure authentication methods.

Multiple choice

Which of the following is a common method for tokenizing data in e-commerce?

  1. Encryption

  2. Hashing

  3. Masking

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Encryption, hashing, and masking are all common methods for tokenizing data in e-commerce.

Multiple choice

Which of the following is a requirement for PCI DSS compliance?

  1. Implementing strong security measures

  2. Regularly monitoring and testing systems

  3. Maintaining a secure network

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Implementing strong security measures, regularly monitoring and testing systems, and maintaining a secure network are all requirements for PCI DSS compliance.

Multiple choice

What is the role of firewalls in securing e-commerce websites?

  1. To block unauthorized access to the website

  2. To prevent malware and viruses from infecting the website

  3. To protect customer data from unauthorized access

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Firewalls play a crucial role in securing e-commerce websites by blocking unauthorized access to the website, preventing malware and viruses from infecting the website, and protecting customer data from unauthorized access.

Multiple choice

What is the primary goal of optimization in signature-based intrusion detection?

  1. Maximizing Detection Rate

  2. Minimizing False Positives

  3. Balancing Detection Rate and False Positives

  4. Reducing Computational Complexity

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

In signature-based intrusion detection, the goal of optimization is to find a set of signatures that maximizes the detection rate while minimizing false positives. This balance is crucial to ensure that the intrusion detection system is both effective and efficient.

Multiple choice

In intrusion detection, what is the trade-off between detection rate and false positive rate?

  1. Higher detection rate leads to lower false positive rate

  2. Higher detection rate leads to higher false positive rate

  3. Lower detection rate leads to lower false positive rate

  4. Lower detection rate leads to higher false positive rate

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

In intrusion detection, there is a trade-off between detection rate and false positive rate. As the detection rate increases, the false positive rate also tends to increase. This is because the system becomes more sensitive to detecting intrusions, which can lead to more legitimate activities being误报 as intrusions.

Multiple choice

What is the purpose of using optimization in security analytics to detect zero-day attacks?

  1. Optimizing Data Collection

  2. Optimizing Data Analysis

  3. Optimizing Data Dissemination

  4. Optimizing Data Storage

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

In security analytics, optimization techniques are used to optimize the analysis of large volumes of security data to detect zero-day attacks. The goal is to identify patterns and anomalies that indicate the presence of zero-day attacks, which are previously unknown and highly sophisticated attacks that can evade traditional security defenses.

Multiple choice

How can data privacy and security be protected in sports technology?

  1. Encryption

  2. Access control

  3. Data retention policies

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

All of the above can be used to protect data privacy and security in sports technology.

Multiple choice

Which of the following is NOT a common cybersecurity metric?

  1. Mean Time to Detect (MTTD)

  2. Mean Time to Respond (MTTR)

  3. Return on Security Investment (ROSI)

  4. Mean Time Between Failures (MTBF)

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

MTBF is a reliability metric used in engineering to measure the average time between failures of a system. It is not a specific cybersecurity metric.

Multiple choice

Which of the following is NOT a common cybersecurity measurement framework?

  1. NIST Cybersecurity Framework

  2. ISO 27001/27002

  3. COBIT

  4. PCI DSS

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

PCI DSS is a security standard specifically designed for the payment card industry, while the other options are more general cybersecurity frameworks.

Multiple choice

Which of the following is NOT a common cybersecurity metric for measuring the effectiveness of security controls?

  1. False Positive Rate (FPR)

  2. True Positive Rate (TPR)

  3. Mean Time to Resolution (MTTR)

  4. Detection Rate

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

MTTR is a metric used to measure the time it takes to resolve a security incident, while the other options are metrics for evaluating the performance of security controls.

Multiple choice

Which of the following is NOT a common cybersecurity metric for measuring risk exposure?

  1. Annualized Loss Expectancy (ALE)

  2. Single Loss Expectancy (SLE)

  3. Value at Risk (VaR)

  4. Mean Time to Failure (MTTF)

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

MTTF is a reliability metric used in engineering to measure the average time between failures of a system. It is not a specific cybersecurity metric for measuring risk exposure.