Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is an example of a social engineering attack?

  1. Phishing

  2. Malware

  3. Brute-force attack

  4. Zero-day attack

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Phishing is a type of social engineering attack in which an attacker sends a fraudulent email or text message that appears to be from a legitimate source in order to trick the recipient into giving up sensitive information, such as their password or credit card number.

Multiple choice

What is the term used for a type of cyberattack in which an attacker gains unauthorized access to a computer system by guessing the password?

  1. Phishing

  2. Malware

  3. Brute-force attack

  4. Zero-day attack

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

A brute-force attack is a type of cyberattack in which an attacker gains unauthorized access to a computer system by guessing the password. This type of attack is often used to crack passwords for online accounts or to gain access to encrypted files.

Multiple choice

What is the term used for a type of cyberattack in which an attacker gains unauthorized access to a computer system by exploiting a vulnerability in the system's hardware?

  1. Phishing

  2. Malware

  3. Side-channel attack

  4. Zero-day attack

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

A side-channel attack is a type of cyberattack in which an attacker gains unauthorized access to a computer system by exploiting a vulnerability in the system's hardware. This type of attack can be used to extract sensitive information, such as cryptographic keys, from a computer system without having to guess the password.

Multiple choice

Which of the following is a common defense mechanism used to protect against malware?

  1. Firewall

  2. Antivirus software

  3. Intrusion detection system

  4. All of the above

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Antivirus software is a common defense mechanism used to protect against malware. Antivirus software scans files for malicious code and removes it if it is found.

Multiple choice

What is the term used for a type of cyberattack in which an attacker gains unauthorized access to a computer system by exploiting a vulnerability in the system's software?

  1. Phishing

  2. Malware

  3. Buffer overflow attack

  4. Zero-day attack

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

A buffer overflow attack is a type of cyberattack in which an attacker gains unauthorized access to a computer system by exploiting a vulnerability in the system's software. This type of attack can be used to execute arbitrary code on the computer system.

Multiple choice

What is the term used for a type of cyberattack in which an attacker gains unauthorized access to a computer system by exploiting a vulnerability in the system's network configuration?

  1. Phishing

  2. Malware

  3. Man-in-the-middle attack

  4. Zero-day attack

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

A man-in-the-middle attack is a type of cyberattack in which an attacker gains unauthorized access to a computer system by exploiting a vulnerability in the system's network configuration. This type of attack can be used to intercept and modify data that is being transmitted between two parties.

Multiple choice

Which of the following is a common defense mechanism used to protect against man-in-the-middle attacks?

  1. Firewall

  2. Antivirus software

  3. Intrusion detection system

  4. Virtual private network (VPN)

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

A virtual private network (VPN) is a common defense mechanism used to protect against man-in-the-middle attacks. A VPN encrypts data that is being transmitted between two parties, making it difficult for an attacker to intercept and modify the data.

Multiple choice

What is the term used for a type of cyberattack in which an attacker gains unauthorized access to a computer system by exploiting a vulnerability in the system's operating system?

  1. Phishing

  2. Malware

  3. Kernel exploit

  4. Zero-day attack

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

A kernel exploit is a type of cyberattack in which an attacker gains unauthorized access to a computer system by exploiting a vulnerability in the system's operating system. This type of attack can be used to execute arbitrary code on the computer system.

Multiple choice

Which of the following is a common defense mechanism used to protect against kernel exploits?

  1. Firewall

  2. Antivirus software

  3. Intrusion detection system

  4. Patch management

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Patch management is a common defense mechanism used to protect against kernel exploits. Patch management involves regularly updating the operating system and software on a computer system with the latest security patches. This helps to fix vulnerabilities that could be exploited by attackers.

Multiple choice

What is the term used for a type of cyberattack in which an attacker gains unauthorized access to a computer system by exploiting a vulnerability in the system's application software?

  1. Phishing

  2. Malware

  3. Application exploit

  4. Zero-day attack

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

An application exploit is a type of cyberattack in which an attacker gains unauthorized access to a computer system by exploiting a vulnerability in the system's application software. This type of attack can be used to execute arbitrary code on the computer system.

Multiple choice

Which of the following is a common defense mechanism used to protect against application exploits?

  1. Firewall

  2. Antivirus software

  3. Intrusion detection system

  4. Secure coding practices

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Secure coding practices are a common defense mechanism used to protect against application exploits. Secure coding practices involve writing code that is free of vulnerabilities that could be exploited by attackers.

Multiple choice

What is the term used to describe the malicious act of disrupting or damaging critical infrastructure, including energy systems, through cyber attacks?

  1. Cyberterrorism

  2. Cyberwarfare

  3. Cybercrime

  4. Cyber espionage

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Cyberterrorism is the deliberate use of cyber attacks to cause harm or disruption to critical infrastructure, including energy systems, with the intent to intimidate or coerce a government or population.

Multiple choice

Which of the following is NOT a common type of cyber attack used against energy systems?

  1. Malware

  2. Phishing

  3. Distributed denial-of-service (DDoS)

  4. Man-in-the-middle (MitM)

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Phishing is a type of cyber attack that attempts to trick individuals into revealing sensitive information, such as passwords or financial data, by disguising itself as a legitimate entity. While phishing is a common type of cyber attack, it is not typically used against energy systems.

Multiple choice

Which of the following is NOT a recommended cybersecurity practice for energy companies to protect their systems from cyber attacks?

  1. Implementing strong passwords and multi-factor authentication

  2. Regularly updating software and firmware

  3. Educating and training employees on cybersecurity

  4. Leaving remote access ports open for convenience

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Leaving remote access ports open for convenience is not a recommended cybersecurity practice, as it can provide an easy entry point for attackers to gain access to energy systems.

Multiple choice

Which of the following is NOT a recommended cybersecurity practice for energy companies to protect their systems from cyber attacks?

  1. Implementing firewalls and intrusion detection systems

  2. Regularly backing up data

  3. Using outdated software and firmware

  4. Educating and training employees on cybersecurity

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Using outdated software and firmware is not a recommended cybersecurity practice, as it can contain vulnerabilities that can be exploited by attackers.