Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is a type of malware that encrypts files and demands a ransom payment to decrypt them?

  1. Virus

  2. Trojan horse

  3. Ransomware

  4. Worm

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Ransomware is a type of malware that encrypts files on a victim's computer and demands a ransom payment to decrypt them.

Multiple choice

What is the term for a network of computers infected with malware and controlled by a single entity?

  1. Botnet

  2. Zombie network

  3. DDoS network

  4. Malware network

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A botnet is a network of computers infected with malware and controlled by a single entity, often used to launch cyberattacks or spread malware.

Multiple choice

Which of the following is a common method used to protect sensitive data during transmission?

  1. Encryption

  2. Hashing

  3. Steganography

  4. Digital signature

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Encryption is a common method used to protect sensitive data during transmission by converting it into an unreadable format.

Multiple choice

What is the term for a security measure that involves restricting access to certain resources or information based on specific criteria?

  1. Authentication

  2. Authorization

  3. Encryption

  4. Non-repudiation

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Authorization is a security measure that involves restricting access to certain resources or information based on specific criteria, such as user roles or permissions.

Multiple choice

Which of the following is a type of cyberattack that involves flooding a target system or network with excessive traffic to disrupt its normal operation?

  1. Phishing

  2. Malware

  3. Denial-of-service (DoS)

  4. Man-in-the-middle (MitM)

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

A denial-of-service (DoS) attack involves flooding a target system or network with excessive traffic to disrupt its normal operation.

Multiple choice

What is the term for a security measure that involves monitoring and analyzing system logs and events to detect suspicious activities?

  1. Intrusion detection system (IDS)

  2. Firewall

  3. Antivirus software

  4. Security information and event management (SIEM)

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

An intrusion detection system (IDS) is a security measure that involves monitoring and analyzing system logs and events to detect suspicious activities that may indicate a security breach.

Multiple choice

Which of the following is a common type of security monitoring tool?

  1. Intrusion Detection System (IDS)

  2. Security Information and Event Management (SIEM)

  3. Vulnerability Scanner

  4. Penetration Testing Tool

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

SIEM is a widely used security monitoring tool that collects, aggregates, and analyzes security-related events from various sources to provide a comprehensive view of an organization's security posture.

Multiple choice

Which of the following is a common compliance auditing standard for cybersecurity?

  1. ISO 27001

  2. NIST Cybersecurity Framework

  3. PCI DSS

  4. HIPAA

Reveal answer Fill a bubble to check yourself
Correct answer
Explanation

ISO 27001, NIST Cybersecurity Framework, PCI DSS, and HIPAA are widely recognized compliance auditing standards for cybersecurity.

Multiple choice

Which of the following is a common type of cybersecurity audit?

  1. Internal Audit

  2. External Audit

  3. Compliance Audit

  4. Risk Assessment

Reveal answer Fill a bubble to check yourself
Correct answer
Explanation

Internal Audit, External Audit, Compliance Audit, and Risk Assessment are common types of cybersecurity audits.

Multiple choice

Which of the following is a common type of vulnerability assessment tool?

  1. Network Scanner

  2. Web Application Scanner

  3. Host-Based Scanner

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Network Scanner, Web Application Scanner, and Host-Based Scanner are common types of vulnerability assessment tools.

Multiple choice

Which of the following is a common type of security monitoring tool?

  1. Log Management System

  2. Security Information and Event Management (SIEM)

  3. Intrusion Detection System (IDS)

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Log Management System, Security Information and Event Management (SIEM), and Intrusion Detection System (IDS) are common types of security monitoring tools.

Multiple choice

Which of the following is a common type of cybersecurity audit?

  1. Financial Audit

  2. Operational Audit

  3. IT Audit

  4. All of the above

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

IT Audit is a common type of cybersecurity audit that focuses on assessing the security of an organization's information technology systems and infrastructure.

Multiple choice

Which of the following is NOT a common type of cyberattack?

  1. Phishing

  2. Malware

  3. DDoS

  4. Social engineering

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

DDoS (Distributed Denial of Service) attacks are not a common type of cyberattack. Phishing, malware, and social engineering are more prevalent types of cyberattacks that target individuals or organizations.

Multiple choice

Which of the following is NOT a good practice for protecting against phishing attacks?

  1. Hovering over links before clicking

  2. Enabling two-factor authentication

  3. Using a strong password

  4. Ignoring suspicious emails

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Ignoring suspicious emails is not a good practice for protecting against phishing attacks. Users should be cautious of emails from unknown senders, emails with suspicious attachments or links, and emails that request personal information.

Multiple choice

What is the purpose of a firewall?

  1. To block unauthorized access to a network

  2. To detect and remove malware

  3. To encrypt data

  4. To back up data

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A firewall is a network security device that monitors and controls incoming and outgoing network traffic based on predetermined security rules. Its primary purpose is to block unauthorized access to a network.