Computer Knowledge ยท General Awareness
Information Security
4,634 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
Which of the following is NOT a common type of social engineering attack?
-
Baiting
-
Tailgating
-
Pretexting
-
Quid Pro Quo
D
Correct answer
Explanation
Quid Pro Quo is not a common type of social engineering attack.
What is the term used to describe a type of cybercrime in which an attacker uses malicious software to gain unauthorized access to a computer system or network?
-
Malware Attack
-
Phishing Attack
-
DDoS Attack
-
Man-in-the-Middle Attack
A
Correct answer
Explanation
Malware attacks are a common type of cybercrime that can be used to steal personal information, compromise online accounts, and disrupt computer systems.
Which of the following is a primary concern for non-profit organizations regarding cybersecurity?
-
Protecting sensitive donor information
-
Maintaining compliance with industry regulations
-
Ensuring the integrity of financial transactions
-
All of the above
D
Correct answer
Explanation
Non-profit organizations handle sensitive data, including donor information, financial records, and personal data of beneficiaries. They must prioritize cybersecurity to protect this data from unauthorized access, theft, or misuse.
Which type of cyberattack is most commonly used to target non-profit organizations?
-
Phishing attacks
-
Malware attacks
-
Ransomware attacks
-
Distributed denial-of-service (DDoS) attacks
A
Correct answer
Explanation
Phishing attacks are a common method used to target non-profit organizations. These attacks attempt to trick employees or volunteers into providing sensitive information, such as login credentials or financial data, by posing as legitimate organizations or individuals.
Which of the following is a best practice for non-profit organizations to protect against ransomware attacks?
-
Regularly backing up data
-
Implementing strong access controls
-
Educating employees and volunteers about ransomware
-
All of the above
D
Correct answer
Explanation
Non-profit organizations should implement a combination of measures to protect against ransomware attacks, including regular data backups, strong access controls, and employee education.
Which of the following is a best practice for non-profit organizations to protect against phishing attacks?
-
Educating employees and volunteers about phishing
-
Implementing email filtering and anti-malware software
-
Enabling two-factor authentication
-
All of the above
D
Correct answer
Explanation
Non-profit organizations should implement a combination of measures to protect against phishing attacks, including educating employees and volunteers, implementing email filtering and anti-malware software, and enabling two-factor authentication.
Which of the following is a legal requirement for non-profit organizations in many jurisdictions?
-
To implement appropriate cybersecurity measures to protect personal data
-
To notify individuals affected by a data breach
-
To maintain a comprehensive cybersecurity policy
-
All of the above
D
Correct answer
Explanation
In many jurisdictions, non-profit organizations are legally required to implement appropriate cybersecurity measures to protect personal data, notify individuals affected by a data breach, and maintain a comprehensive cybersecurity policy.
Which of the following is a best practice for non-profit organizations to protect against malware attacks?
-
Installing and updating antivirus software
-
Educating employees and volunteers about malware risks
-
Implementing email filtering and anti-malware software
-
All of the above
D
Correct answer
Explanation
Non-profit organizations should implement a combination of measures to protect against malware attacks, including installing and updating antivirus software, educating employees and volunteers about malware risks, and implementing email filtering and anti-malware software.
Which of the following is a best practice for non-profit organizations to protect against DDoS attacks?
-
Implementing DDoS mitigation strategies
-
Educating employees and volunteers about DDoS risks
-
Maintaining a comprehensive cybersecurity policy
-
All of the above
D
Correct answer
Explanation
Non-profit organizations should implement a combination of measures to protect against DDoS attacks, including implementing DDoS mitigation strategies, educating employees and volunteers about DDoS risks, and maintaining a comprehensive cybersecurity policy.
Which of the following is a potential privacy concern in context-aware computing?
-
Collection of sensitive personal data without consent.
-
Unauthorized access to context data.
-
Misuse of context data for targeted advertising.
-
All of the above
D
Correct answer
Explanation
Context-aware computing raises privacy concerns related to data collection, access, and misuse.
Which of the following is NOT a type of privacy breach?
-
Unauthorized access to personal data
-
Unauthorized disclosure of personal data
-
Unauthorized use of personal data
-
Unauthorized destruction of personal data
D
Correct answer
Explanation
Unauthorized destruction of personal data is not a type of privacy breach. Instead, it is a type of data breach.
Which of the following is NOT a type of data protection law?
-
The General Data Protection Regulation (GDPR)
-
The California Consumer Privacy Act (CCPA)
-
The Health Insurance Portability and Accountability Act (HIPAA)
-
The Children's Online Privacy Protection Act (COPPA)
C
Correct answer
Explanation
The Health Insurance Portability and Accountability Act (HIPAA) is not a type of data protection law. Instead, it is a type of healthcare law.
Which of the following is NOT a type of privacy technology?
-
Encryption
-
Tokenization
-
Anonymization
-
Pseudonymization
D
Correct answer
Explanation
Pseudonymization is not a type of privacy technology. Instead, it is a type of data protection technique.
Which of the following is NOT a type of privacy certification?
-
The Privacy Shield Framework
-
The EU-U.S. Privacy Shield Framework
-
The ISO 27001 certification
-
The SOC 2 certification
D
Correct answer
Explanation
The SOC 2 certification is not a type of privacy certification. Instead, it is a type of security certification.
Which of the following is NOT a type of privacy framework?
-
The Privacy Shield Framework
-
The EU-U.S. Privacy Shield Framework
-
The NIST Privacy Framework
-
The ISO 27001 framework
D
Correct answer
Explanation
The ISO 27001 framework is not a type of privacy framework. Instead, it is a type of security framework.