Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is a common type of security threat?

  1. Phishing

  2. Malware

  3. DDoS attack

  4. SQL injection

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Phishing is a type of security threat in which attackers attempt to trick users into revealing sensitive information, such as passwords or credit card numbers, by disguising themselves as legitimate organizations.

Multiple choice

What is the purpose of a firewall?

  1. To block unauthorized access to a network

  2. To encrypt data

  3. To detect and respond to security threats

  4. To backup data

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A firewall is a network security device that monitors and controls incoming and outgoing network traffic based on predetermined security rules.

Multiple choice

Which of the following is a best practice for creating strong passwords?

  1. Use common words or phrases

  2. Include personal information

  3. Use the same password for multiple accounts

  4. Make passwords at least 12 characters long and include a mix of upper and lower case letters, numbers, and symbols

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Strong passwords should be at least 12 characters long and include a mix of upper and lower case letters, numbers, and symbols. Avoid using common words or phrases, personal information, or the same password for multiple accounts.

Multiple choice

Which of the following is a type of cryptographic attack?

  1. Brute-force attack

  2. Man-in-the-middle attack

  3. Phishing attack

  4. DDoS attack

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A brute-force attack is a type of cryptographic attack in which an attacker tries all possible combinations of keys until they find the correct one.

Multiple choice

What is the term used to describe the process of verifying the identity of a mobile device on a cellular network?

  1. Roaming

  2. Handoff

  3. Registration

  4. Authentication

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Authentication is the process of verifying the identity of a mobile device on a cellular network. This is done to ensure that only authorized devices can access the network.

Multiple choice

What is the term "Phishing" used to describe?

  1. Online Scams

  2. Identity Theft

  3. Malware Attacks

  4. Spam Emails

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Phishing involves sending fraudulent emails or messages to trick people into revealing personal information or financial details.

Multiple choice

What is the term "Cybersecurity" used to describe?

  1. Online Safety

  2. Data Protection

  3. Network Security

  4. Information Security

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Cybersecurity involves protecting information and systems from unauthorized access, use, disclosure, disruption, modification, or destruction.

Multiple choice

Which of the following is NOT a common type of cyberattack in e-commerce?

  1. Phishing

  2. Malware

  3. SQL injection

  4. Denial-of-service (DoS) attack

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

SQL injection is a type of cyberattack that targets websites and web applications that use SQL databases. It involves injecting malicious SQL code into a website or web application to gain unauthorized access to sensitive data or to manipulate the data in the database.

Multiple choice

What is the purpose of a secure socket layer (SSL) certificate in e-commerce?

  1. To encrypt data transmitted between a website and a user's browser

  2. To increase website speed and performance

  3. To improve website ranking in search engine results pages (SERPs)

  4. To prevent unauthorized access to a website's content

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

An SSL certificate is used to establish a secure connection between a website and a user's browser. It encrypts data transmitted between the two parties, such as personal information, credit card numbers, and transaction details, to protect it from eavesdropping and interception.

Multiple choice

What is the role of multi-factor authentication (MFA) in e-commerce security?

  1. To require users to provide multiple forms of identification when logging in

  2. To block unauthorized access to a website or web application

  3. To detect and prevent malicious activity on a website

  4. To encrypt data transmitted between a website and a user's browser

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Multi-factor authentication (MFA) is a security measure that requires users to provide multiple forms of identification when logging in to an account. This makes it more difficult for unauthorized individuals to gain access to a user's account, even if they have obtained the user's password.

Multiple choice

What is the best practice for creating strong passwords in e-commerce?

  1. Use a combination of upper and lowercase letters, numbers, and symbols

  2. Use the same password for all online accounts

  3. Keep passwords simple and easy to remember

  4. Share passwords with friends and family

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Strong passwords should be at least 12 characters long and should include a combination of upper and lowercase letters, numbers, and symbols. Avoid using common words or phrases, and do not reuse passwords across multiple accounts.

Multiple choice

What is the purpose of a web application firewall (WAF) in e-commerce security?

  1. To filter and block malicious traffic at the network level

  2. To detect and prevent unauthorized access to a website or web application

  3. To encrypt data transmitted between a website and a user's browser

  4. To scan websites and web applications for vulnerabilities

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A web application firewall (WAF) is a security device that is placed in front of a website or web application to filter and block malicious traffic at the network level. It can help to protect against a variety of cyberattacks, including SQL injection, cross-site scripting (XSS), and distributed denial-of-service (DDoS) attacks.

Multiple choice

What is the role of regular security audits in e-commerce security?

  1. To identify and fix vulnerabilities in a website or web application

  2. To improve website speed and performance

  3. To increase website traffic and sales

  4. To prevent unauthorized access to a website's content

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Regular security audits are essential for identifying and fixing vulnerabilities in a website or web application. These audits should be conducted by qualified security professionals who can assess the website or web application for potential security risks and recommend appropriate remediation measures.

Multiple choice

What is the best practice for handling customer data in e-commerce?

  1. Store customer data in plain text format

  2. Encrypt customer data before storing it

  3. Share customer data with third parties without their consent

  4. Keep customer data indefinitely

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Customer data should be encrypted before storing it to protect it from unauthorized access and theft. Encryption involves converting data into a format that is difficult to read or understand without the appropriate key.

Multiple choice

What is the purpose of a security incident response plan (IRP) in e-commerce?

  1. To outline the steps to be taken in the event of a security incident

  2. To improve website speed and performance

  3. To increase website traffic and sales

  4. To prevent unauthorized access to a website's content

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A security incident response plan (IRP) is a document that outlines the steps to be taken in the event of a security incident, such as a data breach or cyberattack. The IRP should include procedures for detecting, responding to, and recovering from security incidents.