Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
What is the purpose of a content delivery network (CDN) in e-commerce security?
-
To improve website speed and performance
-
To detect and prevent unauthorized access to a website or web application
-
To encrypt data transmitted between a website and a user's browser
-
To scan websites and web applications for vulnerabilities
A
Correct answer
Explanation
A content delivery network (CDN) is a system of distributed servers that deliver content to users based on their geographic location. This can help to improve website speed and performance, especially for users who are located far from the origin server. CDNs can also help to mitigate the impact of DDoS attacks by distributing traffic across multiple servers.
What is the role of regular software updates in e-commerce security?
-
To fix security vulnerabilities and improve software performance
-
To improve website speed and performance
-
To increase website traffic and sales
-
To prevent unauthorized access to a website's content
A
Correct answer
Explanation
Regular software updates are essential for fixing security vulnerabilities and improving software performance. E-commerce businesses should ensure that they are running the latest versions of all software, including operating systems, web servers, and e-commerce platforms. This can help to reduce the risk of cyberattacks and improve the overall security of the e-commerce website.
Which of the following is NOT a common data warehousing security measure?
-
Access control
-
Encryption
-
Data masking
-
Data profiling
D
Correct answer
Explanation
Data profiling is not a common data warehousing security measure. Data profiling is the process of analyzing data to understand its structure, content, and quality. Access control, encryption, and data masking are all common data warehousing security measures.
Which of the following is a key security concern in IaaS?
-
Data Leakage
-
Network Infiltration
-
DDoS Attacks
-
All of the above
D
Correct answer
Explanation
In IaaS, data leakage, network infiltration, and DDoS attacks are all key security concerns.
Which of the following is a common attack vector in IaaS environments?
-
Cross-site scripting (XSS)
-
SQL injection
-
Phishing
-
Man-in-the-middle (MitM) attacks
D
Correct answer
Explanation
Man-in-the-middle (MitM) attacks are a common attack vector in IaaS environments, where an attacker intercepts communication between two parties and impersonates one of them.
Which of the following is a type of security control that can be used to protect IaaS resources from unauthorized access?
-
Firewall
-
Intrusion detection system (IDS)
-
Virtual private network (VPN)
-
All of the above
D
Correct answer
Explanation
Firewalls, intrusion detection systems (IDSs), and virtual private networks (VPNs) are all types of security controls that can be used to protect IaaS resources from unauthorized access.
Which of the following is a type of security assessment that can be used to identify vulnerabilities in an IaaS environment?
-
Penetration testing
-
Vulnerability scanning
-
Risk assessment
-
All of the above
D
Correct answer
Explanation
Penetration testing, vulnerability scanning, and risk assessment are all types of security assessments that can be used to identify vulnerabilities in an IaaS environment.
Which of the following is a type of security control that can be used to protect IaaS resources from data leakage?
-
Data loss prevention (DLP)
-
Encryption
-
Tokenization
-
All of the above
D
Correct answer
Explanation
Data loss prevention (DLP), encryption, and tokenization are all types of security controls that can be used to protect IaaS resources from data leakage.
Which of the following is a type of security assessment that can be used to evaluate the overall security posture of an IaaS environment?
-
Security audit
-
Risk assessment
-
Compliance assessment
-
All of the above
D
Correct answer
Explanation
Security audits, risk assessments, and compliance assessments are all types of security assessments that can be used to evaluate the overall security posture of an IaaS environment.
Which of the following is a type of security control that can be used to protect IaaS resources from phishing attacks?
-
User awareness training
-
Email filtering
-
Multi-factor authentication (MFA)
-
All of the above
D
Correct answer
Explanation
User awareness training, email filtering, and multi-factor authentication (MFA) are all types of security controls that can be used to protect IaaS resources from phishing attacks.
Which of the following is a type of security assessment that can be used to identify misconfigurations in an IaaS environment?
-
Configuration audit
-
Vulnerability scanning
-
Penetration testing
-
All of the above
A
Correct answer
Explanation
A configuration audit is a type of security assessment that can be used to identify misconfigurations in an IaaS environment.
Which of the following is NOT a common mobile device security risk?
-
Malware and viruses
-
Phishing attacks
-
Strong passwords
-
Unsecured Wi-Fi networks
C
Correct answer
Explanation
Strong passwords are a security measure, not a risk.
Which of the following is NOT a recommended best practice for securing mobile devices?
-
Using strong and unique passwords or passcodes
-
Enabling two-factor authentication
-
Jailbreaking or rooting devices
-
Installing security updates and patches regularly
C
Correct answer
Explanation
Jailbreaking or rooting devices compromises the security of the device and makes it more vulnerable to attacks.
What is the most effective way to protect against phishing attacks on mobile devices?
-
Using a strong antivirus software
-
Being cautious when clicking on links in emails or text messages
-
Enabling pop-up blockers
-
Using a VPN
B
Correct answer
Explanation
Being cautious and verifying the authenticity of links before clicking is the most effective way to prevent phishing attacks.
Which of the following is NOT a recommended practice for securing mobile devices when using public Wi-Fi networks?
-
Using a VPN
-
Disabling automatic Wi-Fi connections
-
Using strong passwords for Wi-Fi networks
-
Accessing sensitive information over public Wi-Fi
D
Correct answer
Explanation
Accessing sensitive information over public Wi-Fi is not recommended due to the risk of eavesdropping and interception.