Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is NOT a recommended practice for securing mobile devices against malware and viruses?

  1. Installing a reputable antivirus software

  2. Keeping the device's operating system and apps up to date

  3. Downloading apps only from official app stores

  4. Clicking on suspicious links in emails or text messages

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Clicking on suspicious links is a common way for malware and viruses to infect devices.

Multiple choice

What is the purpose of two-factor authentication (2FA) on mobile devices?

  1. To add an extra layer of security to user accounts

  2. To improve the device's performance

  3. To allow users to access their accounts from multiple devices simultaneously

  4. To track the location of the device

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

2FA adds an extra layer of security by requiring users to provide two different forms of identification when logging in.

Multiple choice

Which of the following is NOT a recommended practice for securing mobile devices against theft or loss?

  1. Using a strong and unique passcode

  2. Enabling remote tracking and wiping capabilities

  3. Backing up important data regularly

  4. Leaving the device unattended in public places

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Leaving the device unattended in public places increases the risk of theft or loss.

Multiple choice

Which of the following is NOT a recommended practice for securing mobile devices when using Bluetooth?

  1. Only connecting to trusted Bluetooth devices

  2. Keeping Bluetooth turned off when not in use

  3. Accepting Bluetooth connection requests from unknown devices

  4. Using a strong passcode for Bluetooth pairing

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Accepting Bluetooth connection requests from unknown devices can compromise the security of the device.

Multiple choice

Which of the following is NOT a recommended practice for securing mobile devices against unauthorized access?

  1. Using a strong and unique passcode

  2. Enabling remote tracking and wiping capabilities

  3. Backing up important data regularly

  4. Jailbreaking or rooting devices

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Jailbreaking or rooting devices compromises the security of the device and makes it more vulnerable to attacks.

Multiple choice

Which of the following is NOT a recommended practice for securing mobile devices when using public charging stations?

  1. Using a reputable charging station

  2. Avoiding charging stations in high-traffic areas

  3. Using a personal charging cable

  4. Leaving the device unattended while charging

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Leaving the device unattended while charging increases the risk of theft or unauthorized access.

Multiple choice

What is the term used to describe the unauthorized access, use, disclosure, disruption, modification, or destruction of information in an IoT system?

  1. Data breach

  2. Cyberattack

  3. Malware infection

  4. Phishing scam

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

A cyberattack refers to any malicious attempt to compromise the security of an IoT system, potentially leading to unauthorized access, data theft, or disruption of services.

Multiple choice

Which of the following is NOT a common type of supply chain attack?

  1. Man-in-the-Middle (MitM) Attack

  2. Zero-Day Attack

  3. Phishing Attack

  4. Insider Attack

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Zero-Day Attacks are not specifically targeted at supply chains. They exploit vulnerabilities in software or systems that are not yet known to the vendor or the general public.

Multiple choice

Which of the following is a best practice for mitigating supply chain attacks?

  1. Conducting regular security audits of suppliers

  2. Implementing multi-factor authentication (MFA) for supplier access

  3. Educating employees about supply chain security risks

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

All of the mentioned practices contribute to reducing the risk of supply chain attacks.

Multiple choice

What is the term used to describe the unauthorized modification of a legitimate software package or component?

  1. Software Tampering

  2. Software Counterfeiting

  3. Software Piracy

  4. Software Hijacking

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Software Tampering refers to the unauthorized modification of a legitimate software package or component, often with malicious intent.

Multiple choice

Which of the following is an example of a supply chain attack that targeted a physical product?

  1. The SolarWinds Orion attack

  2. The Stuxnet attack

  3. The Mirai botnet attack

  4. The WannaCry ransomware attack

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

The Stuxnet attack is an example of a supply chain attack that targeted a physical product, specifically programmable logic controllers (PLCs) used in industrial control systems.

Multiple choice

What is the term used to describe the practice of introducing malicious code into a software product during the development or manufacturing process?

  1. Software Poisoning

  2. Software Sabotage

  3. Software Espionage

  4. Software Hijacking

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Software Poisoning refers to the practice of introducing malicious code into a software product during the development or manufacturing process, often with the intent to compromise the integrity or functionality of the product.

Multiple choice

What is the term used to describe the practice of using a legitimate software package or component as a conduit for malicious activity?

  1. Software Hijacking

  2. Software Tampering

  3. Software Counterfeiting

  4. Software Piracy

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Software Hijacking refers to the practice of using a legitimate software package or component as a conduit for malicious activity, such as delivering malware or launching attacks against other systems.

Multiple choice

Which of the following is an example of a supply chain attack that targeted a software product?

  1. The SolarWinds Orion attack

  2. The Stuxnet attack

  3. The Mirai botnet attack

  4. The WannaCry ransomware attack

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The SolarWinds Orion attack is an example of a supply chain attack that targeted a software product, specifically the SolarWinds Orion network management software.

Multiple choice

Which of the following is NOT a recommended practice for mitigating supply chain attacks?

  1. Implementing strong access controls and authentication mechanisms

  2. Conducting regular security audits and penetration testing

  3. Educating employees about supply chain security risks

  4. Relaxing security measures to reduce costs

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Relaxing security measures to reduce costs is not a recommended practice for mitigating supply chain attacks. It can increase the risk of successful attacks.