Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is NOT a common type of supply chain attack?

  1. Man-in-the-Middle (MitM) Attack

  2. Zero-Day Attack

  3. Phishing Attack

  4. Insider Attack

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Zero-Day Attacks are not specifically targeted at supply chains. They exploit vulnerabilities in software or systems that are not yet known to the vendor or the general public.

Multiple choice

Which of the following is NOT a common security measure implemented in geospatial technologies?

  1. Access control

  2. Data encryption

  3. Data anonymization

  4. Data backup

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Data backup is a process of creating copies of geographical data for recovery purposes in case of data loss or corruption. While it is an important practice for data management, it is not specifically related to enhancing geographical data privacy and security.

Multiple choice

Which of the following is a widely recognized cybersecurity framework developed by the National Institute of Standards and Technology (NIST)?

  1. ISO 27001

  2. COBIT

  3. NIST Cybersecurity Framework

  4. PCI DSS

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

The NIST Cybersecurity Framework is a voluntary framework that provides a set of guidelines and best practices for organizations to manage and reduce cybersecurity risks.

Multiple choice

Which framework focuses on providing guidance for managing information security risks in an organization?

  1. ISO 27001

  2. NIST Cybersecurity Framework

  3. COBIT

  4. PCI DSS

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

ISO 27001 is an international standard that provides a comprehensive set of requirements for an information security management system (ISMS).

Multiple choice

Which framework is specifically designed to protect the privacy of personal data in the European Union?

  1. ISO 27001

  2. NIST Cybersecurity Framework

  3. COBIT

  4. GDPR

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

The General Data Protection Regulation (GDPR) is a comprehensive framework that regulates the processing and protection of personal data in the European Union.

Multiple choice

Which framework is designed to help organizations manage cybersecurity risks in the financial sector?

  1. ISO 27001

  2. NIST Cybersecurity Framework

  3. COBIT

  4. Financial Industry Regulatory Authority (FINRA) Cybersecurity Assessment Tool (CAT)

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

The FINRA CAT is a framework that helps financial institutions assess and manage cybersecurity risks.

Multiple choice

What is the purpose of the Center for Internet Security (CIS) Critical Security Controls (CSC)?

  1. To protect sensitive data in cloud environments

  2. To ensure compliance with government regulations

  3. To secure mobile devices and applications

  4. To provide a prioritized list of security controls for organizations to implement

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

The CIS CSC is a prioritized list of security controls that organizations can implement to reduce cybersecurity risks.

Multiple choice

Which framework provides guidance for securing mobile devices and applications?

  1. ISO 27001

  2. NIST Cybersecurity Framework

  3. COBIT

  4. Mobile Device Management (MDM) and Mobile Application Management (MAM) frameworks

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

MDM and MAM frameworks provide guidance for securing mobile devices and applications.

Multiple choice

What is the security protocol like at Inaugural Balls?

  1. Tight security measures are in place

  2. Security is relaxed to allow for a more festive atmosphere

  3. There is no security protocol in place

  4. None of the above

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Inaugural Balls have strict security protocols in place, including thorough screening of guests and heightened security presence to ensure the safety of attendees.

Multiple choice

Which of the following is NOT a common data security threat in astroinformatics?

  1. Malware attacks

  2. Phishing scams

  3. Insider threats

  4. Natural disasters

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Natural disasters are not typically considered a data security threat in astroinformatics, as they are not caused by malicious intent.

Multiple choice

Which of the following is NOT a best practice for data security in astroinformatics?

  1. Implementing strong access controls

  2. Regularly backing up data

  3. Using outdated security software

  4. Educating users about data security risks

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Using outdated security software is not a best practice for data security, as it can leave systems vulnerable to attacks.

Multiple choice

In cryptography, what is the relationship between key length and security?

  1. Longer keys provide weaker security

  2. Key length is irrelevant to security

  3. Longer keys provide stronger security

  4. Key length is inversely proportional to security

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

In cryptography, longer keys provide stronger security because they increase the number of possible combinations, making it more difficult for an attacker to break the encryption.

Multiple choice

What is the purpose of the Cybersecurity Framework developed by the National Institute of Standards and Technology (NIST)?

  1. To provide guidance to organizations on how to protect their systems from cyberattacks

  2. To establish cybersecurity standards for government agencies

  3. To create a centralized database of cybersecurity vulnerabilities

  4. To develop new cybersecurity technologies

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The Cybersecurity Framework is a voluntary set of guidelines and best practices that organizations can use to improve their cybersecurity posture and reduce the risk of cyberattacks.

Multiple choice

What is the purpose of the Cybersecurity and Infrastructure Security Agency's (CISA) National Vulnerability Database (NVD)?

  1. To provide information about known cybersecurity vulnerabilities

  2. To develop and maintain cybersecurity standards

  3. To conduct cybersecurity research and develop new cybersecurity technologies

  4. To investigate cyberattacks and prosecute cybercrimes

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

CISA's NVD is a database of known cybersecurity vulnerabilities, including information about the vulnerability, its impact, and how to mitigate it.

Multiple choice

What is ransomware?

  1. A type of malware that encrypts files and demands a ransom payment to decrypt them.

  2. A type of malware that steals personal information.

  3. A type of malware that deletes files.

  4. A type of malware that takes control of a computer.

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Ransomware is a type of malware that encrypts files on a computer and demands a ransom payment to decrypt them. The ransom is typically paid in cryptocurrency, such as Bitcoin.