Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
Which of the following is NOT a common type of supply chain attack?
-
Man-in-the-Middle (MitM) Attack
-
Zero-Day Attack
-
Phishing Attack
-
Insider Attack
B
Correct answer
Explanation
Zero-Day Attacks are not specifically targeted at supply chains. They exploit vulnerabilities in software or systems that are not yet known to the vendor or the general public.
Which of the following is NOT a common security measure implemented in geospatial technologies?
-
Access control
-
Data encryption
-
Data anonymization
-
Data backup
D
Correct answer
Explanation
Data backup is a process of creating copies of geographical data for recovery purposes in case of data loss or corruption. While it is an important practice for data management, it is not specifically related to enhancing geographical data privacy and security.
Which of the following is a widely recognized cybersecurity framework developed by the National Institute of Standards and Technology (NIST)?
-
ISO 27001
-
COBIT
-
NIST Cybersecurity Framework
-
PCI DSS
C
Correct answer
Explanation
The NIST Cybersecurity Framework is a voluntary framework that provides a set of guidelines and best practices for organizations to manage and reduce cybersecurity risks.
Which framework focuses on providing guidance for managing information security risks in an organization?
-
ISO 27001
-
NIST Cybersecurity Framework
-
COBIT
-
PCI DSS
A
Correct answer
Explanation
ISO 27001 is an international standard that provides a comprehensive set of requirements for an information security management system (ISMS).
Which framework is specifically designed to protect the privacy of personal data in the European Union?
-
ISO 27001
-
NIST Cybersecurity Framework
-
COBIT
-
GDPR
D
Correct answer
Explanation
The General Data Protection Regulation (GDPR) is a comprehensive framework that regulates the processing and protection of personal data in the European Union.
Which framework is designed to help organizations manage cybersecurity risks in the financial sector?
-
ISO 27001
-
NIST Cybersecurity Framework
-
COBIT
-
Financial Industry Regulatory Authority (FINRA) Cybersecurity Assessment Tool (CAT)
D
Correct answer
Explanation
The FINRA CAT is a framework that helps financial institutions assess and manage cybersecurity risks.
What is the purpose of the Center for Internet Security (CIS) Critical Security Controls (CSC)?
-
To protect sensitive data in cloud environments
-
To ensure compliance with government regulations
-
To secure mobile devices and applications
-
To provide a prioritized list of security controls for organizations to implement
D
Correct answer
Explanation
The CIS CSC is a prioritized list of security controls that organizations can implement to reduce cybersecurity risks.
Which framework provides guidance for securing mobile devices and applications?
-
ISO 27001
-
NIST Cybersecurity Framework
-
COBIT
-
Mobile Device Management (MDM) and Mobile Application Management (MAM) frameworks
D
Correct answer
Explanation
MDM and MAM frameworks provide guidance for securing mobile devices and applications.
What is the security protocol like at Inaugural Balls?
-
Tight security measures are in place
-
Security is relaxed to allow for a more festive atmosphere
-
There is no security protocol in place
-
None of the above
A
Correct answer
Explanation
Inaugural Balls have strict security protocols in place, including thorough screening of guests and heightened security presence to ensure the safety of attendees.
Which of the following is NOT a common data security threat in astroinformatics?
-
Malware attacks
-
Phishing scams
-
Insider threats
-
Natural disasters
D
Correct answer
Explanation
Natural disasters are not typically considered a data security threat in astroinformatics, as they are not caused by malicious intent.
Which of the following is NOT a best practice for data security in astroinformatics?
-
Implementing strong access controls
-
Regularly backing up data
-
Using outdated security software
-
Educating users about data security risks
C
Correct answer
Explanation
Using outdated security software is not a best practice for data security, as it can leave systems vulnerable to attacks.
In cryptography, what is the relationship between key length and security?
-
Longer keys provide weaker security
-
Key length is irrelevant to security
-
Longer keys provide stronger security
-
Key length is inversely proportional to security
C
Correct answer
Explanation
In cryptography, longer keys provide stronger security because they increase the number of possible combinations, making it more difficult for an attacker to break the encryption.
What is the purpose of the Cybersecurity Framework developed by the National Institute of Standards and Technology (NIST)?
-
To provide guidance to organizations on how to protect their systems from cyberattacks
-
To establish cybersecurity standards for government agencies
-
To create a centralized database of cybersecurity vulnerabilities
-
To develop new cybersecurity technologies
A
Correct answer
Explanation
The Cybersecurity Framework is a voluntary set of guidelines and best practices that organizations can use to improve their cybersecurity posture and reduce the risk of cyberattacks.
What is the purpose of the Cybersecurity and Infrastructure Security Agency's (CISA) National Vulnerability Database (NVD)?
-
To provide information about known cybersecurity vulnerabilities
-
To develop and maintain cybersecurity standards
-
To conduct cybersecurity research and develop new cybersecurity technologies
-
To investigate cyberattacks and prosecute cybercrimes
A
Correct answer
Explanation
CISA's NVD is a database of known cybersecurity vulnerabilities, including information about the vulnerability, its impact, and how to mitigate it.
-
A type of malware that encrypts files and demands a ransom payment to decrypt them.
-
A type of malware that steals personal information.
-
A type of malware that deletes files.
-
A type of malware that takes control of a computer.
A
Correct answer
Explanation
Ransomware is a type of malware that encrypts files on a computer and demands a ransom payment to decrypt them. The ransom is typically paid in cryptocurrency, such as Bitcoin.