Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
What is the best way to protect yourself from social engineering attacks?
-
Be aware of the different types of social engineering attacks
-
Be suspicious of unsolicited requests for personal information
-
Never give out personal information over the phone or email
-
All of the above
D
Correct answer
Explanation
All of the above are important steps to take to protect yourself from social engineering attacks.
Which of the following is NOT a common social engineering technique used in phishing attacks?
-
Pretexting
-
Baiting
-
Tailgating
-
Shoulder surfing
D
Correct answer
Explanation
Shoulder surfing is a technique used to steal information by looking over someone's shoulder while they are using a computer or mobile device.
Which of the following is NOT a common type of phishing attack that targets businesses?
-
Spear phishing
-
Whaling
-
Business email compromise (BEC)
-
Smishing
D
Correct answer
Explanation
Smishing is a type of phishing attack that uses SMS or text messages to trick people into giving up sensitive information. It is not as common as other types of phishing attacks that target businesses.
What is the best way to protect your business from phishing attacks?
-
Educate your employees about phishing attacks
-
Implement a strong email security solution
-
Use multi-factor authentication (MFA) for all accounts
-
All of the above
D
Correct answer
Explanation
All of the above are important steps to take to protect your business from phishing attacks.
Which of the following is NOT a common social engineering technique used in whaling attacks?
-
Pretexting
-
Impersonation
-
Baiting
-
Tailgating
D
Correct answer
Explanation
Tailgating is a technique used to gain unauthorized access to a building or facility by following someone who has authorized access.
Which of the following is NOT a common social engineering technique used in BEC attacks?
-
Pretexting
-
Impersonation
-
Baiting
-
Vishing
D
Correct answer
Explanation
Vishing is a type of phishing attack that uses voice calls to trick people into giving up sensitive information.
Which of the following is NOT a common type of cybersecurity vulnerability?
-
Buffer overflow
-
Cross-site scripting
-
Man-in-the-middle attack
-
Social engineering
D
Correct answer
Explanation
Social engineering is a type of attack that targets human behavior rather than technical vulnerabilities.
What is the most common type of man-in-the-middle (MitM) attack?
-
ARP spoofing
-
DNS spoofing
-
SSL stripping
-
IP spoofing
A
Correct answer
Explanation
ARP spoofing is a type of MitM attack in which an attacker sends fake ARP (Address Resolution Protocol) messages to a victim's computer, causing the victim's traffic to be routed through the attacker's computer.
Which of the following is NOT a common type of social engineering attack?
-
Phishing
-
Baiting
-
Tailgating
-
Vishing
C
Correct answer
Explanation
Tailgating is not a common type of social engineering attack. It occurs when an attacker follows a victim into a secure area without authorization.
What is the most common type of phishing attack?
-
Spear phishing
-
Whaling
-
Clone phishing
-
CEO fraud
A
Correct answer
Explanation
Spear phishing is a type of phishing attack in which an attacker targets a specific individual or organization with a personalized email message.
Which of the following is NOT a common type of baiting attack?
-
USB drop
-
Malicious website
-
Fake software update
-
Poisoned search results
D
Correct answer
Explanation
Poisoned search results are not a common type of baiting attack. They occur when an attacker manipulates search engine results to display malicious websites or links.
What is the most common type of vishing attack?
-
Automated calls
-
Live calls
-
Robocalls
-
Smishing
A
Correct answer
Explanation
Automated calls are the most common type of vishing attack. They use pre-recorded messages to trick victims into giving up personal information or downloading malware.
Which of the following is NOT a common type of smishing attack?
-
Text message phishing
-
SMS spoofing
-
MMS phishing
-
QR code phishing
D
Correct answer
Explanation
QR code phishing is not a common type of smishing attack. It occurs when an attacker creates a malicious QR code that, when scanned, directs the victim to a malicious website or downloads malware.
What is the most common type of zero-day vulnerability?
-
Buffer overflow
-
Cross-site scripting
-
SQL injection
-
Remote code execution
D
Correct answer
Explanation
Remote code execution is the most common type of zero-day vulnerability. It allows an attacker to execute arbitrary code on a victim's computer.
Which of the following is NOT a common type of supply chain attack?
-
Software tampering
-
Dependency confusion
-
Typosquatting
-
Man-in-the-middle attack
D
Correct answer
Explanation
Man-in-the-middle attack is not a common type of supply chain attack. It occurs when an attacker intercepts communications between two parties and impersonates one of them.