Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

What is the best way to protect yourself from social engineering attacks?

  1. Be aware of the different types of social engineering attacks

  2. Be suspicious of unsolicited requests for personal information

  3. Never give out personal information over the phone or email

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

All of the above are important steps to take to protect yourself from social engineering attacks.

Multiple choice

Which of the following is NOT a common social engineering technique used in phishing attacks?

  1. Pretexting

  2. Baiting

  3. Tailgating

  4. Shoulder surfing

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Shoulder surfing is a technique used to steal information by looking over someone's shoulder while they are using a computer or mobile device.

Multiple choice

Which of the following is NOT a common type of phishing attack that targets businesses?

  1. Spear phishing

  2. Whaling

  3. Business email compromise (BEC)

  4. Smishing

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Smishing is a type of phishing attack that uses SMS or text messages to trick people into giving up sensitive information. It is not as common as other types of phishing attacks that target businesses.

Multiple choice

What is the best way to protect your business from phishing attacks?

  1. Educate your employees about phishing attacks

  2. Implement a strong email security solution

  3. Use multi-factor authentication (MFA) for all accounts

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

All of the above are important steps to take to protect your business from phishing attacks.

Multiple choice

Which of the following is NOT a common social engineering technique used in whaling attacks?

  1. Pretexting

  2. Impersonation

  3. Baiting

  4. Tailgating

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Tailgating is a technique used to gain unauthorized access to a building or facility by following someone who has authorized access.

Multiple choice

Which of the following is NOT a common social engineering technique used in BEC attacks?

  1. Pretexting

  2. Impersonation

  3. Baiting

  4. Vishing

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Vishing is a type of phishing attack that uses voice calls to trick people into giving up sensitive information.

Multiple choice

Which of the following is NOT a common type of cybersecurity vulnerability?

  1. Buffer overflow

  2. Cross-site scripting

  3. Man-in-the-middle attack

  4. Social engineering

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Social engineering is a type of attack that targets human behavior rather than technical vulnerabilities.

Multiple choice

What is the most common type of man-in-the-middle (MitM) attack?

  1. ARP spoofing

  2. DNS spoofing

  3. SSL stripping

  4. IP spoofing

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

ARP spoofing is a type of MitM attack in which an attacker sends fake ARP (Address Resolution Protocol) messages to a victim's computer, causing the victim's traffic to be routed through the attacker's computer.

Multiple choice

Which of the following is NOT a common type of social engineering attack?

  1. Phishing

  2. Baiting

  3. Tailgating

  4. Vishing

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Tailgating is not a common type of social engineering attack. It occurs when an attacker follows a victim into a secure area without authorization.

Multiple choice

What is the most common type of phishing attack?

  1. Spear phishing

  2. Whaling

  3. Clone phishing

  4. CEO fraud

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Spear phishing is a type of phishing attack in which an attacker targets a specific individual or organization with a personalized email message.

Multiple choice

Which of the following is NOT a common type of baiting attack?

  1. USB drop

  2. Malicious website

  3. Fake software update

  4. Poisoned search results

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Poisoned search results are not a common type of baiting attack. They occur when an attacker manipulates search engine results to display malicious websites or links.

Multiple choice

What is the most common type of vishing attack?

  1. Automated calls

  2. Live calls

  3. Robocalls

  4. Smishing

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Automated calls are the most common type of vishing attack. They use pre-recorded messages to trick victims into giving up personal information or downloading malware.

Multiple choice

Which of the following is NOT a common type of smishing attack?

  1. Text message phishing

  2. SMS spoofing

  3. MMS phishing

  4. QR code phishing

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

QR code phishing is not a common type of smishing attack. It occurs when an attacker creates a malicious QR code that, when scanned, directs the victim to a malicious website or downloads malware.

Multiple choice

What is the most common type of zero-day vulnerability?

  1. Buffer overflow

  2. Cross-site scripting

  3. SQL injection

  4. Remote code execution

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Remote code execution is the most common type of zero-day vulnerability. It allows an attacker to execute arbitrary code on a victim's computer.

Multiple choice

Which of the following is NOT a common type of supply chain attack?

  1. Software tampering

  2. Dependency confusion

  3. Typosquatting

  4. Man-in-the-middle attack

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Man-in-the-middle attack is not a common type of supply chain attack. It occurs when an attacker intercepts communications between two parties and impersonates one of them.