Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
What is the primary goal of a social engineering attack on critical infrastructure?
-
To steal sensitive data
-
To disrupt operations
-
To hold data for ransom
-
To gain unauthorized access to systems
D
Correct answer
Explanation
Social engineering attacks on critical infrastructure are often designed to gain unauthorized access to systems, such as by tricking employees into giving up their passwords.
Which of the following is a common type of cybersecurity threat to critical infrastructure that involves supply chain attacks?
-
Supply chain attacks
-
Third-party attacks
-
Vendor attacks
-
All of the above
D
Correct answer
Explanation
Supply chain attacks, third-party attacks, and vendor attacks are all common types of cybersecurity threats to critical infrastructure that involve supply chain attacks.
Which data privacy principle allows individuals to request access to their personal data held by an organization?
-
Data minimization
-
Data retention
-
Data subject access rights
-
Data security
C
Correct answer
Explanation
Data subject access rights are a fundamental data privacy principle that allows individuals to request access to their personal data held by an organization. This includes the right to obtain a copy of their data, as well as information about how it is being processed.
Which data privacy regulation grants individuals the 'right to be forgotten'?
-
General Data Protection Regulation (GDPR)
-
California Consumer Privacy Act (CCPA)
-
Health Insurance Portability and Accountability Act (HIPAA)
-
Payment Card Industry Data Security Standard (PCI DSS)
A
Correct answer
Explanation
The General Data Protection Regulation (GDPR) grants individuals the 'right to be forgotten', which allows them to request that their personal data be erased from an organization's records under certain circumstances.
Which data privacy principle requires organizations to take appropriate security measures to protect personal data from unauthorized access, use, or disclosure?
-
Data security
-
Data integrity
-
Data availability
-
Data confidentiality
A
Correct answer
Explanation
The data security principle in data privacy requires organizations to implement appropriate security measures to protect personal data from unauthorized access, use, or disclosure.
Which data privacy regulation requires organizations to notify individuals of data breaches within a specific timeframe?
-
General Data Protection Regulation (GDPR)
-
California Consumer Privacy Act (CCPA)
-
Health Insurance Portability and Accountability Act (HIPAA)
-
Payment Card Industry Data Security Standard (PCI DSS)
A
Correct answer
Explanation
The General Data Protection Regulation (GDPR) requires organizations to notify individuals of data breaches within a specific timeframe, typically 72 hours after becoming aware of the breach.
Which data privacy regulation requires organizations to implement appropriate technical and organizational measures to protect personal data?
-
General Data Protection Regulation (GDPR)
-
California Consumer Privacy Act (CCPA)
-
Health Insurance Portability and Accountability Act (HIPAA)
-
Payment Card Industry Data Security Standard (PCI DSS)
A
Correct answer
Explanation
The General Data Protection Regulation (GDPR) requires organizations to implement appropriate technical and organizational measures to protect personal data from unauthorized access, use, or disclosure.
Which of the following is a common IT security standard?
-
ISO/IEC 27001
-
NIST SP 800-53
-
PCI DSS
-
All of the above
D
Correct answer
Explanation
ISO/IEC 27001, NIST SP 800-53, and PCI DSS are common IT security standards that provide guidance on how to protect IT systems and data from unauthorized access, use, disclosure, disruption, modification, or destruction.
What is the best way to protect your personal information when using public Wi-Fi?
-
Use a virtual private network (VPN)
-
Only access websites that use HTTPS
-
Avoid using public Wi-Fi altogether
-
All of the above
D
Correct answer
Explanation
All of the above options are important for protecting your personal information when using public Wi-Fi.
Which of the following is not a common type of mobile application security threat?
-
Malware
-
Phishing
-
Man-in-the-middle attacks
-
Denial-of-service attacks
D
Correct answer
Explanation
Denial-of-service attacks are not a common type of mobile application security threat, as they are typically targeted at servers or networks rather than mobile devices.
Which of the following is NOT a common source of cybersecurity threat intelligence?
-
Open-source intelligence (OSINT)
-
Social media monitoring
-
Vulnerability databases
-
Internal security logs
B
Correct answer
Explanation
While social media monitoring can be used for other purposes, it is not typically considered a primary source of cybersecurity threat intelligence.
Which of the following is NOT a common type of cybersecurity threat intelligence report?
-
Strategic reports
-
Tactical reports
-
Operational reports
-
Technical reports
A
Correct answer
Explanation
Strategic reports are typically not specific to cybersecurity threat intelligence.
Which of the following is NOT a common type of cybersecurity threat actor?
-
Nation-state actors
-
Cybercriminals
-
Hacktivists
-
Insiders
D
Correct answer
Explanation
Insiders are typically not considered a type of cybersecurity threat actor in the context of threat intelligence.
Which of the following is NOT a common type of cybersecurity threat?
-
Malware
-
Phishing
-
DDoS attacks
-
Insider threats
D
Correct answer
Explanation
Insider threats are typically not considered a type of cybersecurity threat in the context of threat intelligence.
What is the process of responding to and mitigating cybersecurity threats known as?
-
Incident response
-
Threat hunting
-
Vulnerability management
-
Risk assessment
A
Correct answer
Explanation
Incident response involves the actions taken to contain, eradicate, and recover from a cybersecurity incident.