Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

What is the primary goal of a social engineering attack on critical infrastructure?

  1. To steal sensitive data

  2. To disrupt operations

  3. To hold data for ransom

  4. To gain unauthorized access to systems

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Social engineering attacks on critical infrastructure are often designed to gain unauthorized access to systems, such as by tricking employees into giving up their passwords.

Multiple choice

Which of the following is a common type of cybersecurity threat to critical infrastructure that involves supply chain attacks?

  1. Supply chain attacks

  2. Third-party attacks

  3. Vendor attacks

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Supply chain attacks, third-party attacks, and vendor attacks are all common types of cybersecurity threats to critical infrastructure that involve supply chain attacks.

Multiple choice

Which data privacy principle allows individuals to request access to their personal data held by an organization?

  1. Data minimization

  2. Data retention

  3. Data subject access rights

  4. Data security

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Data subject access rights are a fundamental data privacy principle that allows individuals to request access to their personal data held by an organization. This includes the right to obtain a copy of their data, as well as information about how it is being processed.

Multiple choice

Which data privacy regulation grants individuals the 'right to be forgotten'?

  1. General Data Protection Regulation (GDPR)

  2. California Consumer Privacy Act (CCPA)

  3. Health Insurance Portability and Accountability Act (HIPAA)

  4. Payment Card Industry Data Security Standard (PCI DSS)

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The General Data Protection Regulation (GDPR) grants individuals the 'right to be forgotten', which allows them to request that their personal data be erased from an organization's records under certain circumstances.

Multiple choice

Which data privacy principle requires organizations to take appropriate security measures to protect personal data from unauthorized access, use, or disclosure?

  1. Data security

  2. Data integrity

  3. Data availability

  4. Data confidentiality

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The data security principle in data privacy requires organizations to implement appropriate security measures to protect personal data from unauthorized access, use, or disclosure.

Multiple choice

Which data privacy regulation requires organizations to notify individuals of data breaches within a specific timeframe?

  1. General Data Protection Regulation (GDPR)

  2. California Consumer Privacy Act (CCPA)

  3. Health Insurance Portability and Accountability Act (HIPAA)

  4. Payment Card Industry Data Security Standard (PCI DSS)

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The General Data Protection Regulation (GDPR) requires organizations to notify individuals of data breaches within a specific timeframe, typically 72 hours after becoming aware of the breach.

Multiple choice

Which data privacy regulation requires organizations to implement appropriate technical and organizational measures to protect personal data?

  1. General Data Protection Regulation (GDPR)

  2. California Consumer Privacy Act (CCPA)

  3. Health Insurance Portability and Accountability Act (HIPAA)

  4. Payment Card Industry Data Security Standard (PCI DSS)

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The General Data Protection Regulation (GDPR) requires organizations to implement appropriate technical and organizational measures to protect personal data from unauthorized access, use, or disclosure.

Multiple choice

Which of the following is a common IT security standard?

  1. ISO/IEC 27001

  2. NIST SP 800-53

  3. PCI DSS

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

ISO/IEC 27001, NIST SP 800-53, and PCI DSS are common IT security standards that provide guidance on how to protect IT systems and data from unauthorized access, use, disclosure, disruption, modification, or destruction.

Multiple choice

What is the best way to protect your personal information when using public Wi-Fi?

  1. Use a virtual private network (VPN)

  2. Only access websites that use HTTPS

  3. Avoid using public Wi-Fi altogether

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

All of the above options are important for protecting your personal information when using public Wi-Fi.

Multiple choice

Which of the following is not a common type of mobile application security threat?

  1. Malware

  2. Phishing

  3. Man-in-the-middle attacks

  4. Denial-of-service attacks

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Denial-of-service attacks are not a common type of mobile application security threat, as they are typically targeted at servers or networks rather than mobile devices.

Multiple choice

Which of the following is NOT a common source of cybersecurity threat intelligence?

  1. Open-source intelligence (OSINT)

  2. Social media monitoring

  3. Vulnerability databases

  4. Internal security logs

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

While social media monitoring can be used for other purposes, it is not typically considered a primary source of cybersecurity threat intelligence.

Multiple choice

Which of the following is NOT a common type of cybersecurity threat intelligence report?

  1. Strategic reports

  2. Tactical reports

  3. Operational reports

  4. Technical reports

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Strategic reports are typically not specific to cybersecurity threat intelligence.

Multiple choice

Which of the following is NOT a common type of cybersecurity threat actor?

  1. Nation-state actors

  2. Cybercriminals

  3. Hacktivists

  4. Insiders

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Insiders are typically not considered a type of cybersecurity threat actor in the context of threat intelligence.

Multiple choice

Which of the following is NOT a common type of cybersecurity threat?

  1. Malware

  2. Phishing

  3. DDoS attacks

  4. Insider threats

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Insider threats are typically not considered a type of cybersecurity threat in the context of threat intelligence.

Multiple choice

What is the process of responding to and mitigating cybersecurity threats known as?

  1. Incident response

  2. Threat hunting

  3. Vulnerability management

  4. Risk assessment

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Incident response involves the actions taken to contain, eradicate, and recover from a cybersecurity incident.