Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
What is the term for a DDoS attack that uses multiple compromised devices to launch the attack?
-
Botnet DDoS attack
-
SYN flood attack
-
UDP flood attack
-
HTTP flood attack
A
Correct answer
Explanation
A botnet DDoS attack uses multiple compromised devices, known as bots, to launch a DDoS attack. These bots are controlled by a central command and control server and can be used to generate a large amount of traffic to overwhelm the target.
Which of the following is NOT a common impact of a DDoS attack?
-
Loss of revenue
-
Damage to reputation
-
Increased bandwidth costs
-
Improved website performance
D
Correct answer
Explanation
Improved website performance is not a common impact of a DDoS attack. DDoS attacks typically result in decreased website performance or even complete unavailability.
Which of the following is NOT a common defense mechanism against DDoS attacks at the network layer?
-
Rate limiting
-
Blacklisting malicious IP addresses
-
Using a firewall
-
Implementing access control lists (ACLs)
Correct answer
Explanation
Implementing ACLs is not a common defense mechanism against DDoS attacks at the network layer. ACLs are used to control access to network resources, but they do not provide protection against DDoS attacks.
What is the term for a DDoS attack that targets a specific application or service by exploiting vulnerabilities in the application code?
-
Application-layer DDoS attack
-
Protocol-layer DDoS attack
-
Network-layer DDoS attack
-
Transport-layer DDoS attack
A
Correct answer
Explanation
An application-layer DDoS attack targets a specific application or service by exploiting vulnerabilities in the application code. This type of attack can cause the application to crash or become unavailable.
Which of the following is NOT a common defense mechanism against DDoS attacks at the application layer?
-
Using a web application firewall (WAF)
-
Implementing input validation
-
Using a content delivery network (CDN)
-
Blacklisting malicious IP addresses
D
Correct answer
Explanation
Blacklisting malicious IP addresses is not a common defense mechanism against DDoS attacks at the application layer. Blacklisting is typically used to prevent access to specific IP addresses at the network layer.
What is the term for a DDoS attack that uses a large number of compromised devices to launch the attack?
-
Botnet DDoS attack
-
SYN flood attack
-
UDP flood attack
-
HTTP flood attack
A
Correct answer
Explanation
A botnet DDoS attack uses a large number of compromised devices, known as bots, to launch a DDoS attack. These bots are controlled by a central command and control server and can be used to generate a large amount of traffic to overwhelm the target.
Which of the following is NOT a common target of cyberterrorism?
-
Government agencies
-
Financial institutions
-
Critical infrastructure
-
Private individuals
D
Correct answer
Explanation
While private individuals can be victims of cybercrime, they are not typically the target of cyberterrorism, which is focused on causing harm or disruption to governments, businesses, and other organizations.
What is the term used to describe a type of cyberattack that involves taking control of a computer system and holding it for ransom?
-
Phishing
-
Malware
-
Ransomware
-
DDoS attack
C
Correct answer
Explanation
Ransomware is a type of cyberattack that involves taking control of a computer system and holding it for ransom, typically demanding payment in the form of cryptocurrency.
Which of the following is NOT a common method used by cyberterrorists to carry out attacks?
-
Hacking
-
Phishing
-
Social engineering
-
Physical attacks
D
Correct answer
Explanation
While cyberterrorists may use physical attacks as part of their operations, such as planting explosives or carrying out assassinations, these are not typically considered to be common methods of cyberterrorism.
What is the term used to describe a type of cyberattack that involves flooding a website or server with traffic in order to make it inaccessible?
-
Phishing
-
Malware
-
DDoS attack
-
Ransomware
C
Correct answer
Explanation
A DDoS attack (Distributed Denial of Service attack) involves flooding a website or server with traffic from multiple sources in order to make it inaccessible to legitimate users.
Which of the following is NOT a potential consequence of cyberterrorism?
-
Economic losses
-
Loss of life
-
Disruption of critical infrastructure
-
Increased public awareness of cybersecurity risks
D
Correct answer
Explanation
While cyberterrorism can lead to increased public awareness of cybersecurity risks, this is not typically considered to be a negative consequence.
What is the term used to describe the use of cyberattacks to target and disrupt critical infrastructure, such as power grids, water systems, and transportation networks?
-
Cyberwarfare
-
Cyberterrorism
-
Cybercrime
-
Cyberespionage
A
Correct answer
Explanation
Cyberwarfare involves the use of cyberattacks to target and disrupt critical infrastructure, with the intent of causing widespread harm and disruption.
Which of the following is NOT a common motivation for cyberterrorism?
-
Political extremism
-
Financial gain
-
Personal revenge
-
National security
D
Correct answer
Explanation
National security is not typically a motivation for cyberterrorism, as cyberattacks are more commonly carried out by non-state actors with political or financial motivations.
What is the term used to describe the use of cyberattacks to steal sensitive information, such as trade secrets, financial data, or personal information?
-
Cyberwarfare
-
Cyberterrorism
-
Cybercrime
-
Cyberespionage
D
Correct answer
Explanation
Cyberespionage involves the use of cyberattacks to steal sensitive information, such as trade secrets, financial data, or personal information, for economic or political advantage.
Which of the following is NOT a common target of cyberterrorism?
-
Government agencies
-
Financial institutions
-
Critical infrastructure
-
Small businesses
D
Correct answer
Explanation
Small businesses are not typically a common target of cyberterrorism, as they are less likely to have the resources and expertise to defend against sophisticated cyberattacks.