Computer Knowledge ยท General Awareness
Information Security
4,634 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
What is the term used to describe the unauthorized modification of a legitimate software package or component?
-
Software Tampering
-
Software Counterfeiting
-
Software Piracy
-
Software Hijacking
A
Correct answer
Explanation
Software Tampering refers to the unauthorized modification of a legitimate software package or component, often with malicious intent.
Which of the following is an example of a supply chain attack that targeted a physical product?
-
The SolarWinds Orion attack
-
The Stuxnet attack
-
The Mirai botnet attack
-
The WannaCry ransomware attack
B
Correct answer
Explanation
The Stuxnet attack is an example of a supply chain attack that targeted a physical product, specifically programmable logic controllers (PLCs) used in industrial control systems.
What is the term used to describe the practice of introducing malicious code into a software product during the development or manufacturing process?
-
Software Poisoning
-
Software Sabotage
-
Software Espionage
-
Software Hijacking
A
Correct answer
Explanation
Software Poisoning refers to the practice of introducing malicious code into a software product during the development or manufacturing process, often with the intent to compromise the integrity or functionality of the product.
Which of the following is NOT a common consequence of a supply chain attack?
-
Financial loss
-
Reputational damage
-
Operational disruption
-
Increased customer satisfaction
D
Correct answer
Explanation
Supply chain attacks typically result in negative consequences such as financial loss, reputational damage, and operational disruption. Increased customer satisfaction is not a common outcome of a supply chain attack.
What is the term used to describe the practice of using a legitimate software package or component as a conduit for malicious activity?
-
Software Hijacking
-
Software Tampering
-
Software Counterfeiting
-
Software Piracy
A
Correct answer
Explanation
Software Hijacking refers to the practice of using a legitimate software package or component as a conduit for malicious activity, such as delivering malware or launching attacks against other systems.
Which of the following is an example of a supply chain attack that targeted a software product?
-
The SolarWinds Orion attack
-
The Stuxnet attack
-
The Mirai botnet attack
-
The WannaCry ransomware attack
A
Correct answer
Explanation
The SolarWinds Orion attack is an example of a supply chain attack that targeted a software product, specifically the SolarWinds Orion network management software.
Which of the following is NOT a recommended practice for mitigating supply chain attacks?
-
Implementing strong access controls and authentication mechanisms
-
Conducting regular security audits and penetration testing
-
Educating employees about supply chain security risks
-
Relaxing security measures to reduce costs
D
Correct answer
Explanation
Relaxing security measures to reduce costs is not a recommended practice for mitigating supply chain attacks. It can increase the risk of successful attacks.
Which of the following is NOT a common type of supply chain attack?
-
Man-in-the-Middle (MitM) Attack
-
Zero-Day Attack
-
Phishing Attack
-
Insider Attack
B
Correct answer
Explanation
Zero-Day Attacks are not specifically targeted at supply chains. They exploit vulnerabilities in software or systems that are not yet known to the vendor or the general public.
Which of the following is NOT a common security measure implemented in geospatial technologies?
-
Access control
-
Data encryption
-
Data anonymization
-
Data backup
D
Correct answer
Explanation
Data backup is a process of creating copies of geographical data for recovery purposes in case of data loss or corruption. While it is an important practice for data management, it is not specifically related to enhancing geographical data privacy and security.
Which of the following is a widely recognized cybersecurity framework developed by the National Institute of Standards and Technology (NIST)?
-
ISO 27001
-
COBIT
-
NIST Cybersecurity Framework
-
PCI DSS
C
Correct answer
Explanation
The NIST Cybersecurity Framework is a voluntary framework that provides a set of guidelines and best practices for organizations to manage and reduce cybersecurity risks.
Which framework focuses on providing guidance for managing information security risks in an organization?
-
ISO 27001
-
NIST Cybersecurity Framework
-
COBIT
-
PCI DSS
A
Correct answer
Explanation
ISO 27001 is an international standard that provides a comprehensive set of requirements for an information security management system (ISMS).
Which framework is specifically designed to protect the privacy of personal data in the European Union?
-
ISO 27001
-
NIST Cybersecurity Framework
-
COBIT
-
GDPR
D
Correct answer
Explanation
The General Data Protection Regulation (GDPR) is a comprehensive framework that regulates the processing and protection of personal data in the European Union.
Which framework is designed to help organizations manage cybersecurity risks in the financial sector?
-
ISO 27001
-
NIST Cybersecurity Framework
-
COBIT
-
Financial Industry Regulatory Authority (FINRA) Cybersecurity Assessment Tool (CAT)
D
Correct answer
Explanation
The FINRA CAT is a framework that helps financial institutions assess and manage cybersecurity risks.
What is the purpose of the Center for Internet Security (CIS) Critical Security Controls (CSC)?
-
To protect sensitive data in cloud environments
-
To ensure compliance with government regulations
-
To secure mobile devices and applications
-
To provide a prioritized list of security controls for organizations to implement
D
Correct answer
Explanation
The CIS CSC is a prioritized list of security controls that organizations can implement to reduce cybersecurity risks.
Which framework is designed to help organizations manage cybersecurity risks in the energy sector?
-
ISO 27001
-
NIST Cybersecurity Framework
-
COBIT
-
North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) Standards
D
Correct answer
Explanation
The NERC CIP Standards are a set of regulations that electric utilities must follow to protect the reliability and security of the bulk electric system.