Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
What is the legal term for the unauthorized use of a person's personal information for commercial purposes?
-
Data mining
-
Data harvesting
-
Data scraping
-
Dataveillance
A
Correct answer
Explanation
Data mining is the legal term for the unauthorized use of a person's personal information for commercial purposes.
What is the legal term for the unauthorized use of a person's personal information to make a decision about them?
-
Profiling
-
Scoring
-
Targeting
-
Dataveillance
A
Correct answer
Explanation
Profiling is the legal term for the unauthorized use of a person's personal information to make a decision about them.
What is the best way to educate employees about cybersecurity?
-
Provide them with training materials
-
Hold regular security awareness training sessions
-
Make them sign a security policy
-
All of the above
D
Correct answer
Explanation
The best way to educate employees about cybersecurity is to provide them with training materials, hold regular security awareness training sessions, and make them sign a security policy.
Which of the following is NOT a common type of security control?
-
Firewalls
-
Intrusion detection systems
-
Antivirus software
-
Penetration testing
D
Correct answer
Explanation
Penetration testing is not a common type of security control. It is a security assessment technique that is used to identify vulnerabilities in a system.
What is the best way to protect against zero-day attacks?
-
Use a firewall
-
Use an intrusion detection system
-
Use antivirus software
-
Keep software up to date
D
Correct answer
Explanation
The best way to protect against zero-day attacks is to keep software up to date. This is because zero-day attacks exploit vulnerabilities in software that have not yet been patched.
What is the difference between a denial-of-service attack and a distributed denial-of-service attack?
-
A denial-of-service attack is an attack that targets a single system, while a distributed denial-of-service attack is an attack that targets multiple systems
-
A denial-of-service attack is an attack that targets a network, while a distributed denial-of-service attack is an attack that targets a system
-
A denial-of-service attack is an attack that targets a service, while a distributed denial-of-service attack is an attack that targets a network
-
A denial-of-service attack is an attack that targets a system, while a distributed denial-of-service attack is an attack that targets a service
A
Correct answer
Explanation
A denial-of-service attack is an attack that targets a single system, while a distributed denial-of-service attack is an attack that targets multiple systems. A denial-of-service attack is typically carried out by a single attacker, while a distributed denial-of-service attack is typically carried out by a group of attackers.
What is the best way to protect against phishing attacks?
-
Use a firewall
-
Use an intrusion detection system
-
Use antivirus software
-
Educate employees about phishing
D
Correct answer
Explanation
The best way to protect against phishing attacks is to educate employees about phishing. This is because phishing attacks rely on tricking employees into clicking on malicious links or opening malicious attachments.
What is the best way to protect against ransomware attacks?
-
Use a firewall
-
Use an intrusion detection system
-
Use antivirus software
-
Back up data regularly
D
Correct answer
Explanation
The best way to protect against ransomware attacks is to back up data regularly. This is because ransomware attacks encrypt data, making it inaccessible to the victim. If the victim has a backup of their data, they can restore their data after the ransomware attack.
Which of the following is NOT a common method for detecting security incidents?
-
Security information and event management (SIEM) systems
-
Intrusion detection systems (IDS)
-
Vulnerability scanners
-
Penetration testing
D
Correct answer
Explanation
Penetration testing is not a common method for detecting security incidents. It is a proactive measure that is used to identify vulnerabilities in a system before they can be exploited.
Which of the following is NOT a common method for eradicating security incidents?
-
Antivirus software
-
Malware removal tools
-
Patch management
-
Vulnerability assessment
D
Correct answer
Explanation
Vulnerability assessment is not a common method for eradicating security incidents. It is a proactive measure that is used to identify vulnerabilities in a system before they can be exploited.
Which of the following is NOT a common type of security incident?
-
Malware attacks
-
Phishing attacks
-
Denial-of-service attacks
-
Vulnerability assessments
D
Correct answer
Explanation
Vulnerability assessments are not a common type of security incident. They are a proactive measure that is used to identify vulnerabilities in a system before they can be exploited.
Which of the following is NOT a common component of an intrusion detection system (IDS)?
-
Sensors
-
Console
-
Reporting system
-
Vulnerability scanner
D
Correct answer
Explanation
A vulnerability scanner is not a common component of an intrusion detection system (IDS). It is a proactive measure that is used to identify vulnerabilities in a system before they can be exploited.
Which of the following is NOT a common type of vulnerability assessment?
-
Network vulnerability assessment
-
Host vulnerability assessment
-
Application vulnerability assessment
-
Penetration testing
D
Correct answer
Explanation
Penetration testing is not a common type of vulnerability assessment. It is a proactive measure that is used to identify vulnerabilities in a system before they can be exploited.
Which of the following is NOT a common method for containing an incident?
-
Isolating affected systems
-
Disabling user accounts
-
Patching vulnerable systems
-
Rolling back to a previous system state
C
Correct answer
Explanation
Patching vulnerable systems is not a common method for containing an incident. It is a preventive measure that can be taken to reduce the risk of an incident occurring in the first place.
Which of the following is NOT a common type of incident response tool?
-
Security information and event management (SIEM) system
-
Vulnerability scanner
-
Incident response platform
-
Penetration testing tool
D
Correct answer
Explanation
Penetration testing tools are not a common type of incident response tool. They are used to identify vulnerabilities in an organization's systems and networks.