Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
Which of the following is an example of a stream cipher?
D
Correct answer
Explanation
RC4 (Rivest Cipher 4) is an example of a stream cipher.
Which of the following is an example of a public-key cryptosystem?
B
Correct answer
Explanation
RSA (Rivest-Shamir-Adleman) is an example of a public-key cryptosystem.
Which of the following is an example of a private-key cryptosystem?
A
Correct answer
Explanation
AES (Advanced Encryption Standard) is an example of a private-key cryptosystem.
What are the three main types of security threats?
-
Natural disasters, human error, and cyberattacks
-
Malware, phishing, and social engineering
-
Hackers, crackers, and script kiddies
-
DDoS attacks, zero-day exploits, and advanced persistent threats
B
Correct answer
Explanation
The three main types of security threats are malware, phishing, and social engineering. Malware is malicious software that can damage or disable computer systems, phishing is a type of online fraud that attempts to trick users into revealing personal information, and social engineering is a type of attack that relies on human error to trick users into compromising security.
What is the best way to protect against phishing attacks?
-
Use strong passwords and change them regularly
-
Be suspicious of unsolicited emails and links
-
Never enter personal information on a website that you don't trust
-
All of the above
D
Correct answer
Explanation
The best way to protect against phishing attacks is to use strong passwords and change them regularly, be suspicious of unsolicited emails and links, and never enter personal information on a website that you don't trust.
What is the most common type of malware?
-
Viruses
-
Worms
-
Trojan horses
-
Ransomware
A
Correct answer
Explanation
Viruses are the most common type of malware. They are self-replicating programs that can attach themselves to other files and spread from one computer to another.
What is the best way to protect against ransomware attacks?
-
Back up your data regularly
-
Use strong passwords and change them regularly
-
Be suspicious of unsolicited emails and links
-
All of the above
D
Correct answer
Explanation
The best way to protect against ransomware attacks is to back up your data regularly, use strong passwords and change them regularly, and be suspicious of unsolicited emails and links.
What is the difference between a denial-of-service (DoS) attack and a distributed denial-of-service (DDoS) attack?
-
A DoS attack is launched from a single computer, while a DDoS attack is launched from multiple computers
-
A DoS attack targets a single server, while a DDoS attack targets multiple servers
-
A DoS attack is more difficult to defend against than a DDoS attack
-
All of the above
A
Correct answer
Explanation
A DoS attack is launched from a single computer, while a DDoS attack is launched from multiple computers. A DoS attack targets a single server, while a DDoS attack targets multiple servers. A DDoS attack is more difficult to defend against than a DoS attack.
What is the best way to protect against social engineering attacks?
-
Be aware of the different types of social engineering attacks
-
Be suspicious of unsolicited emails and links
-
Never give out personal information over the phone or online unless you are sure who you are dealing with
-
All of the above
D
Correct answer
Explanation
The best way to protect against social engineering attacks is to be aware of the different types of social engineering attacks, be suspicious of unsolicited emails and links, and never give out personal information over the phone or online unless you are sure who you are dealing with.
What is the best way to protect against zero-day exploits?
-
Keep software up to date with the latest security patches
-
Use a firewall and intrusion detection system (IDS)
-
Educate employees about security risks and best practices
-
All of the above
D
Correct answer
Explanation
The best way to protect against zero-day exploits is to keep software up to date with the latest security patches, use a firewall and intrusion detection system (IDS), and educate employees about security risks and best practices.
What is the best way to protect against advanced persistent threats (APTs)?
-
Use a multi-layered security approach
-
Educate employees about security risks and best practices
-
Monitor network traffic for suspicious activity
-
All of the above
D
Correct answer
Explanation
The best way to protect against advanced persistent threats (APTs) is to use a multi-layered security approach, educate employees about security risks and best practices, and monitor network traffic for suspicious activity.
Which of the following is NOT a common security threat in computer engineering?
-
Malware
-
Phishing
-
Spam
-
Hardware failure
D
Correct answer
Explanation
Hardware failure is not a common security threat in computer engineering. Common security threats include malware, phishing, and spam.
What is the term used to describe the illegal practice of using a computer or electronic device to access or manipulate data without authorization?
-
Cybercrime
-
Hacking
-
Phishing
-
Malware
A
Correct answer
Explanation
Cybercrime refers to illegal activities committed using computers or electronic devices, including hacking, phishing, and malware attacks.
Which of the following is NOT a common type of data privacy and security risk in educational research?
-
Unauthorized access to research data
-
Accidental data loss or destruction
-
Malware attacks
-
Human error
C
Correct answer
Explanation
Malware attacks are not typically a common type of data privacy and security risk in educational research. However, unauthorized access to research data, accidental data loss or destruction, and human error are all common risks.
Which of the following is NOT a common method for authenticating digital evidence?
-
Hash value verification
-
Metadata analysis
-
Chain of custody documentation
-
Witness testimony
D
Correct answer
Explanation
Witness testimony is not typically used to authenticate digital evidence. Instead, methods such as hash value verification, metadata analysis, and chain of custody documentation are commonly employed.