Computer Knowledge ยท General Awareness
Information Security
4,634 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
Which of the following is NOT a common social engineering technique used in whaling attacks?
-
Pretexting
-
Impersonation
-
Baiting
-
Tailgating
D
Correct answer
Explanation
Tailgating is a technique used to gain unauthorized access to a building or facility by following someone who has authorized access.
Which of the following is NOT a common social engineering technique used in BEC attacks?
-
Pretexting
-
Impersonation
-
Baiting
-
Vishing
D
Correct answer
Explanation
Vishing is a type of phishing attack that uses voice calls to trick people into giving up sensitive information.
What is the most common type of man-in-the-middle (MitM) attack?
-
ARP spoofing
-
DNS spoofing
-
SSL stripping
-
IP spoofing
A
Correct answer
Explanation
ARP spoofing is a type of MitM attack in which an attacker sends fake ARP (Address Resolution Protocol) messages to a victim's computer, causing the victim's traffic to be routed through the attacker's computer.
Which of the following is NOT a common type of social engineering attack?
-
Phishing
-
Baiting
-
Tailgating
-
Vishing
C
Correct answer
Explanation
Tailgating is not a common type of social engineering attack. It occurs when an attacker follows a victim into a secure area without authorization.
What is the most common type of phishing attack?
-
Spear phishing
-
Whaling
-
Clone phishing
-
CEO fraud
A
Correct answer
Explanation
Spear phishing is a type of phishing attack in which an attacker targets a specific individual or organization with a personalized email message.
Which of the following is NOT a common type of baiting attack?
-
USB drop
-
Malicious website
-
Fake software update
-
Poisoned search results
D
Correct answer
Explanation
Poisoned search results are not a common type of baiting attack. They occur when an attacker manipulates search engine results to display malicious websites or links.
What is the most common type of vishing attack?
-
Automated calls
-
Live calls
-
Robocalls
-
Smishing
A
Correct answer
Explanation
Automated calls are the most common type of vishing attack. They use pre-recorded messages to trick victims into giving up personal information or downloading malware.
Which of the following is NOT a common type of smishing attack?
-
Text message phishing
-
SMS spoofing
-
MMS phishing
-
QR code phishing
D
Correct answer
Explanation
QR code phishing is not a common type of smishing attack. It occurs when an attacker creates a malicious QR code that, when scanned, directs the victim to a malicious website or downloads malware.
What is the most common type of zero-day vulnerability?
-
Buffer overflow
-
Cross-site scripting
-
SQL injection
-
Remote code execution
D
Correct answer
Explanation
Remote code execution is the most common type of zero-day vulnerability. It allows an attacker to execute arbitrary code on a victim's computer.
What is the most common type of ransomware attack?
-
Cryptolocker
-
WannaCry
-
Petya
-
Locky
A
Correct answer
Explanation
Cryptolocker is the most common type of ransomware attack. It encrypts a victim's files and demands a ransom payment to decrypt them.
What are some of the security risks associated with using mobile devices in government?
-
Malware and viruses
-
Phishing attacks
-
Data breaches
-
All of the above
D
Correct answer
Explanation
Mobile devices in government can be vulnerable to malware and viruses, phishing attacks, data breaches, and other security risks.
How can government agencies protect themselves from mobile security risks?
-
Implementing strong security policies and procedures
-
Using mobile device management (MDM) solutions
-
Educating employees about mobile security risks
-
All of the above
D
Correct answer
Explanation
Government agencies can protect themselves from mobile security risks by implementing strong security policies and procedures, using MDM solutions, and educating employees about mobile security risks.
How can I make sure that I am using technology safely for sexual health?
-
Only use reputable sources of information about sexual health
-
Be careful about who you connect with online
-
Use strong passwords and security measures
-
All of the above
D
Correct answer
Explanation
To make sure that you are using technology safely for sexual health, you should only use reputable sources of information about sexual health, be careful about who you connect with online, and use strong passwords and security measures.
What is the difference between a phishing attack and a man-in-the-middle attack?
-
A phishing attack is an attempt to trick a user into revealing their personal information, while a man-in-the-middle attack is an attempt to intercept communications between two parties.
-
Phishing attacks are typically carried out through email or text messages, while man-in-the-middle attacks are typically carried out through network vulnerabilities.
-
Phishing attacks can lead to identity theft, while man-in-the-middle attacks can lead to eavesdropping or data theft.
-
All of the above.
D
Correct answer
Explanation
A phishing attack is an attempt to trick a user into revealing their personal information, while a man-in-the-middle attack is an attempt to intercept communications between two parties. Phishing attacks are typically carried out through email or text messages, while man-in-the-middle attacks are typically carried out through network vulnerabilities. Phishing attacks can lead to identity theft, while man-in-the-middle attacks can lead to eavesdropping or data theft.
Which of the following is NOT a common type of cybersecurity threat faced by healthcare organizations?
-
Phishing attacks
-
Ransomware attacks
-
DDoS attacks
-
Medical device hacking
C
Correct answer
Explanation
DDoS attacks are typically aimed at disrupting the availability of online services, rather than compromising sensitive data or systems. Phishing, ransomware, and medical device hacking are more common threats in the healthcare context.