Computer Knowledge ยท General Awareness

Information Security

4,634 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is NOT a common social engineering technique used in whaling attacks?

  1. Pretexting

  2. Impersonation

  3. Baiting

  4. Tailgating

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Tailgating is a technique used to gain unauthorized access to a building or facility by following someone who has authorized access.

Multiple choice

Which of the following is NOT a common social engineering technique used in BEC attacks?

  1. Pretexting

  2. Impersonation

  3. Baiting

  4. Vishing

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Vishing is a type of phishing attack that uses voice calls to trick people into giving up sensitive information.

Multiple choice

What is the most common type of man-in-the-middle (MitM) attack?

  1. ARP spoofing

  2. DNS spoofing

  3. SSL stripping

  4. IP spoofing

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

ARP spoofing is a type of MitM attack in which an attacker sends fake ARP (Address Resolution Protocol) messages to a victim's computer, causing the victim's traffic to be routed through the attacker's computer.

Multiple choice

Which of the following is NOT a common type of social engineering attack?

  1. Phishing

  2. Baiting

  3. Tailgating

  4. Vishing

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Tailgating is not a common type of social engineering attack. It occurs when an attacker follows a victim into a secure area without authorization.

Multiple choice

What is the most common type of phishing attack?

  1. Spear phishing

  2. Whaling

  3. Clone phishing

  4. CEO fraud

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Spear phishing is a type of phishing attack in which an attacker targets a specific individual or organization with a personalized email message.

Multiple choice

Which of the following is NOT a common type of baiting attack?

  1. USB drop

  2. Malicious website

  3. Fake software update

  4. Poisoned search results

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Poisoned search results are not a common type of baiting attack. They occur when an attacker manipulates search engine results to display malicious websites or links.

Multiple choice

What is the most common type of vishing attack?

  1. Automated calls

  2. Live calls

  3. Robocalls

  4. Smishing

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Automated calls are the most common type of vishing attack. They use pre-recorded messages to trick victims into giving up personal information or downloading malware.

Multiple choice

Which of the following is NOT a common type of smishing attack?

  1. Text message phishing

  2. SMS spoofing

  3. MMS phishing

  4. QR code phishing

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

QR code phishing is not a common type of smishing attack. It occurs when an attacker creates a malicious QR code that, when scanned, directs the victim to a malicious website or downloads malware.

Multiple choice

What is the most common type of zero-day vulnerability?

  1. Buffer overflow

  2. Cross-site scripting

  3. SQL injection

  4. Remote code execution

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Remote code execution is the most common type of zero-day vulnerability. It allows an attacker to execute arbitrary code on a victim's computer.

Multiple choice

What is the most common type of ransomware attack?

  1. Cryptolocker

  2. WannaCry

  3. Petya

  4. Locky

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Cryptolocker is the most common type of ransomware attack. It encrypts a victim's files and demands a ransom payment to decrypt them.

Multiple choice

What are some of the security risks associated with using mobile devices in government?

  1. Malware and viruses

  2. Phishing attacks

  3. Data breaches

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Mobile devices in government can be vulnerable to malware and viruses, phishing attacks, data breaches, and other security risks.

Multiple choice

How can government agencies protect themselves from mobile security risks?

  1. Implementing strong security policies and procedures

  2. Using mobile device management (MDM) solutions

  3. Educating employees about mobile security risks

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Government agencies can protect themselves from mobile security risks by implementing strong security policies and procedures, using MDM solutions, and educating employees about mobile security risks.

Multiple choice

How can I make sure that I am using technology safely for sexual health?

  1. Only use reputable sources of information about sexual health

  2. Be careful about who you connect with online

  3. Use strong passwords and security measures

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

To make sure that you are using technology safely for sexual health, you should only use reputable sources of information about sexual health, be careful about who you connect with online, and use strong passwords and security measures.

Multiple choice

What is the difference between a phishing attack and a man-in-the-middle attack?

  1. A phishing attack is an attempt to trick a user into revealing their personal information, while a man-in-the-middle attack is an attempt to intercept communications between two parties.

  2. Phishing attacks are typically carried out through email or text messages, while man-in-the-middle attacks are typically carried out through network vulnerabilities.

  3. Phishing attacks can lead to identity theft, while man-in-the-middle attacks can lead to eavesdropping or data theft.

  4. All of the above.

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

A phishing attack is an attempt to trick a user into revealing their personal information, while a man-in-the-middle attack is an attempt to intercept communications between two parties. Phishing attacks are typically carried out through email or text messages, while man-in-the-middle attacks are typically carried out through network vulnerabilities. Phishing attacks can lead to identity theft, while man-in-the-middle attacks can lead to eavesdropping or data theft.

Multiple choice

Which of the following is NOT a common type of cybersecurity threat faced by healthcare organizations?

  1. Phishing attacks

  2. Ransomware attacks

  3. DDoS attacks

  4. Medical device hacking

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

DDoS attacks are typically aimed at disrupting the availability of online services, rather than compromising sensitive data or systems. Phishing, ransomware, and medical device hacking are more common threats in the healthcare context.