Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
Which of the following is an example of a geographical data privacy breach in India?
-
The Aadhaar data breach
-
The Uber data breach
-
The Facebook data breach
-
The Equifax data breach
A
Correct answer
Explanation
The Aadhaar data breach is an example of a geographical data privacy breach in India. The breach involved the unauthorized access to the personal data of over 1 billion Indian citizens, including their names, addresses, fingerprints, and iris scans. The breach had a significant impact on individuals, including identity theft and financial loss.
What is the primary function of GPUs in automotive cybersecurity?
-
Intrusion detection
-
Malware analysis
-
Vulnerability assessment
-
All of the above
D
Correct answer
Explanation
GPUs are used in automotive cybersecurity to perform complex tasks such as intrusion detection, malware analysis, and vulnerability assessment in real time, helping to protect vehicles from cyber threats.
Which law in the United States requires organizations to notify individuals affected by a data breach?
-
Health Insurance Portability and Accountability Act (HIPAA)
-
Gramm-Leach-Bliley Act (GLBA)
-
Sarbanes-Oxley Act (SOX)
-
General Data Protection Regulation (GDPR)
B
Correct answer
Explanation
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to notify individuals affected by a data breach.
Which regulatory framework requires organizations to implement and maintain a vulnerability management program?
-
National Institute of Standards and Technology (NIST)
-
Payment Card Industry Data Security Standard (PCI DSS)
-
Health Insurance Portability and Accountability Act (HIPAA)
-
International Organization for Standardization (ISO)
B
Correct answer
Explanation
The Payment Card Industry Data Security Standard (PCI DSS) requires organizations that process credit card data to implement and maintain a vulnerability management program.
Which of the following is NOT a common type of mobile device incident?
-
Malware infection
-
Phishing attack
-
Device theft
-
Denial-of-service attack
D
Correct answer
Explanation
Denial-of-service attacks are typically not associated with mobile devices, as they are more commonly targeted at servers or networks.
Which of the following is a common method for containing a mobile device incident?
-
Isolating the device from the network
-
Powering off the device
-
Rebooting the device
-
Updating the device's software
A
Correct answer
Explanation
Isolating the device from the network is a common method for containing a mobile device incident, as it prevents the incident from spreading to other devices.
Which of the following is NOT a common type of mobile device malware?
-
Spyware
-
Adware
-
Ransomware
-
Cryptocurrency miner
D
Correct answer
Explanation
Cryptocurrency miners are typically not associated with mobile devices, as they are more commonly found on computers.
What is the CIA triad in data security?
-
Confidentiality, Integrity, Availability
-
Confidentiality, Integrity, Authentication
-
Confidentiality, Integrity, Authorization
-
Confidentiality, Integrity, Encryption
A
Correct answer
Explanation
The CIA triad is a model that defines the three main objectives of data security: confidentiality, integrity, and availability.
Which of the following is an example of a physical data security measure?
-
Encryption
-
Access control lists
-
Firewalls
-
Intrusion detection systems
C
Correct answer
Explanation
Firewalls are physical devices or software programs that monitor and control incoming and outgoing network traffic based on predetermined security rules.
Which of the following is a common type of cyber attack that targets data security?
-
Phishing
-
Malware
-
DDoS attacks
-
SQL injection
B
Correct answer
Explanation
Malware, such as viruses, worms, and trojan horses, can compromise data security by infecting systems and stealing, modifying, or destroying data.
What is the role of access control in data security?
-
To restrict unauthorized access to data
-
To ensure data integrity
-
To enhance data availability
-
To improve data performance
A
Correct answer
Explanation
Access control mechanisms, such as authentication and authorization, are used to restrict unauthorized access to data and resources.
Which of the following is a best practice for data privacy?
-
Collecting only necessary data
-
Storing data securely
-
Providing clear privacy policies
-
All of the above
D
Correct answer
Explanation
Data privacy best practices include collecting only necessary data, storing data securely, and providing clear privacy policies to users.
What is the concept of data minimization in data security?
-
Collecting only necessary data
-
Storing data securely
-
Providing clear privacy policies
-
All of the above
A
Correct answer
Explanation
Data minimization refers to the practice of collecting only the data that is essential for a specific purpose, reducing the risk of data breaches and unauthorized access.
Which of the following is a common type of data security incident?
-
Data breach
-
Malware infection
-
Phishing attack
-
DDoS attack
A
Correct answer
Explanation
A data breach occurs when sensitive or confidential data is accessed, used, or disclosed without authorization.
Which of the following is a common type of data privacy violation?
-
Unauthorized collection of personal data
-
Unlawful use of personal data
-
Disclosure of personal data without consent
-
All of the above
D
Correct answer
Explanation
Unauthorized collection, unlawful use, and disclosure of personal data without consent are all examples of data privacy violations.