Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is an example of a geographical data privacy breach in India?

  1. The Aadhaar data breach

  2. The Uber data breach

  3. The Facebook data breach

  4. The Equifax data breach

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The Aadhaar data breach is an example of a geographical data privacy breach in India. The breach involved the unauthorized access to the personal data of over 1 billion Indian citizens, including their names, addresses, fingerprints, and iris scans. The breach had a significant impact on individuals, including identity theft and financial loss.

Multiple choice

What is the primary function of GPUs in automotive cybersecurity?

  1. Intrusion detection

  2. Malware analysis

  3. Vulnerability assessment

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

GPUs are used in automotive cybersecurity to perform complex tasks such as intrusion detection, malware analysis, and vulnerability assessment in real time, helping to protect vehicles from cyber threats.

Multiple choice

Which law in the United States requires organizations to notify individuals affected by a data breach?

  1. Health Insurance Portability and Accountability Act (HIPAA)

  2. Gramm-Leach-Bliley Act (GLBA)

  3. Sarbanes-Oxley Act (SOX)

  4. General Data Protection Regulation (GDPR)

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to notify individuals affected by a data breach.

Multiple choice

Which regulatory framework requires organizations to implement and maintain a vulnerability management program?

  1. National Institute of Standards and Technology (NIST)

  2. Payment Card Industry Data Security Standard (PCI DSS)

  3. Health Insurance Portability and Accountability Act (HIPAA)

  4. International Organization for Standardization (ISO)

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

The Payment Card Industry Data Security Standard (PCI DSS) requires organizations that process credit card data to implement and maintain a vulnerability management program.

Multiple choice

Which of the following is NOT a common type of mobile device incident?

  1. Malware infection

  2. Phishing attack

  3. Device theft

  4. Denial-of-service attack

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Denial-of-service attacks are typically not associated with mobile devices, as they are more commonly targeted at servers or networks.

Multiple choice

Which of the following is a common method for containing a mobile device incident?

  1. Isolating the device from the network

  2. Powering off the device

  3. Rebooting the device

  4. Updating the device's software

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Isolating the device from the network is a common method for containing a mobile device incident, as it prevents the incident from spreading to other devices.

Multiple choice

Which of the following is NOT a common type of mobile device malware?

  1. Spyware

  2. Adware

  3. Ransomware

  4. Cryptocurrency miner

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Cryptocurrency miners are typically not associated with mobile devices, as they are more commonly found on computers.

Multiple choice

What is the CIA triad in data security?

  1. Confidentiality, Integrity, Availability

  2. Confidentiality, Integrity, Authentication

  3. Confidentiality, Integrity, Authorization

  4. Confidentiality, Integrity, Encryption

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The CIA triad is a model that defines the three main objectives of data security: confidentiality, integrity, and availability.

Multiple choice

Which of the following is an example of a physical data security measure?

  1. Encryption

  2. Access control lists

  3. Firewalls

  4. Intrusion detection systems

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Firewalls are physical devices or software programs that monitor and control incoming and outgoing network traffic based on predetermined security rules.

Multiple choice

Which of the following is a common type of cyber attack that targets data security?

  1. Phishing

  2. Malware

  3. DDoS attacks

  4. SQL injection

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Malware, such as viruses, worms, and trojan horses, can compromise data security by infecting systems and stealing, modifying, or destroying data.

Multiple choice

What is the role of access control in data security?

  1. To restrict unauthorized access to data

  2. To ensure data integrity

  3. To enhance data availability

  4. To improve data performance

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Access control mechanisms, such as authentication and authorization, are used to restrict unauthorized access to data and resources.

Multiple choice

Which of the following is a best practice for data privacy?

  1. Collecting only necessary data

  2. Storing data securely

  3. Providing clear privacy policies

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Data privacy best practices include collecting only necessary data, storing data securely, and providing clear privacy policies to users.

Multiple choice

What is the concept of data minimization in data security?

  1. Collecting only necessary data

  2. Storing data securely

  3. Providing clear privacy policies

  4. All of the above

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Data minimization refers to the practice of collecting only the data that is essential for a specific purpose, reducing the risk of data breaches and unauthorized access.

Multiple choice

Which of the following is a common type of data security incident?

  1. Data breach

  2. Malware infection

  3. Phishing attack

  4. DDoS attack

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A data breach occurs when sensitive or confidential data is accessed, used, or disclosed without authorization.

Multiple choice

Which of the following is a common type of data privacy violation?

  1. Unauthorized collection of personal data

  2. Unlawful use of personal data

  3. Disclosure of personal data without consent

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Unauthorized collection, unlawful use, and disclosure of personal data without consent are all examples of data privacy violations.