Computer Knowledge ยท General Awareness

Information Security

4,634 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is a common cloud computing security threat that involves exploiting vulnerabilities in web applications?

  1. Cross-site scripting (XSS)

  2. Distributed Denial of Service (DDoS) attacks

  3. Malware and virus infections

  4. Data breaches and unauthorized access

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Cross-site scripting (XSS) is a common cloud computing security threat that involves injecting malicious code into web applications, allowing attackers to steal sensitive information or compromise user accounts.

Multiple choice

Which of the following is a common cloud computing security threat that involves gaining unauthorized access to sensitive data?

  1. Data breaches and unauthorized access

  2. Distributed Denial of Service (DDoS) attacks

  3. Malware and virus infections

  4. Cross-site scripting (XSS)

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Data breaches and unauthorized access involve gaining unauthorized access to sensitive data stored in cloud systems, often through vulnerabilities or weak security controls.

Multiple choice

What does the OR operator do?

  1. It connects two search terms and broadens the results

  2. It connects two search terms and narrows the results

  3. It excludes one search term from the results

  4. None of the above

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The OR operator connects two search terms and broadens the results.

Multiple choice

How does blockchain technology impact data privacy?

  1. It enhances data privacy by encrypting all data on the blockchain.

  2. It reduces data privacy by making all data on the blockchain publicly accessible.

  3. It has no impact on data privacy.

  4. It depends on the specific blockchain application.

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

The impact of blockchain on data privacy depends on the specific application and its design. Some blockchain applications may enhance data privacy, while others may reduce it.

Multiple choice

Which of the following is an example of a physical security control?

  1. Firewall

  2. Intrusion detection system

  3. Access control list

  4. Security guard

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

A security guard is an example of a physical security control because it involves the use of physical measures to protect assets from unauthorized access or damage.

Multiple choice

Which of the following is an example of a technical security control?

  1. Security policy

  2. Encryption

  3. Employee training

  4. Physical access control

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Encryption is an example of a technical security control because it involves the use of technology to protect data from unauthorized access or disclosure.

Multiple choice

Which of the following is an example of an administrative security control?

  1. Firewall

  2. Intrusion detection system

  3. Security policy

  4. Employee training

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

A security policy is an example of an administrative security control because it involves the establishment of rules and procedures to guide the behavior of users and administrators in order to protect information assets.

Multiple choice

What is the primary objective of the European Union's General Data Protection Regulation (GDPR) in relation to blockchain technologies?

  1. To promote the adoption of blockchain technologies in the EU

  2. To regulate the use of blockchain technologies in financial transactions

  3. To protect the privacy and personal data of individuals using blockchain technologies

  4. To establish a common regulatory framework for blockchain technologies across the EU

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

The primary objective of the GDPR is to protect the privacy and personal data of individuals, including in the context of blockchain technologies.

Multiple choice

Which of the following is a common IoT connectivity security threat?

  1. Buffer overflow attacks

  2. Cross-site scripting attacks

  3. SQL injection attacks

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Buffer overflow attacks, cross-site scripting attacks, and SQL injection attacks are all common IoT connectivity security threats that can exploit vulnerabilities in IoT devices and cloud platforms to compromise their security.

Multiple choice

Which privacy-enhancing feature is a core aspect of PureOS?

  1. Automatic updates

  2. Encrypted file system

  3. Pre-installed antivirus software

  4. Default root access

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

PureOS utilizes an encrypted file system by default, ensuring that user data remains secure and protected from unauthorized access.

Multiple choice

Which of the following is NOT a privacy-enhancing feature of PureOS?

  1. Automatic updates

  2. Encrypted file system

  3. Pre-installed antivirus software

  4. Default root access

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

PureOS does not come with pre-installed antivirus software. It relies on the user's choice of security tools.

Multiple choice

What is the responsibility of a software developer in ensuring the privacy of user data?

  1. To collect only the data that is necessary for the software to function

  2. To store and transmit data securely

  3. To provide users with clear and concise information about how their data will be used

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Software developers have a responsibility to ensure the privacy of user data by taking all necessary measures to protect it from unauthorized access, use, or disclosure.

Multiple choice

Which of the following is NOT a common security risk associated with mobile devices in business?

  1. Malware and viruses

  2. Phishing attacks

  3. Data breaches

  4. Physical theft or loss of devices

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Phishing attacks are typically carried out through email or malicious websites, and are not directly related to mobile devices. Malware, viruses, data breaches, and physical theft or loss of devices are all common security risks associated with mobile devices in business.

Multiple choice

Which of the following is NOT a common feature of an MDM solution?

  1. Device enrollment and provisioning

  2. App distribution and management

  3. Security policy enforcement

  4. Remote device wiping

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Remote device wiping is not a common feature of an MDM solution. It is typically a feature of mobile security solutions.

Multiple choice

Which of the following is NOT a common cybersecurity risk in the energy and utilities sector?

  1. Malware attacks

  2. Phishing scams

  3. Physical security breaches

  4. DDoS attacks

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Physical security breaches are not typically considered a cybersecurity risk, as they involve unauthorized access to physical assets rather than digital systems.