Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is NOT a common type of cybersecurity incident?

  1. Malware attack

  2. Phishing attack

  3. DDoS attack

  4. SQL injection attack

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

DDoS attacks are not a common type of cybersecurity incident. They are a type of cyberattack.

Multiple choice

What is the default encryption algorithm used by Cloud Storage?

  1. AES-256

  2. AES-128

  3. RSA-2048

  4. ECC-256

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Cloud Storage uses AES-256 as the default encryption algorithm for data at rest.

Multiple choice

Which type of cryptographic key is used to decrypt data encrypted with a public key?

  1. Public Key

  2. Private Key

  3. Symmetric Key

  4. Asymmetric Key

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

A private key is used to decrypt data encrypted with a public key. The private key is kept secret by the owner and is used to access and control the associated cryptocurrency or digital assets.

Multiple choice

Which cryptographic algorithm is commonly used for securing data in Ethereum smart contracts?

  1. AES-256

  2. SHA-256

  3. RSA

  4. Keccak-256

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Keccak-256 is a cryptographic hash function commonly used for securing data in Ethereum smart contracts. It is known for its high security and resistance to collision attacks, making it suitable for protecting sensitive information on the blockchain.

Multiple choice

What is the first step in responding to a cybersecurity incident?

  1. Identify the incident

  2. Contain the incident

  3. Eradicate the incident

  4. Recover from the incident

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The first step in responding to a cybersecurity incident is to identify the incident. This involves gathering information about the incident, such as the time and date of the incident, the source of the incident, and the impact of the incident.

Multiple choice

Which of the following is NOT a common method for containing a cybersecurity incident?

  1. Isolating the affected system

  2. Disabling user accounts

  3. Patching the affected system

  4. Changing passwords

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Patching the affected system is not a common method for containing a cybersecurity incident. The common methods for containing a cybersecurity incident are isolating the affected system, disabling user accounts, and changing passwords.

Multiple choice

What is the goal of eradicating a cybersecurity incident?

  1. To prevent the incident from spreading

  2. To restore the affected system to its normal state

  3. To collect evidence of the incident

  4. To identify the source of the incident

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The goal of eradicating a cybersecurity incident is to prevent the incident from spreading. This involves removing the malware or other malicious software from the affected system and closing any security holes that allowed the incident to occur.

Multiple choice

Which of the following is NOT a common method for recovering from a cybersecurity incident?

  1. Restoring data from backups

  2. Rebuilding the affected system

  3. Implementing new security measures

  4. Conducting a post-mortem analysis

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Rebuilding the affected system is not a common method for recovering from a cybersecurity incident. The common methods for recovering from a cybersecurity incident are restoring data from backups, implementing new security measures, and conducting a post-mortem analysis.

Multiple choice

Which of the following is NOT a common type of cybersecurity incident?

  1. Malware attack

  2. Phishing attack

  3. DDoS attack

  4. Insider attack

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Insider attack is not a common type of cybersecurity incident. The common types of cybersecurity incidents are malware attack, phishing attack, and DDoS attack.

Multiple choice

Which of the following is NOT a common type of cybersecurity regulation?

  1. GDPR

  2. HIPAA

  3. PCI DSS

  4. SOX

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

SOX is not a common type of cybersecurity regulation. The common types of cybersecurity regulations are GDPR, HIPAA, and PCI DSS.

Multiple choice

Which of the following is NOT a common type of cybersecurity control?

  1. Access control

  2. Network security

  3. Data security

  4. Incident response

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Incident response is not a common type of cybersecurity control. The common types of cybersecurity controls are access control, network security, and data security.

Multiple choice

Which of the following is NOT a common type of cybersecurity metric?

  1. Number of security incidents

  2. Mean time to detect a security incident

  3. Mean time to respond to a security incident

  4. Cost of a security incident

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Cost of a security incident is not a common type of cybersecurity metric. The common types of cybersecurity metrics are number of security incidents, mean time to detect a security incident, and mean time to respond to a security incident.

Multiple choice

What is the minimum required security measure for HIPAA covered entities?

  1. Encryption of electronic protected health information (ePHI)

  2. Regular security risk assessments

  3. Employee training on HIPAA requirements

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

HIPAA covered entities are required to implement a comprehensive security program that includes all of the above measures.

Multiple choice

Which of the following is NOT a common type of HIPAA violation?

  1. Unauthorized access to ePHI

  2. Disclosure of ePHI without patient consent

  3. Failure to encrypt ePHI

  4. Failure to provide patients with a Notice of Privacy Practices

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Failure to provide patients with a Notice of Privacy Practices is not a common type of HIPAA violation.

Multiple choice

Which of the following is NOT a recommended best practice for HIPAA compliance?

  1. Use strong passwords and regularly change them

  2. Implement multi-factor authentication

  3. Use a firewall to protect your network

  4. Back up your data regularly

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Backing up your data regularly is not a recommended best practice for HIPAA compliance.