Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
Which of the following is NOT a recommended best practice for HIPAA compliance?
-
Use strong passwords and regularly change them
-
Implement multi-factor authentication
-
Use a firewall to protect your network
-
Allow employees to access ePHI from their personal devices
D
Correct answer
Explanation
Allowing employees to access ePHI from their personal devices is not a recommended best practice for HIPAA compliance.
Which of the following is NOT a type of web application vulnerability?
-
Cross-site scripting (XSS)
-
SQL injection
-
Buffer overflow
-
Man-in-the-middle attack
C
Correct answer
Explanation
Buffer overflow is a type of memory corruption vulnerability that can occur in any program, not just web applications.
What is the purpose of a web application firewall (WAF)?
-
To block malicious traffic at the network layer
-
To detect and prevent SQL injection attacks
-
To protect against cross-site scripting (XSS) attacks
-
All of the above
D
Correct answer
Explanation
A WAF is a security device that is placed in front of a web application to protect it from malicious traffic and attacks.
What is the OWASP Top 10?
-
A list of the most common web application vulnerabilities
-
A set of best practices for securing web applications
-
A tool for scanning web applications for vulnerabilities
-
A training program for web application developers
A
Correct answer
Explanation
The OWASP Top 10 is a list of the most common web application vulnerabilities, as identified by the Open Web Application Security Project (OWASP).
What is the purpose of a security header?
-
To protect a web application from malicious traffic and attacks
-
To improve the performance of a web application
-
To make a web application more user-friendly
-
To track user activity on a web application
A
Correct answer
Explanation
A security header is a response header that is sent by a web server to a web browser in order to protect the web application from malicious traffic and attacks.
Which of the following is NOT a type of honeypot?
-
Production honeypot
-
Research honeypot
-
Honeynet
-
Decoy system
D
Correct answer
Explanation
A decoy system is not a type of honeypot. It is a system that is designed to look like a real system, but is actually a fake system. Decoy systems are used to trick attackers into thinking that they have compromised a real system, when in fact they have not.
Which of the following is NOT a type of security audit?
-
Vulnerability assessment
-
Penetration testing
-
Risk assessment
-
Compliance audit
D
Correct answer
Explanation
A compliance audit is not a type of security audit. It is an audit that is conducted to ensure that a system complies with a set of regulations or standards.
Which of the following is a best practice for improving network resiliency?
-
Regularly updating network firmware and software.
-
Implementing security measures to protect against cyberattacks.
-
Conducting regular network audits and assessments.
-
All of the above
D
Correct answer
Explanation
All of the options are best practices for improving network resiliency. Regularly updating network firmware and software helps to address vulnerabilities and improve performance. Implementing security measures protects against cyberattacks, and conducting regular network audits and assessments helps to identify potential problems and vulnerabilities.
Which of the following is NOT a common type of mobile device malware?
-
Virus
-
Trojan
-
Spyware
-
Adware
D
Correct answer
Explanation
Adware is not a common type of mobile device malware.
What is the best way to protect a mobile device from malware?
-
Install a mobile security app
-
Keep the device's software up to date
-
Avoid downloading apps from unknown sources
-
All of the above
D
Correct answer
Explanation
All of the options listed are important in protecting a mobile device from malware.
Which of the following is a common web application security best practice?
-
Implementing input validation and sanitization
-
Using secure coding practices
-
Regularly updating software and dependencies
-
All of the above
D
Correct answer
Explanation
Implementing input validation and sanitization, using secure coding practices, and regularly updating software and dependencies are all common web application security best practices that help protect web applications from vulnerabilities and attacks.
Which of the following is a common cybersecurity compliance framework for critical infrastructure?
-
NIST Cybersecurity Framework
-
ISO 27001/27002
-
PCI DSS
-
HIPAA
A
Correct answer
Explanation
The NIST Cybersecurity Framework is a comprehensive framework that provides guidance on how to manage cybersecurity risks in critical infrastructure.
What is the primary focus of the NIST Cybersecurity Framework?
-
Protecting sensitive data
-
Ensuring the continuity of essential services
-
Maintaining a competitive advantage
-
Complying with industry regulations
B
Correct answer
Explanation
The NIST Cybersecurity Framework focuses on ensuring the continuity of essential services by providing guidance on how to identify, protect, detect, respond to, and recover from cybersecurity incidents.
What is the importance of cybersecurity compliance in critical infrastructure?
-
To protect sensitive data and systems from unauthorized access
-
To ensure the continuity of essential services
-
To maintain a competitive advantage
-
To comply with industry regulations
Correct answer
Explanation
Cybersecurity compliance in critical infrastructure is important for protecting sensitive data and systems from unauthorized access, ensuring the continuity of essential services, maintaining a competitive advantage, and complying with industry regulations.
Which of the following is a common cybersecurity compliance framework for critical infrastructure in the water and wastewater sector?
-
AWWA G430
-
ISO 27001/27002
-
PCI DSS
-
HIPAA
A
Correct answer
Explanation
AWWA G430 is a cybersecurity compliance framework specifically designed for the water and wastewater sector, developed by the American Water Works Association (AWWA).