Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

What is the importance of cybersecurity compliance in critical infrastructure in the water and wastewater sector?

  1. To protect sensitive data and systems from unauthorized access

  2. To ensure the continuity of essential services

  3. To maintain a competitive advantage

  4. To comply with industry regulations

Reveal answer Fill a bubble to check yourself
Correct answer
Explanation

Cybersecurity compliance in critical infrastructure in the water and wastewater sector is important for protecting sensitive data and systems from unauthorized access, ensuring the continuity of essential services, maintaining a competitive advantage, and complying with industry regulations.

Multiple choice

Which type of app has better security?

  1. Native app

  2. Hybrid app

  3. Web app

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Native apps typically have better security because they are built specifically for a particular platform and have access to the full range of security features provided by the platform.

Multiple choice

Which of the following is NOT a common solution to address security concerns in mobile applications?

  1. Implementing strong authentication mechanisms

  2. Regular security audits and updates

  3. Encryption of sensitive data

  4. Ignoring security altogether

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Ignoring security altogether is never a solution to address security concerns in mobile applications.

Multiple choice

What is the national security exemption?

  1. An exemption from the Freedom of Information Act that allows the government to withhold information from disclosure if the information would harm national security.

  2. An exemption from the Privacy Act that allows the government to collect and maintain information about individuals without their knowledge or consent if the information is necessary for national security purposes.

  3. An exemption from the Foreign Intelligence Surveillance Act that allows the government to conduct surveillance of foreign nationals without a warrant if the surveillance is necessary for national security purposes.

  4. An exemption from the Electronic Communications Privacy Act that allows the government to intercept electronic communications without a warrant if the interception is necessary for national security purposes.

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The national security exemption is an exemption from the Freedom of Information Act that allows the government to withhold information from disclosure if the information would harm national security. This exemption is based on the principle that the government has a legitimate interest in protecting national security and that this interest outweighs the public's right to access information.

Multiple choice

Which of the following is a common type of cyberattack that involves tricking users into revealing sensitive information or installing malware?

  1. Phishing

  2. Malware

  3. DoS

  4. SQL Injection

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Phishing is a type of cyberattack that involves sending fraudulent emails or messages that appear to be from legitimate sources in order to trick users into revealing sensitive information or installing malware.

Multiple choice

What is the practice of using strong and unique passwords for different accounts called?

  1. Password Management

  2. Multi-factor Authentication

  3. Encryption

  4. Firewall Protection

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Password management involves creating strong and unique passwords for different accounts and using a password manager to securely store and manage them.

Multiple choice

Which of the following is a type of malware that encrypts files and demands a ransom payment to decrypt them?

  1. Virus

  2. Trojan

  3. Ransomware

  4. Spyware

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Ransomware is a type of malware that encrypts files on a victim's computer and demands a ransom payment in exchange for the decryption key.

Multiple choice

Which of the following is a type of security control that restricts access to certain resources based on user roles and permissions?

  1. Access Control

  2. Encryption

  3. Multi-factor Authentication

  4. Firewall Protection

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Access control is a type of security control that restricts access to certain resources based on user roles and permissions, ensuring that only authorized users can access sensitive data and systems.

Multiple choice

What is the practice of backing up important data and systems regularly to protect against data loss or corruption called?

  1. Data Backup

  2. Disaster Recovery

  3. Encryption

  4. Vulnerability Assessment

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Data backup involves regularly backing up important data and systems to protect against data loss or corruption, ensuring that data can be restored in the event of a disaster or system failure.

Multiple choice

Which of the following is a type of security control that monitors network traffic and identifies suspicious activity?

  1. Intrusion Detection System (IDS)

  2. Firewall

  3. Antivirus Software

  4. Vulnerability Assessment

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

An intrusion detection system (IDS) is a type of security control that monitors network traffic and identifies suspicious activity, such as unauthorized access attempts or malware infections.

Multiple choice

What is the practice of regularly reviewing and updating security policies and procedures to ensure they are effective and up-to-date called?

  1. Security Policy Management

  2. Risk Management

  3. Incident Response

  4. Vulnerability Assessment

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Security policy management involves regularly reviewing and updating security policies and procedures to ensure they are effective and up-to-date, addressing new threats and vulnerabilities.

Multiple choice

Which of the following is a type of security control that encrypts data in transit to protect it from eavesdropping?

  1. Encryption

  2. Firewall

  3. Multi-factor Authentication

  4. Vulnerability Assessment

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Encryption is a type of security control that encrypts data in transit to protect it from eavesdropping, ensuring that unauthorized parties cannot access sensitive information.

Multiple choice

Which of the following is a type of cyberattack that involves exploiting vulnerabilities in software or systems to gain unauthorized access?

  1. Malware

  2. Phishing

  3. SQL Injection

  4. DoS

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

SQL injection is a type of cyberattack that involves exploiting vulnerabilities in software or systems to gain unauthorized access by injecting malicious SQL code into a database.

Multiple choice

What is the practice of regularly monitoring security logs and alerts to identify and respond to security incidents called?

  1. Security Monitoring

  2. Risk Management

  3. Incident Response

  4. Vulnerability Assessment

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Security monitoring involves regularly monitoring security logs and alerts to identify and respond to security incidents, enabling organizations to detect and mitigate threats promptly.

Multiple choice

Which of the following is a type of cyberattack that involves flooding a target system with traffic to disrupt its services?

  1. Malware

  2. Phishing

  3. SQL Injection

  4. DoS

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

DoS (Denial of Service) is a type of cyberattack that involves flooding a target system with traffic to disrupt its services, making it unavailable to legitimate users.