Computer Knowledge ยท General Awareness

Information Security

4,634 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

What is the term for a DDoS attack that targets a specific application or service by exploiting vulnerabilities in the application code?

  1. Application-layer DDoS attack

  2. Protocol-layer DDoS attack

  3. Network-layer DDoS attack

  4. Transport-layer DDoS attack

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

An application-layer DDoS attack targets a specific application or service by exploiting vulnerabilities in the application code. This type of attack can cause the application to crash or become unavailable.

Multiple choice

Which of the following is NOT a common defense mechanism against DDoS attacks at the application layer?

  1. Using a web application firewall (WAF)

  2. Implementing input validation

  3. Using a content delivery network (CDN)

  4. Blacklisting malicious IP addresses

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Blacklisting malicious IP addresses is not a common defense mechanism against DDoS attacks at the application layer. Blacklisting is typically used to prevent access to specific IP addresses at the network layer.

Multiple choice

What is the term for a DDoS attack that uses a large number of compromised devices to launch the attack?

  1. Botnet DDoS attack

  2. SYN flood attack

  3. UDP flood attack

  4. HTTP flood attack

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A botnet DDoS attack uses a large number of compromised devices, known as bots, to launch a DDoS attack. These bots are controlled by a central command and control server and can be used to generate a large amount of traffic to overwhelm the target.

Multiple choice

Which of the following is NOT a common target of cyberterrorism?

  1. Government agencies

  2. Financial institutions

  3. Critical infrastructure

  4. Private individuals

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

While private individuals can be victims of cybercrime, they are not typically the target of cyberterrorism, which is focused on causing harm or disruption to governments, businesses, and other organizations.

Multiple choice

What is the term used to describe a type of cyberattack that involves taking control of a computer system and holding it for ransom?

  1. Phishing

  2. Malware

  3. Ransomware

  4. DDoS attack

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Ransomware is a type of cyberattack that involves taking control of a computer system and holding it for ransom, typically demanding payment in the form of cryptocurrency.

Multiple choice

Which of the following is NOT a common method used by cyberterrorists to carry out attacks?

  1. Hacking

  2. Phishing

  3. Social engineering

  4. Physical attacks

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

While cyberterrorists may use physical attacks as part of their operations, such as planting explosives or carrying out assassinations, these are not typically considered to be common methods of cyberterrorism.

Multiple choice

What is the term used to describe a type of cyberattack that involves flooding a website or server with traffic in order to make it inaccessible?

  1. Phishing

  2. Malware

  3. DDoS attack

  4. Ransomware

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

A DDoS attack (Distributed Denial of Service attack) involves flooding a website or server with traffic from multiple sources in order to make it inaccessible to legitimate users.

Multiple choice

Which of the following is NOT a potential consequence of cyberterrorism?

  1. Economic losses

  2. Loss of life

  3. Disruption of critical infrastructure

  4. Increased public awareness of cybersecurity risks

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

While cyberterrorism can lead to increased public awareness of cybersecurity risks, this is not typically considered to be a negative consequence.

Multiple choice

Which of the following is NOT a recommended measure for mitigating the risks of cyberterrorism?

  1. Implementing strong cybersecurity measures

  2. Educating the public about cybersecurity risks

  3. Developing international agreements on cybercrime

  4. Reducing the use of technology

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Reducing the use of technology is not a recommended measure for mitigating the risks of cyberterrorism, as technology is essential for modern society and the global economy.

Multiple choice

What is the term used to describe the use of cyberattacks to target and disrupt critical infrastructure, such as power grids, water systems, and transportation networks?

  1. Cyberwarfare

  2. Cyberterrorism

  3. Cybercrime

  4. Cyberespionage

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Cyberwarfare involves the use of cyberattacks to target and disrupt critical infrastructure, with the intent of causing widespread harm and disruption.

Multiple choice

Which of the following is NOT a common motivation for cyberterrorism?

  1. Political extremism

  2. Financial gain

  3. Personal revenge

  4. National security

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

National security is not typically a motivation for cyberterrorism, as cyberattacks are more commonly carried out by non-state actors with political or financial motivations.

Multiple choice

What is the term used to describe the use of cyberattacks to steal sensitive information, such as trade secrets, financial data, or personal information?

  1. Cyberwarfare

  2. Cyberterrorism

  3. Cybercrime

  4. Cyberespionage

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Cyberespionage involves the use of cyberattacks to steal sensitive information, such as trade secrets, financial data, or personal information, for economic or political advantage.

Multiple choice

Which of the following is NOT a common target of cyberterrorism?

  1. Government agencies

  2. Financial institutions

  3. Critical infrastructure

  4. Small businesses

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Small businesses are not typically a common target of cyberterrorism, as they are less likely to have the resources and expertise to defend against sophisticated cyberattacks.

Multiple choice

What is the primary concern associated with data privacy?

  1. Unauthorized access to personal information

  2. Data breaches and cyberattacks

  3. Data manipulation and misuse

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Data privacy encompasses the protection of personal information from unauthorized access, data breaches, and manipulation or misuse.

Multiple choice

What are privacy-enhancing technologies, and how do they contribute to balancing data privacy and security with the need for open data?

  1. Technologies that minimize the collection and storage of personal data

  2. Technologies that enable secure data sharing and collaboration

  3. Technologies that allow individuals to control their data

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Privacy-enhancing technologies encompass a range of technologies that minimize data collection and storage, enable secure data sharing, and empower individuals to control their data.