Computer Knowledge ยท General Awareness
Information Security
4,634 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
What is the term used to describe the unauthorized use of a computer or network to launch attacks against other systems?
-
Botnet
-
Malware
-
Phishing
-
Spam
A
Correct answer
Explanation
A botnet is a network of compromised computers that are controlled remotely by a single entity and used to launch attacks against other systems.
Which of the following is a common type of malware that encrypts files and demands a ransom payment to decrypt them?
-
Virus
-
Trojan horse
-
Ransomware
-
Worm
C
Correct answer
Explanation
Ransomware is a type of malware that encrypts files on a victim's computer and demands a ransom payment to decrypt them.
Which of the following is a common type of phishing attack that attempts to trick victims into revealing sensitive information by posing as a legitimate organization or individual?
-
Spear phishing
-
Whaling
-
Smishing
-
Vishing
A
Correct answer
Explanation
Spear phishing is a type of phishing attack that targets specific individuals or organizations with personalized emails or messages designed to trick them into revealing sensitive information.
What is the term used to describe the unauthorized access to a computer system or network by exploiting a vulnerability?
-
Hacking
-
Cracking
-
Exploit
-
Malware
A
Correct answer
Explanation
Hacking refers to the unauthorized access to a computer system or network by exploiting a vulnerability.
Which of the following is a common type of cyberattack that involves flooding a target system with excessive traffic to disrupt its normal operation?
-
Denial-of-service attack
-
Man-in-the-middle attack
-
SQL injection attack
-
Cross-site scripting attack
A
Correct answer
Explanation
A denial-of-service attack involves flooding a target system with excessive traffic to disrupt its normal operation.
Which of the following is a common type of cyberattack that involves injecting malicious code into a legitimate website or application?
-
Cross-site scripting attack
-
SQL injection attack
-
Buffer overflow attack
-
Man-in-the-middle attack
A
Correct answer
Explanation
A cross-site scripting attack involves injecting malicious code into a legitimate website or application.
What is the term used to describe the unauthorized interception and reading of private communications over a network?
-
Eavesdropping
-
Sniffing
-
Spoofing
-
Pharming
A
Correct answer
Explanation
Eavesdropping refers to the unauthorized interception and reading of private communications over a network.
What are some threats to the right to privacy?
-
Government surveillance.
-
Corporate data collection.
-
Identity theft.
-
All of the above.
D
Correct answer
Explanation
The right to privacy is threatened by government surveillance, corporate data collection, identity theft, and other factors.
What is the role of individuals in protecting their own privacy?
-
To be aware of their privacy rights.
-
To use strong passwords and security measures.
-
To be careful about what information they share online.
-
All of the above.
D
Correct answer
Explanation
Individuals have a role to play in protecting their own privacy by being aware of their privacy rights, using strong passwords and security measures, and being careful about what information they share online.
Which of the following is a common threat to SaaS applications?
-
Cross-site scripting (XSS)
-
SQL injection
-
Phishing
-
Denial-of-service (DoS) attack
Correct answer
Explanation
SaaS applications are vulnerable to a variety of threats, including XSS, SQL injection, phishing, and DoS attacks.
Which of the following is not a recommended practice for securing a blockchain network?
-
Using strong cryptography
-
Implementing access control mechanisms
-
Storing private keys on a centralized server
-
Regularly updating software and patching vulnerabilities
C
Correct answer
Explanation
Storing private keys on a centralized server is a security risk, as it creates a single point of failure that can be exploited by attackers.
Which of the following is a common type of blockchain attack?
-
51% attack
-
Sybil attack
-
Phishing attack
-
Man-in-the-middle attack
A
Correct answer
Explanation
A 51% attack is a type of blockchain attack in which an attacker gains control of more than 50% of the network's hashrate, allowing them to manipulate the blockchain.
How do engineers ensure the reliability and security of telecommunications networks?
-
Implementing robust network architectures
-
Employing encryption and other security measures
-
Performing regular maintenance and upgrades
-
All of the above
D
Correct answer
Explanation
Engineers ensure the reliability and security of telecommunications networks by implementing robust network architectures, employing encryption and other security measures, and performing regular maintenance and upgrades.
Which of the following is NOT a common type of security technology used at concerts?
-
Facial recognition systems
-
Surveillance cameras
-
Metal detectors
-
Turnstiles
D
Correct answer
Explanation
Turnstiles are not typically considered a type of security technology used at concerts. Metal detectors, surveillance cameras, and facial recognition systems are more common.
What are some of the trends in inmate classification and security levels?
-
A move towards more evidence-based classification systems.
-
An increase in the use of technology to assess inmate risk.
-
A focus on providing more treatment and rehabilitation opportunities for inmates.
-
All of the above.
D
Correct answer
Explanation
All of the above trends are occurring in inmate classification and security levels.