Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

What is the role of secure storage in mobile app security?

  1. To protect sensitive data from unauthorized access

  2. To prevent data breaches

  3. To comply with data protection regulations

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Secure storage helps protect sensitive data from unauthorized access, prevents data breaches, and ensures compliance with data protection regulations.

Multiple choice

Which of the following is a common type of mobile app attack?

  1. Man-in-the-middle (MITM) attack

  2. Phishing attack

  3. Denial-of-service (DoS) attack

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Mobile apps can be targeted by various types of attacks, including man-in-the-middle (MITM) attacks, phishing attacks, and denial-of-service (DoS) attacks.

Multiple choice

What is the role of secure network communication in mobile app security?

  1. To protect data in transit

  2. To prevent eavesdropping and man-in-the-middle attacks

  3. To ensure data integrity and authenticity

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Secure network communication protects data in transit, prevents eavesdropping and man-in-the-middle attacks, and ensures data integrity and authenticity.

Multiple choice

Which of the following is a best practice for managing mobile app permissions?

  1. Request only the permissions necessary for the app's functionality

  2. Clearly explain to users why each permission is required

  3. Allow users to control which permissions the app has access to

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

To protect user privacy and prevent misuse of permissions, it's essential to request only necessary permissions, explain their purpose, and allow users to control them.

Multiple choice

What is the purpose of regular security updates for mobile apps?

  1. To fix security vulnerabilities

  2. To improve the app's performance

  3. To add new features and functionality

  4. To comply with app store policies

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Regular security updates are crucial for fixing security vulnerabilities, preventing attacks, and maintaining the app's security posture.

Multiple choice

Which of the following is a common type of mobile app security misconfiguration?

  1. Leaving debug mode enabled in production

  2. Using default or weak passwords

  3. Storing sensitive data in plaintext

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Common mobile app security misconfigurations include leaving debug mode enabled, using default or weak passwords, and storing sensitive data in plaintext.

Multiple choice

Which of the following is a common tool used for incident detection?

  1. Security Information and Event Management (SIEM) system

  2. Intrusion Detection System (IDS)

  3. Vulnerability Scanner

  4. Firewall

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A SIEM system is a common tool used for incident detection. It collects and analyzes logs from various sources to identify suspicious activity.

Multiple choice

Which of the following is a common type of cyber attack that targets critical infrastructure?

  1. Distributed Denial of Service (DDoS) attack

  2. Man-in-the-Middle (MitM) attack

  3. Phishing attack

  4. SQL injection attack

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

DDoS attacks are a common type of cyber attack that targets critical infrastructure. They involve flooding a target system with so much traffic that it becomes unavailable.

Multiple choice

Which of the following is a common type of cyber attack that targets financial institutions?

  1. Phishing attack

  2. SQL injection attack

  3. Cross-site scripting (XSS) attack

  4. Malware attack

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Phishing attacks are a common type of cyber attack that targets financial institutions. They involve sending fraudulent emails or text messages that appear to come from a legitimate source in order to trick victims into giving up their personal information.

Multiple choice

What is the role of a Security Operations Center (SOC) in incident response?

  1. To monitor the network for suspicious activity

  2. To investigate security incidents

  3. To respond to security incidents

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

The SOC is responsible for monitoring the network for suspicious activity, investigating security incidents, and responding to security incidents.

Multiple choice

Which of the following is a common type of cyber attack that targets healthcare organizations?

  1. Ransomware attack

  2. Malware attack

  3. Phishing attack

  4. SQL injection attack

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Ransomware attacks are a common type of cyber attack that targets healthcare organizations. They involve encrypting the victim's files and demanding a ransom payment in order to decrypt them.

Multiple choice

Which of the following is a common type of cyber attack that targets government agencies?

  1. Advanced Persistent Threat (APT) attack

  2. Malware attack

  3. Phishing attack

  4. SQL injection attack

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

APT attacks are a common type of cyber attack that targets government agencies. They involve a sophisticated and persistent attack campaign that is designed to steal sensitive information or disrupt operations.

Multiple choice

Which of the following is a common type of cyber incident that government agencies face?

  1. Malware attacks

  2. Phishing attacks

  3. DDoS attacks

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Government agencies face a variety of cyber incidents, including malware attacks, phishing attacks, DDoS attacks, and other types of cyber attacks.

Multiple choice

Which of the following is NOT a common type of data encryption used in cloud security?

  1. Symmetric Encryption

  2. Asymmetric Encryption

  3. Hashing

  4. Polyalphabetic Encryption

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Polyalphabetic Encryption is not a common type of data encryption used in cloud security. Symmetric Encryption, Asymmetric Encryption, and Hashing are more commonly used.

Multiple choice

Which of the following is NOT a common DLP technique used in cloud security?

  1. Data Masking

  2. Data Encryption

  3. Data Tokenization

  4. Data Watermarking

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Data Watermarking is not a common DLP technique used in cloud security. Data Masking, Data Encryption, and Data Tokenization are more commonly used.