Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
What is a side-channel attack?
-
A type of cyberattack that exploits the physical characteristics of a device
-
A type of cyberattack that steals data from a server
-
A type of cyberattack that takes control of a server
-
A type of cyberattack that deletes data from a server
A
Correct answer
Explanation
A side-channel attack is a type of cyberattack that exploits the physical characteristics of a device, such as its power consumption or electromagnetic emissions, to extract information from the device.
What is a zero-day attack?
-
A type of cyberattack that exploits a vulnerability that is not yet known to the vendor
-
A type of cyberattack that steals data from a server
-
A type of cyberattack that takes control of a server
-
A type of cyberattack that deletes data from a server
A
Correct answer
Explanation
A zero-day attack is a type of cyberattack that exploits a vulnerability that is not yet known to the vendor, allowing the attacker to take advantage of the vulnerability before it can be patched.
What is a buffer overflow attack?
-
A type of cyberattack that exploits a buffer overflow vulnerability
-
A type of cyberattack that steals data from a server
-
A type of cyberattack that takes control of a server
-
A type of cyberattack that deletes data from a server
A
Correct answer
Explanation
A buffer overflow attack is a type of cyberattack that exploits a buffer overflow vulnerability, allowing the attacker to execute arbitrary code on the device.
What is a SQL injection attack?
-
A type of cyberattack that exploits a SQL injection vulnerability
-
A type of cyberattack that steals data from a server
-
A type of cyberattack that takes control of a server
-
A type of cyberattack that deletes data from a server
A
Correct answer
Explanation
A SQL injection attack is a type of cyberattack that exploits a SQL injection vulnerability, allowing the attacker to execute arbitrary SQL queries on the database.
What is a cross-site scripting (XSS) attack?
-
A type of cyberattack that exploits a cross-site scripting vulnerability
-
A type of cyberattack that steals data from a server
-
A type of cyberattack that takes control of a server
-
A type of cyberattack that deletes data from a server
A
Correct answer
Explanation
A cross-site scripting (XSS) attack is a type of cyberattack that exploits a cross-site scripting vulnerability, allowing the attacker to inject malicious code into a web page.
What is a remote code execution (RCE) attack?
-
A type of cyberattack that allows the attacker to execute arbitrary code on the device
-
A type of cyberattack that steals data from a server
-
A type of cyberattack that takes control of a server
-
A type of cyberattack that deletes data from a server
A
Correct answer
Explanation
A remote code execution (RCE) attack is a type of cyberattack that allows the attacker to execute arbitrary code on the device.
What is a denial-of-service (DoS) attack?
-
A type of cyberattack that prevents the device from providing its services
-
A type of cyberattack that steals data from a server
-
A type of cyberattack that takes control of a server
-
A type of cyberattack that deletes data from a server
A
Correct answer
Explanation
A denial-of-service (DoS) attack is a type of cyberattack that prevents the device from providing its services.
What is a man-in-the-middle (MITM) attack?
-
A type of cyberattack that allows the attacker to intercept communications between two parties
-
A type of cyberattack that steals data from a server
-
A type of cyberattack that takes control of a server
-
A type of cyberattack that deletes data from a server
A
Correct answer
Explanation
A man-in-the-middle (MITM) attack is a type of cyberattack that allows the attacker to intercept communications between two parties.
What is a phishing attack?
-
A type of cyberattack that attempts to trick the user into giving up their personal information
-
A type of cyberattack that steals data from a server
-
A type of cyberattack that takes control of a server
-
A type of cyberattack that deletes data from a server
A
Correct answer
Explanation
A phishing attack is a type of cyberattack that attempts to trick the user into giving up their personal information, such as their password or credit card number.
What is a social engineering attack?
-
A type of cyberattack that exploits human psychology to trick the user into performing a desired action
-
A type of cyberattack that steals data from a server
-
A type of cyberattack that takes control of a server
-
A type of cyberattack that deletes data from a server
A
Correct answer
Explanation
A social engineering attack is a type of cyberattack that exploits human psychology to trick the user into performing a desired action, such as clicking on a malicious link or opening a malicious email attachment.
Which of the following is a common MDM strategy for securing mobile devices?
-
Implementing a Bring Your Own Device (BYOD) policy
-
Enforcing strong password policies
-
Enabling remote wipe capabilities
-
All of the above
D
Correct answer
Explanation
MDM strategies for securing mobile devices include implementing BYOD policies, enforcing strong passwords, enabling remote wipe capabilities, and more.
Which of the following is NOT a common MDM feature?
-
Remote device management
-
Application management
-
Data encryption
-
Device tracking
D
Correct answer
Explanation
Device tracking is typically not a common MDM feature, as it involves monitoring the physical location of devices, which may raise privacy concerns.
Which of the following is a common MDM security policy?
-
Requiring strong passwords
-
Enforcing device encryption
-
Restricting access to certain apps
-
All of the above
D
Correct answer
Explanation
Common MDM security policies include requiring strong passwords, enforcing device encryption, restricting access to certain apps, and more.
Which of the following is a common MAM security policy?
-
Requiring strong passwords
-
Enforcing application encryption
-
Restricting access to certain data
-
All of the above
D
Correct answer
Explanation
Common MAM security policies include requiring strong passwords, enforcing application encryption, restricting access to certain data, and more.
Which of the following is a common MDM compliance requirement?
-
Encryption of sensitive data
-
Strong password policies
-
Remote wipe capabilities
-
All of the above
D
Correct answer
Explanation
Common MDM compliance requirements include encryption of sensitive data, strong password policies, remote wipe capabilities, and more.