Computer Knowledge ยท General Awareness

Information Security

4,634 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is NOT a common type of mobile malware?

  1. Virus

  2. Trojan

  3. Worm

  4. Ransomware

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Ransomware is a type of malware that is typically used to target computers, not mobile devices.

Multiple choice

What is the purpose of a mobile application firewall (MAFW)?

  1. To block malicious traffic from reaching the application

  2. To improve the performance of the application

  3. To reduce the size of the application

  4. To make the application more user-friendly

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A mobile application firewall is a security solution that is designed to block malicious traffic from reaching the application.

Multiple choice

Which of the following is NOT a best practice for mobile application security testing?

  1. Use a variety of testing tools and techniques

  2. Test the application on multiple devices and operating systems

  3. Only test the application on the latest version of the operating system

  4. Test the application for both known and unknown vulnerabilities

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Only testing the application on the latest version of the operating system is not a best practice, as it does not account for the fact that many users may be using older versions of the operating system.

Multiple choice

Which of the following is NOT a common type of mobile application security vulnerability?

  1. Buffer overflow

  2. Cross-site scripting (XSS)

  3. SQL injection

  4. Insecure storage of sensitive data

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Buffer overflow is a type of vulnerability that is typically found in desktop applications, not mobile applications.

Multiple choice

Which of the following is NOT a best practice for mobile application security awareness training?

  1. Provide training to all employees who use mobile devices

  2. Focus on the latest mobile security threats

  3. Only provide training to employees who have access to sensitive data

  4. Make training mandatory for all employees

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Only providing training to employees who have access to sensitive data is not a best practice, as all employees who use mobile devices should be aware of the latest mobile security threats.

Multiple choice

Which of the following is NOT a common type of mobile application security attack?

  1. Phishing

  2. Malware

  3. Man-in-the-middle attack

  4. Denial-of-service attack

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Denial-of-service attacks are typically used to target websites and servers, not mobile applications.

Multiple choice

Which of the following is NOT a key component of an incident response plan?

  1. Identification

  2. Containment

  3. Eradication

  4. Mitigation

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Mitigation is not a key component of an incident response plan. It is a component of a disaster recovery plan.

Multiple choice

Which of the following is NOT a common type of incident?

  1. Cybersecurity incident

  2. Natural disaster

  3. Human error

  4. Equipment failure

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Natural disasters are not a common type of incident. They are a type of disaster.

Multiple choice

Which of the following is NOT a common type of cybersecurity incident?

  1. Malware attack

  2. Phishing attack

  3. DDoS attack

  4. SQL injection attack

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

DDoS attacks are not a common type of cybersecurity incident. They are a type of cyberattack.

Multiple choice

What is the default encryption algorithm used by Cloud Storage?

  1. AES-256

  2. AES-128

  3. RSA-2048

  4. ECC-256

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Cloud Storage uses AES-256 as the default encryption algorithm for data at rest.

Multiple choice

Which type of cryptographic key is used to decrypt data encrypted with a public key?

  1. Public Key

  2. Private Key

  3. Symmetric Key

  4. Asymmetric Key

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

A private key is used to decrypt data encrypted with a public key. The private key is kept secret by the owner and is used to access and control the associated cryptocurrency or digital assets.

Multiple choice

Which of the following is NOT a key component of an incident response plan?

  1. Identification

  2. Containment

  3. Eradication

  4. Negotiation

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Negotiation is not a key component of an incident response plan. The key components are identification, containment, eradication, and recovery.

Multiple choice

What is the first step in responding to a cybersecurity incident?

  1. Identify the incident

  2. Contain the incident

  3. Eradicate the incident

  4. Recover from the incident

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The first step in responding to a cybersecurity incident is to identify the incident. This involves gathering information about the incident, such as the time and date of the incident, the source of the incident, and the impact of the incident.

Multiple choice

Which of the following is NOT a common method for containing a cybersecurity incident?

  1. Isolating the affected system

  2. Disabling user accounts

  3. Patching the affected system

  4. Changing passwords

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Patching the affected system is not a common method for containing a cybersecurity incident. The common methods for containing a cybersecurity incident are isolating the affected system, disabling user accounts, and changing passwords.

Multiple choice

What is the goal of eradicating a cybersecurity incident?

  1. To prevent the incident from spreading

  2. To restore the affected system to its normal state

  3. To collect evidence of the incident

  4. To identify the source of the incident

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The goal of eradicating a cybersecurity incident is to prevent the incident from spreading. This involves removing the malware or other malicious software from the affected system and closing any security holes that allowed the incident to occur.