Computer Knowledge ยท General Awareness
Information Security
4,634 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
Which of the following is NOT a common type of mobile malware?
-
Virus
-
Trojan
-
Worm
-
Ransomware
D
Correct answer
Explanation
Ransomware is a type of malware that is typically used to target computers, not mobile devices.
What is the purpose of a mobile application firewall (MAFW)?
-
To block malicious traffic from reaching the application
-
To improve the performance of the application
-
To reduce the size of the application
-
To make the application more user-friendly
A
Correct answer
Explanation
A mobile application firewall is a security solution that is designed to block malicious traffic from reaching the application.
Which of the following is NOT a best practice for mobile application security testing?
-
Use a variety of testing tools and techniques
-
Test the application on multiple devices and operating systems
-
Only test the application on the latest version of the operating system
-
Test the application for both known and unknown vulnerabilities
C
Correct answer
Explanation
Only testing the application on the latest version of the operating system is not a best practice, as it does not account for the fact that many users may be using older versions of the operating system.
Which of the following is NOT a common type of mobile application security vulnerability?
-
Buffer overflow
-
Cross-site scripting (XSS)
-
SQL injection
-
Insecure storage of sensitive data
A
Correct answer
Explanation
Buffer overflow is a type of vulnerability that is typically found in desktop applications, not mobile applications.
Which of the following is NOT a best practice for mobile application security awareness training?
-
Provide training to all employees who use mobile devices
-
Focus on the latest mobile security threats
-
Only provide training to employees who have access to sensitive data
-
Make training mandatory for all employees
C
Correct answer
Explanation
Only providing training to employees who have access to sensitive data is not a best practice, as all employees who use mobile devices should be aware of the latest mobile security threats.
Which of the following is NOT a common type of mobile application security attack?
-
Phishing
-
Malware
-
Man-in-the-middle attack
-
Denial-of-service attack
D
Correct answer
Explanation
Denial-of-service attacks are typically used to target websites and servers, not mobile applications.
Which of the following is NOT a key component of an incident response plan?
-
Identification
-
Containment
-
Eradication
-
Mitigation
D
Correct answer
Explanation
Mitigation is not a key component of an incident response plan. It is a component of a disaster recovery plan.
Which of the following is NOT a common type of incident?
-
Cybersecurity incident
-
Natural disaster
-
Human error
-
Equipment failure
B
Correct answer
Explanation
Natural disasters are not a common type of incident. They are a type of disaster.
Which of the following is NOT a common type of cybersecurity incident?
-
Malware attack
-
Phishing attack
-
DDoS attack
-
SQL injection attack
C
Correct answer
Explanation
DDoS attacks are not a common type of cybersecurity incident. They are a type of cyberattack.
What is the default encryption algorithm used by Cloud Storage?
-
AES-256
-
AES-128
-
RSA-2048
-
ECC-256
A
Correct answer
Explanation
Cloud Storage uses AES-256 as the default encryption algorithm for data at rest.
Which type of cryptographic key is used to decrypt data encrypted with a public key?
-
Public Key
-
Private Key
-
Symmetric Key
-
Asymmetric Key
B
Correct answer
Explanation
A private key is used to decrypt data encrypted with a public key. The private key is kept secret by the owner and is used to access and control the associated cryptocurrency or digital assets.
Which of the following is NOT a key component of an incident response plan?
-
Identification
-
Containment
-
Eradication
-
Negotiation
D
Correct answer
Explanation
Negotiation is not a key component of an incident response plan. The key components are identification, containment, eradication, and recovery.
What is the first step in responding to a cybersecurity incident?
-
Identify the incident
-
Contain the incident
-
Eradicate the incident
-
Recover from the incident
A
Correct answer
Explanation
The first step in responding to a cybersecurity incident is to identify the incident. This involves gathering information about the incident, such as the time and date of the incident, the source of the incident, and the impact of the incident.
Which of the following is NOT a common method for containing a cybersecurity incident?
-
Isolating the affected system
-
Disabling user accounts
-
Patching the affected system
-
Changing passwords
C
Correct answer
Explanation
Patching the affected system is not a common method for containing a cybersecurity incident. The common methods for containing a cybersecurity incident are isolating the affected system, disabling user accounts, and changing passwords.
What is the goal of eradicating a cybersecurity incident?
-
To prevent the incident from spreading
-
To restore the affected system to its normal state
-
To collect evidence of the incident
-
To identify the source of the incident
A
Correct answer
Explanation
The goal of eradicating a cybersecurity incident is to prevent the incident from spreading. This involves removing the malware or other malicious software from the affected system and closing any security holes that allowed the incident to occur.