Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

What is the term for a type of cyberattack that involves flooding a target with traffic to disrupt its services?

  1. Phishing

  2. Malware

  3. DDoS

  4. Social engineering

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

DDoS (Distributed Denial of Service) is a type of cyberattack that involves flooding a target with traffic to disrupt its services.

Multiple choice

Which of the following is NOT a good practice for protecting your devices from unauthorized access?

  1. Using strong passwords

  2. Enabling two-factor authentication

  3. Leaving your devices unlocked when you're not using them

  4. Using a VPN when connecting to public Wi-Fi networks

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Leaving your devices unlocked when you're not using them is not a good practice for protecting them from unauthorized access.

Multiple choice

What is the term for a type of cyberattack that involves tricking people into revealing sensitive information by posing as a legitimate organization or individual?

  1. Phishing

  2. Malware

  3. DDoS

  4. Social engineering

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Social engineering is a type of cyberattack that involves tricking people into revealing sensitive information by posing as a legitimate organization or individual.

Multiple choice

What is the term for a type of cyberattack that involves exploiting a vulnerability in software to gain unauthorized access to a system?

  1. Phishing

  2. Malware

  3. Exploit

  4. Social engineering

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

An exploit is a type of cyberattack that involves exploiting a vulnerability in software to gain unauthorized access to a system.

Multiple choice

Which of the following is NOT a good practice for protecting your devices from physical theft?

  1. Using a strong lock and chain to secure your laptop

  2. Keeping your devices in a safe place when you're not using them

  3. Leaving your devices unattended in public places

  4. Using a tracking device to locate your devices if they're lost or stolen

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Leaving your devices unattended in public places is not a good practice for protecting them from physical theft.

Multiple choice

Which of the following is a significant cybersecurity risk associated with electronic voting?

  1. Malware attacks on voting machines

  2. Unauthorized access to voter data

  3. Manipulation of election results

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Electronic voting systems are vulnerable to a range of cybersecurity threats, including malware attacks, unauthorized access to voter data, and manipulation of election results.

Multiple choice

Which of the following is NOT a common approach to addressing privacy concerns in ubiquitous computing?

  1. Implementing strong encryption and security measures

  2. Providing users with clear and transparent privacy policies

  3. Allowing users to control and manage their own data

  4. Collecting and storing as much data as possible to improve the user experience

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Collecting and storing excessive amounts of data without user consent is not a privacy-friendly approach and can lead to privacy risks.

Multiple choice

What is a digital signature?

  1. A mathematical scheme that allows a person to verify the authenticity of a message or document

  2. A mathematical scheme that allows a person to encrypt a message or document

  3. A mathematical scheme that allows a person to decrypt a message or document

  4. None of the above

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A digital signature is a mathematical scheme that allows a person to verify the authenticity of a message or document. Digital signatures are used in blockchain technology to verify the authenticity of transactions.

Multiple choice

Which international standard provides a comprehensive framework for cybersecurity compliance?

  1. ISO 27001

  2. ISO 27002

  3. NIST Cybersecurity Framework

  4. GDPR

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

ISO 27001 is an international standard that provides a comprehensive framework for cybersecurity compliance. It specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

Multiple choice

How does a comprehensive cybersecurity compliance framework contribute to compliance in emerging technologies?

  1. By providing a structured approach to managing cybersecurity risks

  2. By establishing clear roles and responsibilities for cybersecurity compliance

  3. By facilitating continuous monitoring and improvement of cybersecurity practices

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

A comprehensive cybersecurity compliance framework provides a structured approach to managing cybersecurity risks, establishes clear roles and responsibilities for cybersecurity compliance, and facilitates continuous monitoring and improvement of cybersecurity practices, thus contributing to compliance in emerging technologies.

Multiple choice

Which of the following is a key element of the NIST Cybersecurity Framework?

  1. Identify

  2. Protect

  3. Detect

  4. Respond

  5. Recover

Reveal answer Fill a bubble to check yourself
Correct answer
Explanation

The NIST Cybersecurity Framework consists of five key elements: Identify, Protect, Detect, Respond, and Recover. These elements provide a comprehensive approach to managing cybersecurity risks and ensuring compliance.

Multiple choice

Which international standard provides a framework for managing information security?

  1. ISO 27001

  2. NIST 800-53

  3. PCI DSS

  4. HIPAA

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

ISO 27001 is an international standard that provides a framework for managing information security. It includes requirements for establishing and maintaining an information security management system (ISMS).

Multiple choice

Which international standard provides a framework for managing cybersecurity risks?

  1. ISO 27005

  2. NIST 800-30

  3. PCI DSS

  4. HIPAA

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

ISO 27005 is an international standard that provides a framework for managing cybersecurity risks. It includes requirements for identifying, assessing, and mitigating cybersecurity risks.

Multiple choice

Which U.S. federal law requires organizations to protect the privacy of financial information?

  1. PCI DSS

  2. HIPAA

  3. NIST 800-53

  4. ISO 27001

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The Payment Card Industry Data Security Standard (PCI DSS) requires organizations to protect the privacy of financial information. It includes requirements for implementing security measures to protect financial information from unauthorized access, use, or disclosure.

Multiple choice

Which U.S. federal law requires organizations to protect the privacy of personal information?

  1. NIST 800-53

  2. PCI DSS

  3. HIPAA

  4. ISO 27001

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The National Institute of Standards and Technology (NIST) Special Publication 800-53 provides a framework for protecting the privacy of personal information. It includes requirements for implementing security measures to protect personal information from unauthorized access, use, or disclosure.