Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
What is the term for a type of cyberattack that involves flooding a target with traffic to disrupt its services?
-
Phishing
-
Malware
-
DDoS
-
Social engineering
C
Correct answer
Explanation
DDoS (Distributed Denial of Service) is a type of cyberattack that involves flooding a target with traffic to disrupt its services.
Which of the following is NOT a good practice for protecting your devices from unauthorized access?
-
Using strong passwords
-
Enabling two-factor authentication
-
Leaving your devices unlocked when you're not using them
-
Using a VPN when connecting to public Wi-Fi networks
C
Correct answer
Explanation
Leaving your devices unlocked when you're not using them is not a good practice for protecting them from unauthorized access.
What is the term for a type of cyberattack that involves tricking people into revealing sensitive information by posing as a legitimate organization or individual?
-
Phishing
-
Malware
-
DDoS
-
Social engineering
D
Correct answer
Explanation
Social engineering is a type of cyberattack that involves tricking people into revealing sensitive information by posing as a legitimate organization or individual.
What is the term for a type of cyberattack that involves exploiting a vulnerability in software to gain unauthorized access to a system?
-
Phishing
-
Malware
-
Exploit
-
Social engineering
C
Correct answer
Explanation
An exploit is a type of cyberattack that involves exploiting a vulnerability in software to gain unauthorized access to a system.
Which of the following is NOT a good practice for protecting your devices from physical theft?
-
Using a strong lock and chain to secure your laptop
-
Keeping your devices in a safe place when you're not using them
-
Leaving your devices unattended in public places
-
Using a tracking device to locate your devices if they're lost or stolen
C
Correct answer
Explanation
Leaving your devices unattended in public places is not a good practice for protecting them from physical theft.
Which of the following is a significant cybersecurity risk associated with electronic voting?
-
Malware attacks on voting machines
-
Unauthorized access to voter data
-
Manipulation of election results
-
All of the above
D
Correct answer
Explanation
Electronic voting systems are vulnerable to a range of cybersecurity threats, including malware attacks, unauthorized access to voter data, and manipulation of election results.
Which of the following is NOT a common approach to addressing privacy concerns in ubiquitous computing?
-
Implementing strong encryption and security measures
-
Providing users with clear and transparent privacy policies
-
Allowing users to control and manage their own data
-
Collecting and storing as much data as possible to improve the user experience
D
Correct answer
Explanation
Collecting and storing excessive amounts of data without user consent is not a privacy-friendly approach and can lead to privacy risks.
What is a digital signature?
-
A mathematical scheme that allows a person to verify the authenticity of a message or document
-
A mathematical scheme that allows a person to encrypt a message or document
-
A mathematical scheme that allows a person to decrypt a message or document
-
None of the above
A
Correct answer
Explanation
A digital signature is a mathematical scheme that allows a person to verify the authenticity of a message or document. Digital signatures are used in blockchain technology to verify the authenticity of transactions.
Which international standard provides a comprehensive framework for cybersecurity compliance?
-
ISO 27001
-
ISO 27002
-
NIST Cybersecurity Framework
-
GDPR
A
Correct answer
Explanation
ISO 27001 is an international standard that provides a comprehensive framework for cybersecurity compliance. It specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
How does a comprehensive cybersecurity compliance framework contribute to compliance in emerging technologies?
-
By providing a structured approach to managing cybersecurity risks
-
By establishing clear roles and responsibilities for cybersecurity compliance
-
By facilitating continuous monitoring and improvement of cybersecurity practices
-
All of the above
D
Correct answer
Explanation
A comprehensive cybersecurity compliance framework provides a structured approach to managing cybersecurity risks, establishes clear roles and responsibilities for cybersecurity compliance, and facilitates continuous monitoring and improvement of cybersecurity practices, thus contributing to compliance in emerging technologies.
Which of the following is a key element of the NIST Cybersecurity Framework?
-
Identify
-
Protect
-
Detect
-
Respond
-
Recover
Correct answer
Explanation
The NIST Cybersecurity Framework consists of five key elements: Identify, Protect, Detect, Respond, and Recover. These elements provide a comprehensive approach to managing cybersecurity risks and ensuring compliance.
Which international standard provides a framework for managing information security?
-
ISO 27001
-
NIST 800-53
-
PCI DSS
-
HIPAA
A
Correct answer
Explanation
ISO 27001 is an international standard that provides a framework for managing information security. It includes requirements for establishing and maintaining an information security management system (ISMS).
Which international standard provides a framework for managing cybersecurity risks?
-
ISO 27005
-
NIST 800-30
-
PCI DSS
-
HIPAA
A
Correct answer
Explanation
ISO 27005 is an international standard that provides a framework for managing cybersecurity risks. It includes requirements for identifying, assessing, and mitigating cybersecurity risks.
Which U.S. federal law requires organizations to protect the privacy of financial information?
-
PCI DSS
-
HIPAA
-
NIST 800-53
-
ISO 27001
A
Correct answer
Explanation
The Payment Card Industry Data Security Standard (PCI DSS) requires organizations to protect the privacy of financial information. It includes requirements for implementing security measures to protect financial information from unauthorized access, use, or disclosure.
Which U.S. federal law requires organizations to protect the privacy of personal information?
-
NIST 800-53
-
PCI DSS
-
HIPAA
-
ISO 27001
A
Correct answer
Explanation
The National Institute of Standards and Technology (NIST) Special Publication 800-53 provides a framework for protecting the privacy of personal information. It includes requirements for implementing security measures to protect personal information from unauthorized access, use, or disclosure.