Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
Which of the following is NOT a common type of cyber threat actor?
-
Hackers
-
Cybercriminals
-
Nation-States
-
Employees
D
Correct answer
Explanation
Employees are not typically considered a type of cyber threat actor, as they are not typically motivated by malicious intent.
Which of the following is NOT a common type of security control?
-
Access Control
-
Encryption
-
Firewalls
-
Software Updates
D
Correct answer
Explanation
Software updates are not considered a type of security control, as they are intended to improve the functionality and security of a system, rather than specifically protect against security threats.
Which of the following is NOT a common type of security incident?
-
Malware Infection
-
Phishing Attack
-
Denial of Service Attack
-
System Update
D
Correct answer
Explanation
System updates are not considered security incidents as they are intended to improve the security and functionality of a system.
What is the term for a type of attack that involves sending a large number of requests to a website or online service in order to overwhelm it and make it unavailable?
-
Buffer Overflow
-
Cross-Site Scripting
-
Denial of Service
-
SQL Injection
C
Correct answer
Explanation
A denial of service (DoS) attack is a type of attack that involves sending a large number of requests to a website or online service in order to overwhelm it and make it unavailable.
Which of the following is a common type of cloud security attack?
-
Distributed denial-of-service (DDoS) attack
-
Phishing attack
-
Malware attack
-
All of the above
D
Correct answer
Explanation
All of the options are common types of cloud security attacks. DDoS attacks attempt to overwhelm a cloud service with traffic, phishing attacks attempt to trick users into giving up their credentials, and malware attacks attempt to infect cloud systems with malicious software. These attacks can result in data breaches, service disruptions, and financial losses.
How can security and privacy concerns in mobile cloud AI be addressed?
-
Implementing robust encryption and authentication mechanisms
-
Regularly updating software and security patches
-
Educating users about safe practices and potential risks
-
All of the above
D
Correct answer
Explanation
Addressing security and privacy concerns in mobile cloud AI requires a combination of measures, including implementing robust encryption and authentication mechanisms, regularly updating software and security patches, educating users about safe practices and potential risks, and adhering to industry standards and regulations.
Which of the following is NOT a common type of data that can be recovered from a mobile device?
-
Text messages
-
Call logs
-
Web browsing history
-
Social media activity
D
Correct answer
Explanation
Social media activity is not typically stored on a mobile device in a way that can be easily recovered.
Which of the following is NOT a common tool used for mobile device forensics?
-
Cellebrite UFED
-
XRY
-
Oxygen Forensic Suite
-
Wireshark
D
Correct answer
Explanation
Wireshark is a network protocol analyzer and is not typically used for mobile device forensics.
Which of the following is NOT a common challenge in mobile device forensics?
-
Data encryption
-
Data deletion
-
Data fragmentation
-
Data recovery
D
Correct answer
Explanation
Data recovery is not typically a challenge in mobile device forensics, as data can be easily recovered from most mobile devices.
Which of the following is NOT a common type of data that can be recovered from a mobile device?
-
Text messages
-
Call logs
-
Web browsing history
-
Social media activity
D
Correct answer
Explanation
Social media activity is not typically stored on a mobile device in a way that can be easily recovered.
Which of the following is NOT a common tool used for mobile device forensics?
-
Cellebrite UFED
-
XRY
-
Oxygen Forensic Suite
-
Wireshark
D
Correct answer
Explanation
Wireshark is a network protocol analyzer and is not typically used for mobile device forensics.
What is the main concern associated with phishing attacks in DeFi platforms?
-
Loss of private keys
-
Unauthorized access to funds
-
Malware infection
-
Identity theft
B
Correct answer
Explanation
Phishing attacks aim to trick users into revealing their private keys or other sensitive information, which can lead to unauthorized access to their funds and loss of assets.
Which of the following is NOT a common type of cyber incident?
-
Malware infection
-
Phishing attack
-
Denial-of-service attack
-
Insider threat
D
Correct answer
Explanation
Insider threat is not a common type of cyber incident. Insider threats are typically malicious activities carried out by individuals within an organization who have authorized access to its systems and data.
Which of the following is NOT a common type of evidence collected during an incident investigation?
-
Log files
-
Network traffic captures
-
Malware samples
-
Employee interviews
D
Correct answer
Explanation
Employee interviews are not a common type of evidence collected during an incident investigation. Employee interviews may be conducted to gather information about the incident, but they are not typically considered to be evidence.
Which of the following is NOT a common type of cyber attack?
-
Phishing
-
Malware
-
DDoS
-
Insider threat
D
Correct answer
Explanation
Insider threat is not a common type of cyber attack. Insider threats are typically malicious activities carried out by individuals within an organization who have authorized access to its systems and data.