Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is NOT a common type of cyber threat actor?

  1. Hackers

  2. Cybercriminals

  3. Nation-States

  4. Employees

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Employees are not typically considered a type of cyber threat actor, as they are not typically motivated by malicious intent.

Multiple choice

Which of the following is NOT a common type of security control?

  1. Access Control

  2. Encryption

  3. Firewalls

  4. Software Updates

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Software updates are not considered a type of security control, as they are intended to improve the functionality and security of a system, rather than specifically protect against security threats.

Multiple choice

Which of the following is NOT a common type of security incident?

  1. Malware Infection

  2. Phishing Attack

  3. Denial of Service Attack

  4. System Update

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

System updates are not considered security incidents as they are intended to improve the security and functionality of a system.

Multiple choice

What is the term for a type of attack that involves sending a large number of requests to a website or online service in order to overwhelm it and make it unavailable?

  1. Buffer Overflow

  2. Cross-Site Scripting

  3. Denial of Service

  4. SQL Injection

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

A denial of service (DoS) attack is a type of attack that involves sending a large number of requests to a website or online service in order to overwhelm it and make it unavailable.

Multiple choice

Which of the following is a common type of cloud security attack?

  1. Distributed denial-of-service (DDoS) attack

  2. Phishing attack

  3. Malware attack

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

All of the options are common types of cloud security attacks. DDoS attacks attempt to overwhelm a cloud service with traffic, phishing attacks attempt to trick users into giving up their credentials, and malware attacks attempt to infect cloud systems with malicious software. These attacks can result in data breaches, service disruptions, and financial losses.

Multiple choice

How can security and privacy concerns in mobile cloud AI be addressed?

  1. Implementing robust encryption and authentication mechanisms

  2. Regularly updating software and security patches

  3. Educating users about safe practices and potential risks

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Addressing security and privacy concerns in mobile cloud AI requires a combination of measures, including implementing robust encryption and authentication mechanisms, regularly updating software and security patches, educating users about safe practices and potential risks, and adhering to industry standards and regulations.

Multiple choice

Which of the following is NOT a common type of data that can be recovered from a mobile device?

  1. Text messages

  2. Call logs

  3. Web browsing history

  4. Social media activity

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Social media activity is not typically stored on a mobile device in a way that can be easily recovered.

Multiple choice

Which of the following is NOT a common tool used for mobile device forensics?

  1. Cellebrite UFED

  2. XRY

  3. Oxygen Forensic Suite

  4. Wireshark

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Wireshark is a network protocol analyzer and is not typically used for mobile device forensics.

Multiple choice

Which of the following is NOT a common challenge in mobile device forensics?

  1. Data encryption

  2. Data deletion

  3. Data fragmentation

  4. Data recovery

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Data recovery is not typically a challenge in mobile device forensics, as data can be easily recovered from most mobile devices.

Multiple choice

Which of the following is NOT a common type of data that can be recovered from a mobile device?

  1. Text messages

  2. Call logs

  3. Web browsing history

  4. Social media activity

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Social media activity is not typically stored on a mobile device in a way that can be easily recovered.

Multiple choice

Which of the following is NOT a common tool used for mobile device forensics?

  1. Cellebrite UFED

  2. XRY

  3. Oxygen Forensic Suite

  4. Wireshark

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Wireshark is a network protocol analyzer and is not typically used for mobile device forensics.

Multiple choice

What is the main concern associated with phishing attacks in DeFi platforms?

  1. Loss of private keys

  2. Unauthorized access to funds

  3. Malware infection

  4. Identity theft

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Phishing attacks aim to trick users into revealing their private keys or other sensitive information, which can lead to unauthorized access to their funds and loss of assets.

Multiple choice

Which of the following is NOT a common type of cyber incident?

  1. Malware infection

  2. Phishing attack

  3. Denial-of-service attack

  4. Insider threat

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Insider threat is not a common type of cyber incident. Insider threats are typically malicious activities carried out by individuals within an organization who have authorized access to its systems and data.

Multiple choice

Which of the following is NOT a common type of evidence collected during an incident investigation?

  1. Log files

  2. Network traffic captures

  3. Malware samples

  4. Employee interviews

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Employee interviews are not a common type of evidence collected during an incident investigation. Employee interviews may be conducted to gather information about the incident, but they are not typically considered to be evidence.

Multiple choice

Which of the following is NOT a common type of cyber attack?

  1. Phishing

  2. Malware

  3. DDoS

  4. Insider threat

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Insider threat is not a common type of cyber attack. Insider threats are typically malicious activities carried out by individuals within an organization who have authorized access to its systems and data.