Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

What is the term used to describe the unauthorized access to a mobile device or its data?

  1. Phishing

  2. Spoofing

  3. Jailbreaking

  4. Malware

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Jailbreaking refers to the unauthorized modification of a mobile device's operating system to remove restrictions imposed by the manufacturer.

Multiple choice

Which of the following is a common defense mechanism used to protect mobile devices from malicious software?

  1. Secure Boot

  2. Multi-Factor Authentication

  3. Application Sandboxing

  4. Data Encryption

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Application sandboxing is a security technique that isolates applications from each other and the operating system, preventing them from accessing sensitive data or performing unauthorized actions.

Multiple choice

Which of the following is a common research methodology used in mobile security?

  1. Vulnerability Analysis

  2. Penetration Testing

  3. Formal Verification

  4. User Experience Evaluation

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Vulnerability analysis involves identifying and assessing weaknesses in mobile systems that could be exploited by attackers.

Multiple choice

What is the term used to describe the unauthorized modification of a mobile device's operating system?

  1. Rooting

  2. Jailbreaking

  3. Spoofing

  4. Phishing

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Rooting refers to the process of gaining administrative privileges on an Android device, allowing users to modify the operating system and install unauthorized applications.

Multiple choice

Which of the following is NOT a common type of mobile security attack?

  1. Man-in-the-Middle Attack

  2. Denial-of-Service Attack

  3. Social Engineering Attack

  4. Buffer Overflow Attack

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Buffer overflow attacks are typically associated with desktop and server systems, not mobile devices.

Multiple choice

What is the term used to describe the process of securing mobile devices and data from unauthorized access?

  1. Mobile Hardening

  2. Mobile Encryption

  3. Mobile Authentication

  4. Mobile Device Management

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Mobile Device Management (MDM) involves the use of tools and technologies to manage and secure mobile devices within an organization.

Multiple choice

Which of the following is a common type of mobile security research?

  1. Malware Analysis

  2. Privacy Analysis

  3. Usability Analysis

  4. Performance Analysis

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Malware analysis involves studying malicious software targeting mobile devices to understand its behavior, capabilities, and potential impact.

Multiple choice

What is the term used to describe the unauthorized interception of data transmitted over a network?

  1. Eavesdropping

  2. Spoofing

  3. Phishing

  4. Man-in-the-Middle Attack

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Eavesdropping refers to the unauthorized interception of data transmitted over a network, typically using specialized tools or techniques.

Multiple choice

Which of the following is a common type of mobile security research?

  1. Risk Assessment

  2. Threat Modeling

  3. Security Evaluation

  4. Vulnerability Discovery

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Vulnerability discovery involves identifying and reporting vulnerabilities in mobile operating systems, applications, and devices.

Multiple choice

Which of the following is NOT a common type of mobile security research?

  1. Privacy Analysis

  2. Performance Analysis

  3. Usability Analysis

  4. Malware Analysis

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

Performance analysis is typically not considered a specific area of mobile security research, as it focuses on optimizing the performance of mobile systems rather than addressing security concerns.

Multiple choice

Which of the following is NOT a common type of human error that can lead to cybersecurity breaches?

  1. Phishing attacks

  2. Weak password management

  3. Social engineering attacks

  4. Regular software updates

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Regular software updates are not a human error but a recommended practice to maintain system security. Phishing attacks, weak password management, and social engineering attacks are common human errors that can lead to cybersecurity breaches.

Multiple choice

Which of the following is NOT a recommended best practice for creating strong passwords?

  1. Using a combination of uppercase and lowercase letters

  2. Including special characters and symbols

  3. Reusing the same password across multiple accounts

  4. Using a password manager to store and generate secure passwords

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Reusing the same password across multiple accounts is a poor security practice as it increases the risk of unauthorized access if one account is compromised.

Multiple choice

What is the term used to describe the act of tricking someone into revealing sensitive information or taking actions that compromise security?

  1. Phishing

  2. Malware

  3. Social engineering

  4. DDoS attack

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Social engineering is the act of manipulating people into divulging confidential information or performing actions that compromise security.

Multiple choice

Which of the following is NOT a common social engineering technique used by attackers?

  1. Pretending to be a legitimate authority figure

  2. Sending malicious links or attachments in emails

  3. Offering free gifts or rewards in exchange for personal information

  4. Installing security software on a victim's computer

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Installing security software on a victim's computer is not a common social engineering technique. Attackers typically use tactics that exploit human vulnerabilities and trust to gain access to sensitive information or systems.

Multiple choice

What is the recommended approach for handling suspicious emails or attachments?

  1. Open and read the email to determine its legitimacy

  2. Forward the email to the IT department for analysis

  3. Click on links or attachments without verifying their authenticity

  4. Delete the email without opening it

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

The safest approach is to delete suspicious emails without opening them, especially if they come from unknown senders or contain unexpected attachments.