Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is NOT a recommended practice for securing mobile devices?

  1. Using a strong password or biometric authentication

  2. Keeping software and apps up to date

  3. Connecting to public Wi-Fi networks without a VPN

  4. Installing security apps and anti-malware software

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Connecting to public Wi-Fi networks without a VPN can expose your device to eavesdropping and man-in-the-middle attacks. It is recommended to use a VPN to encrypt your internet traffic when using public Wi-Fi.

Multiple choice

Which of the following is NOT a common type of cyberattack that targets businesses and organizations?

  1. Phishing

  2. Ransomware

  3. Distributed denial-of-service (DDoS) attack

  4. Software update

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Software update is not a type of cyberattack. It is a recommended practice to keep software and systems up to date to address security vulnerabilities and improve overall system stability.

Multiple choice

What is the primary purpose of a firewall in cybersecurity?

  1. To block unauthorized access to a network

  2. To scan for and remove malware from a computer

  3. To encrypt data during transmission

  4. To provide secure remote access to a network

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The primary purpose of a firewall is to monitor and control incoming and outgoing network traffic, blocking unauthorized access and protecting the network from external threats.

Multiple choice

Which of the following is NOT a recommended practice for creating a secure password?

  1. Using a combination of uppercase and lowercase letters

  2. Including special characters and symbols

  3. Using a common word or phrase found in a dictionary

  4. Using a password manager to generate and store strong passwords

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Using a common word or phrase found in a dictionary is not a secure password practice as it can be easily guessed or cracked by attackers.

Multiple choice

What is the term used to describe the process of recovering data that has been encrypted or locked by ransomware?

  1. Decryption

  2. Encryption

  3. Malware removal

  4. System restore

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Decryption is the process of recovering data that has been encrypted or locked by ransomware by using a decryption key or algorithm.

Multiple choice

Which of the following is NOT a common type of phishing attack?

  1. Spear phishing

  2. Whaling

  3. Smishing

  4. Software update

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Software update is not a type of phishing attack. It is a recommended practice to keep software and systems up to date to address security vulnerabilities and improve overall system stability.

Multiple choice

Which of the following is NOT a common data security control implemented as part of Data Governance?

  1. Data encryption

  2. Data masking

  3. Data lineage tracking

  4. Multi-factor authentication

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Data lineage tracking, while important for Data Governance, is not typically considered a data security control. Data encryption, data masking, and multi-factor authentication are common security controls used to protect data.

Multiple choice

Which regulation requires organizations to implement appropriate security measures to protect personal data?

  1. GDPR

  2. HIPAA

  3. PCI DSS

  4. SOX

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The General Data Protection Regulation (GDPR) is a European Union regulation that requires organizations to implement appropriate security measures to protect personal data.

Multiple choice

Which of the following is NOT a key component of the NIST Cybersecurity Framework?

  1. Identify

  2. Protect

  3. Detect

  4. Respond

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

The NIST Cybersecurity Framework consists of five key components: Identify, Protect, Detect, Respond, and Recover.

Multiple choice

Which of the following is NOT a key component of the HIPAA Security Rule?

  1. Administrative safeguards

  2. Physical safeguards

  3. Technical safeguards

  4. Organizational safeguards

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

The HIPAA Security Rule consists of three key components: Administrative safeguards, Physical safeguards, and Technical safeguards.

Multiple choice

Which of the following is NOT a key component of the PCI DSS?

  1. Build and maintain a secure network

  2. Protect cardholder data

  3. Maintain a vulnerability management program

  4. Implement strong access control measures

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

The PCI DSS consists of six key components: Build and maintain a secure network, Protect cardholder data, Maintain a vulnerability management program, Implement strong authentication measures, Regularly test security systems and processes, and Maintain an information security policy.

Multiple choice

Which of the following is NOT a key component of the FISMA?

  1. Information security management system

  2. Risk assessment

  3. Incident response

  4. Business continuity

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

The FISMA consists of three key components: Information security management system, Risk assessment, and Incident response.

Multiple choice

What is the primary goal of social engineering attacks?

  1. To gain unauthorized access to sensitive information

  2. To disrupt or disable computer systems

  3. To steal physical assets

  4. To cause physical harm to individuals

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Social engineering attacks aim to manipulate individuals into divulging confidential information or performing actions that compromise security, leading to unauthorized access to sensitive data.

Multiple choice

Which of the following is a common social engineering technique?

  1. Phishing

  2. Malware

  3. DDoS attacks

  4. SQL injection

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Phishing is a social engineering technique that involves sending fraudulent emails or creating fake websites to trick individuals into providing personal information or clicking malicious links.

Multiple choice

What is the primary defense against social engineering attacks?

  1. Strong passwords

  2. Firewalls

  3. Anti-virus software

  4. User education and awareness

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Educating users about social engineering techniques and raising awareness of potential threats is the most effective defense against these attacks, as it empowers individuals to recognize and resist manipulation attempts.