Computer Knowledge ยท General Awareness

Information Security

4,634 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

What is the significance of regular security updates for mobile devices?

  1. To improve the device's performance

  2. To fix bugs and glitches in the operating system

  3. To add new features and functionalities

  4. To patch security vulnerabilities

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Regular security updates are crucial for patching security vulnerabilities and protecting the device from potential threats.

Multiple choice

Which of the following is a recommended practice for securing mobile devices when connecting to public Wi-Fi networks?

  1. Use a virtual private network (VPN)

  2. Disable the device's firewall

  3. Connect to unsecured networks without a password

  4. Share personal information over public Wi-Fi

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Using a VPN encrypts internet traffic, providing an added layer of security when connecting to public Wi-Fi networks.

Multiple choice

Which of the following is a recommended practice for securing mobile devices against physical theft?

  1. Leave the device unattended in public places

  2. Use a weak lock screen password

  3. Enable remote wipe capabilities

  4. Keep the device in a secure location

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Keeping the device in a secure location, such as a locked bag or pocket, helps prevent physical theft.

Multiple choice

Which of the following is a recommended practice for securing mobile devices against unauthorized access?

  1. Use a strong password or passphrase

  2. Disable the device's lock screen

  3. Allow installation of apps from unknown sources

  4. Connect to public Wi-Fi networks without a VPN

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Using a strong password or passphrase adds an extra layer of security to prevent unauthorized access to the device.

Multiple choice

Which of the following is a recommended practice for securing mobile devices against phishing attacks?

  1. Click on suspicious links in emails or text messages

  2. Provide personal information on unverified websites

  3. Enable two-factor authentication for online accounts

  4. Install apps from unknown sources

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Enabling two-factor authentication adds an extra layer of security to online accounts, making it more difficult for attackers to gain access.

Multiple choice

Which of the following is NOT a key phase in the Incident Response lifecycle?

  1. Preparation and Prevention

  2. Detection and Analysis

  3. Containment and Eradication

  4. Recovery and Lessons Learned

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Preparation and Prevention is not a phase in the Incident Response lifecycle. It is a proactive approach to minimize the risk of incidents and improve the organization's ability to respond effectively.

Multiple choice

Which framework provides a comprehensive approach to Incident Response and Disaster Recovery?

  1. NIST Cybersecurity Framework

  2. ISO 27001/27002

  3. PCI DSS

  4. HIPAA

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The NIST Cybersecurity Framework is a comprehensive framework that provides guidance on how to manage cybersecurity risks, including Incident Response and Disaster Recovery.

Multiple choice

Which of the following is a common type of cyber attack that involves encrypting files and demanding a ransom?

  1. Phishing

  2. Malware

  3. Ransomware

  4. DDoS

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Ransomware is a type of malware that encrypts files and demands a ransom payment to decrypt them.

Multiple choice

Which of the following is a key component of a Disaster Recovery Plan?

  1. Incident Response Plan

  2. Business Impact Analysis

  3. Data Backup and Recovery Plan

  4. Employee Training

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

A Data Backup and Recovery Plan is a key component of a Disaster Recovery Plan as it outlines the procedures for backing up and recovering data in the event of a disaster.

Multiple choice

Which of the following is a common type of security control used to prevent unauthorized access to systems and data?

  1. Firewall

  2. Intrusion Detection System

  3. Antivirus Software

  4. Multi-Factor Authentication

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Multi-Factor Authentication is a common type of security control used to prevent unauthorized access to systems and data by requiring multiple forms of authentication.

Multiple choice

Which of the following is a key component of an Incident Response Plan?

  1. Communication Plan

  2. Roles and Responsibilities

  3. Incident Handling Procedures

  4. Post-Incident Review

Reveal answer Fill a bubble to check yourself
Correct answer
Explanation

All of the above options are key components of an Incident Response Plan.

Multiple choice

Which of the following is a common type of cyber attack that involves exploiting vulnerabilities in software to gain unauthorized access to systems?

  1. Phishing

  2. Malware

  3. Ransomware

  4. Zero-Day Exploit

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Zero-Day Exploit is a type of cyber attack that involves exploiting vulnerabilities in software that are not yet known to the vendor or the public.

Multiple choice

Which of the following is NOT a type of national security law?

  1. Anti-terrorism laws

  2. Espionage laws

  3. Immigration laws

  4. Cybersecurity laws

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Immigration laws are not typically considered to be national security laws, although they can be used to address national security concerns, such as preventing terrorists from entering the country.

Multiple choice

Which of the following is NOT a type of national security threat?

  1. Terrorism

  2. Espionage

  3. Cybersecurity

  4. Climate change

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Climate change is not typically considered to be a national security threat, although it can have a negative impact on national security by causing instability and conflict.

Multiple choice

Which of the following is NOT a type of national security risk?

  1. Terrorism

  2. Espionage

  3. Cybersecurity

  4. Economic instability

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Economic instability is not typically considered to be a national security risk, although it can have a negative impact on national security by causing instability and conflict.