Computer Knowledge ยท General Awareness

Information Security

4,634 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

Which of the following is a common mitigation strategy to prevent Sybil attacks?

  1. Proof-of-Work

  2. Proof-of-Stake

  3. Byzantine Fault Tolerance

  4. Sharding

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Proof-of-Work is a common mitigation strategy to prevent Sybil attacks by requiring participants to solve complex mathematical puzzles to participate in the network.

Multiple choice

Which of the following is a common type of security control?

  1. Access control

  2. Encryption

  3. Firewalls

  4. Intrusion detection systems

Reveal answer Fill a bubble to check yourself
Correct answer
Explanation

Access control, encryption, firewalls, and intrusion detection systems are all examples of common security controls used to protect information systems and data.

Multiple choice

What is the principle of least privilege?

  1. Users should only have the minimum access necessary to perform their job duties.

  2. Users should have access to all information systems and data.

  3. Users should be able to access any information system or data they want.

  4. Users should have access to all information systems and data, but only during certain times.

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The principle of least privilege states that users should only have the minimum access necessary to perform their job duties, which helps to reduce the risk of unauthorized access to information systems and data.

Multiple choice

Which of the following is a common security standard?

  1. ISO 27001

  2. NIST 800-53

  3. PCI DSS

  4. HIPAA

Reveal answer Fill a bubble to check yourself
Correct answer
Explanation

ISO 27001, NIST 800-53, PCI DSS, and HIPAA are all examples of common security standards that organizations can use to implement security controls and protect information systems and data.

Multiple choice

Which of the following is a common security control used to protect against unauthorized access to information systems?

  1. Firewalls

  2. Intrusion detection systems

  3. Access control lists

  4. Multi-factor authentication

Reveal answer Fill a bubble to check yourself
Correct answer
Explanation

Firewalls, intrusion detection systems, access control lists, and multi-factor authentication are all examples of common security controls used to protect against unauthorized access to information systems.

Multiple choice

Which of the following is a common security control used to protect data in transit?

  1. Encryption

  2. Firewalls

  3. Intrusion detection systems

  4. Multi-factor authentication

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Encryption is a common security control used to protect data in transit by scrambling it so that it cannot be read by unauthorized individuals.

Multiple choice

Which of the following is a common security control used to protect against malware?

  1. Antivirus software

  2. Firewalls

  3. Intrusion detection systems

  4. Multi-factor authentication

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Antivirus software is a common security control used to protect against malware by detecting and removing malicious software from information systems.

Multiple choice

Which of the following is a common security control used to protect against phishing attacks?

  1. Anti-phishing software

  2. Firewalls

  3. Intrusion detection systems

  4. Multi-factor authentication

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Anti-phishing software is a common security control used to protect against phishing attacks by detecting and blocking phishing emails.

Multiple choice

Which of the following is a common security measure used in correctional facilities to prevent contraband from entering?

  1. Body scanners

  2. Metal detectors

  3. X-ray machines

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Body scanners, metal detectors, and X-ray machines are all common security measures used in correctional facilities to prevent contraband from entering.

Multiple choice

Which of the following is NOT a type of HIPAA security safeguard?

  1. Administrative safeguards

  2. Physical safeguards

  3. Technical safeguards

  4. Organizational safeguards

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Organizational safeguards are not a type of HIPAA security safeguard. The three types of HIPAA security safeguards are administrative, physical, and technical.

Multiple choice

What is the first step in responding to a security incident in healthcare?

  1. Identify and contain the incident

  2. Eradicate the threat

  3. Recover from the incident

  4. Conduct a risk assessment

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

The first step in responding to a security incident in healthcare is to identify and contain the incident to prevent further damage.

Multiple choice

Which of the following is NOT a common type of security incident in healthcare?

  1. Phishing attacks

  2. Ransomware attacks

  3. Data breaches

  4. Denial-of-service attacks

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Denial-of-service attacks are not as common in healthcare as phishing attacks, ransomware attacks, and data breaches.

Multiple choice

Which of the following is NOT a common type of data breach in healthcare?

  1. Phishing attacks

  2. Ransomware attacks

  3. Insider attacks

  4. Denial-of-service attacks

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Denial-of-service attacks are not a common type of data breach in healthcare.

Multiple choice

Which of the following is NOT a common type of security incident in healthcare?

  1. Phishing attacks

  2. Ransomware attacks

  3. Data breaches

  4. Denial-of-service attacks

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Denial-of-service attacks are not as common in healthcare as phishing attacks, ransomware attacks, and data breaches.

Multiple choice

Which of the following is a common type of supply chain disruption caused by cyberattacks?

  1. Denial of service (DoS) attacks

  2. Man-in-the-middle (MitM) attacks

  3. Malware infections

  4. Phishing attacks

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Malware infections can disrupt supply chain operations by compromising systems, stealing sensitive information, or causing operational disruptions.