Computer Knowledge ยท General Awareness
Information Security
4,634 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
Which of the following is a common mitigation strategy to prevent Sybil attacks?
-
Proof-of-Work
-
Proof-of-Stake
-
Byzantine Fault Tolerance
-
Sharding
A
Correct answer
Explanation
Proof-of-Work is a common mitigation strategy to prevent Sybil attacks by requiring participants to solve complex mathematical puzzles to participate in the network.
Which of the following is a common type of security control?
-
Access control
-
Encryption
-
Firewalls
-
Intrusion detection systems
Correct answer
Explanation
Access control, encryption, firewalls, and intrusion detection systems are all examples of common security controls used to protect information systems and data.
What is the principle of least privilege?
-
Users should only have the minimum access necessary to perform their job duties.
-
Users should have access to all information systems and data.
-
Users should be able to access any information system or data they want.
-
Users should have access to all information systems and data, but only during certain times.
A
Correct answer
Explanation
The principle of least privilege states that users should only have the minimum access necessary to perform their job duties, which helps to reduce the risk of unauthorized access to information systems and data.
Which of the following is a common security standard?
-
ISO 27001
-
NIST 800-53
-
PCI DSS
-
HIPAA
Correct answer
Explanation
ISO 27001, NIST 800-53, PCI DSS, and HIPAA are all examples of common security standards that organizations can use to implement security controls and protect information systems and data.
Which of the following is a common security control used to protect against unauthorized access to information systems?
-
Firewalls
-
Intrusion detection systems
-
Access control lists
-
Multi-factor authentication
Correct answer
Explanation
Firewalls, intrusion detection systems, access control lists, and multi-factor authentication are all examples of common security controls used to protect against unauthorized access to information systems.
Which of the following is a common security control used to protect data in transit?
-
Encryption
-
Firewalls
-
Intrusion detection systems
-
Multi-factor authentication
A
Correct answer
Explanation
Encryption is a common security control used to protect data in transit by scrambling it so that it cannot be read by unauthorized individuals.
Which of the following is a common security control used to protect against malware?
-
Antivirus software
-
Firewalls
-
Intrusion detection systems
-
Multi-factor authentication
A
Correct answer
Explanation
Antivirus software is a common security control used to protect against malware by detecting and removing malicious software from information systems.
Which of the following is a common security control used to protect against phishing attacks?
-
Anti-phishing software
-
Firewalls
-
Intrusion detection systems
-
Multi-factor authentication
A
Correct answer
Explanation
Anti-phishing software is a common security control used to protect against phishing attacks by detecting and blocking phishing emails.
Which of the following is a common security measure used in correctional facilities to prevent contraband from entering?
-
Body scanners
-
Metal detectors
-
X-ray machines
-
All of the above
D
Correct answer
Explanation
Body scanners, metal detectors, and X-ray machines are all common security measures used in correctional facilities to prevent contraband from entering.
Which of the following is NOT a type of HIPAA security safeguard?
-
Administrative safeguards
-
Physical safeguards
-
Technical safeguards
-
Organizational safeguards
D
Correct answer
Explanation
Organizational safeguards are not a type of HIPAA security safeguard. The three types of HIPAA security safeguards are administrative, physical, and technical.
What is the first step in responding to a security incident in healthcare?
-
Identify and contain the incident
-
Eradicate the threat
-
Recover from the incident
-
Conduct a risk assessment
A
Correct answer
Explanation
The first step in responding to a security incident in healthcare is to identify and contain the incident to prevent further damage.
Which of the following is NOT a common type of security incident in healthcare?
-
Phishing attacks
-
Ransomware attacks
-
Data breaches
-
Denial-of-service attacks
D
Correct answer
Explanation
Denial-of-service attacks are not as common in healthcare as phishing attacks, ransomware attacks, and data breaches.
Which of the following is NOT a common type of data breach in healthcare?
-
Phishing attacks
-
Ransomware attacks
-
Insider attacks
-
Denial-of-service attacks
D
Correct answer
Explanation
Denial-of-service attacks are not a common type of data breach in healthcare.
Which of the following is NOT a common type of security incident in healthcare?
-
Phishing attacks
-
Ransomware attacks
-
Data breaches
-
Denial-of-service attacks
D
Correct answer
Explanation
Denial-of-service attacks are not as common in healthcare as phishing attacks, ransomware attacks, and data breaches.
Which of the following is a common type of supply chain disruption caused by cyberattacks?
-
Denial of service (DoS) attacks
-
Man-in-the-middle (MitM) attacks
-
Malware infections
-
Phishing attacks
C
Correct answer
Explanation
Malware infections can disrupt supply chain operations by compromising systems, stealing sensitive information, or causing operational disruptions.