Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
Which of the following is a common type of data leakage?
-
Email exfiltration
-
Unencrypted data transfer
-
Data theft by malicious insiders
-
All of the above
D
Correct answer
Explanation
Common types of data leakage include email exfiltration, unencrypted data transfer, and data theft by malicious insiders, among others.
What is the role of data encryption in DLP?
-
To protect data at rest
-
To protect data in transit
-
To prevent data leakage
-
All of the above
D
Correct answer
Explanation
Data encryption plays a crucial role in DLP by protecting data at rest, protecting data in transit, and preventing data leakage.
Which of the following is a best practice for monitoring DLP systems?
-
Regularly review DLP logs
-
Conduct periodic security audits
-
Implement a SIEM solution
-
All of the above
D
Correct answer
Explanation
Best practices for monitoring DLP systems include regularly reviewing DLP logs, conducting periodic security audits, and implementing a SIEM solution.
What is the role of incident response in DLP?
-
To investigate data breaches
-
To contain data leakage
-
To recover from data breaches
-
All of the above
D
Correct answer
Explanation
Incident response in DLP involves investigating data breaches, containing data leakage, and recovering from data breaches.
What is the role of data masking in DLP?
-
To protect sensitive data
-
To prevent data leakage
-
To comply with data protection regulations
-
All of the above
D
Correct answer
Explanation
Data masking in DLP serves to protect sensitive data, prevent data leakage, and comply with data protection regulations.
What is the role of DLP policies in preventing data leakage?
-
To define what data is considered sensitive
-
To specify how sensitive data should be protected
-
To enforce data protection measures
-
All of the above
D
Correct answer
Explanation
DLP policies play a crucial role in preventing data leakage by defining what data is considered sensitive, specifying how sensitive data should be protected, and enforcing data protection measures.
Which type of attack involves unauthorized access to and modification of IoT devices in an agricultural setting?
-
Malware infection
-
Phishing
-
Man-in-the-middle attack
-
Denial-of-service attack
A
Correct answer
Explanation
Malware infection is a common threat in IoT security, where malicious software can infect IoT devices, allowing attackers to gain control and compromise the integrity of the system.
Which security measure involves monitoring and analyzing network traffic to detect suspicious activities?
-
Intrusion detection system (IDS)
-
Data encryption
-
Strong authentication
-
Firmware updates
A
Correct answer
Explanation
An intrusion detection system (IDS) monitors and analyzes network traffic to identify suspicious activities, such as unauthorized access attempts, malware infections, and network attacks.
Which cybersecurity framework provides guidance on securing critical infrastructure?
-
The National Institute of Standards and Technology (NIST) Cybersecurity Framework
-
The International Organization for Standardization (ISO) 27000 series
-
The Payment Card Industry Data Security Standard (PCI DSS)
-
The Health Insurance Portability and Accountability Act (HIPAA)
A
Correct answer
Explanation
The NIST Cybersecurity Framework provides guidance on securing critical infrastructure and improving the overall cybersecurity posture of organizations.
What is the concept of 'Least Privilege' in Cybersecurity Governance?
-
Organizations should grant users only the minimum level of access necessary to perform their job duties
-
Organizations should allow users to access all data and systems without restrictions
-
Organizations should grant users elevated privileges to ensure efficient operations
-
Organizations should allow users to share their credentials with others to improve collaboration
A
Correct answer
Explanation
The principle of Least Privilege is a fundamental cybersecurity practice that minimizes the risk of unauthorized access and data breaches.
Which cybersecurity standard is specifically designed for protecting payment card data?
-
The National Institute of Standards and Technology (NIST) Cybersecurity Framework
-
The International Organization for Standardization (ISO) 27000 series
-
The Payment Card Industry Data Security Standard (PCI DSS)
-
The Health Insurance Portability and Accountability Act (HIPAA)
C
Correct answer
Explanation
PCI DSS is a comprehensive security standard that organizations must comply with to process, store, or transmit payment card data.
What is the concept of 'Defense in Depth' in Cybersecurity Governance?
-
Implementing multiple layers of security controls to protect data and systems
-
Relying on a single security control to protect against all threats
-
Granting users unrestricted access to all data and systems
-
Ignoring security vulnerabilities and risks
A
Correct answer
Explanation
Defense in Depth is a cybersecurity strategy that involves implementing multiple layers of security controls to protect data and systems from various threats.
Which regulation focuses on protecting the privacy of individuals' financial information?
-
The General Data Protection Regulation (GDPR)
-
The Health Insurance Portability and Accountability Act (HIPAA)
-
The Gramm-Leach-Bliley Act (GLBA)
-
The Sarbanes-Oxley Act (SOX)
C
Correct answer
Explanation
GLBA is a US regulation that sets forth comprehensive privacy and security standards for protecting individuals' financial information.
What is the term used to describe the process of encrypting data before it is stored or transmitted?
-
Data Discovery and Classification
-
Data Encryption and Decryption
-
Data Masking and Tokenization
-
Data Loss Prevention (DLP)
B
Correct answer
Explanation
Data Encryption and Decryption involves converting data into an unreadable format to protect its confidentiality.
Which of the following is NOT a common type of mobile security incident?
-
Malware Attacks
-
Phishing Attacks
-
Data Breaches
-
Hardware Failures
D
Correct answer
Explanation
Hardware failures are not typically considered mobile security incidents, as they are not caused by malicious actors.