Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
What is the term for a type of phishing attack that targets mobile devices?
-
Smishing
-
Vishing
-
Pharming
-
Spear Phishing
A
Correct answer
Explanation
Smishing is a type of phishing attack that uses SMS messages to trick victims into giving up personal information or downloading malicious software.
Which of the following is NOT a best practice for securing mobile devices?
-
Using a strong password or passcode
-
Installing security updates promptly
-
Jailbreaking or rooting your device
-
Using a virtual private network (VPN)
C
Correct answer
Explanation
Jailbreaking or rooting a device can compromise its security by allowing unauthorized access to the operating system and installed apps.
Which of the following is NOT a type of mobile malware?
-
Spyware
-
Adware
-
Ransomware
-
Antivirus Software
D
Correct answer
Explanation
Antivirus software is not a type of mobile malware, but rather a tool used to protect devices from malware.
What was the name of the security vulnerability that allowed attackers to remotely execute code on iOS devices?
-
Jailbreak
-
Heartbleed
-
Stagefright
-
Spectre and Meltdown
A
Correct answer
Explanation
Jailbreaking an iOS device involves exploiting a security vulnerability to gain unauthorized access to the operating system.
Which of the following is NOT a type of mobile security threat?
-
Malware
-
Phishing
-
Social Engineering
-
Physical Theft
D
Correct answer
Explanation
Physical theft is not a type of mobile security threat, as it does not involve the use of technology.
What is the term for a type of malware that locks a mobile device and demands a ransom payment to unlock it?
-
Ransomware
-
Spyware
-
Adware
-
Trojan Horse
A
Correct answer
Explanation
Ransomware is a type of malware that encrypts files on a device and demands a ransom payment to decrypt them.
Which of the following is NOT a best practice for securing mobile devices?
-
Using a strong password or passcode
-
Installing security updates promptly
-
Using a virtual private network (VPN)
-
Disabling automatic app updates
D
Correct answer
Explanation
Disabling automatic app updates can leave devices vulnerable to security vulnerabilities that are patched in newer versions of apps.
What was the name of the security vulnerability that allowed attackers to eavesdrop on encrypted communications on Android devices?
-
Stagefright
-
Heartbleed
-
Spectre and Meltdown
-
KRACK
D
Correct answer
Explanation
KRACK was a particularly serious vulnerability that allowed attackers to eavesdrop on encrypted Wi-Fi traffic.
Which of the following is NOT a type of mobile security control?
-
Encryption
-
Authentication
-
Authorization
-
Jailbreaking
D
Correct answer
Explanation
Jailbreaking is not a type of mobile security control, but rather a process of modifying a device's operating system to allow unauthorized access.
What is the term for a type of malware that steals personal information from mobile devices?
-
Spyware
-
Adware
-
Ransomware
-
Trojan Horse
A
Correct answer
Explanation
Spyware is a type of malware that collects personal information from a device without the user's knowledge or consent.
Which of the following is NOT a best practice for securing mobile devices?
-
Using a strong password or passcode
-
Installing security updates promptly
-
Using a virtual private network (VPN)
-
Disabling automatic app updates
D
Correct answer
Explanation
Disabling automatic app updates can leave devices vulnerable to security vulnerabilities that are patched in newer versions of apps.
Which of the following is NOT a key component of cybersecurity governance?
-
Risk assessment
-
Policy development
-
Incident response
-
Compliance management
C
Correct answer
Explanation
Incident response is a process for responding to and managing cybersecurity incidents. It is not a key component of cybersecurity governance, which is focused on establishing and maintaining a framework for managing cybersecurity risks.
Which of the following is NOT a common cybersecurity metric?
-
Mean time to detect (MTTD)
-
Mean time to respond (MTTR)
-
Number of security incidents
-
Cost of security breaches
D
Correct answer
Explanation
The cost of security breaches is not a common cybersecurity metric. This is because it is difficult to accurately measure the cost of a security breach.
Which of the following is NOT a common cybersecurity measurement tool?
-
Security information and event management (SIEM) system
-
Vulnerability scanner
-
Penetration testing tool
-
Risk assessment tool
D
Correct answer
Explanation
Risk assessment tools are not common cybersecurity measurement tools. This is because risk assessment is a process, not a tool.
Which of the following is NOT a common cybersecurity metric?
-
Number of security incidents
-
Mean time to detect (MTTD)
-
Mean time to respond (MTTR)
-
Return on security investment (ROSI)
D
Correct answer
Explanation
Return on security investment (ROSI) is not a common cybersecurity metric. This is because it is difficult to accurately measure the return on investment in cybersecurity.