Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

What is the term for a type of phishing attack that targets mobile devices?

  1. Smishing

  2. Vishing

  3. Pharming

  4. Spear Phishing

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Smishing is a type of phishing attack that uses SMS messages to trick victims into giving up personal information or downloading malicious software.

Multiple choice

Which of the following is NOT a best practice for securing mobile devices?

  1. Using a strong password or passcode

  2. Installing security updates promptly

  3. Jailbreaking or rooting your device

  4. Using a virtual private network (VPN)

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Jailbreaking or rooting a device can compromise its security by allowing unauthorized access to the operating system and installed apps.

Multiple choice

Which of the following is NOT a type of mobile malware?

  1. Spyware

  2. Adware

  3. Ransomware

  4. Antivirus Software

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Antivirus software is not a type of mobile malware, but rather a tool used to protect devices from malware.

Multiple choice

What was the name of the security vulnerability that allowed attackers to remotely execute code on iOS devices?

  1. Jailbreak

  2. Heartbleed

  3. Stagefright

  4. Spectre and Meltdown

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Jailbreaking an iOS device involves exploiting a security vulnerability to gain unauthorized access to the operating system.

Multiple choice

Which of the following is NOT a type of mobile security threat?

  1. Malware

  2. Phishing

  3. Social Engineering

  4. Physical Theft

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Physical theft is not a type of mobile security threat, as it does not involve the use of technology.

Multiple choice

What is the term for a type of malware that locks a mobile device and demands a ransom payment to unlock it?

  1. Ransomware

  2. Spyware

  3. Adware

  4. Trojan Horse

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Ransomware is a type of malware that encrypts files on a device and demands a ransom payment to decrypt them.

Multiple choice

Which of the following is NOT a best practice for securing mobile devices?

  1. Using a strong password or passcode

  2. Installing security updates promptly

  3. Using a virtual private network (VPN)

  4. Disabling automatic app updates

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Disabling automatic app updates can leave devices vulnerable to security vulnerabilities that are patched in newer versions of apps.

Multiple choice

What was the name of the security vulnerability that allowed attackers to eavesdrop on encrypted communications on Android devices?

  1. Stagefright

  2. Heartbleed

  3. Spectre and Meltdown

  4. KRACK

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

KRACK was a particularly serious vulnerability that allowed attackers to eavesdrop on encrypted Wi-Fi traffic.

Multiple choice

Which of the following is NOT a type of mobile security control?

  1. Encryption

  2. Authentication

  3. Authorization

  4. Jailbreaking

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Jailbreaking is not a type of mobile security control, but rather a process of modifying a device's operating system to allow unauthorized access.

Multiple choice

What is the term for a type of malware that steals personal information from mobile devices?

  1. Spyware

  2. Adware

  3. Ransomware

  4. Trojan Horse

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Spyware is a type of malware that collects personal information from a device without the user's knowledge or consent.

Multiple choice

Which of the following is NOT a best practice for securing mobile devices?

  1. Using a strong password or passcode

  2. Installing security updates promptly

  3. Using a virtual private network (VPN)

  4. Disabling automatic app updates

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Disabling automatic app updates can leave devices vulnerable to security vulnerabilities that are patched in newer versions of apps.

Multiple choice

Which of the following is NOT a key component of cybersecurity governance?

  1. Risk assessment

  2. Policy development

  3. Incident response

  4. Compliance management

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Incident response is a process for responding to and managing cybersecurity incidents. It is not a key component of cybersecurity governance, which is focused on establishing and maintaining a framework for managing cybersecurity risks.

Multiple choice

Which of the following is NOT a common cybersecurity metric?

  1. Mean time to detect (MTTD)

  2. Mean time to respond (MTTR)

  3. Number of security incidents

  4. Cost of security breaches

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

The cost of security breaches is not a common cybersecurity metric. This is because it is difficult to accurately measure the cost of a security breach.

Multiple choice

Which of the following is NOT a common cybersecurity measurement tool?

  1. Security information and event management (SIEM) system

  2. Vulnerability scanner

  3. Penetration testing tool

  4. Risk assessment tool

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Risk assessment tools are not common cybersecurity measurement tools. This is because risk assessment is a process, not a tool.

Multiple choice

Which of the following is NOT a common cybersecurity metric?

  1. Number of security incidents

  2. Mean time to detect (MTTD)

  3. Mean time to respond (MTTR)

  4. Return on security investment (ROSI)

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Return on security investment (ROSI) is not a common cybersecurity metric. This is because it is difficult to accurately measure the return on investment in cybersecurity.