Computer Knowledge ยท General Awareness
Information Security
4,634 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
Which of the following is NOT a recommended best practice for creating strong passwords?
-
Using a combination of uppercase and lowercase letters
-
Including special characters and symbols
-
Reusing the same password across multiple accounts
-
Using a password manager to store and generate secure passwords
C
Correct answer
Explanation
Reusing the same password across multiple accounts is a poor security practice as it increases the risk of unauthorized access if one account is compromised.
What is the term used to describe the act of tricking someone into revealing sensitive information or taking actions that compromise security?
-
Phishing
-
Malware
-
Social engineering
-
DDoS attack
C
Correct answer
Explanation
Social engineering is the act of manipulating people into divulging confidential information or performing actions that compromise security.
Which of the following is NOT a common social engineering technique used by attackers?
-
Pretending to be a legitimate authority figure
-
Sending malicious links or attachments in emails
-
Offering free gifts or rewards in exchange for personal information
-
Installing security software on a victim's computer
D
Correct answer
Explanation
Installing security software on a victim's computer is not a common social engineering technique. Attackers typically use tactics that exploit human vulnerabilities and trust to gain access to sensitive information or systems.
What is the recommended approach for handling suspicious emails or attachments?
-
Open and read the email to determine its legitimacy
-
Forward the email to the IT department for analysis
-
Click on links or attachments without verifying their authenticity
-
Delete the email without opening it
D
Correct answer
Explanation
The safest approach is to delete suspicious emails without opening them, especially if they come from unknown senders or contain unexpected attachments.
Which of the following is NOT a recommended practice for securing mobile devices?
-
Using a strong password or biometric authentication
-
Keeping software and apps up to date
-
Connecting to public Wi-Fi networks without a VPN
-
Installing security apps and anti-malware software
C
Correct answer
Explanation
Connecting to public Wi-Fi networks without a VPN can expose your device to eavesdropping and man-in-the-middle attacks. It is recommended to use a VPN to encrypt your internet traffic when using public Wi-Fi.
Which of the following is NOT a common type of cyberattack that targets businesses and organizations?
-
Phishing
-
Ransomware
-
Distributed denial-of-service (DDoS) attack
-
Software update
D
Correct answer
Explanation
Software update is not a type of cyberattack. It is a recommended practice to keep software and systems up to date to address security vulnerabilities and improve overall system stability.
What is the primary purpose of a firewall in cybersecurity?
-
To block unauthorized access to a network
-
To scan for and remove malware from a computer
-
To encrypt data during transmission
-
To provide secure remote access to a network
A
Correct answer
Explanation
The primary purpose of a firewall is to monitor and control incoming and outgoing network traffic, blocking unauthorized access and protecting the network from external threats.
Which of the following is NOT a recommended practice for creating a secure password?
-
Using a combination of uppercase and lowercase letters
-
Including special characters and symbols
-
Using a common word or phrase found in a dictionary
-
Using a password manager to generate and store strong passwords
C
Correct answer
Explanation
Using a common word or phrase found in a dictionary is not a secure password practice as it can be easily guessed or cracked by attackers.
What is the term used to describe the process of recovering data that has been encrypted or locked by ransomware?
-
Decryption
-
Encryption
-
Malware removal
-
System restore
A
Correct answer
Explanation
Decryption is the process of recovering data that has been encrypted or locked by ransomware by using a decryption key or algorithm.
Which of the following is NOT a common type of phishing attack?
-
Spear phishing
-
Whaling
-
Smishing
-
Software update
D
Correct answer
Explanation
Software update is not a type of phishing attack. It is a recommended practice to keep software and systems up to date to address security vulnerabilities and improve overall system stability.
How does Data Security contribute to effective Data Governance?
-
It ensures the confidentiality, integrity, and availability of data.
-
It facilitates data sharing and collaboration among authorized users.
-
It enables data analysis and insights for decision-making.
-
It promotes data transparency and accountability.
A
Correct answer
Explanation
Data Security measures, such as encryption, access controls, and intrusion detection systems, help ensure the confidentiality, integrity, and availability of data, which are essential aspects of effective Data Governance.
Which of the following is NOT a common data security control implemented as part of Data Governance?
-
Data encryption
-
Data masking
-
Data lineage tracking
-
Multi-factor authentication
C
Correct answer
Explanation
Data lineage tracking, while important for Data Governance, is not typically considered a data security control. Data encryption, data masking, and multi-factor authentication are common security controls used to protect data.
What is the role of data security incident response in the integration of Data Governance and Data Security?
-
To detect and respond to data security incidents promptly
-
To minimize the impact of data breaches and data loss
-
To ensure business continuity and data recovery
-
All of the above
D
Correct answer
Explanation
Data security incident response plays a crucial role in the integration of Data Governance and Data Security by enabling organizations to promptly detect, respond to, and mitigate data security incidents, minimizing their impact and ensuring business continuity.
How can Data Governance and Data Security work together to improve data quality?
-
By implementing data validation and verification processes
-
By establishing data lineage and provenance
-
By monitoring data usage and identifying data anomalies
-
All of the above
D
Correct answer
Explanation
Data Governance and Data Security can collaborate to improve data quality by implementing data validation, establishing data lineage, monitoring data usage, and identifying data anomalies, ensuring that data is accurate, consistent, and reliable.
Which regulation requires organizations to implement appropriate security measures to protect personal data?
A
Correct answer
Explanation
The General Data Protection Regulation (GDPR) is a European Union regulation that requires organizations to implement appropriate security measures to protect personal data.