Computer Knowledge ยท General Awareness
Information Security
4,634 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
Which of the following is NOT a key component of the NIST Cybersecurity Framework?
-
Identify
-
Protect
-
Detect
-
Respond
D
Correct answer
Explanation
The NIST Cybersecurity Framework consists of five key components: Identify, Protect, Detect, Respond, and Recover.
Which of the following is NOT a key component of the HIPAA Security Rule?
-
Administrative safeguards
-
Physical safeguards
-
Technical safeguards
-
Organizational safeguards
D
Correct answer
Explanation
The HIPAA Security Rule consists of three key components: Administrative safeguards, Physical safeguards, and Technical safeguards.
Which of the following is NOT a key component of the PCI DSS?
-
Build and maintain a secure network
-
Protect cardholder data
-
Maintain a vulnerability management program
-
Implement strong access control measures
D
Correct answer
Explanation
The PCI DSS consists of six key components: Build and maintain a secure network, Protect cardholder data, Maintain a vulnerability management program, Implement strong authentication measures, Regularly test security systems and processes, and Maintain an information security policy.
Which of the following is NOT a key component of the FISMA?
-
Information security management system
-
Risk assessment
-
Incident response
-
Business continuity
D
Correct answer
Explanation
The FISMA consists of three key components: Information security management system, Risk assessment, and Incident response.
What is the primary goal of social engineering attacks?
-
To gain unauthorized access to sensitive information
-
To disrupt or disable computer systems
-
To steal physical assets
-
To cause physical harm to individuals
A
Correct answer
Explanation
Social engineering attacks aim to manipulate individuals into divulging confidential information or performing actions that compromise security, leading to unauthorized access to sensitive data.
Which of the following is a common social engineering technique?
-
Phishing
-
Malware
-
DDoS attacks
-
SQL injection
A
Correct answer
Explanation
Phishing is a social engineering technique that involves sending fraudulent emails or creating fake websites to trick individuals into providing personal information or clicking malicious links.
What is the primary defense against social engineering attacks?
-
Strong passwords
-
Firewalls
-
Anti-virus software
-
User education and awareness
D
Correct answer
Explanation
Educating users about social engineering techniques and raising awareness of potential threats is the most effective defense against these attacks, as it empowers individuals to recognize and resist manipulation attempts.
Which of the following is an example of a human factor that can contribute to cybersecurity breaches?
-
Lack of user training
-
Software vulnerabilities
-
Hardware failures
-
Natural disasters
A
Correct answer
Explanation
Lack of user training can lead to employees making mistakes that compromise security, such as clicking on malicious links or providing sensitive information to unauthorized individuals.
Which of the following is a recommended best practice for creating strong passwords?
-
Use common words found in the dictionary
-
Include personal information like birthdates or names
-
Use the same password for multiple accounts
-
Create long and complex passwords with a mix of characters
D
Correct answer
Explanation
Strong passwords should be long, complex, and include a mix of uppercase and lowercase letters, numbers, and symbols to make them difficult to guess or crack.
What is the purpose of multi-factor authentication (MFA)?
-
To increase the number of authentication factors required for access
-
To reduce the number of authentication factors required for access
-
To bypass the need for authentication altogether
-
To allow users to access multiple accounts with a single password
A
Correct answer
Explanation
MFA adds an extra layer of security by requiring multiple forms of authentication, such as a password and a one-time code sent to a mobile device, to verify a user's identity.
Which of the following is a common social engineering tactic used in phishing attacks?
-
Creating a sense of urgency or fear
-
Offering too-good-to-be-true deals
-
Impersonating legitimate organizations or individuals
-
All of the above
D
Correct answer
Explanation
Phishing attacks often employ a combination of tactics to manipulate individuals, including creating a sense of urgency or fear, offering attractive deals, and impersonating legitimate entities to gain trust.
What is the recommended approach to handling suspicious emails?
-
Open and read the email to see what it's about
-
Click on any links or attachments included in the email
-
Forward the email to your IT department for analysis
-
Delete the email without opening it
D
Correct answer
Explanation
It is recommended to delete suspicious emails without opening them to avoid potential malware infections or phishing attempts.
Which of the following is a good practice for protecting against social engineering attacks?
-
Never share personal information online
-
Be cautious of unsolicited emails and phone calls
-
Use strong passwords and enable MFA
-
All of the above
D
Correct answer
Explanation
To protect against social engineering attacks, it is important to be vigilant, protect personal information, be cautious of suspicious communications, and implement strong security measures like strong passwords and MFA.
Which of the following is a common human error that can lead to cybersecurity breaches?
-
Clicking on malicious links in emails
-
Using weak passwords
-
Sharing sensitive information over unsecure networks
-
All of the above
D
Correct answer
Explanation
Common human errors that can compromise cybersecurity include clicking on malicious links, using weak passwords, and sharing sensitive information over unsecure networks.
Which of the following is a good practice for protecting against social engineering attacks on social media?
-
Be cautious of friend requests from strangers
-
Never share personal information on public posts
-
Use strong passwords and enable privacy settings
-
All of the above
D
Correct answer
Explanation
To protect against social engineering attacks on social media, it is important to be cautious of friend requests from strangers, avoid sharing personal information publicly, use strong passwords, and enable privacy settings.