Computer Knowledge ยท General Awareness

Information Security

4,634 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

What are some common signs of a spear phishing email?

  1. The email address of the sender is familiar, but the email contains grammatical errors or typos.

  2. The email contains a link to a website that looks similar to a legitimate website, but is actually fake.

  3. The email asks you to click on a link or open an attachment to access a document or file.

  4. The email contains information that is specific to you or your organization.

  5. All of the above

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

Common signs of a spear phishing email include a familiar sender email address with grammatical errors or typos, a link to a fake website, a request to click on a link or open an attachment, and information that is specific to the victim or their organization.

Multiple choice

What should you do if you receive a spear phishing email?

  1. Ignore the email and delete it.

  2. Click on the link in the email to see where it goes.

  3. Open the attachment in the email to see what it is.

  4. Forward the email to your IT department or security team.

  5. Report the email as spam.

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

If you receive a spear phishing email, the best thing to do is to forward it to your IT department or security team. Do not click on any links or open any attachments in the email.

Multiple choice

What is whaling?

  1. A type of phishing attack that targets high-level executives or other important individuals.

  2. A type of phishing attack that uses social engineering to trick victims into giving up their personal information.

  3. A type of phishing attack that uses malware to infect a victim's computer.

  4. A type of phishing attack that uses a fake website to trick victims into entering their personal information.

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Whaling is a type of phishing attack that targets high-level executives or other important individuals. Whaling emails are often very sophisticated and may contain information that is specific to the victim and their organization.

Multiple choice

What is smishing?

  1. A type of phishing attack that uses SMS messages to trick victims into giving up their personal information.

  2. A type of phishing attack that uses social engineering to trick victims into giving up their personal information.

  3. A type of phishing attack that uses malware to infect a victim's computer.

  4. A type of phishing attack that uses a fake website to trick victims into entering their personal information.

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Smishing is a type of phishing attack that uses SMS messages to trick victims into giving up their personal information. Smishing messages often contain a link to a fake website or a request to call a fake phone number.

Multiple choice

What are some common signs of a smishing message?

  1. The sender of the message is unfamiliar or suspicious.

  2. The message contains grammatical errors or typos.

  3. The message contains a link to a website that looks similar to a legitimate website, but is actually fake.

  4. The message asks you to call a phone number that you don't recognize.

  5. All of the above

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

Common signs of a smishing message include an unfamiliar or suspicious sender, grammatical errors or typos, a link to a fake website, a request to call a fake phone number, and other suspicious content.

Multiple choice

What is vishing?

  1. A type of phishing attack that uses voice calls to trick victims into giving up their personal information.

  2. A type of phishing attack that uses social engineering to trick victims into giving up their personal information.

  3. A type of phishing attack that uses malware to infect a victim's computer.

  4. A type of phishing attack that uses a fake website to trick victims into entering their personal information.

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Vishing is a type of phishing attack that uses voice calls to trick victims into giving up their personal information. Vishing calls often involve a scammer pretending to be from a legitimate company or organization.

Multiple choice

What are some common signs of a vishing call?

  1. The caller ID of the call is unfamiliar or suspicious.

  2. The caller asks you to provide your personal information, such as your Social Security number or credit card number.

  3. The caller asks you to call a phone number that you don't recognize.

  4. The caller tries to pressure you into making a decision quickly.

  5. All of the above

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

Common signs of a vishing call include an unfamiliar or suspicious caller ID, a request for personal information, a request to call a fake phone number, and pressure to make a decision quickly.

Multiple choice

Which of the following is a common security threat in mobile cloud computing?

  1. Malware attacks

  2. Phishing attacks

  3. Man-in-the-middle attacks

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

All of the above options are common security threats in mobile cloud computing.

Multiple choice

What is cybersecurity?

  1. The protection of digital information from unauthorized access, use, disclosure, disruption, modification, or destruction

  2. The protection of computer systems from unauthorized access, use, disclosure, disruption, modification, or destruction

  3. The protection of networks from unauthorized access, use, disclosure, disruption, modification, or destruction

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Cybersecurity is the protection of digital information, computer systems, and networks from unauthorized access, use, disclosure, disruption, modification, or destruction.

Multiple choice

Which of the following is NOT a common cloud security threat?

  1. Distributed Denial of Service (DDoS) attacks

  2. Malware and virus infections

  3. Phishing and social engineering attacks

  4. Hardware failures and natural disasters

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Hardware failures and natural disasters are not considered common cloud security threats. Cloud providers typically implement measures to protect against these physical risks.

Multiple choice

Which of the following is a best practice for data governance in emerging technologies?

  1. Establishing clear data ownership and accountability

  2. Implementing data security and privacy controls

  3. Promoting data literacy and awareness

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Best practices for data governance in emerging technologies include establishing clear data ownership and accountability, implementing data security and privacy controls, and promoting data literacy and awareness among stakeholders.

Multiple choice

Which of the following is NOT a common cybersecurity policy?

  1. Password management policy

  2. Data encryption policy

  3. Social media policy

  4. Incident response policy

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Social media policy is not a common cybersecurity policy. Password management policy, data encryption policy, and incident response policy are all common cybersecurity policies.

Multiple choice

Which of the following is NOT a common cybersecurity standard?

  1. ISO 27001

  2. NIST SP 800-53

  3. PCI DSS

  4. HIPAA

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

HIPAA is not a cybersecurity standard. It is a healthcare privacy law that sets standards for the protection of patient health information.

Multiple choice

What are some common types of cybersecurity policies?

  1. Password management policy

  2. Data encryption policy

  3. Incident response policy

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Common types of cybersecurity policies include password management policy, data encryption policy, and incident response policy.

Multiple choice

What are some common types of cybersecurity standards?

  1. ISO 27001

  2. NIST SP 800-53

  3. PCI DSS

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Common types of cybersecurity standards include ISO 27001, NIST SP 800-53, and PCI DSS.