Computer Knowledge ยท General Awareness
Information Security
4,634 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
What are some common signs of a spear phishing email?
-
The email address of the sender is familiar, but the email contains grammatical errors or typos.
-
The email contains a link to a website that looks similar to a legitimate website, but is actually fake.
-
The email asks you to click on a link or open an attachment to access a document or file.
-
The email contains information that is specific to you or your organization.
-
All of the above
E
Correct answer
Explanation
Common signs of a spear phishing email include a familiar sender email address with grammatical errors or typos, a link to a fake website, a request to click on a link or open an attachment, and information that is specific to the victim or their organization.
What should you do if you receive a spear phishing email?
-
Ignore the email and delete it.
-
Click on the link in the email to see where it goes.
-
Open the attachment in the email to see what it is.
-
Forward the email to your IT department or security team.
-
Report the email as spam.
D
Correct answer
Explanation
If you receive a spear phishing email, the best thing to do is to forward it to your IT department or security team. Do not click on any links or open any attachments in the email.
-
A type of phishing attack that targets high-level executives or other important individuals.
-
A type of phishing attack that uses social engineering to trick victims into giving up their personal information.
-
A type of phishing attack that uses malware to infect a victim's computer.
-
A type of phishing attack that uses a fake website to trick victims into entering their personal information.
A
Correct answer
Explanation
Whaling is a type of phishing attack that targets high-level executives or other important individuals. Whaling emails are often very sophisticated and may contain information that is specific to the victim and their organization.
-
A type of phishing attack that uses SMS messages to trick victims into giving up their personal information.
-
A type of phishing attack that uses social engineering to trick victims into giving up their personal information.
-
A type of phishing attack that uses malware to infect a victim's computer.
-
A type of phishing attack that uses a fake website to trick victims into entering their personal information.
A
Correct answer
Explanation
Smishing is a type of phishing attack that uses SMS messages to trick victims into giving up their personal information. Smishing messages often contain a link to a fake website or a request to call a fake phone number.
What are some common signs of a smishing message?
-
The sender of the message is unfamiliar or suspicious.
-
The message contains grammatical errors or typos.
-
The message contains a link to a website that looks similar to a legitimate website, but is actually fake.
-
The message asks you to call a phone number that you don't recognize.
-
All of the above
E
Correct answer
Explanation
Common signs of a smishing message include an unfamiliar or suspicious sender, grammatical errors or typos, a link to a fake website, a request to call a fake phone number, and other suspicious content.
-
A type of phishing attack that uses voice calls to trick victims into giving up their personal information.
-
A type of phishing attack that uses social engineering to trick victims into giving up their personal information.
-
A type of phishing attack that uses malware to infect a victim's computer.
-
A type of phishing attack that uses a fake website to trick victims into entering their personal information.
A
Correct answer
Explanation
Vishing is a type of phishing attack that uses voice calls to trick victims into giving up their personal information. Vishing calls often involve a scammer pretending to be from a legitimate company or organization.
What are some common signs of a vishing call?
-
The caller ID of the call is unfamiliar or suspicious.
-
The caller asks you to provide your personal information, such as your Social Security number or credit card number.
-
The caller asks you to call a phone number that you don't recognize.
-
The caller tries to pressure you into making a decision quickly.
-
All of the above
E
Correct answer
Explanation
Common signs of a vishing call include an unfamiliar or suspicious caller ID, a request for personal information, a request to call a fake phone number, and pressure to make a decision quickly.
Which of the following is a common security threat in mobile cloud computing?
-
Malware attacks
-
Phishing attacks
-
Man-in-the-middle attacks
-
All of the above
D
Correct answer
Explanation
All of the above options are common security threats in mobile cloud computing.
-
The protection of digital information from unauthorized access, use, disclosure, disruption, modification, or destruction
-
The protection of computer systems from unauthorized access, use, disclosure, disruption, modification, or destruction
-
The protection of networks from unauthorized access, use, disclosure, disruption, modification, or destruction
-
All of the above
D
Correct answer
Explanation
Cybersecurity is the protection of digital information, computer systems, and networks from unauthorized access, use, disclosure, disruption, modification, or destruction.
Which of the following is NOT a common cloud security threat?
-
Distributed Denial of Service (DDoS) attacks
-
Malware and virus infections
-
Phishing and social engineering attacks
-
Hardware failures and natural disasters
D
Correct answer
Explanation
Hardware failures and natural disasters are not considered common cloud security threats. Cloud providers typically implement measures to protect against these physical risks.
Which of the following is a best practice for data governance in emerging technologies?
-
Establishing clear data ownership and accountability
-
Implementing data security and privacy controls
-
Promoting data literacy and awareness
-
All of the above
D
Correct answer
Explanation
Best practices for data governance in emerging technologies include establishing clear data ownership and accountability, implementing data security and privacy controls, and promoting data literacy and awareness among stakeholders.
Which of the following is NOT a common cybersecurity policy?
-
Password management policy
-
Data encryption policy
-
Social media policy
-
Incident response policy
C
Correct answer
Explanation
Social media policy is not a common cybersecurity policy. Password management policy, data encryption policy, and incident response policy are all common cybersecurity policies.
Which of the following is NOT a common cybersecurity standard?
-
ISO 27001
-
NIST SP 800-53
-
PCI DSS
-
HIPAA
D
Correct answer
Explanation
HIPAA is not a cybersecurity standard. It is a healthcare privacy law that sets standards for the protection of patient health information.
What are some common types of cybersecurity policies?
-
Password management policy
-
Data encryption policy
-
Incident response policy
-
All of the above
D
Correct answer
Explanation
Common types of cybersecurity policies include password management policy, data encryption policy, and incident response policy.
What are some common types of cybersecurity standards?
-
ISO 27001
-
NIST SP 800-53
-
PCI DSS
-
All of the above
D
Correct answer
Explanation
Common types of cybersecurity standards include ISO 27001, NIST SP 800-53, and PCI DSS.