Computer Knowledge ยท General Awareness
Information Security
4,634 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
What was the name of the security vulnerability that allowed attackers to remotely execute code on iOS devices?
-
Jailbreak
-
Heartbleed
-
Stagefright
-
Spectre and Meltdown
A
Correct answer
Explanation
Jailbreaking an iOS device involves exploiting a security vulnerability to gain unauthorized access to the operating system.
Which of the following is NOT a type of mobile security threat?
-
Malware
-
Phishing
-
Social Engineering
-
Physical Theft
D
Correct answer
Explanation
Physical theft is not a type of mobile security threat, as it does not involve the use of technology.
What is the term for a type of malware that locks a mobile device and demands a ransom payment to unlock it?
-
Ransomware
-
Spyware
-
Adware
-
Trojan Horse
A
Correct answer
Explanation
Ransomware is a type of malware that encrypts files on a device and demands a ransom payment to decrypt them.
Which of the following is NOT a best practice for securing mobile devices?
-
Using a strong password or passcode
-
Installing security updates promptly
-
Using a virtual private network (VPN)
-
Disabling automatic app updates
D
Correct answer
Explanation
Disabling automatic app updates can leave devices vulnerable to security vulnerabilities that are patched in newer versions of apps.
What was the name of the security vulnerability that allowed attackers to eavesdrop on encrypted communications on Android devices?
-
Stagefright
-
Heartbleed
-
Spectre and Meltdown
-
KRACK
D
Correct answer
Explanation
KRACK was a particularly serious vulnerability that allowed attackers to eavesdrop on encrypted Wi-Fi traffic.
What is the term for a type of malware that steals personal information from mobile devices?
-
Spyware
-
Adware
-
Ransomware
-
Trojan Horse
A
Correct answer
Explanation
Spyware is a type of malware that collects personal information from a device without the user's knowledge or consent.
Which of the following is NOT a best practice for securing mobile devices?
-
Using a strong password or passcode
-
Installing security updates promptly
-
Using a virtual private network (VPN)
-
Disabling automatic app updates
D
Correct answer
Explanation
Disabling automatic app updates can leave devices vulnerable to security vulnerabilities that are patched in newer versions of apps.
Which of the following is NOT a key component of cybersecurity governance?
-
Risk assessment
-
Policy development
-
Incident response
-
Compliance management
C
Correct answer
Explanation
Incident response is a process for responding to and managing cybersecurity incidents. It is not a key component of cybersecurity governance, which is focused on establishing and maintaining a framework for managing cybersecurity risks.
Which of the following is NOT a common cybersecurity metric?
-
Mean time to detect (MTTD)
-
Mean time to respond (MTTR)
-
Number of security incidents
-
Cost of security breaches
D
Correct answer
Explanation
The cost of security breaches is not a common cybersecurity metric. This is because it is difficult to accurately measure the cost of a security breach.
Which of the following is NOT a common cybersecurity measurement tool?
-
Security information and event management (SIEM) system
-
Vulnerability scanner
-
Penetration testing tool
-
Risk assessment tool
D
Correct answer
Explanation
Risk assessment tools are not common cybersecurity measurement tools. This is because risk assessment is a process, not a tool.
Which of the following is NOT a common cybersecurity metric?
-
Number of security incidents
-
Mean time to detect (MTTD)
-
Mean time to respond (MTTR)
-
Return on security investment (ROSI)
D
Correct answer
Explanation
Return on security investment (ROSI) is not a common cybersecurity metric. This is because it is difficult to accurately measure the return on investment in cybersecurity.
Which of the following is NOT a key component of cybersecurity governance?
-
Risk assessment
-
Policy development
-
Incident response
-
Compliance management
C
Correct answer
Explanation
Incident response is a process for responding to and managing cybersecurity incidents. It is not a key component of cybersecurity governance, which is focused on establishing and maintaining a framework for managing cybersecurity risks.
Which of the following is NOT a common cybersecurity metric?
-
Mean time to detect (MTTD)
-
Mean time to respond (MTTR)
-
Number of security incidents
-
Cost of security breaches
D
Correct answer
Explanation
The cost of security breaches is not a common cybersecurity metric. This is because it is difficult to accurately measure the cost of a security breach.
Which of the following is NOT a common authorization mechanism?
-
Access Control Lists (ACLs)
-
Capabilities
-
Tokens
-
Biometrics
D
Correct answer
Explanation
Biometrics is not a common authorization mechanism. ACLs, Capabilities, and Tokens are more commonly used.
Capabilities are typically implemented using:
-
Cryptographic keys
-
Tokens
-
Certificates
-
All of the above
A
Correct answer
Explanation
Capabilities are typically implemented using cryptographic keys.