Computer Knowledge ยท General Awareness

Information Security

4,634 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice

What was the name of the security vulnerability that allowed attackers to remotely execute code on iOS devices?

  1. Jailbreak

  2. Heartbleed

  3. Stagefright

  4. Spectre and Meltdown

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Jailbreaking an iOS device involves exploiting a security vulnerability to gain unauthorized access to the operating system.

Multiple choice

Which of the following is NOT a type of mobile security threat?

  1. Malware

  2. Phishing

  3. Social Engineering

  4. Physical Theft

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Physical theft is not a type of mobile security threat, as it does not involve the use of technology.

Multiple choice

What is the term for a type of malware that locks a mobile device and demands a ransom payment to unlock it?

  1. Ransomware

  2. Spyware

  3. Adware

  4. Trojan Horse

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Ransomware is a type of malware that encrypts files on a device and demands a ransom payment to decrypt them.

Multiple choice

Which of the following is NOT a best practice for securing mobile devices?

  1. Using a strong password or passcode

  2. Installing security updates promptly

  3. Using a virtual private network (VPN)

  4. Disabling automatic app updates

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Disabling automatic app updates can leave devices vulnerable to security vulnerabilities that are patched in newer versions of apps.

Multiple choice

What was the name of the security vulnerability that allowed attackers to eavesdrop on encrypted communications on Android devices?

  1. Stagefright

  2. Heartbleed

  3. Spectre and Meltdown

  4. KRACK

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

KRACK was a particularly serious vulnerability that allowed attackers to eavesdrop on encrypted Wi-Fi traffic.

Multiple choice

What is the term for a type of malware that steals personal information from mobile devices?

  1. Spyware

  2. Adware

  3. Ransomware

  4. Trojan Horse

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Spyware is a type of malware that collects personal information from a device without the user's knowledge or consent.

Multiple choice

Which of the following is NOT a best practice for securing mobile devices?

  1. Using a strong password or passcode

  2. Installing security updates promptly

  3. Using a virtual private network (VPN)

  4. Disabling automatic app updates

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Disabling automatic app updates can leave devices vulnerable to security vulnerabilities that are patched in newer versions of apps.

Multiple choice

Which of the following is NOT a key component of cybersecurity governance?

  1. Risk assessment

  2. Policy development

  3. Incident response

  4. Compliance management

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Incident response is a process for responding to and managing cybersecurity incidents. It is not a key component of cybersecurity governance, which is focused on establishing and maintaining a framework for managing cybersecurity risks.

Multiple choice

Which of the following is NOT a common cybersecurity metric?

  1. Mean time to detect (MTTD)

  2. Mean time to respond (MTTR)

  3. Number of security incidents

  4. Cost of security breaches

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

The cost of security breaches is not a common cybersecurity metric. This is because it is difficult to accurately measure the cost of a security breach.

Multiple choice

Which of the following is NOT a common cybersecurity measurement tool?

  1. Security information and event management (SIEM) system

  2. Vulnerability scanner

  3. Penetration testing tool

  4. Risk assessment tool

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Risk assessment tools are not common cybersecurity measurement tools. This is because risk assessment is a process, not a tool.

Multiple choice

Which of the following is NOT a common cybersecurity metric?

  1. Number of security incidents

  2. Mean time to detect (MTTD)

  3. Mean time to respond (MTTR)

  4. Return on security investment (ROSI)

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Return on security investment (ROSI) is not a common cybersecurity metric. This is because it is difficult to accurately measure the return on investment in cybersecurity.

Multiple choice

Which of the following is NOT a key component of cybersecurity governance?

  1. Risk assessment

  2. Policy development

  3. Incident response

  4. Compliance management

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

Incident response is a process for responding to and managing cybersecurity incidents. It is not a key component of cybersecurity governance, which is focused on establishing and maintaining a framework for managing cybersecurity risks.

Multiple choice

Which of the following is NOT a common cybersecurity metric?

  1. Mean time to detect (MTTD)

  2. Mean time to respond (MTTR)

  3. Number of security incidents

  4. Cost of security breaches

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

The cost of security breaches is not a common cybersecurity metric. This is because it is difficult to accurately measure the cost of a security breach.

Multiple choice

Which of the following is NOT a common authorization mechanism?

  1. Access Control Lists (ACLs)

  2. Capabilities

  3. Tokens

  4. Biometrics

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Biometrics is not a common authorization mechanism. ACLs, Capabilities, and Tokens are more commonly used.

Multiple choice

Capabilities are typically implemented using:

  1. Cryptographic keys

  2. Tokens

  3. Certificates

  4. All of the above

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Capabilities are typically implemented using cryptographic keys.