Computer Knowledge ยท General Awareness
Information Security
4,634 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
-
Clickjacking/ Videojacking
-
GIFAR
-
Cross Site Scripting
-
Flash Parameter Injection
B
Correct answer
Explanation
GIFAR is a hacking technique that involves combining a GIF image file with a Java archive (JAR) file. This hybrid file can execute malicious code and potentially steal viewer credentials when loaded in a vulnerable browser.
-
Clickjacking/ Videojacking
-
GIFAR
-
Cross Site Scripting
-
Flash Parameter Injection
B
Correct answer
Explanation
This is a duplicate of question 57468. GIFAR is a hacking technique combining GIF and JAR files that can execute malicious code and steal credentials when rendered by vulnerable browsers.
-
Network based
-
Host based
-
Application based
-
Both A & B
D
Correct answer
Explanation
Data Leakage Prevention (DLP) methods include network-based solutions (monitoring network traffic) and host-based solutions (installed on endpoints). Application-based DLP is also a category, making 'Both A & B' the most accurate single choice.
-
Data at rest, in motion and at endpoints
-
Data in USB, on servers and on paper
-
Both of the above
-
Only data in motion
A
Correct answer
Explanation
Data Leakage Prevention solutions can protect data at rest (stored data), in motion (data being transmitted), and at endpoints (devices where data is accessed). This comprehensive coverage is a key feature of enterprise DLP solutions.
-
Employee Training
-
Defining a company wide policy for data handling
-
Implementing encryption and outbound filtering tools for keywords
-
All of the above
D
Correct answer
Explanation
Besides technical DLP solutions, organizations should implement employee training on data handling, establish company-wide data policies, and use encryption with outbound filtering. A holistic approach combining people, process, and technology is most effective.
-
Phishing
-
E-mail bomb
-
Spam
-
All of the above
D
Correct answer
Explanation
Phishing tricks users into revealing credentials through fake emails, compromising email security. E-mail bombs flood systems with massive volumes to cause denial-of-service. Spam consumes bandwidth and storage, making it harder to identify legitimate emails. All three attack vectors weaken corporate email systems.
-
Directing users to enter details in a fake website, sent in an e-mail, whose look and feel are almost identical to the legitimate one
-
Form of net abuse consisting of sending huge volumes of e-mail to an address in an attempt to overflow the mailbox or overwhelm the server where the email address is hosted in a denial-of-service attack
-
Fraudulent e-mail in which the sender address and other parts of the e-mail header are altered to appear as though the e-mail originated from a different source
-
Sending unsolicited messages consuming band-width and slowing down e-mail systems, making it difficult for the owner to see legitimate e-mails
B
Correct answer
Explanation
An e-mail bomb is a denial-of-service attack where an address is sent huge volumes of email to overflow the mailbox or overwhelm the hosting server. Phishing (A) involves fake websites to steal credentials. Spoofing (C) alters email headers to fake the sender. Spam (D) is unsolicited bulk mail.
-
Lexicographer Attack
-
Cafe Latte Attack
-
All except A
-
Man in the Middle attack
C
Correct answer
Explanation
WAPs are vulnerable to multiple attacks: Cafe Latte (exploits WEP to generate packets), Man-in-the-Middle (intercepts communications), and various replay/forgery attacks. Lexicographer attack is not a recognized WAP vulnerability - it's either a distractor or refers to something unrelated to wireless security.
-
To protect reputation and brand
-
Ensure business continuity
-
Protect IT infrastructure and critical data
-
All of the above
D
Correct answer
Explanation
Vulnerability Management protects reputation by preventing security breaches, ensures business continuity by minimizing disruption, and safeguards IT infrastructure and data from exploitation. It is a foundational cybersecurity practice.
-
Analyze, Identify, Mitigate, Monitor
-
Identify, Analyze, Mitigate, Manage
-
Analyze, Identify, Manage, Mitigate
-
Monitor, Analyze, Mitigate, Manage
B
Correct answer
Explanation
The Vulnerability Management Lifecycle begins with identifying vulnerabilities, then analyzing their severity and exploitability, mitigating through patching or other controls, and ongoing management. Monitoring is continuous but not a sequential step.
-
Fault Tree Analysis (FTA)
-
Probability Risk Assessment (PRA)
-
Failure Mode and Effect Analysis (FMEA)
-
Operationally Critical Threat, Asset and Vulnerability (OCTAVE)
-
Cyber Crimes and Intellectual Property
-
Electronic and Digital Signature
-
Data Protection and Privacy Laws
-
All of the above
D
Correct answer
Explanation
Cyber law encompasses multiple domains including criminalizing cyber offenses, protecting intellectual property in digital formats, regulating electronic and digital signatures for transactions, and establishing data protection and privacy frameworks. All listed domains fall under cyber law.
-
Hackers compromising search engines
-
Reverse software engineering
-
Cracking of licensed software
-
Another name for DNS spoofing
A
Correct answer
Explanation
SEO poisoning (also called search engine poisoning) is a technique where hackers manipulate search engine results to rank malicious websites highly. When users search for legitimate topics, they click these poisoned links and get infected with malware. It does not involve compromising search engines directly, reverse engineering, software cracking, or DNS spoofing.
-
Social Networking Site attacks
-
Rogue Security software
-
Drive by downloads
-
All of the above
D
Correct answer
Explanation
2009 saw significant social networking attacks on platforms like Facebook and Twitter, widespread rogue security software scams (fake antivirus), and drive-by downloads where malware automatically infected visitors to compromised websites. All three were major attack vectors that year.
-
Firewall
-
Good Password
-
Updated software
-
VLAN
D
Correct answer
Explanation
Firewalls, strong passwords, and updated software all directly improve computer security by blocking threats, preventing unauthorized access, and patching vulnerabilities. VLAN is a network segmentation technology for organizing networks, not a security tool.