Computer Knowledge ยท General Awareness

Information Security

4,634 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice general knowledge
  1. Clickjacking/ Videojacking

  2. GIFAR

  3. Cross Site Scripting

  4. Flash Parameter Injection

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

GIFAR is a hacking technique that involves combining a GIF image file with a Java archive (JAR) file. This hybrid file can execute malicious code and potentially steal viewer credentials when loaded in a vulnerable browser.

Multiple choice general knowledge
  1. Clickjacking/ Videojacking

  2. GIFAR

  3. Cross Site Scripting

  4. Flash Parameter Injection

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

This is a duplicate of question 57468. GIFAR is a hacking technique combining GIF and JAR files that can execute malicious code and steal credentials when rendered by vulnerable browsers.

Multiple choice general knowledge
  1. Data at rest, in motion and at endpoints

  2. Data in USB, on servers and on paper

  3. Both of the above

  4. Only data in motion

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

Data Leakage Prevention solutions can protect data at rest (stored data), in motion (data being transmitted), and at endpoints (devices where data is accessed). This comprehensive coverage is a key feature of enterprise DLP solutions.

Multiple choice general knowledge
  1. Employee Training

  2. Defining a company wide policy for data handling

  3. Implementing encryption and outbound filtering tools for keywords

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Besides technical DLP solutions, organizations should implement employee training on data handling, establish company-wide data policies, and use encryption with outbound filtering. A holistic approach combining people, process, and technology is most effective.

Multiple choice general knowledge
  1. Phishing

  2. E-mail bomb

  3. Spam

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Phishing tricks users into revealing credentials through fake emails, compromising email security. E-mail bombs flood systems with massive volumes to cause denial-of-service. Spam consumes bandwidth and storage, making it harder to identify legitimate emails. All three attack vectors weaken corporate email systems.

Multiple choice general knowledge
  1. Directing users to enter details in a fake website, sent in an e-mail, whose look and feel are almost identical to the legitimate one

  2. Form of net abuse consisting of sending huge volumes of e-mail to an address in an attempt to overflow the mailbox or overwhelm the server where the email address is hosted in a denial-of-service attack

  3. Fraudulent e-mail in which the sender address and other parts of the e-mail header are altered to appear as though the e-mail originated from a different source

  4. Sending unsolicited messages consuming band-width and slowing down e-mail systems, making it difficult for the owner to see legitimate e-mails

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

An e-mail bomb is a denial-of-service attack where an address is sent huge volumes of email to overflow the mailbox or overwhelm the hosting server. Phishing (A) involves fake websites to steal credentials. Spoofing (C) alters email headers to fake the sender. Spam (D) is unsolicited bulk mail.

Multiple choice general knowledge
  1. Lexicographer Attack

  2. Cafe Latte Attack

  3. All except A

  4. Man in the Middle attack

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

WAPs are vulnerable to multiple attacks: Cafe Latte (exploits WEP to generate packets), Man-in-the-Middle (intercepts communications), and various replay/forgery attacks. Lexicographer attack is not a recognized WAP vulnerability - it's either a distractor or refers to something unrelated to wireless security.

Multiple choice general knowledge
  1. To protect reputation and brand

  2. Ensure business continuity

  3. Protect IT infrastructure and critical data

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Vulnerability Management protects reputation by preventing security breaches, ensures business continuity by minimizing disruption, and safeguards IT infrastructure and data from exploitation. It is a foundational cybersecurity practice.

Multiple choice general knowledge
  1. Analyze, Identify, Mitigate, Monitor

  2. Identify, Analyze, Mitigate, Manage

  3. Analyze, Identify, Manage, Mitigate

  4. Monitor, Analyze, Mitigate, Manage

Reveal answer Fill a bubble to check yourself
B Correct answer
Explanation

The Vulnerability Management Lifecycle begins with identifying vulnerabilities, then analyzing their severity and exploitability, mitigating through patching or other controls, and ongoing management. Monitoring is continuous but not a sequential step.

Multiple choice general knowledge
  1. Cyber Crimes and Intellectual Property

  2. Electronic and Digital Signature

  3. Data Protection and Privacy Laws

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Cyber law encompasses multiple domains including criminalizing cyber offenses, protecting intellectual property in digital formats, regulating electronic and digital signatures for transactions, and establishing data protection and privacy frameworks. All listed domains fall under cyber law.

Multiple choice general knowledge
  1. Hackers compromising search engines

  2. Reverse software engineering

  3. Cracking of licensed software

  4. Another name for DNS spoofing

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

SEO poisoning (also called search engine poisoning) is a technique where hackers manipulate search engine results to rank malicious websites highly. When users search for legitimate topics, they click these poisoned links and get infected with malware. It does not involve compromising search engines directly, reverse engineering, software cracking, or DNS spoofing.

Multiple choice general knowledge
  1. Social Networking Site attacks

  2. Rogue Security software

  3. Drive by downloads

  4. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

2009 saw significant social networking attacks on platforms like Facebook and Twitter, widespread rogue security software scams (fake antivirus), and drive-by downloads where malware automatically infected visitors to compromised websites. All three were major attack vectors that year.