Computer Knowledge · General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
-
Directing users to enter details in a fake website, sent in an e-mail, whose look and feel are almost identical to the legitimate one
-
Form of net abuse consisting of sending huge volumes of e-mail to an address in an attempt to overflow the mailbox or overwhelm the server where the email address is hosted in a denial-of-service attack
-
Fraudulent e-mail in which the sender address and other parts of the e-mail header are altered to appear as though the e-mail originated from a different source
-
Sending unsolicited messages consuming band-width and slowing down e-mail systems, making it difficult for the owner to see legitimate e-mails
B
Correct answer
Explanation
An e-mail bomb is a denial-of-service attack where an address is sent huge volumes of email to overflow the mailbox or overwhelm the hosting server. Phishing (A) involves fake websites to steal credentials. Spoofing (C) alters email headers to fake the sender. Spam (D) is unsolicited bulk mail.
-
Lexicographer Attack
-
Cafe Latte Attack
-
All except A
-
Man in the Middle attack
C
Correct answer
Explanation
WAPs are vulnerable to multiple attacks: Cafe Latte (exploits WEP to generate packets), Man-in-the-Middle (intercepts communications), and various replay/forgery attacks. Lexicographer attack is not a recognized WAP vulnerability - it's either a distractor or refers to something unrelated to wireless security.
-
Cyber Crimes and Intellectual Property
-
Electronic and Digital Signature
-
Data Protection and Privacy Laws
-
All of the above
D
Correct answer
Explanation
Cyber law encompasses multiple domains including criminalizing cyber offenses, protecting intellectual property in digital formats, regulating electronic and digital signatures for transactions, and establishing data protection and privacy frameworks. All listed domains fall under cyber law.
-
Hackers compromising search engines
-
Reverse software engineering
-
Cracking of licensed software
-
Another name for DNS spoofing
A
Correct answer
Explanation
SEO poisoning (also called search engine poisoning) is a technique where hackers manipulate search engine results to rank malicious websites highly. When users search for legitimate topics, they click these poisoned links and get infected with malware. It does not involve compromising search engines directly, reverse engineering, software cracking, or DNS spoofing.
-
Social Networking Site attacks
-
Rogue Security software
-
Drive by downloads
-
All of the above
D
Correct answer
Explanation
2009 saw significant social networking attacks on platforms like Facebook and Twitter, widespread rogue security software scams (fake antivirus), and drive-by downloads where malware automatically infected visitors to compromised websites. All three were major attack vectors that year.
-
Firewall
-
Good Password
-
Updated software
-
VLAN
D
Correct answer
Explanation
Firewalls, strong passwords, and updated software all directly improve computer security by blocking threats, preventing unauthorized access, and patching vulnerabilities. VLAN is a network segmentation technology for organizing networks, not a security tool.
-
mcafee
-
Symantec
-
kaspersky
-
avg
B
Correct answer
Explanation
Symantec's 'Be Fearless' campaign promoted their cybersecurity solutions as enabling users to navigate the digital world confidently without fear of threats. The tagline was widely used in their marketing materials during the 2000s.
-
Black Hat
-
White Hat
-
Grey Hat
-
All of the above
D
Correct answer
Explanation
Hackers are ethically classified by their intentions: Black Hat (malicious), White Hat (authorized security professionals), and Grey Hat (operates between ethical boundaries, sometimes without permission but no malicious intent). Since all three categories represent legitimate hacker classifications, 'All of the above' is the correct answer.
-
Zombie
-
Spoofing
-
DoS
-
Smurf Attack
C
Correct answer
Explanation
Denial of Service (DoS) is an attack where a hacker makes computer resources unavailable to intended users by overwhelming systems with traffic or exploiting vulnerabilities to crash services. Options A, B, and D (Zombie, Spoofing, Smurf) are specific techniques or related attacks, but DoS is the general term for the resource unavailability objective.
-
Credit card numbers
-
Social security numbers
-
Phone numbers
-
Anything you wouldn't want shared with unknown parties, like social security numbers, credit card numbers, addresses, personal information
D
Correct answer
Explanation
Email is inherently insecure and can be intercepted or forwarded unexpectedly. Never include sensitive information like social security numbers, credit card numbers, passwords, or personal addresses in email messages.
-
To provide a master security to all users and informations of the client
-
The right our costumers and employees have to protect they PI from misuse or disclosure.
-
Protect information received from the client and delivered to it.
-
Addition to protecting information, but the workplace, so caring staff and users
B
Correct answer
Explanation
Privacy in the context of database management refers to protecting Personal Information (PI) from unauthorized access, use, or disclosure. Option B correctly captures this as the right of customers and employees to protect their personal information. Options A, C, and D are either too vague, grammatically incorrect, or miss the core concept of privacy as protecting individual's personal data.
-
Personal Information means protecting professional information to customer
-
Means working with security of all information involved in the Project
-
Protect the quality of information generated in the Project, Orly for Deutsche Bank Brazil
-
Customer or employee PI is any information concerning the personal or material circumstances of an identified individual (customer or employee).
D
Correct answer
Explanation
Personal Information (PI) encompasses any data that relates to an identified or identifiable individual, including both personal circumstances (like address, phone number) and material circumstances (like financial information). Option D correctly defines PI as information concerning personal or material circumstances of identified individuals (customers or employees). Options A, B, and C incorrectly focus on protection processes rather than defining what constitutes personal information.
-
digital signature
-
smart card
-
public key
-
password
-
signature file
D
Correct answer
Explanation
A password should contain at least one digit and not match a natural language word for security. Strong passwords mix uppercase, lowercase, numbers, and special characters. Avoiding dictionary words makes them resistant to dictionary attacks. Digital signatures and public keys are cryptographic concepts, not passwords.
-
They are the evildoers or the bad guys of hacking.
-
They do ethical hacking for helping security personnels.
-
They are generally evidoers but posed as ethical hackers
-
These are the persons who posseses grey matter.
C
Correct answer
Explanation
Grey hat hackers occupy an ethical middle ground - they may break laws or ethics but not for malicious purposes. They might hack without permission to expose vulnerabilities, sometimes claiming it's for security. Unlike white hats (ethical hackers with permission) or black hats (malicious hackers), grey hats operate in the grey area between legal and illegal, ethical and unethical.
-
A delicious way to cook potatoes
-
An encrypted value
-
A decryption key
-
None of these