Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
-
Identity management
-
SAML (Security Assertion Markup Language)
-
IdP (Identity Provider)
-
WS-Security
-
Single sign-on
E
Correct answer
Explanation
Single sign-on (SSO) is a property of access control of multiple related, but independent software systems. With this property a user logs in once and gains access to all systems without being prompted to log in again at each of them. Conversely, Single sign-off is the property whereby a single action of signing out terminates access to multiple software systems.
-
Protecting integrity
-
Hierarchy
-
Restricted access
-
Bundling of data and methods
-
Information hiding
B
Correct answer
Explanation
In classical inheritance where objects are defined by classes, classes can inherit attributes and behavior from pre-existing classes called base classes, superclasses, or parent classes. The resulting classes are known as derived classes, subclasses, or child classes. The relationships of classes through inheritance gives rise to a hierarchy.
-
A smart card is embedded an integrated circuits.
-
A smart card can be contactless.
-
Smart cards can serve as ATM cards.
-
Smart cards are not affected by malware.
-
Smart cards can be used as a security token for computers.
D
Correct answer
Explanation
If the account holder's computer hosts malware, the smart card security model may be broken. Malware can override the communication (both input via keyboard and output via application screen) between the user and the application. Man-in-the-browser malware could modify a transaction, unnoticed by the user.
-
Force.com
-
Access control
-
Output reconciliation control
-
Input validation control
-
Transport level encryption
B
Correct answer
Explanation
This security technique applied on database provides guarantee that only those who are authorized can access the data.
-
Virtual machine technology
-
Input validation control
-
Web application firewall
-
Access control list
-
Transport level encryption
C
Correct answer
Explanation
This security mechanism is used to protect against outside attacks launched against the data centre.
-
Hardening of the server
-
Access control list
-
Transport level encryption
-
Output reconciliation control
-
Client server computing
A
Correct answer
Explanation
This security mechanism applied on data is used to protect against known or unknown vulnerabilities in the operating system.
-
Payroll
-
Storage encryption
-
Access control list
-
Transport level security
-
Encryption
B
Correct answer
Explanation
This security mechanism applied on the data is used to protect against unauthorized access at the data center.
-
Virtual machine technology
-
Access control list
-
Change management control
-
Output reconciliation control
-
Input validation control
C
Correct answer
Explanation
This security technique is used to ensure that data cannot be changed without proper agreement.
-
Sales force
-
Physical security
-
Transport level security
-
Encryption
-
Output reconciliation control
B
Correct answer
Explanation
This security mechanism applied on the data is used to protect against illegal physical access to data.
-
Finger prints and palm recognition only.
-
Face recognition and voice recognition only.
-
Hand writing and manual recognition only.
-
Only (1) and (2)
-
All (1), (2) & (3)
E
Correct answer
Explanation
Biometric security uses physiological and behavioral characteristics for authentication. This includes fingerprints (the oldest and most widely used), palm prints, facial recognition, voice patterns, and handwriting/signature recognition. All three options listed are valid biometric modalities used in security systems worldwide.
-
SHA384
-
SHA1Cng
-
SHA256Cng
-
SHA384Cng
-
ProtectedData
D
Correct answer
Explanation
This .NET cryptographic class provides a CNG implementation of the secure hash algorithm for 384-bit hash values.
-
SHA384Managed
-
SHA384
-
SHA256Managed
-
SHA1Managed
-
ProtectedData
A
Correct answer
Explanation
This .NET cryptographic class computes the secure hash algorithm 384 hash for the input data using the managed library.
-
Encryption
-
Security certificate
-
Digital signature
-
Both (2) and (3)
-
None of the above
B
Correct answer
Explanation
It has unique id to identify the website.
-
Integrity
-
Authenticity
-
Auditability
-
Availability
-
None of the above
E
Correct answer
Explanation
All are the essential requirement for the transaction in e-payment system.
-
involves registering a domain name to extort their later sale
-
is prohibited by the US law
-
is prohibited by the Canadian law
-
Both (1) and (2)
D
Correct answer
Explanation
(4) Cybersquatting involves registering a domain name to extort their later sale and is prohibited by the US law.