Computer Knowledge · General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
-
Update the IOS images.
-
Change console passwords.
-
Employ end-user authentication.
-
Configure routing protocol authentication.
D
Correct answer
Explanation
When falsified routing information propagates through a network, it indicates that unauthorized or malicious routers are injecting incorrect routing data. The most effective mitigation is routing protocol authentication, which ensures that only trusted routers can participate in the routing process. Authentication methods like MD5 or plain text passwords verify the identity of routing peers before accepting their updates. Changing console passwords or updating IOS images address different security concerns (access control and software vulnerabilities respectively), while end-user authentication is unrelated to routing protocol security.
-
QoS
-
Latency
-
Reliability
-
Confidentiality
D
Correct answer
Explanation
VPN technology uses encryption and tunneling protocols to provide confidentiality, which prevents unauthorized parties from reading the contents of data communications. Even if traffic is intercepted, the encrypted data is unreadable without the decryption keys. QoS manages traffic priority, latency refers to delay, and reliability ensures delivery - none of these prevent data from being read if intercepted.
-
Cracking
-
Phishing
-
Phreaking
-
Spamming
B
Correct answer
Explanation
Phishing is a social engineering attack where fraudulent emails appear to come from trusted sources (like the administrator's office) to trick recipients into revealing sensitive information like passwords and account details. The email described matches this pattern exactly. Cracking involves breaking passwords or encryption, phreaking refers to hacking telecommunications systems, and spamming is unsolicited bulk email - none of which involve tricking users into voluntarily revealing credentials.
-
Detect potential attacks
-
Stop the detected attack from executing
-
Update OS patches for computer systems
-
Scan computer systems for viruses and spyware
B
Correct answer
Explanation
The key difference between IDS (Intrusion Detection System) and IPS (Intrusion Prevention System) is that IDS is passive - it only detects and alerts on attacks. IPS is inline and can actively block or prevent detected attacks from executing. This provides real-time protection rather than just notification after the fact.
-
Asymmetric cryptography
-
Symmetric cryptography
-
Cryptographic signing
-
MD5
-
QueryString parameter
A
Correct answer
Explanation
This type of encryption uses a public/private key pair to encrypt and decrypt data.
-
SHA384Cng
-
SHA384
-
SHA384Managed
-
SHA256
-
QueryString parameter
B
Correct answer
Explanation
It computes the secure hash algorithm 384 hash for the input data.
-
SHA512Cng
-
SHA512Managed
-
SHA1CryptoServiceProvider
-
SHA512
-
ProtectedData
D
Correct answer
Explanation
It computes the secure hash algorithm 512 hash for the input data.
-
DSASignatureDeformatter
-
DSA
-
DSASignatureFormatter
-
RSAPKCS1SignatureFormatter
-
ProtectedMemeory
A
Correct answer
Explanation
It verifies a digital signature algorithm PKCS#1 v1.5 signature.
-
FileAuthorizationModule
-
QueryString parameter
-
UrlAuthorizationModule
-
Symmetric cryptography
-
ProtectedData
C
Correct answer
Explanation
This module can be used to selectively allow or deny access to arbitrary parts of an application for specific users or roles.
-
SHA1CryptoServiceProvider
-
SHA1Managed
-
ProtectedData
-
SHA256
-
SHA1
E
Correct answer
Explanation
It computes the secure hash algorithm1 hash for the input data.
-
URL authorization
-
QueryString parameter
-
Cryptographic signing
-
ProtectedData
-
ACL permissions
E
Correct answer
Explanation
These are verified for the user's windows identity or for the windows identity of the ASP.NET process.
-
RSA
-
RSAOAEPKeyExchangeFormatter
-
RSAOAEPKeyExchangeDeformatter
-
AsymmetricKeyExchangeDeformatter
-
ProtectedMemory
A
Correct answer
Explanation
It represents the base class from which all implementations of the RSA algorithm inherit.
-
Password cracking
-
Packet sniffer
-
Spoofing attack
-
Rootkit
-
Trojan horse
B
Correct answer
Explanation
A packet sniffer is an application that captures data packets, which can be used to capture passwords and other data in transit over the network.
-
Strong authentication controls
-
Access controls
-
Error checking controls
-
Do risk analysis
-
All of the above
-
spam
-
trojan horse
-
international tampering
-
junk mail
-
bug
A
Correct answer
Explanation
Yes, it is correct choice. Spam is a threat email .