Computer Knowledge · General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
-
Stateful inspection firewall
-
Packet filtering gateway
-
Message integrity check
-
Secure electronic transaction
-
Sender authenticity
A
Correct answer
Explanation
This security mechanism maintains state information from one packet to another in the input stream.
-
The certificate scheme
-
DEK-Info
-
Packet filter gateway
-
Pretty good privacy processing
-
ProtectedData
D
Correct answer
Explanation
The PGP processing generates a session key at random depending on whether confidentiality, integrity, etc.
-
It includes enforce policy-based encryption of files as they are copied in real-time to USBs.
-
It includes scanning of backup images for confidential data.
-
It includes incident data that can be imported into control compliance suite to identify systems that may be subject to technical control policies.
-
It includes mobile management to enforce virtual private network settings on mobile devices.
-
It uses messaging gateway to release and route quarantined messages directly from the DLP enforce platform.
B
Correct answer
Explanation
Data loss prevention integrates with backup exec system recovery to enable scanning of backup images for confidential data.
-
It includes scanning of backup images for confidential data.
-
It is used to identify systems that may be subject to technical control policies based on the data that is stored in them.
-
It includes enforce policy-based encryption of files as they are copied in real-time to USBs.
-
It uses messaging gateway to release and route quarantined messages directly from the DLP enforce platform.
-
It includes mobile management to enforce virtual private network settings on mobile devices.
B
Correct answer
Explanation
This is correct as the incident data can be imported into control compliance suite to identify systems that may be subject to technical control policies based on the data that is stored in them.
-
It is used to keep the email confidential, simplify compliance, and reduce management costs.
-
It protects PCs, USB devices and removable media with full disk encryption.
-
It provides an efficient and easy-to-use encryption service to keep the data safe in public and private clouds.
-
It does not belong to enterprise data protection.
-
It is used with VMware vSphere virtual environments.
B
Correct answer
Explanation
This is correct, as it provides file encryption and removable media encryption, so that if lost or stolen, your data remains secure.
-
Integrated data loss prevention
-
Mobile security
-
Endpoint encryption
-
VLAN security
-
Email encryption gateway
D
Correct answer
Explanation
EDP does not provide VLAN security.
-
It is used to provide mobile security for all the data and applications.
-
It is an important part of endpoint security.
-
It enforces compliance and prevents data loss from lost or stolen mobile devices.
-
It provides an efficient and easy-to-use encryption service to keep your data safe in public and private clouds.
-
It is a component of the enterprise data protection.
D
Correct answer
Explanation
Trend Micro™ mobile security does not work for cloud security.
-
IRM prevents the leakage of sensitive information to others.
-
It uses the encryption techniques to secure the documents.
-
The authorised users can have their access revoked at any time.
-
IRM protection does not require any document to be encrypted.
-
It is suitable to sensitive data and triggers the IRM encryption process.
D
Correct answer
Explanation
This is incorrect, as IRM protection requires documents to be encrypted.
-
It includes discover and protects confidential data stored on file shares, databases, and repositories.
-
The policy-based encryption and digital rights management are required for such security.
-
Scanning of files or documents is used for that.
-
It also uses encryption techniques to secure the files.
-
The business data owners can not review such network file policy violations directly from an intuitive online portal.
E
Correct answer
Explanation
It enables business data owners to review and remediate network file policy violations directly from an intuitive online portal.
-
It extends the existing security with single-click deployment of data loss prevention (DLP).
-
It provides device security also.
-
It does not provide central management for security and data protection.
-
DLP policies can be enforced across multiple layers of security to prevent data loss.
-
It also provides security for microsoft sharepoint.
C
Correct answer
Explanation
Integrated DLP technique provides central management for security and data protection.
-
Email and the web can cause data loss.
-
For email and web security, the detection of the data in the networking medium is needed.
-
The users are not informed for the security policy violations while detecting the confidential data.
-
Encryption gateways should be separated to secure the emails.
-
Web security can be maintained by securing data from the HTTP protocol.
C
Correct answer
Explanation
Network prevents email detection of confidential data and notifies users of policy violations.
-
It is used to protect the data used within the network or in the network.
-
This technique is used to scan and protect the confidential data.
-
Endpoint agent monitors a wide range of user events on physical endpoints.
-
It does not protect the shared data.
-
It monitors the data transferred through the microsoft remote desktop protocol (RDP).
D
Correct answer
Explanation
Endpoint prevents confidential data from being copied or shared inappropriately over email, removable storage.
-
It is used to prevent leaks of sensitive information.
-
The monitoring and blocking DLP components run either on the network or on endpoints.
-
DLP is used for the organisations that have all internal knowledge about the stored information.
-
It can not block access of previously bypass information to the third parties.
-
DLP provides decisions about content at a point in time.
C
Correct answer
Explanation
DLP is used where an organisation doesn't know where its sensitive information is being stored or sent.
-
It uses an arbitrary authentication method, such as certificates, smart cards or credentials.
-
It is used in certificate-based security environments.
-
It uses a mutual authentication method that supports password-based user or computer authentication.
-
It uses an authentication method that uses TLS to enhance the security of other authentication protocols.
-
It provides security violations.
A
Correct answer
Explanation
This is correct for EAP and it is used to secure the smart cards and other personnel credentials.
-
Firewall
-
VLAN
-
Good Password
-
Updated software
B
Correct answer
Explanation
A Virtual LAN (VLAN) is a network segmentation technique used within organizations, not a personal computer security measure. While VLANs improve network security by isolating traffic, the question asks about 'your computer's' personal security - which is protected by firewalls, strong passwords, and updated software. The other options are direct personal security tools.