Computer Knowledge · General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice
  1. This attack is an attempt to make a computer resource unavailable to its intended users.

  2. This attack is done by overloading the resource.

  3. It allows attackers to inject code into web pages viewed by other users.

  4. It does not allow attackers to inject code into web pages viewed by other users.

  5. Both (1) and (2)

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

These are the correct statements about the DoS attack in web applications.

Multiple choice
  1. Installing patches regularly and timely

  2. By using automated test tools

  3. By using dynamic SQL only

  4. Escape user input

  5. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Escaping user input is less effective than parameterized queries and stored procedures in case of SQL injection attack. All are the techniques to handle the SQL injection attack.

Multiple choice
  1. Security researches are used typically to find vulnerability in the system.

  2. Security research has the similar tools that the penetration testing has.

  3. Security researches have more time than penetration test.

  4. It makes sure you check your country’s legislation before you start researching and especially before you publish any research.

  5. All of the above

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

All are correct statements.

Multiple choice
  1. Vulnerability can be as simple as weak passwords.

  2. Buffer overflows

  3. SQL injection

  4. Security hole in a piece of software, hardware or operating system

  5. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

These problems may affect the target system requirement so these are often tested by penetration tools.

Multiple choice
  1. This tool determines whether sufficient encryption is employed and whether a piece of software contain any application backdoors through hard-coded user names or passwords.

  2. Veracode's binary scanning approach produces more accurate testing results.

  3. This tool performs both dynamic and static code analysis.

  4. All of the above

  5. Both (1) and (3)

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

All statements are applicable for veracode tool.

Multiple choice
  1. When the threats and vulnerabilities have been evaluated, then design the penetration testing to address the risks identified throughout the environment.

  2. Penetration testing should be appropriate for the complexity and size of an organisation.

  3. Penetration testing determines if there is any unauthorised access to key systems and files can be achieved.

  4. The penetration testing can be re-performed until the test is clean and no longer allows unauthorised access or other malicious activity.

  5. All of the above

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

All are the correct statements.

Multiple choice
  1. 'White hat' is a penetration strategy.

  2. It identifies a security weakness in a computer system or network.

  3. The white hat hacker may work as a consultant or be a permanent employee on a company's payroll.

  4. All of the above

  5. Only (1) and (3)

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

All are correct statements about 'white hat'.

Multiple choice
  1. Non repudiation

  2. The certificate scheme

  3. Transport layer security

  4. Stateful inspection firewall

  5. Guard

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

This security technique provides activity such as a university wants to allow its students to use email up to a limit of so many messages or so many characters of email in the last so many days.

Multiple choice
  1. Message authentication code

  2. Transport layer security

  3. Secure electronic transaction

  4. Proc-Type

  5. Stateful inspection firewall

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

This security mechanism includes vital attributes required for secure over the internet credit-card transactions such as confidentiality of information, merchant authentication etc.......