Computer Knowledge · General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
-
This approach requires to have a shared key for the sender and the receiver.
-
Exchange of keys also possible.
-
It allows the data, without allowing others to see the key.
-
The secure system can be failure in this technique.
-
It also works for asymmetric schemas.
E
Correct answer
Explanation
Key Distribution techniques is not applicable for asymmetric schemas.
-
It uses multiple text blocks.
-
It performs attack by repeatedly encrypting plaintext pairs with known input XOR.
-
This technique is not efficient for large number of rounds.
-
It gives linear equation for key bits.
-
The differential cryptanalysis attack is complex and provides a complete description.
D
Correct answer
Explanation
This is incorrect about Differential Cryptanalysis attack. Linear Cryptanalysis attack uses linear equation for key bits.
-
It is used for content types and texts messages.
-
S/MIME supports in many mail agents.
-
It has signed data to encode messages.
-
It has encrypted content and associated keys.
-
It uses digital signatures with DES algorithm.
E
Correct answer
Explanation
S/MIME uses digital signatures with DSS and RSA algorithms only and not DES.
-
It uses X.509 v3 certificates.
-
Each client has a list of trusted CA’s certificates.
-
Each client has own public/private key pairs and certificates.
-
The certificates must be signed by trusted CA’s.
-
It verifies the incoming signatures and decrypt outgoing messages.
E
Correct answer
Explanation
It encrypts outgoing messages and not encrypt.
-
It is used for email security.
-
It can be used for file storage applications.
-
It does not use digital signature service.
-
It uses RSA algorithm to authenticate the message.
-
It runs on a wide range of systems, in both free and commercial versions.
C
Correct answer
Explanation
This is incorrect as digital signature service is provided by PGP.
-
It uses 2 DES for encryption.
-
Decryption requires that the keys be applied in reverse order.
-
It results in a dramatic increase in cryptographic strength for DES.
-
It uses 2 keys for processing.
-
It is used to provide the potential vulnerability of DES to a brute force attack.
D
Correct answer
Explanation
Double-DES uses a single key that is equivalent to using 2 keys.
-
It occurs where a valid signed message is copied and later resent.
-
The message repetition that can be logged.
-
The message repetition that cannot be detected.
-
It used sequence numbers for the process.
-
There is no timestamp defined in this attack.
E
Correct answer
Explanation
Timestamp is used for synchronised blocks.
-
It must depend on the message signed.
-
It must be practically save digital signature in storage.
-
Security depends on sender’s private-key.
-
The signed message and signature should be encrypted.
-
The message can encrypt using receivers private-key.
E
Correct answer
Explanation
It can only be encrypted by using receiver's public key.
-
It uses a trusted Key Distribution Center (KDC).
-
Each party shares own master key with KDC.
-
There is a session keys is maintained between the parties.
-
The master keys are used to distribute the session keys to both the parties.
-
This approach is useful for more then two senders.
E
Correct answer
Explanation
This is incorrect as there can be only one sender and one receiver.
-
Identification and authentication
-
Lattice model of access security
-
Multilevel security model
-
Protection of memory
-
Security policy
B
Correct answer
Explanation
In lattice model of access security, the dominance relation <= is defined in the military model.
-
Non-repudiation
-
Threat
-
Virus
-
Worm
-
Logic bomb
E
Correct answer
Explanation
This type of malicious code is a class of malicious code that detonates when a specified condition occurs.
-
Mandatory access control
-
Discretionary access control
-
Complete mediation
-
Authentication of users
-
Ease of use
A
Correct answer
Explanation
It means that access control policy decisions are made beyond the control of the individual owner of an object.
-
Object reuse protection
-
Complete meditation
-
Discretionary access control
-
Identification and authentication
-
Message integrity check
A
Correct answer
Explanation
This security feature is used when a malicious user may claim a large amount of disk space and then scavenge for sensitive data.
-
Open design
-
Least privilege
-
Ease of use
-
Authentication of users
-
Message confidentiality
A
Correct answer
Explanation
This principle applied in the design element of OS is also available for extensive public scrutiny, thereby providing independent confirmation of the design security.
-
Packet filtering gateway firewall
-
Secure socket layer
-
Secure electronic transaction
-
Key-Info
-
The certificate scheme
B
Correct answer
Explanation
This security mechanism provides services such as fragmentation, compression, message integrity etc.