Computer Knowledge · General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
-
These programs capture data from information packets.
-
These programs infect the computer with the intruders.
-
These are used by intruders to gain remote access to the computer.
-
These programs cause the computer to crash or make it busy in processing data.
-
Using these programs, a malicious web developer may attach a script to something sent to a website.
B
Correct answer
Explanation
Trojan horse programs allow intruders easy access to the computer and change the system configurations.
-
This attack is spread by using the web URL.
-
By this attack, a malicious script is transferred to the browser.
-
This type of attack is very harmful for e-mails or other forms.
-
It can be used by intruders to gather information.
-
Due to this attack, the generated pages are affected where users can post text containing HTML tags.
D
Correct answer
Explanation
This attack cannot be used by intruders for such information.
-
The forging packets can be modified in this attack.
-
This attack is performed by a single forged packet.
-
It causes the changes in the domain names for the respective IP addresses.
-
No web traffic is analysed in this attack.
-
It affects the IP configuration.
C
Correct answer
Explanation
In this attack, the DNS server is spoofed to alter entries of domain names to reflect the attackers’ IP address.
-
This attack can be spread in a multitude of systems.
-
It denies service to the system to legitimate users.
-
It can exploit a vulnerability in one computer system and makes it the DDoS master.
-
A network-centric attack overloads a service by using up bandwidth and an application-layer attack, which overloads a service or database with application calls.
-
It gains malicious access to resources, applications or databases.
E
Correct answer
Explanation
SQL injection attack gains malicious access to resources, applications or databases. DDoS attack does not exploit database.
-
In this attack, the attacker makes independent connections with the victims.
-
It is an attack on mutual authentication.
-
It includes some form of endpoint authentication.
-
It does not affect the transaction processing.
-
SSL can authenticate one or both parties using a mutually trusted certification authority.
D
Correct answer
Explanation
A MITM attack exploits the real time processing of transactions.
-
It involves sniffing data packets to steal session cookies.
-
It has the cookies which can contain encrypted login information.
-
The attacker can launch a man-in-the-middle attack, intercepting all data between you and the network.
-
This involves a malicious actor using readily available software to intercept data being sent from or to the device.
-
It involves data synchronisation.
A
Correct answer
Explanation
Sidejacking attack involves sniffing data packets to steal session cookies and hijack a user’s session.
-
It is a flaw in software, hardware or firmware that is exploited.
-
It shows that there are zero days between the time the vulnerability is discovered and the first attack.
-
It is caused due to invalid software codes.
-
This attack can cause the website to slow down.
-
It occurs at the same time as vulnerability.
D
Correct answer
Explanation
This attack does not slow the website or any server.
-
In this attack, the vulnerability becomes generally known.
-
There are zero days between the time the vulnerability is discovered and the first attack.
-
Hackers can also discover the vulnerability.
-
The vulnerability is not known in advance.
-
It can obtain any unencrypted information.
E
Correct answer
Explanation
This is incorrect as this attack cannot obtain any unencrypted information.
-
Virtual LAN/IPsec can be used to reduce this attack
-
Deploying an intrusion detection system (IDS) helps to reduce this attack.
-
Locking down wireless access points helps to remove this attack.
-
Maximising protection against wireless-based attacks helps prevent this attack.
-
Applying cryptographic techniques can reduce this attack.
E
Correct answer
Explanation
Cryptographic techniques are not useful to reduce this attack.
-
It has the malicious actor using readily available software to intercept data.
-
The attacker can launch a man-in-the-middle attack, intercepting all data between the user and the network.
-
It can decrypt login information.
-
This attack is performed by repeatedly executing invalid data.
-
This is a form of Session Hijacking attack.
A
Correct answer
Explanation
This involves a malicious actor using readily available software to intercept data being sent from or to the device.
-
Barcode
-
Decoder
-
Encryption
-
Mnemonics
-
None of these
C
Correct answer
Explanation
It is the conversion of data into a secret code for transmission over a network. It can't be easily understood if intercepted.
-
Ergonomics
-
Encapsulation
-
Emulation
-
Encryption
D
Correct answer
Explanation
Encryption is the process of converting plaintext data into coded form (ciphertext) to prevent unauthorized access during storage or transmission. Only authorized parties with the decryption key can recover the original data. Ergonomics (Option A) relates to user comfort, Encapsulation (Option B) is an OOP concept for bundling data and methods, and Emulation (Option C) mimics one system on another.
-
Scanning
-
Foot printing
-
Printing
-
Exploits
-
Trojan horses
B
Correct answer
Explanation
The art of gathering complete security profiles of an organisation or a target computer is called footprinting.
-
Scanning
-
Port scanning
-
Trojan horses
-
DOS [denial of service] attack
-
Exploits
D
Correct answer
Explanation
Win spoof a7 is a DOS attack.
-
Bo2k
-
Shadow security scanner
-
My spoof
-
Perl scripts
-
Ratina
A
Correct answer
Explanation
It is a type of trojan horse.