Computer Knowledge ยท General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
-
It causes a fake web page.
-
It can be used to get the password of the victims.
-
It might bypass logins.
-
The attacker copies the source code to spread such attack.
-
It is created due to uploading of the webpage to any free web hosting sites.
-
Accessing the secret data
-
By passing the logins
-
Modifying the contents of website
-
Displaying repeated error messages
-
Shutting down the my SQL server
-
Social Engineering
-
Port Scanning
-
Brute Force Attack
-
Keylogger
-
Guessing a answer for the security question
-
It is self-replicating.
-
It has no population growth.
-
It might be present in the system memory.
-
It might consume disk space.
-
It works like malware.
-
Slowing down of the system
-
Problem in shut down or restart
-
lot of pop-up ads
-
Unusable web pages
-
DOS attack
-
It protects against web-based application attacks.
-
It identifies the potentially dangerous or malforms attacked towards a given web application.
-
It uses many bypass techniques for such execution.
-
It also identifies the malicious worms.
-
It is a defensive measure implemented into most operating systems and prevents execute permission when an overwrite in the memory has occurred.
E
Correct answer
Explanation
Web Application Firewall (WAF) is not implemented in operating systems.
-
Locations assessment
-
Security guards to be bypassed
-
Entrances into the building
-
Video cameras
-
Login systems
E
Correct answer
Explanation
Login systems accessibility is checked in the Web Application Penetration Test.
-
It occurs due to improper coding techniques.
-
It occurs due to closing of application by the exception handler.
-
It is a technique of identifying what type of information is being sent.
-
It uses data execution prevention (DEP) in its execution.
-
This exploit is not present during penetration testing.
B
Correct answer
Explanation
This is correct and SEH Overwrites exploit is caused when the structured exception handler begins to gracefully close an application.
-
To gather relevant documentation
-
To encode the method of obfuscating data
-
Identify and categorize primary and secondary assets
-
Identify and categorize threats and threat communities
-
Map threat communities against primary and secondary assets
B
Correct answer
Explanation
This is not a part of Threat modelling approach. It does not encode any method.
-
Total number of IP addresses
-
Attempt to gain the highest privileges
-
Specific compliance requirement
-
Status of the devices in place that may impact the results of a penetration test
-
Physical security measures
E
Correct answer
Explanation
Network Penetration Test does not measure the physical security. It comes under Physical Penetration Test.
-
It occurs during a physical penetration test.
-
It provides the gaining access to the social engineer.
-
Organisation business information is necessary for such exploit.
-
It is an attempt to circumvent physical security controls.
-
It is the part of intelligence gathering phase.
D
Correct answer
Explanation
This is true about 'Physical Access' exploit. 'Human Angle' does not check physical security controls.
-
It is used in order to escape detection during a penetration test.
-
It uses Intrusion Detection Systems (IDS) or Intrusion Prevention Systems (IPS) to encode the request.
-
It circumvents web application firewalls.
-
This technique is necessary for a successful test.
-
This technique uses a method to inject into an already running process.
E
Correct answer
Explanation
Evasion technique does not use such method for any running process. Process Injection technique is responsible for that.
-
This type of attack often represents a highly advanced organization.
-
It recreates a protocol or application and attempts to send data at the application.
-
This attack is possible due to countermeasure technology.
-
There should be some countermeasures and the relevant operating system to perform such exploit.
-
Zero-day angle exploit is often a last resort for most penetration testers.
B
Correct answer
Explanation
'Zero-Day Angle' does not recreate or attempt to send any protocol to any application. Fuzzing uses such protocols.
-
It is used to prevent the malicious software from being deployed on the system.
-
It is used to obfuscate data in a way that the deployed piece of code does not appear the same.
-
It is an attempt to re-arrange data to compress the application or pack it.
-
It leveraged a trusted model for applications that have been seen on a given system at a time.
-
It uses encryption methods.
D
Correct answer
Explanation
This technique takes a baseline of the system and identifies what is normal to be run on the system versus what is something foreign.
-
It uses a method to inject the running application.
-
The information of the application can be hidden within a process.
-
The running processes can not be inspected easily.
-
It is implemented into most operating systems and prevents execute permission when an overwrite in memory has occurred.
-
It is used to hide in a different process that the application would think is a trusted one.
D
Correct answer
Explanation
This is incorrect about 'Process injection'. Data Execution Prevention (DEP) is responsible for that.