Computer Knowledge ยท General Awareness

Information Security

4,143 Questions

Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.

Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection

Information Security Questions

Multiple choice
  1. It uses multiple payload sets.

  2. The total number of requests generated by the attack is the product of the number of payloads.

  3. This attack iterates through all payload sets simultaneously.

  4. Both (1) and (3)

  5. Both (1) and (2)

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

These are the correct statements about cluster bomb attack.

Multiple choice
  1. It is used to maintain the security of the database in a shared medium.

  2. It provides a baseline for the security tools related to the organisation.

  3. It is a list or dictionary that provides common names for publicly known information security vulnerabilities and exposures.

  4. The MITRE Corporation maintains CVE and manages the CVE Editorial Board.

  5. All of the above

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

All are correct statements.

Multiple choice
  1. It has the information that includes the related CVE name(s).

  2. It acts like the repository owner and is used to provide a mapping relative to a specific version of CVE.

  3. A user can search using a CVE name to find related information.

  4. Both (1) and (2)

  5. Both (1) and (3)

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

This is correct about 'CVE OUTPUT'.

Multiple choice
  1. It is based on the CVE list to identify the vulnerabilities in the database.

  2. CVE has some numbers, IDs and unique identifier to detect vulnerability from the database.

  3. Security of the database is officially compatible.

  4. The CVE names, which are used as references in the CVE-ID field in all Alerts Vulnerability definitions stored in the Definitions Repository.

  5. All of the above

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

These are correct statements about Security of Database using CVE.

Multiple choice
  1. It is used to identify and store the information related to vulnerabilities in the system.

  2. It collects the information and executes the files for the database specific to the vulnerability monitor.

  3. It checks the version of a started program for vulnerabilities against a special database.

  4. The vulnerability check is performed in the background mode and does not delay the program start.

  5. Both (1) and (2)

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

Both are the correct statements.

Multiple choice
  1. In this approach, all the admin functionality should be remapped onto internal IPs.

  2. It allows SQL tables to be dropped, commands run on SQL servers or the Web server to have privilege escalation vulnerabilities.

  3. This approach is used to identify the common coding errors might allow shell code to be uploaded to attack the server, or malicious files uploaded for other users.

  4. Both (1) and (2)

  5. Both (1) and (3)

Reveal answer Fill a bubble to check yourself
A Correct answer
Explanation

A certain IPs over a VPN functions include content management systems (CMS), server status scripts (server-status) and info scripts or SQL admin programs.

Multiple choice
  1. It is a program to attack the code of the target system.

  2. It includes the buffer flow attacks to target the arbitrary software on the malicious web server.

  3. It is a weakness or flaw in a computer application or operating system that can be exploited to cause the application to operate in a manner unintended by its designers.

  4. All of the above

  5. Both (1) and (2)

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

These are correct statements about 'Exploit'.

Multiple choice
  1. It attacks the target organisation by spreading various malicious codes.

  2. It includes the various spyware, malware and other malicious codes.

  3. It is some flaw in our environment that a malicious attacker could use to cause damage in your organisation.

  4. It is a tool by which an attacker uses a vulnerability to cause damage to the target system.

  5. Both (1) and (2)

Reveal answer Fill a bubble to check yourself
E Correct answer
Explanation

These are the correct statements.

Multiple choice
  1. It is used to provide a network security from the targeted vulnerabilities.

  2. It has a server component with a set of plugins to test various vulnerabilities in remote systems and applications.

  3. It is a multi-threaded, multi-platform web server audit tool.

  4. Both (1) and (2)

  5. All of the above

Reveal answer Fill a bubble to check yourself
D Correct answer
Explanation

Both of these are correct about OpenVAS tool.

Multiple choice
  1. To ensure that no one can read the message except the intended receiver

  2. To assure the receiver that the received message has not been altered in any way from the original

  3. A mechanism to prove that the sender really sent this message

  4. The process of proving one's identity

  5. Both (2) and (4)

Reveal answer Fill a bubble to check yourself
C Correct answer
Explanation

This is correct about non-repudiation and it is used to check the status of the message, sent by the sender.