Computer Knowledge · General Awareness
Information Security
4,143 Questions
Information security involves protecting computer systems and data from unauthorized access, cyber threats, and damage. It is a core part of the computer knowledge section in various banking and government exams. Practicing these concepts helps in understanding digital signatures, network security, and access control effectively.
Cybersecurity threatsAccess controlCryptography basicsSecurity risk managementDatabase protection
Information Security Questions
-
It involves gathering information regarding a potential target without the targeted individual’s or company’s knowledge.
-
It involves probing the network to discover individual hosts, IP addresses and services on the network.
-
In this phase, once a hacker has gained access, they want to keep that access for future exploitation and attacks.
-
It involves taking the information discovered during reconnaissance and using it to examine the network.
-
Both (3) and (4)
C
Correct answer
Explanation
This is correct about 'Maintaining Access phase' of hacking.
-
In this phase, once a hacker has gained access, they want to keep that access for future exploitation and attacks.
-
It involves taking the information discovered during reconnaissance and using it to examine the network.
-
It involves gathering information regarding a potential target without the targeted individual’s or company’s knowledge.
-
In this phase, the vulnerabilities discovered during the reconnaissance and scanning phase are now exploited to gain access.
-
None of the above
D
Correct answer
Explanation
This is true about 'Gaining Access'. This is a process in which access provides for the vulnerabilities and other exploits after filtration of the reconnaissance and scanning phase.
-
It is the process by which security flaws in technology are identified.
-
It involves reverse engineering process.
-
Any technology vendor can use vulnerability research services.
-
All of the above
-
Both (1) and (3)
D
Correct answer
Explanation
All are the correct statements about Vulnerability Research in Ethical Hacking.
-
The attacks on Voice over IP (VoIP).
-
The attacks on the mail server and web apps.
-
Several protocol attacks.
-
Exploiting specific network protocol implementations.
-
Both (3) and (4)
D
Correct answer
Explanation
This is an Operating system attack and not Application level attack. Network protocols can affect OS issues mostly.
-
Port Scanning is used to find out the vulnerabilities in the services listing on a port.
-
In this scanning, the associate resources find out the parts of the target organisation.
-
This scanning involves connecting with TCP and UDP ports on a system.
-
The most common and popular tool is Nmap in Port scanning.
-
All of the above
E
Correct answer
Explanation
All are the correct statements about Port Scanning in Ethical Hacking.
-
In this process, the hackers cover their tracks to avoid detection by security personnel.
-
In this process, the hackers remove all traces of the attack, such as log files or intrusion detection system (IDS) alarms.
-
In this process, once the hacker owns the system, they can use it as a base to launch additional attacks.
-
The steganography, the use of tunneling protocols and altering log files are the example of such processes.
-
Both (2) and (3)
C
Correct answer
Explanation
This is incorrect statement about 'Covering Tracks' process in hacking and this is known as 'Maintaining access'.
-
Hacking is a breach of computer security.
-
Hackers may even delete sensitive information on gaining access to it.
-
Identity theft is another important consequence of computer hacking.
-
It can lead to theft of critical business information.
-
All of the above
E
Correct answer
Explanation
All are the scenarios of Computer hacking.
-
The attacks on Voice over IP (VoIP).
-
Exploiting specific network protocol implementations.
-
Installing a network analyzer on a network and capturing every packet.
-
Flooding a network with multiple requests.
-
Both (3) and (4)
E
Correct answer
Explanation
These are Network infrastructure attacks in Ethical Hacking.
-
The attacks on Voice over IP (VoIP).
-
Exploiting specific network protocol implementations.
-
Attacking built-in authentication systems.
-
Breaking file system security.
-
Option (2), (3) and (4)
E
Correct answer
Explanation
These are the OS level attacks in Ethical hacking.
-
To determe the feasibility of a particular set of attack vectors.
-
Penetration tester identifies all level vulnerabilities for a successful exploit.
-
Assessing the magnitude of potential business and operational impacts of successful attacks.
-
All of the above
-
Both (1) and (2)
D
Correct answer
Explanation
These are the causes to apply Penetration test in Ethical Hacking.
-
The attack may be directed to a specific computer addressed as though it is from that same computer.
-
In this attack, the hackers may be able to break through other friendly but less secure networks and get access to your network using this method.
-
This attack may cause the IP address location ambiguity.
-
All of the above
-
Both (1) and (3)
E
Correct answer
Explanation
These are the correct statements about IP spoofing attack in hacking.
-
In this attack, the attacker uses the authentication to track the session information.
-
In this attack, the attacker may fake their IP address so the receiver thinks it is sent from a location that it is not actually from.
-
This is an attack where DNS information is falsified.
-
This attack may cause unauthorized access in the system.
-
Both (1) and (4)
D
Correct answer
Explanation
By Password cracking attack, the attacker gets the password of a user or administrator on a network and gain unauthorized access.
-
In this attack, the attacker uses the LANMAN authentication to get information about the credentials of the network packets.
-
By this attack, the attacker gets the password of a user or administrator on a network and gain unauthorized access.
-
In this attack, the attacker may fake their IP address so the receiver thinks it is sent from a location that it is not actually from.
-
Both (1) and (2)
-
None of the above
A
Correct answer
Explanation
This is correct as If the client is tricked into sending LANMAN authentication, the attacker can read their username and password from the network packets sent.
-
In this attack, the attacker uses the authentication to track the session information.
-
In this attack, the attacker may fake their IP address so the receiver thinks it is sent from a location that it is not actually from.
-
This is an attack where DNS information is falsified.
-
By this attack, the attacker gets the password of a user or administrator on a network and gain unauthorized access.
-
None of the above
A
Correct answer
Explanation
This is correct as once authentication is complete, they may attack the client computer to disable it, and use IP spoofing to claim to be the client who was just authenticated and steal the session.
-
GET
-
Proxy object
-
Burp sequencer
-
Burp repeater
-
Burp intruder target tab
C
Correct answer
Explanation
This is a tool for analysing the degree of randomness in security critical tokens issued by an application.