Skip to content
GK24
GK QuizComputer Awareness

Computer Awareness Quiz: Cyber Security and Threats

  • 12 questions
  • 12 minutes
  • Difficulty: Medium

About this quiz

This Computer Awareness quiz on Cyber Security and Threats puts 12 multiple-choice questions to you, the verified MCQs published with GK24's note on the topic, 4 of them asked in real previous-year papers. Every question carries a full explanation of why the correct option is right and why the other options are wrong, so you learn the fact behind the answer rather than the letter. Attempt it right after reading the note, keep to the timer, and use the explanations at the end to mark what needs another look. Sit it again before the exam as a quick revision of the topic.

Questions in this quiz

12 questions with answers and explanations

Q1.Computer AwarenessAsked in: Madhya Pradesh · 17 Dec, 2023Easy

Which of the following is a type of cyber attack that involves tricking users into revealing sensitive information?

  1. A.Phishing attack
  2. B.SQL injection attack
  3. C.DoS attack
  4. D.None of the above
Show answer

Correct answer: A. Phishing attack

Explanation

The correct answer is A, phishing attack. Phishing sends a message that looks as if it came from a bank, an employer or a government office, and asks the reader to confirm a password, a card number or a one-time password on a page that belongs to the attacker; the target of the attack is the person, not the machine, which is why it is classed as social engineering. Option B is wrong because SQL injection puts database commands into a web form to make the server reveal stored data; the user is not tricked at all. Option C is wrong because a denial of service attack floods a server with requests so that genuine users cannot reach it, which harms availability and steals nothing. Option D is wrong because option A is correct. Remember the family: spear phishing on one person, whaling on an executive, vishing by call, smishing by message.

Q2.Computer AwarenessAsked in: Madhya Pradesh · 17 Dec, 2023Easy

What is the purpose of a firewall in cyber security?

  1. A.To allow unrestricted access to a network
  2. B.To block unauthorised access to a network
  3. C.To create a backup of a network's data
  4. D.None of the above
Show answer

Correct answer: B. To block unauthorised access to a network

Explanation

The correct answer is B, to block unauthorised access to a network. A firewall sits between a trusted internal network and the untrusted world outside, inspects the traffic crossing it and permits only what its rules allow, dropping the rest; it may be a hardware appliance, a software program or both together. Option A is wrong because unrestricted access is the exact opposite of what a firewall exists to provide, and a network left open in that way needs no firewall at all. Option C is wrong because taking backups is the work of backup software and storage policy; a firewall keeps no copy of data and would not help after a disk failure. Option D is wrong because option B states the purpose correctly. Note the common types for objective questions: packet filtering, stateful inspection and the proxy or application gateway firewall.

Q3.Computer AwarenessAsked in: Uttar Pradesh · 27 August 2023Medium

What is the term for a cyber security attack that targets multiple interconnected devices simultaneously to create a large-scale attack network?

  1. A.DDoS attack
  2. B.Botnet attack
  3. C.Zero-day attack
  4. D.Spear phishing attack
Show answer

Correct answer: B. Botnet attack

Explanation

The correct answer is B, botnet attack. A botnet is built by infecting many connected devices, each of which becomes a zombie obeying a single controller; the network so assembled is then rented out or used for spam, fraud or a flood of traffic. The wording of the question, many interconnected devices turned into one attack network, describes the building of the botnet itself. Option A is wrong for a reason worth understanding: a distributed denial of service attack is usually launched from a botnet, but it names the flooding of one victim, not the assembling of the device network. Option C is wrong because a zero-day attack exploits a flaw the vendor does not yet know of and has nothing to do with numbers of devices. Option D is wrong because spear phishing is a targeted fraudulent message sent to one chosen person.

Q4.Computer AwarenessAsked in: Madhya Pradesh · 21 May 2023Easy

The feature(s) of cyber security is/are:

  1. A.Compliance
  2. B.Defence against internal threats
  3. C.Threat prevention
  4. D.All of the above
Show answer

Correct answer: D. All of the above

Explanation

The correct answer is D, all of the above, because cyber security is not one activity but a programme that covers all three. Option A by itself is incomplete: compliance means following the rules, standards and laws that apply to the data an organisation holds, and it is only one strand of the work. Option B by itself is incomplete as well: defence against internal threats guards against the employee who misuses access or leaks data, a large share of real incidents, but an organisation that watched only its insiders would still fall to an outside attack. Option C by itself is incomplete too: threat prevention covers firewalls, antivirus, patching and monitoring that stop an attack before it lands. Since each of the three is a genuine part of cyber security and none of them alone is the whole, the combined option is the answer.

Q5.Computer AwarenessEasy

In the CIA triad of information security, the letter I stands for:

  1. A.Identification
  2. B.Integrity
  3. C.Internet
  4. D.Isolation
Show answer

Correct answer: B. Integrity

Explanation

The correct answer is B, integrity. The triad names the three goals of information security: confidentiality, that only authorised people can read the data; integrity, that the data is complete and unaltered from the moment it was created or sent; and availability, that the system works when an authorised user needs it. Option A is wrong because identification, along with authentication, is a means of achieving these goals rather than one of the three goals themselves. Option C is wrong because the internet is the medium over which most attacks travel and is no part of the model. Option D is wrong because isolation, such as keeping a critical machine off the network, is one technique among many for protecting a system. A useful way to recall the triad is to ask who may read the data, whether it can be changed, and whether it can be reached.

Q6.Computer AwarenessMedium

Which type of malware is a stand-alone program that replicates itself across a network without attaching to a host file?

  1. A.Virus
  2. B.Worm
  3. C.Trojan horse
  4. D.Adware
Show answer

Correct answer: B. Worm

Explanation

The correct answer is B, worm. A worm carries its own code, finds other machines through the network and copies itself to them without any help from the user, which is why worms can spread across the world in hours. Option A is wrong because a virus must attach itself to a file or program and spreads only when that host is opened, copied or run, so human action is always needed. Option C is wrong because a Trojan horse neither attaches nor replicates; it is disguised as useful software and depends entirely on the user installing it, after which it opens a back door for the attacker. Option D is wrong because adware merely displays unwanted advertisements and gathers browsing habits, and although it is a nuisance it does not spread on its own. The one-line distinction to memorise is that a virus needs a host and a user, a worm needs neither.

Q7.Computer AwarenessEasy

Malware that encrypts a victim's files and demands payment for the decryption key is called:

  1. A.Ransomware
  2. B.Rootkit
  3. C.Keylogger
  4. D.Honeypot
Show answer

Correct answer: A. Ransomware

Explanation

The correct answer is A, ransomware. It locks the files by encrypting them and shows a demand for money, usually in a crypto currency, in exchange for the key; the WannaCry outbreak of 2017 struck hospitals, factories and offices in many countries and is the example examiners quote. Option B is wrong because a rootkit hides an intruder's presence by burying itself in the operating system so that scanners and system tools do not report it; it conceals rather than extorts. Option C is wrong because a keylogger silently records every key pressed and sends the log to the attacker, which is a way of stealing passwords. Option D is wrong and is not malware at all: a honeypot is a decoy computer set up on purpose by defenders so that attackers waste effort on it and can be studied. Regular offline backups are the standard protection against ransomware.

Q8.Computer AwarenessMedium

Which is the national nodal agency of India for responding to computer security incidents?

  1. A.NIC
  2. B.CERT-In
  3. C.TRAI
  4. D.STQC
Show answer

Correct answer: B. CERT-In

Explanation

The correct answer is B, CERT-In, the Indian Computer Emergency Response Team, which works under the Ministry of Electronics and Information Technology and is the national agency for collecting, analysing and issuing alerts on cyber incidents and for coordinating the response to them. Option A is wrong because the National Informatics Centre builds and runs the information technology infrastructure of government departments; it is a service provider, not the incident response agency. Option C is wrong because the Telecom Regulatory Authority of India regulates tariffs and the quality of telecom service and has no incident response role. Option D is wrong because the Standardisation Testing and Quality Certification directorate certifies the quality of information technology products and services. Also remember the National Critical Information Infrastructure Protection Centre for critical sectors and the Cyber Swachhta Kendra for cleaning botnets.

Q9.Computer AwarenessMedium

The full form of CAPTCHA, used on websites, is Completely Automated Public Turing test to tell Computers and ______ Apart.

  1. A.Consoles
  2. B.Humans
  3. C.Hackers
  4. D.Hosts
Show answer

Correct answer: B. Humans

Explanation

The correct answer is B, humans. CAPTCHA stands for Completely Automated Public Turing test to tell Computers and Humans Apart, and it is the distorted text, image grid or check box that a site shows before accepting a form, so that automated programs cannot register accounts, book tickets in bulk or guess passwords by the thousand. The name recalls Alan Turing, whose test asked whether a machine could pass for a person. Option A is wrong because consoles are gaming or control devices and have no place in the expansion. Option C is wrong because a CAPTCHA does not separate hackers from honest users; a human attacker can solve it, so it stops automation, not intent. Option D is wrong because a host is any computer connected to a network, again unrelated. Examiners ask this expansion word for word, so learn it exactly.

Q10.Computer AwarenessHard

A zero-day attack is one that exploits:

  1. A.A vulnerability for which no patch yet exists
  2. B.A password that is exactly zero characters long
  3. C.A computer that has been switched off
  4. D.A network with zero bandwidth
Show answer

Correct answer: A. A vulnerability for which no patch yet exists

Explanation

The correct answer is A. The name counts the days the software maker has had to fix the flaw, and that number is zero: the attacker knows of a weakness that the vendor has not discovered or not yet repaired, so no update protects the user and even a fully patched system is exposed. Such flaws are valuable and are traded quietly, which is why the attacks are often aimed at high value targets. Option B is wrong because an empty password is simply a case of weak authentication, defeated by a basic password policy. Option C is wrong because an attack needs a running system to act on; a machine that is switched off is out of reach over the network. Option D is wrong because bandwidth measures the capacity of a link and has nothing to do with software flaws. Defence rests on quick patching, layered controls and behaviour based detection.

Q11.Computer AwarenessMedium

Which method of encryption uses a pair consisting of a public key and a private key?

  1. A.Symmetric encryption
  2. B.Asymmetric encryption
  3. C.Hashing
  4. D.Compression
Show answer

Correct answer: B. Asymmetric encryption

Explanation

The correct answer is B, asymmetric encryption, also called public key encryption. Anyone may hold the public key and use it to encrypt a message, but only the holder of the matching private key can decrypt it, so no secret has to be exchanged in advance; RSA is the standard example, and the same pair used the other way round produces a digital signature. Option A is wrong because symmetric encryption, such as AES or the older DES, uses one shared secret key for both operations and is fast but requires a safe way to pass that key. Option C is wrong because hashing is a one-way function that turns data into a fixed length digest for checking integrity and cannot be reversed to recover the message. Option D is wrong because compression only reduces the size of a file and provides no secrecy at all.

Q12.Computer AwarenessMedium

The national cybercrime helpline number of India for reporting financial fraud is:

  1. A.1930
  2. B.1098
  3. C.1800
  4. D.1091
Show answer

Correct answer: A. 1930

Explanation

The correct answer is A, 1930. It is the helpline on which a victim of online financial fraud should call at once, because a report made within the first hours lets banks and payment operators freeze the money before it is withdrawn; complaints can also be filed on the national cybercrime reporting portal. Option B is wrong because 1098 is Childline, the helpline for children in distress. Option C is wrong because 1800 is not a helpline at all but the prefix of toll free numbers in India, which run to ten or eleven digits. Option D is wrong because 1091 is the women's helpline. A related fact worth carrying is that the Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs runs this reporting system, while CERT-In handles technical incidents.

View all quizzes