Skip to content
GK24
GK QuizScience & Technology

Science & Technology Quiz: Cyber Security and Digital Public Infrastructure

  • 10 questions
  • 10 minutes
  • Difficulty: Medium

About this quiz

This Science & Technology quiz on Cyber Security and Digital Public Infrastructure puts 10 multiple-choice questions to you, the verified MCQs published with GK24's note on the topic. Every question carries a full explanation of why the correct option is right and why the other options are wrong, so you learn the fact behind the answer rather than the letter. Attempt it right after reading the note, keep to the timer, and use the explanations at the end to mark what needs another look. Sit it again before the exam as a quick revision of the topic.

Questions in this quiz

10 questions with answers and explanations

Q1.Science & TechnologyEasy

Which Act is the principal law governing cyber activity and electronic records in India?

  1. A.Information Technology Act, 2000
  2. B.Indian Telegraph Act, 1885
  3. C.Indian Evidence Act, 1872
  4. D.Companies Act, 2013
Show answer

Correct answer: A. Information Technology Act, 2000

Explanation

The correct answer is A, the Information Technology Act, 2000. It gives legal recognition to electronic records and digital signatures, creates the offences of computer-related crime, and was amended substantially in 2008 to add provisions on cyber terrorism, interception and data protection by body corporates. Option B is wrong; the Indian Telegraph Act of 1885 governs telegraph and telephone services and the licensing of telecommunications, not computer offences. Option C is wrong because the Indian Evidence Act of 1872 deals with evidence generally, although the IT Act amended it so that electronic records could be admitted as evidence. Option D is wrong since the Companies Act of 2013 regulates companies and their governance. The IT Act was drafted on the model of the UNCITRAL Model Law on Electronic Commerce.

Q2.Science & TechnologyEasy

In cyber security, the CIA triad stands for:

  1. A.Control, Information, Access
  2. B.Confidentiality, Integrity, Availability
  3. C.Cryptography, Identity, Authentication
  4. D.Compliance, Inspection, Audit
Show answer

Correct answer: B. Confidentiality, Integrity, Availability

Explanation

The correct answer is B, Confidentiality, Integrity and Availability. These are the three goals of information security: only authorised persons should read the data, the data must not be altered without authority, and the system must work when it is needed. Option A is wrong; control and access are mechanisms rather than the named goals of the triad. Option C is wrong because cryptography, identity and authentication are tools used to achieve the three goals, not the goals themselves, and this option is attractive to anyone who remembers the technical vocabulary instead of the framework. Option D is wrong since compliance, inspection and audit belong to governance and assurance work. A denial of service attack is a good illustration, because it attacks availability alone while leaving confidentiality and integrity untouched.

Q3.Science & TechnologyMedium

Section 66A of the Information Technology Act was struck down by the Supreme Court in which case?

  1. A.K. S. Puttaswamy v. Union of India
  2. B.Shreya Singhal v. Union of India
  3. C.Anuradha Bhasin v. Union of India
  4. D.Maneka Gandhi v. Union of India
Show answer

Correct answer: B. Shreya Singhal v. Union of India

Explanation

The correct answer is B, Shreya Singhal v. Union of India. In 2015 the Supreme Court held section 66A, which punished the sending of offensive messages through a communication service, to be unconstitutional because it was vague and overbroad and violated the freedom of speech under Article 19(1)(a). Option A is wrong, although it is the closest in subject matter: the Puttaswamy judgment of 2017 held the right to privacy to be a fundamental right under Article 21, and it led to the data protection law rather than to the striking down of 66A. Option C is wrong; Anuradha Bhasin in 2020 concerned internet shutdowns in Jammu and Kashmir. Option D is wrong because Maneka Gandhi in 1978 expanded the meaning of personal liberty under Article 21 long before the internet.

Q4.Science & TechnologyHard

CERT-In, the national nodal agency for responding to cyber security incidents, is designated under which section of the IT Act?

  1. A.Section 69
  2. B.Section 70A
  3. C.Section 70B
  4. D.Section 79
Show answer

Correct answer: C. Section 70B

Explanation

The correct answer is C, Section 70B. The Indian Computer Emergency Response Team functions under the Ministry of Electronics and Information Technology and is designated by section 70B as the national agency for collecting and analysing information on cyber incidents, issuing advisories and coordinating responses. Option A is wrong; section 69 gives the power to intercept, monitor or decrypt information in specified circumstances. Option B is the hardest distractor because section 70A designates the nodal agency for critical information infrastructure, which is the NCIIPC, a different body working under the National Technical Research Organisation. Option D is wrong since section 79 is the safe harbour provision that limits an intermediary's liability for content uploaded by third parties. Keep 70A with NCIIPC and 70B with CERT-In.

Q5.Science & TechnologyHard

The National Critical Information Infrastructure Protection Centre (NCIIPC) functions under which organisation?

  1. A.Reserve Bank of India
  2. B.National Technical Research Organisation
  3. C.Ministry of Home Affairs
  4. D.National Informatics Centre
Show answer

Correct answer: B. National Technical Research Organisation

Explanation

The correct answer is B, the National Technical Research Organisation. The NCIIPC was designated under section 70A of the IT Act to protect critical information infrastructure, meaning computer resources whose incapacitation would have a debilitating effect on national security, the economy, public health or safety, and it works as a unit of the NTRO. Option A is wrong; the Reserve Bank regulates the financial sector's own cyber resilience but does not house the NCIIPC. Option C is wrong, although the Ministry of Home Affairs runs the Indian Cyber Crime Coordination Centre and the national cybercrime reporting portal, which is why it is a tempting choice. Option D is wrong because the National Informatics Centre provides information technology services to government departments rather than protecting critical infrastructure.

Q6.Science & TechnologyEasy

The Unified Payments Interface (UPI) was launched by which organisation?

  1. A.Reserve Bank of India
  2. B.National Payments Corporation of India
  3. C.State Bank of India
  4. D.Ministry of Electronics and Information Technology
Show answer

Correct answer: B. National Payments Corporation of India

Explanation

The correct answer is B, the National Payments Corporation of India. The NPCI, set up in 2008 under the Payment and Settlement Systems Act of 2007 by the Reserve Bank and the Indian Banks' Association, launched UPI in 2016; it also runs RuPay, IMPS, the Aadhaar Enabled Payment System, NACH and FASTag. Option A is wrong but is the commonest mistake, because the Reserve Bank promoted the NPCI and regulates payment systems, yet UPI is an NPCI product. Option C is wrong; the State Bank of India is one of the banks that participate in UPI, not its owner. Option D is wrong because the Ministry of Electronics and Information Technology runs DigiLocker and the Digital India programme, not the payments layer. UPI forms the payments layer of what is called India Stack.

Q7.Science & TechnologyMedium

An attack that floods a server with requests from many compromised machines so that genuine users cannot reach it is called:

  1. A.Phishing
  2. B.SQL injection
  3. C.Distributed denial of service
  4. D.Man-in-the-middle attack
Show answer

Correct answer: C. Distributed denial of service

Explanation

The correct answer is C, a distributed denial of service attack. A denial of service attack exhausts a server's capacity with a flood of requests, and when the flood is generated from many machines at once, often a botnet of infected computers, it is called distributed. The goal attacked here is availability, the third limb of the CIA triad. Option A is wrong; phishing is a fraudulent message imitating a trusted institution in order to obtain a password or card number. Option B is wrong because SQL injection inserts malicious database commands through an input field to read or alter stored data, which attacks confidentiality and integrity. Option D is wrong since a man-in-the-middle attack intercepts traffic between two parties without either of them knowing. The Cyber Swachhta Kendra exists to clean the botnets used in such attacks.

Q8.Science & TechnologyMedium

Under the Digital Personal Data Protection Act, 2023, the individual whose personal data is being processed is called the:

  1. A.Data Fiduciary
  2. B.Data Principal
  3. C.Consent Manager
  4. D.Data Processor
Show answer

Correct answer: B. Data Principal

Explanation

The correct answer is B, Data Principal. The Act of 2023 calls the individual to whom the personal data relates the Data Principal, and gives that person rights of access, correction, erasure and grievance redressal. Option A is wrong and is the commonest confusion: a Data Fiduciary is the person or entity that decides the purpose and means of processing the data, and it carries the duties under the Act. Option C is wrong because a Consent Manager is an entity registered with the Data Protection Board through which a Data Principal can give, manage and withdraw consent. Option D is wrong since a Data Processor processes data on behalf of a Data Fiduciary. The Act follows the Puttaswamy judgment of 2017 and the report of the Justice B. N. Srikrishna Committee.

Q9.Science & TechnologyMedium

A fraudulent email that imitates a bank in order to make the reader reveal a password or card number is an example of:

  1. A.Phishing
  2. B.Ransomware
  3. C.Spoofing of a network address
  4. D.A zero-day exploit
Show answer

Correct answer: A. Phishing

Explanation

The correct answer is A, phishing. Phishing uses a message that looks as though it comes from a trusted institution, so that the reader voluntarily gives up credentials; the same fraud carried out by telephone call is called vishing and by text message smishing. Option B is wrong; ransomware is malicious software that encrypts the victim's files and demands a payment for the key, so it does not depend on the victim disclosing a password. Option C is wrong because spoofing is the faking of an address or identifier at the technical level, and while a phishing email often spoofs a sender address, the named offence here is the deception of the reader. Option D is wrong since a zero-day exploit attacks a software flaw for which no patch yet exists, which is a technical weakness rather than a trick played on a person.

Q10.Science & TechnologyMedium

The Digital India programme was launched on which date?

  1. A.15 August 2014
  2. B.1 July 2015
  3. C.1 January 2016
  4. D.2 October 2014
Show answer

Correct answer: B. 1 July 2015

Explanation

The correct answer is B, 1 July 2015. Digital India was launched on that date with three stated aims: digital infrastructure as a utility for every citizen, governance and services on demand, and the digital empowerment of citizens; BharatNet, Common Service Centres, DigiLocker and the UMANG application all sit within it. Option A is wrong; 15 August 2014 is the date of the announcement of the Jan Dhan Yojana from the Red Fort, which was launched later that month. Option C is wrong and corresponds to no launch, although the Unified Payments Interface did come in 2016. Option D is wrong because 2 October 2014 is the launch of the Swachh Bharat Mission, chosen for Gandhi's birth anniversary, which makes it a plausible date for anyone guessing from the pattern of government launches.

View all quizzes