Cyber Security and Threats: Malware, Attacks and PYQs
Exam notes on cyber security: the CIA triad, viruses, worms, Trojans and ransomware, phishing and DDoS attacks, firewalls, encryption and CERT-In.
By GK24 Editorial Team· Published · 4 min read

Cyber security is the practice of protecting computers, networks, programs and data from unauthorised access, damage or theft. As banking, ticketing, examinations and government records moved online, the same network that made them convenient exposed them to attack, so every competitive examination now asks a few questions from this chapter. The subject is built on three goals, remembered as the CIA triad: confidentiality, that only authorised people can read the data; integrity, that the data is not altered on the way; and availability, that the authorised user can reach the system when needed. Authentication and non-repudiation are usually added to the list.
Malicious software
Malware is the general name for any program written to harm a system. A virus attaches itself to a file or program and spreads only when that host is copied or run, so it needs human action. A worm is a stand-alone program that copies itself across a network by itself and needs no host file, which is why worms spread far faster. A Trojan horse pretends to be useful software, and once installed opens a back door; it does not replicate. Ransomware encrypts the victim's files and demands payment for the key, the WannaCry outbreak of 2017 being the best known case. Spyware watches quietly and reports back, a keylogger records every keystroke, adware pushes advertisements, and a rootkit hides deep in the system so that scanners miss it. A logic bomb is code that waits for a condition or a date before it fires.
| Malware | Needs a host file | Spreads by itself |
|---|---|---|
| Virus | Yes | No, it needs the host to be run or copied |
| Worm | No | Yes, across the network |
| Trojan horse | No | No, the user is tricked into installing it |
| Ransomware | Varies | Varies; it encrypts data and demands money |
Attacks on people and on systems
Phishing is the sending of a fake message that appears to come from a bank or an office so that the reader gives away a password, a card number or a one-time password. Spear phishing aims at one named person, whaling at a senior executive, vishing works by telephone call and smishing by text message. Pharming quietly redirects a correct web address to a fake site. All of these are forms of social engineering, in which the weakest link attacked is the human being rather than the machine.
Against systems, a denial of service attack floods a server with requests until genuine users cannot be served; when the flood comes from thousands of hijacked machines at once it is a distributed denial of service attack. Those hijacked machines, controlled together by an attacker, form a botnet, and each infected machine is called a zombie. A man in the middle attack places the attacker silently between two parties who believe they are talking directly. SQL injection feeds database commands into a web form so that the site returns data it should not. A zero-day attack uses a flaw that the maker does not yet know about, so no patch exists. A brute force attack tries every possible password, while a dictionary attack tries likely words first.
Defences
A firewall stands between a trusted internal network and the untrusted outside, examining traffic and blocking whatever the rules do not permit; it may be hardware, software or both. Antivirus software compares files against a store of known signatures and also watches for suspicious behaviour, quarantining what it finds. Encryption turns readable plaintext into ciphertext. In symmetric encryption the same secret key locks and unlocks the message, as in AES and the older DES; in asymmetric or public key encryption a public key encrypts and a matching private key decrypts, as in RSA, and this is what makes the digital signature possible. A digital signature proves who sent a document, shows that it was not altered, and prevents the sender from later denying it.
Everyday defences matter as much. A strong password mixes cases, digits and symbols and is not reused. Two-factor authentication adds a second proof, usually a one-time password or a fingerprint, so that a stolen password alone is not enough. HTTPS, shown by the padlock in the address bar, means the connection is protected by SSL or TLS. A virtual private network carries traffic through an encrypted tunnel, useful on public wi-fi. A CAPTCHA tells a human apart from an automated program, and a honeypot is a decoy system set up to attract and study attackers.
The Indian framework
The Information Technology Act, 2000, amended in 2008, is the parent law for cyber offences in India. CERT-In, the Indian Computer Emergency Response Team, is the national nodal agency for responding to computer security incidents and works under the Ministry of Electronics and Information Technology. The National Critical Information Infrastructure Protection Centre protects systems in sectors such as power, banking and transport whose failure would harm national security. The Cyber Swachhta Kendra is the botnet cleaning and malware analysis centre that helps users remove infections. Complaints are filed on the national cybercrime reporting portal, and the national cybercrime helpline number is 1930. Safer Internet Day is observed on the second Tuesday of February.
Exam Point of View
Most marks here come from definitions and from telling look-alike terms apart. The favourite pairs are virus against worm, worm against Trojan, and DDoS against botnet, and the safest way to answer is to ask whether the program needs a host file and whether it spreads by itself. Full forms are asked word for word, CAPTCHA above all. Phishing and its family, spear phishing, vishing, smishing and pharming, appear in every banking paper. Firewall, antivirus, digital signature and the difference between symmetric and asymmetric encryption are asked as simple purpose questions. On the Indian side, learn CERT-In as the nodal agency, the helpline 1930 and the Information Technology Act of 2000 as amended in 2008. Do not memorise numbers of reported incidents or the latest attack of the year, because such figures change and are easily misremembered.
Important Facts
| CIA triad | Confidentiality, integrity, availability |
|---|---|
| Virus | Attaches to a host file; spreads when the host is run or copied |
| Worm | Stand-alone; replicates across a network without a host |
| Trojan horse | Disguised as useful software; does not replicate |
| Ransomware example | WannaCry, 2017 |
| Botnet | Network of infected zombie machines under one controller |
| Firewall | Filters traffic between a trusted and an untrusted network |
| Symmetric encryption | One shared key; DES, AES |
| Asymmetric encryption | Public and private key pair; RSA |
| CAPTCHA | Completely Automated Public Turing test to tell Computers and Humans Apart |
| Parent law in India | Information Technology Act, 2000, amended in 2008 |
| Nodal agency | CERT-In, under the Ministry of Electronics and Information Technology |
| Cybercrime helpline | 1930 |
Practice MCQs on this topic
Which of the following is a type of cyber attack that involves tricking users into revealing sensitive information?
- A.Phishing attack
- B.SQL injection attack
- C.DoS attack
- D.None of the above
Show answer
Correct answer: A. Phishing attack
Explanation
The correct answer is A, phishing attack. Phishing sends a message that looks as if it came from a bank, an employer or a government office, and asks the reader to confirm a password, a card number or a one-time password on a page that belongs to the attacker; the target of the attack is the person, not the machine, which is why it is classed as social engineering. Option B is wrong because SQL injection puts database commands into a web form to make the server reveal stored data; the user is not tricked at all. Option C is wrong because a denial of service attack floods a server with requests so that genuine users cannot reach it, which harms availability and steals nothing. Option D is wrong because option A is correct. Remember the family: spear phishing on one person, whaling on an executive, vishing by call, smishing by message.
What is the purpose of a firewall in cyber security?
- A.To allow unrestricted access to a network
- B.To block unauthorised access to a network
- C.To create a backup of a network's data
- D.None of the above
Show answer
Correct answer: B. To block unauthorised access to a network
Explanation
The correct answer is B, to block unauthorised access to a network. A firewall sits between a trusted internal network and the untrusted world outside, inspects the traffic crossing it and permits only what its rules allow, dropping the rest; it may be a hardware appliance, a software program or both together. Option A is wrong because unrestricted access is the exact opposite of what a firewall exists to provide, and a network left open in that way needs no firewall at all. Option C is wrong because taking backups is the work of backup software and storage policy; a firewall keeps no copy of data and would not help after a disk failure. Option D is wrong because option B states the purpose correctly. Note the common types for objective questions: packet filtering, stateful inspection and the proxy or application gateway firewall.
What is the term for a cyber security attack that targets multiple interconnected devices simultaneously to create a large-scale attack network?
- A.DDoS attack
- B.Botnet attack
- C.Zero-day attack
- D.Spear phishing attack
Show answer
Correct answer: B. Botnet attack
Explanation
The correct answer is B, botnet attack. A botnet is built by infecting many connected devices, each of which becomes a zombie obeying a single controller; the network so assembled is then rented out or used for spam, fraud or a flood of traffic. The wording of the question, many interconnected devices turned into one attack network, describes the building of the botnet itself. Option A is wrong for a reason worth understanding: a distributed denial of service attack is usually launched from a botnet, but it names the flooding of one victim, not the assembling of the device network. Option C is wrong because a zero-day attack exploits a flaw the vendor does not yet know of and has nothing to do with numbers of devices. Option D is wrong because spear phishing is a targeted fraudulent message sent to one chosen person.
The feature(s) of cyber security is/are:
- A.Compliance
- B.Defence against internal threats
- C.Threat prevention
- D.All of the above
Show answer
Correct answer: D. All of the above
Explanation
The correct answer is D, all of the above, because cyber security is not one activity but a programme that covers all three. Option A by itself is incomplete: compliance means following the rules, standards and laws that apply to the data an organisation holds, and it is only one strand of the work. Option B by itself is incomplete as well: defence against internal threats guards against the employee who misuses access or leaks data, a large share of real incidents, but an organisation that watched only its insiders would still fall to an outside attack. Option C by itself is incomplete too: threat prevention covers firewalls, antivirus, patching and monitoring that stop an attack before it lands. Since each of the three is a genuine part of cyber security and none of them alone is the whole, the combined option is the answer.
In the CIA triad of information security, the letter I stands for:
- A.Identification
- B.Integrity
- C.Internet
- D.Isolation
Show answer
Correct answer: B. Integrity
Explanation
The correct answer is B, integrity. The triad names the three goals of information security: confidentiality, that only authorised people can read the data; integrity, that the data is complete and unaltered from the moment it was created or sent; and availability, that the system works when an authorised user needs it. Option A is wrong because identification, along with authentication, is a means of achieving these goals rather than one of the three goals themselves. Option C is wrong because the internet is the medium over which most attacks travel and is no part of the model. Option D is wrong because isolation, such as keeping a critical machine off the network, is one technique among many for protecting a system. A useful way to recall the triad is to ask who may read the data, whether it can be changed, and whether it can be reached.
Which type of malware is a stand-alone program that replicates itself across a network without attaching to a host file?
- A.Virus
- B.Worm
- C.Trojan horse
- D.Adware
Show answer
Correct answer: B. Worm
Explanation
The correct answer is B, worm. A worm carries its own code, finds other machines through the network and copies itself to them without any help from the user, which is why worms can spread across the world in hours. Option A is wrong because a virus must attach itself to a file or program and spreads only when that host is opened, copied or run, so human action is always needed. Option C is wrong because a Trojan horse neither attaches nor replicates; it is disguised as useful software and depends entirely on the user installing it, after which it opens a back door for the attacker. Option D is wrong because adware merely displays unwanted advertisements and gathers browsing habits, and although it is a nuisance it does not spread on its own. The one-line distinction to memorise is that a virus needs a host and a user, a worm needs neither.
Malware that encrypts a victim's files and demands payment for the decryption key is called:
- A.Ransomware
- B.Rootkit
- C.Keylogger
- D.Honeypot
Show answer
Correct answer: A. Ransomware
Explanation
The correct answer is A, ransomware. It locks the files by encrypting them and shows a demand for money, usually in a crypto currency, in exchange for the key; the WannaCry outbreak of 2017 struck hospitals, factories and offices in many countries and is the example examiners quote. Option B is wrong because a rootkit hides an intruder's presence by burying itself in the operating system so that scanners and system tools do not report it; it conceals rather than extorts. Option C is wrong because a keylogger silently records every key pressed and sends the log to the attacker, which is a way of stealing passwords. Option D is wrong and is not malware at all: a honeypot is a decoy computer set up on purpose by defenders so that attackers waste effort on it and can be studied. Regular offline backups are the standard protection against ransomware.
Which is the national nodal agency of India for responding to computer security incidents?
- A.NIC
- B.CERT-In
- C.TRAI
- D.STQC
Show answer
Correct answer: B. CERT-In
Explanation
The correct answer is B, CERT-In, the Indian Computer Emergency Response Team, which works under the Ministry of Electronics and Information Technology and is the national agency for collecting, analysing and issuing alerts on cyber incidents and for coordinating the response to them. Option A is wrong because the National Informatics Centre builds and runs the information technology infrastructure of government departments; it is a service provider, not the incident response agency. Option C is wrong because the Telecom Regulatory Authority of India regulates tariffs and the quality of telecom service and has no incident response role. Option D is wrong because the Standardisation Testing and Quality Certification directorate certifies the quality of information technology products and services. Also remember the National Critical Information Infrastructure Protection Centre for critical sectors and the Cyber Swachhta Kendra for cleaning botnets.
The full form of CAPTCHA, used on websites, is Completely Automated Public Turing test to tell Computers and ______ Apart.
- A.Consoles
- B.Humans
- C.Hackers
- D.Hosts
Show answer
Correct answer: B. Humans
Explanation
The correct answer is B, humans. CAPTCHA stands for Completely Automated Public Turing test to tell Computers and Humans Apart, and it is the distorted text, image grid or check box that a site shows before accepting a form, so that automated programs cannot register accounts, book tickets in bulk or guess passwords by the thousand. The name recalls Alan Turing, whose test asked whether a machine could pass for a person. Option A is wrong because consoles are gaming or control devices and have no place in the expansion. Option C is wrong because a CAPTCHA does not separate hackers from honest users; a human attacker can solve it, so it stops automation, not intent. Option D is wrong because a host is any computer connected to a network, again unrelated. Examiners ask this expansion word for word, so learn it exactly.
A zero-day attack is one that exploits:
- A.A vulnerability for which no patch yet exists
- B.A password that is exactly zero characters long
- C.A computer that has been switched off
- D.A network with zero bandwidth
Show answer
Correct answer: A. A vulnerability for which no patch yet exists
Explanation
The correct answer is A. The name counts the days the software maker has had to fix the flaw, and that number is zero: the attacker knows of a weakness that the vendor has not discovered or not yet repaired, so no update protects the user and even a fully patched system is exposed. Such flaws are valuable and are traded quietly, which is why the attacks are often aimed at high value targets. Option B is wrong because an empty password is simply a case of weak authentication, defeated by a basic password policy. Option C is wrong because an attack needs a running system to act on; a machine that is switched off is out of reach over the network. Option D is wrong because bandwidth measures the capacity of a link and has nothing to do with software flaws. Defence rests on quick patching, layered controls and behaviour based detection.
Which method of encryption uses a pair consisting of a public key and a private key?
- A.Symmetric encryption
- B.Asymmetric encryption
- C.Hashing
- D.Compression
Show answer
Correct answer: B. Asymmetric encryption
Explanation
The correct answer is B, asymmetric encryption, also called public key encryption. Anyone may hold the public key and use it to encrypt a message, but only the holder of the matching private key can decrypt it, so no secret has to be exchanged in advance; RSA is the standard example, and the same pair used the other way round produces a digital signature. Option A is wrong because symmetric encryption, such as AES or the older DES, uses one shared secret key for both operations and is fast but requires a safe way to pass that key. Option C is wrong because hashing is a one-way function that turns data into a fixed length digest for checking integrity and cannot be reversed to recover the message. Option D is wrong because compression only reduces the size of a file and provides no secrecy at all.
The national cybercrime helpline number of India for reporting financial fraud is:
- A.1930
- B.1098
- C.1800
- D.1091
Show answer
Correct answer: A. 1930
Explanation
The correct answer is A, 1930. It is the helpline on which a victim of online financial fraud should call at once, because a report made within the first hours lets banks and payment operators freeze the money before it is withdrawn; complaints can also be filed on the national cybercrime reporting portal. Option B is wrong because 1098 is Childline, the helpline for children in distress. Option C is wrong because 1800 is not a helpline at all but the prefix of toll free numbers in India, which run to ten or eleven digits. Option D is wrong because 1091 is the women's helpline. A related fact worth carrying is that the Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs runs this reporting system, while CERT-In handles technical incidents.
Frequently Asked Questions
What is the difference between a virus and a worm?
A virus attaches itself to a file or program and spreads only when that host is opened, copied or run, so it depends on the user. A worm is a complete program in itself, copies itself over the network without any user action, and therefore spreads much faster.
Is a cookie a kind of virus?
No. A cookie is a small text file that a website stores in the browser to remember a login, a language choice or the contents of a cart. It cannot execute, so it cannot infect a computer, though tracking cookies do raise questions of privacy.
What does two-factor authentication add?
It adds a second, independent proof of identity to the password, usually a one-time password on the phone, a hardware token or a fingerprint. A thief who has stolen only the password still cannot log in, which defeats most password leaks.
What is the difference between DoS and DDoS?
A denial of service attack floods a server from one source until genuine users cannot be served. A distributed denial of service attack sends the same flood from thousands of compromised machines at once, which makes it far harder to block by address.
What does the padlock and HTTPS in the address bar mean?
It means the connection to that website is encrypted with SSL or TLS, so data travelling between the browser and the server cannot be read in transit. It does not by itself prove that the website is honest, since a fake site can also obtain a certificate.
Sources
- About CERT-In and its functions — Indian Computer Emergency Response Team
- The Information Technology Act, 2000 — Ministry of Electronics and Information Technology
- Computer Science, Class XI, Chapter on Societal Impacts — NCERT





