Skip to content
GK24
Science & TechnologyMedium

A fraudulent email that imitates a bank in order to make the reader reveal a password or card number is an example of:

  1. A.Phishing
  2. B.Ransomware
  3. C.Spoofing of a network address
  4. D.A zero-day exploit

Correct answer

A. Phishing

Explanation

The correct answer is A, phishing. Phishing uses a message that looks as though it comes from a trusted institution, so that the reader voluntarily gives up credentials; the same fraud carried out by telephone call is called vishing and by text message smishing. Option B is wrong; ransomware is malicious software that encrypts the victim's files and demands a payment for the key, so it does not depend on the victim disclosing a password. Option C is wrong because spoofing is the faking of an address or identifier at the technical level, and while a phishing email often spoofs a sender address, the named offence here is the deception of the reader. Option D is wrong since a zero-day exploit attacks a software flaw for which no patch yet exists, which is a technical weakness rather than a trick played on a person.

Read the full article: Cyber Security and Digital Public Infrastructure: Notes

View all
Q1.Science & TechnologyEasy

Which Act is the principal law governing cyber activity and electronic records in India?

  1. A.Information Technology Act, 2000
  2. B.Indian Telegraph Act, 1885
  3. C.Indian Evidence Act, 1872
  4. D.Companies Act, 2013
Show answer

Correct answer: A. Information Technology Act, 2000

Explanation

The correct answer is A, the Information Technology Act, 2000. It gives legal recognition to electronic records and digital signatures, creates the offences of computer-related crime, and was amended substantially in 2008 to add provisions on cyber terrorism, interception and data protection by body corporates. Option B is wrong; the Indian Telegraph Act of 1885 governs telegraph and telephone services and the licensing of telecommunications, not computer offences. Option C is wrong because the Indian Evidence Act of 1872 deals with evidence generally, although the IT Act amended it so that electronic records could be admitted as evidence. Option D is wrong since the Companies Act of 2013 regulates companies and their governance. The IT Act was drafted on the model of the UNCITRAL Model Law on Electronic Commerce.

Q2.Science & TechnologyEasy

In cyber security, the CIA triad stands for:

  1. A.Control, Information, Access
  2. B.Confidentiality, Integrity, Availability
  3. C.Cryptography, Identity, Authentication
  4. D.Compliance, Inspection, Audit
Show answer

Correct answer: B. Confidentiality, Integrity, Availability

Explanation

The correct answer is B, Confidentiality, Integrity and Availability. These are the three goals of information security: only authorised persons should read the data, the data must not be altered without authority, and the system must work when it is needed. Option A is wrong; control and access are mechanisms rather than the named goals of the triad. Option C is wrong because cryptography, identity and authentication are tools used to achieve the three goals, not the goals themselves, and this option is attractive to anyone who remembers the technical vocabulary instead of the framework. Option D is wrong since compliance, inspection and audit belong to governance and assurance work. A denial of service attack is a good illustration, because it attacks availability alone while leaving confidentiality and integrity untouched.

Q3.Science & TechnologyMedium

Section 66A of the Information Technology Act was struck down by the Supreme Court in which case?

  1. A.K. S. Puttaswamy v. Union of India
  2. B.Shreya Singhal v. Union of India
  3. C.Anuradha Bhasin v. Union of India
  4. D.Maneka Gandhi v. Union of India
Show answer

Correct answer: B. Shreya Singhal v. Union of India

Explanation

The correct answer is B, Shreya Singhal v. Union of India. In 2015 the Supreme Court held section 66A, which punished the sending of offensive messages through a communication service, to be unconstitutional because it was vague and overbroad and violated the freedom of speech under Article 19(1)(a). Option A is wrong, although it is the closest in subject matter: the Puttaswamy judgment of 2017 held the right to privacy to be a fundamental right under Article 21, and it led to the data protection law rather than to the striking down of 66A. Option C is wrong; Anuradha Bhasin in 2020 concerned internet shutdowns in Jammu and Kashmir. Option D is wrong because Maneka Gandhi in 1978 expanded the meaning of personal liberty under Article 21 long before the internet.

Q4.Science & TechnologyHard

CERT-In, the national nodal agency for responding to cyber security incidents, is designated under which section of the IT Act?

  1. A.Section 69
  2. B.Section 70A
  3. C.Section 70B
  4. D.Section 79
Show answer

Correct answer: C. Section 70B

Explanation

The correct answer is C, Section 70B. The Indian Computer Emergency Response Team functions under the Ministry of Electronics and Information Technology and is designated by section 70B as the national agency for collecting and analysing information on cyber incidents, issuing advisories and coordinating responses. Option A is wrong; section 69 gives the power to intercept, monitor or decrypt information in specified circumstances. Option B is the hardest distractor because section 70A designates the nodal agency for critical information infrastructure, which is the NCIIPC, a different body working under the National Technical Research Organisation. Option D is wrong since section 79 is the safe harbour provision that limits an intermediary's liability for content uploaded by third parties. Keep 70A with NCIIPC and 70B with CERT-In.

Q5.Science & TechnologyHard

The National Critical Information Infrastructure Protection Centre (NCIIPC) functions under which organisation?

  1. A.Reserve Bank of India
  2. B.National Technical Research Organisation
  3. C.Ministry of Home Affairs
  4. D.National Informatics Centre
Show answer

Correct answer: B. National Technical Research Organisation

Explanation

The correct answer is B, the National Technical Research Organisation. The NCIIPC was designated under section 70A of the IT Act to protect critical information infrastructure, meaning computer resources whose incapacitation would have a debilitating effect on national security, the economy, public health or safety, and it works as a unit of the NTRO. Option A is wrong; the Reserve Bank regulates the financial sector's own cyber resilience but does not house the NCIIPC. Option C is wrong, although the Ministry of Home Affairs runs the Indian Cyber Crime Coordination Centre and the national cybercrime reporting portal, which is why it is a tempting choice. Option D is wrong because the National Informatics Centre provides information technology services to government departments rather than protecting critical infrastructure.