Which method of encryption uses a pair consisting of a public key and a private key?
- A.Symmetric encryption
- B.Asymmetric encryption
- C.Hashing
- D.Compression
Correct answer
B. Asymmetric encryption
Explanation
The correct answer is B, asymmetric encryption, also called public key encryption. Anyone may hold the public key and use it to encrypt a message, but only the holder of the matching private key can decrypt it, so no secret has to be exchanged in advance; RSA is the standard example, and the same pair used the other way round produces a digital signature. Option A is wrong because symmetric encryption, such as AES or the older DES, uses one shared secret key for both operations and is fast but requires a safe way to pass that key. Option C is wrong because hashing is a one-way function that turns data into a fixed length digest for checking integrity and cannot be reversed to recover the message. Option D is wrong because compression only reduces the size of a file and provides no secrecy at all.
Read the full article: Cyber Security and Threats: Malware, Attacks and PYQs
Practice Questions
View allWhich of the following is a type of cyber attack that involves tricking users into revealing sensitive information?
- A.Phishing attack
- B.SQL injection attack
- C.DoS attack
- D.None of the above
Show answer
Correct answer: A. Phishing attack
Explanation
The correct answer is A, phishing attack. Phishing sends a message that looks as if it came from a bank, an employer or a government office, and asks the reader to confirm a password, a card number or a one-time password on a page that belongs to the attacker; the target of the attack is the person, not the machine, which is why it is classed as social engineering. Option B is wrong because SQL injection puts database commands into a web form to make the server reveal stored data; the user is not tricked at all. Option C is wrong because a denial of service attack floods a server with requests so that genuine users cannot reach it, which harms availability and steals nothing. Option D is wrong because option A is correct. Remember the family: spear phishing on one person, whaling on an executive, vishing by call, smishing by message.
What is the purpose of a firewall in cyber security?
- A.To allow unrestricted access to a network
- B.To block unauthorised access to a network
- C.To create a backup of a network's data
- D.None of the above
Show answer
Correct answer: B. To block unauthorised access to a network
Explanation
The correct answer is B, to block unauthorised access to a network. A firewall sits between a trusted internal network and the untrusted world outside, inspects the traffic crossing it and permits only what its rules allow, dropping the rest; it may be a hardware appliance, a software program or both together. Option A is wrong because unrestricted access is the exact opposite of what a firewall exists to provide, and a network left open in that way needs no firewall at all. Option C is wrong because taking backups is the work of backup software and storage policy; a firewall keeps no copy of data and would not help after a disk failure. Option D is wrong because option B states the purpose correctly. Note the common types for objective questions: packet filtering, stateful inspection and the proxy or application gateway firewall.
What is the term for a cyber security attack that targets multiple interconnected devices simultaneously to create a large-scale attack network?
- A.DDoS attack
- B.Botnet attack
- C.Zero-day attack
- D.Spear phishing attack
Show answer
Correct answer: B. Botnet attack
Explanation
The correct answer is B, botnet attack. A botnet is built by infecting many connected devices, each of which becomes a zombie obeying a single controller; the network so assembled is then rented out or used for spam, fraud or a flood of traffic. The wording of the question, many interconnected devices turned into one attack network, describes the building of the botnet itself. Option A is wrong for a reason worth understanding: a distributed denial of service attack is usually launched from a botnet, but it names the flooding of one victim, not the assembling of the device network. Option C is wrong because a zero-day attack exploits a flaw the vendor does not yet know of and has nothing to do with numbers of devices. Option D is wrong because spear phishing is a targeted fraudulent message sent to one chosen person.
The feature(s) of cyber security is/are:
- A.Compliance
- B.Defence against internal threats
- C.Threat prevention
- D.All of the above
Show answer
Correct answer: D. All of the above
Explanation
The correct answer is D, all of the above, because cyber security is not one activity but a programme that covers all three. Option A by itself is incomplete: compliance means following the rules, standards and laws that apply to the data an organisation holds, and it is only one strand of the work. Option B by itself is incomplete as well: defence against internal threats guards against the employee who misuses access or leaks data, a large share of real incidents, but an organisation that watched only its insiders would still fall to an outside attack. Option C by itself is incomplete too: threat prevention covers firewalls, antivirus, patching and monitoring that stop an attack before it lands. Since each of the three is a genuine part of cyber security and none of them alone is the whole, the combined option is the answer.
In the CIA triad of information security, the letter I stands for:
- A.Identification
- B.Integrity
- C.Internet
- D.Isolation
Show answer
Correct answer: B. Integrity
Explanation
The correct answer is B, integrity. The triad names the three goals of information security: confidentiality, that only authorised people can read the data; integrity, that the data is complete and unaltered from the moment it was created or sent; and availability, that the system works when an authorised user needs it. Option A is wrong because identification, along with authentication, is a means of achieving these goals rather than one of the three goals themselves. Option C is wrong because the internet is the medium over which most attacks travel and is no part of the model. Option D is wrong because isolation, such as keeping a critical machine off the network, is one technique among many for protecting a system. A useful way to recall the triad is to ask who may read the data, whether it can be changed, and whether it can be reached.