Nasscom Model Questions
Module 8
Module 8: Cybersecurity and Data Protection
Question 1
_________ uses software and hardware methods to tackle external threats that can
arise in the development stage of an application.
(a) Disaster Recovery
(b) Application Security
(c) Information Security
(d) Endpoint Security
Answer: b) Application Security
Question 2
Critical Infrastructure does not include:
(a) Electricity Grid
(b) Water Purification
(c) Traffic Lights
(d) Cooking Gas Lines
Answer: d) Cooking Gas Lines
Question 3
The full form of SEG is:
(a) Secure Email Gateway
(b) Secure Ecommerce Gateway
(c) Security Email Gateway
(d) Secure Email Gate
Answer: a) Secure Email Gateway
1|Page
Question 4
Application security uses software and hardware methods to tackle external threats.
(a) True
(b) False
Answer: a) True
Question 5
Who alongside the FDA recently launched a joint initiative to "increase coordination in
dealing with threats related to medical devices?
(a) HHS
(b) DHS
(c) LHS
(d) AHS
Answer: b) DHS
Question 6
Prioritizing simple security strategies is the best way to defeat evolving security threats.
(a) True
(b) False
Answer: b) False
Question 7
The easiest way for attackers to gain network access is to:
(a) Leverage existing vulnerabilities
(b) Creating new vulnerabilities
(c) Send Spam mails
Answer: a) Leverage existing vulnerabilities
2|Page
Question 8
A cybersecurity framework can be any document that defines procedures and goals to
guide more detailed cybersecurity policies.
(a) True
(b) False
Answer: a) True
Question 9
Which of the following is the recommended security standard for electronic payment
processing?
(a) COBIT
(b) HiPAA rules
(c) PCI DSS
Answer: c) PCI DSS
Question 10
It's impractical to use multiple cybersecurity solutions to address different threats to
your infrastructure.
(a) True
(b) False
Answer: b) False
Question 11
Hackers are always looking for opportunities to invade privacy and steal data that's of
crucial importance.
(a) True
(b) False
Answer: a) True
3|Page
Question 12
A cyber attack is any type of offensive action that targets computer Information
systems, infrastructures, computer networks or personal computer devices, using
various methods to steal, alter or destroy data or information systems.
(a) True
(b) False
Answer: a) True
Question 13
One of the easiest ways your information can become hacked is through easy-to-guess
passwords.
(a) True
(b) False
Answer: a) True
Question 14
Which attack involves using IP spoofing and the ICMP to saturate a target network with
traffic?
(a) Smurf attack
(b) Teardrop attack
(c) Replay attack
Answer: a) Smurf attack
Question 15
Botnets are the millions of systems infected with malware under hacker control in order
to carry out DDoS attacks.
(a) True
(b) False
Answer: a) True
4|Page
Question 16
Which of the following are true for Data Privacy?
(a) Data Privacy is a branch of Data Security which deals mainly with the handling of
data
(b) Consent, Data Collection and Regulatory Compliance are the main entities of Data
Privacy
(c) Data Security concentrates on keeping data safe from attacks and hackers
(d) Regulations such as GDPR, HIPAA, GLBA, or CCPA are entitled to protect data when
sharing with third parties
Answer: a, b, d
Question 17
What are the benefits of Data Control ?
(a) Data flaws are identified before they cause issues
(b) Root cause of issues are identified and remediated
(c) Data is monitored and controlled
(d) Sensitive data can be mishandled
Answer: a, b, c
Question 18 What are the types of Data Security control? (Select all that apply.) (a) Data
Encryption (b) Data Masking (c) Data Corruption (d) Data Resilience (e) Data Erasure
Answer: a, b, d, e
Question 19
Automating process helps in reducing the number of data silos and the risk of human
error.
(a) True
(b) False
Answer: a) True
5|Page
Question 20
What steps should your organization take to ensure compliance with Data Privacy
regulations?
(a) Implement a robust compliance strategy with primary focus on Data Privacy
(b) Hire Subject Matter Experts who are well-versed with compliance regulations
(c) Call the authorities in case of a Data Breach
(d) Maintain an inventory of personal information
Answer: a, b, d
Question 21
Which are the five types of Deepfakes?
(a) Textual Deepfakes
(b) Deepfake Videos
(c) Deepfake Coding
(d) Deepfake Images
(e) Deepfake Audio
(f) Live Deepfake
Answer: a, b, d, e, f
Question 22
Which are some of the ways through which businesses can protect against Deepfakes?
(a) Verifying authenticity with the original source
(b) Superimposing images and videos to assess dissimilarities
(c) Detecting Deepfakes by using the technology against itself
(d) Accelerating Digital Transformation and Education
Answer: a, c, d
6|Page
Question 23
Deepfakes are manipulated content powered by Machine Learning and are produced in
different forms, such as text, audio, images, videos, and even real-time streams.
(a) True
(b) False
Answer: a) True
Question 24
According to Steinberg, which are the three Deepfake threat categories ?
(a) Disinformation campaigns mostly involving edits to legitimate content
(b) Subtle changes to images, logos, and other content to bypass automated detection
tools
(c) Synthetic or composite Deepfakes that are derived from a collection of originals
(d) Replicas of legitimate email addresses with a slight variation that is easily missed
Answer: a, b, c
Question 25
What type of cybercrime is described as potentially becoming more financially
damaging due to deepfakes?
(a) Ransomware attacks
(b) Distributed Denial of Service (DDoS) attacks
(c) Business Email Compromise (BEC) scams
(d) Man-in-the-middle attacks
Answer: c) Business Email Compromise (BEC) scams
7|Page