✅ UNIT–1 (Cyber Crime) – Short Answer (3
Marks Each)
1) Define cybercrime with examples.
Cybercrime means any illegal activity done using computers, mobile phones,
or the internet.
It targets systems, data, or people online.
Examples:
Hacking someone’s computer or account
Spreading viruses
Online banking fraud
Identity theft
Cybercrime causes financial loss and harms privacy.
2) What is the importance of information security in the
digital era?
Information security protects data from unauthorized access, misuse, or loss.
In today’s digital world, people store personal, financial, and business data
online.
Security ensures:
Safety of sensitive information
Prevention of cyberattacks
Trust in online services
Smooth working of organizations and digital transactions
3) What are the main classifications of cybercrimes?
Cybercrimes can be divided into three main types:
1. Crime against Individuals – identity theft, cyberstalking, email
scams
2. Crime against Property – hacking, data theft, spreading malware
3. Crime against Government/Organizations – cyber terrorism,
attacking servers, website defacement
These categories show how cybercrime affects people and systems
differently.
4) Explain the concept of Cybercrime Era.
Cybercrime Era refers to the modern period where technology is widely used,
and criminals use digital methods to commit crimes.
With increasing internet users and digital services, cyber threats have also
grown.
This era highlights the need for awareness, strong security, and laws to
protect users online.
5) What is “Survival Mantra” for netizens?
Survival Mantra means simple safety rules that every internet user should
follow to stay protected.
Examples:
Use strong and unique passwords
Do not share personal details with strangers
Avoid clicking unknown links
Keep software and antivirus updated
Be aware of fake messages and scams
These habits help netizens stay safe from cyber threats.
6) What are phishing attacks? How do they work?
Phishing is a cyber-attack in which attackers trick people into giving personal
information like passwords, bank details, or OTPs.
How it works:
Attackers send fake emails, messages, or websites that look real.
The victim clicks the link and enters sensitive information.
The attacker collects and misuses that data.
Phishing mainly targets human trust rather than systems.
7) Explain botnets and their role in cyberattacks.
A botnet is a network of infected computers controlled by a hacker (called
botmaster).
Each infected device becomes a “bot” and follows the attacker’s commands.
Role in cyberattacks:
Launching DDoS attacks
Sending spam emails
Spreading malware
Stealing data
Botnets are powerful because they use thousands of devices at the
same time.
8) What is cyberstalking? Give examples.
Cyberstalking means continuously harassing or threatening a person through
online platforms.
It affects a person’s privacy and mental peace.
Examples:
Sending repeated unwanted messages
Tracking someone’s online activities
Posting false information to harm reputation
Using fake accounts to follow or threaten someone
9) Explain cyberspace and its characteristics.
Cyberspace refers to the virtual world created by computers, networks, and
the internet.
It is where online communication, data sharing, and digital activities happen.
Characteristics:
Borderless world
Fast and real-time communication
Large amount of information
Anonymous interactions
Highly interconnected systems
10) What is an attack vector? Provide examples.
An attack vector is a method or path through which a hacker enters a system
to perform an attack.
It helps attackers spread malware, steal data, or damage systems.
Examples:
Phishing emails
Malware-infected files
Unsecured Wi-Fi
Weak passwords
Social engineering attacks
11) Differentiate between cybercrime and
traditional crime.
Cybercrime:
Done using computers, mobile phones, or the internet.
Criminals can be anonymous and far away.
Example: hacking, phishing, data theft.
Traditional Crime:
Happens physically in the real world.
Criminals are usually present at the location.
Example: robbery, murder, physical assault.
Cybercrime is digital, while traditional crime is physical.
12) What are common motivations behind
cybercriminals?
Cybercriminals commit crimes for different purposes:
1. Financial Gain – stealing money, online fraud, ransomware
2. Revenge or Personal Grudge – harming someone’s reputation
3. Fun or Challenge – hacking for enjoyment or showing skills
4. Political or Ideological Reasons – cyber terrorism
5. Data Theft – stealing personal or organizational information
13) Short note: Spam
Spam refers to unwanted or bulk messages sent over email, SMS, or social
media.
It is mainly used for advertising or spreading malware.
Spam wastes time, fills inboxes, and can also be dangerous if it contains
malicious links.
14) Short note: Malware
Malware means “malicious software” designed to damage or steal data from
a system.
Types include virus, worm, Trojan, ransomware, spyware, etc.
Malware can corrupt files, slow down systems, steal personal information,
and allow hackers to control devices.
15) Short note: Hacking
Hacking is the process of breaking into a computer system or network
without permission.
Hackers exploit weaknesses in software or security settings.
It can lead to data theft, system damage, or loss of privacy.
Hacking can be ethical (for security testing) or illegal (for cybercrime).
✅ UNIT–2 – Short Answers (3 Marks Each)
1) What are mobile and wireless devices? Why are
they vulnerable?
Mobile and wireless devices include smartphones, tablets, laptops,
smartwatches, etc., that use Wi-Fi, Bluetooth, or mobile networks to connect.
They are vulnerable because:
They connect to open or public networks
They store sensitive personal data
They can easily get lost or stolen
Apps may have weak security
This makes them a common target for attackers.
2) Discuss trends in mobile technology and related
risks.
Recent trends in mobile technology include mobile banking, online shopping,
cloud storage, 5G networks, and advanced apps.
Related risks include:
Increased chances of malware attacks
Data leakage through apps
Privacy issues due to permissions
Network-based attacks through Wi-Fi or Bluetooth
More technology means more attack points.
3) List and explain security challenges faced by
mobile devices.
Mobile devices face different security problems such as:
1. Malware infections – harmful apps or files
2. App permissions misuse – apps accessing camera, location,
contacts
3. Network attacks – connecting to unsafe Wi-Fi networks
4. Device theft – loss of data if stolen
5. Outdated software – old versions with vulnerabilities
These issues can compromise data and privacy.
4) What are registry settings in mobile devices?
Registry settings store important configuration information of the device,
apps, and system.
They control how the device behaves, manages resources, and stores user
preferences.
If attackers change registry settings, they can:
Modify system functions
Install unauthorized apps
Bypass security features
Thus, registry security is necessary for device safety.
5) Explain authentication services used in mobile
environments.
Authentication services verify a user's identity before giving access.
Common methods include:
PIN / Password – basic protection
Biometrics – fingerprint, face unlock
Two-Factor Authentication (2FA) – OTP or app-based verification
Token-based authentication – security keys
These services ensure that only authorized users can access the device
or apps.
6) How infections spread in mobile devices?
Mobile infections (malware) spread through several ways:
Downloading untrusted apps from third-party stores
Opening suspicious links or email attachments
Connecting to infected devices via Bluetooth or USB
Using unsecured Wi-Fi networks where attackers inject malware
Installing cracked or modified apps
These infections can steal data, damage the system, or track user
activity.
7) What are security implications of a stolen
mobile phone?
If a phone gets stolen, it can cause:
Loss of personal data (photos, contacts, messages)
Unauthorized access to banking apps, email, and social media
Identity theft if attacker misuses saved information
Corporate data leak if phone is used for work
Financial loss through digital payment apps
A stolen phone becomes a major security risk if not protected with
passwords or remote lock.
8) What is Mobile Device Management (MDM)?
MDM is a security solution used by organizations to manage and control
employee mobile devices.
It helps in:
Enforcing security policies
Remote locking or wiping data
Monitoring device activity
Installing or restricting apps
MDM ensures that official data remains safe, even if the device is lost
or misused.
9) Explain SIM card cloning with example.
SIM cloning means creating a duplicate SIM card that has the same
information as the original one.
Attackers copy the IMSI and authentication key from the victim’s
SIM.
Example:
A hacker clones someone’s SIM and receives their calls and OTPs.
This allows them to hack banking accounts or social media by
intercepting verification messages.
10) Discuss the importance of encryption in mobile
security.
Encryption converts data into unreadable code so unauthorized users cannot
access it.
Importance:
Protects personal and financial data
Secures communication (messages, calls, emails)
Protects stored files even if device is stolen
Prevents misuse of sensitive information
Encryption is one of the strongest methods to ensure data privacy.
11) What is mobile malware? Name and explain
types.
Mobile malware is harmful software designed to attack mobile devices, steal
data, or damage the system.
Types:
Virus: Attaches to files and spreads when the file is opened.
Worm: Spreads automatically through networks like Wi-Fi or
Bluetooth.
Trojan: Looks like a normal app but secretly performs harmful
activities.
Mobile malware can steal passwords, spy on users, or damage the
device.
12) What is the role of biometrics in mobile
security?
Biometrics use unique human characteristics to verify identity.
Common types include fingerprint, face recognition, iris scan, and voice
recognition.
Role:
Provides strong and fast authentication
Reduces dependency on passwords
Prevents unauthorized access
Increases overall device security
Biometrics make mobile security more reliable and user-friendly.
13) What is the need for mobile app security
testing?
Mobile apps store sensitive data like passwords, banking details, and
personal info.
Security testing ensures:
No vulnerabilities in the app
Safe storage and handling of data
Protection against malware, hacking, and data leaks
Trust for users and compliance with security standards
It helps prevent cyberattacks through mobile apps.
14) Explain NFC-based attacks.
NFC (Near Field Communication) allows short-range communication between
devices.
Attackers can misuse NFC in several ways:
Eavesdropping: Intercepting data being transferred
Data Modification: Changing information being sent
Unauthorized payments: Triggering unwanted transactions
NFC attacks occur when users keep NFC on or tap unknown devices.
✅ UNIT–3 – Short Answers (3 Marks Each)
1) What are anonymizers? How do they work?
An anonymizer is a tool or service that hides the user’s identity while
browsing the internet.
It works by routing a user’s internet traffic through different servers, masking
their real IP address.
This prevents websites and attackers from tracking location or identity.
Examples: VPN, Tor browser.
2) Explain proxy servers and their uses.
A proxy server acts as an intermediary between a user and the internet.
When a user sends a request, the proxy forwards it and returns the
response.
Uses:
Hides user IP address
Filters content (block/unblock websites)
Increases browsing speed with caching
Provides security against attacks
Proxy servers help maintain privacy and control network traffic.
3) What is phishing? Explain with an example.
Phishing is a cyberattack where attackers pretend to be trusted sources to
steal personal information.
They send fake emails, messages, or links.
Example:
A user receives a fake bank email asking to “verify account.”
When they click and enter login details, attackers steal the information.
Phishing mainly targets human trust.
4) Explain keyloggers and how they steal data.
A keylogger is a malicious program or device that records every keystroke
typed on a computer or phone.
How it steals data:
Captures typed passwords, messages, and credit card numbers
Sends recorded data to the attacker
Runs silently in the background
Keyloggers are used for spying, identity theft, and online fraud.
5) What are spyware and adware?
Spyware:
A malicious software that secretly monitors user activities and steals data
like browsing habits, passwords, and personal details.
Adware:
Software that displays unwanted advertisements on the device.
It may track user behavior to show targeted ads.
Both slow down the system and affect privacy.
6) Explain viruses and worms with differences.
Virus:
Attaches itself to files or programs.
Spreads only when the infected file is executed.
Can corrupt files or slow down the system.
Worm:
Does not need a host file.
Spreads automatically through networks.
Consumes bandwidth and causes network slowdown.
Difference:
Virus needs user action to spread; worm spreads on its own.
7) What are Trojan horses?
A Trojan horse is malicious software disguised as a useful or legitimate
application.
When installed, it secretly performs harmful activities like:
Stealing data
Giving remote access to attackers
Downloading more malware
Trojans rely on tricking users rather than self-spreading like viruses or
worms.
8) How do backdoors work?
A backdoor is a hidden entry point in a system created by attackers or poorly
designed software.
It allows unauthorized access without normal authentication.
Attackers use backdoors to:
Bypass security controls
Install malware
Steal or manipulate data
Backdoors are dangerous because they remain hidden for long periods.
9) What is steganography?
Steganography is the technique of hiding secret information inside another
file, such as an image, audio, or video.
The hidden message is not visible to normal users.
It is used for:
Secret communication
Hiding confidential data
Avoiding detection by security tools
It differs from encryption because the existence of the message is
hidden.
10) What is SQL injection?
SQL injection is a cyberattack where attackers insert malicious SQL
commands into a website’s input fields.
This tricks the database into revealing or modifying sensitive data.
Attackers can:
Access usernames and passwords
Delete or change database records
Take full control of the website
It occurs due to poor input validation.
11) What is spoofing?
Spoofing is a cyber technique in which attackers fake their identity to trick
users or systems.
They change information like email address, IP address, caller ID, or website
URL.
Purpose:
Steal information
Spread malware
Gain unauthorized access
Spoofing works by making the victim believe the attacker is a trusted
person or service.
12) Explain identity theft.
Identity theft occurs when a criminal illegally uses someone’s personal
information—like name, Aadhaar number, phone number, bank details, or
passwords—to commit fraud.
Attackers may:
Open fake bank accounts
Make unauthorized transactions
Misuse social media accounts
Identity theft leads to financial loss and privacy violations.
13) What is an exploit kit?
An exploit kit is a collection of tools used by cybercriminals to find and
attack software vulnerabilities.
It scans the victim’s device for weaknesses in browsers, plugins, or
applications.
Once a weakness is found, it automatically installs malware.
Exploit kits make cyberattacks easier even for attackers with low
technical skills.
14) Describe ransomware attacks.
Ransomware is malicious software that locks or encrypts a user’s data
and demands money (ransom) to unlock it.
Attackers usually spread ransomware through emails, malicious links,
or infected downloads.
The victim cannot access their files until they pay the ransom, but
payment doesn't guarantee recovery.
It is one of the most dangerous cybercrimes today.
15) Notes: Sniffers, Footprinting, Recon Tools
Sniffers:
Tools that capture network traffic to read usernames, passwords, and data
packets. Used for monitoring or attacks.
Footprinting:
Process of collecting information about a target system or organization
before attacking (like IP address, domain, network details).
Recon Tools:
Tools used for reconnaissance (information gathering) such as Nmap,
Wireshark, Maltego.
They help attackers or security professionals understand the target’s
weaknesses.
✅ UNIT–4 – Short Answers (3 Marks Each)
1) What is digital forensics?
Digital forensics is the process of collecting, analyzing, and preserving digital
evidence from computers, mobiles, and other electronic devices.
Its main purpose is to investigate cybercrimes and present evidence in court.
It ensures that data is collected legally and without tampering.
2) Branches of digital forensics.
Digital forensics has several branches based on the type of device or data:
Computer Forensics: Investigation of computers, laptops, storage
media.
Mobile Forensics: Extraction of data from mobile phones and tablets.
Network Forensics: Monitoring and analyzing network traffic to
detect attacks.
Cloud Forensics: Investigation of data stored on cloud platforms.
Email Forensics: Examining emails to trace fraud, threats, or
phishing.
3) Need for computer forensics.
Computer forensics is needed to:
Investigate cybercrimes such as hacking, fraud, or data theft
Recover deleted or damaged data
Provide digital evidence in legal cases
Detect insider threats within an organization
Prevent future cyberattacks by understanding how the attack
happened
4) Email forensic analysis.
Email forensics involves examining email messages to find evidence of
cybercrimes.
It includes checking:
Sender and receiver details
Email headers (IP address, routing path)
Attachments and links
Time stamps
It helps solve phishing attacks, harassment cases, fraud, and corporate
data leaks.
5) Digital evidence.
Digital evidence is any information stored or transmitted in digital form that
can be used in court.
Examples: emails, logs, images, call records, browsing history, USB data.
Characteristics:
Easily altered, so must be handled carefully
Must be authentic and reliable
Should be collected using proper forensic techniques
6) Chain of custody.
Chain of custody is the documented process that shows how digital evidence
was handled from the moment it was collected until it is presented in court.
It includes:
Who collected the evidence
When and where it was collected
How it was stored and transferred
This ensures that the evidence is not altered or tampered with and
remains valid in legal proceedings.
7) Metadata in investigations.
Metadata is “data about data.”
It provides hidden details such as:
File creation date
Modification history
Author name
Location data (GPS) in photos
Investigators use metadata to trace activities, verify timelines, and
identify suspects in cybercrime cases.
8) Forensic tools.
Forensic tools help in collecting, analyzing, and recovering digital evidence.
Common tools include:
EnCase: For imaging and analyzing hard drives
FTK (Forensic Toolkit): For index search and file recovery
Autopsy: Open-source tool for investigating disk images
These tools make forensic work accurate and reliable.
9) Social media forensics.
Social media forensics involves collecting and analyzing data from platforms
like Facebook, Instagram, Twitter, and WhatsApp.
It helps in cases of:
Cyberbullying
Identity theft
Harassment
Fake accounts
Investigators examine posts, messages, photos, and account activity to
gather evidence.
10) Privacy issues in forensics.
Digital forensics may involve accessing personal data, which can raise
privacy concerns.
Issues include:
Viewing private messages or photos
Accessing confidential files
Misuse or leakage of sensitive information
To avoid this, investigators must follow legal procedures and work
within authorized limits.
11) Live vs Dead Forensics.
Live Forensics:
Performed when the system is running.
Collects data such as RAM contents, network connections, active
processes.
Useful for detecting ongoing attacks.
Dead Forensics:
Performed when the system is powered off.
Analyzes storage devices like HDD, SSD, USB.
Safer because data does not change during investigation.
Both methods help investigators understand different aspects of a cyber
incident.
12) Forensic imaging.
Forensic imaging is the process of creating an exact bit-by-bit copy of a
digital storage device.
The image includes all files, hidden data, and deleted information.
This ensures the original evidence is preserved while investigation is done on
the copied image, preventing data alteration.
13) Disk cloning and hashing.
Disk Cloning:
Creating a complete duplicate of a storage device for analysis or backup.
Hashing:
Generating a unique digital fingerprint (hash value) of data using algorithms
like MD5 or SHA-1.
If the hash value remains the same, it proves the data was not changed.
Hashing ensures evidence integrity.
14) Notes: Autopsy, EnCase, FTK
Autopsy:
An open-source digital forensics tool used for analyzing hard drive images,
recovering deleted files, and generating reports.
EnCase:
A professional forensic tool widely used by law enforcement for imaging,
analyzing, and documenting digital evidence.
FTK (Forensic Toolkit):
A powerful tool that supports fast indexing, searching, and file recovery.
Helps investigators quickly find relevant evidence.
✅ UNIT–5 – Short Answers (3 Marks Each)
1) Need for security policies.
Security policies are required to protect an organization’s data, systems, and
networks from threats.
They define rules on how employees should handle information.
They help:
Prevent unauthorized access
Reduce cyber risks
Ensure safe use of technology
Without security policies, data breaches and misuse can easily occur.
2) Components of a good security policy.
A good security policy includes:
Purpose: Why the policy exists
Scope: Who and what it applies to
Roles & Responsibilities: Duties of employees and IT staff
Security Controls: Password rules, access rules, backup rules
Incident Response: Steps to handle cyber incidents
These components ensure clarity and strong protection.
3) Objective of information security.
The main objectives are:
Confidentiality: Only authorized people can access data
Integrity: Data remains accurate and unchanged
Availability: Data and systems are accessible when needed
These three form the CIA Triad and ensure complete information
protection.
4) Types of security policies.
Common types include:
Access Control Policy: Rules for who can access what
Password Policy: Requirements for strong passwords
Network Security Policy: Safe use of networks and Wi-Fi
Backup Policy: How data should be backed up
Acceptable Use Policy: Defines allowed and prohibited activities on
company devices
These policies help maintain a secure working environment.
5) Intellectual property.
Intellectual Property (IP) refers to creations of the mind such as
inventions, designs, software, music, writing, etc.
IP laws protect these creations from being copied or misused.
Types of IP include copyrights, trademarks, and patents.
IP protection encourages innovation and creativity.
6) Copyrights.
Copyright is a legal protection given to creators of original work such
as books, music, software, videos, and artwork.
It prevents others from copying, distributing, or selling the work
without permission.
Copyright ensures that creators get credit and financial benefit for
their work.
7) Trademarks.
A trademark is a symbol, word, logo, design, or phrase used by a
company to represent its brand.
Examples: Nike logo, Apple symbol.
Trademarks prevent others from using similar marks that may confuse
customers.
They help maintain brand identity and trust.
8) Patent law.
A patent is a legal right granted to an inventor for a new product,
process, or technology.
It gives exclusive rights to make, use, or sell the invention for a fixed
period (usually 20 years).
Patent law encourages innovation by protecting inventors from
unauthorized copying.
9) Cyberbullying law.
Cyberbullying involves online harassment, threats, or humiliation through
social media, messages, or emails.
In India, cyberbullying is punishable under:
IT Act, Section 66A (now replaced by related IPC sections)
IPC Sections 354D (stalking), 506 (criminal intimidation)
These laws help protect individuals—especially students and teenagers
—from online abuse.
10) Privacy & data protection.
Privacy and data protection refer to safeguarding personal information from
unauthorized access and misuse.
Organizations must follow rules to protect user data, such as:
Not sharing data without permission
Encrypting sensitive information
Collecting only necessary data
These measures ensure user trust and prevent data breaches.
11) E-transaction legal issues.
E-transactions (online payments) involve legal issues such as:
Fraud & Unauthorized transactions: Hackers may access accounts.
Identity theft: Customer details may be stolen.
Data privacy concerns: Sensitive financial data can be misused.
Lack of proper authentication: Weak verification increases risks.
Laws like the IT Act help in regulating e-commerce and protecting
users.
12) Cyber defamation.
Cyber defamation occurs when someone posts false information online
to damage another person’s reputation.
It can happen through social media posts, emails, blogs, or messages.
It is punishable under the IT Act and IPC Sections 499 & 500.
Cyber defamation affects both personal and professional image.
13) Cyber ethics.
Cyber ethics are rules and moral principles for using the internet responsibly.
They include:
Not hacking or harming others’ systems
Respecting privacy
Avoiding fake news, bullying, or cheating
Using software legally
Cyber ethics ensure safe, respectful, and fair use of technology.
14) Importance of IPR.
Intellectual Property Rights (IPR) protect inventions, creative work, and brand
identity.
Their importance includes:
Preventing unauthorized copying
Encouraging innovation
Helping creators earn recognition and income
Supporting economic growth
IPR ensures fair use and rewards creativity.
15) Notes: Digital Signature, Cyber Contract,
Computer Offenses
Digital Signature:
A secure electronic signature used to verify the identity of the sender and
ensure that the document has not been altered.
Cyber Contract:
A legally valid agreement made through electronic means such as emails, e-
forms, or online terms & conditions.
Computer Offenses:
Crimes involving computers such as hacking, data theft, malware attacks,
phishing, ransomware, and unauthorized access.