Top Network Security Interview Questions
Top Network Security Interview Questions
Q8. What are the factors that affect the performance of the
network?
Ans. The factors that affect the performance of the network are:
“Wired” refers to any physical medium connected via wires and cables.
wireless” refers to the transmission of electromagnetic or infrared waves across the air.
Application layer
Presentation layer
Session layer
Pure Aloha
Slotted Aloha
SMTP
DNS
TELNET
FTP
Access control
Antivirus and antimalware software
Application security
Data Loss Prevention (DLP)
Email security
Firewalls
Intrusion prevention systems
Mobile device security
Host-based Intrusion Detection System (HIDS)
Network Intrusion Detection System (NIDS)
Behavioral analytics
Network segmentation
Virtual Private Network (VPN)
Web security
Wireless security
Authentication ascertains whether a user is legitimate to use the system and the network
or not. It requires a login and password.
Authorization refers to access control rights. It means that every user on the network can
access only certain data and information, depending on his/her level in the organization.
Accounting helps in gathering all activity on the network for each use.
Biometric Authentication
Password Authentication Protocol (PAP)
Authentication Token
The IPS reports such events to system administrators and takes preventative action, such as
closing access points and configuring firewalls to prevent future attacks.
Network encryption helps maintain the confidentiality of information transmitted over a network
by making it difficult for unauthorized agents to have the information and understand it or get
anything useful from it if they intercept the information in transit. Each message is sent in an
encrypted form and is decrypted and converted back into its original form at the recipient’s end
using encryption/decryption keys.
Q25. What do you mean by the CIA Triad?
Ans. CIA stands for Confidentiality, Integrity, and Availability. CIA or CIA Triad is a popular
model designed to maintain privacy policies for information security in organizations. Security
professionals evaluate threats after assessing their potential impact on the organisation’s assets’
confidentiality, integrity, and availability. A network is secure only when it possesses the CIA
Triad components.
Confidentiality refers to an organization’s efforts to keep its data private or secret. Thus,
only authorised people have access to specific assets, while unauthorised people are
prevented from accessing them.
Integrity refers to ensuring that data is authentic and reliable. Also, it has not been
tampered with.
Availability refers to ensuring that systems, applications, and data are up and running;
and authorized users can access resources when needed.
Now let’s take a look at some Firewall-related Network Security interview questions.
Volume-based attacks – they use high traffic to overload the network bandwidth
Protocol attacks – their objective is to exploit server resources
Application attacks – they focus on web applications and are the most serious type of
attacks
Different types of attacks fall into categories based on the traffic quantity and the vulnerabilities
being targeted. Here are some popular types of DDoS attacks:
The software gets into your network by an executable file that may have been in a zip folder or
any other attachment. The download file will then encrypt your data, add an extension to your
files, and makes them inaccessible.
CryptoLocker
WannaCry
Bad Rabbit
Cerber
Crysis
CryptoWall
GoldenEye
Jigsaw
TeslaCrypt
TorrentLocker
Locky
Now, let’s move forward with some Malware-related Network Security interview questions.
The phishers dupe victims into opening those emails or text messages, and the victim is coaxed
into providing confidential information, leading to devastating results.
Apart from stealing sensitive data, hackers can infect computers with viruses and convince
victims to participate in money laundering.
1. Email Phishing: This is the most common type of Phishing. The phisher will register a
fake domain that looks like a genuine source and send generic requests to obtain
confidential information from the victims. Phishers use the data to steal money or to
launch other attacks.
2. Spear Phishing: It targets specific individuals instead of a wide group of people after
searching the victims on social media and other sites to customize their communications
and appear more authentic.
3. Whaling: In this, the attackers go after those working in senior positions. Attackers
spend considerable time profiling the target to find the best way to steal their sensitive
information.
4. Smishing and Vishing: In smishing, the victim is contacted through text messages, while
vishing involves a telephonic conversation. Both end goals are the same as any other kind
of phishing attack.
This practice has grown exponentially lately with adopting of cloud-based applications and
services. Shadow IT can introduce security risks to the organization through data leaks and
potential compliance violations.
Hardware: PCs, laptops, tablets, servers, flash drives, external drives, and smartphones
Productivity apps: Trello and Slack
Communication apps: Skype and VOIP
Packaged software
Cloud Services: Software as a Service (SaaS), Infrastructure as a Service (IaaS), and
Platform as a Service (PaaS)
What is a Hub?
Hub definition: A hub is a network device in a computer network where data from various
directions converge and are then distributed to various devices.
In lay terms, a hub is a device that allows various computers/PCs and other devices to connect to
a single network.
A hub sends data packets to all network devices, regardless of whether the data packet contains
any MAC addresses. A hub has many ports, and a computer that wants to connect to the network
plugs into one of them. When a data frame arrives at a port, the hub broadcasts it to all other
ports, regardless of whether it is destined for a specific destination.
Active hub: An active hub has its own power supply and can clean, improve, and relay
network signals.
Passive hub: A passive hub collects power from active hub devices and wiring from
nodes. Aside from that, a hub sends signals into the network without cleaning or boosting
them.
Applications of Hub
There are various applications of a hub, and some of the most important ones are:
For more information regarding Hub, you can also explore: What is Hub in Computer
Networks?
Explore the fundamentals of operating systems. Explore our top OS programmes offered by the
best colleges in India and online Operating system Courses, and advance your career.
What is a Switch?
Switch definition: A switch is a networking device that connects multiple devices on a single
computer network.
You can use a switch to open or close a connection. When the switch is opened, a signal or
power can pass through the connection. The flow is stopped, and the circuit connection is broken
when the switch is closed.
A switch keeps a table of the addresses of the computers connected to it. When traffic passes
through, the switch reads the address of the destination and routes it to the relevant computer
rather than all connected computers. The traffic is routed to all connected computers if the
destination address is not in the table.
Manageable switch: As the name suggests, a manageable switch has a console port and
an IP address that can be assigned and configured.
Unmanageable switch: An unmanageable switch is a switch that cannot be configured
as there is no console port; hence it is not possible to assign an IP address.
LAN Switch: This switch connects devices in an organization’s internal LAN (Local
Area Network). This switch allocates bandwidth so that data packets do not overlap in a
network.
PoE Switch: This type of switch is used in PoE (Power over Ethernet) Gigabit Ethernets.
A PoE switch delivers greater flexibility and simplifies the cabling connections.
For more information regarding switches, you can also explore: What Is A Network Switch
And Its Types.
Research leading job-oriented courses post-12th. Also, pursue a fulfilling career through
specialized online degree programs.
Applications of Switch
There are various applications of a switch, and some of the most important ones are:
A hub is a networking device that connects multiple PCs to a single network, whereas a
Switch connects multiple devices on a single computer network.
A hub operates on the OSI physical layer, whereas a switch operates on the OSI data link
layer.
The hub uses a half-duplex cable, whereas the switch uses a full-duplex cable.
The switch is an active device, whereas the hub is a passive device.
The switch employs the Spanning Tree Protocol to avoid switching loops. On the other
hand, the hub cannot avoid switching loops.
The hub shares the bandwidth between the ports. A switch, on the other hand, provides
dedicated bandwidth to the ports.
The number of ports connecting to the device is significantly greater in switches than in
the hub.
The hub’s data transmission speed is quite slow compared to a switch.
A hub network device is difficult to hack, whereas a switch is easily hackable.
A hub device is not so popular nowadays, whereas a switch is quite popular and widely
used.
The switch is an intelligent device that sends messages to selected destinations, whereas a
hub sends messages to all ports.
The hub has only one collision domain, but different ports have their own collision
domain in a switch.
You can also explore: What is the Difference Between Internet and Intranet?
Conclusion
A hub forwards data packets to each connected computer. Assume four computers are linked to a
hub, and two communicate. A hub will send data packets to all four computers. Switches, on the
other hand, can determine the destination of each data packet and selectively route it to the
computer that requires it.
Cryptography refers to the domain of cyber security that serves the purpose of safeguarding
information from individuals known as adversaries, thereby ensuring that the data is exclusively
accessed by only senders and intended recipients.
Traceroute is a network diagnostic tool that helps track the route taken by a packet sent across
the IP network. It also shows the IP addresses of all the routers it pinged between the source and
the destination.
Uses:
It shows the time taken by the packet for each hop during the transmission.
When the packet is lost during the transmission, the traceroute will identify the point of
failure.
In cybersecurity, a firewall refers to a type of network security system that blocks malicious
traffic from hackers and hence maintains the data privacy. This includes bots, phishing links,
worms viruses, malware, trojan viruses, etc.
Uses:
The firewall monitors the inbound and outbound network traffic. It permits or allows only
data packets agreeable to the set of security guidelines the server owner sets.
A firewall acts as a barrier between the internal network and the inbound traffic from
external sources like the Internet.
Enroll in our Cyber Security course to learn from experts and get certified!
Step 1: The client makes a connection with the server with SYN.
Step 3: The client acknowledges the server’s response with ACK, and the actual data
transmission begins.
By providing your contact details, you agree to our Terms of Use & Privacy Policy
5. What is a response code? List them.
HTTP response codes indicate a server’s response when a client makes a request to the server. It
shows whether an HTTP request is completed or not.
1xx: Informational
The request is received, and the process continues. Some example codes are:
100 (continue)
101 (switching protocol)
102 (processing)
103 (early hints)
2xx: Success
The action is received, understood, and accepted successfully. A few example codes for this are:
200 (OK)
202 (accepted)
205 (reset content)
208 (already reported)
3xx: Redirection
To complete the request, further action is required to take place. Example codes:
The request has incorrect syntax, or it is not fulfilled. Here are the example codes for this:
The server fails to complete a valid request. Example codes for this are:
Also, check out this blog for Top Cyber Security Skills!
CIA Triad is a security model to ensure IT security. CIA stands for confidentiality, integrity, and
availability.
Check out our blog on Cyber Security Tips and Best Practices to prevent Cyber Security
attacks!
Data leakage is the term used to describe the unauthorized release of data from a business to a
third party. The internet, email, mobile data, as well as storage devices like USB keys, laptops,
and optical discs, are just a few of the routes via which this transmission may take place.
Career Transition
A port scan helps you determine the ports that are open, listening, or closed on a network.
Administrators use this to test network security and the system’s firewall strength. For hackers, it
is a popular reconnaissance tool to identify the weak point to break into a system.
1. UDP
2. Ping scan
3. TCP connect
4. TCP half-open
5. Stealth scanning
10. Explain brute force attacks and the ways to prevent them.
A brute force attack is a hack where the attacker tries to guess the target password by trial and
error. It is mostly implemented with the help of automated software used to login with
credentials.
Cryptography is a domain of cyber security, and its main purpose is to keep information safe
from individuals known as adversaries and ensure data is accessed by only senders and intended
recipients.
A firewall in cybersecurity is like a wall that keeps track of incoming and outgoing traffic to
block any malicious activity from hackers. This acts like a network security system that can
maintain data privacy. Some malicious activities include bots, phishing links, worms viruses,
malware, trojan viruses, etc.
Uses:
Firewall checks if there are any data violations by monitoring the inbound and outbound
network traffic. Data packets with an agreeable set of security guidelines set by the server
owner are permitted.
It is like a wall, keeping the internal network and outer traffic separate from external
sources like the internet.
Below is a list of cybersecurity attacks that aim to cause damage to the system.
Man in the Middle Attack: As the name suggests, an attacker puts himself in the middle
of the communication between the sender and receiver to steal data by eavesdropping.
Phishing: This type of attack is when the attacker acts like someone trustworthy by
sending links from reputed sources and then stealing your information, like usernames,
passwords, and credit card numbers.
Rogue Software: This type of attack is when the attacker fakes by making the target
believe they have a virus in their system and offers an anti-virus tool to remove the virus.
This is done to install the malware software on the target’s system.
Malware: This is software that is intentionally created to cause harm to the target’s
system. The type of software can be a virus, worm, ransomware, spyware, and so on.
Drive-by Downloads: This is a type of attack that occurs when the target unknowingly
installs a virus. The hacker takes advantage of the lack of updates on OS, apps, or
browsers, which can automatically install virus code into the system.
DDoS: A Distributed Denial of Service attack is when the target’s network, for example,
gets a huge amount of traffic at a time, forcing the website to reach its limit and not
operate.
Malvertising: This is a type of attack where a harmful malware code is injected into a
legitimate advertisement, which will redirect a user to an unintended website.
Password Attacks: As the name suggests, the hacker takes advantage of the tendency of
users to give easy passwords by researching their online-given information. This can then
be used to access password-protected information.
An HTTP response code is a response that the server gives to a client’s request. It is indicated if
an HTTP request is completed or not. Below are the code statuses and their categories:
1xx: Informational
This tells us that the request has been received and the process can continue. Below are some of
the sample code statuses:
100 (continue)
101 (switching protocol)
102 (processing)
103 (early hints)
2xx: Success
This code indicates that the action was successful by receiving, understanding, and accepting the
information.
200 (OK)
202 (accepted)
205 (reset content)
208 (already reported)
3xx: Redirection
This code status indicates that to complete the request, an additional action is required. Below
are some examples of the codes:
This indicates that the requested page couldn’t be reached or the request has a syntax error.
Below are some of the code examples:
This status is when the server is not able to complete the valid request. Below are some code
examples:
Uses:
It shows the time taken by the packet for each hop during the transmission, where hop is
the move our data makes to go from one point to another.
When the packet is lost during the transmission, the traceroute will identify the point of
failure. This is done by receiving an ICMP time exceeded message from the hop, which
tells us that the time-to-live value of that packet has reached zero.
A three-way handshake is a term given to the process of making the connection between a local
host and the server in a TCP/IP network. As the name suggests, it is a three-way process where
a reliable connection is set up between 2 devices with synchronization (SYN) and
acknowledgment (ACK) before sharing of data.
Step 1: The client first sends a synchronization (SYN) to the server to make the connection.
Step 2: The server then responds to the client’s request with synchronization (SYN) and
acknowledgment (ACK).
Step 3: The client sends back an acknowledgment (ACK) to the server’s response, telling that
the connection was established.
Data leakage is when unauthorized information about a business is sent to a third party via the
internet, mobile data, email, USK keys, laptops, etc.
19. Explain brute force attacks and the ways to prevent them.
This is an attack where the attacker tries to guess the password with trial and error. This is done
with the help of software used to log in with credentials.
A port scan helps to check for open ports, listening, or closed on a network. This is used by
administrators to check for network security and the system’s firewall strength. This is a popular
exploration tool to identify the weak point in the system to break in.
1. UDP
2. Ping scan
3. TCP connect
4. TCP half-open
5. Stealth scanning
The OSI model was introduced by the International Organization for Standardization for
different computer systems to communicate with each other using standard protocols.
Physical layer: This layer allows the transmission of raw data bits over a physical
medium.
Data Link layer: This layer determines the format of the data in the network.
Network layer: It tells which path the data will take.
Transport layer: This layer allows the transmission of data using TCP/UDP protocols.
Session layer: It controls sessions and ports to maintain the connections in the network.
Presentation layer: Data encryptions happen in this layer, and it ensures that the data is
in a usable/presentable format.
Application layer: This is where the user interacts with the application.
Your online activities are protected from the risks of a public internet connection by a virtual
private network, or VPN, which establishes a private and secure network. You may protect tasks
like sending emails, making online payments, and conducting e-commerce by utilizing a VPN to
increase your anonymity and privacy.
Working of VPN
1. When you make a VPN connection, your device routes the internet connection to the
VPN’s private server, instead of your Internet Service Provider (ISP).
2. During this transmission, your data is encrypted and sent through another point on the
internet.
3. When it reaches the server, the data is decrypted.
4. The response from the server reaches the VPN where it is encrypted, and it will be
decrypted by another point in the VPN.
5. At last, the data, which is decrypted, reaches you.
Are you excited to know about the Access Control List, so check out this blog!
28. Who are White Hat, Grey Hat, and Black Hat Hackers?
A black hat hacker uses his/her hacking skills to breach confidential data without permission.
With the obtained data, the individual performs malicious activities such as injecting malware,
viruses, and worms.
Immediate action is required to perform patch management as soon as software updates are
released. It is crucial that all network devices within the organization undergo patch management
within a timeframe of one month or less.
BIOS being hardware, setting it up with a password locks the operating system. There are three
ways to reset the BIOS password:
1. you need to unplug the PC and remove the CMOS battery in the cabinet for 15–30
minutes. Then, you can put it back.
2. You can use third-party software such as CmosPwd and Kiosk.
3. You can run the below commands from the MS-DOS prompt with the help of the debug
tool. For this method to work, you need to have access to the OS installed.
In the Man-in-the-Middle attack, the hacker eavesdrops on the communication between two
parties. The individual then impersonates another person and makes the data transmission look
normal for the other parties. The intent is to alter the data, steal personal information, or get login
credentials for sabotaging communication.
Distributed denial-of-service attack overwhelms the target website, system, or network with
huge traffic, more than the server’s capacity. The aim is to make the server/website inaccessible
to its intended users. A DDoS attack happens in the below two ways:
Flooding attacks: This is the most commonly occurring type of DDoS attack. Flooding attacks
stop the system when the server is accumulated with massive amounts of traffic that it cannot
handle. The attacker sends packets continuously with the help of automated software.
Crash attacks: This is the least common DDoS attack where the attacker exploits a bug in the
targeted system to cause a system crash. It prevents legitimate users from accessing email,
websites, banking accounts, and gaming sites.
Cross-site scripting also known as XSS attack allows the attacker to pretend as a victimised user
to carry out the actions that the user can perform, in turn, stealing any of the user’s data. If the
attacker can masquerade as a privileged victimised user, one can gain full control over all the
application’s data and functionality. Here, the attacker injects malicious client-side code into web
services to steal information, run destructive code, take control of a user’s session, and perform a
phishing scam.
Address Resolution Protocol is a communication protocol of the network layer in the OSI model.
Its function is to find the MAC address for the given IP address of the system. It converts the
IPv4 address, which is 32-bit, into a 48-bit MAC address.
Port blocking within LAN involves the act of preventing users from accessing a specific set of
services within the local area network. The primary objective is to halt the source’s capability to
grant access to destination nodes through ports. As all applications operate on ports, it becomes
crucial to obstruct these ports in order to limit unauthorized access, which could potentially
exploit security vulnerabilities within the network infrastructure.
Application NFS, NIS, SNMP, telnet, ftp, rlogin, rsh, rcp, RIP, RDISC, DNS, LDAP, and
Layer others
Transport Layer TCP, SCTP, UDP, etc.
Internet IPv4, ARP, ICMP, IPv6, etc.
Data Link Layer IEEE 802.2, PPP, etc.
Physical Layer Ethernet (IEEE 802.3), FDDI, Token Ring, RS-232, and others
A botnet, also called a robot network, is a malware that infects networks of computers and gets
them under the control of a single attacker who is called a ‘bot herder.’ A bot is an individual
machine that is under the control of bot herders. The attacker acts as a central party who can
command every bot to perform simultaneous and coordinated criminal actions.
A botnet is usually always responsible for large-scale attacks since a bot herder can control
millions of bots at a time. All the bot can receive updates from the attacker to change their
behavior in no time.
Cross-Site Request Forgery (CSRF) attack, also known as session riding or one-click attack, is a
malicious exploit that tricks a victim into performing unintended actions on a website on which
they are authenticated. It occurs when an attacker exploits the trust between a user’s browser and
a targeted website. The attack takes advantage of the fact that websites often rely on cookies or
other authentication credentials to verify a user’s identity.
When two users have the same password, it will result in the creation of the same password
hashes. In such a case, an attacker can easily crack the password by performing a dictionary or
brute-force attack. To avoid this, a salted hash is implemented.
A salted hash is used to randomize hashes by prepending or appending a random string (salt) to
the password before hashing. This results in the creation of two completely different hashes,
which can be employed to protect the users’ passwords in the database against the attacker.
Address Resolution Protocol (ARP) poisoning, also known as ARP spoofing or ARP cache
poisoning, is a type of cyber attack where an attacker manipulates the ARP tables on a local area
network (LAN). The attack involves sending falsified ARP messages to associate the attacker’s
MAC address with the IP address of another device on the network, redirecting network traffic
intended for that device to the attacker.
It employs encryption algorithms to keep any sensitive data that is sent between a client and a
server by scrambling the data in transit. This helps prevent hackers from reading any data, such
as credit card details and personal and other financial information; it is done by keeping the
internet connection secure.
TLS is the successor of SSL. It is an improved protocol version that works just like SSL to
protect information transfer. However, to provide better security, both TLS and SSL are often
implemented together.
Stay one step ahead: Enhance your knowledge of application security and proactively
mitigate risks in your software!
43. What is 2FA, and how can it be implemented for public websites?
Two-factor authentication (2FA) requires a password, along with a unique form of identification
like a login code via text message (SMS) or a mobile application, to verify a user. When the user
enters the password, they are prompted to enter the security code to log in to the website. If the
code mismatches, the user will be blocked from entering the website.
Let’s get a dive into the Cyber Security Interview Questions for Freshers.
Hashing Encryption
A one-way function where you cannot decrypt Encrypted data can be decrypted to the original
the original message text with a proper key
Used to verify data Used to transmit data securely
Used to send files, passwords, etc. and to
Used to transfer sensitive business information
search
Looking for a rewarding career in ethical hacking? Enroll in our Ethical Hacking course and
pave the way for success!
The Secure Socket Layer (SSL) functions as a security protocol utilized for encryption, enabling
network privacy, data integrity, and authentication, particularly in scenarios like online
transactions.
1. To establish SSL encryption, the following steps are undertaken in an active tone:
2. The browser initiates a connection with an SSL-secured web server.
3. The browser requests the server’s public key while providing its own private key.
4. Upon confirming the server’s trustworthiness, the browser proceeds to establish an
encrypted connection with the web server.
5. The web server acknowledges the request and commences an SSL-encrypted connection.
6. SSL communication takes place between the browser and the web server.
48. With the differential parameters, differentiate between HTTP and HTTPS.
Below mentioned are the differences between HTTP and HTTPS protocols:
A server that is secured uses the Secure Socket Layer (SSL) protocol to encrypt and decrypt data
to protect it from unauthorized access.
Cognitive Cybersecurity is a way of using human-like thought mechanisms and converting them
to be used by Artificial Intelligence technologies in cyber security to detect security threats. It is
to impart human knowledge to the cognitive system, which will be able to serve as a self-
learning system. This helps identify the threats, determine their impact, and manifest reactive
strategies.
1. Install firewalls
2. Rotate passwords frequently
3. Do not click on or download from unknown sources
4. Get free anti-phishing tools
5. Do not provide your personal information on an unsecured/unknown site
SQL injection is an injection attack where an attacker executes malicious SQL commands on
the database server, including MySQL, SQL Server, or Oracle, that runs behind a web
application. The intent is to gain unauthorized access to sensitive data such as client information,
personal information, intellectual property details, and so on. In this attack, the attacker can add,
modify, and delete records in the database, which results in the loss of data integrity in an
organization.
Want to know How to become a cyber security engineer in 2023? check this blog out!
1. Install firewalls
2. Rotate passwords frequently
3. Do not click on or download from unknown sources
4. Get free anti-phishing tools
5. Do not provide your personal information on an unsecured/unknown site
SQL injection is an injection attack where an attacker executes malicious SQL commands in the
database server, including MySQL, SQL Server, or Oracle, that runs behind a web application.
The intent is to gain unauthorized access to sensitive data such as client information, personal
information, intellectual property details, and so on. In this attack, the attacker can add, modify,
and delete records in the database, which results in the loss of data integrity in an organization.
Have a look at this Cyber Security Tutorial, which will make it easier for you to dive into this
field!
Dear YYY,
We are deleting all inactive emails to create space for other new users. If you want to save your
account data, please provide the following details: First Name and Last Name:
Email ID:
Password:
Date of Birth:
Alternate Email: Please submit the above detail by the end of the week to avoid any account
termination.
The above email is an excellent illustration of phishing. Here are the reasons why:
1. A reputed organization will never ask for an employee’s personal information in the mail.
2. In a normal mail, the salutation is not done in a generalized manner. This happens only in
spam emails where the attacker tricks you into ‘biting.’
As a rule of thumb, you should never revert to a sender who demands personal information and
passwords via emails, phone calls, text messages, and instant messages (IMs). You must not
disclose your data to any external party even if the sender works for organizations such as ITS or
UCSC.
58. You get an e-card in your mail from a friend. It asks you to download an
attachment to view the card. What will you do? Justify your answer.
1. Do not download the attachment as it may have viruses, malware, or bugs, which might
corrupt your system.
2. Do not visit any links as they might redirect you to an unintended page.
3. As fake email addresses are common and easy to create, you should not perform any
action like clicking/downloading any links, unless you confirm it with the actual person.
4. Many websites masquerade as legitimate sites to steal sensitive information, so you
should be careful not to fall into the wrong hands.
It is highly likely that the above-mentioned three newsletters are from a parent company, which
are distributed through different channels. It can be used to gather essential pieces of information
that might look safe in the user’s eyes. However, this can be misused to sell personal information
to carry out identity theft. It might further ask the user for the date of birth for the activation of
the fourth newsletter.
In many scenarios, questions that involve personal details are unnecessary, and you should not
provide them to any random person, company, or website unless it is for a legitimate purpose.
60. Case study:In our computing labs and departments, the print billing system
is typically linked to the user's login. Users log in, initiate print jobs, and
subsequently receive a bill for the printed material, either individually or
through their respective departments. Occasionally, individuals contact us to
express their dissatisfaction with invoices for printing they claim they did not
perform, only to discover that the bills are, in fact, accurate. Question: What do
you believe could be the underlying issue in this situation?
To avoid this situation, you should always sign out of all accounts, close the browser, and quit
the programs when you use a shared or public computer. There are chances that an illegitimate
user can retrieve your authorized data and perform actions on behalf of you without your
knowledge when you keep the accounts in a logged-in state.
DMZ stands for demilitarized zone. It is a network architecture that acts as a buffer zone
between an organization’s internal network and an external or untrusted network, typically the
internet. The purpose of a DMZ is to provide an additional layer of security by segregating and
isolating certain systems or services that need to be accessible from the internet.
The DMZ is designed to host publicly accessible services such as web servers, email servers, or
FTP servers that need to be accessed by users outside the organization. Placing these services in
the DMZ separates them from the internal network, reducing the potential attack surface and
minimizing the risk to sensitive resources and data. A DMZ is implemented using firewalls and
network segmentation techniques.
Typically, two firewalls are employed: one facing the internet and another separating the DMZ
from the internal network. The external-facing firewall allows limited and controlled inbound
traffic to reach the DMZ, while the internal-facing firewall enforces strict rules to prevent
unauthorized access from the DMZ to the internal network.
62. Differentiate between DDoS and DoS attack.
63. Case study: In your college computer lab, one of your friends logged into her
email account. When she left the lab, she only logged out from her email account.
Later, she received a notification that someone had re-accessed her account from
the college computer system’s browser, which she has used to send emails.
Question- How do you think this happened?
1. The attacker can visit the browser’s history to access her account if she hasn’t logged out.
2. Even if she has logged out but has not cleared the web cache (pages a browser saves to
gain easy and quick access for the future)
64. Case study: An employee’s bank account faces an error during a direct
deposit procedure. Two different offices need to work on it to straighten this out.
Office #1 contacts Office #2 by email to send the valid account information for
the deposit. The employee now gives the bank confirmation that the error no
longer exists. Question- What is wrong here?
Any sensitive information cannot be shared via email as it can lead to identity theft. This is
because emails are mostly not private and secure. Sharing or sending personal information along
the network is not recommended as the route can be easily tracked.
In such scenarios, the involved parties should call each other and work with ITS as a secure way
of sending the information.
Check out this interesting blog on the difference between Cyber Security and Information
Security!
65. You see an unusual activity of the mouse pointer, which starts to move
around on its own and clicks on various things on the desktop. What should you
do in this situation?
The answer is (D) and (E). This kind of activity is surely suspicious as an unknown authority
seems to have the access to control the computer remotely. In such cases, you should
immediately report it to the respective supervisor. You can keep the computer disconnected from
the network till help arrives.
66. Check out the list of passwords below, which are pulled out from a database
and choose the passwords that are in line with the UCSC’s password
requirements:
A. Password1
B. @#$)*&^%
C. UcSc4Evr!
D. akHGksmLN
Choose the passwords that are in line with the UCSC’s password requirements.
The answer is C (UcSc4Evr!). As per the UCSC requirements, a password should be:
67. The bank sends you an email, which says it has encountered a problem with
your account. The email is provided with instructions and also a link to log in to
the account so that you can fix it. What do you infer from the above situation?
Explain.
It appears to be an unsolicited email. You should report it as spam and move the email to the
trash immediately in the respective web client you use (Yahoo Mail, Gmail, etc.). Before
providing any bank-related credentials online, you should call the bank to check if the message is
legitimate and is from the bank.
68. In your IT company, employees are registering numerous complaints that the
campus computers are delivering Viagra spam. To verify it, you check the
reports, and it turns out to be correct. The computer program is automatically
sending tons of spam emails without the owner’s knowledge. This happened
because a hacker had installed a malicious program into the system. What are
the reasons you think might have caused this incident?
This type of attack happens when the password is hacked. To avoid this, whenever you set a
password, always use a proper standard, i.e., use passwords that are at least 8-character length
and have a combination of upper case/lower case letters, symbols/special characters, and
numbers.
Here are some immediate steps to contain the damage and mitigate the attack:
1. Isolate infected systems: Immediately disconnect affected devices from the network to
prevent further spread.
2. Identify the payload and entry point: Investigate the ransomware strain and analyze logs
to pinpoint the attack vector.
3. Assess data impacted: Determine what data was encrypted and if backups are available
for restoring critical information.
4. Notify stakeholders: Inform key personnel and authorities according to your incident
response plan.
5. Prepare for recovery: If restoring from backups is feasible, ensure their validity and
initiate the restoration process.
70. You suspect a coworker might be accessing unauthorized data. What are
your initial steps to investigate and address the situation?
The initial steps to investigate and address the situation are as follows:
1. Document your observations: Note specific behaviors, data accessed, and timestamps
without directly accusing the individual.
2. Report your concerns to your supervisor or designated security personnel: Follow
established internal reporting procedures.
3. Cooperate with the investigation: Offer any relevant information and assist with
collecting evidence ethically and discreetly.
4. Maintain confidentiality: Avoid discussing the situation with others before official
inquiries conclude.
71. You receive a suspicious email claiming to be from a vendor you regularly
work with. How would you determine its legitimacy and avoid falling victim to a
phishing attack?
Here are some ideas to determine its legitimacy and avoid falling victim to a phishing attack:
1. Verify sender details: Check the email address and domain name for inconsistencies with
the vendor’s usual communication.
2. Hover over links without clicking: Preview links to see if they redirect to the expected
vendor website.
3. Contact the vendor directly: Use trusted phone numbers or websites to confirm the
email’s authenticity.
4. Report the attempt: Report the suspicious email to your IT security team for further
investigation.
72. You detect unusual activity on your company's cloud storage platform. How
do you identify and respond to the potential security incident?
The following steps will help identify and respond to the potential security incident:
1. Analyze logs and audit trails: Identify the nature of the activity, affected files, and
potential access points.
2. Utilize cloud security tools: Leverage platform-specific features for threat detection,
isolation, and investigation.
3. Engage cloud security support: Collaborate with the cloud provider’s security team for
advanced analysis and remediation.
4. Notify internal stakeholders: Inform relevant teams about the incident and keep them
updated on the response progress
1. Identify the attack type and source: Utilize security tools to analyze traffic patterns and
identify the attackers.
2. Activate mitigation strategies: Implement pre-configured DoS protection measures or
seek assistance from your security provider.
3. Communicate with users: Inform customers and stakeholders about the attack and any
potential service disruptions.
4. Analyze and improve incident response: Evaluate the attack methods and update your
defense strategies for future prevention.
A. Viruses need a host program to run, while worms can replicate on their own.
B. Worms are always more destructive than viruses.
C. Viruses are always written in assembly language, while worms are written in higher-level
languages.
D. There is no difference between a virus and a worm.
Viruses need a host program to run, while worms can replicate on their own.
A type of attack that tries to crash a website or system. A DoS attack floods a website or system
with traffic, making it unavailable to legitimate users.
An IDS monitors network traffic and system activity for signs of malicious behavior, alerting
security personnel to potential threats.
77. What is the most effective way to protect yourself from social engineering
attacks like phishing?
All of the above. Maintaining vigilance, being cautious with links and attachments, and
protecting personal information are crucial for avoiding social engineering traps.
78. Which cryptographic algorithm provides the highest level of security for data
at rest, making it suitable for highly sensitive information?
A. AES-256
B. RSA-2048
C. SHA-256
D. MD5
Continuous authentication and authorization for all users and devices. (Image of Zero Trust
security model diagram)
India:
US:
Entry-Level: $70,000
Experienced Professionals: $178,000
Average Salary: $88,325 – $164,861 per year
1. With more than 200,000 active jobs in the field of cyber security, the tally is expected to
increase by 30% in the coming years.
2. With the increase in cyber security remote jobs, it gets more flexible for both companies
and working professionals.
3. As the field expands, specializing in areas like threat analysis, forensics, or ethical
hacking is becoming increasingly valuable.
With the increasing threat of cyber attacks, cyber security jobs are always in demand. Below are
some of the core roles for Cyber Security Professionals.
Security Engineer
Information Security Analyst
Chief information security officer
Security Architect
Security Consultant
Penetration test
Security Administrator
Security Manager
Ethical hacker
Monitor network activity, investigate security incidents, and implement security controls.
Design, implement, and manage security infrastructures and solutions.
Perform simulated cyber attacks to identify vulnerabilities in systems and networks.
Develops and oversees the overall security architecture of an organization.
Leads and manages the organization’s overall cybersecurity strategy and posture
Cyber Security
MCQs on " Cyber Security": Find the multiple choice questions on " Cyber Security", frequently
asked for all competitive examinations.
Table of Content
1.
1. Against Malware
2. Against cyber-terrorists
3. Defends a device from threat.
4. All mentioned options
Answer: D
1.
1. Robert
2. August Kerckhoffs
3. Bob Thomas
4. Charles
Answer: B
1.
1. Cloud Security
2. Application Security
3. Cloud Security
4. All options mentioned above
Answer: D
1.
1. refusal of service
2. Man in the middle
3. Phishing
4. AES
Answer: D (AES stands for Advanced Encryption Standard) safeguards data by encoding it)
1.
1. System getting slower
2. Computer lagging and crashes
3. provide privacy to users
4. Secures system against viruses
Answer: A
1.
1. William Gibson
2. Andrew Tannenbaum
3. Scott Fahlman
4. Richard Stallman
Answer: A
7. Which of the below is a hacking technique in which cybercriminals create fictitious web
pages or domains to deceive or obtain more traffic?
1.
1. Pharming
2. Mimicking
3. Spamming
4. Website-Duplication
8. Which of the below is a popular victim of cyber attackers looking to gain the IP address
of a target or victim user?
1.
1. emails
2. websites
3. IP tracer
4. web pages
Answer: B
1.
1. Trojans are implanted into a targeted device.
2. On the deep web, payment information is leaked.
3. mm
4. Phishing
Answer: B
1.
1. Digital crime
2. Threats
3. System hijacking
4. Cyber Attack
Answer: D
1.
1. Software Security Specialist
2. CEO of the organisation
3. Security Auditor
4. IT Security Engineer
12. Which of the below is an internet fraud in which a consumer is digitally persuaded to
reveal personal data by cybercriminals?
1.
1. MiTM attack
2. Phishing attack
3. Website attack
4. DoS attack
Answer: B
1.
1. WPA3
2. WPA2
3. WPA
4. WEP
Answer: D ( WEP stands for wired Equivalent Privacy. It is a most insecure encrypted protocol)
14. Which of the below measures can help reduce the risk of data leakage?
1.
1. Steganography
2. Chorography
3. Cryptography
4. Authentication
15. This is the concept for guiding information security policy within a corporation, firm,
or organisation. What exactly is “this” in this context?
1.
1. Confidentiality
2. Non-repudiation
3. CIA Triad
4. Authenticity
Answer: C (CIA Triad is the most popular and frequently used approach, focusing on the
confidentiality of information)
16. ___________ means the security of data from tampering by unidentified users.
1.
1. Confidentiality
2. Integrity
3. Authentication
4. Non-repudiation
Answer: B
17. Which of the below implemented is not a good means of safeguarding privacy?
1.
1. Biometric verification
2. ID and password-based verification
3. 2-factor authentication
4. switching off the phone
Answer: D
18. When ____ and ____ are in charge of data, the integrity of the data is imperilled?
1.
1. Access control, file deletion
2. Network, file permission
3. Access control, file permission
4. Network, system
Answer: C
19. The authenticity and security of data travelling over a network are ensured by?
1.
1. Firewall
2. Antivirus
3. Pentesting Tools
4. Network-security protocols
Answer: D ( Network-security protocols govern the procedures and processes used to protect
network data against illegal content collection)
20. _________ creates an isolated passage across a public network that enables computing
devices to communicate and receive data discreetly as though they were directly linked to
the private network.
1.
1. Visual Private Network
2. Virtual Protocol Network
3. Virtual Protocol Networking
4. Virtual Private Network
Answer: D
21. ___________ is one of the safest Linux operating systems, offering invisibility and an
incognito mode to protect user data.
1.
1. Fedora
2. Tails
3. Ubuntu
4. OpenSUSE
Answer: B
1.
1. Web services
2. phishing
3. Directory service
4. worms
Answer: C (A directory service is the following system of software and protocols that keep track
of knowledge about the company, clients, or sometimes both)
1.
1. They’re expensive
2. They’re complex in architecture
3. They do not filter individual packets
4. They’re complex to setup
Answer: C
1.
1. DNS poisoning
2. Footprinting
3. ARP-poisoning
4. Enumeration
Answer: B ( In this Phase, The attacker attempts to find as many attack vectors as he can,
reconnaissance is another term for footprinting)
1.
1. Dos Attack
2. Phishing
3. Soliciting
4. Both A and C
Answer: A ( A denial of service attack is referred to as a dos attack, it’s a type of cyber-attack in
which someone tries to prevent a machine from serving its intended consumers)
26. In system hacking, which of the below is the most crucial activity?
1.
1. Information gathering
2. Covering tracks
3. Cracking passwords
4. None of the above
Answer: C
27. When the number of users surpasses the network’s capacity, which of the below
network factors suffers the most?
1.
1. Reliability
2. Performance
3. Security
4. Longevity
Answer: D
28. Which of the below cyber security principles states that the security system should be as
compact and straightforward as possible?
1.
1. Open-design
2. The economy of the Mechanism
3. Least privilege
4. Fail-safe Defaults
Answer: B
29. Which of the below malware types permits the hackers to access administrative controls
and do nearly everything he wants with the infected systems?
1.
1. RATs
2. Worms
3. Rootkits
4. Botnets
Answer: A ( RATs stands for Remote Access Trojans which gives the attacker administrative
power over your device, just as if they had physical access)
30. The first hacker’s conference was held in which of the below locations?
1.
1. OSCON
2. DEVON
3. DEFCON
4. SECTION
Answer: C ( DEFCON is one of the most well-known and biggest hackers and security
consultant conferences in the world. It’s often conducted in Las Vegas, Nevada, once a year)
31. When any IT device, service, or system requires security checks, the term “security
testing” is employed.?
1.
1. Threat
2. Vulnerability
3. Objective of evaluation
4. Attack
Answer: C ( When any IT system, device, or platform requires assessment for safety purposes or
to address any faults after being evaluated by security researchers, the term “objective of
evaluation” is used)
32. Which of the below is used to analyse network flow and monitor traffic?
1.
1. Managed detection and response
2. Cloud access security broker
3. Network traffic analysis
4. Network traffic analysis
Answer: C
33. Which of the below is a method of gaining access to a computer program or an entire
computer system while circumventing all security measures?
1.
1. Backdoor
2. Masquerading
3. Phishing
4. Trojan Horse
34. The term “protection from ______of source code” refers to limiting access to the source
code to just authorised individuals.
1.
1. disclosure
2. alteration
3. destruction
4. log of changes
Answer: C
35. _______________ are programmes or procedures that enable hackers to maintain
control of a computer system.?
1.
1. Exploits
2. Antivirus
3. Firewall by-passers
4. Worms
Answer: A ( Exploits are programs or algorithms that allow hackers to gain total control of a
computer system)
Related Pages: