SET-1:
1(a) Explain about the organizational security policies and measures in mobile
computing era.
Ans: The mobile computing era has transformed the way employees access data and perform
business operations. However, the increased use of smartphones and tablets also increases
security risks such as data leakage, malware attacks, and unauthorized access. Therefore,
organizations must establish strong security policies and measures.
Mobile Device Management (MDM)
One of the most important strategies is the implementation of Mobile Device Management
tools. MDM allows the organization to monitor, control, and secure mobile devices used for
business. It can enforce password rules, restrict unsafe applications, and even remotely wipe
the device if it is lost.
BYOD (Bring Your Own Device) Policies
As many employees prefer using personal devices for work, organizations formulate BYOD
policies. These policies define what information employees can access, the security settings
required on personal devices, and the responsibilities of the user to maintain data
confidentiality.
Data Protection and Encryption
To protect organizational data, encryption is enforced both during transmission and storage.
This ensures that even if a device is stolen or hacked, the attacker cannot read sensitive
information without the encryption keys.
Secure Network Access
Organizations ensure secure connectivity by allowing mobile devices to connect only through
secure Wi-Fi networks or VPNs. Network Access Control (NAC) is used to verify that
devices meet the organization’s security standards before accessing internal systems.
Application Usage Control
Another key measure is controlling the applications that employees are allowed to use.
Unauthorized apps are blocked, and only trusted corporate apps are permitted to prevent
malware and data leakage.
1(b) Illustrate about the attacks on Mobile-Cell Phones.
Ans: Mobile phones have become essential for communication, banking, and business
operations. Because of their extensive use, they are an attractive target for attackers. Various
types of attacks aim to steal information, control devices, or track users.
Malware-Based Attacks
Mobile devices are often infected through malicious applications disguised as legitimate apps.
These include spyware, ransomware, and Trojans. Once installed, they can steal personal data,
record activities, or lock the device until payment is made.
Phishing and Smishing
Attackers frequently use fake emails and SMS messages to trick users into providing
confidential information. These messages often look like bank alerts or service messages and
redirect the user to harmful websites.
Wireless Exploits
Mobile phones are also attacked through Bluetooth and Wi-Fi. Attackers may use rogue Wi-
Fi hotspots or Bluetooth vulnerabilities to intercept data, install malware, or gain control of
the device.
SIM-Based Attacks
SIM cloning or SIM swapping is another serious threat. In a SIM swap attack, the attacker
convinces the telecom provider to issue a duplicate SIM, allowing them to receive the
victim’s calls and OTPs, eventually enabling financial fraud.
OS Vulnerabilities and Zero-Day Exploits
Both Android and iOS occasionally contain security weaknesses. Cybercriminals exploit
these vulnerabilities to gain root access or install advanced spyware without the user’s
knowledge
2(a) Distinguish about various types of web threats for Organizations.
Ans: As organizations depend heavily on web-based applications and internet services, they
are exposed to various online threats. These threats can disrupt operations, steal data, or
damage the organization's reputation.
Phishing and Fake Websites
One of the most common threats is phishing, where attackers create fake websites that closely
resemble legitimate login pages. Employees who unknowingly enter their credentials cause
serious data breaches.
SQL Injection Attacks
Web applications that fail to validate user input are vulnerable to SQL injection. In this attack,
malicious SQL commands are inserted into input fields, enabling attackers to access or alter
sensitive database information.
Cross-Site Scripting (XSS)
In XSS attacks, hackers inject malicious scripts into web pages viewed by users. This script
may steal cookies, manipulate web pages, or redirect users to harmful sites. It compromises
both users and organizational servers.
Drive-By Downloads
Some websites automatically download malware as soon as they are visited. Employees with
outdated browsers or plugins are especially vulnerable to these types of attacks.
DDoS (Distributed Denial of Service)
Attackers may flood an organization’s servers with massive traffic, making the website
unavailable. This affects business continuity and often results in financial losses.
2(b) Discuss about social computing and the associated challenges for
organizations.
Ans: Meaning of Social Computing
Social computing refers to the use of online social platforms, collaboration tools, blogs,
online communities, and social media networks where people share information,
communicate, and collaborate. Although useful, it introduces serious challenges for
organizations.
Information Leakage
Employees may unintentionally post sensitive information related to projects or customers on
social platforms. This leakage can be exploited by competitors and attackers.
Reputation and Brand Damage
Negative comments, false rumors, or customer dissatisfaction expressed on social media can
damage an organization’s reputation. Once information goes viral, it becomes difficult to
control or remove.
Social Engineering Risks
Cybercriminals use social media to gather personal information about employees. This
information is then used for phishing, impersonation, or tricking employees into revealing
confidential data.
Legal and Compliance Issues
Organizations must adhere to different data privacy regulations. Misuse of social platforms or
inappropriate posting by employees can result in legal consequences and penalties.
Employee Productivity Concerns
Excessive use of social media during working hours reduces productivity. Organizations need
to regulate access without affecting genuine work requirements.
3)Discuss about various Data Privacy attacks.
Ans: Data privacy attacks aim to access, infer, or steal personal and confidential information.
As organizations increasingly store valuable data, privacy attacks have become more
sophisticated.
Inference Attacks
In inference attacks, attackers determine sensitive information by analyzing available non-
sensitive data. For example, analyzing purchase patterns may reveal personal habits or
medical conditions.
Re-Identification or Linkage Attacks
Even when data is anonymized, attackers can combine it with other public datasets to identify
individuals. This technique was famously used to identify users in anonymized movie-rating
databases.
Side-Channel Attacks
Instead of directly accessing data, attackers study indirect information such as system timing,
power usage, or network traffic. These subtle clues help them extract sensitive information
such as encryption keys.
Unauthorized Access and Insider Threats
Sometimes employees with legitimate access misuse or leak sensitive information. This
category also includes hackers who break into databases to steal data.
Interception Attacks
Data sent over unsecure networks can be intercepted by attackers using packet sniffing or
MITM attacks. This allows them to steal private communications, passwords, and financial
data.
Profiling Attacks
By tracking user behavior, browsing habits, and online activity, attackers create detailed
profiles. These profiles may invade privacy and enable manipulation, targeted scams, or
surveillance.
SET-2
1(a) Discuss about the Organizational Measures for Handling Mobile.
Ans: Mobile devices are widely used in organizations for communication, collaboration, and
access to business resources. However, they also introduce risks such as data leakage,
unauthorized access, theft, and malware. To manage these risks, organizations implement
several technical and administrative measures.
Mobile Device Management (MDM)
Organizations use MDM software to monitor, secure, and manage mobile devices used by
employees. Through MDM, administrators can enforce password policies, restrict high-risk
applications, configure security settings, and remotely lock or wipe devices in case of loss.
Device Usage Policies
Clear mobile usage guidelines are established for employees. These policies specify
acceptable use, approved applications, restrictions on personal apps, and rules for accessing
sensitive data. They ensure that employees understand their responsibilities in safeguarding
organizational information.
Secure Network Access
Mobile devices are allowed to access corporate networks only through secure channels.
Organizations enforce VPN connections, WPA3-secured Wi-Fi, and network access control
systems to prevent unauthorized devices from entering the internal network.
Data Encryption and Protection
To protect sensitive organizational data, encryption is used both for data stored on the device
and data transmitted over networks. Encrypted containers and secure file-sharing tools are
implemented to prevent unauthorized data access.
Regular Updates and Patch Management
Keeping the operating system and mobile applications updated helps reduce vulnerabilities.
Organizations ensure timely installation of security patches to protect devices from malware
and exploitation.
1(b) Describe about the Physical Security Countermeasures for protecting Laptops.
Ans: Laptops are portable and convenient, but their mobility makes them vulnerable to theft,
loss, and physical tampering. Physical security is essential to prevent unauthorized access and
protect sensitive data.
Laptop Locks and Securing Devices
One of the simplest countermeasures is using cable locks or security anchors to physically
attach the laptop to a desk. This discourages casual theft in offices, classrooms, and public
places.
Proper Storage Practices
When not in use, laptops should be stored in locked drawers, cabinets, or secure rooms.
Employees are advised not to leave them unattended in cars, public areas, or hotel rooms
without proper security.
Access Control and Identification
Organizations may use physical access controls such as ID cards, biometric entry systems,
and surveillance cameras to restrict entry to areas where laptops are stored or used. This
reduces the chances of unauthorized physical access.
Use of Privacy Screens
Privacy filters prevent shoulder surfing and unauthorized viewing of confidential information.
These screens are especially important in public spaces, airports, and open office
environments.
Security Marking and Tracking
Laptops can be marked with barcodes, RFID tags, or asset IDs for easy tracking. Some
organizations use GPS-based tracking tools to locate lost or stolen devices.
Environmental Protection
Physical security also includes protecting laptops from damage due to heat, liquids, dust, or
electrical hazards. Proper handling and environmental controls ensure longer device lifespan
and data safety.
2(a) Explain about the ethical dimension of cybercrimes.
Ans: Cybercrimes not only violate laws but also raise serious ethical issues. Ethics deals with
moral principles that guide human behavior, and cyber activities should follow these
principles to maintain trust and integrity in the digital world.
Violation of Privacy
Cybercrimes such as hacking, unauthorized surveillance, and data theft violate the ethical
principle of respecting others' privacy. Individuals and organizations have a moral right to
control their personal information.
Misuse of Technology
Technology is intended to improve society. Using it for harmful purposes—such as spreading
malware, committing fraud, or launching attacks—shows unethical misuse of digital tools
and knowledge.
Trust and Responsibility
Cyber attackers break the trust that users place in online systems. Ethical behavior requires
individuals to use their skills responsibly, ensuring that digital platforms remain safe and
reliable for all.
Impact on Society and Economy
Cybercrimes can cause financial loss, emotional distress, and disruption of essential services.
Ethically, harming society or individuals through digital means is unacceptable and morally
wrong.
Professional Ethics in Computing
Individuals working in IT and cybersecurity must follow professional codes of ethics. They
are expected to protect user data, follow legal guidelines, and avoid exploiting system
vulnerabilities for personal gain.
2(b) Describe the Psychology, mindset and skills of Hackers.
Ans: Hackers are individuals who use their technical knowledge to explore, manipulate, or
exploit computer systems. Understanding their psychology, mindset, and skills is essential in
cybersecurity to predict and counter their actions.
Curiosity and Problem-Solving Mindset
Most hackers possess a high level of curiosity and a desire to understand how systems work.
They enjoy solving complex problems and overcoming digital barriers.
Motivations and Psychological Factors
Some hackers are motivated by financial gain, others by ideological beliefs, revenge, thrill-
seeking, or the desire for recognition. Their mindset varies from harmless exploration (white-
hat) to destructive intent (black-hat).
Technical Skills and Expertise
Hackers develop deep knowledge in programming, networking, operating systems, and
cryptography. They are skilled at exploiting software vulnerabilities, writing malware, and
bypassing security mechanisms.
Persistence and Patience
Successful hacking requires time, research, and persistence. Hackers spend long hours
analyzing systems, testing exploits, and observing system behavior.
Adaptability and Rapid Learning
Cybersecurity evolves constantly, so hackers continuously learn new techniques. They
actively follow technological trends, attend underground forums, and experiment with new
tools.
3(a) Explain about Privacy policies in different languages.
Ans: Privacy policies are documents that explain how an organization collects, uses, stores,
and protects personal data. To ensure transparency and global compliance, privacy policies
are written in different languages so they can be understood by diverse users.
English-Language Privacy Policies
Most international companies use English as the primary language for their privacy policies.
These documents typically cover data collection methods, third-party sharing, user rights,
cookie usage, and data protection practices.
Regional Language Versions
To comply with local laws and increase accessibility, organizations translate privacy policies
into regional languages. For example, companies operating in India may provide privacy
policies in Hindi, Tamil, Telugu, Kannada, and other regional languages.
Compliance with International Regulations
Different countries have different data protection laws. For example, GDPR in Europe
requires privacy policies to be clear and understandable in the local language. Therefore,
organizations translate the policy into French, German, Spanish, Italian, etc.
Machine-Readable Privacy Policies
Besides human-readable languages, some privacy frameworks use machine-readable
languages such as P3P (Platform for Privacy Preferences). These allow web browsers to
automatically interpret privacy practices.
Need for Multilingual Policies
Having privacy policies in multiple languages ensures that users from various backgrounds
fully understand how their data is handled. It improves transparency, builds trust, and helps
organizations meet global compliance requirements.