wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

IS Security

Total questions: 44

Worksheet time: 15mins

Name
Class
Date
1.
One of your customer went on a foreign tour, and locked the user access. Now she has come back, and tried to login into INB site but in vain. She approaches you for solutions. As a Banker, what is your response?
a)
Ask her to unlock herself online
b)
Approach the Branch to unlock the user by submitting a duly signed letter
c)
Unlock the user by using SBI Quick application
d)
None of the above.
2.
Information Security is all about C I A. CIA stands for
a)
Confidentiality, Information and Availability
b)
Confidentiality, Integrity and Availability
c)
Communication, Integrity and Availability
d)
Communication, Information and Availability
3.
Ensuring confidentiality in Information Security means
a)
Information is available to the requested persons
b)
Information is available to all employees of the Organisation
c)
Information is available only to the authorised employees on need to know basis
d)
Information is available only to the closed group of Top Management
4.
Ensuring Integrity in Information Security means
a)
Information is available only to the authorised employees on need to know basis
b)
Employees with integrity are only allowed to access the information
c)
Safeguarding the completeness of information always
d)
Safeguarding the accuracy, completeness and processing methods always
5.
Ensuring Availability in Information Security means
a)
Keeping the data in database in a secure manner
b)
Keeping Information Assets as per commitment when required
c)
Data is to be made available for data analysis and analytics
d)
Making Information Assets available to all people at all times
6.
Maintaining the Confidentiality, Integrity and Availability is the responsibility of
a)
Global Information Technology Centre
b)
System Officers at branches / offices and Departments
c)
Head of Departments and Branch Managers
d)
It is a collective responsibility of all employees in the Bank
7.

One of the following is not the activities of the State Bank Security Operations Centre (SBSOC).

a)

Monitor users' activities in Internet (through EMM)

b)

Monitor various applications / programs installed in PCs/Servers

c)

Monitor, Check and identify virus infections if any, in the network

d)

None of the above

8.
While you are working in CBS, your Branch Manager calls you to come urgently to his cabin to discuss some issue, relating to a valued customer of your Branch. What is your course of action?
a)
Rush to the BM's cabin as per his directive
b)
Log out from CBS and go to the BM's cabin
c)
Lock the CBS screen and go to the BM's cabin
d)
Lock the Desktop by pressing Windows+L keys together and proceed to the BM's cabin
9.

As the band width is the main concern of the Bank, we are developing many mobile applications for the use of customers. However, usage of mobile have many vulnerabilities. Which one of the following is not a drawback in securing the Mobile Devises?

a)

ADS environment is not available

b)

Screen lock can be enabled with 'pattern', 'PIN' or 'Password'

c)

Proxy server or firewall facility is not available

d)

Anti-virus set up is not available

10.
Password maintenance is the most important Information Security threat for the Bank. What is the main reason for this?
a)
It is the passport to enter into the Bank's network and various applications
b)
This aspect of information security is to be maintained by people
c)
Compromise with the password may lead to financial loss and data loss
d)
All of the above
11.

Your colleague has created his Facebook account and provided the Bank's email id for registration purposes. What is your advice to your colleague?

a)

Bank may intercept our emails to ensure that they are used as per Bank's IS Policy

b)

.Even the Bank's personal email account will be equal to Bank's Letter Head

c)

Bank's official mail account for personal purposes is discouraged.

d)

All of these

12.
In an emergency, your colleague has accessed email at a cyber café. What is the most important precaution you will advise to your colleague as a Banker?
a)
Don't open any new email while in the café
b)
Change the password of the email immediately after coming out from café
c)
Don't open any attachment of any new mail
d)
None of the above
13.
Your colleague had recently created a Facebook account. In the profile section, he has disclosed that he is Manager of SBI. What is the Bank's IS Policy guideline applicable to this activity?
a)
Not to directly or indirectly disclose / criticise Bank
b)
Post opinions in the official capacity of the Bank
c)
Canvass for any donation
d)
Promote any business
14.
One of your colleague visited a local internet café to transfer funds online to his friend urgently. What is the most effective precaution you can give to your friend as a Banker?
a)
Don't use Profile Password for any reason
b)
Use the virtual key board for logging into Internet Banking site.
c)
Confirm that the website address starts with https://
d)
The address bar turns into Green
15.
One of the following is not an effective way to prevent card skimming.
a)
Installing anti-skimming devices
b)
Using of EMV chip based cards
c)
Usage of Foreign Object Detection Technology
d)
Swiping a card at POS machine of an unknown merchant
16.
One of your customer informed you that, in the morning he had tried to login into Bank's internet banking site. But because of using a wrong password successively for three times, the system has displayed a message that the user is blocked. He wants to unlock the user. As a Banker, what is your response?
a)
Unblock the user, through INB interface
b)
Suggest to the customer to wait upto 12 O'clock in the night, so that it will be automatically unblocked.
c)
Either first or second
d)
Neither first nor second
17.

What is the best practice in using 'Bluetooth' in your mobile?

a)

Disable Bluetooth facility

b)

Keep the Bluetooth in 'invisible mode'.

c)

Only when you want to receive data from other devices, switch on Bluetooth

d)

None of the above.

18.
One of the following is not a part of Acceptable Usage Policy for Desktops deployed in the Bank.
a)
Must be brought under Active Directory
b)
Anti-virus be installed in the system immediately
c)
While leaving the system even for a minute, Desktop is to be locked by clicking Windows+L keys together
d)
System Administrator is to ensure that Anti-virus is updated regularly
19.

One of the following is not a part of Acceptable Usage Policy for Desktops deployed in the Bank.

a)

Remember my credentials / Remember Password shall not be invoked for accessing any website or application

b)

Stay logged in' facility can be used wherever required

c)

While exchanging any information through any website, ensure that it is a secure site with URL address starting with https://

d)

None of the above

20.
One of the following is not a part of Acceptable Usage Policy for Portable devises used for Bank's work.
a)
Take adequate measures for physical protection of devices
b)
Shall not leave them unattended while travelling or at public places
c)
Screen locking system is not to be enabled
d)
Loss of such systems shall be reported to local police or the appropriate authority in the Bank.
21.

One of the following is not a part of Acceptable Usage Policy for Password Security of various apps and softwares.

a)

Password shall be treated as a signature

b)

It must be a combination of alphabets (with Capital letter and small letters), numeric and special characters

c)

It shall be easy to remember and difficult to guess

d)

Where there no specific period for changing the password is prescribed for any app or software, it shall be changed once in 30 days

22.
One of the following is not a part of Acceptable Usage Policy for Email Usage.
a)
Shall not use official email account for personal purposes
b)
Shall not share official email, for registering with social media sites
c)
In exceptional cases, official email id can be registered with merchant websites.
d)
User is fully responsible for any content originated through his/her official email account.
23.
Bank may intercept the email communications generated from
a)
Officially designated email ids
b)
Personal emails ids allotted to users
c)
Both the First and Second Options are correct
d)
Neither the first nor the second option is correct.
24.
Attachments in the form of photos, videos shall not be opened while you are accessing your mail in intranet.
a)
No. Office 365 scans each email before it is received
b)
Yes. Photos or videos may contain hidden messages which cannot be seen in normal course.
25.
Official email accounts shall not be accessed through one of the following:-
a)
Unprotected Wi-Fi connections
b)
Public Hotspots
c)
Insecure cybercafé
d)
All of the above
26.
One of your colleague has provided his official email id, in the application for opening a demat account with SBCapSecurities. What is your advice to him?
a)
No advice is required.
b)
No advice is required as the email id is provided to our Bank's Subsidiary only
c)
Not to provide official email id for personal purposes.
d)
None of the above
27.
You are posted as a Branch Manager and you find a message of criticism from a customer against your branch on 'Facebook' about non-receipt of a Cheque Book. A lot of comments are there on Facebook supporting the customer's criticism. On enquiry you find that the criticism is baseless. Would you:
a)
Retaliate on Facebook itself immediately that the fact posted, is not true
b)
Ignore the comments on Facebook and offer no comments
c)
Bring it to your controller's notice
d)
Contact the customer personally & resolve the issue if any. If the customer is satisfied with your resolution, request her to post her experience on Facebook
28.
Your colleague is enthusiastic and knowledgeable. He wants to answer questions generated through Quora, (a Social Media site) especially on Bank related questions. What are the precautions he has to take before he registers his name in Quora?
a)
Not to directly or indirectly disclose State Bank's name, logo, url, email address, contact or his own official capacity
b)
Not to refer / disclose Bank's Circulars, business information or official papers
c)
A disclaimer is to be attached at the end of the answer that, the opinions expressed in the answers are of his personal and not official.
d)
All of the above.
29.
What are the security features of our Internet Banking?
a)
It is a secured site (secured by SSL)
b)
URL starts with http://
c)
The address bar turns red when accessed
d)
Third party is activated only upto 10.00 PM each day
30.
What is not a security feature of our Retail Internet Banking?
a)
It is a secured site (secured by SSL)
b)
The address bar turns green when accessed
c)
Third party is activated only upto 8.00 PM each day
d)
Apart from password, OTP is mandatory to login into the site
31.
What is not a security feature of our Retail Internet Banking?
a)
There is a cap on funds than can be transferred during the initial four days of addition of third party
b)
Dynamic Virtual Key Board can be used for entering the user id and password
c)
When you login, 'Previous Site Visit' and Last Login Failed attempt' are displayed on the first screen
d)
A visual icon of your choice appear on the login page to identify that it is the official site
32.
You are compelled to use the Internet Café for making funds transfer through INB urgently to your friend's account. To avoid the problem of key loggers, what type of security feature do you use while login?
a)
Login with OTP
b)
Use Dynamic Virtual Board for entering User ID and Password
c)
Either of the first two options
d)
Neither of the first two options
33.
When you try to login to INB site, you get a message that, your account is LOCKED? What shall be the inference that can be derived?
a)
Bank has blocked your account for Internet Banking to update the software
b)
The Internet Banking site is down for maintenance.
c)
Somebody who knows your user id has attempted to login to your account
d)
None of the above
34.
One of your customer who uses INB called you over phone and requested you to deactivate his INB service, as he will be going on International tour for 3 months. What is your response?
a)
Insist for a written request from the customer for deactivation
b)
Accept the request of the customer and deactivate
c)
Suggest the customer to lock the account facility available on Login page and providing the information required therein.
d)
None of the above
35.
What are the security features available for mobile apps of our Bank?
a)
No personal information is stored in the mobile or SIM card.
b)
The mPIN or user id or password for accessing app is transmitted to the Bank's server through SSL
c)
The apps force close, if kept idle for 5 minutes or it is shut down
d)
All of the above
36.
Which of the following is not a security feature available for mobile apps of our Bank?
a)
Session ends as soon as you close the application
b)
Application can only be accessed after proper authentication of customer username and password / mPIN
c)
Both the first option and second option are correct
d)
Neither the first option nor the second option is correct
37.
Which of the following is not a threat for using a Debit / Credit / Prepaid Card?
a)
Unauthorised usage as a result of it being lost or stolen
b)
Duplicating / cloning legitimate cards
c)
Skimming while doing a legitimate transaction at ATM or PoS machine
d)
None of the above
38.
Which of the following is not a threat for using Mobile Apps of the Bank?
a)
Using fake applications, which are named and appear similar to genuine ones
b)
Data leakage
c)
Smishing
d)
None of the above
39.
Which of the following is one of the method of protecting the data stored in the mobile phone?
a)
Verification of the identity of the user, who is attempting to access the data
b)
Multi-factor authentication
c)
Determining which data files can be made available to a particular user
d)
All of the above
40.
Which of the following is not one of the method of protecting the data stored in the mobile phone?
a)
Protecting the Mobile with access control with password, or PIN or pattern
b)
Multi-factor authentication like finger print
c)
Encrypting the data traffic using Transport Layer Security (TLS)
d)
None of the above
41.
Which one of the following is one of the best practices of State Bank Anywhere Users?
a)
Updating the OS Versions of the mobile regularly
b)
Using secure Wi-Fi network
c)
Installing anti-spyware
d)
All the above
42.
Which of the following is not one of the best practices of Internet Banking Users through laptops and PCs?
a)
Updating the OS Versions regularly
b)
Updating browser application with security enhancements
c)
Not installing anti-spyware in the PC
d)
All the above
43.
Which of the following is not a threat in PoS Systems?
a)
Skimming through PoS machine
b)
PoS Malware
c)
EMV Chip based Card
d)
All the above
44.
What is (are) the best practice(s) for merchants using PoS Machines?
a)
Update PoS software applications
b)
Implementing Account lock Out Policy
c)
Shall not use PoS machines for accessing general Internet websites
d)
All of the above