wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

ICD Policy and Cybersecurity

Total questions: 60

Worksheet time: 30mins

Name
Class
Date
1.

Which of the following is not a mandatory member of Information Security Committee (ISC) meeting?

a)

CISO

b)

CFO

c)

CTO

d)

MD&CEO

e)

ED

2.

What are the objectives of Information Security as per ICD Policy?

a)

Confidentiality, Integrity, Availability of all Information assets of Bank

b)

All Information is protected from Unauthorised Physical and Logical access whether by Staff, Contractors, Visitors or Outsiders

c)

The users are aware of and comply with relevant legislation relating to the maintenance, protection, retention and withholding of information

d)

Information is protected from Fraud, corruption or loss during input, processing, transmission and storage

e)

All of the above

3.

Which of the below is not a category of classification of Information based on the ICD policy of the bank?

a)

Classified

b)

Confidential

c)

Internal

d)

Public

e)

Secret

4.

What are the key objectives of multi-factor authentication?

a)

Protect the Confidentiality

b)

Avoid Cyber Attack

c)

Enhance confidence in digital payment

d)

Only a&b

e)

All a,b&c

5.

Bank has implemented which of the following security features for improving the security posture of the ATM?

a)

BIOS password

b)

Disabling USB ports

c)

Disabling auto-run facility

d)

Implement anti-skimming and whitelisting solution

e)

All of the above

6.

Who among the following is not a member in the Cyber Crisis Management Team

a)

CISO

b)

CTO

c)

CGM - HR Operations

d)

CRO

e)

CFO

7.

In the computer networks, the encryption techniques are primarily used for improving the ________

a)

Security

b)

Performance

c)

Reliability

d)

Longevity

e)

All of the above

8.

Which of the below are the Crisis Identification Criteria as per Bank's ICD policy?

a)

Only A

b)

Only B

c)

Only C

d)

Only A & B

e)

All A, B & C

9.

As per ICD Policy which among the following are considered as information assets of Bank?

a)

Servers

b)

Laptop/Desktops

c)

Hardware Devices/Softwares

d)

Customer Data/Transaction Data

e)

All of the above

10.

What is the purpose of a Cyber Crisis Management Plan (CCMP)?

a)

To effectively respond to a crisis

b)

To recover and restore the affected systems within the expected time duration

c)

To minimize the business impact due to a crisis

d)

To establish a response structure with representation from key stakeholders across the Bank

e)

All of the above

11.

Which among the below is not a recommended guideline for evidence handling during a cyber crisis?

a)

Remove the network cable if plugged in

b)

If the computer is on do not turn it off

c)

Format the Entire System Completely

d)

If the computer is off do not turn it on

e)

Do not connect infected systems to any network

12.

Sensitive Personal Information are Data elements which may pose heightened risks to the individual if disclosed or compromised. Which of the below is not considered a sensitive personal information?

a)

PAN Card/Aadhar card

b)

Bank account information

c)

Passport

d)

Mobile Handset Make & Model

e)

Driver’s license number

13.

As per Banks policy, which of the below minimum credentials should be recorded in audit trail and activity logs maintainance?

a)

User ID’s

b)

Dates and times for logon and logoff

c)

Terminal identity or location if possible

d)

Only A & B

e)

All A,B & C

14.

What are the benefits of the Business Continuity Plan?

a)

Identify & Reduce Risk of any cyber incident

b)

It helps to carry business in the normal manner with least interruption

c)

It helps to restore critical processes within acceptable time scale

d)

It helps to reduce the damage caused by disasters and security failures to an acceptable level

e)

All of the above

15.

What is the Objective for assessing and evaluating the Cyber Risk of Vendors as per ICD policy of Bank?

a)

Visualize the risk involved with vendor onboarding

b)

Annual Information/Cyber Security Risk Assessment to maintain the risk level

c)

Classify the vendor’s based on criticality of risk assessment

d)

To assess the business dependency on the vendors

e)

All A, B & C

16.

What is the objective of Cyber Fraud Prevention Chapter under ICD policy of Bank?

a)

Prevent Cyber-attacks

b)

Reduce vulnerabilities in critical infrastructure

c)

Minimize damage and recovery in reasonable time

d)

Reporting to Monitoring authorities

e)

All of the above

17.

Bank will ensure the security, privacy and confidentiality of any sensitive personal data or information that it collects, receives, possess, stores or deals with. Which of the following is a method via which Bank collects personal information?

a)

Open an account or perform online transactions

b)

For the Government purpose, like tax collection

c)

Via cookies when the customer visits the bank’s web site

d)

Apply for a loan or use his/her credit or debit card

e)

All of the above

18.

What pillar of information security ensures that sensitive information is not disclosed without authorization?

a)

Availability

b)

Non-repudiation

c)

Integrity

d)

Confidentiality

e)

None of the above

19.

All types of phishing URLs/Emails to be reported to which email ID of CISO office?

a)

antiphishing@unionbankofindia.bank

b)

antiphishing.ciso@unionbankofindia.bank

c)

phishing-report@unionbankofindia.bank

d)

antiphishing@unionbankofindia.in

e)

ciso.phishing@unionbankofindia.co.in

20.

What is a Ransomware?

a)

Accessing information that was not intended for the specific user

b)

A type of malicious software designed to block access to a computer system until a sum of money is paid

c)

A software used to forward phishing mails

d)

A malicious program for gaining access to information for the sake of fun

e)

Any computer virus is a Ransomware

21.

What is Spoofing?

a)

Sending indiscriminately unsolicited bulk messages

b)

Attack on Update mechanism of softwares/apps to distribute malware

c)

It is a new kind of cyber attack started this year

d)

Attack in which the system files are locked

e)

Attack in which the hacker impersonates as another user by falsifying data to gain advantage

22.

What is a supply chain attack?

a)

Sending indiscriminately unsolicited bulk messages

b)

Attack on Update mechanism of softwares/apps to distribute malware

c)

Attack by exploiting a vulnerability in a software that is unknown to the vendor/developer

d)

A cyber attack which happens on the last day of the month

e)

Attack in which the system files are locked

23.

What is a Zero Day Attack?

a)

A hole in the system in the shape of a circle

b)

An attack that happens on the last day of the month

c)

A vulnerability in software that is unknown to the vendor

d)

The attack that happens on the first day of application launch

e)

Device Security

24.

What are the key objectives of multi-factor authentication?

a)

Protect the Confidentiality

b)

Avoid Cyber Attack

c)

Enhance user confidence

d)

Only a&b

e)

All a,b&c

25.

A scenario where an employee discloses sensitive information to a third party, is a type of:

a)

Man-in-the-middle attack

b)

Phishing Attack

c)

Insider Threat

d)

Ransomware Attack

e)

All of the above

26.

Which of the following month is celebrated as National Cyber Security Awareness Month

a)

August

b)

September

c)

October

d)

November

e)

December

27.

How can you report a Cyber Fraud? How can you report a Cyber Fraud ? A) Call 1930 (Toll free) B) Register your complain in www.cybercrime.gov.in C) Complain at the nearest Cyber Crime Police Station

a)

Only A

b)

Only B

c)

Only C

d)

Only A & B

e)

Any of A, B or C

28.

To report/block suspected fraud communications received through call/SMS/WhatsApp messages, Department of Telecommunications has launched a new portal named CHAKSHU (चक्षु). Which of the below is the URL of the portal?

A. https://saathi.gov.in

B. https://sancharsaathi.gov.in/sfc/

C. https://cyberdost.in

D. https://cybercrime.gov.in

a)

Only A

b)

Only B

c)

Only A & B

d)

Any of A, B or C

e)

Only C

29.
a)

Only A

b)

Only B

c)

Only C

d)

Only A & B

e)

Any of A, B or C

30.

A situation in which an unauthorized person can view another user's display or keyboard to learn their password or other confidential information is referred to as

a)

Tailgating

b)

Spear Phishing

c)

Man-in-the-middle

d)

Spoofing

e)

Shoulder Surfing

31.

Which protocol is commonly used for secure web browsing?

a)

HTTP

b)

HTTPS

c)

FTP

d)

SMTP

e)

Telnet

32.

What does the term 'phishing' refer to?

a)

Sending bulk ads

b)

Tricking users to give credentials

c)

Infecting files with virus

d)

Encrypting data

e)

Securing payment gateways

33.

Which of the following is a strong password?

a)

123456

b)

MyNam@2023

c)

password

d)

Summer2020

e)

qwerty

34.

What does a firewall primarily protect against?

a)

Hardware damage

b)

Unauthorized access

c)

Power outage

d)

Traffic congestion

e)

Strong passwords

35.

Which malware type locks users out of their system until payment is made?

a)

Adware

b)

Ransomware

c)

Trojan

d)

Spyware

e)

Worm

36.

Which organization publishes the OWASP Top 10 vulnerabilities list?

a)

NIST

b)

OWASP

c)

ISO

d)

CERT

e)

IEEE

37.

What does VPN stand for?

a)

Virtual Private Network

b)

Virtual Public Node

c)

Verified Private Network

d)

Virtual Privacy Network

e)

Virtual Protection Node

38.

In cybersecurity, what does CIA triad stand for?

a)

Confidentiality, Integrity, Availability

b)

Confidentiality, Identity, Access

c)

Control, Integrity, Access

d)

Confidentiality, Integrity, Authentication

e)

Critical Infrastructure Assessment

39.

What is the main function of IDS (Intrusion Detection System)?

a)

Block malware execution

b)

Detect malicious activity

c)

Encrypt traffic

d)

Store logs

e)

Stop phishing emails

40.

What type of attack involves overwhelming a system with traffic?

a)

Phishing

b)

DDoS

c)

SQL Injection

d)

XSS

e)

Brute force

41.

Which of the following is an example of multi-factor authentication?

a)

Password only

b)

Password + OTP

c)

PIN only

d)

Security questions only

e)

Username only

42.

The main purpose of encryption is:

a)

Speed up communication

b)

Protect data confidentiality

c)

Prevent phishing

d)

Detect viruses

e)

Boost system speed

43.

Which type of attack exploits human psychology rather than technical flaws?

a)

SQL injection

b)

Social engineering

c)

Buffer overflow

d)

Cross-site scripting

e)

Phishing

44.

What is SQL Injection primarily used to target?

a)

Databases

b)

Operating systems

c)

Memory

d)

Email

e)

Mobile devices

45.

What does zero-day vulnerability mean?

a)

Vulnerability with no patch released

b)

Vulnerability already patched

c)

Attack with known exploit

d)

Vulnerability used by insiders

e)

Security tool for insiders

46.

What is the safest way to connect to public Wi-Fi?

a)

Use open Wi-Fi directly

b)

Use VPN

c)

Share credentials

d)

Use Bluetooth tethering

e)

Use cellular data

47.

Which of the following is a hashing algorithm?

a)

AES

b)

SHA-256

c)

RSA

d)

SHA-1

e)

MD5

48.

What does least privilege principle mean?

a)

Allowing broad user permissions

b)

Giving only necessary access

c)

Granting admin rights to all

d)

Removing all user access

e)

Grant all network access

49.

What is the main purpose of patch management?

a)

To upgrade hardware

b)

To fix security flaws

c)

To block DDoS

d)

To add new features

e)

To hire more employees

50.

Which of the following best describes social engineering?

a)

Managing IT teams

b)

Manipulating people into actions

c)

Developing secure software

d)

Training IT staff only

e)

Protecting servers

51.

Which attack involves intercepting communication between two parties without their knowledge?

a)

Replay attack

b)

MITM (Man-in-the-Middle)

c)

Phishing

d)

Brute force

e)

DoS attack

52.

What is the primary purpose of two-factor authentication?

a)

To simplify login

b)

To provide stronger identity verification

c)

To reduce costs

d)

To increase server uptime

e)

To reduce downtime

53.

Which of the following is NOT a form of malware?

a)

Trojan

b)

Network scanner

c)

Ransomware

d)

Worm

e)

Keylogger

54.

Which security measure helps protect against brute force attacks?

a)

Weak password

b)

Account lockout

c)

Encryption

d)

Firewalls

e)

CAPTCHA

55.

What is a common sign of a phishing email?

a)

Professional grammar

b)

Generic greetings like 'Dear user'

c)

Personalized details

d)

Valid sender addresses

e)

Technical language

56.

Which of the following is an example of biometric authentication?

a)

PIN code

b)

Fingerprint scan

c)

Password

d)

Smart card

e)

Username

57.

Which of the following best describes a Trojan horse?

a)

Self-replicating worm

b)

Malware disguised as legit software

c)

Adware

d)

Network scanner

e)

Spyware

58.

What is the main risk of using outdated software?

a)

Better system speed

b)

Data breaches

c)

New features

d)

Longer battery life

e)

Improved UI

59.

Which cybersecurity principle is enforced by regular backups?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Authentication

e)

Non-repudiation

60.

What does DLP (Data Loss Prevention) software aim to prevent?

a)

Prevent insider trading

b)

Prevent data leakage

c)

Prevent phishing emails

d)

Prevent malware infections

e)

Prevent password reuse