NEW
Font size
WorksheetsICD Policy and Cybersecurity
Total questions: 60
Worksheet time: 30mins
Which of the following is not a mandatory member of Information Security Committee (ISC) meeting?
CISO
CFO
CTO
MD&CEO
ED
What are the objectives of Information Security as per ICD Policy?
Confidentiality, Integrity, Availability of all Information assets of Bank
All Information is protected from Unauthorised Physical and Logical access whether by Staff, Contractors, Visitors or Outsiders
The users are aware of and comply with relevant legislation relating to the maintenance, protection, retention and withholding of information
Information is protected from Fraud, corruption or loss during input, processing, transmission and storage
All of the above
Which of the below is not a category of classification of Information based on the ICD policy of the bank?
Classified
Confidential
Internal
Public
Secret
What are the key objectives of multi-factor authentication?
Protect the Confidentiality
Avoid Cyber Attack
Enhance confidence in digital payment
Only a&b
All a,b&c
Bank has implemented which of the following security features for improving the security posture of the ATM?
BIOS password
Disabling USB ports
Disabling auto-run facility
Implement anti-skimming and whitelisting solution
All of the above
Who among the following is not a member in the Cyber Crisis Management Team
CISO
CTO
CGM - HR Operations
CRO
CFO
In the computer networks, the encryption techniques are primarily used for improving the ________
Security
Performance
Reliability
Longevity
All of the above
Which of the below are the Crisis Identification Criteria as per Bank's ICD policy?
Only A
Only B
Only C
Only A & B
All A, B & C
As per ICD Policy which among the following are considered as information assets of Bank?
Servers
Laptop/Desktops
Hardware Devices/Softwares
Customer Data/Transaction Data
All of the above
What is the purpose of a Cyber Crisis Management Plan (CCMP)?
To effectively respond to a crisis
To recover and restore the affected systems within the expected time duration
To minimize the business impact due to a crisis
To establish a response structure with representation from key stakeholders across the Bank
All of the above
Which among the below is not a recommended guideline for evidence handling during a cyber crisis?
Remove the network cable if plugged in
If the computer is on do not turn it off
Format the Entire System Completely
If the computer is off do not turn it on
Do not connect infected systems to any network
Sensitive Personal Information are Data elements which may pose heightened risks to the individual if disclosed or compromised. Which of the below is not considered a sensitive personal information?
PAN Card/Aadhar card
Bank account information
Passport
Mobile Handset Make & Model
Driver’s license number
As per Banks policy, which of the below minimum credentials should be recorded in audit trail and activity logs maintainance?
User ID’s
Dates and times for logon and logoff
Terminal identity or location if possible
Only A & B
All A,B & C
What are the benefits of the Business Continuity Plan?
Identify & Reduce Risk of any cyber incident
It helps to carry business in the normal manner with least interruption
It helps to restore critical processes within acceptable time scale
It helps to reduce the damage caused by disasters and security failures to an acceptable level
All of the above
What is the Objective for assessing and evaluating the Cyber Risk of Vendors as per ICD policy of Bank?
Visualize the risk involved with vendor onboarding
Annual Information/Cyber Security Risk Assessment to maintain the risk level
Classify the vendor’s based on criticality of risk assessment
To assess the business dependency on the vendors
All A, B & C
What is the objective of Cyber Fraud Prevention Chapter under ICD policy of Bank?
Prevent Cyber-attacks
Reduce vulnerabilities in critical infrastructure
Minimize damage and recovery in reasonable time
Reporting to Monitoring authorities
All of the above
Bank will ensure the security, privacy and confidentiality of any sensitive personal data or information that it collects, receives, possess, stores or deals with. Which of the following is a method via which Bank collects personal information?
Open an account or perform online transactions
For the Government purpose, like tax collection
Via cookies when the customer visits the bank’s web site
Apply for a loan or use his/her credit or debit card
All of the above
What pillar of information security ensures that sensitive information is not disclosed without authorization?
Availability
Non-repudiation
Integrity
Confidentiality
None of the above
All types of phishing URLs/Emails to be reported to which email ID of CISO office?
antiphishing@unionbankofindia.bank
antiphishing.ciso@unionbankofindia.bank
phishing-report@unionbankofindia.bank
antiphishing@unionbankofindia.in
ciso.phishing@unionbankofindia.co.in
What is a Ransomware?
Accessing information that was not intended for the specific user
A type of malicious software designed to block access to a computer system until a sum of money is paid
A software used to forward phishing mails
A malicious program for gaining access to information for the sake of fun
Any computer virus is a Ransomware
What is Spoofing?
Sending indiscriminately unsolicited bulk messages
Attack on Update mechanism of softwares/apps to distribute malware
It is a new kind of cyber attack started this year
Attack in which the system files are locked
Attack in which the hacker impersonates as another user by falsifying data to gain advantage
What is a supply chain attack?
Sending indiscriminately unsolicited bulk messages
Attack on Update mechanism of softwares/apps to distribute malware
Attack by exploiting a vulnerability in a software that is unknown to the vendor/developer
A cyber attack which happens on the last day of the month
Attack in which the system files are locked
What is a Zero Day Attack?
A hole in the system in the shape of a circle
An attack that happens on the last day of the month
A vulnerability in software that is unknown to the vendor
The attack that happens on the first day of application launch
Device Security
What are the key objectives of multi-factor authentication?
Protect the Confidentiality
Avoid Cyber Attack
Enhance user confidence
Only a&b
All a,b&c
A scenario where an employee discloses sensitive information to a third party, is a type of:
Man-in-the-middle attack
Phishing Attack
Insider Threat
Ransomware Attack
All of the above
Which of the following month is celebrated as National Cyber Security Awareness Month
August
September
October
November
December
How can you report a Cyber Fraud? How can you report a Cyber Fraud ? A) Call 1930 (Toll free) B) Register your complain in www.cybercrime.gov.in C) Complain at the nearest Cyber Crime Police Station
Only A
Only B
Only C
Only A & B
Any of A, B or C
To report/block suspected fraud communications received through call/SMS/WhatsApp messages, Department of Telecommunications has launched a new portal named CHAKSHU (चक्षु). Which of the below is the URL of the portal?
Only A
Only B
Only A & B
Any of A, B or C
Only C
Choose the correct Email ID issued by Bank for reporting Cyber Crime:
A. cybercrimecell.co@unionbankofindia.bank
B. cybercrimecell.co@unionbankofindia.com
Only A
Only B
Only C
Only A & B
Any of A, B or C
A situation in which an unauthorized person can view another user's display or keyboard to learn their password or other confidential information is referred to as
Tailgating
Spear Phishing
Man-in-the-middle
Spoofing
Shoulder Surfing
Which protocol is commonly used for secure web browsing?
HTTP
HTTPS
FTP
SMTP
Telnet
What does the term 'phishing' refer to?
Sending bulk ads
Tricking users to give credentials
Infecting files with virus
Encrypting data
Securing payment gateways
Which of the following is a strong password?
123456
MyNam@2023
password
Summer2020
qwerty
What does a firewall primarily protect against?
Hardware damage
Unauthorized access
Power outage
Traffic congestion
Strong passwords
Which malware type locks users out of their system until payment is made?
Adware
Ransomware
Trojan
Spyware
Worm
Which organization publishes the OWASP Top 10 vulnerabilities list?
NIST
OWASP
ISO
CERT
IEEE
What does VPN stand for?
Virtual Private Network
Virtual Public Node
Verified Private Network
Virtual Privacy Network
Virtual Protection Node
In cybersecurity, what does CIA triad stand for?
Confidentiality, Integrity, Availability
Confidentiality, Identity, Access
Control, Integrity, Access
Confidentiality, Integrity, Authentication
Critical Infrastructure Assessment
What is the main function of IDS (Intrusion Detection System)?
Block malware execution
Detect malicious activity
Encrypt traffic
Store logs
Stop phishing emails
What type of attack involves overwhelming a system with traffic?
Phishing
DDoS
SQL Injection
XSS
Brute force
Which of the following is an example of multi-factor authentication?
Password only
Password + OTP
PIN only
Security questions only
Username only
The main purpose of encryption is:
Speed up communication
Protect data confidentiality
Prevent phishing
Detect viruses
Boost system speed
Which type of attack exploits human psychology rather than technical flaws?
SQL injection
Social engineering
Buffer overflow
Cross-site scripting
Phishing
What is SQL Injection primarily used to target?
Databases
Operating systems
Memory
Mobile devices
What does zero-day vulnerability mean?
Vulnerability with no patch released
Vulnerability already patched
Attack with known exploit
Vulnerability used by insiders
Security tool for insiders
What is the safest way to connect to public Wi-Fi?
Use open Wi-Fi directly
Use VPN
Share credentials
Use Bluetooth tethering
Use cellular data
Which of the following is a hashing algorithm?
AES
SHA-256
RSA
SHA-1
MD5
What does least privilege principle mean?
Allowing broad user permissions
Giving only necessary access
Granting admin rights to all
Removing all user access
Grant all network access
What is the main purpose of patch management?
To upgrade hardware
To fix security flaws
To block DDoS
To add new features
To hire more employees
Which of the following best describes social engineering?
Managing IT teams
Manipulating people into actions
Developing secure software
Training IT staff only
Protecting servers
Which attack involves intercepting communication between two parties without their knowledge?
Replay attack
MITM (Man-in-the-Middle)
Phishing
Brute force
DoS attack
What is the primary purpose of two-factor authentication?
To simplify login
To provide stronger identity verification
To reduce costs
To increase server uptime
To reduce downtime
Which of the following is NOT a form of malware?
Trojan
Network scanner
Ransomware
Worm
Keylogger
Which security measure helps protect against brute force attacks?
Weak password
Account lockout
Encryption
Firewalls
CAPTCHA
What is a common sign of a phishing email?
Professional grammar
Generic greetings like 'Dear user'
Personalized details
Valid sender addresses
Technical language
Which of the following is an example of biometric authentication?
PIN code
Fingerprint scan
Password
Smart card
Username
Which of the following best describes a Trojan horse?
Self-replicating worm
Malware disguised as legit software
Adware
Network scanner
Spyware
What is the main risk of using outdated software?
Better system speed
Data breaches
New features
Longer battery life
Improved UI
Which cybersecurity principle is enforced by regular backups?
Integrity
Availability
Confidentiality
Authentication
Non-repudiation
What does DLP (Data Loss Prevention) software aim to prevent?
Prevent insider trading
Prevent data leakage
Prevent phishing emails
Prevent malware infections
Prevent password reuse
