విజ్ఞాన శాస్త్రం మరియు సాంకేతిక విజ్ఞానం - టెస్ట్ 26 - సైబర్ భద్రత ప్రాథమికాలు మరియు నెట్వర్క్ రక్షణ
Please keep at least one language enabled. || కనీసం ఒక భాషను ఎంచుకోండి.
Question 1
ప్రశ్న 1
An organisation encrypts a confidential personnel file so that an unauthorised person who obtains a copy cannot readily read its contents. Which security objective is being protected most directly?
ఒక సంస్థ గోప్యమైన సిబ్బంది దస్త్రాన్ని గుప్తీకరించింది. అనుమతి లేని వ్యక్తి ఆ దస్త్రం ప్రతిని పొందినా అందులోని సమాచారాన్ని సులభంగా చదవలేడు. ఇక్కడ ప్రధానంగా ఏ భద్రతా లక్ష్యం రక్షించబడుతోంది?
Explanation:
• Confidentiality preserves authorised restrictions on information access and disclosure.
• Encryption can reduce the usefulness of stolen or intercepted data to an unauthorised party when keys are protected.
• Encryption alone does not guarantee data availability or prove that the data have not been maliciously altered.
• Encryption can reduce the usefulness of stolen or intercepted data to an unauthorised party when keys are protected.
• Encryption alone does not guarantee data availability or prove that the data have not been maliciously altered.
వివరణ:
• Confidentiality అంటే సమాచారాన్ని అనుమతి లేని వ్యక్తులు చూడకుండా లేదా పొందకుండా రక్షించడం.
• గుప్తీకరణ తాళాలు సురక్షితంగా ఉంటే దొంగిలించిన లేదా మధ్యలో పట్టుకున్న సమాచారాన్ని చదవడం కష్టమవుతుంది.
• గుప్తీకరణ ఒక్కటే సమాచారం అందుబాటులో ఉంటుందని లేదా అది మార్చబడలేదని హామీ ఇవ్వదు.
• గుప్తీకరణ తాళాలు సురక్షితంగా ఉంటే దొంగిలించిన లేదా మధ్యలో పట్టుకున్న సమాచారాన్ని చదవడం కష్టమవుతుంది.
• గుప్తీకరణ ఒక్కటే సమాచారం అందుబాటులో ఉంటుందని లేదా అది మార్చబడలేదని హామీ ఇవ్వదు.
Question 2
ప్రశ్న 2
A financial record is protected so that unauthorised modification can be detected and improper changes are prevented. Which cybersecurity property is most directly involved?
ఒక ఆర్థిక నమోదులో అనుమతి లేని మార్పులను గుర్తించి, అనుచిత మార్పులను నిరోధించే ఏర్పాట్లు చేశారు. ఇది ప్రధానంగా ఏ సైబర్ భద్రతా లక్షణానికి సంబంధించినది?
Explanation:
• Integrity concerns protecting information against improper modification or destruction and preserving accuracy and completeness.
• Integrity controls can include authorised change processes, cryptographic integrity checks, access controls and logging.
• Confidentiality addresses unauthorised disclosure, which is a different security objective.
• Integrity controls can include authorised change processes, cryptographic integrity checks, access controls and logging.
• Confidentiality addresses unauthorised disclosure, which is a different security objective.
వివరణ:
• Integrity అంటే సమాచారాన్ని అనుచిత మార్పు లేదా నాశనం నుంచి రక్షించి దాని ఖచ్చితత్వం, సంపూర్ణతను కాపాడటం.
• అధికారిక మార్పు విధానాలు, క్రిప్టోగ్రాఫిక్ సమగ్రత తనిఖీలు, ప్రాప్తి నియంత్రణలు, లాగ్ నమోదు వంటి పద్ధతులు దీనికి సహాయపడవచ్చు.
• Confidentiality అనుమతి లేని సమాచార వెల్లడింపును నిరోధించడం గురించి; అది వేరే భద్రతా లక్ష్యం.
• అధికారిక మార్పు విధానాలు, క్రిప్టోగ్రాఫిక్ సమగ్రత తనిఖీలు, ప్రాప్తి నియంత్రణలు, లాగ్ నమోదు వంటి పద్ధతులు దీనికి సహాయపడవచ్చు.
• Confidentiality అనుమతి లేని సమాచార వెల్లడింపును నిరోధించడం గురించి; అది వేరే భద్రతా లక్ష్యం.
Question 3
ప్రశ్న 3
A hospital's authorised staff must be able to access its clinical information system reliably when it is needed for patient care. Which cybersecurity objective does this requirement primarily describe?
రోగి సంరక్షణకు అవసరమైన సమయంలో ఆసుపత్రి అనుమతించిన సిబ్బంది క్లినికల్ సమాచార వ్యవస్థను విశ్వసనీయంగా ఉపయోగించగలగాలి. ఈ అవసరం ప్రధానంగా ఏ సైబర్ భద్రతా లక్ష్యాన్ని సూచిస్తుంది?
Explanation:
• Availability means ensuring timely and reliable access to information and systems for authorised users.
• Resilient infrastructure, redundancy, incident recovery and protection from denial-of-service can support availability.
• A system may preserve confidentiality yet still fail the availability objective if authorised users cannot access it when needed.
• Resilient infrastructure, redundancy, incident recovery and protection from denial-of-service can support availability.
• A system may preserve confidentiality yet still fail the availability objective if authorised users cannot access it when needed.
వివరణ:
• Availability అంటే అనుమతించిన వినియోగదారులకు అవసరమైన సమయంలో సమాచారం, వ్యవస్థలు విశ్వసనీయంగా అందుబాటులో ఉండేలా చేయడం.
• ప్రత్యామ్నాయ వ్యవస్థలు, redundancy, incident recovery మరియు denial-of-service నుంచి రక్షణ availabilityను మెరుగుపరచగలవు.
• గోప్యత బాగా ఉన్నా అవసరమైన సమయంలో అధికారిక వినియోగదారులు వ్యవస్థను చేరుకోలేకపోతే availability లక్ష్యం నెరవేరదు.
• ప్రత్యామ్నాయ వ్యవస్థలు, redundancy, incident recovery మరియు denial-of-service నుంచి రక్షణ availabilityను మెరుగుపరచగలవు.
• గోప్యత బాగా ఉన్నా అవసరమైన సమయంలో అధికారిక వినియోగదారులు వ్యవస్థను చేరుకోలేకపోతే availability లక్ష్యం నెరవేరదు.
Question 4
ప్రశ్న 4
Which statement correctly distinguishes authentication from authorization?
Authentication మరియు authorization మధ్య తేడాను సరైన విధంగా తెలిపేది ఏది?
Explanation:
• Authentication establishes confidence in the identity of a user, device or process.
• Authorization is the subsequent access-control decision about permitted resources or actions.
• Successful authentication is therefore not equivalent to unrestricted access.
• Authorization is the subsequent access-control decision about permitted resources or actions.
• Successful authentication is therefore not equivalent to unrestricted access.
వివరణ:
• Authentication వినియోగదారు, పరికరం లేదా ప్రక్రియ ప్రకటించిన గుర్తింపు నిజమా అని ధృవీకరిస్తుంది.
• Authorization తరువాత ఏ వనరులు లేదా చర్యలకు అనుమతి ఇవ్వాలో నిర్ణయిస్తుంది.
• కాబట్టి authentication విజయవంతమైంది అంటే పరిమితిలేని ప్రాప్తి లభించిందని కాదు.
• Authorization తరువాత ఏ వనరులు లేదా చర్యలకు అనుమతి ఇవ్వాలో నిర్ణయిస్తుంది.
• కాబట్టి authentication విజయవంతమైంది అంటే పరిమితిలేని ప్రాప్తి లభించిందని కాదు.
Question 5
ప్రశ్న 5
Which example is genuine multi-factor authentication (MFA) according to the standard factor categories?
ప్రామాణిక authentication-factor వర్గాల ప్రకారం నిజమైన multi-factor authentication (MFA)కు సరైన ఉదాహరణ ఏది?
Explanation:
• MFA requires more than one distinct authentication-factor type, commonly something you know, have or are.
• A password is a knowledge factor and a hardware security key is a possession factor, so the combination uses distinct factors.
• Password plus PIN uses two knowledge secrets, while two biometric modalities remain within the inherence category.
• A password is a knowledge factor and a hardware security key is a possession factor, so the combination uses distinct factors.
• Password plus PIN uses two knowledge secrets, while two biometric modalities remain within the inherence category.
వివరణ:
• MFAలో ఒకటి కంటే ఎక్కువ వేర్వేరు authentication-factor వర్గాలను ఉపయోగించాలి; సాధారణంగా తెలిసిన రహస్యం, వద్ద ఉన్న సాధనం, శారీరక లక్షణం అనే వర్గాలు ఉంటాయి.
• Password తెలిసిన రహస్యానికి ఉదాహరణ; hardware security key వ్యక్తి వద్ద ఉండే సాధనానికి ఉదాహరణ.
• Password + PIN రెండూ ఒకే knowledge-factor వర్గానికి చెందుతాయి; రెండు biometrics కూడా ఒకే inherence వర్గానికి చెందుతాయి.
• Password తెలిసిన రహస్యానికి ఉదాహరణ; hardware security key వ్యక్తి వద్ద ఉండే సాధనానికి ఉదాహరణ.
• Password + PIN రెండూ ఒకే knowledge-factor వర్గానికి చెందుతాయి; రెండు biometrics కూడా ఒకే inherence వర్గానికి చెందుతాయి.
Question 6
ప్రశ్న 6
Which action best applies the principle of least privilege?
Least privilege సూత్రాన్ని అత్యంత సరైన విధంగా అమలు చేసేది ఏ చర్య?
Explanation:
• Least privilege restricts users and processes to the minimum permissions and resources needed to perform their functions.
• This limits damage from mistakes, compromised accounts and malicious activity.
• Broad administrator rights and shared privileged accounts increase rather than reduce security risk.
• This limits damage from mistakes, compromised accounts and malicious activity.
• Broad administrator rights and shared privileged accounts increase rather than reduce security risk.
వివరణ:
• Least privilegeలో వినియోగదారు లేదా ప్రక్రియ తన పని చేయడానికి అవసరమైన కనిష్ఠ అనుమతులు, వనరులు మాత్రమే పొందుతుంది.
• దీంతో పొరపాట్లు, చొరబాటుకు గురైన ఖాతాలు లేదా దుర్వినియోగం వల్ల కలిగే నష్టం పరిమితం అవుతుంది.
• అవసరం లేని administrator హక్కులు మరియు shared privileged accounts ప్రమాదాన్ని పెంచుతాయి.
• దీంతో పొరపాట్లు, చొరబాటుకు గురైన ఖాతాలు లేదా దుర్వినియోగం వల్ల కలిగే నష్టం పరిమితం అవుతుంది.
• అవసరం లేని administrator హక్కులు మరియు shared privileged accounts ప్రమాదాన్ని పెంచుతాయి.
Question 7
ప్రశ్న 7
What is the principal defensive role of a network firewall?
Network firewall యొక్క ప్రధాన రక్షణాత్మక పాత్ర ఏమిటి?
Explanation:
• NIST defines a firewall as a device or program that controls network-traffic flow between networks or hosts with differing security postures.
• Firewall rules can permit, reject or otherwise handle traffic according to policy.
• A firewall is one defence layer and does not replace endpoint security, authentication, patching or monitoring.
• Firewall rules can permit, reject or otherwise handle traffic according to policy.
• A firewall is one defence layer and does not replace endpoint security, authentication, patching or monitoring.
వివరణ:
• NIST ప్రకారం firewall అనేది నెట్వర్క్లు లేదా hosts మధ్య డేటా ప్రవాహాన్ని భద్రతా విధానాల ప్రకారం నియంత్రించే పరికరం లేదా program.
• Firewall rules అవసరాన్ని బట్టి trafficను అనుమతించడం, నిరోధించడం లేదా ఇతర విధంగా నియంత్రించడం చేయగలవు.
• Firewall ఒక రక్షణ పొర మాత్రమే; endpoint security, authentication, patching, పర్యవేక్షణ అవసరాలను భర్తీ చేయదు.
• Firewall rules అవసరాన్ని బట్టి trafficను అనుమతించడం, నిరోధించడం లేదా ఇతర విధంగా నియంత్రించడం చేయగలవు.
• Firewall ఒక రక్షణ పొర మాత్రమే; endpoint security, authentication, patching, పర్యవేక్షణ అవసరాలను భర్తీ చేయదు.
Question 8
ప్రశ్న 8
Which statement most accurately distinguishes an Intrusion Detection System (IDS) from an Intrusion Prevention System (IPS)?
Intrusion Detection System (IDS) మరియు Intrusion Prevention System (IPS) మధ్య తేడాను అత్యంత సరైన విధంగా తెలిపేది ఏది?
Explanation:
• IDS technology monitors events and analyses them for signs of possible security incidents.
• IPS includes detection capabilities and can also attempt active prevention or blocking.
• Detection and prevention controls require proper configuration and monitoring and do not guarantee that every attack will be identified.
• IPS includes detection capabilities and can also attempt active prevention or blocking.
• Detection and prevention controls require proper configuration and monitoring and do not guarantee that every attack will be identified.
వివరణ:
• IDS వ్యవస్థ లేదా నెట్వర్క్లో జరుగుతున్న సంఘటనలను పరిశీలించి భద్రతా దాడి లేదా incident సంకేతాలను గుర్తించడానికి ప్రయత్నిస్తుంది.
• IPSలో detectionతో పాటు అవసరమైనప్పుడు intrusive activityను ఆపడం లేదా block చేయడం చేసే సామర్థ్యం ఉంటుంది.
• సరైన అమరిక, పర్యవేక్షణ అవసరం; ప్రతి దాడి తప్పకుండా గుర్తించబడుతుందని IDS/IPS హామీ ఇవ్వవు.
• IPSలో detectionతో పాటు అవసరమైనప్పుడు intrusive activityను ఆపడం లేదా block చేయడం చేసే సామర్థ్యం ఉంటుంది.
• సరైన అమరిక, పర్యవేక్షణ అవసరం; ప్రతి దాడి తప్పకుండా గుర్తించబడుతుందని IDS/IPS హామీ ఇవ్వవు.
Question 9
ప్రశ్న 9
Which statement best describes endpoint security in an organisation?
ఒక సంస్థలో endpoint securityను అత్యంత సరైన విధంగా వివరించేది ఏది?
Explanation:
• Endpoints are common targets and entry points, so security controls are applied directly to devices as well as to the network.
• Patching, secure configuration, anti-malware, application controls and EDR can reduce or detect endpoint compromise.
• Endpoint security and network defence are complementary layers rather than substitutes.
• Patching, secure configuration, anti-malware, application controls and EDR can reduce or detect endpoint compromise.
• Endpoint security and network defence are complementary layers rather than substitutes.
వివరణ:
• Endpoints దాడులకు సాధారణ లక్ష్యాలు, ప్రవేశ బిందువులు కావచ్చు; అందువల్ల నెట్వర్క్తో పాటు పరికరాలపైనా రక్షణ అవసరం.
• Patching, secure configuration, anti-malware, application controls మరియు EDR ద్వారా endpoint compromise ప్రమాదాన్ని తగ్గించడం లేదా గుర్తించడం సాధ్యమవుతుంది.
• Endpoint security మరియు network defence పరస్పర పూరక రక్షణ పొరలు.
• Patching, secure configuration, anti-malware, application controls మరియు EDR ద్వారా endpoint compromise ప్రమాదాన్ని తగ్గించడం లేదా గుర్తించడం సాధ్యమవుతుంది.
• Endpoint security మరియు network defence పరస్పర పూరక రక్షణ పొరలు.
Question 10
ప్రశ్న 10
Why is network segmentation a useful defensive control?
Network segmentation ఉపయోగకరమైన రక్షణ చర్యగా ఎందుకు పరిగణించబడుతుంది?
Explanation:
• Segmentation divides a network into zones with controlled communication between them.
• CISA recommends segmentation to help contain intrusions and reduce an attacker's ability to move laterally through an environment.
• Segmentation reduces potential blast radius but does not make a compromised segment automatically safe.
• CISA recommends segmentation to help contain intrusions and reduce an attacker's ability to move laterally through an environment.
• Segmentation reduces potential blast radius but does not make a compromised segment automatically safe.
వివరణ:
• Network segmentationలో నెట్వర్క్ను నియంత్రిత భాగాలుగా విడదీసి వాటి మధ్య సమాచార ప్రవాహాన్ని నియంత్రిస్తారు.
• CISA ప్రకారం ఇది intrusion ప్రభావాన్ని పరిమితం చేసి attacker ఒక భాగం నుంచి మరో భాగానికి lateral movement చేయడాన్ని తగ్గించగలదు.
• Segmentation నష్టం వ్యాప్తిని తగ్గిస్తుంది; ఒక భాగం compromise అయినంత మాత్రాన అది స్వయంగా సురక్షితం కాదు.
• CISA ప్రకారం ఇది intrusion ప్రభావాన్ని పరిమితం చేసి attacker ఒక భాగం నుంచి మరో భాగానికి lateral movement చేయడాన్ని తగ్గించగలదు.
• Segmentation నష్టం వ్యాప్తిని తగ్గిస్తుంది; ఒక భాగం compromise అయినంత మాత్రాన అది స్వయంగా సురక్షితం కాదు.
Question 11
ప్రశ్న 11
Which backup strategy most directly improves recovery resilience against ransomware?
Ransomware దాడి తరువాత recovery సామర్థ్యాన్ని అత్యంత నేరుగా మెరుగుపరచే backup strategy ఏది?
Explanation:
• CISA recommends offline, encrypted backups of critical data and regular testing of backup availability and integrity.
• Isolation reduces the chance that ransomware can encrypt or delete the recovery copies through the same compromised environment.
• A backup is useful only if required data can be restored reliably when needed.
• Isolation reduces the chance that ransomware can encrypt or delete the recovery copies through the same compromised environment.
• A backup is useful only if required data can be restored reliably when needed.
వివరణ:
• CISA ముఖ్యమైన డేటాకు offline, encrypted backups ఉంచి వాటి availability, integrity మరియు restorationను క్రమం తప్పకుండా పరీక్షించాలని సూచిస్తుంది.
• ప్రధాన వ్యవస్థ చొరబాటుకు గురైనప్పుడు అదే మార్గం ద్వారా ransomware backup copiesను encrypt లేదా delete చేసే ప్రమాదాన్ని isolation తగ్గిస్తుంది.
• అవసరమైన సమయంలో డేటాను విశ్వసనీయంగా restore చేయగలిగితేనే backup నిజంగా ఉపయోగపడుతుంది.
• ప్రధాన వ్యవస్థ చొరబాటుకు గురైనప్పుడు అదే మార్గం ద్వారా ransomware backup copiesను encrypt లేదా delete చేసే ప్రమాదాన్ని isolation తగ్గిస్తుంది.
• అవసరమైన సమయంలో డేటాను విశ్వసనీయంగా restore చేయగలిగితేనే backup నిజంగా ఉపయోగపడుతుంది.
Question 12
ప్రశ్న 12
Which statement best captures the Zero Trust security concept?
Zero Trust security భావనను అత్యంత సరైన విధంగా తెలిపేది ఏది?
Explanation:
• NIST Zero Trust does not grant implicit trust merely because an asset or account is inside an enterprise network or owned by the organisation.
• Authentication and authorization are explicit functions used before access to protected resources is established, with least-privilege decisions as a key goal.
• Zero Trust means verify and constrain access based on policy and context, not 'never allow anyone access'.
• Authentication and authorization are explicit functions used before access to protected resources is established, with least-privilege decisions as a key goal.
• Zero Trust means verify and constrain access based on policy and context, not 'never allow anyone access'.
వివరణ:
• NIST Zero Trustలో సంస్థ నెట్వర్క్ లోపల ఉందని లేదా సంస్థకు చెందినదని మాత్రమే వినియోగదారు, పరికరాన్ని implicit trustedగా పరిగణించరు.
• రక్షిత వనరుకు ప్రాప్తి ఇవ్వడానికి ముందు స్పష్టమైన authentication, authorization చేసి least-privilege ప్రాప్తి ఇవ్వడం ప్రధాన సూత్రం.
• Zero Trust అంటే 'ఎవరినీ ఎప్పుడూ అనుమతించవద్దు' కాదు; policy, context ఆధారంగా verify చేసి ప్రాప్తిని పరిమితం చేయడం.
• రక్షిత వనరుకు ప్రాప్తి ఇవ్వడానికి ముందు స్పష్టమైన authentication, authorization చేసి least-privilege ప్రాప్తి ఇవ్వడం ప్రధాన సూత్రం.
• Zero Trust అంటే 'ఎవరినీ ఎప్పుడూ అనుమతించవద్దు' కాదు; policy, context ఆధారంగా verify చేసి ప్రాప్తిని పరిమితం చేయడం.
Question 13
ప్రశ్న 13
Why is timely security patching an important cyber-hygiene practice?
Security patchesను సమయానికి అమలు చేయడం ముఖ్యమైన cyber-hygiene చర్య ఎందుకు?
Explanation:
• Security updates commonly fix known vulnerabilities in operating systems, applications, firmware and devices.
• Timely patching reduces the window during which known weaknesses can be exploited.
• Patching is only one security layer and cannot prevent attacks that use unknown vulnerabilities, stolen credentials or unsafe configuration.
• Timely patching reduces the window during which known weaknesses can be exploited.
• Patching is only one security layer and cannot prevent attacks that use unknown vulnerabilities, stolen credentials or unsafe configuration.
వివరణ:
• Security updates operating systems, applications, firmware, పరికరాల్లో తెలిసిన vulnerabilitiesను సరిచేయవచ్చు.
• Patchesను సమయానికి అమలు చేయడం తెలిసిన బలహీనతలను దాడులు ఉపయోగించగల సమయాన్ని తగ్గిస్తుంది.
• Patching ఒక రక్షణ పొర మాత్రమే; తెలియని vulnerabilities, stolen credentials లేదా unsafe configuration ఆధారిత దాడులను పూర్తిగా నిరోధించదు.
• Patchesను సమయానికి అమలు చేయడం తెలిసిన బలహీనతలను దాడులు ఉపయోగించగల సమయాన్ని తగ్గిస్తుంది.
• Patching ఒక రక్షణ పొర మాత్రమే; తెలియని vulnerabilities, stolen credentials లేదా unsafe configuration ఆధారిత దాడులను పూర్తిగా నిరోధించదు.
Question 14
ప్రశ్న 14
A user receives an urgent message claiming to be from an administrator and is asked to enter a password on an unfamiliar login page. Which defensive response is most appropriate?
ఒక వినియోగదారికి administrator నుంచి వచ్చినట్లు కనిపించే అత్యవసర సందేశం వచ్చింది. తెలియని login pageలో password నమోదు చేయమని కోరుతోంది. అత్యంత సరైన రక్షణాత్మక చర్య ఏది?
Explanation:
• Phishing attempts often create urgency and imitate trusted organisations to trick users into revealing credentials.
• Verification through a known contact method or official service path avoids relying on the suspicious message itself.
• MFA can reduce the impact of some stolen-password attacks and should not be disabled simply because a message requests it.
• Verification through a known contact method or official service path avoids relying on the suspicious message itself.
• MFA can reduce the impact of some stolen-password attacks and should not be disabled simply because a message requests it.
వివరణ:
• Phishingలో నమ్మదగిన సంస్థలా నటిస్తూ urgency సృష్టించి credentials బయటపెట్టించే ప్రయత్నం సాధారణం.
• అనుమానాస్పద సందేశంపైనే ఆధారపడకుండా తెలిసిన అధికారిక సంప్రదింపు మార్గం ద్వారా request నిజమా అని verify చేయాలి.
• MFA కొన్ని stolen-password దాడుల ప్రభావాన్ని తగ్గించగలదు; సందేశం కోరిందని దాన్ని disable చేయకూడదు.
• అనుమానాస్పద సందేశంపైనే ఆధారపడకుండా తెలిసిన అధికారిక సంప్రదింపు మార్గం ద్వారా request నిజమా అని verify చేయాలి.
• MFA కొన్ని stolen-password దాడుల ప్రభావాన్ని తగ్గించగలదు; సందేశం కోరిందని దాన్ని disable చేయకూడదు.
Question 15
ప్రశ్న 15
Which statement about encryption is most accurate from a cybersecurity-defence perspective?
సైబర్ రక్షణ దృష్టిలో encryption గురించి అత్యంత సరైన ప్రకటన ఏది?
Explanation:
• Encryption is a major confidentiality control for stored and transmitted information when algorithms, keys and implementations are secure.
• Other controls are still needed for identity, authorization, availability, malware defence and recovery.
• Key management is essential because lost or compromised keys can make encrypted data unavailable or exposed.
• Other controls are still needed for identity, authorization, availability, malware defence and recovery.
• Key management is essential because lost or compromised keys can make encrypted data unavailable or exposed.
వివరణ:
• Algorithms, keys మరియు implementation సురక్షితంగా ఉన్నప్పుడు encryption నిల్వలోని, ప్రసారంలో ఉన్న సమాచార confidentialityకు ముఖ్యమైన రక్షణ.
• Identity, authorization, availability, malware defence, recovery కోసం ఇతర controls ఇంకా అవసరం.
• Keys పోతే డేటా అందుబాటులో లేకపోవచ్చు; keys compromise అయితే గోప్యత దెబ్బతినవచ్చు. కాబట్టి key management ముఖ్యమైనది.
• Identity, authorization, availability, malware defence, recovery కోసం ఇతర controls ఇంకా అవసరం.
• Keys పోతే డేటా అందుబాటులో లేకపోవచ్చు; keys compromise అయితే గోప్యత దెబ్బతినవచ్చు. కాబట్టి key management ముఖ్యమైనది.
Question 16
ప్రశ్న 16
Which measure most directly improves availability against failure of a single server while a service must remain continuously online?
ఒక్క server విఫలమైనా సేవ నిరంతరం onlineలో ఉండాల్సిన పరిస్థితిలో availabilityను అత్యంత నేరుగా మెరుగుపరచే చర్య ఏది?
Explanation:
• Redundancy and failover can keep a service running when one component fails and therefore directly support availability.
• Backups primarily support recovery of data and systems after loss or corruption; restoration may involve downtime.
• Strong resilience often uses both redundancy for continuity and backups for recovery.
• Backups primarily support recovery of data and systems after loss or corruption; restoration may involve downtime.
• Strong resilience often uses both redundancy for continuity and backups for recovery.
వివరణ:
• Redundancy, failover వల్ల ఒక component విఫలమైనప్పుడు మరొకటి సేవను కొనసాగించగలదు; అందువల్ల availabilityకు నేరుగా సహాయపడతాయి.
• Backups ప్రధానంగా డేటా లేదా వ్యవస్థ నష్టం తరువాత recoveryకు ఉపయోగపడతాయి; restore చేయడానికి కొంత downtime అవసరమవచ్చు.
• మంచి resilience కోసం service continuityకు redundancy, recoveryకు backups రెండూ ఉపయోగపడతాయి.
• Backups ప్రధానంగా డేటా లేదా వ్యవస్థ నష్టం తరువాత recoveryకు ఉపయోగపడతాయి; restore చేయడానికి కొంత downtime అవసరమవచ్చు.
• మంచి resilience కోసం service continuityకు redundancy, recoveryకు backups రెండూ ఉపయోగపడతాయి.
Question 17
ప్రశ్న 17
Why are security logs and monitoring important in network defence?
Network defenceలో security logs మరియు monitoring ఎందుకు ముఖ్యమైనవి?
Explanation:
• Security monitoring uses system, application and network events to identify anomalies and possible incidents.
• Logs provide historical evidence useful for investigation, scoping, response and recovery.
• Logging is valuable only when records are appropriately protected, reviewed and integrated into operational response processes.
• Logs provide historical evidence useful for investigation, scoping, response and recovery.
• Logging is valuable only when records are appropriately protected, reviewed and integrated into operational response processes.
వివరణ:
• Security monitoringలో వ్యవస్థ, application, network eventsను పరిశీలించి అసాధారణ ప్రవర్తన మరియు possible incidentsను గుర్తిస్తారు.
• Logs గత సంఘటనల ఆధారాలను అందించి investigation, incident scope, response, recoveryలో సహాయపడతాయి.
• Logsను సురక్షితంగా ఉంచి, క్రమం తప్పకుండా పరిశీలించి, operational responseతో అనుసంధానించినప్పుడు పూర్తి ప్రయోజనం ఉంటుంది.
• Logs గత సంఘటనల ఆధారాలను అందించి investigation, incident scope, response, recoveryలో సహాయపడతాయి.
• Logsను సురక్షితంగా ఉంచి, క్రమం తప్పకుండా పరిశీలించి, operational responseతో అనుసంధానించినప్పుడు పూర్తి ప్రయోజనం ఉంటుంది.
Question 18
ప్రశ్న 18
Which list contains the six Functions of the current NIST Cybersecurity Framework (CSF) 2.0?
ప్రస్తుత NIST Cybersecurity Framework (CSF) 2.0లోని ఆరు Functions సరైన సమూహం ఏది?
Explanation:
• NIST CSF 2.0 organises high-level cybersecurity outcomes into six Functions: Govern, Identify, Protect, Detect, Respond and Recover.
• CSF 2.0 added Govern to the five Functions used in CSF 1.1.
• The Functions provide a risk-management structure and are not a claim that one specific security product can achieve all outcomes.
• CSF 2.0 added Govern to the five Functions used in CSF 1.1.
• The Functions provide a risk-management structure and are not a claim that one specific security product can achieve all outcomes.
వివరణ:
• NIST CSF 2.0లో high-level cybersecurity outcomesను Govern, Identify, Protect, Detect, Respond, Recover అనే ఆరు Functionsగా అమర్చారు.
• CSF 1.1లో ఉన్న ఐదు Functionsకు CSF 2.0లో Governను చేర్చారు.
• ఇవి cybersecurity risk managementకు నిర్మాణాన్ని అందిస్తాయి; ఒక్క security productతో అన్ని outcomes సాధ్యమవుతాయని అర్థం కాదు.
• CSF 1.1లో ఉన్న ఐదు Functionsకు CSF 2.0లో Governను చేర్చారు.
• ఇవి cybersecurity risk managementకు నిర్మాణాన్ని అందిస్తాయి; ఒక్క security productతో అన్ని outcomes సాధ్యమవుతాయని అర్థం కాదు.
Question 19
ప్రశ్న 19
Which statement correctly describes CERT-In's current role in India?
భారతదేశంలో CERT-In ప్రస్తుత పాత్రను సరైన విధంగా తెలిపేది ఏది?
Explanation:
• CERT-In is designated under Section 70B of India's Information Technology Act as the national nodal agency for responding to cybersecurity incidents.
• Its statutory functions include collecting and analysing incident information, forecasts and alerts, emergency measures, response coordination and issuing advisories or guidelines.
• It operates under the Ministry of Electronics and Information Technology and serves the Indian cyber community.
• Its statutory functions include collecting and analysing incident information, forecasts and alerts, emergency measures, response coordination and issuing advisories or guidelines.
• It operates under the Ministry of Electronics and Information Technology and serves the Indian cyber community.
వివరణ:
• భారత Information Technology Actలోని Section 70B కింద CERT-In cybersecurity incidentsకు స్పందించే national nodal agencyగా నియమించబడింది.
• Incident information సేకరణ, విశ్లేషణ, alerts, emergency measures, response coordination మరియు advisories/guidelines జారీ చేయడం దాని చట్టబద్ధ functionsలో ఉన్నాయి.
• ఇది Ministry of Electronics and Information Technology కింద పనిచేస్తూ భారత cyber communityకు సేవలందిస్తుంది.
• Incident information సేకరణ, విశ్లేషణ, alerts, emergency measures, response coordination మరియు advisories/guidelines జారీ చేయడం దాని చట్టబద్ధ functionsలో ఉన్నాయి.
• ఇది Ministry of Electronics and Information Technology కింద పనిచేస్తూ భారత cyber communityకు సేవలందిస్తుంది.
Question 20
ప్రశ్న 20
Consider the following statements:
1. Confidentiality concerns restricting unauthorised disclosure of information.
2. Integrity concerns protecting information from improper modification or destruction.
3. Availability concerns timely and reliable access for authorised users.
4. Authentication and authorization are exactly the same process.
How many of the statements given above are correct?
1. Confidentiality concerns restricting unauthorised disclosure of information.
2. Integrity concerns protecting information from improper modification or destruction.
3. Availability concerns timely and reliable access for authorised users.
4. Authentication and authorization are exactly the same process.
How many of the statements given above are correct?
క్రింది ప్రకటనలను పరిశీలించండి:
1. Confidentiality అనుమతి లేని సమాచార వెల్లడింపును పరిమితం చేయడాన్ని సూచిస్తుంది.
2. Integrity సమాచారాన్ని అనుచిత మార్పు లేదా నాశనం నుంచి రక్షించడాన్ని సూచిస్తుంది.
3. Availability అనుమతించిన వినియోగదారులకు అవసరమైన సమయంలో విశ్వసనీయ access ఉండటాన్ని సూచిస్తుంది.
4. Authentication మరియు authorization ఖచ్చితంగా ఒకే ప్రక్రియ.
పై ప్రకటనల్లో ఎన్ని సరైనవి?
1. Confidentiality అనుమతి లేని సమాచార వెల్లడింపును పరిమితం చేయడాన్ని సూచిస్తుంది.
2. Integrity సమాచారాన్ని అనుచిత మార్పు లేదా నాశనం నుంచి రక్షించడాన్ని సూచిస్తుంది.
3. Availability అనుమతించిన వినియోగదారులకు అవసరమైన సమయంలో విశ్వసనీయ access ఉండటాన్ని సూచిస్తుంది.
4. Authentication మరియు authorization ఖచ్చితంగా ఒకే ప్రక్రియ.
పై ప్రకటనల్లో ఎన్ని సరైనవి?
Explanation:
• Statements 1, 2 and 3 correctly describe confidentiality, integrity and availability as distinct information-security objectives.
• Statement 4 is incorrect because authentication verifies identity, while authorization determines permitted access or actions.
• Therefore exactly three statements are correct.
• Statement 4 is incorrect because authentication verifies identity, while authorization determines permitted access or actions.
• Therefore exactly three statements are correct.
వివరణ:
• 1, 2, 3 ప్రకటనలు confidentiality, integrity, availability అనే వేర్వేరు information-security లక్ష్యాలను సరిగ్గా వివరిస్తాయి.
• Authentication గుర్తింపును ధృవీకరిస్తుంది; authorization అనుమతించిన ప్రాప్తి లేదా చర్యలను నిర్ణయిస్తుంది. కాబట్టి 4వ ప్రకటన తప్పు.
• అందువల్ల మూడు ప్రకటనలు మాత్రమే సరైనవి.
• Authentication గుర్తింపును ధృవీకరిస్తుంది; authorization అనుమతించిన ప్రాప్తి లేదా చర్యలను నిర్ణయిస్తుంది. కాబట్టి 4వ ప్రకటన తప్పు.
• అందువల్ల మూడు ప్రకటనలు మాత్రమే సరైనవి.
Answer Key సమాధానాల పట్టిక
-
Question 1 ప్రశ్న 1Answer: A. Confidentiality సమాధానం: A. గోప్యత (Confidentiality)
-
Question 2 ప్రశ్న 2Answer: B. Integrity సమాధానం: B. సమగ్రత (Integrity)
-
Question 3 ప్రశ్న 3Answer: A. Availability సమాధానం: A. అందుబాటు (Availability)
-
Question 4 ప్రశ్న 4Answer: A. Authentication verifies an asserted identity; authorization determines what an authenticated user or process is allowed to access or do సమాధానం: A. Authentication ప్రకటించిన గుర్తింపును ధృవీకరిస్తుంది; authorization ధృవీకరించిన వినియోగదారు లేదా ప్రక్రియ ఏ వనరులను ఉపయోగించవచ్చో, ఏ పనులు చేయవచ్చో నిర్ణయిస్తుంది
-
Question 5 ప్రశ్న 5Answer: C. Password plus a cryptographic hardware security key that the user possesses సమాధానం: C. Passwordతో పాటు వినియోగదారి వద్ద ఉండే cryptographic hardware security key
-
Question 6 ప్రశ్న 6Answer: B. Grant a user only the minimum permissions required for assigned duties and remove unnecessary privileges సమాధానం: B. అప్పగించిన పనులకు అవసరమైన కనిష్ఠ permissions మాత్రమే ఇచ్చి అవసరం లేని privileges తొలగించడం
-
Question 7 ప్రశ్న 7Answer: A. To control network traffic between hosts or networks according to security policy సమాధానం: A. భద్రతా విధానాల ప్రకారం hosts లేదా networks మధ్య నెట్వర్క్ డేటా ప్రవాహాన్ని నియంత్రించడం
-
Question 8 ప్రశ్న 8Answer: A. An IDS monitors and detects signs of possible incidents, while an IPS also has the ability to attempt to stop or block detected intrusive activity సమాధానం: A. IDS సంభవించే దాడి లేదా భద్రతా సంఘటన సంకేతాలను గుర్తించేందుకు activityను పరిశీలిస్తుంది; IPS గుర్తింపుతో పాటు intrusive activityను ఆపడానికి లేదా block చేయడానికి ప్రయత్నించగలదు
-
Question 9 ప్రశ్న 9Answer: A. Protecting devices such as laptops, desktops and servers through measures such as secure configuration, patching, anti-malware and endpoint detection/response సమాధానం: A. Laptops, desktops, servers వంటి devicesను secure configuration, patching, anti-malware మరియు endpoint detection/response వంటి చర్యలతో రక్షించడం
-
Question 10 ప్రశ్న 10Answer: A. It separates systems or resources into controlled network segments, helping restrict unnecessary access and limit lateral movement if one segment is compromised సమాధానం: A. Systems లేదా resourcesను నియంత్రిత network segmentsగా విడదీసి అవసరం లేని accessను తగ్గించడం, ఒక segment compromise అయినా దాడి ఇతర భాగాలకు lateral movement చేయడాన్ని పరిమితం చేయడంలో సహాయపడుతుంది
-
Question 11 ప్రశ్న 11Answer: A. Maintain protected offline or otherwise isolated backups of critical data and regularly test restoration procedures సమాధానం: A. ముఖ్యమైన dataకు రక్షిత offline లేదా ఇతర విధంగా isolated backups ఉంచి restoration proceduresను క్రమం తప్పకుండా పరీక్షించడం
-
Question 12 ప్రశ్న 12Answer: B. No user, device or workload receives implicit trust solely because of network location or ownership; access decisions are explicitly authenticated, authorized and constrained according to policy సమాధానం: B. Network location లేదా ownership కారణంగా మాత్రమే user, device లేదా workloadకు implicit trust ఇవ్వకుండా, policy ప్రకారం authentication, authorization చేసి accessను పరిమితం చేయడం
-
Question 13 ప్రశ్న 13Answer: A. Patches can correct known software vulnerabilities and reduce exposure to attacks that exploit them సమాధానం: A. తెలిసిన software vulnerabilitiesను patches సరిచేసి వాటిని ఉపయోగించే attacksకు exposureను తగ్గించగలవు
-
Question 14 ప్రశ్న 14Answer: B. Verify the request through a trusted independent channel and avoid entering credentials into the suspicious page సమాధానం: B. నమ్మదగిన స్వతంత్ర మార్గం ద్వారా ఆ request నిజమా అని verify చేసి, అనుమానాస్పద pageలో credentials నమోదు చేయకుండా ఉండడం
-
Question 15 ప్రశ్న 15Answer: A. Encryption can protect confidentiality of data at rest or in transit when properly implemented, but it does not by itself provide complete endpoint, availability and access-control security సమాధానం: A. సరిగ్గా అమలు చేసిన encryption నిల్వలో ఉన్న లేదా ప్రసారంలో ఉన్న data confidentialityను రక్షించగలదు; కానీ endpoint security, availability, access control అన్నింటినీ ఒక్కటే పూర్తిగా అందించదు
-
Question 16 ప్రశ్న 16Answer: A. Use redundant service instances or failover infrastructure so another system can continue service when one fails సమాధానం: A. ఒక system విఫలమైనప్పుడు మరొకటి వెంటనే సేవ కొనసాగించేలా redundant service instances లేదా failover infrastructure ఏర్పాటు చేయడం
-
Question 17 ప్రశ్న 17Answer: A. They can provide evidence of unusual activity, help detect incidents and support investigation and response సమాధానం: A. అసాధారణ activityకు ఆధారాలు అందించి incidentsను గుర్తించడం, investigation మరియు responseకు సహాయపడగలవు
-
Question 18 ప్రశ్న 18Answer || సమాధానం: A. Govern, Identify, Protect, Detect, Respond, Recover
-
Question 19 ప్రశ్న 19Answer: A. CERT-In is the national nodal agency under Section 70B of the Information Technology Act for cyber-incident response functions including information collection and analysis, alerts, response coordination and security advisories సమాధానం: A. Information Technology Actలోని Section 70B కింద CERT-In సైబర్ incidentsకు సంబంధించిన జాతీయ nodal agency; incident information సేకరణ–విశ్లేషణ, alerts, response coordination మరియు security advisories వంటి పనులు నిర్వహిస్తుంది
-
Question 20 ప్రశ్న 20Answer: C. Only three సమాధానం: C. మూడు మాత్రమే
