విజ్ఞాన శాస్త్రం మరియు సాంకేతిక విజ్ఞానం - టెస్ట్ 28 - సైబర్ ముప్పులు, మాల్వేర్ మరియు రక్షణ సాంకేతికతలు
Please keep at least one language enabled. || కనీసం ఒక భాషను ఎంచుకోండి.
Question 1
ప్రశ్న 1
Which description best matches malware?
Malwareను అత్యంత సరైన విధంగా వివరించేది ఏది?
Explanation:
• Malware is malicious software or firmware intended to perform unauthorised processes or harm systems and data.
• Viruses, worms, Trojans and spyware are among common malware categories.
• The term describes malicious intent or function, not every software fault or advertisement.
• Viruses, worms, Trojans and spyware are among common malware categories.
• The term describes malicious intent or function, not every software fault or advertisement.
వివరణ:
• Malware అనేది అనుమతి లేని ప్రక్రియలు నిర్వహించడం లేదా systems, dataకు హాని కలిగించడం కోసం ఉద్దేశించిన హానికర software లేదా firmware.
• Viruses, worms, Trojans, spyware వంటి వాటి రూపాలు malwareలో ఉంటాయి.
• ప్రతి software fault లేదా advertisementను malwareగా పరిగణించకూడదు; హానికర ఉద్దేశం లేదా పని ప్రధాన అంశం.
• Viruses, worms, Trojans, spyware వంటి వాటి రూపాలు malwareలో ఉంటాయి.
• ప్రతి software fault లేదా advertisementను malwareగా పరిగణించకూడదు; హానికర ఉద్దేశం లేదా పని ప్రధాన అంశం.
Question 2
ప్రశ్న 2
Which statement correctly distinguishes a computer virus from a worm?
Computer virus మరియు worm మధ్య తేడాను సరైన విధంగా తెలిపేది ఏది?
Explanation:
• A virus replicates by inserting itself into host programs, files or related data structures.
• A worm is a self-contained program capable of propagating to other systems without requiring a host program.
• Both are malware, but their replication mechanisms are conceptually different.
• A worm is a self-contained program capable of propagating to other systems without requiring a host program.
• Both are malware, but their replication mechanisms are conceptually different.
వివరణ:
• Virus host programs, files లేదా సంబంధిత data structuresలో తన copiesను చొప్పించడం ద్వారా replicate అవుతుంది.
• Worm self-contained program; host program అవసరం లేకుండానే ఇతర systemsకు వ్యాపించగలదు.
• రెండూ malware అయినప్పటికీ వాటి replication విధానాలు భిన్నమైనవి.
• Worm self-contained program; host program అవసరం లేకుండానే ఇతర systemsకు వ్యాపించగలదు.
• రెండూ malware అయినప్పటికీ వాటి replication విధానాలు భిన్నమైనవి.
Question 3
ప్రశ్న 3
Which description best matches a Trojan horse?
Trojan horseను అత్యంత సరైన విధంగా వివరించేది ఏది?
Explanation:
• A Trojan appears useful or legitimate while hiding a malicious function that runs when the program is invoked.
• Unlike a worm, automatic self-replication is not the defining characteristic of a Trojan.
• Defensive measures include obtaining software from trusted sources and using endpoint security controls.
• Unlike a worm, automatic self-replication is not the defining characteristic of a Trojan.
• Defensive measures include obtaining software from trusted sources and using endpoint security controls.
వివరణ:
• Trojan ఉపయోగకరమైన లేదా legitimate programలా కనిపిస్తూ అమలు చేసినప్పుడు hidden malicious functionను నిర్వహిస్తుంది.
• Wormతో పోలిస్తే automatic self-replication Trojan యొక్క defining characteristic కాదు.
• Trusted sources నుంచి software పొందడం మరియు endpoint security controls ఉపయోగించడం రక్షణకు సహాయపడుతుంది.
• Wormతో పోలిస్తే automatic self-replication Trojan యొక్క defining characteristic కాదు.
• Trusted sources నుంచి software పొందడం మరియు endpoint security controls ఉపయోగించడం రక్షణకు సహాయపడుతుంది.
Question 4
ప్రశ్న 4
What is the primary characteristic of spyware?
Spyware యొక్క ప్రధాన లక్షణం ఏమిటి?
Explanation:
• Spyware is software installed or operating surreptitiously to collect information without the subject's knowledge.
• It can threaten privacy and confidentiality by observing or extracting user or organisational information.
• Spyware is malware and should not be confused with legitimate monitoring performed with proper authorisation and notice.
• It can threaten privacy and confidentiality by observing or extracting user or organisational information.
• Spyware is malware and should not be confused with legitimate monitoring performed with proper authorisation and notice.
వివరణ:
• Spyware వ్యక్తి లేదా సంస్థకు తెలియకుండా రహస్యంగా సమాచారం సేకరించే software.
• User లేదా organisational informationను observe లేదా extract చేయడం ద్వారా privacy, confidentialityకు ముప్పు కలిగించవచ్చు.
• సరైన authorisation, noticeతో జరిగే legitimate monitoringను spywareతో కలపకూడదు.
• User లేదా organisational informationను observe లేదా extract చేయడం ద్వారా privacy, confidentialityకు ముప్పు కలిగించవచ్చు.
• సరైన authorisation, noticeతో జరిగే legitimate monitoringను spywareతో కలపకూడదు.
Question 5
ప్రశ్న 5
Which statement best describes ransomware?
Ransomwareను అత్యంత సరైన విధంగా వివరించేది ఏది?
Explanation:
• Ransomware is malware that attempts to deny access to a victim's data or systems, often through encryption.
• Some ransomware incidents also involve data theft and threats of disclosure, so encryption is common but not the only possible pressure tactic.
• Defensive preparation includes secure backups, patching, MFA and recovery planning.
• Some ransomware incidents also involve data theft and threats of disclosure, so encryption is common but not the only possible pressure tactic.
• Defensive preparation includes secure backups, patching, MFA and recovery planning.
వివరణ:
• Ransomware బాధితుడి data లేదా systemsకు accessను నిరాకరించేందుకు ప్రయత్నించే malware; సాధారణంగా encryptionను ఉపయోగిస్తుంది.
• కొన్ని ransomware incidentsలో data theft మరియు disclosure threats కూడా ఉంటాయి; కాబట్టి encryption మాత్రమే ఉండే tactic అని భావించకూడదు.
• Secure backups, patching, MFA మరియు recovery planning వంటి చర్యలు రక్షణ సామర్థ్యాన్ని పెంచుతాయి.
• కొన్ని ransomware incidentsలో data theft మరియు disclosure threats కూడా ఉంటాయి; కాబట్టి encryption మాత్రమే ఉండే tactic అని భావించకూడదు.
• Secure backups, patching, MFA మరియు recovery planning వంటి చర్యలు రక్షణ సామర్థ్యాన్ని పెంచుతాయి.
Question 6
ప్రశ్న 6
Which statement correctly distinguishes phishing from the broader concept of social engineering?
Phishing మరియు విస్తృతమైన social engineering భావన మధ్య తేడాను సరైన విధంగా తెలిపేది ఏది?
Explanation:
• Social engineering broadly means deceiving people into revealing sensitive information, granting access or taking harmful actions.
• Phishing is a common social-engineering technique delivered through email, text, social media or similar messages.
• Not every social-engineering attempt is necessarily phishing.
• Phishing is a common social-engineering technique delivered through email, text, social media or similar messages.
• Not every social-engineering attempt is necessarily phishing.
వివరణ:
• Social engineeringలో మోసంతో వ్యక్తిని sensitive information వెల్లడించడానికి, access ఇవ్వడానికి లేదా హానికర చర్య చేయడానికి ప్రభావితం చేస్తారు.
• Phishing email, text, social media వంటి messages ద్వారా జరిగే సాధారణ social-engineering technique.
• ప్రతి social-engineering ప్రయత్నం తప్పనిసరిగా phishing రూపంలోనే ఉండాల్సిన అవసరం లేదు.
• Phishing email, text, social media వంటి messages ద్వారా జరిగే సాధారణ social-engineering technique.
• ప్రతి social-engineering ప్రయత్నం తప్పనిసరిగా phishing రూపంలోనే ఉండాల్సిన అవసరం లేదు.
Question 7
ప్రశ్న 7
What most clearly distinguishes spear phishing from broad untargeted phishing?
Spear phishingను సాధారణ untargeted phishing నుంచి అత్యంత స్పష్టంగా వేరు చేసే లక్షణం ఏది?
Explanation:
• Spear phishing is a highly targeted form of phishing directed toward a particular individual, department or group.
• Target-specific context can make the message appear more credible.
• Unusual requests should be verified through trusted independent channels rather than relying on the message itself.
• Target-specific context can make the message appear more credible.
• Unusual requests should be verified through trusted independent channels rather than relying on the message itself.
వివరణ:
• Spear phishing ఒక నిర్దిష్ట వ్యక్తి, department లేదా groupను లక్ష్యంగా చేసుకునే highly targeted phishing రూపం.
• Targetకు సంబంధించిన context వాడటం వల్ల message మరింత credibleగా కనిపించవచ్చు.
• Unusual requestను messageపైనే ఆధారపడకుండా trusted independent channel ద్వారా verify చేయాలి.
• Targetకు సంబంధించిన context వాడటం వల్ల message మరింత credibleగా కనిపించవచ్చు.
• Unusual requestను messageపైనే ఆధారపడకుండా trusted independent channel ద్వారా verify చేయాలి.
Question 8
ప్రశ్న 8
Which description best matches a botnet?
Botnetను అత్యంత సరైన విధంగా వివరించేది ఏది?
Explanation:
• A botnet consists of compromised systems organised so they can be controlled or directed remotely as a group.
• Botnets may be used for several malicious purposes, including distributed denial-of-service activity, spam or other abuse.
• Patching, secure configuration and endpoint protection can reduce the chance that devices become part of a botnet.
• Botnets may be used for several malicious purposes, including distributed denial-of-service activity, spam or other abuse.
• Patching, secure configuration and endpoint protection can reduce the chance that devices become part of a botnet.
వివరణ:
• Botnetలో compromise అయిన systemsను ఒక groupగా organise చేసి remotely control లేదా direct చేస్తారు.
• Botnetsను DDoS, spam లేదా ఇతర malicious activitiesకు ఉపయోగించవచ్చు; ఒక్క purposeకే పరిమితం కాదు.
• Patching, secure configuration, endpoint protectionతో devices botnetలో చేరే ప్రమాదాన్ని తగ్గించవచ్చు.
• Botnetsను DDoS, spam లేదా ఇతర malicious activitiesకు ఉపయోగించవచ్చు; ఒక్క purposeకే పరిమితం కాదు.
• Patching, secure configuration, endpoint protectionతో devices botnetలో చేరే ప్రమాదాన్ని తగ్గించవచ్చు.
Question 9
ప్రశ్న 9
Which statement correctly distinguishes DoS from DDoS at an awareness level?
Awareness levelలో DoS మరియు DDoS మధ్య తేడాను సరైన విధంగా తెలిపేది ఏది?
Explanation:
• NIST defines denial of service as preventing authorised access to resources or delaying system operations.
• DDoS is a denial-of-service technique carried out using numerous hosts.
• The security objective most directly threatened is usually availability.
• DDoS is a denial-of-service technique carried out using numerous hosts.
• The security objective most directly threatened is usually availability.
వివరణ:
• NIST ప్రకారం denial of service authorised usersకు resources accessను నిరోధించడం లేదా system operationsను ఆలస్యం చేయడం.
• DDoS అనేక hostsను ఉపయోగించి జరిగే denial-of-service technique.
• ప్రధానంగా ప్రభావితమయ్యే security objective availability.
• DDoS అనేక hostsను ఉపయోగించి జరిగే denial-of-service technique.
• ప్రధానంగా ప్రభావితమయ్యే security objective availability.
Question 10
ప్రశ్న 10
Which action is most appropriate when a user receives an unexpected message urging immediate login through an unfamiliar link?
తెలియని link ద్వారా వెంటనే login కావాలని ఒత్తిడి చేసే unexpected message వచ్చినప్పుడు అత్యంత సరైన చర్య ఏది?
Explanation:
• Phishing messages often use urgency, impersonation and deceptive links to pressure users into unsafe actions.
• NIST recommends verifying suspicious requests through known contact information or an official site rather than through the message itself.
• Passwords, PINs or one-time codes should not be entered into an unverified page.
• NIST recommends verifying suspicious requests through known contact information or an official site rather than through the message itself.
• Passwords, PINs or one-time codes should not be entered into an unverified page.
వివరణ:
• Phishing messages urgency, impersonation, deceptive linksతో usersను unsafe actionsకు ఒత్తిడి చేయవచ్చు.
• Suspicious requestను అదే message ద్వారా కాకుండా తెలిసిన contact information లేదా official site ద్వారా verify చేయాలని NIST సూచిస్తుంది.
• Verify చేయని pageలో password, PIN లేదా one-time code నమోదు చేయకూడదు.
• Suspicious requestను అదే message ద్వారా కాకుండా తెలిసిన contact information లేదా official site ద్వారా verify చేయాలని NIST సూచిస్తుంది.
• Verify చేయని pageలో password, PIN లేదా one-time code నమోదు చేయకూడదు.
Question 11
ప్రశ్న 11
Why are security patches important in defence against malware and other cyber threats?
Malware మరియు ఇతర cyber threats నుంచి రక్షణలో security patches ఎందుకు ముఖ్యమైనవి?
Explanation:
• Patches fix known defects or vulnerabilities in software, firmware and operating systems.
• Timely patching reduces the period during which known weaknesses remain exploitable.
• Patching is one defensive layer and does not replace MFA, backups, endpoint security or user awareness.
• Timely patching reduces the period during which known weaknesses remain exploitable.
• Patching is one defensive layer and does not replace MFA, backups, endpoint security or user awareness.
వివరణ:
• Patches software, firmware, operating systemsలో తెలిసిన defects లేదా vulnerabilitiesను సరిచేస్తాయి.
• Timely patching తెలిసిన weaknesses exploit అయ్యే సమయాన్ని తగ్గిస్తుంది.
• Patching ఒక్క defensive layer మాత్రమే; MFA, backups, endpoint security లేదా user awarenessను భర్తీ చేయదు.
• Timely patching తెలిసిన weaknesses exploit అయ్యే సమయాన్ని తగ్గిస్తుంది.
• Patching ఒక్క defensive layer మాత్రమే; MFA, backups, endpoint security లేదా user awarenessను భర్తీ చేయదు.
Question 12
ప్రశ్న 12
Which statement best describes the role of endpoint protection against malware?
Malware నుంచి రక్షణలో endpoint protection పాత్రను అత్యంత సరైన విధంగా తెలిపేది ఏది?
Explanation:
• Endpoint security tools can identify suspicious files, behaviour, processes or other indicators and support containment and response.
• Endpoint Detection and Response can also preserve telemetry useful for investigation.
• Effective defence combines endpoint protection with patching, identity controls, segmentation, backups and monitoring.
• Endpoint Detection and Response can also preserve telemetry useful for investigation.
• Effective defence combines endpoint protection with patching, identity controls, segmentation, backups and monitoring.
వివరణ:
• Endpoint security tools suspicious files, behaviour, processes లేదా ఇతర indicatorsను గుర్తించి containment, responseకు సహాయపడగలవు.
• Endpoint Detection and Response investigationకు ఉపయోగపడే telemetryను కూడా సేకరించగలదు.
• Effective defenceలో endpoint protectionతో పాటు patching, identity controls, segmentation, backups, monitoring అవసరం.
• Endpoint Detection and Response investigationకు ఉపయోగపడే telemetryను కూడా సేకరించగలదు.
• Effective defenceలో endpoint protectionతో పాటు patching, identity controls, segmentation, backups, monitoring అవసరం.
Question 13
ప్రశ్న 13
Which backup practice is most effective for improving ransomware recovery resilience?
Ransomware recovery resilienceను మెరుగుపరచడంలో అత్యంత ఉపయోగకరమైన backup practice ఏది?
Explanation:
• CISA recommends offline, encrypted backups of critical data and regular tests of backup availability, integrity and restoration procedures.
• Isolation helps prevent ransomware in the production environment from also encrypting or deleting recovery copies.
• Backups are useful only if clean data and systems can be restored when needed.
• Isolation helps prevent ransomware in the production environment from also encrypting or deleting recovery copies.
• Backups are useful only if clean data and systems can be restored when needed.
వివరణ:
• CISA critical dataకు offline, encrypted backups ఉంచి backup availability, integrity, restoration proceduresను క్రమం తప్పకుండా test చేయాలని సూచిస్తుంది.
• Isolation వల్ల production environmentలో ransomware backup copiesను కూడా encrypt లేదా delete చేసే ప్రమాదం తగ్గుతుంది.
• అవసరమైన సమయంలో clean data, systemsను restore చేయగలిగితేనే backups నిజంగా ఉపయోగపడతాయి.
• Isolation వల్ల production environmentలో ransomware backup copiesను కూడా encrypt లేదా delete చేసే ప్రమాదం తగ్గుతుంది.
• అవసరమైన సమయంలో clean data, systemsను restore చేయగలిగితేనే backups నిజంగా ఉపయోగపడతాయి.
Question 14
ప్రశ్న 14
How can multi-factor authentication reduce the risk from credential theft?
Credential theft వల్ల వచ్చే riskను multi-factor authentication ఎలా తగ్గించగలదు?
Explanation:
• MFA uses two or more distinct authentication factors, such as something known, possessed or inherent to the user.
• If one factor such as a password is stolen, a separate factor can provide an additional barrier.
• MFA improves account defence but does not eliminate all phishing, malware or session-hijacking risks.
• If one factor such as a password is stolen, a separate factor can provide an additional barrier.
• MFA improves account defence but does not eliminate all phishing, malware or session-hijacking risks.
వివరణ:
• MFAలో userకు తెలిసినది, user వద్ద ఉన్నది లేదా user శారీరక లక్షణం వంటి రెండు లేదా ఎక్కువ distinct authentication factors ఉపయోగిస్తారు.
• Password వంటి ఒక factor steal అయినా separate factor additional barrierగా పనిచేస్తుంది.
• MFA account defenceను బలపరుస్తుంది; కానీ phishing, malware లేదా session-hijacking risks అన్నింటినీ పూర్తిగా తొలగించదు.
• Password వంటి ఒక factor steal అయినా separate factor additional barrierగా పనిచేస్తుంది.
• MFA account defenceను బలపరుస్తుంది; కానీ phishing, malware లేదా session-hijacking risks అన్నింటినీ పూర్తిగా తొలగించదు.
Question 15
ప్రశ్న 15
Why can network segmentation help limit the impact of a malware intrusion?
Malware intrusion ప్రభావాన్ని పరిమితం చేయడంలో network segmentation ఎందుకు సహాయపడుతుంది?
Explanation:
• Segmentation divides infrastructure into controlled zones and limits which systems can communicate directly.
• If malware compromises one zone, segmentation can reduce opportunities for unrestricted lateral movement into other parts of the environment.
• Segmentation is a containment control and works best alongside endpoint security, patching and least privilege.
• If malware compromises one zone, segmentation can reduce opportunities for unrestricted lateral movement into other parts of the environment.
• Segmentation is a containment control and works best alongside endpoint security, patching and least privilege.
వివరణ:
• Segmentation infrastructureను controlled zonesగా విడదీసి ఏ systems పరస్పరం directగా communicate చేయగలవో limit చేస్తుంది.
• Malware ఒక zoneను compromise చేసినా ఇతర partsకు unrestricted lateral movement చేసే అవకాశాన్ని తగ్గించవచ్చు.
• Segmentation containment control మాత్రమే; endpoint security, patching, least privilegeతో కలిపి ఉపయోగించడం మంచిది.
• Malware ఒక zoneను compromise చేసినా ఇతర partsకు unrestricted lateral movement చేసే అవకాశాన్ని తగ్గించవచ్చు.
• Segmentation containment control మాత్రమే; endpoint security, patching, least privilegeతో కలిపి ఉపయోగించడం మంచిది.
Question 16
ప్రశ్న 16
Which defensive response is most appropriate after a device shows credible signs of active malware infection?
ఒక deviceలో active malware infectionకు నమ్మదగిన signs కనిపించినప్పుడు అత్యంత సరైన defensive response ఏది?
Explanation:
• Isolating an affected endpoint can help limit further spread or malicious communication while incident-response work begins.
• Preserving relevant logs and evidence supports investigation and scoping of the incident.
• Recovery should use trusted procedures and clean backups or rebuild sources rather than spreading suspicious files.
• Preserving relevant logs and evidence supports investigation and scoping of the incident.
• Recovery should use trusted procedures and clean backups or rebuild sources rather than spreading suspicious files.
వివరణ:
• Affected endpointను isolate చేయడం incident response ప్రారంభమయ్యే సమయంలో further spread లేదా malicious communicationను పరిమితం చేయగలదు.
• Relevant logs, evidenceను preserve చేయడం investigation మరియు incident scope నిర్ణయానికి సహాయపడుతుంది.
• Suspicious filesను spread చేయకుండా trusted procedures మరియు clean backups లేదా rebuild sourcesతో recovery చేయాలి.
• Relevant logs, evidenceను preserve చేయడం investigation మరియు incident scope నిర్ణయానికి సహాయపడుతుంది.
• Suspicious filesను spread చేయకుండా trusted procedures మరియు clean backups లేదా rebuild sourcesతో recovery చేయాలి.
Question 17
ప్రశ్న 17
Which statement about threat detection is most accurate?
Threat detection గురించి అత్యంత సరైన ప్రకటన ఏది?
Explanation:
• Defensive detection can combine known signatures and indicators with behavioural analysis and endpoint or network telemetry.
• Signature-based methods are useful for known threats, while behavioural methods can help identify unusual activity without a known signature.
• False positives and false negatives remain possible, so layered monitoring and investigation are necessary.
• Signature-based methods are useful for known threats, while behavioural methods can help identify unusual activity without a known signature.
• False positives and false negatives remain possible, so layered monitoring and investigation are necessary.
వివరణ:
• Defensive detectionలో known signatures, indicatorsతో పాటు behavioural analysis మరియు endpoint/network telemetryను కలిపి ఉపయోగించవచ్చు.
• Signature-based methods తెలిసిన threatsకు ఉపయోగపడతాయి; behavioural methods known signature లేని unusual activityను గుర్తించడంలో సహాయపడవచ్చు.
• False positives, false negatives ఉండవచ్చు; కాబట్టి layered monitoring, investigation అవసరం.
• Signature-based methods తెలిసిన threatsకు ఉపయోగపడతాయి; behavioural methods known signature లేని unusual activityను గుర్తించడంలో సహాయపడవచ్చు.
• False positives, false negatives ఉండవచ్చు; కాబట్టి layered monitoring, investigation అవసరం.
Question 18
ప్రశ్న 18
A legitimate cloud service asks a user to sign in, but the user reached it through a suspicious message. Which response is safest?
ఒక legitimate cloud service userను sign in కావాలని అడుగుతోంది; కానీ user ఆ serviceకు suspicious message ద్వారా చేరుకున్నాడు. అత్యంత సురక్షితమైన response ఏది?
Explanation:
• Social-engineering attacks can imitate trusted brands or route users through convincing-looking pages.
• Independent navigation to a known official service reduces reliance on links or instructions supplied by a suspicious message.
• Familiar branding alone is not sufficient evidence that a request or login flow is legitimate.
• Independent navigation to a known official service reduces reliance on links or instructions supplied by a suspicious message.
• Familiar branding alone is not sufficient evidence that a request or login flow is legitimate.
వివరణ:
• Social-engineering attacks trusted brandsను imitate చేసి convincing-looking pages ద్వారా usersను మోసం చేయవచ్చు.
• Known official serviceకు independentగా navigate చేయడం suspicious message ఇచ్చిన links లేదా instructionsపై relianceను తగ్గిస్తుంది.
• Familiar branding ఒక్కటే request లేదా login flow legitimate అని నిరూపించదు.
• Known official serviceకు independentగా navigate చేయడం suspicious message ఇచ్చిన links లేదా instructionsపై relianceను తగ్గిస్తుంది.
• Familiar branding ఒక్కటే request లేదా login flow legitimate అని నిరూపించదు.
Question 19
ప్రశ్న 19
A ransomware incident encrypts a shared file server so authorised staff can no longer use the files. Which security objective is most directly affected by that encryption impact?
Ransomware ఒక shared file serverలోని filesను encrypt చేయడంతో authorised staff వాటిని ఉపయోగించలేకపోతున్నారు. ఈ encryption ప్రభావం వల్ల ప్రధానంగా ఏ security objective దెబ్బతింటుంది?
Explanation:
• Encrypting files so authorised users cannot access them directly harms availability.
• If ransomware also steals data, confidentiality can be affected as a separate impact.
• One cyber incident can affect multiple security objectives, so the question must distinguish the particular effect being described.
• If ransomware also steals data, confidentiality can be affected as a separate impact.
• One cyber incident can affect multiple security objectives, so the question must distinguish the particular effect being described.
వివరణ:
• Authorised users filesను ఉపయోగించలేని విధంగా encryption జరగడం availabilityను నేరుగా దెబ్బతీస్తుంది.
• Ransomware dataను steal కూడా చేస్తే confidentialityపై వేరే ప్రభావం రావచ్చు.
• ఒకే cyber incident అనేక security objectivesను ప్రభావితం చేయవచ్చు; కాబట్టి ప్రశ్నలో చెప్పిన నిర్దిష్ట ప్రభావాన్ని గుర్తించాలి.
• Ransomware dataను steal కూడా చేస్తే confidentialityపై వేరే ప్రభావం రావచ్చు.
• ఒకే cyber incident అనేక security objectivesను ప్రభావితం చేయవచ్చు; కాబట్టి ప్రశ్నలో చెప్పిన నిర్దిష్ట ప్రభావాన్ని గుర్తించాలి.
Question 20
ప్రశ్న 20
Consider the following statements:
1. A worm can propagate without attaching itself to a host program.
2. Spyware is primarily intended to gather information secretly.
3. Phishing is a form of social engineering.
4. A botnet is defined as a collection of clean backup systems used for recovery.
How many of the statements given above are correct?
1. A worm can propagate without attaching itself to a host program.
2. Spyware is primarily intended to gather information secretly.
3. Phishing is a form of social engineering.
4. A botnet is defined as a collection of clean backup systems used for recovery.
How many of the statements given above are correct?
క్రింది ప్రకటనలను పరిశీలించండి:
1. Worm host programకు attach కాకుండానే propagate అవగలదు.
2. Spyware ప్రధానంగా సమాచారాన్ని రహస్యంగా సేకరించడానికి ఉద్దేశించబడుతుంది.
3. Phishing ఒక social-engineering రూపం.
4. Botnet అంటే recovery కోసం ఉపయోగించే clean backup systems సమూహం.
పై ప్రకటనల్లో ఎన్ని సరైనవి?
1. Worm host programకు attach కాకుండానే propagate అవగలదు.
2. Spyware ప్రధానంగా సమాచారాన్ని రహస్యంగా సేకరించడానికి ఉద్దేశించబడుతుంది.
3. Phishing ఒక social-engineering రూపం.
4. Botnet అంటే recovery కోసం ఉపయోగించే clean backup systems సమూహం.
పై ప్రకటనల్లో ఎన్ని సరైనవి?
Explanation:
• Statements 1, 2 and 3 correctly describe worms, spyware and phishing.
• Statement 4 is incorrect because a botnet is a collection of compromised devices or systems under coordinated control, not a backup system.
• Therefore exactly three statements are correct.
• Statement 4 is incorrect because a botnet is a collection of compromised devices or systems under coordinated control, not a backup system.
• Therefore exactly three statements are correct.
వివరణ:
• 1, 2, 3 ప్రకటనలు worm, spyware, phishing లక్షణాలను సరిగ్గా వివరిస్తాయి.
• Botnet అనేది coordinated controlలో ఉన్న compromised devices లేదా systems సమూహం; backup system కాదు. కాబట్టి 4వ ప్రకటన తప్పు.
• అందువల్ల మూడు ప్రకటనలు మాత్రమే సరైనవి.
• Botnet అనేది coordinated controlలో ఉన్న compromised devices లేదా systems సమూహం; backup system కాదు. కాబట్టి 4వ ప్రకటన తప్పు.
• అందువల్ల మూడు ప్రకటనలు మాత్రమే సరైనవి.
Answer Key సమాధానాల పట్టిక
-
Question 1 ప్రశ్న 1Answer: A. Software or firmware intended to perform unauthorised or harmful actions that can adversely affect a system's confidentiality, integrity or availability సమాధానం: A. ఒక వ్యవస్థ గోప్యత, సమగ్రత లేదా అందుబాటుపై ప్రతికూల ప్రభావం చూపే అనుమతి లేని లేదా హానికర పనులు చేయడానికి ఉద్దేశించిన software లేదా firmware
-
Question 2 ప్రశ్న 2Answer: D. A virus typically replicates by inserting copies into host programs or files, while a worm is self-contained and can propagate without attaching to a host program సమాధానం: D. Virus సాధారణంగా host programs లేదా filesలో తన copiesను చొప్పించి విస్తరిస్తుంది; worm మాత్రం self-containedగా ఉండి host programకు attach కాకుండానే వ్యాపించగలదు
-
Question 3 ప్రశ్న 3Answer: D. A seemingly useful or benign program that contains hidden malicious functionality సమాధానం: D. ఉపయోగకరమైన లేదా harmless programలా కనిపిస్తూ లోపల దాచిన malicious functionality కలిగి ఉండే program
-
Question 4 ప్రశ్న 4Answer: A. It secretly gathers information about individuals or organisations without their knowledge సమాధానం: A. వ్యక్తులు లేదా సంస్థల సమాచారం వారికి తెలియకుండా రహస్యంగా సేకరించడం
-
Question 5 ప్రశ్న 5Answer: A. A type of malware that attempts to deny access to data or systems, commonly by encrypting data, and demands a ransom సమాధానం: A. Data లేదా systemsకు accessను నిరాకరించేందుకు ప్రయత్నించే malware; సాధారణంగా dataను encrypt చేసి ransom కోరుతుంది
-
Question 6 ప్రశ్న 6Answer: C. Social engineering is the broader use of deception to manipulate people, while phishing is a common form that uses deceptive messages or communications to induce unsafe actions or disclosure సమాధానం: C. Social engineering అనేది మనుషులను మోసంతో ప్రభావితం చేసే విస్తృత భావన; phishing అనేది deceptive messages లేదా communicationsతో unsafe actions చేయించడం లేదా sensitive information వెల్లడింపజేయడం వంటి సాధారణ రూపం
-
Question 7 ప్రశ్న 7Answer: D. It is tailored toward a specific person, role or group using more targeted context సమాధానం: D. ఒక నిర్దిష్ట వ్యక్తి, role లేదా groupను లక్ష్యంగా చేసుకుని మరింత targeted contextతో రూపొందించబడటం
-
Question 8 ప్రశ్న 8Answer: A. A collection of compromised devices or systems that can be remotely managed as a group by an attacker సమాధానం: A. Compromise అయిన devices లేదా systemsను attacker ఒక groupగా remotely manage చేయగల collection
-
Question 9 ప్రశ్న 9Answer: A. DoS aims to prevent or delay authorised access to a resource; DDoS is a denial-of-service technique involving numerous hosts or sources సమాధానం: A. DoS ఒక resourceకు authorised accessను నిరోధించడం లేదా ఆలస్యం చేయడాన్ని లక్ష్యంగా పెట్టుకుంటుంది; DDoS అనేక hosts లేదా sourcesతో జరిగే denial-of-service technique
-
Question 10 ప్రశ్న 10Answer: B. Avoid using the suspicious link and independently verify the request through a known official channel సమాధానం: B. Suspicious linkను ఉపయోగించకుండా, తెలిసిన official channel ద్వారా request నిజమా అని స్వతంత్రంగా verify చేయడం
-
Question 11 ప్రశ్న 11Answer: D. They can correct known software vulnerabilities that malicious code or attackers may otherwise exploit సమాధానం: D. Malicious code లేదా attackers ఉపయోగించగల తెలిసిన software vulnerabilitiesను సరిచేయగలవు
-
Question 12 ప్రశ్న 12Answer: A. It can help prevent, detect, contain or investigate malicious activity on devices, but no endpoint tool guarantees detection of every threat సమాధానం: A. Devicesపై malicious activityను prevent, detect, contain లేదా investigate చేయడంలో సహాయపడగలదు; కానీ ప్రతి threatను తప్పకుండా detect చేస్తుందని ఏ endpoint tool guarantee చేయదు
-
Question 13 ప్రశ్న 13Answer: A. Maintain protected offline or otherwise isolated backups of critical data and regularly test restoration సమాధానం: A. Critical dataకు protected offline లేదా ఇతర విధంగా isolated backups ఉంచి restorationను క్రమం తప్పకుండా test చేయడం
-
Question 14 ప్రశ్న 14Answer: A. A stolen password alone may be insufficient if access also requires a separate factor such as a security key or other authenticator సమాధానం: A. Accessకు security key లేదా మరో separate authenticator కూడా అవసరమైతే stolen password ఒక్కటే సరిపోకపోవచ్చు
-
Question 15 ప్రశ్న 15Answer: C. It can restrict unnecessary communication between network zones and reduce lateral movement from a compromised segment సమాధానం: C. Network zones మధ్య అవసరం లేని communicationను restrict చేసి compromised segment నుంచి lateral movementను తగ్గించగలదు
-
Question 16 ప్రశ్న 16Answer: C. Follow the organisation's incident-response process, isolate the affected device when appropriate, preserve relevant evidence and use trusted remediation or recovery procedures సమాధానం: C. Organisation incident-response processను అనుసరించి, అవసరమైనప్పుడు affected deviceను isolate చేసి, relevant evidenceను preserve చేసి trusted remediation లేదా recovery proceduresను ఉపయోగించడం
-
Question 17 ప్రశ్న 17Answer: B. Detection tools can use signatures, indicators, behaviour and telemetry to identify suspicious activity, but no single method detects every threat సమాధానం: B. Detection tools signatures, indicators, behaviour, telemetry వంటి సమాచారంతో suspicious activityను గుర్తించగలవు; కానీ ఒక్క method ప్రతి threatను detect చేయదు
-
Question 18 ప్రశ్న 18Answer: D. Do not trust the path merely because the final brand looks familiar; navigate independently through the known official service and verify the request సమాధానం: D. Final pageలో familiar brand కనిపించిందని మాత్రమే మొత్తం pathను trust చేయకుండా, known official service ద్వారా independentగా navigate చేసి requestను verify చేయడం
-
Question 19 ప్రశ్న 19Answer: C. Availability సమాధానం: C. Availability (అందుబాటు)
-
Question 20 ప్రశ్న 20Answer: D. Only three సమాధానం: D. మూడు మాత్రమే
