Which of the following malware does not require a host program/file to replicate?
(a) Virus (b) Worm (c) Trojan (d) Spyware
Assertion (A): A computer virus remains dormant until the infected file is opened/executed by the user.
Reason (R): A virus needs human triggering for replication, unlike a worm.
(a) Both A and R are true and R is the correct explanation of A.
(b) Both A and R are true but R is not the correct explanation of A.
(c) A is true but R is false.
(d) A is false but R is true.
Which malware encrypts user data and demands payment in cryptocurrency?
(a) Trojan (b) Adware (c) Ransomware (d) Keylogger
Assertion (A): HTTPS encrypts data before transmission while HTTP does not.
Reason (R): HTTPS websites require an SSL Digital Certificate.
(a) Both A and R are true and R is the correct explanation of A.
(b) Both A and R are true but R is not the correct explanation of A.
(c) A is true but R is false.
(d) A is false but R is true.
A malware that looks like legitimate software and creates backdoors is called:
(a) Worm (b) Trojan (c) Spyware (d) Adware
Which method used by antivirus executes a file in a virtual environment to observe its behaviour?
(a) Signature-based detection (b) Sandbox detection (c) Heuristics (d) Data mining
The term “cookie” in web browsing refers to:
(a) A malware (b) A small data file stored by a website on the client’s computer (c) A firewall rule (d) An encryption key
Which type of hacker hacks systems only for fun/challenge without monetary or political gains?
(a) White Hat (b) Black Hat (c) Grey Hat (d) None of these
Distributed Denial of Service (DDoS) attack uses:
(a) A single compromised computer (b) A bot-net of zombie computers (c) Only email attachments (d) Removable storage devices
Snooping is also known as:
(a) Eavesdropping (b) Sniffing (c) Phishing (d) Spoofing
A school provides internet access to students for project work. The network administrator observes frequent pop-ups, unusually slow computers, and mass emails being sent from student accounts. Students are also accessing finance server data which they are not authorised to view.
(i) Identify the possible malware types that may be causing the symptoms.
(ii) Which security device should be configured to prevent unauthorised access to the finance server?
(iii) Suggest two preventive measures the school should adopt immediately.
(iv) Name the type of attack if the slowdown is caused by a large number of illegitimate requests from multiple compromised computers worldwide.
Riya visits an e-commerce site and adds items to her cart. Later she notices targeted advertisements for similar products on other websites. She also receives an unsolicited email with an attachment claiming to be an invoice.
(i) Which chapter concept is responsible for showing targeted advertisements across websites?
(ii) What risk does the email attachment pose? Name the malware distribution method.
(iii) Which protocol should the e-commerce site use while accepting payment details and why?
(iv) Suggest one measure Riya should take to protect her sensitive information on public computers.
Case 1: (i) Virus/Worm/Adware/Keylogger (ii) Firewall (iii) Update antivirus, configure firewall rules, avoid unknown downloads (iv) DDoS
Case 2: (i) Third-party cookies (ii) Trojan/malware via spam email (iii) HTTPS – encrypts sensitive data (iv) Use virtual keyboard, avoid public Wi-Fi for banking, scan devices.
All questions are answerable from the NCERT chapter text. Reviewed by GFIS faculty.