ExamShortcut
high importanceโšก 9 shortcuts4 subtopics

Malware families (virus, worm, trojan, ransomware), social-engineering attacks (phishing and cousins), preventive measures, and IT Act 2000 sections with CERT-In. Statement-based malware questions appear in nearly every CKT shift.

Track record in the exam

Test difficulty mix (69 questions)

21 easy36 medium12 hard

Question patterns exams keep repeating

Taken from previous-year papers. If a pattern is marked "very common", expect to see it in your exam.

Malware identification

very common
Spot it:

'A program that replicates itself is ___', 'which malware disguises as useful software', 'files locked for ransom' โ€” behaviour described, malware named.

How to solve: Match the behaviour: needs a host file = virus; self-replicates alone = worm; disguised as useful software, no replication = trojan; locks files for money = ransomware; spies = spyware; records keystrokes = keylogger; shows ads = adware; army of zombie machines = botnet. The plant swaps virus and worm โ€” check who needs the host.

Example: Which type of malware spreads on its own through a network without a host file?

Worm โ€” viruses ride on host files; worms crawl the network independently.

Learn this in โ€œMalware typesโ€ โ†’

Phishing-family matching

very common
Spot it:

A fraud scenario by e-mail, phone call, SMS, or a correct URL landing on a fake site โ€” the attack's name is asked; 'full form / meaning of vishing, smishing'.

How to solve: Follow the channel: e-mail/fake site = phishing; phone call = vishing; SMS = smishing; correct address, fake destination = pharming; aimed at one chosen victim = spear phishing. All of them are social engineering โ€” attacking the person, and the fix is never sharing OTP/PIN.

Example: An SMS claiming your account will be blocked asks you to open a link and enter your bank password. This is:

Smishing โ€” phishing delivered by SMS; the link leads to a credential-stealing fake.

Learn this in โ€œCyber attacks and social engineeringโ€ โ†’

Preventive-measure odd-one-out

common
Spot it:

'Which of these is NOT a security measure', 'which measure protects against ransomware', lists where one protection role is swapped (firewall cleaning viruses, antivirus filtering traffic).

How to solve: Fix the roles: firewall = filters network traffic by rules at the doorway; antivirus = scans and removes malware inside (needs updates); encryption = scrambles data (plaintext to ciphertext, AES, https padlock); 2FA = password + OTP/biometric; backups = the ransomware antidote. The plant: crediting the firewall with cleaning infections.

Example: Which of the following does a firewall do?

Filters incoming and outgoing network traffic by rules โ€” it does not scan or clean files inside.

Learn this in โ€œPreventive measures and security toolsโ€ โ†’

IT Act sections and authorities

common
Spot it:

'Hacking is punished under which section', 'identity theft section', 'which section was struck down', 'CERT-In works under ___', 'the IT Act was enacted in ___'.

How to solve: Memorise the ladder: 43 unauthorised access, 65 source code, 66 hacking, 66C identity theft, 66D online cheating, 67 obscenity, 72 privacy; 66A struck down in 2015 (Shreya Singhal). Act = 2000 (from 17 Oct, UNCITRAL-based, amended 2008). CERT-In under MeitY; NCIIPC guards critical infrastructure; helpline 1930.

Example: Identity theft (misusing another's password or digital signature) is an offence under which section of the IT Act?

Section 66C โ€” added by the 2008 amendment.

Learn this in โ€œIT Act 2000, offences and authoritiesโ€ โ†’

Attack-mechanism statements

common
Spot it:

'Which statement about a salami attack / logic bomb / DoS is true', a scenario (tiny thefts, waiting code, flooded server, hidden listener) matched to its attack name.

How to solve: Anchor the classics: salami = many tiny thefts; data diddling = records changed at entry; logic bomb = code that waits for a trigger; SQL injection = commands typed into a form; DoS/DDoS = flooding (DDoS from many machines); MITM = secretly reading between two parties, typical on open Wi-Fi.

Example: A malicious program lies dormant in a bank's system until 1 April and then deletes all records. This is a:

Logic bomb โ€” malware waiting for a trigger event before it detonates.

Learn this in โ€œCyber attacks and social engineeringโ€ โ†’

Encryption and password basics

common
Spot it:

'Scrambled data is called ___', 'https/padlock means ___', 'AES full form', 'strongest password' and 2FA meaning.

How to solve: Plaintext = readable, ciphertext = scrambled; decryption needs the key; AES = Advanced Encryption Standard; https + padlock = encrypted connection (TLS/SSL). Strong password = long, mixed characters, not personal; 2FA = password plus a second proof so a stolen password alone fails.

Example: The padlock icon next to https:// in a browser indicates:

The connection to that site is encrypted โ€” data travels as unreadable ciphertext.

Learn this in โ€œPreventive measures and security toolsโ€ โ†’

Your next step

New here? Start with subtopic 1 in Learn. Revision mode? Jump straight to the test and let it tell you what to fix.