Cyber Security
๐ Log in to trackMalware families (virus, worm, trojan, ransomware), social-engineering attacks (phishing and cousins), preventive measures, and IT Act 2000 sections with CERT-In. Statement-based malware questions appear in nearly every CKT shift.
One page per subtopic: detailed notes, every question type, formulas, tricks and practice sets.
Every formula on one printable page, grouped by subtopic.
4 exam-level questions worked step by step.
69 questions โ untimed practice or a timed test with analysis.
Track record in the exam
Test difficulty mix (69 questions)
Question patterns exams keep repeating
Taken from previous-year papers. If a pattern is marked "very common", expect to see it in your exam.
Malware identification
very common'A program that replicates itself is ___', 'which malware disguises as useful software', 'files locked for ransom' โ behaviour described, malware named.
How to solve: Match the behaviour: needs a host file = virus; self-replicates alone = worm; disguised as useful software, no replication = trojan; locks files for money = ransomware; spies = spyware; records keystrokes = keylogger; shows ads = adware; army of zombie machines = botnet. The plant swaps virus and worm โ check who needs the host.
Example: Which type of malware spreads on its own through a network without a host file?
Worm โ viruses ride on host files; worms crawl the network independently.
Phishing-family matching
very commonA fraud scenario by e-mail, phone call, SMS, or a correct URL landing on a fake site โ the attack's name is asked; 'full form / meaning of vishing, smishing'.
How to solve: Follow the channel: e-mail/fake site = phishing; phone call = vishing; SMS = smishing; correct address, fake destination = pharming; aimed at one chosen victim = spear phishing. All of them are social engineering โ attacking the person, and the fix is never sharing OTP/PIN.
Example: An SMS claiming your account will be blocked asks you to open a link and enter your bank password. This is:
Smishing โ phishing delivered by SMS; the link leads to a credential-stealing fake.
Preventive-measure odd-one-out
common'Which of these is NOT a security measure', 'which measure protects against ransomware', lists where one protection role is swapped (firewall cleaning viruses, antivirus filtering traffic).
How to solve: Fix the roles: firewall = filters network traffic by rules at the doorway; antivirus = scans and removes malware inside (needs updates); encryption = scrambles data (plaintext to ciphertext, AES, https padlock); 2FA = password + OTP/biometric; backups = the ransomware antidote. The plant: crediting the firewall with cleaning infections.
Example: Which of the following does a firewall do?
Filters incoming and outgoing network traffic by rules โ it does not scan or clean files inside.
IT Act sections and authorities
common'Hacking is punished under which section', 'identity theft section', 'which section was struck down', 'CERT-In works under ___', 'the IT Act was enacted in ___'.
How to solve: Memorise the ladder: 43 unauthorised access, 65 source code, 66 hacking, 66C identity theft, 66D online cheating, 67 obscenity, 72 privacy; 66A struck down in 2015 (Shreya Singhal). Act = 2000 (from 17 Oct, UNCITRAL-based, amended 2008). CERT-In under MeitY; NCIIPC guards critical infrastructure; helpline 1930.
Example: Identity theft (misusing another's password or digital signature) is an offence under which section of the IT Act?
Section 66C โ added by the 2008 amendment.
Attack-mechanism statements
common'Which statement about a salami attack / logic bomb / DoS is true', a scenario (tiny thefts, waiting code, flooded server, hidden listener) matched to its attack name.
How to solve: Anchor the classics: salami = many tiny thefts; data diddling = records changed at entry; logic bomb = code that waits for a trigger; SQL injection = commands typed into a form; DoS/DDoS = flooding (DDoS from many machines); MITM = secretly reading between two parties, typical on open Wi-Fi.
Example: A malicious program lies dormant in a bank's system until 1 April and then deletes all records. This is a:
Logic bomb โ malware waiting for a trigger event before it detonates.
Encryption and password basics
common'Scrambled data is called ___', 'https/padlock means ___', 'AES full form', 'strongest password' and 2FA meaning.
How to solve: Plaintext = readable, ciphertext = scrambled; decryption needs the key; AES = Advanced Encryption Standard; https + padlock = encrypted connection (TLS/SSL). Strong password = long, mixed characters, not personal; 2FA = password plus a second proof so a stolen password alone fails.
Example: The padlock icon next to https:// in a browser indicates:
The connection to that site is encrypted โ data travels as unreadable ciphertext.