4061 Cybersecurity and Data Protection • Access Security कर्मचारी को केवल उसके कार्य के लिए आवश्यक न्यूनतम पहुँच-अधिकार देना किस सिद्धांत का उदाहरण है? Giving an employee only the minimum access permissions needed for assigned work follows which principle? A. Unlimited Access Unlimited Access B. Public Sharing Public Sharing C. Password Reuse Password Reuse D. Least Privilege Least Privilege उत्तर और व्याख्या देखें Show answer and explanation सही उत्तर: D Correct Answer: D Least Privilege उपयोगकर्ता या प्रक्रिया के अधिकार आवश्यक सीमा तक रखता है। इससे अनावश्यक पहुँच और उसके दुरुपयोग का जोखिम कम होता है। Least privilege limits user or process permissions to what is necessary, reducing unnecessary access and the risk of misuse.
4062 Cybersecurity and Data Protection • Access Security कार्यालय में थोड़ी देर के लिए कंप्यूटर छोड़ते समय खुले कार्य को बंद किए बिना अनधिकृत उपयोग रोकने का उचित तरीका क्या है? What is an appropriate way to prevent unauthorized use when briefly leaving an office computer without closing open work? A. केवल स्क्रीन की चमक कम करना Only reduce screen brightness B. कंप्यूटर का सत्र लॉक करना Lock the computer session C. केवल माउस हटाना Only disconnect the mouse D. पासवर्ड स्क्रीन के पास लिख देना Write the password beside the screen उत्तर और व्याख्या देखें Show answer and explanation सही उत्तर: B Correct Answer: B सत्र लॉक करने पर दोबारा उपयोग के लिए प्रमाणीकरण आवश्यक होता है। केवल मॉनिटर बंद करना या चमक घटाना सत्र को लॉक नहीं करता। Locking the session requires authentication to resume use. Turning off the monitor or reducing brightness does not lock the session.
4063 Cybersecurity and Data Protection • Access Security किसी वेबसाइट पर HTTPS होना किस बात की गारंटी नहीं देता? What does HTTPS on a website not guarantee? A. वेबसाइट का संचालक ईमानदार है और उसकी हर सामग्री विश्वसनीय है। The website operator is honest and all its content is trustworthy. B. सही TLS कनेक्शन में संचार एन्क्रिप्ट किया जाता है। Communication is encrypted in a correctly established TLS connection. C. सही TLS कनेक्शन संचार की अखंडता की रक्षा करता है। A correctly established TLS connection protects communication integrity. D. ब्राउज़र HTTPS के लिए TLS का उपयोग कर सकता है। A browser can use TLS for HTTPS. उत्तर और व्याख्या देखें Show answer and explanation सही उत्तर: A Correct Answer: A HTTPS कनेक्शन की सुरक्षा देता है, वेबसाइट के व्यावसायिक दावों की सत्यता का प्रमाण नहीं। धोखाधड़ी वाली वेबसाइटें भी HTTPS इस्तेमाल कर सकती हैं। HTTPS protects the connection; it does not certify the truth of business claims. Fraudulent websites can also use HTTPS.
4064 Cybersecurity and Data Protection • Data Protection एंटीवायरस द्वारा किसी संदिग्ध फ़ाइल को Quarantine करने का मुख्य उद्देश्य क्या है? What is the main purpose of quarantining a suspicious file through antivirus software? A. उसे सभी संपर्कों को भेजना To send it to all contacts B. उसे अनिवार्य रूप से सुरक्षित घोषित करना To necessarily declare it safe C. उसे अलग रखकर सामान्य रूप से चलने या नुकसान पहुँचाने से रोकना To isolate it and prevent normal execution or harm D. उसे अपने आप अधिक अधिकार देना To automatically grant it more privileges उत्तर और व्याख्या देखें Show answer and explanation सही उत्तर: C Correct Answer: C Quarantine संदिग्ध फ़ाइल को अलग और नियंत्रित स्थिति में रखता है। यह उस फ़ाइल को बिना जाँच फिर चलाने की अनुमति नहीं है। Quarantine isolates a suspicious file under controlled conditions. It is not an instruction to run the file again without verification.
4065 Cybersecurity and Data Protection • Data Protection रैनसमवेयर से सुरक्षा की दृष्टि से एक बैकअप प्रति ऑफलाइन रखने का प्रमुख लाभ क्या है? What is a major ransomware-related benefit of keeping one backup copy offline? A. इससे कंप्यूटर में कभी मालवेयर नहीं आ सकता। It makes malware infection impossible. B. नेटवर्क से पहुँचा जा सकने वाला रैनसमवेयर उस अलग प्रति तक सीधे नहीं पहुँच सकता। Ransomware spreading through network access cannot directly reach that disconnected copy. C. इससे सभी पासवर्ड स्वतः बदल जाते हैं। It automatically changes all passwords. D. इससे बैकअप की जाँच की जरूरत समाप्त हो जाती है। It eliminates the need to test backups. उत्तर और व्याख्या देखें Show answer and explanation सही उत्तर: B Correct Answer: B डिस्कनेक्टेड बैकअप ऑनलाइन संक्रमण से अलग रहता है। उसकी सुरक्षा, स्वच्छता और पुनर्स्थापना की क्षमता फिर भी जाँचना आवश्यक है। A disconnected backup is separated from online infection paths. Its security, cleanliness and restorability still need verification.
4066 Cybersecurity and Data Protection • Data Protection बैकअप फ़ाइलें बन जाने के बाद समय-समय पर Restore Test क्यों करना चाहिए? Why should restoration tests be performed periodically after backup files have been created? A. बैकअप का नाम छोटा करने के लिए To shorten backup filenames B. सभी मूल फ़ाइलें तुरंत हटाने के लिए To immediately delete all original files C. इंटरनेट की गति बढ़ाने के लिए To increase internet speed D. यह सुनिश्चित करने के लिए कि आवश्यक डेटा वास्तव में वापस प्राप्त किया जा सकता है To verify that the required data can actually be recovered उत्तर और व्याख्या देखें Show answer and explanation सही उत्तर: D Correct Answer: D केवल बैकअप बनना पर्याप्त नहीं है। Restore Test खराब, अधूरे या अनुपयोगी बैकअप का पता लगाने में मदद करता है। Creating a backup alone is insufficient. A restoration test helps identify corrupt, incomplete or unusable backups.
4067 Cybersecurity and Data Protection • Data Protection गोपनीय फ़ाइल चोरी होने पर बिना उचित कुंजी उसकी सामग्री पढ़ना कठिन बनाने के लिए कौन-सा उपाय सबसे सीधे उपयोगी है? Which measure most directly makes a stolen confidential file difficult to read without the appropriate key? A. फ़ाइल का नाम बदलना Renaming the file B. फ़ाइल को दूसरे फ़ोल्डर में रखना Moving the file to another folder C. फ़ाइल का एन्क्रिप्शन Encrypting the file D. फ़ाइल के नाम में SECRET लिखना Adding SECRET to the filename उत्तर और व्याख्या देखें Show answer and explanation सही उत्तर: C Correct Answer: C एन्क्रिप्शन डेटा को ऐसे रूप में बदलता है जिसे पढ़ने के लिए उपयुक्त कुंजी चाहिए। नाम बदलना या सामान्य Hidden प्रॉपर्टी समान सुरक्षा नहीं देती। Encryption transforms data so that the appropriate key is needed to read it. Renaming a file or marking it hidden does not provide equivalent protection.
4068 Cybersecurity and Data Protection • Data Protection डाउनलोड की गई फ़ाइल का क्रिप्टोग्राफिक Hash विश्वसनीय स्रोत के प्रकाशित Hash से मिलाने का मुख्य उद्देश्य क्या है? What is the main purpose of comparing a downloaded file cryptographic hash with a hash published by a trusted source? A. फ़ाइल की अखंडता जाँचना To check file integrity B. फ़ाइल की भाषा बदलना To change the file language C. फ़ाइल को स्वतः एन्क्रिप्ट करना To automatically encrypt the file D. फ़ाइल की सामग्री पढ़े बिना उसका सारांश बनाना To summarize the file without reading its content उत्तर और व्याख्या देखें Show answer and explanation सही उत्तर: A Correct Answer: A Hash की तुलना फ़ाइल में बदलाव या भ्रष्टाचार पहचानने में सहायता करती है। Hash मिलना अपने आप यह प्रमाण नहीं है कि मूल फ़ाइल मालवेयर-मुक्त है। Hash comparison helps detect alteration or corruption. A matching hash alone does not prove that the original file is malware-free.
4069 Cybersecurity and Data Protection • Data Protection कार्यालय के कंप्यूटर पर फ़ाइलें अचानक एन्क्रिप्ट होने लगती हैं और फिरौती का संदेश आता है। संक्रमण फैलने से रोकने की उचित प्रारंभिक कार्रवाई क्या है? Files on an office computer suddenly become encrypted and a ransom message appears. What is an appropriate initial action to limit spread? A. उसे सभी साझा ड्राइवों से जोड़ देना Connect it to all shared drives B. विश्वसनीय बैकअप ड्राइव तुरंत संक्रमित कंप्यूटर में लगा देना Immediately attach a trusted backup drive to the infected computer C. संदेश अनदेखा करके नेटवर्क पर काम जारी रखना Ignore the message and continue network activity D. प्रभावित कंप्यूटर को नेटवर्क से अलग करके अधिकृत IT टीम को सूचित करना Isolate the affected computer from the network and notify the authorized IT team उत्तर और व्याख्या देखें Show answer and explanation सही उत्तर: D Correct Answer: D नेटवर्क से अलग करना फैलाव सीमित करने में मदद करता है। अधिकृत टीम को सूचित करें और बिना निर्देश बैकअप जोड़ने या साक्ष्य मिटाने से बचें। Network isolation helps limit spread. Notify the authorized team and avoid connecting backups or erasing evidence without guidance.
4070 Cybersecurity and Data Protection • Data Protection गोपनीय डेटा वाला पुराना स्टोरेज उपकरण किसी अन्य व्यक्ति को देने से पहले कौन-सा उपाय सबसे उपयुक्त है? What is the most appropriate measure before transferring an old storage device containing confidential data to another person? A. केवल फ़ाइलों के नाम बदलना Only rename the files B. उपकरण और डेटा की संवेदनशीलता के अनुसार अनुमोदित डेटा सैनिटाइजेशन करना और सत्यापित करना Perform and verify approved data sanitization appropriate to the device and data sensitivity C. केवल डेस्कटॉप शॉर्टकट हटाना Only delete desktop shortcuts D. सिर्फ फ़ोल्डर को Hidden करना Only mark the folder as hidden उत्तर और व्याख्या देखें Show answer and explanation सही उत्तर: B Correct Answer: B सामान्य Delete या शॉर्टकट हटाना सुरक्षित डेटा-निष्कासन की गारंटी नहीं है। उपयुक्त सैनिटाइजेशन प्रक्रिया और उसका सत्यापन आवश्यक है। Ordinary deletion or removing shortcuts does not guarantee secure data removal. An appropriate sanitization process and verification are required.