Cybersecurity and Data Protection
Cybersecurity protects computers, mobile devices, networks, applications and data from unauthorised access, loss, fraud and disruption. Security is not limited to installing antivirus software; it combines technology, processes and safe user behaviour.
Scope: This material covers the Computer Awareness level of general recruitment examinations. It combines exam-relevant concepts with practical precautions for online applications and digital payments.
1. Cybersecurity and the CIA Triad
The three fundamental information-security objectives are collectively called the CIA Triad:
| Element | Meaning | Example |
| Confidentiality | Information is visible only to authorised people. | Only an employee and authorised officers can view salary details. |
| Integrity | Information remains accurate and is not altered without authority. | Examination marks cannot be changed without authorisation. |
| Availability | Services and data remain available to authorised users when needed. | An application portal remains available on the closing date. |
An attack can affect more than one objective. Ransomware can make files unavailable and may also compromise confidentiality by stealing data.
2. Threats, Vulnerabilities, Risks and Attacks
| Term | Simple meaning |
| Asset | A valuable resource to protect, such as data or a server. |
| Threat | A potential source or circumstance capable of causing harm. |
| Vulnerability | A weakness that can be exploited. |
| Exploit | A method or code that takes advantage of a weakness. |
| Risk | Potential harm from a threat exploiting a vulnerability. |
| Attack | An actual attempt to affect a system or its data. |
Example: A security flaw in outdated software is a vulnerability. A criminal capable of exploiting it is a threat actor. Using the flaw to gain entry is an attack.
A patch is an update that can correct a software error or security vulnerability. Regular updates reduce risk but do not make a system completely risk-free.
3. Malware and Its Main Types
Malware means malicious software. It is software intended to cause damage, conduct espionage, gain unauthorised control or steal information.
| Type | Main identification |
| Virus | Attaches to a host file or program and generally spreads or activates when that host runs. |
| Worm | Can replicate and spread across a network without requiring attachment to a host file. |
| Trojan Horse | Appears useful or legitimate while performing harmful actions; self-replication is not essential to its definition. |
| Ransomware | Blocks access to data or systems and demands payment; some attacks also steal data. |
| Spyware | Secretly monitors a user's activity or information. |
| Adware | Displays unwanted advertising; some adware also performs tracking. |
| Rootkit | Can conceal unauthorised access and maintain elevated privileges. |
| Bot | Can make an infected device act according to remote instructions. |
Exam distinction: Not every form of malware is a virus. A virus generally requires a host, while a worm can spread independently. A Trojan is named for its deceptive appearance.
4. Botnets, Keyloggers and Logic Bombs
- Botnet: A group of infected devices controlled by an attacker. It can be used for spam, DDoS and other attacks.
- Keylogger: Hardware or software that records keyboard input; malicious use can steal passwords.
- Logic Bomb: Harmful code activated when a specified condition or time is reached.
- Backdoor: A concealed route that bypasses normal authentication.
DDoS stands for Distributed Denial of Service. It disrupts availability by directing excessive traffic or requests from multiple sources towards a service.
5. Social Engineering and Phishing
Social engineering exploits human trust, fear, greed or urgency—alone or alongside technical weaknesses—to obtain information or induce an action.
| Type | Identification |
| Phishing | Using deceptive email, messages or websites to obtain information or actions. |
| Spear Phishing | Phishing tailored to a particular person or organisation. |
| Whaling | Phishing focused on high-value targets such as senior executives. |
| Smishing | Phishing through SMS or text messages. |
| Vishing | Phishing or fraud through voice calls. |
| Pretexting | Using an invented role or story to obtain information. |
| Shoulder Surfing | Observing a screen or keyboard to obtain confidential information. |
Phishing indicators: An unusual sender address, pressure to act immediately, requests for an OTP or password, suspicious attachments, an incorrect domain or an offer that appears too attractive.
Important: Good grammar or HTTPS does not prove that a message is genuine. Open the organisation's official website or application independently instead of following an unexpected link.
6. Passwords, Passphrases and Password Managers
- Use a different password for every important account.
- Prefer a long, difficult-to-guess password or passphrase.
- Avoid names, birth dates, phone numbers and common sequences.
- Do not disclose passwords through email, chat or telephone calls.
- Change a password after a data breach or suspicious account activity.
A password manager can help create and securely store separate strong passwords. Protect it with a strong master password and available MFA.
Precise understanding: Adding uppercase letters, numbers and symbols does not make a short, predictable password secure. Length, uniqueness and changing a password after compromise matter more than unnecessary frequent changes.
7. Authentication, Authorization and MFA
| Concept | Meaning |
| Identification | A user states an identity, such as a username. |
| Authentication | Verifies the claimed identity. |
| Authorization | Determines which resources or actions the authenticated user may access. |
Authentication factors:
- Something you know: A password or PIN.
- Something you have: A security token or registered device.
- Something you are: A fingerprint or another biometric.
MFA means Multi-Factor Authentication. It uses two or more different factor types. A password and PIN are both “something you know,” so they alone do not create genuine two-factor authentication.
An OTP is a code valid for limited time or one use. Never disclose it. Do not approve an unexpected MFA prompt when you did not initiate a login.
8. Encryption, Encoding and Hashing
| Process | Main purpose | Can the original be recovered? |
| Encryption | Makes data confidential using a key. | Decryption is possible with the correct key. |
| Encoding | Represents data in a compatible format. | Generally reversible without a secret key. |
| Hashing | Produces a fixed-size digest for purposes such as integrity and password verification. | Designed as one-way; there is no ordinary decryption. |
Plaintext is the original readable data; ciphertext is its encrypted form.
- Symmetric Encryption: Uses the same shared secret key for encryption and decryption.
- Asymmetric Encryption: Uses a related pair of public and private keys.
Exam trap: Encoding such as Base64 is not encryption. “Decrypting a hash” is not the normal concept. Weak or unsalted password hashes can still be vulnerable to attacks.
9. Digital Signatures and Digital Certificates
A digital signature is generally created using the signer's private key and verified using the corresponding public key. It helps with:
- Checking the integrity of a message or document.
- Authenticating the signer.
- Reducing the risk of repudiation in a suitable system.
A digital signature's primary purpose is not to make the message confidential. Encryption may be required for confidentiality.
A digital certificate associates an identity or domain with a public key. A Certificate Authority has a role in issuing and validating certificates.
An electronic signature is a broader concept. Not every signature made electronically is a cryptographic digital signature.
10. Firewalls, Antivirus and Other Security Tools
| Tool | Main function |
| Firewall | Allows or blocks network traffic according to defined rules. |
| Antivirus/Anti-malware | Helps detect, prevent or remove malware using known-pattern and behaviour-based techniques. |
| IDS | Intrusion Detection System; detects suspicious activity and produces alerts. |
| IPS | Intrusion Prevention System; detects suspicious activity and attempts to block it. |
| VPN | Provides a protected logical tunnel over an untrusted network. |
Limitations: A firewall does not stop every form of malware, antivirus does not detect every new threat, and a VPN does not make a user completely anonymous. Layered security is required.
11. Backups and Ransomware Protection
A backup is a separate, recoverable copy of data. Its purpose is to restore data after the original is lost or damaged.
| Type | Main identification |
| Full Backup | A copy of all selected data. |
| Incremental Backup | Changes made since the previous backup. |
| Differential Backup | Changes made since the previous full backup. |
3-2-1 Rule: A common strategy of maintaining 3 copies of important data, on 2 different media types, with at least 1 copy off-site or otherwise isolated.
- Regular, automated backups reduce the risk of forgetting them.
- Keep at least one backup from remaining continuously connected to the main system.
- Test restoration to confirm that the backup is usable.
Important distinction: Synchronisation and backup are not the same. A mistakenly deleted or encrypted file can also be changed at synchronised locations.
12. Safe Browsing, Downloads and Wi-Fi
- Carefully examine the spelling of URLs and domains.
- Obtain software from trusted official sources.
- Keep operating systems, browsers and applications updated.
- Do not connect an unknown USB device without appropriate checks.
- Do not save passwords on a public computer.
- Log out after using a shared device.
Public Wi-Fi: Mobile data or a trusted network may be preferable for sensitive work. Beware of fake hotspot names. HTTPS is useful but does not prove that a suspicious site is genuine.
QR codes: Verify the source and inspect the destination URL. A QR code can conceal a malicious link.
13. Data Protection and Privacy
- Personal Data: Information relating to an identified or identifiable person.
- Data Minimisation: Collecting only the data necessary for the stated purpose.
- Least Privilege: Giving users only the minimum permissions needed for their work.
- Access Control: Determining who can view or change particular data.
- Data Retention: Determining how long information will be retained.
- Secure Disposal: Safely disposing of data and media when no longer needed.
Example: Allowing an attendance operator to record attendance without permission to modify payroll illustrates least privilege.
Emptying the Recycle Bin does not guarantee that a file is permanently unrecoverable. Highly sensitive media can require suitable secure-erasure or physical-destruction procedures.
14. Immediate Action After Cyber Fraud
- Stop suspicious contact and make no further payment when safe to do so.
- Immediately notify the bank or payment service about financial fraud.
- In India, complaints can be registered at the National Cyber Crime Reporting Portal: cybercrime.gov.in.
- For financial cyber fraud, verify the current helpline and instructions on the official portal.
- Preserve evidence such as screenshots, transaction IDs, telephone numbers, URLs and messages.
- Change the affected account's password using a clean, trusted device and review active sessions.
Evidence caution: Advice from an appropriate expert or authority may be needed before deleting suspicious messages or formatting a device. Do not attempt to hack the attacker or take unauthorised action.
15. Quick Revision
- CIA means Confidentiality, Integrity and Availability.
- A virus attaches to a host; a worm can spread independently.
- A Trojan can disguise itself as legitimate software.
- Smishing uses SMS; vishing uses voice calls.
- Authentication verifies identity; authorization determines permissions.
- Encryption can be decrypted; hashing is designed as a one-way process.
- Digital signatures help verify integrity and authenticity.
- Firewalls, antivirus, updates and backups form parts of layered security.
16. Practice Questions
These are original practice questions, not verified previous-year questions. Each question has one correct answer.
Question 1. Preventing unauthorised modification of examination marks primarily protects which security objective?
A. Availability
B. Integrity
C. Compression
D. Portability
View answer and explanation
Correct answer: B. Integrity
Integrity keeps data accurate and protects it from unauthorised changes.
Question 2. Which malware can spread across a network independently without attaching to a host file?
A. Worm
B. Trojan Horse
C. Adware
D. Logic Bomb
View answer and explanation
Correct answer: A. Worm
A worm can replicate and spread independently, while a virus generally attaches to a host.
Question 3. What is a harmful program disguised as useful software called?
A. Firewall
B. Patch
C. Trojan Horse
D. Backup
View answer and explanation
Correct answer: C. Trojan Horse
A Trojan appears legitimate or useful while performing harmful actions.
Question 4. What is phishing conducted through SMS called?
A. Whaling
B. Vishing
C. Pharming
D. Smishing
View answer and explanation
Correct answer: D. Smishing
Smishing is SMS or text-message phishing. Voice-call phishing is called vishing.
Question 5. What determines which files an authenticated user is permitted to modify?
A. Authentication
B. Authorization
C. Identification
D. Encoding
View answer and explanation
Correct answer: B. Authorization
Authentication verifies identity; authorization determines permitted actions.
Question 6. Which is an example of genuine multi-factor authentication?
A. Password and PIN
B. Two different passwords
C. Password and security token
D. PIN and security question
View answer and explanation
Correct answer: C. Password and security token
A password is something you know; a token is something you have. They are different factors.
Question 7. Which process creates a fixed-size, one-way digest of data?
A. Hashing
B. Decryption
C. Compression
D. Formatting
View answer and explanation
Correct answer: A. Hashing
Hashing is designed as a one-way process and can support integrity checks and password verification.
Question 8. Which key is generally used to create a digital signature?
A. The recipient's password
B. The signer's private key
C. Only a public key
D. Any OTP
View answer and explanation
Correct answer: B. The signer's private key
A signature is created with the signer's private key and verified using the corresponding public key.
Question 9. Which tool allows or blocks network traffic according to defined rules?
A. Compiler
B. Defragmenter
C. Firewall
D. Spreadsheet
View answer and explanation
Correct answer: C. Firewall
A firewall filters network traffic according to security rules.
Question 10. What does an incremental backup normally contain?
A. All selected data every time
B. Only the oldest file
C. All changes since the last full backup every time
D. Changes since the previous backup
View answer and explanation
Correct answer: D. Changes since the previous backup
An incremental backup stores changes made since the preceding backup of any type.
Question 11. Giving an employee only the permissions necessary for their work illustrates which principle?
A. Least Privilege
B. Open Access
C. Data Duplication
D. Full Control
View answer and explanation
Correct answer: A. Least Privilege
Least privilege reduces security risk by restricting unnecessary permissions.
Question 12. Which measure is most useful for preparing to recover from ransomware?
A. Only renaming files
B. Keeping every backup continuously connected to the same system
C. Maintaining regular, separate and restore-tested backups
D. Clearing browser history
View answer and explanation
Correct answer: C. Maintaining regular, separate and restore-tested backups
A separately maintained backup that has been successfully tested for restoration is important for recovery.
साइबर सुरक्षा और डेटा संरक्षण
साइबर सुरक्षा का उद्देश्य कंप्यूटर, मोबाइल, नेटवर्क, एप्लिकेशन और डेटा को अनधिकृत पहुँच, हानि, धोखाधड़ी तथा व्यवधान से सुरक्षित रखना है। सुरक्षा केवल Antivirus स्थापित करने तक सीमित नहीं है; इसमें तकनीक, प्रक्रियाएँ और उपयोगकर्ता का सुरक्षित व्यवहार तीनों शामिल हैं।
अध्याय का दायरा: यह सामग्री सामान्य नौकरी-संबंधी प्रतियोगी परीक्षाओं के Computer Awareness स्तर पर आधारित है। इसमें परीक्षा-उपयोगी अवधारणाओं के साथ ऑनलाइन आवेदन और डिजिटल भुगतान से जुड़ी व्यावहारिक सावधानियाँ भी शामिल हैं।
1. Cybersecurity और CIA Triad
सूचना सुरक्षा के तीन आधारभूत उद्देश्य सामूहिक रूप से CIA Triad कहलाते हैं:
| तत्व | अर्थ | उदाहरण |
| Confidentiality | जानकारी केवल अधिकृत व्यक्ति देख सके। | वेतन विवरण केवल संबंधित कर्मचारी और अधिकृत अधिकारी देखें। |
| Integrity | जानकारी अनधिकृत रूप से बदली न जाए और सही बनी रहे। | परीक्षा के अंक बिना अधिकार परिवर्तित न हों। |
| Availability | अधिकृत उपयोगकर्ता को आवश्यकता के समय सेवा या डेटा उपलब्ध हो। | आवेदन की अंतिम तिथि पर पोर्टल उपलब्ध रहे। |
किसी हमले से एक से अधिक उद्देश्य प्रभावित हो सकते हैं। उदाहरणतः Ransomware फाइलें अनुपलब्ध कर सकता है और डेटा चुराकर Confidentiality भी प्रभावित कर सकता है।
2. Threat, Vulnerability, Risk और Attack
| शब्द | सरल अर्थ |
| Asset | सुरक्षित किया जाने वाला मूल्यवान संसाधन, जैसे डेटा या Server। |
| Threat | नुकसान पहुँचाने की संभावित परिस्थिति या स्रोत। |
| Vulnerability | ऐसी कमजोरी जिसका दुरुपयोग हो सकता है। |
| Exploit | कमजोरी का लाभ उठाने वाली विधि या Code। |
| Risk | Threat द्वारा Vulnerability का लाभ उठाने से संभावित हानि। |
| Attack | सिस्टम या डेटा को प्रभावित करने का वास्तविक प्रयास। |
उदाहरण: पुराने Software की सुरक्षा कमजोरी Vulnerability है। उसका लाभ उठाने वाला अपराधी Threat Actor है। कमजोरी का उपयोग कर प्रवेश करना Attack है।
Patch Software की त्रुटि या सुरक्षा कमजोरी ठीक करने वाला Update हो सकता है। नियमित Update Risk कम करता है, लेकिन किसी सिस्टम को पूर्णतः जोखिम-मुक्त नहीं बनाता।
3. Malware और उसके प्रमुख प्रकार
Malware का अर्थ Malicious Software है। यह नुकसान पहुँचाने, जासूसी करने, अनधिकृत नियंत्रण प्राप्त करने या डेटा चुराने के उद्देश्य वाला Software है।
| प्रकार | मुख्य पहचान |
| Virus | Host File या Program से जुड़ता है और सामान्यतः उसे चलाए जाने पर फैलता या सक्रिय होता है। |
| Worm | स्वयं की प्रतिलिपि बनाकर Network में फैल सकता है; Host File से जुड़ना आवश्यक नहीं। |
| Trojan Horse | उपयोगी या वैध Software जैसा दिखकर हानिकारक कार्य करता है; स्वयं की प्रतिलिपि बनाना इसकी अनिवार्य पहचान नहीं। |
| Ransomware | डेटा या सिस्टम की पहुँच रोककर फिरौती माँगता है; कई मामलों में डेटा चोरी भी हो सकती है। |
| Spyware | उपयोगकर्ता की गतिविधि या जानकारी की गुप्त निगरानी करता है। |
| Adware | अनचाहे विज्ञापन दिखाता है; कुछ Adware Tracking भी कर सकते हैं। |
| Rootkit | अनधिकृत पहुँच छिपाने और उच्च अधिकार बनाए रखने में सहायता कर सकता है। |
| Bot | संक्रमित Device को दूरस्थ आदेशों के अनुसार कार्य करा सकता है। |
परीक्षा में अंतर: प्रत्येक Malware Virus नहीं होता। Virus को सामान्यतः Host की आवश्यकता होती है, जबकि Worm स्वतंत्र रूप से फैल सकता है। Trojan का नाम उसके भ्रामक रूप से संबंधित है।
4. Botnet, Keylogger और Logic Bomb
- Botnet: हमलावर द्वारा नियंत्रित संक्रमित Devices का समूह। इसका उपयोग Spam, DDoS या अन्य हमलों में हो सकता है।
- Keylogger: Keyboard Input रिकॉर्ड करने वाला Hardware या Software; इसका दुर्भावनापूर्ण उपयोग Password चुराने में हो सकता है।
- Logic Bomb: निर्धारित स्थिति या समय पूरा होने पर सक्रिय होने वाला हानिकारक Code।
- Backdoor: सामान्य Authentication को दरकिनार करने वाला छिपा प्रवेश मार्ग।
DDoS का पूरा नाम Distributed Denial of Service है। इसमें अनेक स्रोतों से अत्यधिक Traffic या Requests भेजकर सेवा की Availability बाधित की जाती है।
5. Social Engineering और Phishing
Social Engineering तकनीकी कमजोरी के स्थान पर या उसके साथ मनुष्य के विश्वास, भय, लालच या जल्दबाजी का उपयोग करके जानकारी या कार्रवाई प्राप्त करने का प्रयास है।
| प्रकार | पहचान |
| Phishing | भ्रामक ईमेल, संदेश या वेबसाइट से जानकारी या कार्रवाई प्राप्त करना। |
| Spear Phishing | किसी विशेष व्यक्ति या संगठन को लक्ष्य बनाकर तैयार Phishing। |
| Whaling | वरिष्ठ अधिकारी जैसे उच्च-मूल्य लक्ष्य पर केंद्रित Phishing। |
| Smishing | SMS या Text Message के माध्यम से Phishing। |
| Vishing | Voice Call के माध्यम से Phishing या धोखाधड़ी। |
| Pretexting | झूठी भूमिका या कहानी बनाकर जानकारी प्राप्त करना। |
| Shoulder Surfing | स्क्रीन या Keyboard देखकर गोपनीय जानकारी प्राप्त करना। |
Phishing संकेत: असामान्य Sender Address, जल्द कार्रवाई का दबाव, OTP या Password की माँग, संदिग्ध Attachment, गलत Domain और अत्यधिक आकर्षक प्रस्ताव।
महत्वपूर्ण: अच्छी भाषा या HTTPS का उपयोग संदेश को विश्वसनीय सिद्ध नहीं करता। लिंक खोलने के बजाय संस्था की आधिकारिक वेबसाइट या App स्वयं खोलें।
6. Password, Passphrase और Password Manager
- प्रत्येक महत्वपूर्ण Account के लिए अलग Password रखें।
- लंबा और अनुमान लगाना कठिन Password या Passphrase उपयोग करें।
- नाम, जन्मतिथि, मोबाइल नंबर और सामान्य क्रम से बचें।
- Password को ईमेल, Chat या फोन कॉल पर साझा न करें।
- Data Breach या संदिग्ध गतिविधि पर Password बदलें।
Password Manager अलग-अलग मजबूत Password बनाने और सुरक्षित रूप से रखने में सहायता कर सकता है। उसके लिए मजबूत Master Password और उपलब्ध MFA उपयोग करें।
सटीक समझ: केवल बड़े अक्षर, संख्या और चिह्न जोड़ देने से छोटा तथा पूर्वानुमानित Password सुरक्षित नहीं हो जाता। Password बार-बार बिना कारण बदलने से अधिक महत्वपूर्ण उसकी लंबाई, विशिष्टता और Compromise होने पर बदलाव है।
7. Authentication, Authorization और MFA
| अवधारणा | अर्थ |
| Identification | उपयोगकर्ता अपनी पहचान बताता है, जैसे Username। |
| Authentication | दावा की गई पहचान सत्यापित करना। |
| Authorization | सत्यापित उपयोगकर्ता को किन संसाधनों या कार्यों की अनुमति है। |
Authentication Factors:
- Something you know: Password या PIN।
- Something you have: Security Token या Registered Device।
- Something you are: Fingerprint या अन्य Biometric।
MFA का अर्थ Multi-Factor Authentication है। इसमें अलग प्रकार के दो या अधिक Factors उपयोग होते हैं। Password और PIN दोनों “Something you know” हैं; इसलिए वे अकेले वास्तविक Two-Factor Authentication नहीं बनाते।
OTP सीमित समय या एक उपयोग का Code है। इसे किसी को न बताएँ। बिना स्वयं Login प्रयास किए प्राप्त MFA Prompt को Approve न करें।
8. Encryption, Encoding और Hashing
| प्रक्रिया | मुख्य उद्देश्य | क्या वापस मूल रूप संभव है? |
| Encryption | Key की सहायता से डेटा गोपनीय बनाना। | सही Key से Decryption संभव। |
| Encoding | डेटा को संगत प्रारूप में प्रस्तुत करना। | सामान्यतः बिना Secret Key के वापस किया जा सकता है। |
| Hashing | डेटा का निश्चित आकार का Digest बनाना; Integrity और Password Verification जैसे उपयोग। | मूलतः One-Way; सामान्य Decryption नहीं। |
Plaintext मूल पठनीय डेटा है और Ciphertext Encrypt किया गया रूप।
- Symmetric Encryption: Encryption और Decryption के लिए वही साझा Secret Key।
- Asymmetric Encryption: संबंधित Public और Private Keys की जोड़ी।
परीक्षा में भ्रम: Base64 जैसी Encoding Encryption नहीं है। Hash को Decrypt करना सामान्य अवधारणा नहीं है। कमजोर या बिना Salt के Password Hash फिर भी हमलों के प्रति असुरक्षित हो सकता है।
9. Digital Signature और Digital Certificate
Digital Signature सामान्यतः Signer की Private Key से बनाया जाता है और संबंधित Public Key से सत्यापित किया जाता है। यह निम्न में सहायता करता है:
- संदेश या दस्तावेज की Integrity जाँचना।
- हस्ताक्षरकर्ता की प्रामाणिकता सत्यापित करना।
- उचित व्यवस्था में हस्ताक्षर से इनकार के जोखिम को कम करना।
Digital Signature का मुख्य उद्देश्य संदेश को गोपनीय बनाना नहीं है। गोपनीयता के लिए Encryption आवश्यक हो सकती है।
Digital Certificate किसी पहचान या Domain को Public Key से जोड़ता है। Certificate Authority प्रमाणपत्र जारी या सत्यापित करने की व्यवस्था में भूमिका निभाती है।
Electronic Signature एक व्यापक अवधारणा है। प्रत्येक इलेक्ट्रॉनिक रूप से किया गया हस्ताक्षर Cryptographic Digital Signature नहीं होता।
10. Firewall, Antivirus और अन्य सुरक्षा साधन
| साधन | मुख्य कार्य |
| Firewall | निर्धारित नियमों के अनुसार Network Traffic को अनुमति या अवरोध देना। |
| Antivirus/Anti-malware | ज्ञात और व्यवहार-आधारित तकनीकों से Malware पहचानने, रोकने या हटाने में सहायता। |
| IDS | Intrusion Detection System; संदिग्ध गतिविधि पहचानकर Alert देना। |
| IPS | Intrusion Prevention System; संदिग्ध गतिविधि पहचानकर उसे रोकने का प्रयास। |
| VPN | अविश्वसनीय Network पर सुरक्षित Logical Tunnel उपलब्ध कराना। |
सीमाएँ: Firewall हर Malware नहीं रोकता, Antivirus हर नए खतरे को नहीं पहचानता और VPN उपयोगकर्ता को पूर्णतः Anonymous नहीं बनाता। Layered Security आवश्यक है।
11. Backup और Ransomware से सुरक्षा
Backup डेटा की अलग, पुनर्प्राप्ति योग्य प्रति है। Backup का उद्देश्य मूल डेटा खोने या खराब होने पर उसे वापस प्राप्त करना है।
| प्रकार | मुख्य पहचान |
| Full Backup | चुने गए पूरे डेटा की प्रति। |
| Incremental Backup | पिछले Backup के बाद हुए बदलावों की प्रति। |
| Differential Backup | पिछले Full Backup के बाद हुए बदलावों की प्रति। |
3-2-1 Rule: महत्वपूर्ण डेटा की 3 प्रतियाँ, 2 अलग प्रकार के Media पर और कम-से-कम 1 प्रति अलग स्थान या Offline व्यवस्था में रखने की सामान्य रणनीति।
- Backup नियमित और स्वचालित हो तो भूल की संभावना कम होती है।
- कम-से-कम एक Backup लगातार मुख्य सिस्टम से जुड़ा न रहे।
- Restore Test करके जाँचें कि Backup वास्तव में उपयोग योग्य है।
महत्वपूर्ण अंतर: Synchronisation और Backup समान नहीं हैं। Sync में गलती से Delete हुई या Encrypt हुई फाइल अन्य स्थान पर भी बदल सकती है।
12. सुरक्षित Browsing, Download और Wi-Fi
- URL और Domain की Spelling ध्यान से जाँचें।
- Software केवल विश्वसनीय आधिकारिक स्रोत से लें।
- Operating System, Browser और Apps को Update रखें।
- अनजान USB Device को बिना जाँच न लगाएँ।
- सार्वजनिक कंप्यूटर पर Password Save न करें।
- Shared Device से कार्य के बाद Logout करें।
Public Wi-Fi: संवेदनशील कार्य के लिए Mobile Data या विश्वसनीय Network बेहतर हो सकता है। नकली Hotspot नाम से सावधान रहें। HTTPS उपयोगी है, लेकिन संदिग्ध साइट को सुरक्षित सिद्ध नहीं करता।
QR Code: Scan करने से पहले स्रोत जाँचें और खुलने वाला URL देखें। QR Code किसी हानिकारक Link को छिपा सकता है।
13. Data Protection और Privacy
- Personal Data: पहचाने गए या पहचाने जा सकने वाले व्यक्ति से संबंधित जानकारी।
- Data Minimisation: उद्देश्य के लिए आवश्यक न्यूनतम डेटा लेना।
- Least Privilege: उपयोगकर्ता को कार्य के लिए आवश्यक न्यूनतम अधिकार देना।
- Access Control: किसे कौन-सा डेटा देखने या बदलने की अनुमति है।
- Data Retention: डेटा कितने समय तक रखा जाएगा।
- Secure Disposal: आवश्यकता समाप्त होने पर डेटा और Media का सुरक्षित निपटान।
उदाहरण: Attendance दर्ज करने वाले कर्मचारी को Payroll बदलने की अनुमति न देना Least Privilege है।
Recycling Bin खाली करना, फाइल को हमेशा के लिए अप्राप्य बनाने की गारंटी नहीं है। अत्यधिक संवेदनशील Media के लिए उपयुक्त Secure Erasure या भौतिक नष्ट करने की प्रक्रिया आवश्यक हो सकती है।
14. Cyber Fraud होने पर त्वरित कार्रवाई
- यदि सुरक्षित हो तो संदिग्ध संपर्क रोकें और आगे भुगतान न करें।
- वित्तीय धोखाधड़ी में Bank या Payment Service को तुरंत सूचित करें।
- भारत में National Cyber Crime Reporting Portal cybercrime.gov.in पर शिकायत दर्ज की जा सकती है।
- वित्तीय साइबर धोखाधड़ी के लिए आधिकारिक Portal पर वर्तमान Helpline और निर्देश सत्यापित करें।
- Screenshot, Transaction ID, Mobile Number, URL और संदेश जैसे Evidence सुरक्षित रखें।
- प्रभावित Account का Password किसी स्वच्छ और विश्वसनीय Device से बदलें तथा सक्रिय Sessions की समीक्षा करें।
Evidence संबंधी सावधानी: संदिग्ध संदेश Delete करने या Device Format करने से पहले संबंधित विशेषज्ञ या अधिकारी की सलाह आवश्यक हो सकती है। स्वयं हमलावर को Hack करने या अनधिकृत कार्रवाई करने का प्रयास न करें।
15. त्वरित पुनरावृत्ति
- CIA = Confidentiality, Integrity और Availability।
- Virus Host से जुड़ता है; Worm स्वतंत्र रूप से फैल सकता है।
- Trojan वैध Software का भ्रामक रूप ले सकता है।
- Smishing में SMS और Vishing में Voice Call उपयोग होता है।
- Authentication पहचान सत्यापित करता है; Authorization अनुमति निर्धारित करता है।
- Encryption वापस Decrypt किया जा सकता है; Hashing सामान्यतः One-Way है।
- Digital Signature Integrity और Authenticity में सहायता करता है।
- Firewall, Antivirus, Updates और Backups परतदार सुरक्षा के भाग हैं।
16. अभ्यास प्रश्न
ये मौलिक अभ्यास प्रश्न हैं, सत्यापित पूर्ववर्ष प्रश्न नहीं। प्रत्येक प्रश्न का एक सही उत्तर है।
प्रश्न 1. परीक्षा के अंक अनधिकृत रूप से न बदले जाएँ—यह मुख्यतः किस सुरक्षा उद्देश्य से संबंधित है?
A. Availability
B. Integrity
C. Compression
D. Portability
उत्तर और व्याख्या देखें
सही उत्तर: B. Integrity
Integrity का उद्देश्य डेटा को अनधिकृत बदलाव से सुरक्षित और सही बनाए रखना है।
प्रश्न 2. कौन-सा Malware किसी Host File से जुड़े बिना स्वयं Network में फैल सकता है?
A. Worm
B. Trojan Horse
C. Adware
D. Logic Bomb
उत्तर और व्याख्या देखें
सही उत्तर: A. Worm
Worm स्वयं की प्रतिलिपि बनाकर फैल सकता है; Virus सामान्यतः Host से जुड़ता है।
प्रश्न 3. उपयोगी Software जैसा दिखने वाला हानिकारक Program क्या कहलाता है?
A. Firewall
B. Patch
C. Trojan Horse
D. Backup
उत्तर और व्याख्या देखें
सही उत्तर: C. Trojan Horse
Trojan भ्रामक रूप से वैध या उपयोगी दिखाई देता है, लेकिन हानिकारक कार्य कर सकता है।
प्रश्न 4. SMS के माध्यम से होने वाले Phishing को क्या कहा जाता है?
A. Whaling
B. Vishing
C. Pharming
D. Smishing
उत्तर और व्याख्या देखें
सही उत्तर: D. Smishing
Smishing SMS/Text Message आधारित Phishing है। Voice Call आधारित प्रकार Vishing कहलाता है।
प्रश्न 5. सत्यापित उपयोगकर्ता को कौन-सी फाइल बदलने की अनुमति है, यह निर्धारित करना क्या कहलाता है?
A. Authentication
B. Authorization
C. Identification
D. Encoding
उत्तर और व्याख्या देखें
सही उत्तर: B. Authorization
Authentication पहचान सत्यापित करता है; Authorization अधिकार निर्धारित करता है।
प्रश्न 6. इनमें से कौन-सा वास्तविक Multi-Factor Authentication का उदाहरण है?
A. Password और PIN
B. दो अलग Password
C. Password और Security Token
D. PIN और सुरक्षा प्रश्न
उत्तर और व्याख्या देखें
सही उत्तर: C. Password और Security Token
Password “Something you know” और Token “Something you have” है। इसलिए दो अलग Factors उपयोग होते हैं।
प्रश्न 7. डेटा का निश्चित आकार वाला One-Way Digest बनाने की प्रक्रिया कौन-सी है?
A. Hashing
B. Decryption
C. Compression
D. Formatting
उत्तर और व्याख्या देखें
सही उत्तर: A. Hashing
Hashing सामान्यतः One-Way प्रक्रिया है और Integrity तथा Password Verification में उपयोग हो सकती है।
प्रश्न 8. Digital Signature सामान्यतः किस Key से बनाया जाता है?
A. प्राप्तकर्ता के Password से
B. Signer की Private Key से
C. केवल Public Key से
D. किसी भी OTP से
उत्तर और व्याख्या देखें
सही उत्तर: B. Signer की Private Key से
Digital Signature Signer की Private Key से बनता और संबंधित Public Key से सत्यापित होता है।
प्रश्न 9. निर्धारित नियमों के अनुसार Network Traffic को अनुमति या अवरोध देने वाला साधन कौन-सा है?
A. Compiler
B. Defragmenter
C. Firewall
D. Spreadsheet
उत्तर और व्याख्या देखें
सही उत्तर: C. Firewall
Firewall सुरक्षा नियमों के अनुसार Network Traffic Filter करता है।
प्रश्न 10. Incremental Backup में सामान्यतः क्या शामिल होता है?
A. प्रत्येक बार पूरा चुना गया डेटा
B. केवल सबसे पुरानी फाइल
C. पिछले Full Backup के बाद के सभी बदलाव, हर बार
D. पिछले Backup के बाद हुए बदलाव
उत्तर और व्याख्या देखें
सही उत्तर: D. पिछले Backup के बाद हुए बदलाव
Incremental Backup पिछले किसी भी प्रकार के Backup के बाद के परिवर्तन रखता है।
प्रश्न 11. किसी कर्मचारी को केवल अपने कार्य के लिए आवश्यक न्यूनतम अधिकार देना किस सिद्धांत का उदाहरण है?
A. Least Privilege
B. Open Access
C. Data Duplication
D. Full Control
उत्तर और व्याख्या देखें
सही उत्तर: A. Least Privilege
Least Privilege अनावश्यक अधिकार सीमित करके सुरक्षा जोखिम कम करता है।
प्रश्न 12. Ransomware से पुनर्प्राप्ति की तैयारी में कौन-सा उपाय सबसे उपयोगी है?
A. केवल फाइलों के नाम बदलना
B. सभी Backups को लगातार उसी सिस्टम से जोड़कर रखना
C. नियमित, अलग और Restore-Tested Backup रखना
D. Browser History साफ करना
उत्तर और व्याख्या देखें
सही उत्तर: C. नियमित, अलग और Restore-Tested Backup रखना
अलग रखा तथा सफलतापूर्वक Restore करके जाँचा गया Backup डेटा पुनर्प्राप्ति में महत्वपूर्ण है।