Cyber Security: Complete Concepts, Threats, Malware & 50+Difficult MCQs | UGC NET/JRF 2026

Cyber Security: Complete Concepts, Threats, Malware & 50+Difficult MCQs | UGC NET/JRF 2026

Cyber Security

साइबर सुरक्षा 

UGC NET/JRF Paper-I | 2026

1. Cyber Security का सबसे व्यापक अर्थ क्या है?

What is the most comprehensive meaning of Cyber Security?

(A) केवल computer viruses को हटाना / Removing computer viruses only

(B) केवल passwords को सुरक्षित रखना / Protecting passwords only

(C) Digital systems, networks, devices और data को unauthorized access, attacks और damage से सुरक्षित रखना / Protecting digital systems, networks, devices and data from unauthorized access, attacks and damage

(D) केवल internet speed बढ़ाना / Increasing internet speed only

Answer: (C)

2. CIA Triad में निम्न में से कौन-से तीन प्रमुख security principles शामिल हैं?

Which three major security principles are included in the CIA Triad?

(A) Confidentiality, Integrity and Availability

(B) Control, Internet and Authentication

(C) Confidentiality, Internet and Authorization

(D) Control, Integrity and Access

Answer: (A)

3. यदि sensitive information केवल authorized users को उपलब्ध हो, तो यह किस security principle को दर्शाता है?

If sensitive information is accessible only to authorized users, which security principle does this represent?

(A) Availability

(B) Confidentiality

(C) Integrity

(D) Non-repudiation

Answer: (B)

4. किसी database में stored information को unauthorized तरीके से बदल दिया गया। CIA Triad के किस component का मुख्यतः उल्लंघन हुआ?

Information in a database is modified without authorization. Which component of the CIA Triad is primarily violated?

(A) Availability

(B) Confidentiality

(C) Authentication

(D) Integrity

Answer: (D)

5. किसी online service को legitimate users के लिए unavailable बनाने के लिए अत्यधिक traffic भेजा जाता है। यह किस प्रकार के attack से संबंधित है?

Excessive traffic is sent to make an online service unavailable to legitimate users. This is associated with which type of attack?

(A) Phishing

(B) Data masking

(C) Denial-of-Service attack

(D) Encryption

Answer: (C)

6. DDoS attack में “Distributed” शब्द किस ओर संकेत करता है?

What does “Distributed” in a DDoS attack indicate?

(A) Attack traffic multiple compromised sources से आ सकता है।

(B) केवल एक computer attack करता है।

(C) Data multiple formats में stored होता है।

(D) केवल server के अंदर attack होता है।

Answer: (A)

7. Malware का सबसे उपयुक्त अर्थ क्या है?

What is the most appropriate meaning of malware?

(A) केवल malicious website

(B) ऐसा software जो system या data को नुकसान पहुँचाने या unauthorized activity करने के लिए designed हो

(C) केवल antivirus software

(D) केवल encrypted file

Answer: (B)

8. निम्न में से कौन-सा Malware का उदाहरण है?

Which is an example of malware?

(A) Firewall

(B) Digital certificate

(C) Antivirus

(D) Ransomware

Answer: (D)

9. Ransomware की प्रमुख विशेषता क्या है?

What is a major characteristic of ransomware?

(A) Files/data को encrypt या lock करके payment की मांग करना

(B) केवल browser history delete करना

(C) Internet speed बढ़ाना

(D) केवल spam messages भेजना

Answer: (A)

10. Spyware का मुख्य उद्देश्य सामान्यतः क्या होता है?

What is the usual purpose of spyware?

(A) System को physically repair करना

(B) User की activity या information को secretly monitor/collect करना

(C) Network bandwidth बढ़ाना

(D) Files को automatically backup करना

Answer: (B)

11. Trojan Horse की प्रमुख विशेषता क्या है?

What is a major characteristic of a Trojan Horse?

(A) यह केवल network hardware है।

(B) यह स्वयं को legitimate software/file के रूप में प्रस्तुत करके user को deceive कर सकता है।

(C) यह हमेशा केवल encrypted data बनाता है।

(D) यह केवल firewall का दूसरा नाम है।

Answer: (B)

12. Computer Worm और Virus में एक महत्वपूर्ण अंतर क्या है?

What is an important difference between a computer worm and a virus?

(A) Worm को कभी network की आवश्यकता नहीं होती।

(B) Virus हमेशा harmless होता है।

(C) Worm स्वयं फैलने की क्षमता रख सकता है, जबकि virus को सामान्यतः host file/program से जुड़ने की आवश्यकता होती है।

(D) दोनों हमेशा बिल्कुल समान होते हैं।

Answer: (C)

13. Phishing attack मुख्यतः किस प्रकार की technique पर आधारित होता है?

Phishing attacks are primarily based on which technique?

(A) Social engineering और deception

(B) Hardware replacement

(C) Data compression

(D) Network cabling

Answer: (A)

14. एक व्यक्ति को बैंक के नाम से suspicious link वाला e-mail मिलता है और उससे password तथा OTP माँगा जाता है। यह किसका संभावित उदाहरण है?

A person receives an e-mail apparently from a bank containing a suspicious link and asking for a password and OTP. This is potentially an example of:

(A) Encryption

(B) Phishing

(C) Backup

(D) Firewall filtering

Answer: (B)

15. Spear Phishing सामान्य Phishing से किस प्रकार अलग है?

How does spear phishing differ from ordinary phishing?

(A) यह केवल government websites पर होता है।

(B) यह केवल malware से संबंधित है।

(C) यह किसी विशेष व्यक्ति या organization को target करके अधिक customized deception कर सकता है।

(D) इसमें Internet का उपयोग नहीं होता।

Answer: (C)

16. Social Engineering का सबसे उपयुक्त अर्थ क्या है?

What is the most appropriate meaning of social engineering?

(A) Social media website बनाना

(B) Human psychology/manipulation का उपयोग करके sensitive information या unauthorized access प्राप्त करना

(C) Computer network design करना

(D) Software programming करना

Answer: (B)

17. निम्न में से कौन-सा Social Engineering का उदाहरण है?

Which is an example of social engineering?

(A) किसी employee को phone करके IT administrator बनकर password पूछना

(B) Antivirus update करना

(C) Firewall install करना

(D) Data backup लेना

Answer: (A)

18. Password Security के संदर्भ में निम्न में से कौन-सा सबसे सुरक्षित practice है?

Which is the safest practice regarding password security?

(A) सभी accounts में एक ही password रखना

(B) Password को publicly share करना

(C) Strong, unique passwords और multi-factor authentication का उपयोग करना

(D) Password को browser में plain text में लिखना

Answer: (C)

19. Multi-Factor Authentication (MFA) का मूल उद्देश्य क्या है?

What is the basic purpose of Multi-Factor Authentication?

(A) केवल password की length बढ़ाना

(B) Authentication के लिए एक से अधिक independent factors का उपयोग करना

(C) केवल username हटाना

(D) केवल Internet speed बढ़ाना

Answer: (B)

20. निम्न में से कौन-सा Authentication Factor का उदाहरण है?

Which is an example of an authentication factor?

(A) Something you know – password

(B) Something you download – PDF

(C) Something you browse – website

(D) Something you print – document

Answer: (A)

21. Fingerprint authentication किस प्रकार के factor का उदाहरण है?

Fingerprint authentication is an example of which factor?

(A) Something you know

(B) Something you have

(C) Something you are

(D) Somewhere you are

Answer: (C)

22. OTP सामान्यतः किस category से संबंधित authentication factor के रूप में उपयोग किया जाता है?

OTP is generally used as which type of authentication factor?

(A) Something you have

(B) Something you are

(C) Something you know only

(D) Something you see

Answer: (A)

23. Encryption का प्रमुख उद्देश्य क्या है?

What is the primary purpose of encryption?

(A) Data को unauthorized parties के लिए unreadable रूप में बदलना

(B) Data को permanently delete करना

(C) Internet speed बढ़ाना

(D) Computer की RAM बढ़ाना

Answer: (A)

24. Encryption में plaintext का क्या होता है?

What happens to plaintext during encryption?

(A) वह हमेशा delete हो जाता है।

(B) वह ciphertext में transform होता है।

(C) वह automatically print हो जाता है।

(D) वह केवल backup file बन जाता है।

Answer: (B)

25. Decryption का अर्थ क्या है?

What does decryption mean?

(A) Ciphertext को appropriate key/process की सहायता से readable plaintext में बदलना

(B) Data को compress करना

(C) Password को delete करना

(D) Network को disconnect करना

Answer: (A)

26. Symmetric Encryption की प्रमुख विशेषता क्या है?

What is a major characteristic of symmetric encryption?

(A) Encryption और decryption के लिए एक ही secret key का उपयोग

(B) केवल public key का उपयोग

(C) किसी key की आवश्यकता नहीं

(D) केवल biometric authentication

Answer: (A)

27. Asymmetric Cryptography में सामान्यतः कितनी keys की जोड़ी उपयोग की जाती है?

How many keys are generally used in asymmetric cryptography?

(A) एक

(B) दो – public key और private key

(C) तीन

(D) कोई key नहीं

Answer: (B)

28. Digital Signature का प्रमुख उद्देश्य क्या है?

What is the primary purpose of a digital signature?

(A) केवल document का आकार कम करना

(B) केवल document को encrypt करना

(C) केवल password generate करना

(D) Authenticity/integrity सुनिश्चित करने और non-repudiation में सहायता करना

Answer: (D)

29. Digital Certificate मुख्यतः किससे संबंधित है?

A digital certificate is mainly associated with:

(A) Digital identity की verification/authentication

(B) केवल data compression

(C) केवल antivirus scanning

(D) केवल file storage

Answer: (A)

30. Firewall का प्रमुख कार्य क्या है?

What is the primary function of a firewall?

(A) सभी computer files को encrypt करना

(B) Network traffic को predefined security rules के आधार पर monitor/filter करना

(C) केवल password generate करना

(D) केवल backup लेना

Answer: (B)

31. निम्न में से कौन-सा Firewall की limitation हो सकती है?

Which can be a limitation of a firewall?

(A) यह हर प्रकार के social engineering attack को automatically रोक सकता है।

(B) यह सभी human errors को समाप्त कर सकता है।

(C) Properly configured firewall भी phishing जैसे human-targeted attacks को पूरी तरह नहीं रोक सकता।

(D) Firewall कभी network traffic inspect नहीं करता।

Answer: (C)

32. Antivirus software का मुख्य उद्देश्य क्या है?

What is the primary purpose of antivirus software?

(A) Malware को detect, prevent और/or remove करने में सहायता करना

(B) Internet bandwidth को double करना

(C) Password को publicly share करना

(D) केवल website design करना

Answer: (A)

33. Antivirus software को regularly update करने का मुख्य कारण क्या है?

Why should antivirus software be updated regularly?

(A) नए malware signatures/threat intelligence और security improvements प्राप्त करने के लिए

(B) Computer की screen size बढ़ाने के लिए

(C) Keyboard की speed बढ़ाने के लिए

(D) केवल files rename करने के लिए

Answer: (A)

34. निम्नलिखित कथनों पर विचार कीजिए:

1. Strong passwords cyber security को improve कर सकते हैं।

2. Multi-factor authentication अतिरिक्त security layer प्रदान कर सकता है।

3. सभी accounts के लिए एक ही password रखना recommended practice है।

सही विकल्प चुनिए:

(A) केवल 1

(B) केवल 3

(C) 1 और 2

(D) 1, 2 और 3

Answer: (C)

35. निम्नलिखित में से कौन-से Cyber Security threats हैं?

1. Phishing

2. Ransomware

3. Spyware

4. Social Engineering

(A) केवल 1 और 2

(B) 1, 2 और 3

(C) 2, 3 और 4

(D) 1, 2, 3 और 4

Answer: (D)

36. Assertion (A): Multi-Factor Authentication account security को मजबूत कर सकता है।

Reason (R): MFA authentication के लिए एक से अधिक प्रकार के factors का उपयोग कर सकता है।

(A) A और R दोनों सही हैं, लेकिन R सही व्याख्या नहीं है।

(B) A सही है, R गलत है।

(C) A गलत है, R सही है।

(D) A और R दोनों सही हैं तथा R, A की सही व्याख्या है।

Answer: (D)

37. Assertion (A): Encryption confidentiality को मजबूत करने में सहायक है।

Reason (R): Encryption plaintext को ऐसे रूप में बदलता है जिसे उचित decryption mechanism के बिना समझना कठिन होता है।

(A) A और R दोनों सही हैं तथा R, A की सही व्याख्या है।

(B) A और R दोनों सही हैं, लेकिन R सही व्याख्या नहीं है।

(C) A सही है, R गलत है।

(D) A गलत है, R सही है।

Answer: (A)

38. Assertion (A): Firewall सभी प्रकार के cyber attacks को रोक सकता है।

Reason (R): Firewall मुख्यतः network traffic को predefined rules के अनुसार filter/monitor करता है।

(A) A और R दोनों सही हैं।

(B) A सही है, R गलत है।

(C) A गलत है, R सही है।

(D) A और R दोनों गलत हैं।

Answer: (C)

39. निम्नलिखित का सही मिलान कीजिए:

सूची-I सूची-II
A. Phishing 1. Deceptive information harvesting
B. Ransomware 2. Data encryption/extortion
C. Spyware 3. Secret monitoring
D. Firewall 4. Traffic filtering

(A) A-1, B-2, C-3, D-4

(B) A-2, B-1, C-4, D-3

(C) A-3, B-2, C-1, D-4

(D) A-4, B-3, C-2, D-1

Answer: (A)

40. निम्नलिखित का सही मिलान कीजिए:

सूची-I सूची-II
A. Confidentiality 1. Unauthorized disclosure से protection
B. Integrity 2. Unauthorized modification से protection
C. Availability 3. Authorized users के लिए access
D. Authentication 4. Identity verification

(A) A-2, B-1, C-4, D-3

(B) A-1, B-2, C-3, D-4

(C) A-3, B-2, C-1, D-4

(D) A-4, B-3, C-2, D-1

Answer: (B)

41. एक organization के employees को suspicious e-mails की पहचान करने और sensitive information share न करने की training दी जाती है। यह मुख्यतः किस security approach का हिस्सा है?

Employees are trained to identify suspicious e-mails and avoid sharing sensitive information. This is mainly part of which security approach?

(A) Human awareness and security education

(B) Data compression

(C) Hardware virtualization

(D) Network topology design

Answer: (A)

42. यदि attacker किसी legitimate website जैसा दिखने वाला fake website बनाकर users से login credentials प्राप्त करता है, तो इसे किससे सबसे अधिक जोड़ा जाएगा?

If an attacker creates a fake website resembling a legitimate website to obtain login credentials, this is most closely associated with:

(A) Backup

(B) Phishing

(C) Encryption

(D) Load balancing

Answer: (B)

43. Zero-Day Vulnerability का सबसे उपयुक्त अर्थ क्या है?

What is the most appropriate meaning of a Zero-Day Vulnerability?

(A) ऐसी vulnerability जिसके exploitation से पहले या उसके शुरुआती समय में effective patch उपलब्ध नहीं हो सकता

(B) ऐसी vulnerability जो केवल पुराने computers में होती है

(C) ऐसी vulnerability जो हमेशा harmless होती है

(D) ऐसी vulnerability जिसका कोई security relevance नहीं है

Answer: (A)

44. Software updates और security patches cyber security के लिए क्यों महत्वपूर्ण हैं?

Why are software updates and security patches important for cybersecurity?

(A) वे केवल software का appearance बदलते हैं।

(B) वे केवल storage capacity बढ़ाते हैं।

(C) वे ज्ञात vulnerabilities को address कर सकते हैं और security improvements प्रदान कर सकते हैं।

(D) वे हमेशा सभी cyber attacks को समाप्त कर देते हैं।

Answer: (C)

45. Data Backup ransomware attack के संदर्भ में क्यों महत्वपूर्ण है?

Why is data backup important in the context of ransomware attacks?

(A) Backup से compromised/encrypted data को सुरक्षित copy से restore करने में सहायता मिल सकती है।

(B) Backup ransomware को automatically attack करने से रोकता है।

(C) Backup Internet speed बढ़ाता है।

(D) Backup phishing e-mails को delete करता है।

Answer: (A)

46. Public Wi-Fi का उपयोग करते समय sensitive transactions के लिए सबसे उपयुक्त practice क्या है?

What is an appropriate practice when performing sensitive transactions over public Wi-Fi?

(A) किसी भी suspicious network पर बिना verification connect होना

(B) Security protections का उपयोग करना और sensitive activity के लिए trusted/secure connection को प्राथमिकता देना

(C) Password को खुले रूप में share करना

(D) सभी security warnings को ignore करना

Answer: (B)

47. निम्न में से कौन-सा least privilege principle को सबसे अच्छी तरह दर्शाता है?

Which best represents the principle of least privilege?

(A) प्रत्येक user को administrator-level access देना

(B) सभी employees को सभी databases तक access देना

(C) Users को उनके कार्य के लिए आवश्यक न्यूनतम permissions देना

(D) किसी भी user से authentication न माँगना

Answer: (C)

48. Cyber Security में Defense in Depth का अर्थ क्या है?

What does Defense in Depth mean in cybersecurity?

(A) केवल एक मजबूत password पर निर्भर रहना

(B) केवल firewall install करना

(C) केवल antivirus का उपयोग करना

(D) Multiple security layers और controls का उपयोग करना

Answer: (D)

49. निम्न में से कौन-सा cyber incident के बाद सबसे उपयुक्त response sequence को दर्शाता है?

Which represents an appropriate broad response sequence after a cyber incident?

(A) Detect/identify → Contain → Eradicate/Remediate → Recover → Learn/Improve

(B) Ignore → Delete → Restart → Forget

(C) Publish → Share → Ignore → Recover

(D) Shutdown permanently → Destroy all data → Reinstall without investigation

Answer: (A)

50. Cyber Security की सबसे प्रभावी समग्र रणनीति कौन-सी है?

Which is the most effective comprehensive cybersecurity strategy?

(A) केवल antivirus install करना

(B) केवल strong password रखना

(C) केवल firewall लगाना

(D) People + Process + Technology के साथ layered security, awareness, updates, authentication, backup और continuous monitoring का संयोजन

Answer: (D)

UGC NET/JRF Quick Revision

Concept Key Point
Cyber Security Digital systems, networks और data की सुरक्षा
CIA Triad Confidentiality + Integrity + Availability
Confidentiality Unauthorized disclosure से protection
Integrity Unauthorized modification से protection
Availability Authorized users के लिए access
Authentication Identity verification
Authorization Permissions/access rights
Malware Malicious software
Virus Host file/program से जुड़कर फैल सकता है
Worm स्वयं network पर फैल सकता है
Trojan Legitimate software के रूप में deception
Ransomware Data lock/encrypt + extortion
Spyware Secret monitoring/information collection
Phishing Deceptive information theft
Spear Phishing Targeted phishing
Social Engineering Human manipulation
Encryption Plaintext → Ciphertext
Decryption Ciphertext → Plaintext
Symmetric Encryption Same secret key
Asymmetric Encryption Public + Private key
Digital Signature Authenticity + Integrity + Non-repudiation
Firewall Network traffic filtering
Antivirus Malware detection/removal
MFA Multiple authentication factors
Zero-Day Unpatched/unknown vulnerability exploitation
Backup Recovery में सहायता
Least Privilege Minimum necessary access
Defense in Depth Multiple security layers

UGC NET/JRF Super Revision Tricks

CIA → Confidentiality + Integrity + Availability

Confidentiality → Secret रखना

Integrity → Data को सही/unchanged रखना

Availability → जरूरत पर उपलब्ध रखना

Phishing → Fake message/link

Spear Phishing → Targeted Phishing

Ransomware → Encrypt/Lock + Demand

Spyware → Secretly Monitor

Trojan → Disguise

Worm → Self-spreading

Symmetric → One Secret Key

Asymmetric → Public + Private Key

MFA → Multiple Factors

Firewall → Traffic Filter

Digital Signature → Authenticity + Integrity

Least Privilege → Minimum Required Access

Defense in Depth → Multiple Security Layers

Dr. Amar Kumar

Website: https://www.geographynotespdf.com

I ‘Dr. Amar Kumar’ am working as an Assistant Professor in The Department Of Geography in PPU, Patna (Bihar) India. I want to help the students and study lovers across the world who face difficulties to gather the information and knowledge about Geography. I think my latest UNIQUE GEOGRAPHY NOTES are more useful for them and I publish all types of notes regularly.

Leave a Reply

Your email address will not be published. Required fields are marked *

error: