VidBodh AcademyThe art and science of civil services preparation

Prelims · Science and Technology

Cybersecurity

3 questions, from 2017 to 2020.

2017

1 question

2017 · Q85

In India, it is legally mandatory for which of the following to report on cyber security incidents?

  1. 1.Service providers
  2. 2.Data centres
  3. 3.Body corporate.

Select the correct answer using the code given below:

  1. (a)1 only
  2. (b)1 and 2 only
  3. (c)3 only
  4. (d)1, 2 and 3
Show answer and explanation

All three are correct and the official answer (d) follows. Section 70B of the Information Technology Act, 2000 designates the Indian Computer Emergency Response Team, CERT-In, as the national nodal agency for incident response, and subsection (6) empowers it to call for information and give directions. The Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013 make reporting mandatory, rule 12 requiring service providers, intermediaries, data centres and body corporate to report specified cyber security incidents to CERT-In within a reasonable time, and section 70B(7) attaches a penalty of imprisonment up to one year or a fine or both for failure to comply. Every category named in the question therefore appears expressly in the rule. The item is difficult because there is no elimination route: all three categories are plausible, none can be rejected on principle, and the answer depends on knowing the text of a subordinate rule that no standard preparation source reproduces. A candidate's best available reasoning is that a reporting regime designed to give a national agency visibility of the threat landscape would be defeated by exempting any major class of entity, which points towards the inclusive option. Teaching point for the subject: the reporting obligation is on the entity that suffers or observes the incident, and the categories are drawn to cover the whole chain, the network operator, the facility and the enterprise.

Difficult · Current Affairs Inspired · Science and Technology · Cybersecurity

2018

1 question

2018 · Q58

The terms 'WannaCry, Petya and EternalBlue' sometimes mentioned in the news recently are related to

  1. (a)Exoplanets
  2. (b)Cryptocurrency
  3. (c)Cyber attacks
  4. (d)Mini satellites
Show answer and explanation
  • Option (c) is correct. All three terms belong to the same episode. EternalBlue is an exploit of a flaw in Microsoft's Server Message Block version 1 protocol, developed by the United States National Security Agency and released publicly by the Shadow Brokers group in April 2017. WannaCry, which spread worldwide in May 2017 and crippled parts of the British National Health Service among many others, was ransomware that used EternalBlue to propagate from machine to machine without user action, which is what made it a worm rather than an ordinary ransomware campaign. Petya, and more precisely the NotPetya variant of June 2017, used the same exploit but destroyed data irrecoverably while presenting itself as ransomware.
  • Option (b) is the strongest distractor and is worth addressing carefully, because ransomware demands payment in Bitcoin and the two subjects are therefore linked in news coverage. The link is incidental: cryptocurrency is the payment channel, not the subject, and none of the three terms names a currency, a protocol or an exchange.
  • Options (a) and (d) fail on domain, exoplanets and small satellites being unrelated to any of the three names. Governing principle for terms in news questions of this shape: find the single event that accounts for all the terms together rather than assessing each in isolation, since the examiner groups them precisely because they share one origin.

Hence (c).

Easy · Current Affairs Inspired · Science and Technology · Cybersecurity

2020

1 question

2020 · Q46

In India, the term "Public Key Infrastructure" is used in the context of

  1. (a)Digital security infrastructure
  2. (b)Food security infrastructure
  3. (c)Health care and education infrastructure
  4. (d)Telecommunication and transportation infrastructure
Show answer and explanation

Public Key Infrastructure is the framework of certifying authorities, digital certificates and asymmetric key pairs that underpins digital signatures and encrypted communication. In India it is administered by the Controller of Certifying Authorities under the Information Technology Act of 2000, which gives legal recognition to digital signatures. Hence (a). Options (b), (c) and (d) are wrong because the word public in the term refers to the public half of a cryptographic key pair, not to public provision of goods or services. This is a pure vocabulary question in which the whole difficulty lies in resisting the reading of public as governmental, and a candidate who knows that a public key is paired with a private key can answer without any further knowledge.

Easy · Current Affairs Inspired · Science and Technology · Cybersecurity

← All Science and Technology questions