ExamShortcut
high importanceโšก 8 shortcuts4 subtopics

Malware families (virus, worm, trojan, ransomware), social-engineering attacks (phishing and cousins), preventive measures, and IT Act 2000 sections with CERT-In. Statement-based malware questions appear in nearly every CKT shift.

Track record in the exam

Test difficulty mix (69 questions)

21 easy36 medium12 hard

Question patterns exams keep repeating

Taken from previous-year papers. If a pattern is marked "very common", expect to see it in your exam.

Name the malware

very common

"A program that copies itself on its own is called ___"

Needs a host file = virus. Spreads alone = worm.

Looks useful but harmful = trojan. Locks files for money = ransomware.

Example

Which malware spreads by itself through a network without a host file?

Virus needs a host file to travel

Worm does not need any host

It crawls through the network alone

Answer: Worm

Learn this in โ€œMalware typesโ€ โ†’

Phishing type by channel

very common

A fraud by e-mail, call or SMS, and the attack name is asked.

E-mail = phishing. Phone call = vishing. SMS = smishing.

Correct web address but fake site = pharming.

Example

An SMS says your account will be blocked and asks you to enter your bank password on a link. This is:

The message came by SMS

Fraud by SMS has its own name

Phishing by e-mail, vishing by call

Answer: Smishing

Learn this in โ€œCyber attacks and social engineeringโ€ โ†’

What a security tool does

common

"Which of these is a job of a firewall / antivirus / encryption?"

Firewall filters network traffic by rules.

Antivirus scans and removes malware. Encryption scrambles data.

Example

What does a firewall do?

It sits at the doorway of the network

It allows or blocks traffic by rules

It does not scan or clean files (antivirus does that)

Answer: Filters network traffic

Learn this in โ€œPreventive measures and security toolsโ€ โ†’

IT Act sections

common

"Identity theft is punished under which section?"

Learn: 66 hacking, 66C identity theft, 66D online cheating.

Section 66A was struck down in 2015.

Example

Identity theft (misusing another person's password or digital signature) falls under which section of the IT Act?

Section 66 = hacking

Section 66D = cheating online

Misusing a password or signature = identity theft

Answer: Section 66C

Learn this in โ€œIT Act 2000, offences and authoritiesโ€ โ†’

Name the attack from the story

common

A short story (tiny thefts, waiting code, flooded server) and the attack name is asked.

Salami = many tiny thefts. Logic bomb = code that waits for a trigger.

DoS = flooding a server. SQL injection = commands typed into a form.

Example

A harmful program stays hidden in a bank system until 1 April and then deletes all records. This is a:

It stays hidden and waits

It acts only on a trigger (the date)

That is the mark of a logic bomb

Answer: Logic bomb

Learn this in โ€œCyber attacks and social engineeringโ€ โ†’

Encryption and passwords

common

"Scrambled data is called ___" or "the padlock in the browser means ___".

Plaintext = readable. Ciphertext = scrambled.

https + padlock = encrypted connection.

Example

The padlock icon next to https:// in a browser shows that:

https means the connection uses encryption

Data travels as unreadable ciphertext

Outsiders cannot read it on the way

Answer: The connection is encrypted

Learn this in โ€œPreventive measures and security toolsโ€ โ†’

Your next step

New here? Start with subtopic 1 in Learn. Revision mode? Jump straight to the test and let it tell you what to fix.