Cyber Security — UPSC CSE Questions

278 UPSC CSE practice questions on Cyber Security, part of Internal Security. Below are 12 of them in full, each with the answer and a written explanation.

Questions & explanations

1. What is a 'bot network' (botnet) in the context of social media?

  1. (a) A network of computers infected with malware used to send spam.
  2. (b) A group of automated accounts that post content to manipulate public opinion.
  3. (c) A secure communication channel for journalists.
  4. (d) A tool to verify fake news.

Answer: (b) A group of automated accounts that post content to manipulate public opinion.

In the social media context the question refers to a network of automated fake accounts (a bot army) used to artificially post like and share content so as to create false trends and manipulate public opinion. This is option (b) and such coordinated bot networks are a core tool of disinformation and information warfare. Option (a) describes the classic computer-science meaning of a botnet namely a set of internet-connected machines infected with malware and controlled remotely to send spam or launch attacks; that meaning is real but is about compromised devices not influence operations. Because the stem fixes the setting as social media and asks which choice best describes the phenomenon there (b) is the correct answer. Option (c) is a secure channel and option (d) is a verification tool both unrelated.

2. Which government body in India is primarily responsible for identifying and protecting critical infrastructure?

  1. (a) Ministry of Home Affairs
  2. (b) National Critical Information Infrastructure Protection Centre (NCIIPC)
  3. (c) Department of Telecommunications
  4. (d) Indian Computer Emergency Response Team (CERT-In)

Answer: (b) National Critical Information Infrastructure Protection Centre (NCIIPC)

The National Critical Information Infrastructure Protection Centre (NCIIPC) is the body that identifies and protects India's critical information infrastructure. It was set up under Section 70A of the Information Technology Act, 2000, and works under the National Technical Research Organisation (NTRO). Why the others are wrong: (a) The Ministry of Home Affairs handles internal security broadly but is not the lead body for critical information infrastructure. (c) The Department of Telecommunications regulates telecom but does not lead this work. (d) CERT-In handles cyber incident response, not the protection of critical information infrastructure. So the correct answer is (b).

3. With reference to the National Critical Information Infrastructure Protection Centre (NCIIPC) in India, consider the following statements: 1. The National Critical Information Infrastructure Protection Centre (NCIIPC) functions under the National Technical Research Organisation (NTRO). 2. NCIIPC is mandated to protect critical information infrastructure from cyber threats and vulnerabilities. 3. Cybersecurity threats are considered a significant risk to India's Critical Information Infrastructure. Which of the statements given above is/are correct?

  1. (a) 1 and 2 only
  2. (b) 2 and 3 only
  3. (c) 1 only
  4. (d) 1, 2 and 3

Answer: (d) 1, 2 and 3

All three statements are correct, so the answer is (d). Statement 1 is true: the NCIIPC works under the National Technical Research Organisation (NTRO), which sits under the Cabinet Secretariat. Statement 2 is true: the job of the NCIIPC is to protect critical information infrastructure from cyber threats, weak points, and attacks. Statement 3 is true: cyber threats are a big and growing danger to this infrastructure, so strong protection is needed. Why the others are wrong: (a) leaves out statement 3, which is also correct; (b) leaves out statement 1, which is also correct; (c) says only statement 1 is right, but statements 2 and 3 are right too.

4. With reference to the protection of critical infrastructure, consider the following statements: 1. The National Critical Infrastructure Protection Centre (NCIPC) was established under the Ministry of Home Affairs. 2. Cybersecurity threats are a major concern in protecting critical infrastructure. 3. Physical security measures are no longer sufficient to protect critical infrastructure in the digital age. Which of the statements given above is/are correct?

  1. (a) 1 and 2 only
  2. (b) 2 and 3 only
  3. (c) 1 and 3 only
  4. (d) 1, 2 and 3

Answer: (b) 2 and 3 only

The correct body is the National Critical Information Infrastructure Protection Centre (NCIIPC), set up under Section 70A of the IT Act, and it works under the NTRO (National Technical Research Organisation), not the Ministry of Home Affairs. The question also names it wrongly as 'NCIPC'. Statement 2 is correct. Cyber threats are a major worry for critical infrastructure today. Statement 3 is correct. Physical security alone is no longer enough in the digital age; cyber defences are also needed. So statements 2 and 3 are correct and the answer is (b). Options (a), (c) and (d) are wrong because they include statement 1, which is false.

5. Which of the following statements regarding the protection of Critical Information Infrastructure in India are correct? 1. The National Critical Information Infrastructure Protection Centre (NCIIPC) functions as the nodal agency for all measures related to the protection of Critical Information Infrastructure in India. 2. The Information Technology Act, 2000, specifically empowers the Central Government to declare any computer resource as Critical Information Infrastructure. 3. The Indian Computer Emergency Response Team (CERT-In) is responsible for issuing alerts, advisories, and handling cyber incidents concerning Critical Information Infrastructure. 4. Mandatory annual third-party cybersecurity audits are uniformly enforced by law for all private sector entities operating Critical Information Infrastructure across all sectors. Select the correct answer using the code below:

  1. (a) 1, 2 and 3 only
  2. (b) 1, 2 and 4 only
  3. (c) 2, 3 and 4 only
  4. (d) 1, 2, 3 and 4

Answer: (a) 1, 2 and 3 only

1. The National Critical Information Infrastructure Protection Centre (NCIIPC) works as the main agency for all steps to protect Critical Information Infrastructure in India. 2. The Information Technology Act, 2000, gives the Central Government the power to declare any computer resource as Critical Information Infrastructure. 3. The Indian Computer Emergency Response Team (CERT-In) issues alerts and advisories, and handles cyber incidents related to Critical Information Infrastructure. 4. The Information Technology Act, 2000, does NOT make an annual third-party cybersecurity audit legally required for every private company in India.

6. With reference to CERT-In's role in cyber security, consider the following statements: 1. CERT-In is responsible for maintaining a national cyber security incident database. 2. CERT-In can mandate organizations to report cyber incidents within 6 hours of detection. 3. CERT-In is not empowered to issue directions to private sector entities. Which of the statements given above is/are correct?

  1. (a) 1 and 2 only
  2. (b) 2 and 3 only
  3. (c) 1 only
  4. (d) 1, 2 and 3

Answer: (a) 1 and 2 only

Statement 1 is correct. CERT-In is the national nodal agency for cyber incidents, so it collects and keeps a record of cyber security incidents in the country. Statement 2 is correct. Under the CERT-In Directions of April 2022, issued using its powers under Section 70B(6) of the IT Act, organisations must report listed cyber incidents to CERT-In within 6 hours of noticing them. CERT-In can issue binding directions to private firms, data centres and others. This power comes from Section 70B, not Section 70A. (Section 70A deals with the NCIIPC, a different body.) So statements 1 and 2 are correct and the answer is (a).

7. With reference to cyber threats to critical infrastructure, consider the following statements: 1. A cyber attack on a power grid can lead to cascading failures across multiple sectors. 2. The Stuxnet worm is an example of a cyber attack targeting industrial control systems. 3. CERT-In has the authority to conduct forensic investigations on cyber incidents in critical infrastructure. Which of the statements given above is/are correct?

  1. (a) 1 and 2 only
  2. (b) 2 and 3 only
  3. (c) 1 and 3 only
  4. (d) 1, 2 and 3

Answer: (a) 1 and 2 only

Statement 1 is correct: power grid cyber attacks can cause cascading failures across interconnected sectors. Statement 2 is correct: Stuxnet was a state-sponsored cyber weapon targeting Iran's Siemens-controlled industrial systems (SCADA) at the Natanz nuclear facility. Statement 3 is overstated: CERT-In assists in technical analysis and can facilitate forensic investigation, but the authority to independently conduct forensic investigations in the criminal sense rests with law enforcement agencies and NIA, not CERT-In exclusively. Statements 1 and 2 are the clearly correct ones, making (a) the right answer.

8. Under which section of the Information Technology Act, 2000, does CERT-In have the authority to issue directions for securing systems?

  1. (a) Section 70
  2. (b) Section 70A
  3. (c) Section 70B
  4. (d) Section 71

Answer: (c) Section 70B

Section 70B of the IT Act, 2000 makes CERT-In the national agency for cyber incidents and lets it call for information and give directions to keep systems safe. So (c) is correct. (a) Section 70 lets the government declare certain computer systems as \"protected systems\" and control who can access them. It is not about directions for securing systems. (b) Section 70A sets up the NCIIPC, the body that protects critical information infrastructure, not CERT-In's power to give directions. (d) Section 71 is about penalty for misrepresentation to get a licence or certificate, not unauthorised access.

9. Under which section of the Information Technology Act, 2000, does CERT-In have the authority to issue directions during a cyber security incident?

  1. (a) Section 70
  2. (b) Section 70A
  3. (c) Section 70B
  4. (d) Section 71

Answer: (c) Section 70B

Section 70B of the IT Act, 2000 sets up CERT-In and lets it call for information and give directions to handle cyber security incidents and keep computer systems safe. So (c) is correct. (a) Section 70 lets the government declare certain computer systems as \"protected systems\" and control access to them. It is not about CERT-In giving directions. (b) Section 70A sets up the NCIIPC, the body that protects critical information infrastructure. It is not CERT-In's incident power. (d) Section 71 deals with penalty for misrepresentation to get a licence or certificate, not emergency directions.

10. With respect to cyber threats to critical infrastructure, which of the following statements is/are correct? 1. A successful cyber attack on a power grid can lead to cascading failures across multiple sectors. 2. Critical infrastructure systems are increasingly being integrated with IoT devices, increasing their attack surface. 3. CERT-In has the authority to mandate cybersecurity audits for all critical infrastructure providers.

  1. (a) 1 and 2 only
  2. (b) 2 and 3 only
  3. (c) 1 and 3 only
  4. (d) 1, 2 and 3

Answer: (a) 1 and 2 only

Statement 1 is correct. A cyber attack on a power grid can trip other linked sectors like railways, hospitals, and banks, so failures spread in a chain. Statement 2 is correct. Power plants, water systems, and other key services now use many connected IoT sensors and devices, and each one adds a new point that an attacker can target. Statement 3 is not correct. CERT-In issues alerts, advisories, and guidelines, but the job of protecting critical information infrastructure rests with the NCIIPC under Section 70A of the IT Act. So only 1 and 2 are correct, and the answer is (a).

11. Under which section of the Information Technology Act, 2000, does CERT-In have the authority to issue directions for securing computer systems?

  1. (a) Section 70
  2. (b) Section 70A
  3. (c) Section 70B
  4. (d) Section 71

Answer: (c) Section 70B

The answer is (c), Section 70B. Section 70B of the IT Act, 2000, sets up CERT-In and gives it the power to issue directions to secure computer systems and to handle cyber incidents. The other options are wrong. Section 70 lets the government declare a 'protected system' and control access to it. Section 70A names the nodal agency (NCIIPC) for protecting critical information infrastructure, not CERT-In. Section 71 sets the penalty for giving false information to the Controller or a Certifying Authority, so it is not about CERT-In's power to issue directions.

12. Consider the following statements regarding Critical Infrastructure in India: 1. Critical Infrastructure includes power grids, water supply, and telecommunications. 2. The National Critical Information Infrastructure Protection Centre (NCIIPC) is responsible for safeguarding critical information infrastructure. Which of the statements given above is/are correct?

  1. (a) 1 only
  2. (b) 2 only
  3. (c) Both 1 and 2
  4. (d) Neither 1 nor 2

Answer: (c) Both 1 and 2

Statements 1 and 3 are correct, so the answer is (b) 1 and 3. Statement 1 is right because critical infrastructure covers vital services like power grids, water supply, and telecom. Statement 3 is right because the government has named several key sectors as critical. The real body that protects critical information infrastructure is the NCIIPC (National Critical Information Infrastructure Protection Centre). The NCIIPC works under the NTRO (National Technical Research Organisation), which reports to the Prime Minister's Office, not under the IT ministry.

More Internal Security topics

This page shows 12 of 278 questions on this topic. The full set, with progress tracking and five agent perspectives per question, is in the JupiteX app — browse the exam catalogue or browse the Learn library.