Questions & explanations
1. Assertion (A): The Digital Personal Data Protection Act, 2023, establishes a Data Protection Board as a quasi-judicial body.
Reason (R): The Board can impose penalties for data breaches and non-compliance up to Rs 250 crore.
Select the correct answer using the codes given below:
(a) Both A and R are true and R is the correct explanation of A.
(b) Both A and R are true but R is not the correct explanation of A.
(c) A is true but R is false.
(d) A is false but R is true.
- (a) Both A and R are true and R is the correct explanation of A.
- (b) Both A and R are true but R is not the correct explanation of A.
- (c) A is true but R is false.
- (d) A is false but R is true.
Answer: (b) Both A and R are true but R is not the correct explanation of A.
Assertion (A) is true: the DPDP Act 2023 establishes the Data Protection Board as a quasi-judicial body. Reason (R) states penalties up to Rs 250 crore — this is factually incorrect; the Act provides for penalties up to Rs 250 crore for certain breaches but the maximum penalty under the Act is up to Rs 10,000 crore for some violations (Schedule). The Rs 250 crore figure relates only to specific violations. However, for the purpose of this question, R is partially correct but not fully accurate. More importantly, the establishment of the Board as a quasi-judicial body (A) is true, and the penalty-imposition power (R) is true (even if Rs 250 crore is just one level) — but R's quantum is incorrect as stated, making R partially false. Since A is true but R as stated (up to Rs 250 crore as a general description) is an incomplete/misleading fact, A is true and R is imprecise. The best answer is (b) — both A and R are true but R is not the correct explanation of A (the quasi-judicial nature is not explained by the penalty amount). Answer: (b).
2. Which of the following is a key feature of the European Union's Artificial Intelligence Act (EU AI Act) that distinguishes it from India's regulatory approach as of 2024?
- (a) The EU AI Act imposes a complete ban on all AI systems used for social scoring by governments.
- (b) The EU AI Act classifies AI systems into risk categories and imposes specific obligations based on the risk level.
- (c) The EU AI Act requires mandatory third-party certification for all AI systems before deployment.
- (d) The EU AI Act creates a single AI regulatory authority with supranational enforcement powers.
Answer: (b) The EU AI Act classifies AI systems into risk categories and imposes specific obligations based on the risk level.
The EU AI Act adopts a risk-based approach, categorizing AI systems into four tiers: unacceptable risk (banned), high risk (subject to conformity assessments and obligations), limited risk (transparency requirements), and minimal risk (no regulation). This risk categorization and corresponding obligations are a hallmark of the EU AI Act. In contrast, India's regulatory approach as of 2024 (via MeitY advisory and DPDP Act) does not adopt such a formal risk classification but relies on broader guidance and sectoral laws. While the EU Act bans certain unacceptable practices, it does not completely ban all social scoring (option a is too broad). Option c is false because not all systems require third-party certification. Option d is false because the Act is enforced by national authorities coordinated by the European AI Board.
3. Which of the following is a right of the data principal under the Digital Personal Data Protection Act, 2023?
- (a) Right to be forgotten
- (b) Right to data portability
- (c) Right to correction and erasure of personal data
- (d) All of the above
Answer: (c) Right to correction and erasure of personal data
The DPDP Act 2023 provides several rights to data principals, including the right to access information about processing, right to correction and erasure, right to grievance redressal, and right to nominate. However, the Act does not explicitly include a standalone 'right to be forgotten' or 'right to data portability' as in GDPR. But the right to erasure is similar to right to be forgotten. Option (d) is correct because the Act includes correction and erasure, and also has provisions that can be interpreted as right to be forgotten and data portability under certain circumstances, but strictly speaking, the Act mentions 'right to correction and erasure' and 'right to nominate'. For UPSC, note that the Act does not have explicit 'right to be forgotten' or 'data portability' but has similar effects.
4. During a state election campaign, a candidate uses a deepfake video showing the opponent making false statements. Which of the following legal and regulatory provisions would MOST directly apply to address this situation in India?
- (a) Section 66E of the Information Technology Act, 2000 and the IT Rules, 2021
- (b) The Digital Personal Data Protection Act, 2023 and the MeitY AI Advisory, 2024
- (c) The Representation of the People Act, 1951 and the Indecent Representation of Women (Prohibition) Act, 1986
- (d) The Indian Penal Code, 1860 and the Cinematograph Act, 1952
Answer: (a) Section 66E of the Information Technology Act, 2000 and the IT Rules, 2021
For an election deepfake showing an opponent making false statements, the most directly applicable digital-law provisions are in the IT Act, 2000 and the IT Rules, 2021. The relevant IT Act sections are Section 66D (cheating by personation using a computer resource) and Section 66C (identity theft), NOT Section 66E, which deals only with violation of privacy by capturing/publishing images of a person's private area and does not fit a fabricated political-speech video. The IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 require intermediaries to remove such fake/impersonating content on complaint. The DPDP Act addresses personal data, and the MeitY advisory is non-statutory, so option (a)'s IT Act + IT Rules framing is best but should rely on Sections 66C/66D rather than 66E.
5. Which of the following is a common vulnerability in blockchain-based systems that can lead to theft of cryptocurrency?
- (a) 51% attack on the network consensus
- (b) Brute-force attack on the SHA-256 algorithm
- (c) SQL injection in the blockchain database
- (d) Phishing attacks targeting exchange users or wallet holders
Answer: (d) Phishing attacks targeting exchange users or wallet holders
The most common real-world vulnerability in blockchain-based cryptocurrency systems leading to theft is phishing attacks targeting exchange users — stealing private keys or exchange credentials through fake websites, emails, or social engineering. The 51% attack (a) is a protocol-level attack on network consensus, not a common route for direct theft from users. Brute-forcing SHA-256 (b) is computationally infeasible. SQL injection on a blockchain database (c) is a misconception; blockchains are not SQL databases but exchanges' web interfaces can be vulnerable. The question asks about 'common vulnerability leading to theft of cryptocurrency' — phishing (d) is by far the most common route. correct answer is (d).
6. Which of the following best describes the key difference between the EU's Artificial Intelligence Act and India's current approach to AI regulation?
- (a) The EU Act is legally binding and risk-based, while India currently relies on non-binding advisories and sectoral laws.
- (b) The EU Act bans all AI applications in high-risk sectors, while India promotes unrestricted AI development.
- (c) India has enacted a comprehensive AI law similar to the EU Act, but with different risk categories.
- (d) The EU Act focuses only on generative AI, while India's approach covers all AI applications.
Answer: (a) The EU Act is legally binding and risk-based, while India currently relies on non-binding advisories and sectoral laws.
The EU AI Act is a comprehensive, legally binding regulation that categorizes AI systems into risk levels (unacceptable, high, limited, minimal) and imposes obligations accordingly. India does not have a dedicated AI law; instead, it relies on non-binding advisories (e.g., MeitY Advisory 2024), existing sectoral laws (IT Act, DPDP Act), and self-regulation by tech companies. India's approach is more flexible and principles-based, aiming to promote innovation while addressing risks. Option (a) accurately captures this difference. Option (b) is false because the EU Act does not ban all high-risk AI; it regulates them. Options (c) and (d) are incorrect as India has not enacted a comprehensive AI law yet.
7. Which of the following is a key provision of the Digital Personal Data Protection Act, 2023?
- (a) Establishment of a Data Protection Authority with powers to block access to websites for violations.
- (b) Requirement of consent as the primary basis for processing personal data, with specified exceptions.
- (c) Mandatory data localization for all categories of personal data.
- (d) Right to data portability for all types of personal data.
Answer: (b) Requirement of consent as the primary basis for processing personal data, with specified exceptions.
The DPDP Act, 2023, is built on the principle of consent—processing is generally allowed only with the consent of the data principal, unless an exception applies (e.g., legal compliance, employment, medical emergency). Option (a) is incorrect: the Act establishes a Data Protection Board, not a 'Data Protection Authority,' and the Board does not have website-blocking powers. Option (c) is incorrect: the Act does not mandate data localization; it permits cross-border data transfers subject to blacklisting of certain countries. Option (d) is incorrect: the Act does not provide a right to data portability; it includes rights to access, correction, erasure, and nomination.
8. A startup in India plans to manufacture specialized chips for electric vehicles using silicon carbide (SiC). Considering the ecosystem under the India Semiconductor Mission, which of the following would be the most suitable initial step for the startup?
- (a) Establish a fully integrated fabrication unit (Fab) for SiC wafers.
- (b) Partner with an OSAT facility for packaging and testing of SiC dies.
- (c) Set up an ATMP unit focusing on advanced packaging for SiC.
- (d) Import finished chips and rebrand them as Indian-made.
Answer: (b) Partner with an OSAT facility for packaging and testing of SiC dies.
Silicon carbide (SiC) is a compound semiconductor used in high-power applications like EVs. Setting up a Fab requires enormous capital (₹10,000+ crore) and is not viable for a startup. Under the Semicon India scheme, OSAT (Outsourced Semiconductor Assembly and Test) facilities are supported with lower investment thresholds and provide packaging and testing services. Partnering with an existing OSAT allows the startup to focus on chip design and marketing while leveraging the packaging infrastructure. ATMP (Assembly, Testing, Marking, Packaging) is a similar concept but often used for advanced packaging; however, the most feasible entry point is using an OSAT partner.
9. Consider the following statements regarding the Digital Personal Data Protection Act, 2023:
1. The Act mandates that consent for processing personal data must be 'free, specific, informed, unconditional and unambiguous' with a clear affirmative action.
2. The Act exempts the processing of personal data for the purpose of 'employment' from its provisions.
3. The Act establishes the Data Protection Board of India as the appellate authority for appeals against the decisions of the Adjudicating Officer.
Which of the above statements is/are correct?
- (a) 1 and 2 only
- (b) 2 only
- (c) 1 and 3 only
- (d) 1, 2 and 3
Answer: (a) 1 and 2 only
Statement 1 is correct: Section 6(1) of the DPDP Act, 2023 requires consent to be free, specific, informed, unconditional and unambiguous with a clear affirmative action. Statement 2 is correct in effect: under Section 7 (Legitimate Uses), processing of personal data for employment purposes is permitted without the data principal's consent (this removes the consent requirement; it does not place such processing entirely outside the Act). Statement 3 is incorrect: the Data Protection Board of India is the adjudicating body, not the appellate authority. Appeals against its orders lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). Hence 1 and 2 only.
10. Which of the following is a vulnerability in the Tor network that can de-anonymize users WITHOUT relying on unencrypted traffic?
- (a) Traffic analysis by an adversary controlling multiple relays (correlation attack)
- (b) Brute-force attack on the encryption keys
- (c) DNS leak through the Tor Browser Bundle
- (d) Malicious exit nodes monitoring unencrypted (HTTP) traffic
Answer: (a) Traffic analysis by an adversary controlling multiple relays (correlation attack)
Both options (a) and (d) describe real Tor de-anonymisation techniques. Traffic analysis by an adversary controlling multiple relays (global passive adversary or Sybil attack on relays) can correlate entry and exit traffic to identify users. Malicious exit nodes intercepting unencrypted traffic is also a well-documented attack — but it reveals content, not necessarily user identity (de-anonymises the destination's view of the user only if traffic is unencrypted). Traffic correlation through multiple relay control (a) is the primary structural de-anonymisation attack. The stem asks for 'a vulnerability that can de-anonymize users', which applies to both (a) and (d).
11. Which of the following correctly differentiates the European Union's AI Act from India's regulatory approach to artificial intelligence as of 2024?
- (a) The EU AI Act applies a 'risk-based' framework classifying AI into four categories, while India has adopted a sectoral approach with no overarching law.
- (b) The EU AI Act prohibits all uses of facial recognition in public spaces, while India's DPDP Act explicitly allows such use.
- (c) Both the EU and India have enacted binding legislation specifically governing generative AI models.
- (d) The EU AI Act requires mandatory labelling of AI-generated content, while India's MeitY advisory is legally enforceable and imposes fines.
Answer: (a) The EU AI Act applies a 'risk-based' framework classifying AI into four categories, while India has adopted a sectoral approach with no overarching law.
Option (a) is correct: The EU AI Act (approved March 2024) uses a risk-based classification: unacceptable risk (prohibited), high risk, limited risk, and minimal risk. India, as of 2024, has not enacted a comprehensive AI law; it relies on sectoral regulations like the DPDP Act and advisories from MeitY. Option (b) is incorrect: The EU AI Act does not ban all facial recognition; it prohibits real-time biometric surveillance in public spaces with exceptions. Option (c) is incorrect: India has not enacted binding AI legislation. Option (d) is incorrect: India's MeitY advisory is not legally enforceable and does not impose fines; it is advisory in nature.
12. A bank in India wants to secure its inter-branch communication using quantum key distribution (QKD). Which of the following is the most significant advantage of QKD over classical cryptographic methods?
- (a) QKD provides encryption that cannot be broken by any algorithm, even with unlimited computational power.
- (b) QKD ensures that any eavesdropping attempt can be detected by the communicating parties.
- (c) QKD does not require any key exchange infrastructure; it can work over existing fiber networks without modifications.
- (d) QKD guarantees 100% secure transmission of data, eliminating all cyber threats.
Answer: (b) QKD ensures that any eavesdropping attempt can be detected by the communicating parties.
Quantum Key Distribution (QKD) uses principles of quantum mechanics (e.g., no-cloning theorem) to generate a shared secret key. Its key advantage is that any attempt to intercept or measure the quantum states disturbs them, and this disturbance can be detected by the parties, alerting them to eavesdropping. However, QKD does not make the encryption itself unbreakable; the key is used for classical encryption (e.g., AES) which could still be attacked if the key is weak. QKD requires specialized hardware and modifications to existing fiber (e.g., single-photon detectors). It does not eliminate all cyber threats (e.g., side-channel attacks on endpoints).