Master10
Cybersecurity & Digital Safety15 Concepts & Facts

Cybersecurity, Cryptography, Malware Threats & Information Technology Act 2000 GK Questions & Answers

Reviewed by the Master10 Editorial Board for accuracy, clarity and competitive-exam relevance.Editorial Policy
Cybersecurity encompasses the technical protocols, operational processes, and legal frameworks designed to protect computer networks, digital infrastructure, and sensitive data from malicious intrusion or destruction. The contemporary digital threat matrix features diverse malware classifications: viruses that attach to legitimate executable host programs, autonomous worms that self-replicate across network vulnerabilities without host intervention, and Trojan horses delivering hidden malicious payloads. Modern sophisticated attacks include cryptographic ransomware extortion campaigns, exemplified by the global WannaCry outbreak in 2017, and zero-click spyware such as Pegasus. Common attack vectors range from social engineering phishing schemes and Man-in-the-Middle (MitM) packet interceptions to Structured Query Language (SQL) database injections and Distributed Denial of Service (DDoS) botnet assaults.

Data integrity and confidentiality rely upon mathematical cryptographic systems divided into symmetric and asymmetric techniques. Symmetric algorithms, such as the Advanced Encryption Standard (AES) and Data Encryption Standard (DES), employ a single shared secret key for encryption and decryption, offering rapid execution for bulk data. Conversely, asymmetric cryptography, such as Rivest-Shamir-Adleman (RSA) and Elliptic Curve Cryptography (ECC), utilizes a mathematically linked public-private key pair, forming the operational foundation of Public Key Infrastructure (PKI) and legally binding digital signatures. Complementing encryption, cryptographic hash functions like Secure Hash Algorithm 256-bit (SHA-256) generate fixed-length deterministic digests to verify data integrity and prevent unauthorized alteration during transit or storage.

In India, cyberspace governance is codified under the Information Technology Act, 2000, enacted on June 9, 2000, modeled upon the 1996 UNCITRAL Model Law on Electronic Commerce. The statute prescribes civil penalties for unauthorized computer damage under Section 43, penalizes computer-related offences including hacking under Section 66, and regulates state surveillance interception under Section 69. Notably, the Supreme Court struck down Section 66A in the landmark "Shreya Singhal v. Union of India" (2015) decision for violating free speech under Article 19(1)(a). Under Section 70, Critical Information Infrastructure is safeguarded by the National Critical Information Infrastructure Protection Centre (NCIIPC), while Section 70B designates the Indian Computer Emergency Response Team (CERT-In) under MeitY as the national nodal agency for incident response.

Key Concepts & Self-Assessment15 Key Facts

Review key Cybersecurity, Cryptography, Malware Threats & Information Technology Act 2000 exam facts and rate your mastery to track revision.

Progress: 0/15 Rated 0 Mastered 0 Review Later
#1
Malware classifications include viruses (requiring host execution), worms (self-propagating), Trojans (disguised payloads), and ransomware (cryptographic extortion).
#2
Asymmetric cryptography utilizes a public key for encryption and a private key for decryption, underpinning RSA algorithms, PKI, and digital signatures.
#3
The Information Technology Act, 2000 provides statutory legal backing in India, penalizing damage to computer systems (Section 43) and hacking (Section 66).
#4
Section 70B of the IT Act, 2000 establishes CERT-In under MeitY as the national nodal agency for cybersecurity incident response and alerts.
#5
The National Critical Information Infrastructure Protection Centre (NCIIPC), created under Section 70A, protects strategic digital assets vital to national security.
#6
Symmetric encryption employs a single shared secret key for both encryption and decryption, exemplified by the Advanced Encryption Standard (AES) with key lengths of 128, 192, and 256 bits.
#7
The Supreme Court of India in Shreya Singhal v. Union of India (2015) struck down Section 66A of the IT Act, 2000 as unconstitutional for violating freedom of speech under Article 19(1)(a).
#8
Section 66E of the IT Act penalizes violation of bodily privacy through unauthorized transmission of private images, while Section 66F prescribes life imprisonment for cyber terrorism.
#9
Phishing attacks use deceptive electronic communications mimicking trustworthy entities to steal sensitive user credentials, while spear-phishing targets specific individuals or corporate executives.
#10
A Distributed Denial of Service (DDoS) attack overwhelms targeted servers with network traffic from compromised botnets, rendering online services unavailable to legitimate users.
#11
The Digital Personal Data Protection Act (DPDPA), 2023, governs processing of digital personal data in India, establishing the Data Protection Board of India and penalties up to 250 crore rupees.
#12
Zero-day exploits target undisclosed software security vulnerabilities unknown to the software vendor, leaving systems defenseless until a security patch is developed and deployed.
#13
Man-in-the-Middle (MitM) attacks occur when an unauthorized attacker intercepts, decrypts, or alters communications between two parties, mitigated by Transport Layer Security (TLS/HTTPS).
#14
The Cyber Swachhta Kendra (Botnet Cleaning and Malware Analysis Centre) is operated by CERT-In to provide free malware removal tools and secure citizen computing devices.
#15
Multi-Factor Authentication (MFA) requires users to provide two or more verification factors: something you know (password), something you have (OTP/token), or something you are (biometrics).

Subject Specialist Commentary

Analytical perspective & practical exam advice from the Master10 academic board

Educator's Insight
Cybersecurity encompasses the technologies, processes, and legal rules built to protect computer networks and data from malicious digital attacks. Modern threats range from self-replicating worms and deceptive phishing links to ransomware that encrypts corporate databases. To safeguard data transmission, systems rely on cryptography, using symmetric encryption with a single shared secret key or asymmetric encryption with public and private key pairs. In India, the Information Technology Act of 2000 provides the primary legal architecture penalizing cybercrimes.
For UPSC Prelims and mains GS-3 papers, focus on cybersecurity agencies and landmark legal rulings. A high-frequency question trap asks about Section 66A of the IT Act; remember that the Supreme Court struck it down in the 2015 Shreya Singhal case for violating free speech under Article 19(1)(a). In exam questions, distinguish between CERT-In, which handles national emergency incident responses, and NCIIPC under Section 70A, which specifically shields critical national infrastructure.

Related Knowledge Topics to Discover

Indian Polity & Constitution
Indian Constitution & Fundamental Rights

Comprehensive Indian Constitution and Fundamental Rights GK questions. Study Articles 12 to 35, Right to Equality, Right to Freedom, Writ jurisdictions (Habeas Corpus, Mandamus), and landmark Supreme Court rulings.

Explore Topic
Indian Polity & Constitution
Supreme Court & Indian Judicial System

Explore Supreme Court of India GK questions and answers. Learn Articles 124 to 147, original and appellate jurisdictions, advisory powers (Article 143), writ powers (Article 32), and landmark constitutional rulings.

Explore Topic
Indian Economy
National Income Accounting: GDP, GNP, NNP & GVA

Master National Income Accounting GK questions and answers. Study Gross Domestic Product (GDP), Gross National Product (GNP), Net National Product (NNP), Gross Value Added (GVA), factor cost vs market price, and CSO/NSO methodology.

Explore Topic

Looking for more GK practice?

Explore 52,789+ questions across 65 General Knowledge categories.

Open Interactive Search