professional ethics

Cybersecurity Provisions in Pakistan MCQs

Cybersecurity_Pakistan_Legal_MCQs judiciary

100 questions

  1. Question 1 of 100

    A type of malware that can self-replicate and spread across networks WITHOUT needing to attach itself to another program is called a:

  2. Question 2 of 100

    The process of converting readable data (plaintext) into an unreadable format (ciphertext) to protect it from unauthorized access is called:

  3. Question 3 of 100

    The fundamental right to privacy in Pakistan is primarily grounded in which Article of the Constitution?

  4. Question 4 of 100

    The organized approach to addressing and managing the aftermath of a security breach or cyberattack is known as:

  5. Question 5 of 100

    Which of the following is generally recommended as a basic cybersecurity hygiene practice for individuals?

  6. Question 6 of 100

    The Electronic Transactions Ordinance, 2002 amended which older law to formally allow the admissibility of electronic documents as evidence in Pakistani courts?

  7. Question 7 of 100

    A one-way mathematical function that converts data into a fixed-length string of characters, commonly used to verify data integrity, is called a:

  8. Question 8 of 100

    Which of the following is generally recommended when using public Wi-Fi networks (e.g., in a cafe or airport) to reduce cybersecurity risk?

  9. Question 9 of 100

    Software designed to detect, prevent, and remove malicious software from a computer system is generically called:

  10. Question 10 of 100

    A type of malware that replicates itself by attaching to other programs and requires human action (like opening a file) to spread is called a:

  11. Question 11 of 100

    An attack in which an attacker systematically tries many password combinations until the correct one is found is called a:

  12. Question 12 of 100

    In information security, 'availability' primarily refers to:

  13. Question 13 of 100

    Phishing conducted via voice calls, often impersonating banks or officials, is commonly referred to as:

  14. Question 14 of 100

    The framework of the draft Personal Data Protection Bill, 2023 is generally described as being modeled on which major international data protection law?

  15. Question 15 of 100

    Under the draft Personal Data Protection Bill, 2023, personal data is generally categorized into how many tiers of increasing sensitivity?

  16. Question 16 of 100

    What is 'malware' a general term for?

  17. Question 17 of 100

    Under the draft Personal Data Protection Bill, an entity that determines the purposes and means of processing personal data is referred to as a:

  18. Question 18 of 100

    Software programs that display unwanted advertisements, sometimes bundled with legitimate downloads, are known as:

  19. Question 19 of 100

    In information security, 'integrity' primarily refers to:

  20. Question 20 of 100

    Which of the following is a key practical benefit the Electronic Transactions Ordinance, 2002 provided for Pakistan's economy?

  21. Question 21 of 100

    Under Section 41 of the Electronic Transactions Ordinance, 2002, a person generally cannot be compelled to disclose:

  22. Question 22 of 100

    In information security, 'confidentiality' primarily refers to:

  23. Question 23 of 100

    The padlock icon and 'https://' prefix in a browser's address bar generally indicate that a website is using which security protocol to encrypt the connection?

  24. Question 24 of 100

    Under the Payment Systems and Electronic Fund Transfers Act, 2007, primary regulatory oversight of electronic payment systems in Pakistan rests with:

  25. Question 25 of 100

    A security threat originating from within an organization, such as a disgruntled employee misusing authorized access, is known as an:

  26. Question 26 of 100

    Which Pakistani law was the first major legislation to give legal recognition to electronic documents, records, and signatures?

  27. Question 27 of 100

    In which month and year was Pakistan's National Cyber Security Policy formally approved by the Cabinet?

  28. Question 28 of 100

    The Pakistan Telecommunication Authority (PTA) was established under which law?

  29. Question 29 of 100

    Under the Electronic Transactions Ordinance, 2002, a stronger, cryptographically verifiable form of electronic signature -- attracting a legal presumption of authenticity -- is termed a(n):

  30. Question 30 of 100

    Which of the following best describes the overall relationship between Pakistan's various cyber-related laws (ETO 2002, PSEFTA 2007, and cybercrime legislation)?

  31. Question 31 of 100

    Before the enactment of specific cybercrime legislation, offences like online fraud or forgery of electronic documents in Pakistan were generally prosecuted under which general criminal law?

  32. Question 32 of 100

    The broad practice of manipulating people into divulging confidential information or performing actions that compromise security is known as:

  33. Question 33 of 100

    A digital signature is primarily used to verify:

  34. Question 34 of 100

    Pakistan's National Cyber Security Policy, 2021 was formally approved by the Federal Cabinet, and issued by which Ministry?

  35. Question 35 of 100

    The National Centre for Cyber Security (NCCS), established in 2018 as a research and development body, is a joint initiative involving which institutions?

  36. Question 36 of 100

    A fraudulent scheme in which an attacker impersonates a trusted business contact (often via email) to trick an organization into making an unauthorized wire transfer is commonly called:

  37. Question 37 of 100

    The three foundational principles of information security -- often called the CIA triad -- are:

  38. Question 38 of 100

    Under Section 3 of the Electronic Transactions Ordinance, 2002, the core principle established is that:

  39. Question 39 of 100

    A server that acts as an intermediary between a user's device and the internet, often used for privacy or content filtering, is called a:

  40. Question 40 of 100

    Which of the following statements about Pakistan's data protection landscape is most accurate?

  41. Question 41 of 100

    The State Bank of Pakistan issues cybersecurity-related regulatory circulars and frameworks primarily aimed at:

  42. Question 42 of 100

    Under the National Cyber Security Policy, 2021, a cyberattack against Pakistan's critical infrastructure is characterized as:

  43. Question 43 of 100

    The process of regularly copying data to a separate location so it can be restored in case of loss or attack is called:

  44. Question 44 of 100

    An attack that floods a system, server, or network with excessive traffic to make it unavailable to legitimate users is known as a:

  45. Question 45 of 100

    Encryption that uses a PAIR of different keys -- a public key and a private key -- is known as:

  46. Question 46 of 100

    The Electronic Transactions Ordinance, 2002 was promulgated during whose presidency?

  47. Question 47 of 100

    Which of the following is an example of 'sensitive personal data' as typically categorized under modern data protection frameworks (including Pakistan's draft bill)?

  48. Question 48 of 100

    Which of the following best describes 'shoulder surfing' as a security risk?

  49. Question 49 of 100

    The National Cyber Security Policy, 2021 primarily aims to protect Pakistan's:

  50. Question 50 of 100

    A decoy system deliberately set up to attract and study attackers, diverting them from real targets, is known as a:

  51. Question 51 of 100

    A piece of malicious code that lies dormant until triggered by a specific event or date is known as a:

  52. Question 52 of 100

    Prior to 2024, cybercrime complaints in Pakistan were primarily investigated by which body under the Federal Investigation Agency (FIA)?

  53. Question 53 of 100

    Which of the following is generally considered a core objective shared across Pakistan's various cybersecurity-related laws and policies?

  54. Question 54 of 100

    An attack in which a malicious actor secretly intercepts and possibly alters communication between two parties who believe they are directly communicating with each other is called a:

  55. Question 55 of 100

    Under the draft Personal Data Protection Bill, 2023, which category of data is proposed to be subject to the strictest localization requirement, requiring processing exclusively on servers within Pakistan?

  56. Question 56 of 100

    A network of compromised, internet-connected devices controlled remotely by an attacker, often used for large-scale attacks, is called a:

  57. Question 57 of 100

    Malware that encrypts a victim's files and demands payment for their release is known as:

  58. Question 58 of 100

    A phishing attack specifically targeting high-profile individuals such as executives or senior officials is called:

  59. Question 59 of 100

    A service that creates an encrypted, private connection over a public network, often used to protect data and mask a user's IP address, is called a:

  60. Question 60 of 100

    The authorized, simulated cyberattack conducted to evaluate an organization's security posture is known as:

  61. Question 61 of 100

    An isolated, controlled environment used to safely run and analyze suspicious code without risking the host system is called a:

  62. Question 62 of 100

    As of the most recent available information, Pakistan's comprehensive data protection legislation, the Personal Data Protection Bill, is:

  63. Question 63 of 100

    A network security device or software that monitors and filters incoming/outgoing traffic based on predetermined security rules is called a:

  64. Question 64 of 100

    Under the Electronic Transactions Ordinance, 2002, entities that issue digital certificates to verify the identity of parties in electronic transactions are known as:

  65. Question 65 of 100

    Malicious software that hides its presence and provides an attacker with continued privileged access to a system is known as a:

  66. Question 66 of 100

    Authentication based on unique physical characteristics, such as fingerprints or facial recognition, is known as:

  67. Question 67 of 100

    An attack that exploits a previously unknown software vulnerability, for which no patch yet exists, is called a:

  68. Question 68 of 100

    The old Telegraph Act, 1885, historically relevant to interception of communications, has in modern Pakistan been substantially supplemented in the surveillance/interception context by which more recent law?

  69. Question 69 of 100

    A system designed to monitor network traffic for suspicious activity and alert administrators is known as an:

  70. Question 70 of 100

    The fraudulent practice of sending emails that appear to be from reputable sources in order to trick individuals into revealing sensitive information is called:

  71. Question 71 of 100

    Which of the following is explicitly listed as an objective of the National Cyber Security Policy, 2021?

  72. Question 72 of 100

    Under general cybersecurity best practice, why is it recommended to enable automatic software updates on devices?

  73. Question 73 of 100

    The practice of applying updates released by software vendors to fix known vulnerabilities is known as:

  74. Question 74 of 100

    Software that secretly monitors a user's activity and gathers information without their consent is called:

  75. Question 75 of 100

    A highly targeted phishing attack aimed at a specific individual or organization, often using personalized information, is called:

  76. Question 76 of 100

    Encryption that uses the SAME key for both encrypting and decrypting data is known as:

  77. Question 77 of 100

    Malware that disguises itself as legitimate software to trick users into installing it is known as a:

  78. Question 78 of 100

    A malicious program that records a user's keystrokes to steal passwords and sensitive data is known as a:

  79. Question 79 of 100

    Which regulatory body in Pakistan is primarily responsible for licensing telecom operators and Internet Service Providers (ISPs)?

  80. Question 80 of 100

    Under Section 7 of the Electronic Transactions Ordinance, 2002, a legal requirement for a signature is satisfied where:

  81. Question 81 of 100

    An attack technique that inserts malicious code into a database query field to manipulate or extract data from a website's database is known as:

  82. Question 82 of 100

    Phishing conducted via SMS text messages is commonly referred to as:

  83. Question 83 of 100

    The security principle stating that a user should be granted only the minimum access necessary to perform their job is known as the:

  84. Question 84 of 100

    The Personal Data Protection Bill, 2023 proposes the establishment of which regulatory body to oversee data protection compliance?

  85. Question 85 of 100

    A security process that requires a user to provide two or more distinct forms of verification before gaining access is known as:

  86. Question 86 of 100

    Which of the following is generally considered a WEAK password practice?

  87. Question 87 of 100

    Which government body is responsible for coordinating Pakistan's official national-level response to major cybersecurity incidents, established as a formal national CERT in 2024?

  88. Question 88 of 100

    The National Cyber Security Policy, 2021 emphasizes establishing protection and information-sharing mechanisms at all levels, commonly organized around which type of response units?

  89. Question 89 of 100

    When a Denial-of-Service attack is launched simultaneously from multiple compromised devices, it is called a:

  90. Question 90 of 100

    In 2024, a new specialized agency was established to replace the FIA's Cyber Crime Wing for investigating cybercrime in Pakistan. What is this agency called?

  91. Question 91 of 100

    An attack technique in which malicious scripts are injected into otherwise trusted websites, later executing in a victim's browser, is known as:

  92. Question 92 of 100

    Which Pakistani law governs the regulation of payment systems and electronic fund transfers, including obligations for banks and payment service providers?

  93. Question 93 of 100

    Which of the following best distinguishes a 'data controller' from a 'data processor' under modern data protection frameworks (as reflected in Pakistan's draft bill)?

  94. Question 94 of 100

    Under the National Cyber Security Policy, 2021, which type of infrastructure receives special mandated protection through national security standards?

  95. Question 95 of 100

    Which Ministry drafted and finalized the Personal Data Protection Bill, 2023?

  96. Question 96 of 100

    Which Pakistani authority is primarily responsible for safeguarding the security of citizens' data held in the national identity database (CNIC records)?

  97. Question 97 of 100

    Redirecting a website's traffic to a fraudulent, look-alike site (often by corrupting DNS records) is known as:

  98. Question 98 of 100

    Under the Electronic Transactions Ordinance, 2002, which regulatory body was designated to license and regulate Certification Service Providers?

  99. Question 99 of 100

    Small text files stored by a web browser that track user activity and preferences across websites are known as:

  100. Question 100 of 100

    A prolonged, targeted cyberattack in which an intruder gains unauthorized access to a network and remains undetected for an extended period is known as a(n):

Question 1 / 100

0 / 100 answered