UPSC CSE Prelims
Cyber Security Framework Previous Year Questions (PYQs)
Practice solved questions for Cyber Security Framework with detailed step-by-step solutions, key insights, and trend analysis for UPSC CSE PRELIMS.
Solved Previous Year Questions
Filter & practice questions topic-wise
In India, the term “Public Key Infrastructure” is used in the context of
Detailed Explanation:
Answer: Option 1 — Digital security infrastructure
Public Key Infrastructure (PKI) is a comprehensive framework used specifically for digital security infrastructure in India. It enables secure electronic communication and transactions through digital certificates, certificate authorities, and cryptographic key pairs (public and private keys), ensuring authentication, confidentiality, integrity, and non-repudiation of digital data.
📝 Short Notes: Public Key Infrastructure (PKI)
- Definition: PKI is a set of roles, policies, hardware, software, and procedures needed to create, manage, distribute, use, store, and revoke digital certificates and manage public-key encryption.
- Components: Includes Certificate Authority (CA), Registration Authority (RA), digital certificates, certificate repositories, and certificate revocation lists (CRL).
- Function: Uses asymmetric cryptography with a pair of keys - public key (shared openly) and private key (kept secret) for encryption and digital signatures.
- Applications in India: Used in e-governance initiatives, digital signatures, secure email, online banking, e-commerce, and Aadhaar-based authentication.
- Controller of Certifying Authorities (CCA): Under the IT Act 2000, CCA is the authority to license and regulate Certifying Authorities in India.
- Benefits: Ensures data confidentiality, integrity, authentication, and non-repudiation in digital communications and transactions.
Consider the following statements: A digital signature is
- an electronic record that identifies the certifying authority issuing it
- used to serve as a proof of identity of an individual to access information or server on Internet
- an electronic method of signing an electronic document and ensuring that the original content is unchanged
Which of the statements given above is/are correct?
Detailed Explanation:
Answer: Option 3 — 3 only
A digital signature is a cryptographic mechanism used to authenticate the identity of the sender and ensure that the content of an electronic document has not been altered after signing. Only statement 3 correctly captures this fundamental purpose.
❌ Statement 1 – Incorrect: A digital signature does not identify the certifying authority; instead, it uses a digital certificate issued by a Certificate Authority (CA) to verify the signer's identity, but the signature itself is created by the signer's private key.
❌ Statement 2 – Incorrect: Digital signatures are primarily used for ensuring document integrity and authenticity, not for accessing information or servers on the Internet; access control typically relies on usernames, passwords, tokens, or biometric authentication.
✅ Statement 3 – Correct: A digital signature is indeed an electronic method of signing documents that ensures non-repudiation and integrity by creating a unique cryptographic hash that detects any changes to the original content.
📝 Short Notes: Digital Signatures
- Definition: A digital signature is a cryptographic technique that validates the authenticity and integrity of electronic messages, documents, or software.
- Technology: Based on Public Key Infrastructure (PKI) using asymmetric cryptography—a private key to sign and a public key to verify.
- Key Functions: Authentication (verifies sender identity), Integrity (detects alterations), and Non-repudiation (sender cannot deny signing).
- Process: A hash of the document is created and encrypted with the signer's private key; recipients decrypt it with the public key to verify authenticity.
- Legal Status in India: Digital signatures are legally recognized under the Information Technology Act, 2000, and have the same validity as handwritten signatures.
- Certificate Authority (CA): Trusted third parties (like NIC, eMudhra) issue digital certificates that bind a public key to an individual or organization.
- Common Uses: E-filing of tax returns, online banking, e-governance services, legal documents, and software distribution.
🧐 Not Sure What to Study Next?
Get a personalised study plan based on your goals, time and revision needs.
Related Topics in Science & Technology
Frequently Asked Questions
Common questions about Cyber Security Framework in UPSC CSE PRELIMS