UPSC Prelims Practice Questions — CBSE invited ethical hacker to plug security gaps in IT system
Q1. With reference to the recent (2026) cybersecurity incident involving the CBSE On-Screen Marking (OSM) portal and the earlier JEE (Advanced) portal incident, consider the following statements:
1. In contrast to the JEE (Advanced) portal incident — where the conducting IIT team publicly acknowledged the flaw and fixed it — CBSE initially denied any breach of its data security before later acknowledging the OSM vulnerabilities.
2. The OSM vulnerabilities were first reported to CERT-In months before public disclosure, whereas the JEE (Advanced) incident was first disclosed directly through social media without any prior intimation to CERT-In.
3. The IIT expert team that camped at CBSE Headquarters to patch the OSM portal was drawn from IIT Madras and IIT Kanpur.
Which of the statements given above is/are correct?
- In contrast to the JEE (Advanced) portal incident — where the conducting IIT team publicly acknowledged the flaw and fixed it — CBSE initially denied any breach of its data security before later acknowledging the OSM vulnerabilities.
- The OSM vulnerabilities were first reported to CERT-In months before public disclosure, whereas the JEE (Advanced) incident was first disclosed directly through social media without any prior intimation to CERT-In.
- The IIT expert team that camped at CBSE Headquarters to patch the OSM portal was drawn from IIT Madras and IIT Kanpur.
- A. 1 and 3 only
- B. 2 and 3 only
- C. 1 and 2 only
- D. 1, 2 and 3
Q2. Which one of the following is the nodal national agency for incident response on cybersecurity matters in India, to which vulnerabilities such as those in the CBSE On-Screen Marking portal are required to be reported?
- A. National Critical Information Infrastructure Protection Centre (NCIIPC)
- B. Indian Computer Emergency Response Team (CERT-In)
- C. National Technical Research Organisation (NTRO)
- D. National Cyber Coordination Centre (NCCC)
Q3. As per the CERT-In Directions issued on 28 April 2022 under the Information Technology Act, 2000 — which are the operative framework invoked in the CBSE OSM portal disclosure — within how many hours of noticing or being notified of a cyber incident must service providers, intermediaries, data centres, body corporates and government organisations mandatorily report it to CERT-In?
- A. 2 hours
- B. 6 hours
- C. 24 hours
- D. 72 hours
Q4. The Indian Computer Emergency Response Team (CERT-In), which received the initial report of the CBSE OSM portal vulnerabilities, derives its statutory authority exclusively from which one of the following provisions?
- A. Section 43A of the Information Technology Act, 2000
- B. Section 66F of the Information Technology Act, 2000
- C. Section 70B of the Information Technology Act, 2000
- D. Section 69A of the Information Technology Act, 2000