UPSC Prelims Practice Questions — CBSE invited ethical hacker to plug security gaps in IT system

Q1. With reference to the recent (2026) cybersecurity incident involving the CBSE On-Screen Marking (OSM) portal and the earlier JEE (Advanced) portal incident, consider the following statements: 1. In contrast to the JEE (Advanced) portal incident — where the conducting IIT team publicly acknowledged the flaw and fixed it — CBSE initially denied any breach of its data security before later acknowledging the OSM vulnerabilities. 2. The OSM vulnerabilities were first reported to CERT-In months before public disclosure, whereas the JEE (Advanced) incident was first disclosed directly through social media without any prior intimation to CERT-In. 3. The IIT expert team that camped at CBSE Headquarters to patch the OSM portal was drawn from IIT Madras and IIT Kanpur. Which of the statements given above is/are correct?

  1. In contrast to the JEE (Advanced) portal incident — where the conducting IIT team publicly acknowledged the flaw and fixed it — CBSE initially denied any breach of its data security before later acknowledging the OSM vulnerabilities.
  2. The OSM vulnerabilities were first reported to CERT-In months before public disclosure, whereas the JEE (Advanced) incident was first disclosed directly through social media without any prior intimation to CERT-In.
  3. The IIT expert team that camped at CBSE Headquarters to patch the OSM portal was drawn from IIT Madras and IIT Kanpur.
  • A. 1 and 3 only
  • B. 2 and 3 only
  • C. 1 and 2 only
  • D. 1, 2 and 3

Q2. Which one of the following is the nodal national agency for incident response on cybersecurity matters in India, to which vulnerabilities such as those in the CBSE On-Screen Marking portal are required to be reported?

  • A. National Critical Information Infrastructure Protection Centre (NCIIPC)
  • B. Indian Computer Emergency Response Team (CERT-In)
  • C. National Technical Research Organisation (NTRO)
  • D. National Cyber Coordination Centre (NCCC)

Q3. As per the CERT-In Directions issued on 28 April 2022 under the Information Technology Act, 2000 — which are the operative framework invoked in the CBSE OSM portal disclosure — within how many hours of noticing or being notified of a cyber incident must service providers, intermediaries, data centres, body corporates and government organisations mandatorily report it to CERT-In?

  • A. 2 hours
  • B. 6 hours
  • C. 24 hours
  • D. 72 hours

Q4. The Indian Computer Emergency Response Team (CERT-In), which received the initial report of the CBSE OSM portal vulnerabilities, derives its statutory authority exclusively from which one of the following provisions?

  • A. Section 43A of the Information Technology Act, 2000
  • B. Section 66F of the Information Technology Act, 2000
  • C. Section 70B of the Information Technology Act, 2000
  • D. Section 69A of the Information Technology Act, 2000