UPSC Prelims Practice Questions — CERT-In: India’s Frontline Defender against Cyber Threats
Q1. With reference to the statutory basis of CERT-In, consider the following statements:
1. CERT-In is the national nodal agency for cyber security incident response under Section 70B of the IT Act, 2000.
2. Section 70B was inserted into the IT Act, 2000 by the Information Technology (Amendment) Act, 2008.
3. Non-compliance with a direction issued by CERT-In can attract imprisonment up to one year and/or a fine of up to one lakh rupees.
4. Directions issued by CERT-In under Section 70B are recommendatory and legally non-binding on service providers.
Which of the above is/are correctly identified?
- CERT-In is the national nodal agency for cyber security incident response under Section 70B of the IT Act, 2000.
- Section 70B was inserted into the IT Act, 2000 by the Information Technology (Amendment) Act, 2008.
- Non-compliance with a direction issued by CERT-In can attract imprisonment up to one year and/or a fine of up to one lakh rupees.
- Directions issued by CERT-In under Section 70B are recommendatory and legally non-binding on service providers.
- A. 1, 2 and 3
- B. 1 and 4 only
- C. 2, 3 and 4
- D. 1, 2, 3 and 4
Q2. CERT-In functions as the national nodal agency for cyber security incident response primarily under which one of the following ministries/authorities?
- A. Ministry of Electronics and Information Technology
- B. Ministry of Home Affairs
- C. National Security Council Secretariat
- D. Ministry of Defence
Q3. Which one of the following statements best describes the primary statutory mandate of CERT-In?
- A. It is the national agency for collection, analysis and dissemination of information on cyber incidents and for coordinating incident response.
- B. It is the national nodal agency for the protection of Critical Information Infrastructure.
- C. It is the nodal agency for the investigation and prosecution of cybercrimes against individuals.
- D. It is the authority that coordinates the national cyber security strategy across all ministries.
Q4. Under CERT-In's 2022 Cyber Security Directions, covered entities are required to synchronise the clocks of all their ICT systems to the Network Time Protocol (NTP) servers of which one of the following?
- A. National Informatics Centre and National Physical Laboratory
- B. Indian Space Research Organisation
- C. Reserve Bank of India
- D. Telecom Regulatory Authority of India
Q5. Which one of the following best describes the Cyber Swachhta Kendra?
- A. A Botnet Cleaning and Malware Analysis Centre operated by CERT-In that provides free tools to detect and remove malware.
- B. A centre that audits and certifies the security of Critical Information Infrastructure.
- C. A MOOC platform to train police and judicial officers in cybercrime investigation and forensics.
- D. A 24x7 national helpline for reporting financial cyber fraud.
Q6. With reference to the Cyber Swachhta Kendra, consider the following statements:
1. It was launched in 2017 as a Botnet Cleaning and Malware Analysis Centre.
2. It provides free tools for the detection and removal of malicious programmes.
3. It is operated by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs.
4. As of 2025 it covers about 98% of India's digital population.
Which of the above is/are correctly identified?
- It was launched in 2017 as a Botnet Cleaning and Malware Analysis Centre.
- It provides free tools for the detection and removal of malicious programmes.
- It is operated by the Indian Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs.
- As of 2025 it covers about 98% of India's digital population.
- A. 1 and 3 only
- B. 1, 2 and 4
- C. 2, 3 and 4
- D. 1, 2, 3 and 4
Q7. According to the 2026 PIB backgrounder on CERT-In, consider the following figures reported for its 2025 performance:
1. Cyber incidents handled — 29.44 lakh
2. Security alerts issued — 1,530
3. Vulnerability notes issued — 390
4. Advisories issued — 650
Which of the above is/are NOT correctly stated?
- Cyber incidents handled — 29.44 lakh
- Security alerts issued — 1,530
- Vulnerability notes issued — 390
- Advisories issued — 650
- A. 1 and 2
- B. 3 only
- C. 4 only
- D. 2 and 4
Q8. With reference to CERT-In's 2025 performance as reported in the 2026 PIB backgrounder, consider the following statements:
1. CERT-In issued more security alerts than vulnerability notes during 2025.
2. CERT-In issued more advisories than vulnerability notes during 2025.
3. India's cyber-incident response leadership in 2025 was acknowledged by the World Economic Forum, the University of Oxford and France's ANSSI.
Which of the statements given above is/are correct?
- CERT-In issued more security alerts than vulnerability notes during 2025.
- CERT-In issued more advisories than vulnerability notes during 2025.
- India's cyber-incident response leadership in 2025 was acknowledged by the World Economic Forum, the University of Oxford and France's ANSSI.
- A. 1 only
- B. 1 and 2 only
- C. 1 and 3 only
- D. 1, 2 and 3
Q9. Consider the following statements about India's cyber security institutions:
1. NCIIPC is the national nodal agency for the protection of Critical Information Infrastructure under Section 70A of the IT Act.
2. CERT-In is the national nodal agency for cyber security incident response under Section 70B of the IT Act.
3. The Indian Cyber Crime Coordination Centre (I4C) functions under the Ministry of Electronics and Information Technology.
4. NCIIPC is a unit of the National Technical Research Organisation (NTRO).
Which of the above is/are correctly identified?
- NCIIPC is the national nodal agency for the protection of Critical Information Infrastructure under Section 70A of the IT Act.
- CERT-In is the national nodal agency for cyber security incident response under Section 70B of the IT Act.
- The Indian Cyber Crime Coordination Centre (I4C) functions under the Ministry of Electronics and Information Technology.
- NCIIPC is a unit of the National Technical Research Organisation (NTRO).
- A. 1 and 3 only
- B. 1, 2 and 4
- C. 2 and 3 only
- D. 1, 2, 3 and 4
Q10. CERT-In became operational as India's national cyber incident response agency in January 2004. The Cyber Swachhta Kendra (Botnet Cleaning and Malware Analysis Centre) associated with CERT-In was launched how many years after CERT-In became operational?
- A. 9 years
- B. 11 years
- C. 13 years
- D. 15 years