Security

Security

137 questions · Fundamental Engineering · 1–50

Practice

Which of the following is multi-factor authentication?

In the context of information security defined by ISO/IEC 27000, which of the following is the property of accuracy and completeness of information assets?

Which of the following is an appropriate description of a Trojan horse?

Which of the following is an example of ransomware?

Company A, a mobile game developer, is developing a new version of its game with a social media plugin that allows users to post their achievements on social media platforms. However, during beta testing, some users point out that posts from the game can bypass their privacy settings, making them visible to the public. Company A understands the risk and decides not to include the social media plugin in their new version of the game. Which of the following is the risk management strategy that Company A is choosing?

Which of the following is an appropriate explanation of CSIRT?

An SQL injection attack caused the SQL statement below to be executed. Which of the following does the SQL statement do? Here, the accounts table contains user account information in each row.

SELECT * FROM accounts WHERE username='1' or '1'='1'; DROP TABLE accounts;

In an information security audit, which of the following is a check item for confirming availability?

An attacker left a USB stick labeled “Next ITPEC exam questions and answers” that contains malware in front of an office, expecting someone to plug it into a PC. Once plugged in, the attacker gains control of the PC. Which of the following types of attack is this?

When X receives a message with a digital signature that uses public key cryptography from Y, which of the following is the key that X uses to verify that the message truly came from Y?

The IP address of server X that is owned by an attacker, is recorded on Company B’s DNS cache server as the IP address corresponding to the FQDN of Company A’s web server. As a result, which of the following are the users that unintentionally connect to server X? Here, the employees of Company A and Company B use their own company’s DNS cache server for name resolution.

When a fraud occurs, all three (3) elements of the “fraud triangle” are believed to exist. Which of the following is the appropriate explanation of an element of the “fraud triangle”?

Which of the following is a function of an IDS?

Which of the following is an appropriate description concerning the timing and purpose of port scanning when an attacker intrudes into a system?

In a system with the configuration and communication services shown in the figure below, which of the following is the most appropriate location for the installation of a WAF as a countermeasure for a vulnerability in a web application? Here, the WAF has no function to encrypt or decrypt communications.

PCPCPCInternetHTTPSAFirewallHTTPSBSSL acceleratorHTTPCWeb serverDService for accessingthe databaseDatabase server

Which of the following is the attack that is classified as DNS cache poisoning?

A given application only has the functions of retrieving and displaying user information from a database that stores such information. When considering information security, which of the following is the appropriate database access right assigned to an account that the application uses to access the database? The names and scopes of rights are listed below.

[The names and scopes of rights]

Reference right:Allows the application to select a recordUpdate right:Allows the application to insert, update, and drop a recordAdministrator right:Allows the application to display, create, alter, and drop a table

Which of the following is a merit in using SaaS?

Which of the following is an appropriate operation for user authentication that uses an IC card and a PIN?

Which of the following is the most effective method of detecting unauthorized changes of the contents of a web server?

Which of the following is the function of a WAF?

Which of the following is an appropriate description concerning SPF for email communication?

Which of the following is an example of a phishing email?

Which of the following bitwise logical operation can be applied in stream cipher between a plain-text and a keystream to produce a cipher-text, and between a ciphertext and the keystream to recover the plaintext?

Which of the following description is an appropriate use of asymmetric encryption to ensure the confidentiality of a message that a sender is going to send to a receiver?

Which type of attack involves intercepting communication between sender and receiver?

Which of the following refers to a technique that is used in a credential stuffing attack?

Which of the following is the name of an attack where manipulation is made to display a malicious website near the top of the results on a search website?

Which of the following is a function of security information and event management (SIEM)?

Which of the following describes a brute force attack aimed at finding the key of symmetric encryption?

Which of the following is a package of unauthorized programs and tools that has functions such as creating a backdoor on a server and hiding the evidence of intrusion inside the server?

Which of the following is a public-key cryptography algorithm whose security depends on the difficulty of factoring extremely large numbers into primes?

Which of the following is an explanation of the timestamp service in information security?

Which of the following is an appropriate term for an organized and highly skilled team whose mission is to continuously monitor and improve an organization’s security posture while preventing, detecting, analyzing, and responding to cybersecurity incidents, utilizing both technology and well-defined processes and procedures?

Which of the following is a method for embedding a malicious java script code in the content sent to a victim’s web browser from a vulnerable website?

Mr. A encrypts a message to be sent to Mr. B using an asymmetric key encryption method so that only Mr. B can decrypt the message. Which of the following is(are) the private key(s) used to decrypt the message?

Which of the following is an attack using a trial-and-error method to obtain confidential information such as a user password or personal identification number (PIN)?

When information, such as an e-mail or a document file, is sent and received with a digital signature via the Internet, which of the following is an appropriate combination of security properties that ensure that such information is from the signer and has not been altered or tampered with during transmission?

Which of the following is an example of a behavior of a key logger?

Which of the following is a role of a PKI certification authority as a reliable third party?

As shown in the figure below, an application on a client accesses the data in the database on a server via database connection programs. Which of the following is a measure for preventing the leakage of the commands and execution results transmitted between the application and database?

ClientServerApplicationDatabaseDatabaseconnection programDatabaseconnection programTapping by attacker

Companies usually provide a means for their mobile workforce to access the corporate network securely over the Internet through insecure channels such as open wireless networks in hotels or coffee shops. Which of the following is the appropriate technology that can be used for this purpose?

Which of the following is a technique that attempts to intrude into the system in order to detect security-related vulnerabilities of the computer or network?

Which of the following is a key that the SSL/TLS certificate of a website contains?

Which of the following is malware that is activated by attackers to launch attacks on other computers?

Which of the following is considered a violation of confidentiality?

Which of the following is an appropriate description of “asymmetric encryption,” used for encrypting and decrypting messages for secure communication?

Which of the following is a method of social engineering used in a targeted e-mail attack?

In information security, which of the following is a back door?

An asset valued at $200,000 has an exposure factor of 20% and an annual rate of occurrence of 0.5 for the risk of malware infection. How much (in dollars) is the annual loss expectancy of the asset due to malware infection?