Security
137 questions · Fundamental Engineering · 51–100
Which of the following is a security measure that allows users to run potentially malicious programs on a system with the purpose of observing their behavior, while restricting the programs from accessing outside of the system?
A packet filtering firewall is installed at the connection point of an internal network and the Internet. Which of the following is the appropriate combination of filtering rules that enables PCs on the internal network to access a web server on the Internet (port number 80)?
When a sender from domain A sends an e-mail to a recipient in domain B, which of the following is used by the mail server in domain A for authenticating the sender?
The three properties of information security are confidentiality, integrity, and availability. Which of the following is an attack on integrity?
When a system with a database is being developed, a security requirement states that the data must be encrypted with a key before being saved to the database, and the same key is required for decryption when the data is being read. Which of the following is an appropriate algorithm that can be used to satisfy the security requirement?
Which of the following is a cyber-attack that redirects a victim to a fake website by manipulating DNS to obtain personal information from the victim?
When security risk management processes incorporate the approach of the PDCA (Plan, Do, Check, Act) cycle, which of the following is a process that belongs to Act?
Which of the following is the protocol that is used together with HTTP in HTTPS?
Which of the following is an appropriate term associated with the fraudulent action of impersonating an authorized person?
An attacker calls a corporate help desk, masquerading as an employee who has forgotten his password. The help desk staff resets the password to the company default “password1.” The attacker then uses this password to access the company network and information on the server. What is this type of attack called?
When a biometric authentication system is introduced, which of the following is the most appropriate point to be taken into account?
Which of the following is a direct result of SQL injection to a company’s web server?
Which of the following is a program that is designed to block access to a computer or encrypt most of the data on that computer until a sum of money is paid?
In a PKI system, which of the following is an algorithm that creates a key pair?
Which of the following is an appropriate description of a command and control (C&C) server?
Which of the following is an appropriate description of an advanced persistent threat (APT)?
Which of the following is an appropriate description of footprinting in computer security?
Which of the following is an appropriate combination of definitions I through IV for authenticity and reliability in ISO/IEC 27000:2018 (Information security management systems – Overview and vocabulary)?
[Definitions]
When a mirror port is prepared to allow a LAN analyzer to be used for measurement in order to investigate the cause of a network failure, which of the following is a point to consider?
There is a network that is divided into three (3) segments, namely an external segment, a DMZ, and an internal segment, by one (1) firewall. In this network, a service for users is published on the Internet using a system comprising a web server and a database server that contains critical data. Which of the following is the most appropriate server installation method for protecting critical data from unauthorized access via the Internet? Here, the web server performs front end processing for the database server, and the firewall allows only a specific protocol for communication between the external segment and the DMZ as well as between the DMZ and the internal segment. Direct communication between the external segment and the internal segment is not allowed.
Which of the following is a system or network that is intentionally made vulnerable in order to investigate the behavior of an intruder or malware?
When risk treatment is classified as risk avoidance, risk reduction, risk acceptance, and risk sharing, which of the following risk treatments is risk avoidance?
Which of the following is installed into an in-house network or server by an intruder to enter through an access path other than the normal path?
Biometric authentication includes a verification method that extracts physical characteristics and another verification method that extracts behavioral characteristics. Which of the following is the method that uses behavioral characteristics?
Which of the following is an encryption method that can be used for encrypting data managed in a database using the same key for encryption and decryption?
A given application only has the functions of retrieving and displaying user information from a database that stores such information. Considering information security management, which of the following is the appropriate database access right assigned to an account that the application uses when it accesses the database? The names and scopes of rights are listed below.
A cybersecurity incident response plan is defined as a set of instructions to aid the cybersecurity team to detect, respond to, and recover from cybersecurity incidents. The cybersecurity incident response plan resolves issues, such as cybercrime, data loss, and service outages that threaten daily work. Which of the following is part of the cybersecurity incident response plan?
Between a client and web server, which of the following is used for inspecting the data that is sent from the client to the web server and blocking attacks, such as SQL injections?
Which of the following is an appropriate explanation of OP25B for email communication?
Which of the following properties for information security defined in ISO/IEC 27000:2018 refers to a guarantee that the message data received is the same as the message data sent?
A typical example of security threats is information leakage when a sender sends data containing important information to a receiver. Which of the following is the most appropriate measure to prevent information leakage?
Which of the following is a type of malware that embeds itself within a program and inserts its copy into other programs?
According to ISO/IEC 27000:2018 (Information security management systems - Overview and vocabulary), which of the following is the definition of “level of risk”?
To provide a guarantee to its online customers that all credit card information is protected when transferred between their PC and the web service over public networks, which of the following technologies should be used?
Which of the following activities targets the DHCP server and exhausts all its available IP address pool so that it cannot provide any IP addresses to its clients?
Man-in-The-Middle (MITM) attack means the attacker intercepts and alters the communication between the end-user (victim) and the server, which is shown below. In an MITM attack, when the victim sends packets to the server, the attacker receives the packets and then forwards them to the server while the server sends the packets to the victim via the attacker. In this communication channel, which of the following is the appropriate description concerning the MITM attack?
Which of the following is the result when person A sends an e-mail that is encrypted by person B’s public key to person B and person C? Here, these three persons have the public keys of all three persons, and all of them have their own private keys.
Which of the following is the most appropriate countermeasure against cross-site scripting (XSS) attacks?
Which of the following is a method to prevent damage caused by an SQL injection attack?
Which of the following is the network security tool that is usually deployed by a network or system administrator and presents itself as a target machine trying to lure attackers to observe their behavior and attack methodology without harming other systems?
SSL/TLS is the industry-standard security technology creating encrypted connections between a web server and a web browser. This is used to maintain data privacy and to protect the information in online transactions. The steps for establishing an SSL/TLS connection are randomly listed as follows:
Which of the following is the correct step sequence?
Which of the following is a type of public-key cryptography that utilizes the difficulty of factorizing extremely large numbers into primes?