Security

Security

137 questions · Fundamental Engineering · 101–137

Practice

Which of the following is appropriate conduct for a white-hat hacker?

Which of the following is an appropriate explanation of an SQL injection attack?

Which of the following is an appropriate use of a private key for a digital signature?

Which of the following is a characteristic of a worm, as compared with a Trojan horse?

There is a network that is divided into three (3) segments (i.e., external segment, DMZ, and internal segment) by one (1) firewall. In this network, a service for users is to be made available over the Internet by using a system comprising a web server and a database server containing important data. Which of the following is the most appropriate method of server installation that can protect important data from unauthorized access from the Internet? Here, only a specific protocol is allowed for communications between the external segment and the DMZ, and between the DMZ and the internal segment by the firewall. Direct communication between the external segment and the internal segment is not allowed.

Which of the following is a purpose of using a port scanner during an inspection of a web server?

When a packet-filtering firewall is to be installed at the point of connection between a company’s internal network and the Internet, and PCs on the internal network are to be allowed to access port 80 of a web server on the Internet, which of the following is an appropriate combination of rules of filters for allowing traffic?

OptionSourceDestinationSourceport numberDestinationport number

Which of the following is an attack that threatens the “integrity” of information?

Which of the following is a description of a directory traversal attack?

In ISO/IEC 27000:2018 (Information Security Management Systems – Overview and Vocabulary), which of the following is defined as the “property that an entity is what it claims to be”?

Which of the following is the purpose of port scanning when an attacker intrudes into the system?

Which of the following is a description that corresponds to two-factor authentication?

Which of the following is the combination of processes that constitutes risk assessment?

Which of the following is the malware that is used to gain unauthorized privileged access, to hide its own presence, and to perform malicious activities in a computer system?

Which of the following is a method for preventing an SQL injection attack?

The IP address of Server X prepared by an attacker was stored in a DNS cache server of Company B as the IP address corresponding to the FQDN of the web server of Company A. Which of the following users will be unintentionally guided to Server X because of this attack? Here, each employee of Company A and Company B performs name resolution by using the DNS cache server of his/her own company.

Which of the following is a description of a directory traversal attack?

Which of the following is a description of a brute force attack by which an attempt is made to find the key of private key cryptography?

Which of the following is an encryption algorithm for public key cryptography?

Which of the following is a security attack that prevents users from accessing their accounts?

Which of the following is an appropriate description of a botnet?

An attacker captures unencrypted network traffic with a tool and later analyzes it offline to learn about the information contained in those transmissions. Which of the following is this attack?

Which of the following is the technique of actually attempting an attack and intrusion on a system to detect the security-related vulnerabilities of a computer or network?

Which of the following is a password attack that makes use of the possible combination of pre-computed hashes and passwords?

Which of the following is a spoofing attack?

An administrator captures network packets and discovers that hundreds of ICMP packets have been sent to the host. However, it is not a particularly busy time of the day. Which of the following is the most likely the attack executed against the computer in this situation?

Which of the following is a description of spyware?

A security question is used to authenticate a user who forgets his/her password for a web system. After the correct answer is given, which of the following is the most appropriate process in terms of security?

Which of the following is a role that a PKI certification authority performs as a reliable third party?

Which of the following is an appropriate description concerning BYOD and the associated information security risk?

Which of the following is an appropriate description of honeypots?

Which of the following is a technology that prevents automated input by a program by requiring input of characters from a warped image or an image some parts of which are hidden? The technology is based on the differences of recognition of those images between humans and programs.

Which of the following is an appropriate explanation of a SQL injection attack?

In an e-commerce transaction that uses public key cryptography, which of the following is the role of a certificate agency (CA)?

Which of the following is an appropriate purpose of using a hash value in digital forensics?

When malware that has made a successful intrusion into a PC communicates with a command-and-control server on the Internet, which of the following is a reason for using the TCP port number 80 as the destination port in most cases?

When a normally functioning hard disk of a PC on which confidential files are stored is handed over to an industrial waste disposal vendor, which of the following is an appropriate countermeasure against information leakage?