Security

Security

137 questions · IT Passport · 1–50

Practice

Which of the following is a technology that is also used in measures against tampering of software in IoT devices and verifies the digital signature of the OS, firmware, or other such software when it is started, and only executes the software if the verification is successful?

Among the descriptions A through C concerning PKI, which of the following is the list that contains all and only the appropriate descriptions concerning a digital signature in e-mail?

AThe recipient can check whether the sender is the intended person.BIt is possible to prevent e-mail from being read before it reaches the recipient.CThe recipient can confirm that the e-mail has not been tampered with.

In the description below concerning risk management in information security, which of the following is an appropriate combination of words or phrases to be inserted into the blanks A through C?

In information security, a A in an information asset of an organization can be exploited by a B. The potential for damage is called a C.

OptionABC

Among the following attacks against an information system, which attack can be prevented by stopping the use of a given ID when mistakes are made during the entry of a password for the ID more than the preset number of times, ?

Which of the following is an authentication method where a user uses information that differs each time and is generated with a device called a token or other such devices?

Which of the following is an explanation of spyware?

When a PC is connected directly to the Internet during a business trip, which of the following is appropriate to use in order to prevent unauthorized access from the Internet?

Which of the following is appropriate as the characteristic of single sign-on?

Which of the following is an appropriate description concerning the characteristics of the authentication method below?

  • •Users memorize only the positions and their order on the matrix table used for authentication.
  • •Numbers are randomly allocated on the matrix table every time authentication is performed.
  • •A user enters numbers that are shown in memorized positions, in order, as a password.
  • •Authentication succeeds when input of numbers displayed in the correct positions has been confirmed.

[Example of authentication by using a matrix]

51039667189407586505883409284542Password is5025
Nextauthentication
32503379033703686089268118731065Password is3059

Note: The shaded portions indicate memorized positions, and the arrows indicate the memorized order.

Which of the following is a security standard that is used in a wireless LAN?

A user who specifies a correct URL and attempts to access the website on the Internet is connected to a fake website. When the cause was investigated, it was found that there was a vulnerability on the server that matches a domain name with an IP address, and the information on the server was overwritten by an attacker. Which of the following is the attack against this server?

Among descriptions A through D concerning how to conduct information security education to employees, which of the following contains all and only the appropriate descriptions?

AThe re-education of one who has committed an information security breach includes preventive actions to avoid the same fault being repeated.BOne way to conduct it is to incorporate it in a training program for new employees.CIt is restricted to employees in the information systems department.DIt is conducted after an incident or an accident concerning information security as well as on a regular basis.

Among the descriptions A through D of how to handle a contact list that includes customer names, addresses, and other information, which of the following contains all and only the appropriate descriptions in terms of personal information protection?

AEven if a customer asks to check his/her own registration information, this cannot be disclosed on the grounds of information protection.BA list of all names and addresses is extracted from the contact list and is sent to all the customers to have them check for errors.CA CD-ROM that includes contact list data is to be shredded before it is discarded.DContact list data is to be encrypted when it is stored in a file.

Among the threats and vulnerabilities in information security, which of the following is a vulnerability?

Which of the following is an appropriate disposal method for media that stores confidential information to ensure that information leakage does not occur?

Which of the following is a term for software that encrypts files on a computer in order to make them unusable, and demands money or other valuables in exchange for the decryption key?

Which of the following is an appropriate example of biometric authentication?

During the use of a PC in workplace, a message was displayed stating that antivirus software had detected a virus. Which of the following is an appropriate action that should be taken immediately?

There is an IoT system that is composed of IoT devices and an IoT server that manages them. Which of the following is the appropriate combination of information security incidents (i) through (iii) in this system, and confidentiality, integrity, and availability that are compromised because of the incidents?

[Incident]

(i)An IoT device stopped working because its battery ran out.(ii)Communication between the IoT devices and the IoT server was not encrypted, so an information leakage occurred.(iii)Incorrect data was recorded because of a system fault.
Option(i)(ii)(iii)

In the activities of an organization that runs an ISMS on the basis of the PDCA cycle, improvements and corrective measures are decided from the results of monitoring of the risk management activities and other such information. In which process of the PDCA cycle is this activity performed?

When risk treatment in risk management for information security is divided into the four (4) categories of risk avoidance, risk sharing, risk mitigation, and risk retention, which of the following is the appropriate explanation of risk sharing?

Which of the following is an appropriate description concerning user authentication of a system?

If risk assessment is divided into three (3) processes, which of the following is the third process besides risk identification and risk evaluation?

Which of the following is the appropriate description concerning virus infection?

Which of the following is the appropriate combination of the descriptions (i) through (iii) about threats in information security and the terms below?

(i)An attack in which a malicious script injected to a web site that displays data that a visitor enters as it is, is executed on the visitor’s web browser, and data such as cookies are stolen by a third party(ii)A program that infects numerous PCs, executes malicious operations on the PCs by following instructions received via a network, and conducts a coordinated attack(iii)A program that is disguised as a useful program, but once installed and executed, performs unauthorized data destruction or leakage
Option(i)(ii)(iii)

A document file that is stored on a file server is directly edited on a PC and then an attempt is made to overwrite the file, but the message “You do not have permission, so the file cannot be saved” is displayed. Which of the following is the appropriate combination of permissions that were set for the document file and the folder that it is stored in?

OptionFile read permissionFile write permissionFolder read permission

When a digital signature is attached to an e-mail and the e-mail is sent, in comparison to the use of a digital certificate that is issued by a trusted certificate authority, which of the following is the risk on the receiver’s side that is caused by the use of a digital certificate created by the sender themselves?

In risk management for information security, the categories that include risk transfer, risk avoidance, risk mitigation, and risk retention are sometimes used. Which of the following is the appropriate description concerning these?

In a wireless LAN router, which of the following is the appropriate explanation of a function that is set up for devices brought in from external locations and is called a “guest port” or a “guest SSID” or other such names?

Which of the following is the appropriate combination of damage by incidents (i) through (iii), and confidentiality, integrity, and availability in information security?

(i)A website is taken down by a DDoS attack.(ii)Inaccurate data is entered because of a typing mistake on a keyboard.(iii)Personal information is leaked because a PC is infected with malware.
Option(i)(ii)(iii)

A business PC that was connected to a company’s internal wireless LAN network was used to view a website on the Internet. Immediately after this, the web browser crashed and unknown files were created, and other such events occurred that indicated the possibility of infection with malware. Which of the following is the appropriate action that the user of this PC should take first?

Which of the following is the appropriate combination of terms or phrases inserted into A through D in the table that describes the characteristics of encryption methods?

Encryp­tion methodKey charac­teristicsSafedistri­bution ofkeysEncryp­tion/​decryp­tionrelative processingspeed
AThe encryption key and the decryption key are differentEasyC
BThe encryption key and the decryption key are the sameDifficultD
OptionABCD

Which of the following is the appropriate example of activities performed in C (Check) in the organizations that operate ISMS on the basis of the PDCA model?

Which of the following is the most appropriate description of ransomware?

Which of the following is an example of damage incurred by the theft of cookies by a cross-site scripting attack or other attack?

Which of the following is a definition of a zero-day attack that is a threat to information security?

Which of the following is an appropriate action for the secure use of a smartphone?

Security risk treatment in ISMS includes risk transfer, risk avoidance, risk acceptance, and risk reduction. Which of the following is an example of risk avoidance?

Which of the following is an appropriate description of the beginning of a URL indicating that TLS is used for communication between a web browser and a web server?

Which of the following is a technique that is used to detect that the received data has been tampered with?

Among I through III below, which of the following lists all and only the appropriate measures for preventing a PC from getting infected with viruses?

IApplying a security patch to softwareIIStriping across hard disksIIIEducating users about security

Which of the following is an appropriate example of phishing?

Which of the following is an appropriate description concerning behavioral detection technology for protecting systems from unknown threats such as zero-day attacks?

When an attacker makes an unauthorized intrusion into a computer, the attacker sometimes changes a program or settings in the computer in order to make further intrusions into the computer easier. Which of the following is the most appropriate term to express the method used by the attacker for further intrusions into the computer?

When USB memory or other such external recordable media is connected to a PC, which of the following is an OS function that automatically executes programs or plays movies on the media and can also cause malware infection?

Which of the following is an appropriate description concerning encryption of communication when a website with the URL beginning with “https://” is browsed through a PC browser?

Which of the following is the appropriate example of biometric authentication?

When a document file attached to a received e-mail is opened on a PC, the PC begins to behave abnormally. Which of the following is an appropriate suspected attack?

Which of the following is the activity in A (Act) phase in the PDCA model adopted in an organization that operates an ISMS?

Which of the following is an example of an aim of an attacker who infects someone else’s PC with ransomware?