Security
137 questions · IT Passport · 1–50
Which of the following is a technology that is also used in measures against tampering of software in IoT devices and verifies the digital signature of the OS, firmware, or other such software when it is started, and only executes the software if the verification is successful?
Among the descriptions A through C concerning PKI, which of the following is the list that contains all and only the appropriate descriptions concerning a digital signature in e-mail?
In the description below concerning risk management in information security, which of the following is an appropriate combination of words or phrases to be inserted into the blanks A through C?
In information security, a A in an information asset of an organization can be exploited by a B. The potential for damage is called a C.
Among the following attacks against an information system, which attack can be prevented by stopping the use of a given ID when mistakes are made during the entry of a password for the ID more than the preset number of times, ?
Which of the following is an authentication method where a user uses information that differs each time and is generated with a device called a token or other such devices?
When a PC is connected directly to the Internet during a business trip, which of the following is appropriate to use in order to prevent unauthorized access from the Internet?
Which of the following is appropriate as the characteristic of single sign-on?
Which of the following is an appropriate description concerning the characteristics of the authentication method below?
- •Users memorize only the positions and their order on the matrix table used for authentication.
- •Numbers are randomly allocated on the matrix table every time authentication is performed.
- •A user enters numbers that are shown in memorized positions, in order, as a password.
- •Authentication succeeds when input of numbers displayed in the correct positions has been confirmed.
[Example of authentication by using a matrix]
Note: The shaded portions indicate memorized positions, and the arrows indicate the memorized order.
A user who specifies a correct URL and attempts to access the website on the Internet is connected to a fake website. When the cause was investigated, it was found that there was a vulnerability on the server that matches a domain name with an IP address, and the information on the server was overwritten by an attacker. Which of the following is the attack against this server?
Among descriptions A through D concerning how to conduct information security education to employees, which of the following contains all and only the appropriate descriptions?
Among the descriptions A through D of how to handle a contact list that includes customer names, addresses, and other information, which of the following contains all and only the appropriate descriptions in terms of personal information protection?
Among the threats and vulnerabilities in information security, which of the following is a vulnerability?
Which of the following is an appropriate disposal method for media that stores confidential information to ensure that information leakage does not occur?
Which of the following is a term for software that encrypts files on a computer in order to make them unusable, and demands money or other valuables in exchange for the decryption key?
During the use of a PC in workplace, a message was displayed stating that antivirus software had detected a virus. Which of the following is an appropriate action that should be taken immediately?
There is an IoT system that is composed of IoT devices and an IoT server that manages them. Which of the following is the appropriate combination of information security incidents (i) through (iii) in this system, and confidentiality, integrity, and availability that are compromised because of the incidents?
[Incident]
In the activities of an organization that runs an ISMS on the basis of the PDCA cycle, improvements and corrective measures are decided from the results of monitoring of the risk management activities and other such information. In which process of the PDCA cycle is this activity performed?
When risk treatment in risk management for information security is divided into the four (4) categories of risk avoidance, risk sharing, risk mitigation, and risk retention, which of the following is the appropriate explanation of risk sharing?
Which of the following is an appropriate description concerning user authentication of a system?
If risk assessment is divided into three (3) processes, which of the following is the third process besides risk identification and risk evaluation?
Which of the following is the appropriate description concerning virus infection?
Which of the following is the appropriate combination of the descriptions (i) through (iii) about threats in information security and the terms below?
A document file that is stored on a file server is directly edited on a PC and then an attempt is made to overwrite the file, but the message “You do not have permission, so the file cannot be saved” is displayed. Which of the following is the appropriate combination of permissions that were set for the document file and the folder that it is stored in?
When a digital signature is attached to an e-mail and the e-mail is sent, in comparison to the use of a digital certificate that is issued by a trusted certificate authority, which of the following is the risk on the receiver’s side that is caused by the use of a digital certificate created by the sender themselves?
In risk management for information security, the categories that include risk transfer, risk avoidance, risk mitigation, and risk retention are sometimes used. Which of the following is the appropriate description concerning these?
In a wireless LAN router, which of the following is the appropriate explanation of a function that is set up for devices brought in from external locations and is called a “guest port” or a “guest SSID” or other such names?
Which of the following is the appropriate combination of damage by incidents (i) through (iii), and confidentiality, integrity, and availability in information security?
A business PC that was connected to a company’s internal wireless LAN network was used to view a website on the Internet. Immediately after this, the web browser crashed and unknown files were created, and other such events occurred that indicated the possibility of infection with malware. Which of the following is the appropriate action that the user of this PC should take first?
Which of the following is the appropriate combination of terms or phrases inserted into A through D in the table that describes the characteristics of encryption methods?
Which of the following is the appropriate example of activities performed in C (Check) in the organizations that operate ISMS on the basis of the PDCA model?
Which of the following is an example of damage incurred by the theft of cookies by a cross-site scripting attack or other attack?
Which of the following is a definition of a zero-day attack that is a threat to information security?
Which of the following is an appropriate action for the secure use of a smartphone?
Security risk treatment in ISMS includes risk transfer, risk avoidance, risk acceptance, and risk reduction. Which of the following is an example of risk avoidance?
Which of the following is an appropriate description of the beginning of a URL indicating that TLS is used for communication between a web browser and a web server?
Which of the following is a technique that is used to detect that the received data has been tampered with?
Among I through III below, which of the following lists all and only the appropriate measures for preventing a PC from getting infected with viruses?
Which of the following is an appropriate description concerning behavioral detection technology for protecting systems from unknown threats such as zero-day attacks?
When an attacker makes an unauthorized intrusion into a computer, the attacker sometimes changes a program or settings in the computer in order to make further intrusions into the computer easier. Which of the following is the most appropriate term to express the method used by the attacker for further intrusions into the computer?
When USB memory or other such external recordable media is connected to a PC, which of the following is an OS function that automatically executes programs or plays movies on the media and can also cause malware infection?
Which of the following is an appropriate description concerning encryption of communication when a website with the URL beginning with “https://” is browsed through a PC browser?
Which of the following is the appropriate example of biometric authentication?
When a document file attached to a received e-mail is opened on a PC, the PC begins to behave abnormally. Which of the following is an appropriate suspected attack?
Which of the following is the activity in A (Act) phase in the PDCA model adopted in an organization that operates an ISMS?
Which of the following is an example of an aim of an attacker who infects someone else’s PC with ransomware?