Security

Security

137 questions · IT Passport · 51–100

Practice

A private key and a public key were generated as a key pair and a digital certificate for the public key was issued. Which of the following is an appropriate action that should be taken when the private key is leaked?

Which of the following sets conditions for character type, length, etc. used for passwords that are set for accounts on a computer, etc.?

Among confidentiality, integrity, and availability, which of the following is the list that contains all and only the properties that are lost in the information security incident below?

All files on a server in the workplace were encrypted. However, the server was infected by a virus, and a number of the files were deleted. Removal of the virus and recovery of the files required several hours. During the hours, work could not be performed, and users were inconvenienced. Some files were unable to be recovered.

A problem has been pointed out that the WEP encryption for wireless LANs can be broken easily. Which of the following is an encryption method that does not have the same weakness and is cryptographically stronger?

Company A implements risk analysis for its own information assets. The results show that if a nearby river overflows, the server room on the first floor of the company might be flooded. The company considers the possibility of moving the server room, but decides there is almost no risk of a flood because the last time the river overflowed was 100 years ago, and the management decides that no particular countermeasures are taken. Which of the following is the risk treatment for information security that Company A selects?

The decision is made to digitize a paper-based contact list that only some people are permitted to view, and to manage it as a contact file. Among the measures A through D below, which of the following is the list that contains all and only the appropriate measures against personal information leakage?

AA password for reading is set for the contact file.BThe contact file is encrypted.CThe servers that stores the contact file are configured in a redundant configuration.DAfter the contact list is digitized, the paper-based contact list is disposed of with a shredder.

Among the Web browsing practices (1) through (3) below, which of the following is the list that contains all and only the practices that reduce security risks?

(1)Storing the user ID and the password on the web browser(2)Disabling JavaScript(3)Logging on to the PC with administrator privileges when using the web browser

Which of the following is placed between an internal network and an external network in order to prevent unauthorized access from the external network to the internal network?

Which of the following is an appropriate explanation of a keylogger that is a threat to information security?

Which of the following is the most appropriate explanation of phishing?

Which of the following is a form of direct damage to a server that is caused by a DoS attack?

Among the countermeasures A through D concerning information security, which of the following is the list that contains all and only the appropriate countermeasures for virus infections?

A:Installing antivirus softwareB:Applying a security patch (i.e., update module)C:Setting a password for the hard diskD:Encrypting files

Which of the following is the general name for evil-minded software such as a key logger or worm?

IDs and passwords are leaked from the first website, and the users of this website suffer from a password list attack on the second website. In this case, which of the following is the problem concerning the IDs and passwords for the second website?

Among the types of authentication I through IV, which of the following is a list that contains all and only biometrics authentication?

IPIN (Personal Identification Number)IIIrisIIIFingerprintIVVein

When information security management is based on the PDCA cycle, which of the following corresponds to C?

Which of the following is a protocol that is used for encrypted HTTPS communication between a web server and a web browser?

Which of the following is the most appropriate description concerning a VPN that is used, for example, to connect a PC to a workplace network from outside via the Internet?

Which of the following is an appropriate description concerning a virus check for an e-mail?

All employees are registered in an entry control system with biometric authentication, and the employees who are allowed to enter each room within the company are specified. The exit from a room is not controlled. Among the following lists of the descriptions A through D, which is the list that contains all and only the items that can be achieved by the entry control system?

A:Only authorized employees are allowed to enter a room.B:The time duration for which each person stayed in the room is recorded.C:Any attempts to enter a room but were denied the entry are recorded.D:The number of persons in a room is identified.

Which of the following is the most appropriate description concerning an information security policy for an organization?

Which of the following is the most appropriate explanation of the operation that spyware is meant to perform?

Which of the following is an appropriate description of S/MIME that is used for e-mails?

The communication protocol between a web browser and a web server was changed from HTTP to HTTPS. Which of the following does this achieve?

In a file system that uses the access control methods below, which of the following settings for access rights to file A satisfies the requirements for access control?

[Access control methods of the file system]•Units for the setting of access rights: Owner; Users in the same group as the owner; Other users•Access rights: R (Read), W (Write), X (Execute)•Priority of access rights: From highest priority to lowest, settings are prioritized in the order of “Owner”; “Users in the same group as the owner”; “Other users”
[Requirements for access control to file A]•All users are able to execute the file.•Only the owner and users in the same group as the owner are able to read from the file.•Only the owner is able to write to the file.

*: Set  –: Not set

OwnerUsers in the same group as the ownerOther users
OptionRWXRWXRWX

Which of the following is an appropriate combination of terms or phrases to be inserted into A and B in the description below concerning identification of information security risks in ISMS?

 A of ISMS, the risks that cause loss of confidentiality, B, or availability of information are identified.

OptionAB

In a corporate network, which of the following is a server that should be installed in a corporate LAN rather than in the demilitarized zone (DMZ)?

An IoT device with a vulnerability was used in large numbers by several companies. One (1) of the devices was infected with malware, and the infection spreads to many other IoT devices. On a certain date at a certain time, the many IoT devices that were infected with the malware attempted many connections to a certain website simultaneously, and this forced the service of the website to stop. Which of the following attacks was made against the website?

Which of the following is an appropriate explanation concerning proactive countermeasures against various threats that hinder stable operation of information systems?

Which of the following is an appropriate description concerning biometric authentication?

When a user accessed the URL in the body of an e-mail message with a PC, the message shown in the figure appeared on the screen and the PC was locked. Which of the following is used in this attack?

Your PC is locked. To unlock your PC, youneed a password. If you want to know thepassword, please pay money within 48 hours.If you fail to make the payment within thatperiod, you will no longer be able to unlockyour PC. The payment method is as follows.

Which of the following is an appropriate example of activities conducted in A (Act) in the organizations that operate ISMS on the basis of the PDCA model?

It is reported that WEP suffers from the problem that ciphers are decoded in a short time. Which of the following is a stronger wireless LAN encryption method?

When a smartphone is used, which of the following is an appropriate preventive measure for shoulder surfing?

Which of the following is used to confirm that there is no falsification of the content of an e-mail?

Which of the following is not an appropriate security control concerning human resources as a security risk treatment in ISMS?

Among the following lists consisting of the information security terms availability, integrity, confidentiality, and vulnerability, which is a complete list of properties of information that information security is to preserve?

Which of the following is an appropriate description concerning a scheme for authenticating a user of a system?

Which of the following is the list that contains all appropriate features of chain mail?

A:It is used for the purposes of communication and information sharing within a group.B:It places a wasteful load on network servers.C:The same e-mail is repeatedly replied to.D:The text of the e-mail encourages forwarding of the e-mail to many people.

One of the methods of cracking a password is a brute force attack that involves attempting all character combinations. When the number of characters of a password that is composed of 26 types of characters from A through Z is increased from four (4) to six (6) characters, by what factor is the maximum number of attempts to decode the password with the brute force attack increased?

In e-commerce transactions, which of the following is the most appropriate request to be made to the other party in order to prevent denial of the fact of order placement and details thereof?

Which of the following is an appropriate example of ransomware?

Which of the following is the most appropriate combination of the measures against password theft and brute force attack respectively on websites having a login function?

OptionPassword theftBrute force attack

Which of the following is the appropriate combination of terms or phrases to be inserted into blanks A and B in the description below concerning authentication accuracy in biometric authentication?

In biometric authentication, the probability of incorrectly rejecting the relevant person is called the false rejection rate, and the probability of incorrectly accepting another person is called the false acceptance rate. The rate that an authentication device or algorithm cannot recognize biometric information is called the unsupported rate.

In the settings for authentication accuracy, setting the A lower increases convenience, and setting B lower increases security.

OptionAB

In ISMS risk assessment, which of the following is performed first?

Which of the following is an appropriate example of biometric authentication?

The authentication technology is classified into three (3) types, namely authentication based on one’s possession, authentication based on physical characteristics, and authentication based on one’s memory. Which of the following is an appropriate combination of the implementation examples (1) through (3) and their classifications?

(1)Authentication using an IC card(2)Authentication based on an ID and password(3)Authentication based on fingerprint
Option(1)(2)(3)

When information security measures are grouped into three (3) categories of technical security measures, human security measures, and physical security measures, which of the following is an appropriate example of physical security measures?

Which of the following is a technique for taking advantage of psychological weaknesses or carelessness in order to, for example, improperly obtain confidential information?

Which of the following is an appropriate description concerning password management?