Security

Security

137 questions · IT Passport · 101–137

Practice

When information is classified and managed according to the protection level in information security, which of the following lists all and only the appropriate methods for the management?

IThe protection level that is assigned to each piece of information is not changed until the information is discarded.IIThe procedure for handling information is defined for each protection level.IIIThe protection level for each piece of information is determined on the basis of standards that the organization establishes.IVThe object that is managed according to the protection level is limited to electronic data and storage media that store it.

Which of the following is a DoS attack?

Among I through IV used for authentication, which of the following lists all and only biometrics?

IPIN (Personal Identification Number)IIIrisIIIFingerprintIVVein

ID and password information is leaked from a web site, and the users of this web site suffer from a password list attack on a different web site. In this case, which of the following is considered to be a description of the problem concerning the ID and password that are used on the second web site?

Which of the following is a physical countermeasure for information security where depending on the importance of the information that is handled, an office or other such space is physically divided and separated into areas such as an open area, a security area, and a handover area?

In public key cryptography, a key for encryption and a key for decryption are required. If four (4) people want to encrypt communication and send it to each other, a total of eight (8) keys are required. Of these, how many of these keys are not made public?

When the evaluation values of asset value, threat, and vulnerability of assets A through D are as shown in the table, which of the following assets will be evaluated as the asset where risk measures should be taken at the highest priority? Here, the risk value is calculated by multiplying each three evaluation values together in the table without weighting.

Asset nameAsset valueThreatVulnerability
Asset A523
Asset B612
Asset C225
Asset D153

Mr. A sent an e-mail to Mr. B that was encrypted with Mr. B’s key by using the public key cryptosystem, and this e-mail contains details that Mr. A wants to send only to Mr. B. Which of the following keys is needed to decrypt this e-mail?

When an information security policy is composed of three (3) documents, namely, basic policy, standards, and procedures, which of the following is the appropriate explanation concerning these documents?

When information security measures are classified into three (3) measures, namely, technology measures, personnel measures, and physical measures, which of the following is the appropriate example of physical measures?

When a smartphone is used, which of the following is the appropriate preventive measure for shoulder surfing that is classified as social engineering?

Which of the following is an appropriate information security measures for PC against harmful software?

There is a room that stores important information. Which of the following is the most appropriate countermeasure for unauthorized entry to this room and unauthorized access to the important information in the room?

There is an electronic file that needs to be made confidential. Which of the following is the appropriate security technology to use in order to ensure the confidentiality of this file?

When risk treatment in risk management for information security is divided into the four (4) categories of risk transfer, avoidance, acceptance, and mitigation, which of the following is an appropriate example of risk mitigation?

Which of the following is an appropriate example of biometric authentication?

Which of the following is the aim of an attacker who infects someone else’s PC with ransomware?

When treatments against information security risks are categorized into risk transfer, risk avoidance, risk acceptance, and risk reduction, which of the following is the description that corresponds to risk acceptance?

Which of the following is not an example of a cyber attack?

Company A has decided to digitize a paper list of customers and manage customers by using electronic data. Which of the following is an appropriate method for preventing information leakage from the electronic data of the customer list?

An e-mail with a subject of “Caution: New computer virus” was received from the external network. The sender is not an acquaintance, and the content may or may not be true. However, the e-mail describes the characteristics of the virus, and instructs that the e-mail must be forwarded to as many people as possible. Which of the following is an appropriate course of action to be taken for this e-mail?

A private key and a public key were generated as a key pair when a digital certificate was issued. Which of the following is an appropriate action that should be taken when the private key is leaked?

Risks on information assets are assessed on the basis of threats and vulnerabilities. Which of the following falls under a threat?

Which of the following is an appropriate description of risk assessment in information security?

Which of the following is an appropriate description concerning a scheme for authenticating the user of a system?

Which of the following is an appropriate example of biometric authentication?

Which of the following is a characteristic of symmetric key cryptography and not of public key cryptography?

When risk management in information security is divided into risk identification, risk analysis, risk assessment, and risk treatment, which of the following is included in risk treatment?

Which of the following is an appropriate description in comparison of how to safeguard IC cards and magnetic cards against forgery?

Among information security measures A through D implemented in the workplace to maintain the “confidentiality” and “integrity” of information, which of the following is a list of only the appropriate measures?

A:PCs should remain unlocked to keep them ready for operation from the start to the end of the business day.B:Documents and electronic storage media, such as CD-R containing important information, should be stored in locked cabinets except when they are used.C:Documents sent or received by facsimile should be picked up immediately without being left unattended on the tray.D:Messages or information written on the whiteboard should be erased immediately after use.

Among the descriptions A through C below concerning information security measures, which of the following is the list that contains all and only the goals that can be achieved by encrypting communication content?

A:Recovering the data that is tampered with during communicationB:Ensuring that the communication content is not disclosed to a third partyC:Identifying the person involved in tapping if tapping has occurred

In the description below concerning the ISMS conformity assessment scheme, which of the following is an appropriate combination of words to be inserted into blanks A and B?

It is a scheme for assessment and certification of a company or organization for its proper establishment and operation of the A management system and its conformity to the requirements of the ISMS certification standards. The assessment and certification are conducted by B.

OptionAB

In order to promote risk management, the execution plan for introducing the risk management system was developed as the first step. When the subsequent actions are divided into steps A through C below, which of the following is the order of the steps in accordance with the PDCA cycle?

AImplementing the measures against risks according to the execution planBMeasuring the effect of the implementation and evaluating the effectiveness of the risk management systemCTaking corrective actions and improving the risk management system

Which of the following is the most appropriate description concerning SSL/TLS?

Among the descriptions A through D concerning the operations management of a file server, which of the following is the list that contains all and only the items that are effective as a security measure?

A:The password of an accessing user is complex and of sufficient length.B:Access is enabled only from PCs with the permitted IP address.C:The guest user is also granted permission to access the server.D:The access log of the server is acquired and audited regularly.

Which of the following is the threat that can be prevented by encrypting data?

Among confidentiality, integrity, and availability, which of the following is the list that contains all items that are lost in the incident below, which involves information security?

All of the files on a server in the workplace were encrypted and saved. However, the server was infected by a virus, and a number of the files were deleted. Elimination of the virus and recovery of the files required several hours, during which work could not be performed and users were inconvenienced.