Security
137 questions · IT Passport · 101–137
When information is classified and managed according to the protection level in information security, which of the following lists all and only the appropriate methods for the management?
Among I through IV used for authentication, which of the following lists all and only biometrics?
ID and password information is leaked from a web site, and the users of this web site suffer from a password list attack on a different web site. In this case, which of the following is considered to be a description of the problem concerning the ID and password that are used on the second web site?
Which of the following is a physical countermeasure for information security where depending on the importance of the information that is handled, an office or other such space is physically divided and separated into areas such as an open area, a security area, and a handover area?
In public key cryptography, a key for encryption and a key for decryption are required. If four (4) people want to encrypt communication and send it to each other, a total of eight (8) keys are required. Of these, how many of these keys are not made public?
When the evaluation values of asset value, threat, and vulnerability of assets A through D are as shown in the table, which of the following assets will be evaluated as the asset where risk measures should be taken at the highest priority? Here, the risk value is calculated by multiplying each three evaluation values together in the table without weighting.
Mr. A sent an e-mail to Mr. B that was encrypted with Mr. B’s key by using the public key cryptosystem, and this e-mail contains details that Mr. A wants to send only to Mr. B. Which of the following keys is needed to decrypt this e-mail?
When an information security policy is composed of three (3) documents, namely, basic policy, standards, and procedures, which of the following is the appropriate explanation concerning these documents?
When information security measures are classified into three (3) measures, namely, technology measures, personnel measures, and physical measures, which of the following is the appropriate example of physical measures?
When a smartphone is used, which of the following is the appropriate preventive measure for shoulder surfing that is classified as social engineering?
Which of the following is an appropriate information security measures for PC against harmful software?
There is a room that stores important information. Which of the following is the most appropriate countermeasure for unauthorized entry to this room and unauthorized access to the important information in the room?
There is an electronic file that needs to be made confidential. Which of the following is the appropriate security technology to use in order to ensure the confidentiality of this file?
When risk treatment in risk management for information security is divided into the four (4) categories of risk transfer, avoidance, acceptance, and mitigation, which of the following is an appropriate example of risk mitigation?
Which of the following is the aim of an attacker who infects someone else’s PC with ransomware?
When treatments against information security risks are categorized into risk transfer, risk avoidance, risk acceptance, and risk reduction, which of the following is the description that corresponds to risk acceptance?
Company A has decided to digitize a paper list of customers and manage customers by using electronic data. Which of the following is an appropriate method for preventing information leakage from the electronic data of the customer list?
An e-mail with a subject of “Caution: New computer virus” was received from the external network. The sender is not an acquaintance, and the content may or may not be true. However, the e-mail describes the characteristics of the virus, and instructs that the e-mail must be forwarded to as many people as possible. Which of the following is an appropriate course of action to be taken for this e-mail?
A private key and a public key were generated as a key pair when a digital certificate was issued. Which of the following is an appropriate action that should be taken when the private key is leaked?
Risks on information assets are assessed on the basis of threats and vulnerabilities. Which of the following falls under a threat?
Which of the following is an appropriate description of risk assessment in information security?
Which of the following is an appropriate description concerning a scheme for authenticating the user of a system?
Which of the following is a characteristic of symmetric key cryptography and not of public key cryptography?
When risk management in information security is divided into risk identification, risk analysis, risk assessment, and risk treatment, which of the following is included in risk treatment?
Which of the following is an appropriate description in comparison of how to safeguard IC cards and magnetic cards against forgery?
Among information security measures A through D implemented in the workplace to maintain the “confidentiality” and “integrity” of information, which of the following is a list of only the appropriate measures?
Among the descriptions A through C below concerning information security measures, which of the following is the list that contains all and only the goals that can be achieved by encrypting communication content?
In the description below concerning the ISMS conformity assessment scheme, which of the following is an appropriate combination of words to be inserted into blanks A and B?
It is a scheme for assessment and certification of a company or organization for its proper establishment and operation of the A management system and its conformity to the requirements of the ISMS certification standards. The assessment and certification are conducted by B.
In order to promote risk management, the execution plan for introducing the risk management system was developed as the first step. When the subsequent actions are divided into steps A through C below, which of the following is the order of the steps in accordance with the PDCA cycle?
Which of the following is the most appropriate description concerning SSL/TLS?
Among the descriptions A through D concerning the operations management of a file server, which of the following is the list that contains all and only the items that are effective as a security measure?
Which of the following is the threat that can be prevented by encrypting data?
Among confidentiality, integrity, and availability, which of the following is the list that contains all items that are lost in the incident below, which involves information security?
All of the files on a server in the workplace were encrypted and saved. However, the server was infected by a virus, and a number of the files were deleted. Elimination of the virus and recovery of the files required several hours, during which work could not be performed and users were inconvenienced.