Which is the correct combination of the 3 elements of information security?
Confidentiality, integrity, and reliability
Integrity, availability, and accountability
Confidentiality, authenticity, and availability
Confidentiality, integrity, and availability
AnswerD. Confidentiality, integrity, and availability
The 3 elements of information security are confidentiality, integrity, and availability, known as the CIA triad. Authenticity, accountability, reliability, and non-repudiation are elements considered in addition to the 3, and are not part of the triad itself.
Q2 | Integrity
Which is an appropriate description of integrity in information security?
Information is kept accurate, free from tampering and destruction
Users and information sources are genuine
A state is maintained in which only authorized persons can access the information
Information and systems can be used whenever needed
AnswerA. Information is kept accurate, free from tampering and destruction
Integrity is the property that information is kept accurate and complete, free from tampering, erasure, and destruction. Access limited to authorized persons is confidentiality, usability when needed is availability, and genuineness is authenticity; none of them is integrity.
Q3 | Availability measures
Which is the most appropriate measure for increasing the availability of an information system?
Compare hash values so that data can be confirmed untampered
Use digital signatures to confirm that a document's creator is genuine
Encrypt communication data so third parties cannot read its content
Duplicate servers and take backups so work can continue during failures
AnswerD. Duplicate servers and take backups so work can continue during failures
Availability is the property of being able to use the system when needed, and it is raised through fault-tolerant design such as duplication, redundancy, and backups. Encryption serves confidentiality, tamper detection via hash values serves integrity, and digital signatures serve authenticity and non-repudiation; they do not directly raise availability.
Q4 | Non-repudiation
Which is an appropriate description of non-repudiation in information security?
Records make it possible to trace who accessed which information and when
Making it impossible for someone who performed an act to later claim they did not perform it
The system behaves consistently as intended and the expected results are always reliably obtained
Only authorized persons can view the information, keeping it from third parties
AnswerB. Making it impossible for someone who performed an act to later claim they did not perform it
Non-repudiation is the property that the person who performed an act such as sending or approving cannot later deny having done it, and it is achieved with digital signatures and the like. Consistent behavior is reliability, tracing access is accountability, and use limited to authorized persons describes confidentiality.
Q5 | Risk response
Among information security risk responses, which corresponds to taking out cyber insurance and shifting the burden of losses to a third party?
Risk transfer
Risk reduction
Risk avoidance
Risk retention
AnswerA. Risk transfer
Taking out insurance shifts the burden of losses, should the risk materialize, to a third party — the insurance company — so it corresponds to risk transfer. Avoidance means stopping the activity that causes the risk, reduction means lowering the likelihood or impact through countermeasures, and retention (acceptance) means accepting the risk without countermeasures.
Q6 | Ransomware
Which is an appropriate description of ransomware?
A program that secretly records the user's keyboard input, stealing passwords and sending them out
A virus that abuses the macro function of document files and infects when the file is opened
Malware that makes data unusable, for example by encrypting it, and demands a ransom in exchange for recovery
A program that plants a back door for the attacker to re-enter the infected device
AnswerC. Malware that makes data unusable, for example by encrypting it, and demands a ransom in exchange for recovery
Ransomware is malware that renders systems unusable, for example by encrypting data, and demands a ransom in exchange for recovery; healthcare institutions have reported incidents where electronic medical records were shut down. Stealing keystrokes is a keylogger, planting a back door is a backdoor, and abusing macros is a macro virus.
Q7 | Targeted attacks
Which is the most appropriate characteristic of a targeted attack?
Aiming at a specific organization and tricking recipients with email disguised as business correspondence to infect them with malware
Sending massive traffic simultaneously from many compromised machines to force the target service down
Compromising a website so that everyone who views it is infected indiscriminately
Sending the same spam message in bulk to a large number of unspecified recipients
AnswerA. Aiming at a specific organization and tricking recipients with email disguised as business correspondence to infect them with malware
A targeted attack aims at a specific organization or individual, using cleverly crafted email disguised as correspondence from business partners to get attachments opened and infect the target with malware for intrusion. Bulk sending to unspecified recipients is spam, simultaneous attack from many compromised machines describes DDoS, and indiscriminate infection contradicts the targeted nature of aiming at specific victims.
Q8 | Phishing
Which is an appropriate description of phishing?
An attack that exploits a program vulnerability to seize administrator privileges and intrude
Intercepting packets flowing over the network to peek at their contents
A trick that lures people to fake emails and websites posing as financial institutions and steals IDs, passwords, and the like
An attack that floods a server with traffic, overloading it so legitimate users cannot be served
AnswerC. A trick that lures people to fake emails and websites posing as financial institutions and steals IDs, passwords, and the like
Phishing is a trick that uses email posing as real financial institutions or services to lure victims to fake sites, getting them to enter and thereby steal IDs, passwords, and card numbers. Overload through massive traffic is a DoS attack, eavesdropping on packets is sniffing, and privilege seizure via vulnerabilities describes unauthorized intrusion.
Q9 | DDoS attacks
Which is the most appropriate way a DDoS attack differs from a DoS attack?
It encrypts the target's data and demands a ransom in exchange for recovery
It lures users to fake sites and steals information
It attacks simultaneously and in a distributed way from many compromised machines
It intrudes from 1 computer by exploiting a vulnerability
AnswerC. It attacks simultaneously and in a distributed way from many compromised machines
A DDoS (distributed denial-of-service) attack differs from DoS in using many bot-infected machines as stepping stones and sending massive traffic simultaneously from distributed sources, which makes it hard to block. Encryption with ransom demands describes ransomware, luring to fake sites describes phishing, and intrusion from 1 machine is not a DDoS characteristic.
Q10 | Backups
Which is the most appropriate description of the backup approach known as the 3-2-1 rule for countering ransomware?
Keep 3 copies, store them on 2 different types of media, and keep 1 of them off-site
Protect 3 servers with 2 power feeds and 1 UPS
Take backups every 3 days and keep 2 generations for 1 year
Have 3 staff members use 2 kinds of passwords and manage everything on 1 server
AnswerA. Keep 3 copies, store them on 2 different types of media, and keep 1 of them off-site
The 3-2-1 rule means keeping 3 copies of the data (the original plus 2), storing them on 2 different types of media, and keeping 1 of them off-site, for example at a remote location. Retaining a copy disconnected from the network guards against ransomware encrypting even the backups. The other options talk about backup intervals or power configurations and are not this rule.
Q11 | Symmetric encryption
Which is an appropriate characteristic of symmetric (shared-key) encryption?
The same key is used for encryption and decryption, and the key must be shared securely with each communication partner
A public key certificate guarantees that the key's owner is genuine
A key-pair scheme using a public key for encryption and a private key for decryption
Processing is slower than public key encryption, making it unsuitable for encrypting large volumes of data
AnswerA. The same key is used for encryption and decryption, and the key must be shared securely with each communication partner
Symmetric encryption uses the same key for encryption and decryption, so the key must be shared securely with the communication partner (the key distribution problem). Using a public/private key pair is public key encryption, and public key certificates belong to PKI. Symmetric encryption is actually the faster of the two, so the slowness claim is reversed.
Q12 | RSA
Which is a representative algorithm of public key encryption?
3DES
AES
DES
RSA
AnswerD. RSA
RSA is a representative public key encryption algorithm based on the difficulty of factoring large numbers, and is used both for encryption and for digital signatures. AES, DES, and 3DES are all symmetric encryption algorithms that use the same key for encryption and decryption.
Q13 | Which public key
A sends B a document using public key encryption so that no one else can read it. Which key does A use for encryption?
A's private key
B's public key
B's private key
A's public key
AnswerB. B's public key
When the goal is confidentiality, the document is encrypted with the recipient's (B's) public key so that only the recipient can decrypt it. Only B, holding the matching private key, can decrypt. Processing with A's private key is the case of a digital signature, and B's private key is a key no one but B may hold, so it cannot be used for encryption.
Q14 | Decryption key
Which key does recipient B use to decrypt ciphertext sent with confidentiality under public key encryption?
B's public key
The sender's private key
B's private key
The sender's public key
AnswerC. B's private key
The ciphertext was encrypted with recipient B's public key, so decryption uses the matching key — B's private key. Since only B holds the private key, no one else can decrypt. The sender's public key is used to verify digital signatures, and something encrypted with B's public key cannot be decrypted with B's public key.
Q15 | Signing key
Which key is used to create a digital signature?
The recipient's public key
The sender's (creator's) private key
The sender's (creator's) public key
The recipient's private key
AnswerB. The sender's (creator's) private key
A digital signature is created by processing the document's hash value with the sender's private key, and the recipient verifies it with the sender's public key. Because only the person holds the private key, successful verification confirms that they created it. The recipient's public key is the key used for encryption to ensure confidentiality — note that the direction is the reverse of signing.
Q16 | Signature effects
Which combination of things can be confirmed or achieved by a digital signature?
Prevention of eavesdropping and assurance of availability
Prevention of impersonation and prevention of eavesdropping on content
Faster communication and data compression
Detection of tampering and confirmation of the creator (non-repudiation)
AnswerD. Detection of tampering and confirmation of the creator (non-repudiation)
A digital signature achieves detection of tampering through hash comparison (integrity) and confirmation of the creator — since only the sender's private key could produce it (authenticity and non-repudiation). It does not encrypt the document itself, so prevention of eavesdropping (confidentiality) is not guaranteed, and it has nothing to do with availability or communication speed.
Q17 | Hash functions
Which is an appropriate property of a hash function?
The length of the hash value grows in proportion to the length of the original data
It generates a fixed-length hash value from data of any length, and recovering the original data is practically impossible
Even for identical input data, a different hash value is obtained on every run
The original data can be recovered from the hash value by computation
AnswerB. It generates a fixed-length hash value from data of any length, and recovering the original data is practically impossible
A hash function is a one-way function that generates a fixed-length message digest (hash value) from data of any length, and recovering the original data from the hash is practically impossible. The same input always yields the same hash value (which is exactly why it works for tamper detection), and the hash length is fixed per algorithm, not proportional to the data length.
Q18 | Hybrid encryption
Which is an appropriate description of the hybrid encryption scheme used in SSL/TLS and elsewhere?
The data itself is encrypted with fast symmetric encryption, and public key encryption is used to deliver that symmetric key
The data itself is encrypted with public key encryption, and symmetric encryption is used to deliver the public key
All communication is doubly encrypted with 2 kinds of symmetric keys
The public and private keys are exchanged and reused for every communication
AnswerA. The data itself is encrypted with fast symmetric encryption, and public key encryption is used to deliver that symmetric key
The hybrid scheme combines the strengths of both methods: the bulk of the data is encrypted with fast symmetric encryption, and public key encryption is used only to share the symmetric key, which suffers from the key distribution problem. The reverse combination would process the bulk data with slow public key encryption, which is unreasonable. Double symmetric encryption and reusing key pairs do not describe the hybrid scheme.
Q19 | Certificate authorities
Which is an appropriate role of the certificate authority (CA) in a public key infrastructure (PKI)?
Encrypt communication data and send it securely
Manage users' passwords centrally and decide whether authentication succeeds
Issue public key certificates after identity verification and manage their revocation
Detect unauthorized intrusions into the network and block them automatically
AnswerC. Issue public key certificates after identity verification and manage their revocation
The certificate authority (CA) verifies the applicant's identity, issues the public key certificate (digital certificate) that vouches for the binding between a public key and its owner, and manages revocation. This prevents public key impersonation. Encrypting data is done by the users, central password management by an authentication server, and intrusion detection and blocking by IDS/IPS.
Q20 | HPKI
Which is an appropriate description of HPKI (the public key infrastructure for the health, medical, and welfare fields)?
A public key infrastructure that can certify national qualifications such as physician and pharmacist, and administrator roles, with digital certificates
The government PKI that certifies the status of government employees
One of the encryption schemes for wireless LANs
A public key infrastructure issuing SSL server certificates to prove that websites really exist
AnswerA. A public key infrastructure that can certify national qualifications such as physician and pharmacist, and administrator roles, with digital certificates
HPKI is the public key infrastructure for the health, medical, and welfare fields; it can certify national qualifications such as physician and pharmacist and facility administrator roles with digital certificates, and is used for digital signatures. The government PKI is GPKI, SSL server certificates are a separate mechanism for authenticating Web servers, and wireless encryption schemes are WPA2 and the like — none describes HPKI.
Q21 | TLS
Which protocol protects communication between a Web browser and a Web server with SSL/TLS?
HTTPS
SMTP
FTP
DHCP
AnswerA. HTTPS
HTTPS is the protocol that protects HTTP Web communication by encrypting it with SSL/TLS, verifying the communication partner with a server certificate and encrypting the content. SMTP is for sending mail, DHCP for automatic IP address assignment, and FTP for file transfer; none of them aims to protect Web communication.
Q22 | Multi-factor authentication
Which of the following is multi-factor authentication?
Having the user answer 2 secret questions
Authenticating with a combination of an IC card and a password
Logging in to 2 different systems with the same password
Having the user enter 2 different passwords in succession
AnswerB. Authenticating with a combination of an IC card and a password
Multi-factor authentication combines 2 or more different factors from knowledge (passwords), possession (IC cards and the like), and biometrics (fingerprints and the like); combining an IC card (possession) with a password (knowledge) qualifies. Using 2 passwords or 2 secret questions repeats the same knowledge factor and is not multi-factor.
Q23 | Biometrics
Which is an appropriate characteristic of biometric authentication?
Judgment is always accurate, and false rejection and false acceptance errors never occur
Like an IC card, it can be lent to another person to be authenticated on one's behalf
If the information used for authentication is lost, one need only have it reissued
Unlike passwords there is no worry of forgetting, but false rejection and false acceptance errors cannot be reduced to zero
AnswerD. Unlike passwords there is no worry of forgetting, but false rejection and false acceptance errors cannot be reduced to zero
Biometric authentication uses physical characteristics such as fingerprints, veins, and irises, so there is no risk of forgetting or losing them; on the other hand, the errors of falsely rejecting the genuine person and falsely accepting someone else can never be eliminated completely. Physical characteristics cannot be reissued like passwords and cannot be lent to others, so the other options are wrong.
Q24 | OTP
Which authentication method is effective in preventing unauthorized logins that reuse an eavesdropped password?
Authentication by user ID alone
Authentication that sends a fixed password unencrypted
Authentication that stores the password in plain text on an IC card
One-time password authentication
AnswerD. One-time password authentication
One-time password authentication uses disposable passwords valid only once, so even if the communication is eavesdropped, the same value cannot be used to log in again. Challenge/response authentication has a similar effect. Sending fixed passwords in plain text or authenticating by ID alone is weak against eavesdropping and guessing, and a plain-text password on a card can be abused directly if leaked.
Q25 | SSO
Which is an appropriate description of single sign-on (SSO)?
A mechanism limiting simultaneous logins to a system to 1 user
A mechanism allowing use of multiple linked systems and services after 1 authentication
A mechanism for sharing 1 terminal among multiple users
A mechanism forcing the password to be changed every time
AnswerB. A mechanism allowing use of multiple linked systems and services after 1 authentication
Single sign-on is a mechanism by which one authentication grants use of multiple linked systems without further authentication, improving convenience and reducing the burden of password management. On the other hand, if the credentials are compromised the impact spreads widely, so protecting the authentication platform is critical. Limiting simultaneous logins, periodic password changes, and terminal sharing are not SSO.
Q26 | Access control
Which is the most appropriate approach to managing access rights in an information system?
Leave the accounts of retirees and transferred staff usable as they are, without deleting them
To simplify management, grant administrator privileges uniformly to all staff
Neither collect nor store audit logs, to save storage capacity
Grant rights only within the scope needed for each person's duties, and keep access records as audit logs
AnswerD. Grant rights only within the scope needed for each person's duties, and keep access records as audit logs
The basics of access control are the principle of least privilege — granting rights only within the scope needed for one's duties — and keeping access records as audit logs. Logs are indispensable for deterring misconduct and tracing it afterward. Granting everyone administrator privileges or leaving retirees' accounts active breeds unauthorized access, and operating without audit logs destroys accountability.
Q27 | DMZ
Which is the most appropriate location for a Web server exposed to the outside?
The same segment as users' terminals
An external segment connected directly to the Internet without passing through a firewall
The same internal network as the electronic medical record server
A DMZ separated from both the internal and external networks by firewalls
AnswerD. A DMZ separated from both the internal and external networks by firewalls
A publicly exposed server is placed in the DMZ, a buffer zone separated from both the outside and the inside by firewalls, so that even if the public server is attacked and compromised, the intruder cannot reach the internal network directly. Placing it on the internal network or the terminal segment spreads damage inward when compromised, and a direct connection without a firewall is defenseless.
Q28 | IDS and IPS
Which is the appropriate difference between an intrusion detection system (IDS) and an intrusion prevention system (IPS)?
An IDS blocks malicious traffic, while an IPS only detects and notifies
An IDS is a device exclusively for wireless LANs and an IPS exclusively for wired LANs
An IDS removes viruses and an IPS encrypts communications
An IDS goes as far as detecting and reporting malicious traffic, while an IPS additionally takes automatic defensive action such as blocking
AnswerD. An IDS goes as far as detecting and reporting malicious traffic, while an IPS additionally takes automatic defensive action such as blocking
An IDS detects traffic that signals intrusion attempts and notifies the administrator, while an IPS goes further and automatically takes defensive action such as blocking the offending traffic. The option reversing the roles is wrong, and the distinction is not wired versus wireless. Virus removal is the job of antivirus software and encryption of cryptographic technology; neither is an IDS/IPS function.
Q29 | VPN
Which technology builds a virtual leased line over a public network such as the Internet using encryption and authentication?
DNS
DHCP
NTP
VPN
AnswerD. VPN
A VPN is a technology that creates a virtual leased line over a public network with encryption and authentication; variants include IPsec-VPN and SSL-VPN, and it is used to protect site-to-site links and remote access. DNS maps domain names to IP addresses, NTP synchronizes time, and DHCP assigns IP addresses automatically; none protects the communication channel.
Q30 | Patching
Which is the most direct countermeasure against attacks exploiting a published OS security hole (vulnerability)?
Increase the length of passwords
Take data backups every day
Promptly apply the security patches distributed by the vendor
Attach a privacy filter to the display to prevent shoulder surfing
AnswerC. Promptly apply the security patches distributed by the vendor
The direct countermeasure against attacks on security holes is to promptly apply the fix programs (security patches) distributed by the vendor, eliminating the vulnerability itself. Many attacks exploit known vulnerabilities left unpatched. Backups are for recovery after damage, stronger passwords concern authentication, and privacy filters are a physical measure; none removes the vulnerability.
Practice: answer the questions on this page
This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.
* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.
This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original