Karinoya Learning Room

Qualifications · Healthcare Information Technologist Success Lab

Information Security

Read the questions and explanations in English. The lectures (explanatory articles) are available in Japanese only.

View the Japanese version (with lectures) →

Q1 | 3 elements

Which is the correct combination of the 3 elements of information security?

  1. Confidentiality, integrity, and reliability
  2. Integrity, availability, and accountability
  3. Confidentiality, authenticity, and availability
  4. Confidentiality, integrity, and availability
AnswerD. Confidentiality, integrity, and availability

The 3 elements of information security are confidentiality, integrity, and availability, known as the CIA triad. Authenticity, accountability, reliability, and non-repudiation are elements considered in addition to the 3, and are not part of the triad itself.

Q2 | Integrity

Which is an appropriate description of integrity in information security?

  1. Information is kept accurate, free from tampering and destruction
  2. Users and information sources are genuine
  3. A state is maintained in which only authorized persons can access the information
  4. Information and systems can be used whenever needed
AnswerA. Information is kept accurate, free from tampering and destruction

Integrity is the property that information is kept accurate and complete, free from tampering, erasure, and destruction. Access limited to authorized persons is confidentiality, usability when needed is availability, and genuineness is authenticity; none of them is integrity.

Q3 | Availability measures

Which is the most appropriate measure for increasing the availability of an information system?

  1. Compare hash values so that data can be confirmed untampered
  2. Use digital signatures to confirm that a document's creator is genuine
  3. Encrypt communication data so third parties cannot read its content
  4. Duplicate servers and take backups so work can continue during failures
AnswerD. Duplicate servers and take backups so work can continue during failures

Availability is the property of being able to use the system when needed, and it is raised through fault-tolerant design such as duplication, redundancy, and backups. Encryption serves confidentiality, tamper detection via hash values serves integrity, and digital signatures serve authenticity and non-repudiation; they do not directly raise availability.

Q4 | Non-repudiation

Which is an appropriate description of non-repudiation in information security?

  1. Records make it possible to trace who accessed which information and when
  2. Making it impossible for someone who performed an act to later claim they did not perform it
  3. The system behaves consistently as intended and the expected results are always reliably obtained
  4. Only authorized persons can view the information, keeping it from third parties
AnswerB. Making it impossible for someone who performed an act to later claim they did not perform it

Non-repudiation is the property that the person who performed an act such as sending or approving cannot later deny having done it, and it is achieved with digital signatures and the like. Consistent behavior is reliability, tracing access is accountability, and use limited to authorized persons describes confidentiality.

Q5 | Risk response

Among information security risk responses, which corresponds to taking out cyber insurance and shifting the burden of losses to a third party?

  1. Risk transfer
  2. Risk reduction
  3. Risk avoidance
  4. Risk retention
AnswerA. Risk transfer

Taking out insurance shifts the burden of losses, should the risk materialize, to a third party — the insurance company — so it corresponds to risk transfer. Avoidance means stopping the activity that causes the risk, reduction means lowering the likelihood or impact through countermeasures, and retention (acceptance) means accepting the risk without countermeasures.

Q6 | Ransomware

Which is an appropriate description of ransomware?

  1. A program that secretly records the user's keyboard input, stealing passwords and sending them out
  2. A virus that abuses the macro function of document files and infects when the file is opened
  3. Malware that makes data unusable, for example by encrypting it, and demands a ransom in exchange for recovery
  4. A program that plants a back door for the attacker to re-enter the infected device
AnswerC. Malware that makes data unusable, for example by encrypting it, and demands a ransom in exchange for recovery

Ransomware is malware that renders systems unusable, for example by encrypting data, and demands a ransom in exchange for recovery; healthcare institutions have reported incidents where electronic medical records were shut down. Stealing keystrokes is a keylogger, planting a back door is a backdoor, and abusing macros is a macro virus.

Q7 | Targeted attacks

Which is the most appropriate characteristic of a targeted attack?

  1. Aiming at a specific organization and tricking recipients with email disguised as business correspondence to infect them with malware
  2. Sending massive traffic simultaneously from many compromised machines to force the target service down
  3. Compromising a website so that everyone who views it is infected indiscriminately
  4. Sending the same spam message in bulk to a large number of unspecified recipients
AnswerA. Aiming at a specific organization and tricking recipients with email disguised as business correspondence to infect them with malware

A targeted attack aims at a specific organization or individual, using cleverly crafted email disguised as correspondence from business partners to get attachments opened and infect the target with malware for intrusion. Bulk sending to unspecified recipients is spam, simultaneous attack from many compromised machines describes DDoS, and indiscriminate infection contradicts the targeted nature of aiming at specific victims.

Q8 | Phishing

Which is an appropriate description of phishing?

  1. An attack that exploits a program vulnerability to seize administrator privileges and intrude
  2. Intercepting packets flowing over the network to peek at their contents
  3. A trick that lures people to fake emails and websites posing as financial institutions and steals IDs, passwords, and the like
  4. An attack that floods a server with traffic, overloading it so legitimate users cannot be served
AnswerC. A trick that lures people to fake emails and websites posing as financial institutions and steals IDs, passwords, and the like

Phishing is a trick that uses email posing as real financial institutions or services to lure victims to fake sites, getting them to enter and thereby steal IDs, passwords, and card numbers. Overload through massive traffic is a DoS attack, eavesdropping on packets is sniffing, and privilege seizure via vulnerabilities describes unauthorized intrusion.

Q9 | DDoS attacks

Which is the most appropriate way a DDoS attack differs from a DoS attack?

  1. It encrypts the target's data and demands a ransom in exchange for recovery
  2. It lures users to fake sites and steals information
  3. It attacks simultaneously and in a distributed way from many compromised machines
  4. It intrudes from 1 computer by exploiting a vulnerability
AnswerC. It attacks simultaneously and in a distributed way from many compromised machines

A DDoS (distributed denial-of-service) attack differs from DoS in using many bot-infected machines as stepping stones and sending massive traffic simultaneously from distributed sources, which makes it hard to block. Encryption with ransom demands describes ransomware, luring to fake sites describes phishing, and intrusion from 1 machine is not a DDoS characteristic.

Q10 | Backups

Which is the most appropriate description of the backup approach known as the 3-2-1 rule for countering ransomware?

  1. Keep 3 copies, store them on 2 different types of media, and keep 1 of them off-site
  2. Protect 3 servers with 2 power feeds and 1 UPS
  3. Take backups every 3 days and keep 2 generations for 1 year
  4. Have 3 staff members use 2 kinds of passwords and manage everything on 1 server
AnswerA. Keep 3 copies, store them on 2 different types of media, and keep 1 of them off-site

The 3-2-1 rule means keeping 3 copies of the data (the original plus 2), storing them on 2 different types of media, and keeping 1 of them off-site, for example at a remote location. Retaining a copy disconnected from the network guards against ransomware encrypting even the backups. The other options talk about backup intervals or power configurations and are not this rule.

Q11 | Symmetric encryption

Which is an appropriate characteristic of symmetric (shared-key) encryption?

  1. The same key is used for encryption and decryption, and the key must be shared securely with each communication partner
  2. A public key certificate guarantees that the key's owner is genuine
  3. A key-pair scheme using a public key for encryption and a private key for decryption
  4. Processing is slower than public key encryption, making it unsuitable for encrypting large volumes of data
AnswerA. The same key is used for encryption and decryption, and the key must be shared securely with each communication partner

Symmetric encryption uses the same key for encryption and decryption, so the key must be shared securely with the communication partner (the key distribution problem). Using a public/private key pair is public key encryption, and public key certificates belong to PKI. Symmetric encryption is actually the faster of the two, so the slowness claim is reversed.

Q12 | RSA

Which is a representative algorithm of public key encryption?

  1. 3DES
  2. AES
  3. DES
  4. RSA
AnswerD. RSA

RSA is a representative public key encryption algorithm based on the difficulty of factoring large numbers, and is used both for encryption and for digital signatures. AES, DES, and 3DES are all symmetric encryption algorithms that use the same key for encryption and decryption.

Q13 | Which public key

A sends B a document using public key encryption so that no one else can read it. Which key does A use for encryption?

  1. A's private key
  2. B's public key
  3. B's private key
  4. A's public key
AnswerB. B's public key

When the goal is confidentiality, the document is encrypted with the recipient's (B's) public key so that only the recipient can decrypt it. Only B, holding the matching private key, can decrypt. Processing with A's private key is the case of a digital signature, and B's private key is a key no one but B may hold, so it cannot be used for encryption.

Q14 | Decryption key

Which key does recipient B use to decrypt ciphertext sent with confidentiality under public key encryption?

  1. B's public key
  2. The sender's private key
  3. B's private key
  4. The sender's public key
AnswerC. B's private key

The ciphertext was encrypted with recipient B's public key, so decryption uses the matching key — B's private key. Since only B holds the private key, no one else can decrypt. The sender's public key is used to verify digital signatures, and something encrypted with B's public key cannot be decrypted with B's public key.

Q15 | Signing key

Which key is used to create a digital signature?

  1. The recipient's public key
  2. The sender's (creator's) private key
  3. The sender's (creator's) public key
  4. The recipient's private key
AnswerB. The sender's (creator's) private key

A digital signature is created by processing the document's hash value with the sender's private key, and the recipient verifies it with the sender's public key. Because only the person holds the private key, successful verification confirms that they created it. The recipient's public key is the key used for encryption to ensure confidentiality — note that the direction is the reverse of signing.

Q16 | Signature effects

Which combination of things can be confirmed or achieved by a digital signature?

  1. Prevention of eavesdropping and assurance of availability
  2. Prevention of impersonation and prevention of eavesdropping on content
  3. Faster communication and data compression
  4. Detection of tampering and confirmation of the creator (non-repudiation)
AnswerD. Detection of tampering and confirmation of the creator (non-repudiation)

A digital signature achieves detection of tampering through hash comparison (integrity) and confirmation of the creator — since only the sender's private key could produce it (authenticity and non-repudiation). It does not encrypt the document itself, so prevention of eavesdropping (confidentiality) is not guaranteed, and it has nothing to do with availability or communication speed.

Q17 | Hash functions

Which is an appropriate property of a hash function?

  1. The length of the hash value grows in proportion to the length of the original data
  2. It generates a fixed-length hash value from data of any length, and recovering the original data is practically impossible
  3. Even for identical input data, a different hash value is obtained on every run
  4. The original data can be recovered from the hash value by computation
AnswerB. It generates a fixed-length hash value from data of any length, and recovering the original data is practically impossible

A hash function is a one-way function that generates a fixed-length message digest (hash value) from data of any length, and recovering the original data from the hash is practically impossible. The same input always yields the same hash value (which is exactly why it works for tamper detection), and the hash length is fixed per algorithm, not proportional to the data length.

Q18 | Hybrid encryption

Which is an appropriate description of the hybrid encryption scheme used in SSL/TLS and elsewhere?

  1. The data itself is encrypted with fast symmetric encryption, and public key encryption is used to deliver that symmetric key
  2. The data itself is encrypted with public key encryption, and symmetric encryption is used to deliver the public key
  3. All communication is doubly encrypted with 2 kinds of symmetric keys
  4. The public and private keys are exchanged and reused for every communication
AnswerA. The data itself is encrypted with fast symmetric encryption, and public key encryption is used to deliver that symmetric key

The hybrid scheme combines the strengths of both methods: the bulk of the data is encrypted with fast symmetric encryption, and public key encryption is used only to share the symmetric key, which suffers from the key distribution problem. The reverse combination would process the bulk data with slow public key encryption, which is unreasonable. Double symmetric encryption and reusing key pairs do not describe the hybrid scheme.

Q19 | Certificate authorities

Which is an appropriate role of the certificate authority (CA) in a public key infrastructure (PKI)?

  1. Encrypt communication data and send it securely
  2. Manage users' passwords centrally and decide whether authentication succeeds
  3. Issue public key certificates after identity verification and manage their revocation
  4. Detect unauthorized intrusions into the network and block them automatically
AnswerC. Issue public key certificates after identity verification and manage their revocation

The certificate authority (CA) verifies the applicant's identity, issues the public key certificate (digital certificate) that vouches for the binding between a public key and its owner, and manages revocation. This prevents public key impersonation. Encrypting data is done by the users, central password management by an authentication server, and intrusion detection and blocking by IDS/IPS.

Q20 | HPKI

Which is an appropriate description of HPKI (the public key infrastructure for the health, medical, and welfare fields)?

  1. A public key infrastructure that can certify national qualifications such as physician and pharmacist, and administrator roles, with digital certificates
  2. The government PKI that certifies the status of government employees
  3. One of the encryption schemes for wireless LANs
  4. A public key infrastructure issuing SSL server certificates to prove that websites really exist
AnswerA. A public key infrastructure that can certify national qualifications such as physician and pharmacist, and administrator roles, with digital certificates

HPKI is the public key infrastructure for the health, medical, and welfare fields; it can certify national qualifications such as physician and pharmacist and facility administrator roles with digital certificates, and is used for digital signatures. The government PKI is GPKI, SSL server certificates are a separate mechanism for authenticating Web servers, and wireless encryption schemes are WPA2 and the like — none describes HPKI.

Q21 | TLS

Which protocol protects communication between a Web browser and a Web server with SSL/TLS?

  1. HTTPS
  2. SMTP
  3. FTP
  4. DHCP
AnswerA. HTTPS

HTTPS is the protocol that protects HTTP Web communication by encrypting it with SSL/TLS, verifying the communication partner with a server certificate and encrypting the content. SMTP is for sending mail, DHCP for automatic IP address assignment, and FTP for file transfer; none of them aims to protect Web communication.

Q22 | Multi-factor authentication

Which of the following is multi-factor authentication?

  1. Having the user answer 2 secret questions
  2. Authenticating with a combination of an IC card and a password
  3. Logging in to 2 different systems with the same password
  4. Having the user enter 2 different passwords in succession
AnswerB. Authenticating with a combination of an IC card and a password

Multi-factor authentication combines 2 or more different factors from knowledge (passwords), possession (IC cards and the like), and biometrics (fingerprints and the like); combining an IC card (possession) with a password (knowledge) qualifies. Using 2 passwords or 2 secret questions repeats the same knowledge factor and is not multi-factor.

Q23 | Biometrics

Which is an appropriate characteristic of biometric authentication?

  1. Judgment is always accurate, and false rejection and false acceptance errors never occur
  2. Like an IC card, it can be lent to another person to be authenticated on one's behalf
  3. If the information used for authentication is lost, one need only have it reissued
  4. Unlike passwords there is no worry of forgetting, but false rejection and false acceptance errors cannot be reduced to zero
AnswerD. Unlike passwords there is no worry of forgetting, but false rejection and false acceptance errors cannot be reduced to zero

Biometric authentication uses physical characteristics such as fingerprints, veins, and irises, so there is no risk of forgetting or losing them; on the other hand, the errors of falsely rejecting the genuine person and falsely accepting someone else can never be eliminated completely. Physical characteristics cannot be reissued like passwords and cannot be lent to others, so the other options are wrong.

Q24 | OTP

Which authentication method is effective in preventing unauthorized logins that reuse an eavesdropped password?

  1. Authentication by user ID alone
  2. Authentication that sends a fixed password unencrypted
  3. Authentication that stores the password in plain text on an IC card
  4. One-time password authentication
AnswerD. One-time password authentication

One-time password authentication uses disposable passwords valid only once, so even if the communication is eavesdropped, the same value cannot be used to log in again. Challenge/response authentication has a similar effect. Sending fixed passwords in plain text or authenticating by ID alone is weak against eavesdropping and guessing, and a plain-text password on a card can be abused directly if leaked.

Q25 | SSO

Which is an appropriate description of single sign-on (SSO)?

  1. A mechanism limiting simultaneous logins to a system to 1 user
  2. A mechanism allowing use of multiple linked systems and services after 1 authentication
  3. A mechanism for sharing 1 terminal among multiple users
  4. A mechanism forcing the password to be changed every time
AnswerB. A mechanism allowing use of multiple linked systems and services after 1 authentication

Single sign-on is a mechanism by which one authentication grants use of multiple linked systems without further authentication, improving convenience and reducing the burden of password management. On the other hand, if the credentials are compromised the impact spreads widely, so protecting the authentication platform is critical. Limiting simultaneous logins, periodic password changes, and terminal sharing are not SSO.

Q26 | Access control

Which is the most appropriate approach to managing access rights in an information system?

  1. Leave the accounts of retirees and transferred staff usable as they are, without deleting them
  2. To simplify management, grant administrator privileges uniformly to all staff
  3. Neither collect nor store audit logs, to save storage capacity
  4. Grant rights only within the scope needed for each person's duties, and keep access records as audit logs
AnswerD. Grant rights only within the scope needed for each person's duties, and keep access records as audit logs

The basics of access control are the principle of least privilege — granting rights only within the scope needed for one's duties — and keeping access records as audit logs. Logs are indispensable for deterring misconduct and tracing it afterward. Granting everyone administrator privileges or leaving retirees' accounts active breeds unauthorized access, and operating without audit logs destroys accountability.

Q27 | DMZ

Which is the most appropriate location for a Web server exposed to the outside?

  1. The same segment as users' terminals
  2. An external segment connected directly to the Internet without passing through a firewall
  3. The same internal network as the electronic medical record server
  4. A DMZ separated from both the internal and external networks by firewalls
AnswerD. A DMZ separated from both the internal and external networks by firewalls

A publicly exposed server is placed in the DMZ, a buffer zone separated from both the outside and the inside by firewalls, so that even if the public server is attacked and compromised, the intruder cannot reach the internal network directly. Placing it on the internal network or the terminal segment spreads damage inward when compromised, and a direct connection without a firewall is defenseless.

Q28 | IDS and IPS

Which is the appropriate difference between an intrusion detection system (IDS) and an intrusion prevention system (IPS)?

  1. An IDS blocks malicious traffic, while an IPS only detects and notifies
  2. An IDS is a device exclusively for wireless LANs and an IPS exclusively for wired LANs
  3. An IDS removes viruses and an IPS encrypts communications
  4. An IDS goes as far as detecting and reporting malicious traffic, while an IPS additionally takes automatic defensive action such as blocking
AnswerD. An IDS goes as far as detecting and reporting malicious traffic, while an IPS additionally takes automatic defensive action such as blocking

An IDS detects traffic that signals intrusion attempts and notifies the administrator, while an IPS goes further and automatically takes defensive action such as blocking the offending traffic. The option reversing the roles is wrong, and the distinction is not wired versus wireless. Virus removal is the job of antivirus software and encryption of cryptographic technology; neither is an IDS/IPS function.

Q29 | VPN

Which technology builds a virtual leased line over a public network such as the Internet using encryption and authentication?

  1. DNS
  2. DHCP
  3. NTP
  4. VPN
AnswerD. VPN

A VPN is a technology that creates a virtual leased line over a public network with encryption and authentication; variants include IPsec-VPN and SSL-VPN, and it is used to protect site-to-site links and remote access. DNS maps domain names to IP addresses, NTP synchronizes time, and DHCP assigns IP addresses automatically; none protects the communication channel.

Q30 | Patching

Which is the most direct countermeasure against attacks exploiting a published OS security hole (vulnerability)?

  1. Increase the length of passwords
  2. Take data backups every day
  3. Promptly apply the security patches distributed by the vendor
  4. Attach a privacy filter to the display to prevent shoulder surfing
AnswerC. Promptly apply the security patches distributed by the vendor

The direct countermeasure against attacks on security holes is to promptly apply the fix programs (security patches) distributed by the vendor, eliminating the vulnerability itself. Many attacks exploit known vulnerabilities left unpatched. Backups are for recovery after damage, stronger passwords concern authentication, and privacy filters are a physical measure; none removes the vulnerability.

Practice: answer the questions on this page

This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.

* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.

This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original