Karinoya Learning Room

Qualifications · IT Passport Success Lab

Security

Read the questions and explanations in English. The lectures (explanatory articles) are available in Japanese only.

View the Japanese version (with lectures) →

Q1 | Confidentiality

Among the three elements of information security, which of the following is the most appropriate example of confidentiality being compromised?

  1. An operating mistake overwrote the amounts in the sales data with wrong values
  2. A misdirected transmission delivered the customer list to an unrelated third party
  3. A server failure made the business system unavailable for half a day
  4. A program defect made the processing results come out different every time
AnswerB. A misdirected transmission delivered the customer list to an unrelated third party

Confidentiality is the property that only authorized people can access the information. The list reaching a third party means the information was seen by someone who must not see it, which is a breach of confidentiality. Becoming unusable concerns availability, the rewritten amounts concern integrity, and not working as intended is a reliability problem.

Q2 | Integrity

Which of the following is the most appropriate measure for ensuring integrity in information security?

  1. Regularly checking with hash values whether the contents of Web pages have been altered
  2. Duplicating servers so that processing can continue even during a failure
  3. Locking the server room so that outsiders cannot enter
  4. Encrypting communications so that third parties cannot read the contents
AnswerA. Regularly checking with hash values whether the contents of Web pages have been altered

Integrity is the property that information is accurate and untampered, and comparing hash values is tamper detection itself, so it serves to ensure integrity. Duplicating servers is for availability, and encrypting communications and locking the server room are measures for confidentiality, keeping information from being seen.

Q3 | Availability

Which measure has raising availability as its main purpose?

  1. Duplicating servers and installing an uninterruptible power supply, a UPS
  2. Keeping important documents locked in a safe
  3. Setting a password on a file so that it cannot be opened
  4. Assigning an ID to each user and recording operation logs
AnswerA. Duplicating servers and installing an uninterruptible power supply, a UPS

Availability is the property of being able to use systems and information when needed, and duplication and a UPS are measures to keep things running through failures and outages, so they raise availability. Password protection and safe storage are for confidentiality, and recording operation logs is a measure for ensuring accountability.

Q4 | Non-repudiation

Which of the following is the most appropriate description of non-repudiation in information security?

  1. Keeping information and systems in a state where they can be used whenever needed
  2. Making it impossible for unauthorized people to view information or take it outside
  3. Making it impossible for the person who performed an act to claim afterwards that they did not perform it
  4. Guaranteeing that information is not tampered with and is kept up to date and correct
AnswerC. Making it impossible for the person who performed an act to claim afterwards that they did not perform it

Non-repudiation is the property that the fact of an act cannot be denied afterwards, ensured through digital signatures and preservation of logs. Access only for the authorized is confidentiality, usability at any time is availability, and content kept correct is integrity; each is a separate element.

Q5 | Ransomware

Which of the following is the most effective measure to prepare for damage from ransomware?

  1. Clearly stating the company name and contact information in the signature of outgoing e-mails
  2. Weakening the radio output of the wireless LAN access point to narrow its range
  3. Having users change their passwords regularly
  4. Taking backups and storing them disconnected from the network
AnswerD. Taking backups and storing them disconnected from the network

Ransomware encrypts files and demands a ransom, so with a backup from before the infection you can recover without paying. However, a backup left connected to the network gets encrypted too, so it is stored disconnected. The other options do not help recover encrypted files.

Q6 | Malware

Which of the following is the most appropriate characteristic of a Trojan horse?

  1. It self-replicates on its own across the network, spreading infection from device to device
  2. It masquerades as useful software to get installed, then performs malicious actions without the user noticing
  3. It encrypts the files of the infected device and demands money in exchange for decryption
  4. It sends huge volumes of e-mail, bringing the mail server down
AnswerB. It masquerades as useful software to get installed, then performs malicious actions without the user noticing

A Trojan horse is malware that disguises itself as normal software so the user installs it, then steals information or allows remote control behind the scenes; its hallmark is that it does not self-replicate. Self-replicating on its own is a worm, encrypting and demanding money is ransomware, and stopping a server with mass sending describes a DoS attack.

Q7 | SQL injection

Which of the following is the most appropriate description of SQL injection?

  1. An attack that enters database commands into a website's input fields to steal or tamper with data
  2. An attack that attempts logins using ID and password pairs leaked from other sites
  3. An attack that embeds a malicious script in a bulletin board or similar and has it run in visitors' browsers
  4. An attack that sends massive traffic simultaneously from many devices, making a server unresponsive
AnswerA. An attack that enters database commands into a website's input fields to steal or tamper with data

SQL injection slips SQL statements into input values to manipulate the database illicitly, and it is prevented by input validation, the use of placeholders, and deploying a WAF. The second option describes cross-site scripting, the third a DDoS attack, and the fourth a password list attack.

Q8 | Social engineering

Which act corresponds to social engineering?

  1. Intercepting wireless LAN radio waves and decoding the communication
  2. Trying passwords by brute force to find the correct combination
  3. Phoning while posing as the system administrator and coaxing a password out of a user
  4. Exploiting an OS vulnerability to illicitly obtain administrator privileges
AnswerC. Phoning while posing as the system administrator and coaxing a password out of a user

Social engineering is a set of tricks that exploit human psychology and carelessness rather than technology to obtain information; impersonation phone calls, shoulder surfing, and dumpster diving are typical examples. Exploiting vulnerabilities, brute-force attacks, and radio interception are all attacks by technical means and do not qualify.

Q9 | Zero-day attacks

Which of the following is the most appropriate description of a zero-day attack?

  1. An attack that breaks into internal systems by exploiting accounts of retirees left undeleted
  2. An attack that targets the period right after business hours start, sending massive traffic
  3. An attack that abuses an expired digital certificate to lure people to a fake site
  4. An attack that exploits a vulnerability in the window between its disclosure and the delivery of a fix
AnswerD. An attack that exploits a vulnerability in the window between its disclosure and the delivery of a fix

A zero-day attack targets a vulnerability during the period when no fix has yet been provided; since no patch can be applied, damage is contained through defense in depth and disabling unnecessary functions. Abusing certificates, time-targeted DoS attacks, and abusing retirees' accounts are all separate problems, not the definition of a zero-day attack.

Q10 | Risk assessment

Which of the following arranges the three activities composing risk assessment in the order they are performed?

  1. Risk analysis, then risk identification, then risk evaluation
  2. Risk identification, then risk analysis, then risk evaluation
  3. Risk identification, then risk evaluation, then risk analysis
  4. Risk evaluation, then risk analysis, then risk identification
AnswerB. Risk identification, then risk analysis, then risk evaluation

Risk assessment proceeds in the order of risk identification, which uncovers what risks exist; risk analysis, which estimates the likelihood and the size of the impact; and risk evaluation, which compares against criteria to judge whether responses are needed. Analysis and evaluation are impossible before the risks are uncovered, so the other orders cannot stand.

Q11 | Risk response

A company took out cyber insurance in preparation for losses from information system failures. Which risk response does this correspond to?

  1. Risk avoidance
  2. Risk reduction
  3. Risk retention
  4. Risk transfer
AnswerD. Risk transfer

Taking out insurance or outsourcing operations is risk transfer, also called risk sharing, in which the burden of loss is shared with others. Risk avoidance is stopping the causal activity itself, risk reduction is using countermeasures to lower the probability or the damage, and risk retention is accepting the risk without countermeasures; insurance corresponds to none of those.

Q12 | Security policy

When an information security policy is structured in the three tiers of basic policy, countermeasure standards, and implementation procedures, which of the following is the most appropriate content for the implementation procedures?

  1. The organization's philosophy on information security and the declaration by management
  2. The concrete operating steps for the backup software and the procedure for its execution times
  3. A rule to be observed, the standard that passwords must be at least 12 characters including letters, digits, and symbols
  4. The establishment of an information security committee and the definition of its role
AnswerB. The concrete operating steps for the backup software and the procedure for its execution times

The implementation procedures are the lowest-tier documents, recording concrete operating steps that staff can follow while working. The organization's philosophy and management's declaration belong to the top-level basic policy, and the rules, standards, and organizational arrangements belong to the countermeasure standards; those are different tiers.

Q13 | ISMS

Which of the following is the most appropriate statement about an ISMS, an information security management system?

  1. It is a framework in which an organization sets policy, implements measures, and checks and improves them, continuously turning the PDCA cycle, with the requirements set out in JIS Q 27001
  2. It is a program that permits businesses handling personal information appropriately to use a certification mark
  3. It is a specialist organization that monitors the network 24 hours a day and detects signs of attack
  4. It is a specialist team that, when a computer security incident occurs in an organization, handles everything from receiving reports through cause investigation, containment, and recovery
AnswerA. It is a framework in which an organization sets policy, implements measures, and checks and improves them, continuously turning the PDCA cycle, with the requirements set out in JIS Q 27001

An ISMS is a framework for managing information security organizationally and continuously, with its requirements set out in JIS Q 27001, corresponding to ISO/IEC 27001. The first option describes the Privacy Mark program, the third a CSIRT, and the fourth a SOC; none is a description of the ISMS itself.

Q14 | CSIRT

Which of the following is the most appropriate role of a CSIRT?

  1. Drawing up information system development plans and managing development progress and quality
  2. Receiving reports of security incidents and carrying out cause investigation, containment of damage, recovery, and communication with related parties
  3. Auditing, from an independent position, whether the company's accounting and financial statements are proper
  4. Examining businesses for proper handling of personal information and granting a certification mark
AnswerB. Receiving reports of security incidents and carrying out cause investigation, containment of damage, recovery, and communication with related parties

A CSIRT is a specialist team responsible for security incidents, from intake through cause investigation, containment, recovery, and information sharing. Accounting audits, development progress management, and granting certification marks are the roles of other organizations and programs, not CSIRT work. Constantly monitoring logs to detect attacks is the job of a SOC.

Q15 | DMZ

Which of the following is the most appropriate reason for placing a publicly exposed Web server in a DMZ?

  1. Because it raises the server's processing speed and shortens response times
  2. Because even if the public server is compromised, direct intrusion into the internal network can be prevented
  3. Because backups of the public server can then be taken automatically
  4. Because it cuts the server's power consumption and reduces operating costs
AnswerB. Because even if the public server is compromised, direct intrusion into the internal network can be prevented

A DMZ, a demilitarized zone, is a segment separated from both the Internet and the internal LAN, a configuration that keeps damage from spreading inside even if the public server is compromised. Processing speed, power consumption, and automated backups have nothing to do with partitioning the network.

Q16 | WAF

Which of the following is the most appropriate description of a WAF, a Web Application Firewall?

  1. A mechanism that inspects the content of communications to Web applications and blocks attacks such as SQL injection
  2. A mechanism that encrypts wireless LAN communications to prevent eavesdropping
  3. A mechanism that automatically inspects files attached to e-mail for viruses before they are opened
  4. A mechanism that verifies a person's identity using fingerprints or irises
AnswerA. A mechanism that inspects the content of communications to Web applications and blocks attacks such as SQL injection

A WAF inspects the contents of traffic destined for Web applications and blocks Web-specific attacks such as SQL injection and cross-site scripting. Wireless LAN encryption is WPA2 or WPA3, attachment inspection is antivirus software, and fingerprint or iris verification is biometric authentication; none of these is a WAF.

Q17 | Biometrics

In biometric authentication, when the judgment criterion is made stricter, how do the false rejection rate, FRR, and the false acceptance rate, FAR, change?

  1. FRR becomes lower and FAR becomes higher
  2. Both FRR and FAR become higher
  3. FRR becomes higher and FAR becomes lower
  4. Both FRR and FAR become lower
AnswerC. FRR becomes higher and FAR becomes lower

Making the judgment stricter lowers FAR, mistakenly accepting others, but even the genuine person is more easily rejected over slight differences, so FRR rises. The two are in a trade-off where lowering one raises the other; they cannot be lowered or raised together, so the criterion is set by balancing convenience against security.

Q18 | Multi-factor authentication

Which combination corresponds to multi-factor authentication?

  1. Entering a password and entering a one-time password delivered to a smartphone
  2. Entering a login password and answering a secret question
  3. Entering a login password and re-entering another password
  4. Entering a user ID and entering a password
AnswerA. Entering a password and entering a one-time password delivered to a smartphone

Multi-factor authentication combines two or more factors of different kinds: knowledge, possession, and biometrics. A password, knowledge, and a one-time password received on a smartphone, possession, are different kinds, so that combination qualifies. Secret questions and additional passwords are both knowledge, and a user ID is not a secret known only to the person, so none of the others is multi-factor.

Q19 | Zero trust

Which of the following is the most appropriate description of the zero trust concept?

  1. User convenience comes first, and password expiration and mandatory changes are abolished
  2. Nothing is trusted, whether inside or outside the company, and on every access the user and the device are verified and only the minimum necessary privileges are granted
  3. Communications from inside the company network are treated as trustworthy, and authentication may be omitted for subsequent access
  4. All communication with the outside is completely banned, and systems are used only within a closed internal network
AnswerB. Nothing is trusted, whether inside or outside the company, and on every access the user and the device are verified and only the minimum necessary privileges are granted

Zero trust discards the assumption that being inside the perimeter means safety, verifying on every access and granting only the minimum necessary privileges. Skipping authentication for internal traffic is precisely the weakness of traditional perimeter defense, and banning outside communication or abolishing expiration dates has nothing to do with the definition of zero trust.

Q20 | Physical measures

Among information security measures, which is classified as a physical measure?

  1. Promptly applying patches to the Web server
  2. Updating the antivirus software's pattern files every day
  3. Conducting targeted attack e-mail drills for all employees
  4. Installing an IC-card entry control device at the server room entrance
AnswerD. Installing an IC-card entry control device at the server room entrance

Physical measures prevent approach to and removal of the equipment and documents themselves, and include locking, entry control, surveillance cameras, and clear desks. Conducting drills is a human measure, and updating pattern files and applying patches are technical measures implemented through software.

Q21 | Encryption schemes

Compared with symmetric key cryptography, which of the following is the most appropriate characteristic of public key cryptography?

  1. When n people communicate with one another, the total number of keys needed is n(n-1)/2
  2. The key used for encryption can be made public, so the problem of delivering keys securely rarely arises
  3. The same key is used for encryption and decryption, so only one key needs to be managed
  4. Processing is fast, making it suitable for encrypting large amounts of data at once
AnswerB. The key used for encryption can be made public, so the problem of delivering keys securely rarely arises

The greatest advantage of public key cryptography is that the public key may be published, so the key distribution problem rarely arises. Being fast and suited to large data describes symmetric key cryptography, needing n(n-1)/2 keys is also symmetric key cryptography, and using the same key for encryption and decryption is symmetric key cryptography as well.

Q22 | Public key encryption

A wants to send B an e-mail that only B can read, using public key cryptography. Which key does A use for the encryption?

  1. B's public key
  2. A's public key
  3. B's private key
  4. A's private key
AnswerA. B's public key

For encryption aimed at confidentiality, you encrypt with the recipient B's public key. The only key that can decrypt it is B's private key, so no one but B can read it. Encrypting with A's private key would be a digital signature, A's public key is obtainable by anyone so secrecy cannot be kept, and B's private key is not in A's possession.

Q23 | Creating signatures

A attaches a digital signature to a document and sends it. Which is the appropriate combination of the key used to create the signature and its effect?

  1. Using A's private key, showing that A personally created it and that it has not been tampered with
  2. Using B's public key, so that only B can read the document
  3. Using A's public key, keeping the document's contents secret
  4. Using B's private key, proving the fact that B received it
AnswerA. Using A's private key, showing that A personally created it and that it has not been tampered with

A digital signature is created by encrypting the document's hash value with the sender A's private key. Since only A holds that private key, it shows that A personally created the document, authenticity and non-repudiation, and that it has not been altered. Encrypting with the recipient's public key is encryption for confidentiality, the sender's public key is the key used for verification, and the recipient's private key is not usable by the sender.

Q24 | Verifying signatures

B has received a digitally signed document from A. Which key does B use to verify the signature?

  1. B's private key
  2. A symmetric key A and B shared in advance
  3. B's public key
  4. A's public key
AnswerD. A's public key

The signature is created with the sender A's private key, so it can be verified only with its counterpart, A's public key. Successful verification is the evidence that A personally created it. B's keys are for decrypting messages addressed to B and for B's own signatures and cannot verify this, and a symmetric key cannot pin down who created the document, so it cannot be used for signature verification.

Q25 | PKI and TLS

Which of the following is the most appropriate statement about the server's digital certificate used in HTTPS communication?

  1. It is used to deposit passwords entered by users with the certification authority so it can verify them on the server's behalf
  2. It is used to distribute the server's private key itself safely to users' browsers
  3. It guarantees that the communication data is always encrypted with public key cryptography only, never symmetric key cryptography
  4. It is issued by a certification authority and guarantees that the server's public key really belongs to that server
AnswerD. It is issued by a certification authority and guarantees that the server's public key really belongs to that server

A digital certificate is issued by a certification authority, a CA, after verifying the applicant, binding the public key to its owner's information, and it guarantees the public key's legitimacy. The private key is never distributed. Nor is it a scheme for depositing passwords with the CA. TLS uses hybrid encryption: public key cryptography delivers a symmetric key, and the payload is encrypted with symmetric key cryptography.

Practice: answer the questions on this page

This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.

* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.

This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original