Of the three elements of information security (the CIA triad), which best describes integrity?
Making sure a user or a piece of data really is who or what it claims to be
Keeping information accessible only to authorized parties and not disclosing it to anyone unauthorized
Authorized parties being able to use information and information systems without interruption whenever needed
Information being accurate and complete, with no unauthorized alteration or destruction
AnswerD. Information being accurate and complete, with no unauthorized alteration or destruction
Integrity refers to the accuracy of information and the absence of tampering. The first choice describes confidentiality and the third describes availability, while the fourth describes authenticity, an additional property outside the CIA triad. The key point is not to confuse the definitions of the three CIA terms.
Q2 | Tampering and the CIA triad
The top page of a company's website was rewritten by an unknown party and now shows completely different content. Which property was most compromised?
Availability
Non-repudiation
Integrity
Confidentiality
AnswerC. Integrity
Integrity is compromised because the content was altered without authorization. Confidentiality is not the issue since no information leaked outward, and availability is not the issue since the site is still displaying and has not gone down. Non-repudiation, which prevents someone from later denying an action, does not describe this event.
Q3 | Downtime and the CIA triad
A company's order-taking site was hit by a flood of concentrated traffic and stopped responding for half a day. Which property was most compromised?
Confidentiality
Availability
Authenticity
Integrity
AnswerB. Availability
Availability is compromised because the service could not be used when needed. Confidentiality is not the issue since no data was handed to outsiders, and integrity is not the issue since the stored information was not altered. Authenticity concerns confirming that someone or something is genuine, which does not apply here.
Q4 | Leakage and the CIA triad
A customer list file was taken outside the company and published on the internet. The file's contents were not altered, and internal operations were unaffected. Which property was most compromised?
Reliability
Confidentiality
Availability
Integrity
AnswerB. Confidentiality
Confidentiality is compromised because unauthorized parties are now able to view the information. Integrity is preserved since the content was not altered, and availability is preserved since the file remains usable internally. Reliability concerns a system behaving as intended and does not apply here.
Q5 | Double extortion
A company was infected with ransomware, and its business files were encrypted and could no longer be opened. The attacker further warned, “We stole your data before encrypting it. If you do not pay, we will publish it.” Which combination of properties was compromised (or at risk of being compromised) by this event?
Availability and confidentiality
Reliability and non-repudiation
Confidentiality and non-repudiation
Integrity and accountability
AnswerA. Availability and confidentiality
Encryption that makes files unusable is a violation of availability, and the theft of data along with the threat to publish it is a violation of confidentiality. Integrity concerns whether content has been altered, accountability concerns being able to trace whose action something was, reliability concerns behaving as intended, and non-repudiation concerns preventing denial of an action — none of these is the central issue in this event.
Q6 | Accidental overwrite
While editing a summary sheet, a staff member made an operating mistake and saved over a finalized figure with a different value. The file still opens normally and work can continue, but the recorded content no longer matches the facts. Which property was most compromised?
Accountability
Availability
Integrity
Confidentiality
AnswerC. Integrity
This is an integrity problem because the accuracy of the information has been lost. Whether the cause was an attack or not is irrelevant to which property is affected — integrity is compromised even by a mistake. The file still opens, so availability is preserved, and nothing leaked outside, so confidentiality is not the issue. Accountability is the property of being able to trace whose action something was.
Q7 | Shared IDs
In one department, everyone logs into the business system using a single ID shared by the whole department. Which property is most compromised by this practice?
Reliability
Integrity
Accountability
Availability
AnswerC. Accountability
Even if operation logs remain, no one can tell which individual performed a given action, so accountability is compromised. Everyone can still log in, so this is not an availability problem, and neither the system behaving as intended (reliability) nor the accuracy of data (integrity) is directly lost. As a rule, IDs should be assigned to individuals, not shared.
Q8 | Non-repudiation
You want to prevent a situation where a business partner who placed an electronic order later claims, “We never placed that order.” Which combination of a property and a countermeasure is most appropriate for this purpose?
Availability — making servers and networks redundant
Reliability — validating input values
Non-repudiation — applying digital signatures
Confidentiality — encrypting the communication path
AnswerC. Non-repudiation — applying digital signatures
Non-repudiation is the property that prevents someone from later denying an action, and digital signatures and timestamps are its representative countermeasures. Redundancy is an availability measure against downtime, encryption is a confidentiality measure against being observed, and input validation is a measure for making the system behave correctly; none of these guards against later denial.
Q9 | Authenticity
You want to confirm that a message from someone claiming to be a contact person at a business partner really came from that person. Which information security property addresses this purpose?
Authenticity
Availability
Non-repudiation
Integrity
AnswerA. Authenticity
Authenticity is the property of making sure someone or something really is who or what it claims to be, and countermeasures against impersonation fall under it. Availability concerns being usable, integrity concerns content being correct, and non-repudiation concerns preventing denial of an action already taken; none of these directly represents confirming whether the other party is who they claim to be.
Q10 | Example of a vulnerability
In the relationship among threats, vulnerabilities, and risk, which of the following is the most appropriate example of a vulnerability?
An outside attacker attempts unauthorized access to the company's servers over the internet
A server room floods due to a disaster such as an earthquake or lightning strike, making the equipment unusable
The possibility that a leaked customer list results in damages such as compensation claims or loss of trust
A business server has been left without a security patch applied
AnswerD. A business server has been left without a security patch applied
A vulnerability is a weakness that a threat can exploit, and an unapplied patch is a typical example. An earthquake or an attempted intrusion is a threat that acts from outside, and the possibility of resulting damage is risk. In practice, the key point is that threats are hard for a company to eliminate on its own, whereas vulnerabilities can be reduced through organizational effort.
Q11 | The risk formula
There is a way of thinking about the size of risk as “threat × vulnerability × asset value.” As an information security leader in a business unit, which explanation of how to apply this idea is most appropriate?
The most realistic way to reduce risk is for the company to reduce the number of threat occurrences itself through its own effort
Because asset value cannot be changed for business reasons, evaluating the size of risk has no bearing on concrete countermeasures
If even one of the three factors is large, the risk is always at its maximum regardless of how small the other two factors are
Vulnerability is the factor the company can most directly act on, so reducing it lowers risk even if the threat stays the same
AnswerD. Vulnerability is the factor the company can most directly act on, so reducing it lowers risk even if the threat stays the same
The occurrence of a threat itself, such as an earthquake or a malware outbreak, cannot be reduced by the company, and asset value is also hard to lower for business reasons. Reducing vulnerability through patching and training is the realistic way to lower risk. Risk evaluation is not meaningless, since it is used to prioritize countermeasures, and because the relationship is multiplicative, the overall risk shrinks if any one factor is small.
Q12 | Physical threats
When threats are classified into human threats, physical threats, and technical threats, which of the following falls under a physical threat?
A server is accessed without authorization from outside
Someone is tricked by a fake contact into revealing their password
A server stops because a power outage was caused by a lightning strike
An employee sends an email to the wrong recipient
AnswerC. A server stops because a power outage was caused by a lightning strike
Disasters and accidents such as lightning strikes and power outages are physical threats. A misdirected email is a human threat caused by a mistake, unauthorized access is a technical threat using information technology, and tricking someone into revealing a password is social engineering, which is classified as a human threat.
Q13 | Preventing misdirected email
It has become clear that the leading cause of information leaks within the company is misdirected email, caused by choosing the wrong recipient. Which response is most appropriate for the information security leader?
Prioritize defenses against outside attacks by strengthening the firewall and tightening monitoring of external communications
Publicize internally, each time it happens, the name of the employee who sent the misdirected email and the count, to keep everyone alert
Put in place pre-send procedures and checks, such as confirming multiple recipients and encrypting attachments
Ban the use of email entirely and switch all outside communication to phone, postal mail, or in-person meetings
AnswerC. Put in place pre-send procedures and checks, such as confirming multiple recipients and encrypting attachments
Because the cause is human error, preventing recurrence through procedures and checks is the appropriate response. Strengthening the firewall targets outside attacks and does not address the cause. Publicly naming individuals invites people to hide reports out of fear and backfires, and banning email entirely is not realistic since it would prevent business from functioning.
Q14 | The three elements of fraud
Which combination correctly makes up the three elements of the “fraud triangle,” a model that explains why internal fraud occurs?
People, technology, and physical environment
Opportunity, motive, and rationalization
Threat, vulnerability, and asset value
Confidentiality, integrity, and availability
AnswerB. Opportunity, motive, and rationalization
The fraud triangle holds that fraud occurs when opportunity, motive, and rationalization are all present. Threat, vulnerability, and asset value are the factors used to gauge the size of risk; confidentiality, integrity, and availability are the three elements of information security; and people, technology, and physical environment are an axis for classifying threats and controls — all of these are different concepts.
Q15 | Reducing opportunity
Among the three elements of the fraud triangle, which control is most appropriate for reducing “opportunity”?
Setting up a consultation desk for employees so they can discuss personal worries or financial troubles
Repeatedly telling employees in security training that fraud amounts to a crime, to raise awareness
Limiting access rights to important data to only those who need them for their work, and periodically reviewing operation logs
Clarifying performance evaluation criteria and giving treatment employees find fair, so dissatisfaction does not build up
AnswerC. Limiting access rights to important data to only those who need them for their work, and periodically reviewing operation logs
Opportunity is “an environment where wrongdoing is possible if someone chooses to attempt it,” and least-privilege access combined with log review directly reduces it. A consultation desk or improved treatment works on motive, and raising awareness through training works on rationalization; neither directly reduces opportunity itself. Opportunity is also the element an organization can control most reliably.
Q16 | Rationalization
An employee who took a customer list out of the company said, “I made this document myself, so I thought of it as mine.” Which element of the fraud triangle does this statement represent?
Opportunity
Motive
Threat
Rationalization
AnswerD. Rationalization
An excuse that reframes one's own act favorably to dispel guilt is rationalization. Opportunity refers to environmental factors such as loose authority or weak checks, and motive refers to circumstances such as financial hardship or dissatisfaction. Threat is not an element of the triangle but a concept that makes up risk. Rationalization is addressed through training and the signing of pledges.
Q17 | Trashing
Among social engineering techniques, which of the following describes trashing (scavenging)?
Directly peeking at a user's screen or keyboard input from behind them or from a neighboring seat
Collecting information from documents, notes, or storage media that have been thrown away as trash
Calling by phone while posing as a system administrator to get a user to reveal their password
Following closely behind an authorized person entering a door and passing through without being authenticated oneself
AnswerB. Collecting information from documents, notes, or storage media that have been thrown away as trash
Trashing gathers information from discarded waste, and countermeasures include shredding documents and locking up confidential ones for collection. The second choice is shoulder surfing, the third is tailgating (piggybacking), and the fourth is impersonation used to extract information; each is a different technique.
Q18 | Preventing shoulder surfing
A sales representative frequently opens a laptop at a cafe while out and handles customer information there. Which measure is most appropriate against shoulder surfing?
Keep the antivirus software's definition files up to date and run periodic full scans
Attach a privacy filter to prevent peeking, and always lock the screen when stepping away
Encrypt the communication before sending it to a server outside the company
Change passwords periodically and stop reusing the same one across multiple services
AnswerB. Attach a privacy filter to prevent peeking, and always lock the screen when stepping away
Shoulder surfing is directly peeking at a screen or input, so physically blocking the view and locking the screen when away from the seat are effective countermeasures. Updating definition files is a measure against malware, and encrypting communications is a measure against eavesdropping on the transmission path; neither prevents someone from simply looking. Changing passwords reduces the impact after being observed but does not prevent the observation itself.
Q19 | Shadow IT
It turns out that employees have been saving business files to a free online storage service the company is unaware of, and sharing them within the department. Which of the following is the most appropriate description of the problem with this situation?
The organization cannot grasp or control where data is stored or how widely it is shared, so it cannot detect or respond to an incident
The cost of storing the files ends up being borne by the department's budget
Personal use during working hours increases, creating a labor-management issue that must be addressed
Free services have slower transfer speeds than paid ones, which reduces work efficiency when sharing large files
AnswerA. The organization cannot grasp or control where data is stored or how widely it is shared, so it cannot detect or respond to an incident
This is a case of shadow IT, and the essential problem is that it falls outside the organization's management and monitoring. Speed, cost, and labor management are not the main information security issues here. Simply banning the practice leaves the underlying business need unmet, so the countermeasure is for the organization to offer an approved service along with a request-and-record process.
Q20 | Handling a departing employee
A staff member is due to leave the company next week. Which response to the risk posed by a departing employee should be given the highest priority?
Contact the former employee after departure and have them self-report whether they took any data
Leave the account active for a while after departure in case it is needed for the handover
Let the successor take over and continue using the same ID and password as-is
Reliably deactivate the account on the last day and collect any loaned equipment and building access card
AnswerD. Reliably deactivate the account on the last day and collect any loaned equipment and building access card
A departing employee's account remaining active is a classic vulnerability, so deactivating it on the last day and collecting loaned items is the top priority. Keeping an account active for handover purposes leaves room for misuse. Relying on a self-report after departure has little real effect, and handing over an ID to a successor destroys accountability, so both are inappropriate.
Q21 | Via a contractor
The company has strengthened its own defenses, but a computer at a business it outsources work to was infected with malware, and customer data entrusted to that business leaked as a result. Which combination of a name for this kind of threat and an approach to addressing it is most appropriate?
Physical threat — strengthen entry and exit control and locking practices for the company's own server room
Internal fraud — review the company's own employees' access rights and strengthen operation log checks
Shadow IT — ban the use of services the company has not approved and take inventory of usage
Supply chain risk — set selection criteria and contractual terms for contractors, and conduct regular reviews
AnswerD. Supply chain risk — set selection criteria and contractual terms for contractors, and conduct regular reviews
Damage that reaches a company through a contractor or business partner is a supply chain risk, which cannot be prevented by the company's own measures alone. Selection criteria for contractors, contractual safeguards and terms covering subcontracting, and checks on how those terms are carried out form the core of the response. Internal fraud is intentional wrongdoing by the company's own people, a physical threat is a disaster or theft, and shadow IT is use of unrecognized devices or services; none of these captures the essence of this case.
Q22 | Operational shortcomings
Which of the following is the most appropriate example of a vulnerability caused by an operational shortcoming?
Heavy rain floods the basement of a building and submerges equipment installed there
A user keeps using a simple, easily guessed password without changing it
The information asset inventory has not been reviewed in years and no longer matches reality
A programming mistake causes the application to crash when given unexpected input
AnswerC. The information asset inventory has not been reviewed in years and no longer matches reality
Failing to keep the inventory up to date, leaving the organization unaware of the actual state of its assets, is a vulnerability caused by a shortcoming in operating procedures. An implementation mistake is a software flaw, an easily guessed password chosen by the user is a vulnerability caused by carelessness on the user's part, and flooding from heavy rain is a physical threat rather than a vulnerability. Note that a vulnerability is not limited to software flaws alone.
Q23 | Zero-day
Which of the following most appropriately describes a zero-day vulnerability?
A vulnerability caused by lax password management by users, which can be resolved through training
A vulnerability that exists only in products whose support has ended and no longer receive updates
A minor vulnerability for which a patch was released within 30 days of discovery
A vulnerability that exists before a patch has been made available, or an attack that exploits that state
AnswerD. A vulnerability that exists before a patch has been made available, or an attack that exploits that state
Zero-day refers to the state where no patch yet exists, and the essential point is that applying a patch cannot defend against it. It is not defined by the number of days until a fix, nor is it a concept limited to products past end of support. Lax password management is a separate vulnerability caused by user carelessness and is unrelated to zero-day.
Q24 | Responding to a zero-day
A serious vulnerability was announced in software used for business, and the vendor stated that “a patch is under investigation with no release date set, but an interim workaround has been published.” Which response is most appropriate for the information security leader?
Since the vulnerability is already public, quietly wait and see without informing anyone inside the company, to avoid causing confusion
Since there is nothing to be done until a patch is released, wait for it and continue normal operation
Combine applying the workaround, taking affected devices off external exposure or isolating them, and strengthening monitoring and recovery preparedness to limit the damage
Since keeping the definition files up to date is enough to prevent it, just update the antivirus software and observe the situation
AnswerC. Combine applying the workaround, taking affected devices off external exposure or isolating them, and strengthening monitoring and recovery preparedness to limit the damage
Even without a patch, damage can be limited through layered preparations such as applying the workaround, isolating affected systems, strengthening monitoring, and preparing to restore from backup. Simply waiting leaves the organization defenseless, and updating antivirus software mainly detects known malware and cannot by itself block exploitation of the vulnerability. Hiding the situation from those involved only delays the response.
Q25 | Patch decisions
Numerous patches have been released for several servers that make up a business system. Which approach to applying them is most appropriate?
Because operations might stop, postpone applying patches until the next system replacement and keep running as-is
Apply every released patch immediately to the production environment without prior testing or checking the impact on operations
Grasp the affected assets using the asset inventory, prioritize based on severity and business impact, test, and then apply the patches according to a plan
Leave the decision of whether to apply patches to each individual user, to be carried out whenever they feel it necessary and convenient
AnswerC. Grasp the affected assets using the asset inventory, prioritize based on severity and business impact, test, and then apply the patches according to a plan
Patch management is an ongoing process of identifying the affected assets, assessing severity and business impact, testing, applying, and recording. Applying everything at once without testing risks halting operations, while leaving it until the next system replacement leaves the vulnerability exposed in the meantime. Leaving the decision to each individual user means the organization loses track of what has been applied, leading to gaps.
Q26 | CVE
Which of the following most appropriately describes CVE?
A portal site that provides vulnerability countermeasure information in Japanese for domestic use
A common standard that scores the severity of a vulnerability on a scale from 0.0 to 10.0
A testing method that verifies whether intrusion is possible from an attacker's perspective
A globally common identification number assigned to an individual vulnerability
AnswerD. A globally common identification number assigned to an individual vulnerability
CVE is an identification number that lets everyone involved refer to the same vulnerability without confusion; it does not by itself represent severity. The scoring standard for severity is CVSS, the domestic portal for vulnerability information is JVN, and testing whether intrusion is possible is penetration testing — each plays a different role.
Q27 | Using CVSS
An announced vulnerability had a very high CVSS base score. Which way of handling this information is most appropriate?
A vulnerability with a high base score must always be addressed with top priority regardless of the affected device's importance or exposure
The base score is an indicator determined by the product's sale price, so it is unsuited for judging the priority of countermeasures
The base score is a common yardstick, and the organization should decide its own priority by also considering the affected device's importance and its exposure to the outside
A higher base score means the attack is harder to carry out, so applying the patch is unnecessary and monitoring alone is sufficient
AnswerC. The base score is a common yardstick, and the organization should decide its own priority by also considering the affected device's importance and its exposure to the outside
CVSS expresses a vulnerability's severity on a common scale; it is not by itself the organization's own priority. An isolated device and one exposed to the outside carry different levels of urgency, and such circumstances are reflected through the environmental metrics. Settling for monitoring alone despite a high score is inappropriate, and the score has nothing to do with price.
Q28 | JVN
Which of the following is jointly operated by JPCERT/CC and IPA to provide vulnerability information and countermeasures in Japanese for products used domestically?
CVE
ISMS
CVSS
JVN
AnswerD. JVN
JVN is the domestic portal site for vulnerability countermeasure information. CVSS is a severity scoring method and CVE is a common identification number for vulnerabilities; neither is itself an information portal. ISMS refers to an information security management system, a separate concept from providing vulnerability information.
Q29 | Difference between assessments
Which explanation of the difference between vulnerability assessment and penetration testing is most appropriate?
Both can be freely carried out from outside without obtaining the permission of the target system's administrator
Both involve exactly the same activity, differing only in name
Vulnerability assessment is an activity that actually attempts intrusion, while penetration testing is an activity that identifies known weaknesses
Vulnerability assessment comprehensively identifies known weaknesses, while penetration testing actually attempts intrusion to verify whether the objective can be achieved
AnswerD. Vulnerability assessment comprehensively identifies known weaknesses, while penetration testing actually attempts intrusion to verify whether the objective can be achieved
Vulnerability assessment comprehensively identifies weaknesses much like a medical checkup, while penetration testing is a hands-on test of whether an actual breach is possible; because their purposes differ, neither substitutes for the other. The choice that reverses this explanation is incorrect, and both require the target system administrator's permission and an agreed scope before being carried out.
Q30 | Managing end of life (EOL)
Several of the business PCs used in a department are approaching the end of OS support (EOL). They run stably, and the field has requested that they continue to be used. Which judgment is most appropriate for the information security leader?
Installing antivirus software and keeping its definition files updated will maintain safety even after support ends
Since there is no problem as long as it runs stably, keep using it until the hardware fails and can no longer be used
Because newly found vulnerabilities will no longer be fixed after support ends, plan and carry out an upgrade or replacement before the deadline
As long as it is not connected to the internet after support ends, the vulnerability risk disappears
AnswerC. Because newly found vulnerabilities will no longer be fixed after support ends, plan and carry out an upgrade or replacement before the deadline
After support ends, vulnerabilities that are discovered will no longer be fixed, so the risk grows over time. Stable operation is no basis for safety, and antivirus software does not close the OS's own vulnerabilities. Disconnecting from the network is a stopgap that reduces exposure, but risks such as infection via external media remain, so the vulnerability does not disappear.
Q31 | Worms
Which of the following most appropriately describes a worm?
It encrypts many files used for business, making them unreadable, and demands payment in exchange for restoring them
It disguises itself as useful software, gets a user to install and run it, and secretly carries out unauthorized actions such as stealing information
It attaches itself to another program or file and spreads when the host is run by a user
It needs no host, and spreads on its own as an independent program over a network
AnswerD. It needs no host, and spreads on its own as an independent program over a network
A worm's defining feature is that it needs no host and self-propagates on its own. The first choice describes a Trojan horse, the second describes a virus in the narrow sense, and the fourth describes ransomware. Viruses and worms are distinguished by whether or not they require a host.
Q32 | Viruses
Which of the following is the most appropriate characteristic of a virus in the narrow sense?
It cannot exist on its own and spreads by attaching itself to another program or file
It collects information on a device without the user noticing and sends it to an outside attacker
It does not self-propagate, and instead operates by disguising itself as something useful so the user runs it themselves
It makes an infected device act on the instructions of an outside command-and-control server, turning it into a launching point for attacks
AnswerA. It cannot exist on its own and spreads by attaching itself to another program or file
A virus in the narrow sense requires a host program or file, and spreads when that host is run. The second choice describes a bot, the third describes spyware, and the fourth describes a Trojan horse; each is a different type. Note the distinction from cases where the word “virus” is used loosely to mean malware in general.
Q33 | Trojan horse
An employee obtained software introduced as a convenient business tool from the internet and ran it. On the surface it behaved as described, but behind the scenes it was sending internal company documents outside. There is no sign it self-propagated to other devices. Which classification of malware is most appropriate?
Trojan horse
Worm
Macro virus
Ransomware
AnswerA. Trojan horse
Disguising itself as useful software to get the user to run it themselves, without self-propagating, is the defining feature of a Trojan horse. A worm would self-propagate without needing a host, and a macro virus spreads by abusing the macro function of document files. Ransomware would involve encryption and a monetary demand, so none of these fits.
Q34 | Ransomware
Which of the following most appropriately describes ransomware?
It encrypts files or a system to make them unusable and demands a ransom in exchange for restoring them
It plants a backdoor that allows entry without going through proper authentication, so it can be freely accessed afterward
It remotely controls an infected device from outside and bundles it with others as a launching point for a DDoS attack
It secretly logs keyboard input to steal information such as IDs and passwords
AnswerA. It encrypts files or a system to make them unusable and demands a ransom in exchange for restoring them
Ransomware is malware that renders files or systems unusable, typically through encryption, and then demands money. The first choice describes a keylogger, the second a backdoor, and the fourth a bot (part of a botnet), each with a different purpose and behavior. In recent years, double extortion has been added, where data is also stolen and its publication threatened.
Q35 | Responding to double extortion
An organization is considering its policy for preparing against ransomware damage. Which policy is most appropriate?
Since paying the ransom is certain to allow decryption and also prevents recurrence, set aside a budget in advance premised on paying
Upon infection, give top priority to promptly reinitializing devices and resuming operations without keeping any records
Since damage will not occur as long as backups exist on the same network as the production environment, drills of the recovery procedure and preparation for reporting are unnecessary
In addition to backups kept separate from the production environment and drills of the recovery procedure, also prepare reporting and notification processes that assume data has been stolen and may be published
AnswerD. In addition to backups kept separate from the production environment and drills of the recovery procedure, also prepare reporting and notification processes that assume data has been stolen and may be published
There is no guarantee that paying will result in successful decryption, and paying also funds the criminal organization. Under double extortion, even if recovery succeeds, the damage from an information leak remains, so backups alone are not enough and reporting and notification must also be prepared. Reinitializing without keeping evidence prevents both root-cause investigation and prevention of recurrence, and also hampers any explanation to outside parties.
Q36 | Spyware
Which of the following most appropriately describes spyware?
It collects information and activity on a device without the user noticing and sends it outside
It attaches itself to other programs or files and spreads each time the host is run
It encrypts files to make them unusable, halting operations and demanding money
It self-propagates over a network and floods the connection with heavy traffic, hindering business as a whole
AnswerA. It collects information and activity on a device without the user noticing and sends it outside
Spyware neither destroys nor encrypts anything; its defining trait is lying low, collecting information, and sending it out. The second choice describes a worm, the third describes ransomware, and the fourth describes a virus in the narrow sense. Because it produces no obvious symptoms, noticing an infection is a management challenge.
Q37 | Bots and C&C
It was found that several PCs inside a company were repeatedly communicating with an outside server not used for business. Investigation revealed that these devices had been infected with malware and, following commands from outside, had taken part in attacks against other companies. Which combination correctly names this malware and the server it communicates with?
Spyware — proxy server
Ransomware — authentication server
Bot — C&C server
Macro virus — mail server
AnswerC. Bot — C&C server
Malware that makes an infected device act on commands from outside is a bot, and the server that issues those commands is called a C&C server. A collection of many bot-infected devices is a botnet, which can be abused for DDoS attacks or spam. The important point is that an infected organization becomes both a victim and, at the same time, an unwitting attacker; the other combinations mismatch behavior and role.
Q38 | Backdoors and logging
Which combination of explanations for keyloggers and backdoors is most appropriate?
A keylogger records key input to steal information, and a backdoor creates an entry point that bypasses proper authentication
A keylogger encrypts files to make them unusable, and a backdoor provides the decryption key for them
A keylogger encrypts communications, and a backdoor decrypts encrypted communications
A keylogger self-propagates across an entire network, and a backdoor detects and stops that propagation
AnswerA. A keylogger records key input to steal information, and a backdoor creates an entry point that bypasses proper authentication
A keylogger records input to steal IDs and passwords, and a backdoor leaves behind an entry point that makes future re-entry easy. Encryption and decryption relate to ransomware or cryptographic technology, and self-propagation is a characteristic of worms. Because a backdoor allows continued intrusion even after the visible infection has been removed, cutting off the entry route and performing a full inspection are necessary.
Q39 | Fileless malware
Which of the following is the most appropriate reason fileless malware is hard to find with traditional malware countermeasures?
It operates solely through the macro function of document files and has no executable file form whatsoever
It leaves no file on disk and instead operates in memory or by abusing legitimate OS functions
It performs no action at all upon infection and causes no real harm, so there is no need to detect it
It runs extremely slowly, falling outside the scope of monitoring and evading detection
AnswerB. It leaves no file on disk and instead operates in memory or by abusing legitimate OS functions
Because fileless malware leaves no file to be scanned, pattern matching that scans files struggles to catch it. It is not because it runs slowly or causes no harm. Abusing macro functions is characteristic of a macro virus, which differs in that a document file, an actual artifact, remains behind.
Q40 | Detection methods
Despite always keeping the antivirus software's definition files up to date, damage occurred from an unknown piece of malware. Which understanding of and response to this situation is most appropriate?
Because pattern matching can only detect known threats, also use other methods such as behavior-based detection and sandboxing, and prepare a detection, isolation, and recovery system that assumes infection can happen
Since infection is impossible as long as the definition files are current, conclude that this incident was a false positive by the product
Increasing the update frequency to receive definitions many times a day will eventually let the definitions catch up even with malware not yet known to the world, guaranteeing detection
Deploying multiple antivirus products in layers means each product's definition files cover the others' gaps, so no unknown malware can slip through
AnswerA. Because pattern matching can only detect known threats, also use other methods such as behavior-based detection and sandboxing, and prepare a detection, isolation, and recovery system that assumes infection can happen
Pattern matching (signature-based detection) works by comparing against known characteristics, so it is fundamentally unable to handle unknown malware or its variants. Increasing update frequency does not remove this limitation, and stacking multiple products alone does not solve it either. What is needed is combining behavior-based detection, which watches runtime behavior, and sandboxing, which runs code in an isolated environment, together with a response system prepared for after an infection occurs.
Practice: answer the questions on this page
This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.
* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.
This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original