Which of the following most appropriately describes a watering hole attack?
The attacker exchanges harmless emails disguised as routine business inquiries several times to lower the recipient's guard, then sends an attachment containing malware.
The attacker tampers in advance with a website the target organization frequently visits, so that visiting the site alone infects the target with malware.
The attacker sends email impersonating an executive or a business partner's contact person to deceive an accounting staff member into transferring money to an account the attacker prepared.
The attacker sends an SMS disguised as a delivery company's missed-delivery notice, leading the recipient through a shortened URL to a fake site where they enter their ID and password.
AnswerB. The attacker tampers in advance with a website the target organization frequently visits, so that visiting the site alone infects the target with malware.
A watering hole attack lies in wait by planting a trap on a site the target routinely visits, and because it does not use email, email-based countermeasures alone cannot stop it. The second choice describes an exchange-type (interactive) attack, the third describes business email compromise (BEC), and the fourth describes smishing; each is a different technique.
Q2 | Exchange-type attacks
Among targeted attacks, which technique is called an “exchange-type” (interactive) attack?
Sending a flood of traffic all at once from many compromised hosts infected with malware, driving the target service into a state where it cannot respond.
Exchanging a few rounds of initially harmless inquiry emails to lower the recipient's guard, then sending an attachment containing malware.
Investigating a target's affiliation, business partners, and ongoing projects from information posted on public social media.
Having a user view a tampered website so that malware is downloaded onto the device without the user noticing, infecting it.
AnswerB. Exchanging a few rounds of initially harmless inquiry emails to lower the recipient's guard, then sending an attachment containing malware.
An exchange-type attack builds trust through normal-looking email exchanges before attacking, rather than attacking immediately, so the recipient is less likely to be suspicious. The first choice describes a DDoS attack, the second is merely preliminary reconnaissance rather than a named technique, and the fourth is a drive-by download, a method used to carry out watering hole attacks.
Q3 | Preventing BEC
An email arrived under the name of a contact person at a business partner stating, “We have changed our bank account for transfers.” Which response is most appropriate for preventing business email compromise (BEC)?
Immediately call the phone number written in the email and confirm the change with the contact person directly.
If the sender's email address visually matches the one already registered, proceed to transfer money to the new account as instructed.
Call the business partner's phone number that has been registered with the company for some time to confirm the change, and also route the process through approval by multiple people.
Scan the attachment and email body with antivirus software, and proceed as normal if no malware is detected.
AnswerC. Call the business partner's phone number that has been registered with the company for some time to confirm the change, and also route the process through approval by multiple people.
BEC does not use malware, so antivirus scanning or checking the attachment cannot detect it. Confirmation must always be done through a separate channel, and a phone number written in the email body is very likely the attacker's own. Because the sender address display can also be easily spoofed, a visual check of it is not a reliable basis for confirmation.
Q4 | Smishing
Which of the following correctly describes smishing?
Posing as a staff member of a financial institution or public agency over a voice call and asking the victim to reveal a PIN or card number.
Using SMS (short message service) to lead a victim to a fake site and get them to enter an ID, password, or card number.
Rummaging through documents or storage media thrown away in the trash to gather internal company information.
Displaying a fake virus infection warning while browsing the web and getting the victim to call the listed number and hand over money or remote access.
AnswerB. Using SMS (short message service) to lead a victim to a fake site and get them to enter an ID, password, or card number.
Smishing is phishing carried out via SMS. The second choice describes vishing, which uses voice; the third describes a fake warning (tech support scam); and the fourth describes scavenging (trashing) — all different social engineering techniques.
Q5 | Responding to a fake warning
While browsing a website, a warning sound plays and a screen appears saying, “You have been infected with a virus. Please call the number shown immediately.” Which response is most appropriate for the user to take?
Pay the support fee as instructed on the screen and have the infection cleared.
Download antivirus software from the link shown on the screen and run it right away.
Do not call or pay anything; close the browser and report the incident to the information systems department.
Call the phone number shown on the spot and install the recovery software as instructed.
AnswerC. Do not call or pay anything; close the browser and report the incident to the information systems department.
This warning is not an actual detection of infection but simply a web page display. Calling the number can lead to a fake support session that installs remote-control software or extracts a fee under false pretenses. Downloading from a link on the screen would also lead to installing malware and must not be done.
Q6 | Social engineering
Which of the following is an act of social engineering?
Sending a flood of traffic all at once from many malware-infected devices to make a server unable to respond.
Sending a string that rewrites a database query into an input field to extract member information.
Calling a user while posing as a staff member of the information systems department to get them to reveal their password.
Exploiting an OS vulnerability to run arbitrary commands on a server.
AnswerC. Calling a user while posing as a staff member of the information systems department to get them to reveal their password.
Social engineering is an umbrella term for techniques that exploit gaps in human psychology or behavior rather than technology, including impersonation phone calls, peeking, and rummaging through trash. The first and third choices are technical attacks exploiting system vulnerabilities, and the fourth is a DoS/DDoS attack; none of these involves tricking a person.
Q7 | Impersonation
Which mechanism is effective for the receiving side to detect and block spoofed email in which the sender's address has been forged?
Sender domain authentication such as SPF, DKIM, and DMARC
Placeholders (a bind mechanism) used when assembling SQL statements
Escaping symbols contained in strings before outputting them to a web page
Locking an account after a certain number of consecutive failed logins
AnswerA. Sender domain authentication such as SPF, DKIM, and DMARC
Sender domain authentication lets the receiving side verify whether an email's sending domain has been spoofed, making it effective for detecting and blocking spoofed email. Account lockout counters brute-force attacks, placeholders counter SQL injection, and escaping counters XSS; none of these relates to email spoofing.
Q8 | Evaluating training
A targeted-attack email drill was carried out. Which evaluation criterion should the information security leader emphasize?
Measure how many people who noticed a suspicious email actually reported it, and how long it took them to report it after noticing.
Keep the drill email's wording and the time it is sent exactly the same every time, and compare only the trend in open rate over the long term.
Simply tally, by department, how many people opened the drill email and publish an internal ranking ordered from lowest open rate to highest.
Identify the employees who opened the drill email and reflect it in their personnel evaluations, repeating the drill until the open rate falls.
AnswerA. Measure how many people who noticed a suspicious email actually reported it, and how long it took them to report it after noticing.
The goal of the drill is not to bring the open rate to zero, but to build a system where a prompt report comes in even when someone does open the email. Punishing those who opened it encourages hiding reports and delays discovering damage. Publishing rankings or repeating an identical email neither fosters a reporting culture nor reveals the true state of things.
Q9 | Risks of social media
Which of the following most appropriately describes the information security risk of employees' social media use?
Social media users fall outside the scope of social engineering.
Information posted on social media, such as affiliation, job title, and clients visited, is gathered and used as material to make targeted-attack emails look like they concern a real ongoing project.
Using social media inevitably rewrites the cache of DNS servers along the route, redirecting the user to a fake site.
Because text posted to social media is sent over an encrypted connection, posting work-related information does not count as an information leak.
AnswerB. Information posted on social media, such as affiliation, job title, and clients visited, is gathered and used as material to make targeted-attack emails look like they concern a real ongoing project.
Attackers gather a target's relationships and ongoing work from publicly posted information and use it to make an email's wording seem more natural. There is no inherent link between using social media and DNS cache poisoning, and encrypting a post in transit does not solve the problem of who can see it once published. Social media is, if anything, a major source of information for social engineering.
Q10 | Initial response after opening
An employee realizes they opened an attachment from a targeted-attack email. Which initial procedure should the organization have established for this situation?
Let the employee decide on their own to delete the suspicious file and email, and if nothing seems wrong afterward, skip reporting it altogether.
Immediately power off the PC, restart it, run a full antivirus scan, and report to the information systems department only if a problem is found.
Continue working as normal for a while to preserve evidence, then report afterward.
Immediately disconnect the device from the network (unplug a wired connection or turn off Wi-Fi), leave the power on, and contact the information systems department.
AnswerD. Immediately disconnect the device from the network (unplug a wired connection or turn off Wi-Fi), leave the power on, and contact the information systems department.
To stop the infection from spreading and to stop communication with the outside, the first step is disconnecting from the network. Powering off the device would erase traces in memory, making the investigation harder, so the device should be left on while it is handed over to the specialist department. Continuing to work as normal, or deciding on one's own to delete files and not report anything, only lets the damage spread and delays discovery.
Q11 | Credential stuffing (a list-based attack)
Which of the following correctly describes a credential stuffing attack (password list attack)?
Mechanically trying every conceivable character combination against a single ID, starting from the shortest and working through them one by one.
Taking ID-and-password pairs leaked from another service and trying them as-is against a different service.
Fixing the password to a single common string and trying it against a succession of different IDs.
Using a lookup table that maps hash values to their original strings to work out the original password from a stolen hash.
AnswerB. Taking ID-and-password pairs leaked from another service and trying them as-is against a different service.
Credential stuffing tries leaked, genuinely correct pairs against a different service, and it succeeds because of password reuse by users. The first choice is a brute-force attack, the third is a reverse brute-force attack, and the fourth is a rainbow table attack; each targets the password differently.
Q12 | Countering credential stuffing
A company's member site experienced numerous unauthorized logins using correct ID-and-password pairs. Every user's password was sufficiently long and complex. Which countermeasure is most appropriate?
Have the development vendor modify the system so database queries are built using placeholders (a bind mechanism).
Notify users not to reuse the same password across other services, and also introduce multi-factor authentication.
Embed an unguessable token on pages that perform update operations, and verify that the submitted value matches it.
Apply escaping to strings output to the screen so that symbols are not interpreted as script.
AnswerB. Notify users not to reuse the same password across other services, and also introduce multi-factor authentication.
Because even complex passwords were breached, a credential stuffing attack using leaked, genuinely correct pairs is suspected. The cause is password reuse, so banning reuse and introducing multi-factor authentication are the countermeasures. Placeholders address SQL injection, escaping addresses XSS, and tokens address CSRF; none of these addresses this incident.
Q13 | Lockout ineffective
Despite having account lockout in place, an unauthorized login occurred without the lockout ever triggering. Which attack was most likely carried out?
A DoS attack, which sends a flood of traffic to a server to make the service unable to respond
A brute-force attack, which tries every conceivable character combination against a single ID in rapid succession
A password spraying attack, which tries a few commonly used passwords against many IDs, spaced out over time
A dictionary attack, which tries words found in a dictionary or commonly used strings against a single ID in rapid succession
AnswerC. A password spraying attack, which tries a few commonly used passwords against many IDs, spaced out over time
Account lockout works by counting consecutive failures on the same account, so it has no effect on a password spraying attack, where the number of failures per account never reaches the threshold. A brute-force attack and a dictionary attack both try many attempts in succession against the same ID, so lockout would trigger. A DoS attack halts a service and is not a technique for breaking through authentication to log in.
Q14 | Reverse brute force
Which of the following correctly describes a reverse brute-force attack?
Using a precomputed lookup table to work out the original password from a hash value.
Inserting oneself between two communicating parties to eavesdrop on or alter the content.
Fixing the password to one value and trying a succession of different IDs against it.
Resending intercepted authentication data as-is so it passes authentication.
AnswerC. Fixing the password to one value and trying a succession of different IDs against it.
A reverse brute-force attack attacks in the opposite direction from an ordinary brute-force attack: it fixes the password and varies the ID. Because each ID only fails once, account lockout is unlikely to trigger. The first choice describes a replay attack, the third a rainbow table attack, and the fourth a man-in-the-middle (MITM) attack.
Q15 | Dictionary vs. brute force
Which of the following correctly explains the difference between a dictionary attack and a brute-force attack?
A dictionary attack tries candidates such as words and commonly used strings, while a brute-force attack tries every conceivable character combination one after another.
A dictionary attack uses a precomputed lookup table to work out the original string from a hash value, while a brute-force attack varies the ID as it tries.
A dictionary attack hijacks an authenticated session, while a brute-force attack guesses at and tries passwords.
A dictionary attack tries leaked ID-and-password pairs as-is, while a brute-force attack tries dictionary words.
AnswerA. A dictionary attack tries candidates such as words and commonly used strings, while a brute-force attack tries every conceivable character combination one after another.
The difference from brute force is that a dictionary attack narrows the attempts to candidates that are likely to succeed, making it more efficient; both try in rapid succession against the same ID, so account lockout is effective against either. Trying leaked pairs is a credential stuffing attack, working back from a hash is a rainbow table attack, and hijacking a session is session hijacking.
Q16 | Countering rainbow tables
Which countermeasure is most appropriate against a rainbow table attack?
Design the system so it never takes a file name directly from the user, but instead has them specify a pre-defined identifier.
Add a different random string (a salt) to each password before hashing it, and repeat the hash computation multiple times (stretching).
Embed an unguessable token on pages that perform update operations, and have the server verify the submitted token every time.
Temporarily disable an account once consecutive login failures reach a set number, requiring an administrator to unlock it.
AnswerB. Add a different random string (a salt) to each password before hashing it, and repeat the hash computation multiple times (stretching).
A rainbow table is a general-purpose lookup table linking hash values to their original strings, so giving each user a different salt renders the table useless, and stretching further increases the effort required to work backward. Account lockout counters brute-force-family attacks, tokens counter CSRF, and avoiding taking a file name directly from the user counters directory traversal.
Q17 | Session hijacking
Which of the following correctly describes session hijacking?
Spoofing a packet's source IP address to slip past access restrictions and connect.
Sending a flood of traffic all at once from many compromised hosts infected with malware to make a target server unable to respond.
Making a DNS server's cache remember false address information, redirecting a user who typed the correct URL to a fake site.
Guessing or stealing the session ID of a logged-in user and operating the system while impersonating that user.
AnswerD. Guessing or stealing the session ID of a logged-in user and operating the system while impersonating that user.
The key point about session hijacking is that it succeeds without the attacker ever knowing the password, and stealing cookies is a representative method. The first choice describes IP spoofing, the third describes a DDoS attack, and the fourth describes DNS cache poisoning; none of these hijacks an already-authenticated state.
Q18 | Cookies
In a web application, which countermeasure is most appropriate for preventing session hijacking through cookie theft?
Set the HttpOnly and Secure attributes on cookies, encrypt the communication with TLS, and reissue the session ID upon successful login.
Require users to change their password periodically, ban reuse of past passwords, and send reminder notices to users who have not changed theirs.
Temporarily disable an account once consecutive login failures reach a set number, and automatically unlock it after a set time has passed.
Require users to set a password of a minimum length that mixes uppercase and lowercase letters, numbers, and symbols.
AnswerA. Set the HttpOnly and Secure attributes on cookies, encrypt the communication with TLS, and reissue the session ID upon successful login.
What gets stolen is the session ID, not the password, so making passwords more complex, changing them periodically, or locking accounts does not prevent this. Blocking script-based reads and eavesdropping on unencrypted traffic prevents the theft itself, and reissuing the ID at login prevents both abuse of a stolen ID and session fixation.
Q19 | MITM
When using an in-house system from a public Wi-Fi network outside the office, which countermeasure is most appropriate against eavesdropping or tampering via a man-in-the-middle (MITM) attack?
Have users change to long, complex passwords and operate a policy of changing them at regular intervals.
Temporarily disable an account once consecutive login failures reach a set number, and notify the administrator.
Encrypt communications with TLS or a VPN, and abort the connection if a server certificate warning appears.
Modify the system so database queries are built using placeholders (a bind mechanism).
AnswerC. Encrypt communications with TLS or a VPN, and abort the connection if a server certificate warning appears.
A man-in-the-middle attack inserts itself into the communication path, so encrypting that path and treating a certificate warning, a sign of such interception, as something never to be ignored are the countermeasures. Complex passwords and account lockout do not prevent eavesdropping on communications, and placeholders are a countermeasure against SQL injection.
Q20 | Replay attacks
Which combination of a description of a replay attack and its countermeasure is correct?
An attack that tries words found in a dictionary in succession to break authentication; countermeasures are salting and stretching.
An attack that gets a logged-in user to click a crafted link, causing an unintended action to be executed; countermeasures are account lockout and periodic password changes.
An attack that sends a flood of connection requests to a server to stop the service; the countermeasure is multi-factor authentication.
An attack that resends intercepted authentication data as-is to pass authentication; countermeasures include one-time passwords, single-use random numbers, and timestamps.
AnswerD. An attack that resends intercepted authentication data as-is to pass authentication; countermeasures include one-time passwords, single-use random numbers, and timestamps.
A replay attack succeeds without the attacker ever knowing the actual password, so it is neutralized by a mechanism that prevents the same data from being used twice. The countermeasure for the dictionary attack in the second choice is account lockout and the like, the third choice is CSRF for which a token is the countermeasure, and the fourth is a DoS attack for which traffic control is the countermeasure; each combination given is incorrect.
Q21 | Preventing SQL injection
A large amount of member information leaked from a company's member site. Investigation showed that a crafted string sent through an input field had rewritten a database query. Which fundamental fix should be requested from the development vendor?
Require users to use multi-factor authentication, prompting for a verification code at login.
Embed an unguessable token on pages that perform update operations, and add a mechanism that checks that value when it is submitted.
Add a mechanism that temporarily disables an account once consecutive login failures reach a set number, and notify the administrator.
Build SQL statements using placeholders (a bind mechanism) so that input values are never interpreted as commands.
AnswerD. Build SQL statements using placeholders (a bind mechanism) so that input values are never interpreted as commands.
This is SQL injection, caused by building SQL statements by concatenating input as strings. Using placeholders ensures input is only ever treated as a value, fixing the problem at its root. Account lockout counters brute-force-family attacks, tokens counter CSRF, and multi-factor authentication counters unauthorized login; none of these resolves this vulnerability.
Q22 | Preventing XSS
On a message board that displays whatever a user types exactly as entered, a vulnerability was found that lets a malicious script run in the browser of other users who view the page. Which countermeasure is most appropriate?
Hash user passwords with a salt, apply stretching, and then store them in the database.
Apply escaping when outputting to the screen, so symbols are not interpreted as script.
Build SQL statements using placeholders (a bind mechanism) so that input values are never interpreted as commands.
Embed an unguessable token on pages that perform update operations, and check the submitted value on the server side.
AnswerB. Apply escaping when outputting to the screen, so symbols are not interpreted as script.
This is cross-site scripting (XSS), and the countermeasure is escaping at output time. Placeholders counter SQL injection, checking a token counters CSRF, and salting with stretching counters rainbow table attacks; none of these addresses this vulnerability.
Q23 | Preventing CSRF
A logged-in user merely opened a link in an email, and an unintended account-cancellation process was carried out without the user meaning to do so. Which countermeasure is most appropriate against this attack?
Stop accepting a file name directly from the user, and redesign the system so the target is specified with a pre-defined identifier instead.
Temporarily disable an account once consecutive login failures reach a set number, and unlock it after a set time has passed.
Apply escaping to strings output to the screen so that entered symbols are not interpreted as script.
Embed an unguessable token on the page that accepts the request, and confirm that the submitted token is correct.
AnswerD. Embed an unguessable token on the page that accepts the request, and confirm that the submitted token is correct.
This is cross-site request forgery (CSRF), which abuses the logged-in user's own legitimate session, so input validation or account lockout cannot prevent it. Checking a token lets the system reject requests coming from a page the attacker prepared. Escaping counters XSS, and avoiding taking a file name directly counters directory traversal.
Q24 | Traversing paths
Which of the following correctly describes directory traversal?
Mixing a relative path into a parameter that specifies a file name to read a file from a parent directory that was never meant to be exposed.
Sending data longer than the memory area a program has allocated, to hijack the program's behavior.
Putting a crafted string into an input field to rewrite a database query and extract information that is not meant to be public.
Overlaying a transparent page on top of a genuine screen so the user clicks somewhere they did not intend to.
AnswerA. Mixing a relative path into a parameter that specifies a file name to read a file from a parent directory that was never meant to be exposed.
Directory traversal walks back up a path to read non-public files, leading to the leak of things like configuration files. The first choice is SQL injection, the third is clickjacking, and the fourth is a buffer overflow; each targets something different.
Q25 | OS command injection
Which of the following is the most appropriate example of damage that can result from OS command injection?
A malicious script runs in a viewer's browser, stealing cookies or a session ID.
An unintended settings change or account cancellation is carried out under a logged-in user's own authority.
A command chosen by the attacker runs on the web server, taking over the server itself.
A DNS server's cache is rewritten so a user who types the correct URL is redirected to a fake site.
AnswerC. A command chosen by the attacker runs on the web server, taking over the server itself.
OS command injection slips a crafted string into an OS command that a web application internally invokes, letting the attacker run arbitrary commands on the server. The first choice is damage from XSS, the second from CSRF, and the fourth from DNS cache poisoning; each affects a different place.
Q26 | Buffer overflow
Which combination of an attack that exploits a buffer overflow and its countermeasure is correct?
An attack that displays a string entered by a user exactly as typed, running a malicious script in the browser of other viewers; the countermeasure is introducing account lockout.
An attack that tries leaked ID-and-password pairs from another service as-is; the countermeasure is using placeholders.
An attack that sends a flood of traffic from many compromised hosts infected with malware; the countermeasure is escaping at output time.
An attack that sends data longer than the memory area a program has allocated to hijack its behavior; checking input data length and applying patches are the countermeasures.
AnswerD. An attack that sends data longer than the memory area a program has allocated to hijack its behavior; checking input data length and applying patches are the countermeasures.
A buffer overflow hijacks a program's control using overflowing data, and checking data length together with applying patches are the basic countermeasures. The second choice is XSS, for which escaping is the countermeasure; the third is DDoS, for which traffic control is the countermeasure; and the fourth is credential stuffing, for which banning reuse and multi-factor authentication are the countermeasures — every combination given is wrong.
Q27 | A click trap
Which of the following correctly describes clickjacking?
Merely viewing a tampered website triggers an exploit of a browser vulnerability, causing malware to be downloaded without the user noticing.
On a page that displays a string entered by a user exactly as typed, running a script in the browser of other viewers.
Sending queries with a spoofed source IP address to many DNS servers so that large responses are concentrated on the target.
Overlaying a transparent page on top of a genuine screen so a user clicks somewhere they never meant to press, triggering an action.
AnswerD. Overlaying a transparent page on top of a genuine screen so a user clicks somewhere they never meant to press, triggering an action.
Clickjacking tricks a user's actions by overlaying screens, and a setting that prevents one's own site from being displayed inside another site's frame is the countermeasure. The first choice describes XSS, the second describes a drive-by download, and the third describes a DNS reflection (amplification) attack.
Q28 | Infection while browsing
Which countermeasure can be expected to be most effective for a user to prevent infection via a drive-by download?
Delete the web browsing history and cache every day.
Review access rights to the internal shared folder and limit them to only those who need them.
Change passwords periodically and avoid reusing the same one across other services.
Always keep the OS, the browser, and the software used by the browser up to date.
AnswerD. Always keep the OS, the browser, and the software used by the browser up to date.
A drive-by download infects a device by exploiting a vulnerability simply from viewing a tampered site, so leaving no vulnerability behind is the most effective measure. Changing passwords or deleting browsing history has no bearing on whether infection occurs, and shared folder access rights affect the scope of damage after infection but do not prevent the infection itself.
Q29 | XSS versus CSRF
Which of the following correctly explains the difference between cross-site scripting (XSS) and cross-site request forgery (CSRF)?
XSS is an attack that lures a user to a fake website to get them to enter an ID and password, countered by raising user awareness; CSRF is an attack that sends a flood of traffic to a server to make it unable to respond, countered by controlling traffic volume.
XSS is an attack that runs an arbitrary OS command on a web server, countered by input validation; CSRF is an attack that overflows a memory area to hijack behavior, countered by applying patches.
The countermeasure for XSS is checking a token, and the countermeasure for CSRF is escaping at output time.
XSS is an attack that runs a script in another user's browser, countered by escaping; CSRF is an attack that carries out an unintended action under a user's own authority, countered by checking a token.
AnswerD. XSS is an attack that runs a script in another user's browser, countered by escaping; CSRF is an attack that carries out an unintended action under a user's own authority, countered by checking a token.
Despite the similar names, XSS is an attack that runs a script to steal information, while CSRF is an attack that carries out an action under the victim's own authority, and their countermeasures differ too. The fourth choice swaps the two countermeasures. The first and second choices mix in descriptions of other attacks, such as phishing, DoS, OS command injection, and buffer overflow.
Q30 | Input validation
In a web application, against which of the following attacks is validating input values (allowing through only permitted characters or names) one effective countermeasure?
Directory traversal and OS command injection
Replay attacks and session hijacking
DNS cache poisoning and DNS reflection attacks
Rainbow table attacks and credential stuffing
AnswerA. Directory traversal and OS command injection
Values used as part of a file name or an OS command can have unauthorized specifications excluded by validation that allows through only permitted characters or names. That said, the more fundamental fix is to avoid taking a file name directly from the user or avoid invoking OS commands at all, with validation used alongside that. Rainbow table and credential-stuffing attacks are countered by salting and stretching or by banning reuse, replay attacks and session hijacking by one-time passwords or protecting the session ID, and DNS cache poisoning and DNS reflection attacks by configuration and updates on the DNS server side; input validation prevents none of these.
Q31 | DDoS
Which of the following correctly describes a DDoS attack?
Secretly planting a program on a user's PC that mines cryptocurrency, and continuing to use its computing power and electricity without permission for profit.
First compromising a lightly defended organization such as a business partner or subsidiary, then using it as a stepping stone to reach the real target's internal network and steal the intended information.
Secretly inserting oneself between two communicating parties, eavesdropping on the exchange, or relaying altered content to control the communication.
Sending a flood of traffic or processing requests all at once from many devices infected with malware, making the target service unusable.
AnswerD. Sending a flood of traffic or processing requests all at once from many devices infected with malware, making the target service unusable.
A DDoS attack is a distributed denial-of-service attack; because it comes from many compromised hosts at once, blocking source IP addresses alone is difficult, and the property compromised is availability. The first choice describes a man-in-the-middle attack, the third describes cryptojacking, and the fourth describes a supply chain attack.
Q32 | Amplification attacks
Which of the following correctly describes a DNS reflection attack (DNS amplification attack)?
Manually mashing the browser's reload button repeatedly to have the same page loaded over and over, placing a sustained load on the server.
Sending only connection requests in large numbers, never replying, building up a backlog of half-open connections until the server's resources are exhausted, stopping the service.
Sending many small queries, with the source IP address spoofed to the target's address, to numerous DNS servers so that large responses are concentrated on the target.
Making a DNS server's cache remember false address information, redirecting a user who typed the correct URL to the attacker's fake site.
AnswerC. Sending many small queries, with the source IP address spoofed to the target's address, to numerous DNS servers so that large responses are concentrated on the target.
The name “amplification” comes from producing a large volume of attack traffic from a small volume of sent traffic, and it depends on spoofing the source address. The first choice is DNS cache poisoning, the second is a SYN flood attack, and the third is an F5 attack; none of these amplifies a DNS response.
Q33 | SYN flood
Which of the following correctly describes a SYN flood attack?
Attacking by exploiting a vulnerability for which no patch has yet been made available.
Falsely announcing the correspondence between a source MAC address and IP address to pull traffic on the same LAN toward one's own device and eavesdrop on it.
Sending only connection requests in large numbers and never replying, building up a backlog of half-open connections until the server's resources are exhausted.
Sending a crafted string into a web application's input field to rewrite a database query and extract member information.
AnswerC. Sending only connection requests in large numbers and never replying, building up a backlog of half-open connections until the server's resources are exhausted.
A SYN flood attack is a DoS attack that generates a large number of half-open connections, and it can succeed even without a large volume of traffic. The first choice is ARP spoofing, the third is a zero-day attack, and the fourth is SQL injection; none of these is an attack that stops a service.
Q34 | DNS poisoning
Even though a user typed the correct URL, they ended up connecting to a fake website. Which attack is the most likely cause of this?
SYN flood attack
Replay attack
Clickjacking
DNS cache poisoning
AnswerD. DNS cache poisoning
DNS cache poisoning is an attack that makes a DNS server's cache remember false address information, and it is hard to notice because the user genuinely typed the correct URL. A SYN flood attack stops a service, clickjacking overlays screens, and a replay attack resends authentication data; none of these changes the result of name resolution.
Q35 | Two kinds of spoofing
Which combination of explanations for ARP spoofing and IP spoofing is correct?
ARP spoofing falsifies an email sender's name to gain trust, while IP spoofing tampers with a web page to rewrite its display.
ARP spoofing falsifies the correspondence between MAC and IP addresses within the same LAN to pull traffic toward the attacker, while IP spoofing forges a packet's source IP address.
ARP spoofing forges a packet's source IP address, while IP spoofing forges the MAC-address correspondence within the same LAN.
ARP spoofing makes a DNS server's cache remember false information to redirect victims to a fake site, while IP spoofing steals a user's session ID to impersonate them.
AnswerB. ARP spoofing falsifies the correspondence between MAC and IP addresses within the same LAN to pull traffic toward the attacker, while IP spoofing forges a packet's source IP address.
ARP spoofing serves as a foothold for a man-in-the-middle attack within the same LAN, while IP spoofing is used to hide the true source of an attack or to turn a device into a launching point for a reflection attack. The first choice swaps the two explanations. The third and fourth describe other attacks entirely, such as DNS cache poisoning, session hijacking, and spoofed email.
Q36 | Zero-day
Which of the following is the most appropriate preparation against a zero-day attack?
In addition to thoroughly applying updates, combine defense in depth with behavior-based detection, and build a detection and response system that assumes intrusion can happen.
Set all incoming email from outside the company to be rejected, and switch business communication to phone calls only.
Thoroughly enforce a policy of changing passwords periodically and tell everyone to stop reusing them.
Since applying a patch is guaranteed to prevent it, simply tell everyone in the company to keep systems updated and take no other precautions.
AnswerA. In addition to thoroughly applying updates, combine defense in depth with behavior-based detection, and build a detection and response system that assumes intrusion can happen.
A zero-day attack exploits the period during which no patch exists, so thorough updates alone cannot prevent it. The key point is preparing a detection and initial-response system that assumes intrusion will happen. Changing passwords periodically is unrelated, and rejecting all email is not realistic since it would prevent business from functioning.
Q37 | The supply chain
Which of the following correctly describes a supply chain attack?
Compromising a lightly defended business partner, subsidiary, or the provider of widely used software, then reaching the real target through it.
Calling by phone using an AI-synthesized voice of an executive, instructing an accounting staff member to make an urgent transfer into the attacker's account.
Sending a flood of traffic from many compromised hosts against a company's own public server, halting order intake and disrupting operations.
Secretly planting a cryptocurrency mining program on a company's own PCs and using their computing power and electricity without permission.
AnswerA. Compromising a lightly defended business partner, subsidiary, or the provider of widely used software, then reaching the real target through it.
The defining feature of a supply chain attack is not attacking the real target directly but using a related party as a stepping stone, which the target's own technical measures alone cannot prevent. The first choice is a DoS/DDoS attack, the third is cryptojacking, and the fourth is impersonation using a deepfake; none of these involves routing through a business partner.
Q38 | Via an update
For business software a company had used for many years, the provider was compromised, and a malicious program had been mixed into an update published on the legitimate distribution site. Devices at the company that applied the update became infected. Which lesson should be drawn from this case?
Since applying updates itself has proven dangerous, the company should adopt a policy of never applying any patch distributed by the provider from now on and keep running the currently used version, notifying all departments accordingly.
Because even a legitimate acquisition channel can be compromised, continuously check information published by the provider, set up monitoring for suspicious communication or behavior after an update, and prepare a detection and response system that assumes intrusion can happen.
Changing users' passwords to long, complex ones and introducing multi-factor authentication would prevent the same kind of damage.
Since it was the provider that was compromised, and the update was obtained from the legitimate distribution site, there is no way for a user to have seen it coming, and so there is nothing the company itself can do to prepare or respond.
AnswerB. Because even a legitimate acquisition channel can be compromised, continuously check information published by the provider, set up monitoring for suspicious communication or behavior after an update, and prepare a detection and response system that assumes intrusion can happen.
This is a supply chain attack that compromises a software provider, and because it is distributed through the legitimate channel, the correctness of the source alone cannot reveal it. Stopping updates altogether would leave known vulnerabilities unpatched, which is actually more dangerous. Strengthening passwords is unrelated to this infection route, and leaving it entirely up to the provider delays both detection and response.
Q39 | Unauthorized mining
Which of the following is the most appropriate way cryptojacking damage tends to show up?
Customer information is posted on an outside message board, and inquiries and complaints from customers flood in, disrupting normal business as staff scramble to respond day after day.
A company's website stops responding and can no longer take orders, causing lost sales opportunities to keep accumulating until recovery is complete.
Even though the correct URL was typed, the user is connected to a fake site without noticing, and the ID, password, or card number entered there is stolen.
With no sign of any information leak, a device's performance suddenly becomes sluggish, or cloud usage fees or electricity bills increase unnaturally.
AnswerD. With no sign of any information leak, a device's performance suddenly becomes sluggish, or cloud usage fees or electricity bills increase unnaturally.
Cryptojacking uses another party's device to mine cryptocurrency without permission; because it steals no information, it is hard to notice and instead shows up as sluggish performance or rising costs. The first choice is an information leak, the second is a DoS/DDoS attack, and the fourth is damage from DNS cache poisoning.
Q40 | Misuse of AI
As misuse of generative AI and deepfakes spreads, which response should an organization take?
Tell employees that an email may be considered genuine if its Japanese wording is natural and free of errors.
If a caller's voice matches the person's own, allow a transfer or a change of payment destination based on the verbal instruction alone.
Do not let the naturalness of the wording or the voice alone determine authenticity; require a callback to a registered contact and approval from multiple people before any transfer or change of payment destination.
Banning the use of generative AI within the company entirely will eliminate phishing email damage.
AnswerC. Do not let the naturalness of the wording or the voice alone determine authenticity; require a callback to a registered contact and approval from multiple people before any transfer or change of payment destination.
Generative AI can produce natural-sounding wording, and deepfakes can reproduce a voice, so the old approach of “spotting it by its unnaturalness” no longer works. The safeguard is a procedure of confirmation through a separate channel and approval by multiple people, rather than relying on human intuition. Even if a company bans its own use of generative AI, it cannot stop attackers from using it.
Practice: answer the questions on this page
This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.
* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.
This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original