Which of the following most appropriately describes common key (symmetric key) cryptography?
Even with n users, only a total of 2n keys are needed, so key management is easy.
It uses the same key for encryption and decryption, and because it processes faster than public key cryptography, it is well suited to encrypting large volumes of data.
It uses different keys for encryption and decryption, and the key used for encryption may be shared with anyone.
It is a one-way computation that derives a fixed-length value from an input without using a key, and the original data cannot be recovered from that value.
AnswerB. It uses the same key for encryption and decryption, and because it processes faster than public key cryptography, it is well suited to encrypting large volumes of data.
Common key cryptography, represented by AES, uses the same key for encryption and decryption, so it is fast and is used to encrypt communications or the body of files. The second choice describes public key cryptography. The third choice describes a hash function, which uses no key and so is not encryption. The fourth choice is also the key count for public key cryptography; common key cryptography instead needs n(n-1)/2 keys.
Q2 | Number of keys
50 employees will hold encrypted communication with each other using common key cryptography, using a different key for each pair. In total, how many common keys are needed?
4,950
100
2,450
1,225
AnswerD. 1,225
The number of keys needed for common key cryptography is n(n-1)/2, so 50 × 49 ÷ 2 = 1,225. 100 is the value of 2n for the same 50 people using public key cryptography instead. 2,450 is 50 × 49 left un-halved by mistake. 4,950 is the value of n(n-1)/2 for 100 people; all of these are wrong.
Q3 | Number of keys
50 employees will hold encrypted communication with each other using public key cryptography. How many keys will everyone hold in total?
50
100
2,500
1,225
AnswerB. 100
In public key cryptography, each person holds two keys, a public key and a private key, so the total is 2n = 2 × 50 = 100. 1,225 is the n(n-1)/2 value for common key cryptography. 50 mistakenly assumes one key per person. 2,500 is n squared; all of these are wrong. The advantage of public key cryptography is that the number of keys grows more slowly than with the common key approach as the number of people increases.
Q4 | Hybrid cryptography
Which of the following most appropriately describes hybrid cryptography?
A scheme in which the data itself is encrypted with common key cryptography, and that common key is then encrypted with the recipient's public key for delivery.
A scheme that combines two hash functions to produce a hash value that is unlikely to collide.
A scheme that encrypts the same data twice, once with common key cryptography and once with public key cryptography, to increase decryption strength.
A scheme that encrypts the entire body of data with public key cryptography, doing away with a common key altogether.
AnswerA. A scheme in which the data itself is encrypted with common key cryptography, and that common key is then encrypted with the recipient's public key for delivery.
Hybrid cryptography encrypts the data body with the faster common key cryptography and delivers only that common key (the session key) encrypted with the recipient's public key, solving both the speed problem and the key-distribution problem at once. TLS uses this scheme. The first choice concerns hash functions, which are not encryption. It is not double encryption as in the third choice, nor does it process the entire body with public key cryptography as in the fourth choice.
Q5 | The key used to encrypt
A wants to send an electronic file to B, encrypted with public key cryptography so that only B can read it. Which key does A use to encrypt it?
B's public key
A's public key
A's private key
B's private key
AnswerA. B's public key
Encryption to protect confidentiality is done with the recipient B's public key. Only B holds the matching private key, so only B can decrypt it. Transforming the data with A's private key is a digital signature, not encryption. A's public key can be obtained by anyone, so encrypting with it would let no one decrypt it and would not protect confidentiality. B's private key belongs only to B, so A cannot use it.
Q6 | The key used to decrypt
A recipient receives a document encrypted with public key cryptography to protect its confidentiality. Which key does the recipient use to decrypt it?
The sender's private key
The recipient's own private key
The sender's public key
The recipient's public key
AnswerB. The recipient's own private key
Because the recipient's public key was used to encrypt it, only the matching recipient's private key can decrypt it. The recipient's public key is the very key used for encryption and cannot reverse it. The sender's private key belongs only to the sender. The sender's public key is used to verify a digital signature, not to decrypt a confidential document.
Q7 | Hash functions
Which of the following correctly describes a property of hash functions?
The longer the input data, the proportionally longer the output hash value becomes.
Different data that produce the same hash value can easily be found by computation.
Even a one-character change in the input causes the output hash value to change drastically.
The original data can be computationally recovered from the output hash value.
AnswerC. Even a one-character change in the input causes the output hash value to change drastically.
Because even a slight change in input causes a large change in output, hash functions can be used to detect file tampering. The first choice contradicts one-wayness — recovery is not possible (which is why it is not encryption). The second choice is also wrong: regardless of input length, the output is a fixed length (256 bits for SHA-256, for instance). The fourth choice is also wrong; collision resistance, meaning it is hard to find different data with the same value, is a required property.
Q8 | Salt
In a system that stores passwords as hash values, which of the following is the most appropriate purpose of using a salt?
So the number of characters in the password a user sets is standardized to a fixed length
So the stored hash value differs for each user, preventing decoding via a precomputed table
So the time taken for a single hash computation is deliberately lengthened, greatly slowing the rate at which a brute-force attack can be attempted
So the original password can be computationally recovered from the stored hash value whenever needed
AnswerB. So the stored hash value differs for each user, preventing decoding via a precomputed table
A salt is a random string that differs per user, added to a password before hashing, so the stored value differs even for the same password, making a precomputed rainbow table useless. The third choice is the purpose of stretching, which repeats the computation many thousands of times, a separate measure from salting. The first choice contradicts the one-wayness of hashing. The fourth choice describes an effect a salt does not have.
Q9 | Disk encryption
A laptop taken outside the office was set up with full-disk encryption. Which of the following is the most appropriate benefit of this measure?
It prevents the contents from being read out if the storage device is removed after the PC is lost or stolen.
Even if the device is infected with malware while the user is logged in, stored files cannot be read.
It prevents an unauthorized internal user from opening someone else's files on that PC.
It prevents a file attached to an email from being intercepted by a third party while in transit.
AnswerA. It prevents the contents from being read out if the storage device is removed after the PC is lost or stolen.
Full-disk encryption means the contents cannot be read without passing authentication at startup, making it effective against information leaks from loss or theft. The second choice is wrong: once logged in legitimately, data is decrypted and readable, so it does not counter malware. The third choice is the role of encrypting communications or individual files. The fourth choice is achieved through access control.
Q10 | Cryptographic obsolescence
Which of the following is the most appropriate preparation against the obsolescence (weakening) of cryptography over time?
Require users to change their password periodically and ban reuse.
To avoid destabilizing operations, keep using whatever cryptographic algorithm and key length was originally adopted, unchanged.
Since encryption risks making data unrecoverable, always keep a plaintext copy separate from the encrypted document.
Periodically evaluate the security of the cryptographic algorithm and key length in use, and keep the ability to migrate to a newer one when necessary.
AnswerD. Periodically evaluate the security of the cryptographic algorithm and key length in use, and keep the ability to migrate to a newer one when necessary.
Obsolescence refers to cryptography becoming unsafe as computing power improves or weaknesses in an algorithm are discovered. Periodically reviewing the algorithm and key length and keeping the ability to migrate is the preparation, and this includes considering a move to post-quantum cryptography with quantum computers in mind. The first choice is about password practices, a separate matter from cryptographic obsolescence. The third choice undermines confidentiality the moment a plaintext copy is kept. The fourth choice is a dangerous case of leaving the risk unaddressed.
Q11 | The signing key
A sender attaches a digital signature to an electronic document. Which key is used to create the signature?
The recipient's public key
The sender's private key
The recipient's private key
The sender's public key
AnswerB. The sender's private key
A digital signature is created by transforming a document's hash value with the sender's private key. Because only the sender holds that private key, it can demonstrate both that the sender created it and that it has not been altered. Using the recipient's public key is encryption for confidentiality, not signing. The recipient's private key belongs only to the recipient. The sender's public key is used to verify the signature and cannot be used to create it.
Q12 | Verifying a signature
A recipient receives an electronic document with a digital signature attached. Which key does the recipient use to verify that signature?
The sender's private key
The recipient's public key
The recipient's private key
The sender's public key
AnswerD. The sender's public key
Because the signature was created with the sender's private key, it is verified with the matching sender's public key. The sender's private key belongs only to the sender and cannot be used by the recipient. The recipient's public key is the key the sender would use to encrypt for confidentiality, and the recipient's private key is used to decrypt a message addressed to the recipient; neither is used to verify a signature.
Q13 | Signing and encrypting
A wants to send a document to B such that no one else can read it, and such that A can be shown to have created it. A and B have already obtained each other's public keys. Which way of using the keys is correct?
A signs with A's own public key and encrypts with B's private key. B decrypts with B's own public key and verifies with A's private key.
A signs with B's public key and encrypts with A's own private key. B decrypts with A's public key and verifies with B's own private key.
A signs with A's own private key and encrypts with B's public key. B decrypts with B's own private key and verifies with A's public key.
A signs with A's own private key and encrypts with A's own public key. B decrypts with B's own private key and verifies with B's own public key.
AnswerC. A signs with A's own private key and encrypts with B's public key. B decrypts with B's own private key and verifies with A's public key.
A signature is created with sender A's private key and verified with A's public key. Encryption is done with recipient B's public key and decrypted with B's private key. Only the third choice satisfies both of these directions. The other three either use the other party's private key (impossible, since only that person holds it) or encrypt with one's own public key (which no one could then decrypt) — in each case one of the directions is reversed, so it does not work.
Q14 | What a signature achieves
Regarding an email sent with only a digital signature attached (and not encrypted), which of the following is true?
The recipient can confirm that the body was not altered along the way.
It prevents the body's content from being intercepted by a third party while in transit.
The recipient could alter the body and still claim the sender wrote it.
It becomes easy for the sender to later claim they never sent that email.
AnswerA. The recipient can confirm that the body was not altered along the way.
What a digital signature reveals is tampering (integrity), that the sender is genuine, and non-repudiation. The body is still sent in plaintext, so it cannot prevent interception (confidentiality); hiding the content as well would require encrypting it with the recipient's public key. If the recipient altered the body, verification would fail, so they could not pass it off as the sender's. The signature, if anything, closes off the possibility of denial.
Q15 | MAC
Comparing a message authentication code (MAC) with a digital signature, which of the following can a MAC not achieve?
Preventing the sender from later denying having sent the message
Confirming that the message came from a party that shares the key
Confirming that the message was not tampered with in transit
Being lightweight enough to verify repeatedly, every single time, at low cost
AnswerA. Preventing the sender from later denying having sent the message
Because a MAC is produced from a private key shared between sender and recipient, the recipient could also produce the same value, so it cannot demonstrate to a third party that only the sender could have made it. It therefore cannot provide non-repudiation. It can detect tampering and confirm the other party shares the key, and it is lightweight to process. When non-repudiation is also needed, a digital signature, which uses a private key that only one person holds, is used instead.
Q16 | Digital certificates
Which of the following is the most appropriate role of a digital certificate (public key certificate)?
A certificate authority collectively holds users' private keys so they can be reissued if lost.
It encrypts the communication content itself so it cannot be eavesdropped on or altered in transit.
It inspects and guarantees that a distributed file is not infected with malware.
It uses a certificate authority's signature to guarantee that a public key genuinely belongs to the party named in it.
AnswerD. It uses a certificate authority's signature to guarantee that a public key genuinely belongs to the party named in it.
A digital certificate is an electronic form of identification in which a certificate authority (CA) signs, with its own private key, a public key together with information about its owner, letting the recipient confirm that the public key really belongs to that party. A private key is something only its owner keeps under tight control, not something entrusted to a CA. Encrypting the communication itself is done by something like TLS, with the certificate used to confirm the other party's legitimacy. It offers no guarantee about the presence or absence of malware.
Q17 | Root certificates
Which of the following correctly describes a root certificate?
A list a certificate authority periodically publishes, gathering together certificates whose validity period has expired.
A self-signed certificate a certificate authority issues to itself, serving as the root of trust.
A certificate issued by a certificate authority to each individual user, used to identify that person.
A common key for encrypting communication with a server, stored on a user's device.
AnswerB. A self-signed certificate a certificate authority issues to itself, serving as the root of trust.
A root certificate sits at the top of the certificate chain: it is a self-signed certificate the CA issues to itself, pre-installed in an OS or browser, and it serves as the root of trust. This is exactly why installing a root certificate of unknown origin is dangerous — it can make a fake site be trusted as genuine. A certificate that identifies an individual is a user certificate. What might sound like a list of certificates is closer to a certificate revocation list (CRL), but a CRL lists certificates revoked before their expiry, not ones that have expired. No common key is involved.
Q18 | Checking revocation
Even while a digital certificate is within its validity period, it is necessary to check whether it has been revoked. Which combination of mechanisms is used for this check?
SAML and OAuth
AES and RSA
CRL and OCSP
SPF and DKIM
AnswerC. CRL and OCSP
A certificate can be revoked before its expiry date, for example due to a leaked private key or an employee leaving. A list of revoked certificates is the CRL (certificate revocation list), and a method for querying the status of one certificate at a time online is OCSP. SPF and DKIM verify an email's sending source, SAML and OAuth are standards for single sign-on or delegated authorization, and AES and RSA are cryptographic algorithms themselves; none of these is used to check revocation.
Q19 | HTTPS
You accessed a business partner's website and found the URL begins with https:// and the server certificate was validated correctly. Which of the following is the most appropriate conclusion from this?
It is guaranteed that files obtained from the site contain no malware.
It is guaranteed that the organization running the site has an appropriate information management system.
Information entered on that site is now less likely to be intercepted while in transit.
The certificate authority guarantees that the site's operator is a financially sound company.
AnswerC. Information entered on that site is now less likely to be intercepted while in transit.
HTTPS encrypts communication with TLS, and the server certificate confirms the connection is to the server named in the certificate, making it more resistant to eavesdropping and tampering in transit. However, what the certificate shows is the other party's identity, not the adequacy of its information management, the safety of distributed files, or its financial standing. It is worth noting that phishing sites can use HTTPS too.
Q20 | DV, OV, and EV
Which of the following correctly describes the difference between DV, OV, and EV server certificates?
The only difference is the fee charged: a DV certificate is free while OV and EV are paid.
The higher the level, up to EV, the longer the certificate's validity period is set.
The higher the level, up to EV, the stronger the cryptographic algorithm and the longer the key length used in communication, making it more secure.
They differ in how strictly the certificate authority verifies the applicant's identity; a DV certificate verifies only control over the domain name.
AnswerD. They differ in how strictly the certificate authority verifies the applicant's identity; a DV certificate verifies only control over the domain name.
The difference among DV, OV, and EV lies in how strict the certificate authority's identity verification is. DV verifies only control over the domain name, OV also verifies that the organization genuinely exists, and EV involves an even more rigorous review. The type does not change the cryptographic algorithm or key length used, nor does it determine the validity period. Any fee difference is a result of the review effort involved; the essence of the difference is the review itself.
Q21 | The three authentication factors
Among the three factors of user authentication, which of the following is an example of authentication by “possession”?
Having the user type the answer to a secret question they registered in advance.
Entering a one-time password shown in an app on the user's smartphone.
Entering a password the user has memorized in advance, in a form not shown on the screen.
Reading the user's fingerprint with a dedicated scanner and matching it against a pre-registered pattern.
AnswerB. Entering a one-time password shown in an app on the user's smartphone.
The three authentication factors are knowledge (something only the person knows), possession (something only the person has), and inherence (a characteristic of the person's own body). Possession corresponds to methods using a smartphone app, an IC card, or a hardware token. A password and a secret question are both knowledge, and fingerprint matching is inherence. Combining different factors makes it multi-factor authentication.
Q22 | Multi-factor authentication
Which of the following counts as multi-factor authentication?
After entering a password, entering a separately set second password.
After entering a password, entering the user's date of birth and employee number.
After entering a user ID and password, holding the user's own IC card up to a reader.
After entering a password, answering a secret question the user registered in advance.
AnswerC. After entering a user ID and password, holding the user's own IC card up to a reader.
Multi-factor authentication combines two or more different factors among knowledge, possession, and inherence, and a password (knowledge) combined with an IC card (possession) fits this. A secret question, a second password, and a date of birth or employee number are all knowledge; splitting the check into two steps makes it two-step verification, but since it remains a single factor, it is not multi-factor authentication. This distinction is a frequent exam point.
Q23 | FRR and FAR
To reduce the incidents in which a biometric authentication device mistakenly accepts an impostor as the genuine user, the matching threshold was set more strictly. Which of the following correctly describes the resulting change in the false rejection rate (FRR) and false acceptance rate (FAR)?
Both FRR and FAR fall.
FRR falls and FAR rises.
FRR rises and FAR falls.
Both FRR and FAR rise.
AnswerC. FRR rises and FAR falls.
Setting a stricter threshold makes it harder to accept an impostor, but it also makes it more likely to reject the genuine user. In other words, the false acceptance rate (FAR) falls while the false rejection rate (FRR) rises. Because the two sit in a trade-off relationship across the threshold, they never both fall or both rise together. In situations that prioritize safety, such as entry to a restricted area, the threshold is set to lower FAR even at the cost of inconveniencing the genuine user.
Q24 | EER
Comparing biometric authentication devices A and B, device A had a smaller EER (equal error rate). Which of the following is the most appropriate conclusion from this fact?
Device A has higher overall accuracy, combining false rejection rate and false acceptance rate, than device B.
Device A never rejects the genuine user, no matter how the threshold is set.
Device A processes a match faster than device B.
Device A always has a false acceptance rate of zero, regardless of the threshold setting.
AnswerA. Device A has higher overall accuracy, combining false rejection rate and false acceptance rate, than device B.
The EER is the error rate at the point where the false rejection rate (FRR) and false acceptance rate (FAR) become equal, and it serves as a benchmark for comparing devices' overall accuracy — a smaller value means higher accuracy. However, this does not mean the error rate reaches zero, so it cannot be said that the genuine user is never rejected or that the false acceptance rate is always zero. The EER is a measure of accuracy and has nothing to do with processing speed. In actual operation, the threshold is shifted depending on the intended use.
Q25 | OTP
Which of the following is the most appropriate benefit gained by introducing one-time passwords?
It prevents information about users stored on the authentication server from leaking outside.
Even if that single input value becomes known through eavesdropping, it cannot be used for any subsequent login.
It reduces the number and variety of characters a user needs to memorize day to day.
It prevents a user's device from becoming infected with malware.
AnswerB. Even if that single input value becomes known through eavesdropping, it cannot be used for any subsequent login.
A one-time password is disposable and usable only once, so even if the value becomes known through eavesdropping or peeking, it cannot be reused. It is not meant to reduce the number of characters to memorize, and in most cases a dedicated app or token generates the value. It is also not a mechanism that prevents a device from becoming infected with malware or prevents an information leak from the authentication server itself. A similarly aimed approach is challenge-response authentication, which never sends the password itself over the communication path.
Q26 | Password practices
Which of the following is the most appropriate way to handle a password for a business system?
Write the password on a sticky note and put it on the display so it is not forgotten.
Share one ID and password within the department, with everyone logging in under the same account.
Since it is easy to remember, use the same password already used on another service.
Set a sufficiently long password and never reuse it on other services.
AnswerD. Set a sufficiently long password and never reuse it on other services.
Ensuring sufficient length has the biggest effect on making a password hard to break, and stopping reuse is the countermeasure against credential-stuffing attacks. What cannot be memorized should be managed with a password manager. Reuse means a leak in one place spreads to every service, and displaying it on a sticky note invites someone to simply look at it. Sharing an ID makes it impossible to trace whose action something was, violating the basic principle of account management.
Q27 | Risk-based authentication
Which of the following is a method that requests additional identity verification only when access is detected from an unusual country or an unfamiliar device is used to log in?
CAPTCHA
Risk-based authentication
Single sign-on
Challenge-response authentication
AnswerB. Risk-based authentication
Risk-based authentication judges the level of danger from circumstances such as device, region, and time of access, and requests additional verification only when the situation is judged risky, curbing unauthorized login while keeping normal use convenient. Single sign-on is a mechanism that lets a single authentication grant access to multiple systems. Challenge-response authentication uses a different random value each time so the password itself is never sent over the network. CAPTCHA is a mechanism to distinguish a human from an automated program.
Q28 | Passkeys
Which of the following is the most appropriate reason authentication with FIDO2 or passkeys is considered more secure than traditional password authentication?
Because the authentication server centrally manages and protects the private key used for authentication
Because it is designed to set a short expiry for the password, prompting the user to change it frequently
Because no shared secret, such as a password, is stored on the server side, and a signature is returned only to the legitimate site
Because the password entered by the user is encrypted with a stronger algorithm than before, before being sent to the authentication server
AnswerC. Because no shared secret, such as a password, is stored on the server side, and a signature is returned only to the legitimate site
FIDO2 and passkeys work by returning a signature made with a private key kept on the user's own device. Because no shared secret is stored on the server side, a leak from the server cannot be abused, and because a signature is returned only to the legitimate site by design, it also resists phishing. It is not that the password is encrypted before being sent — a password is not used at all. The private key is held by the device, not centrally managed by the server.
Q29 | Authentication and authorization
Which of the following most appropriately describes the relationship between authentication and authorization?
Authentication and authorization mean the same thing, and once login succeeds, all information becomes usable.
Authorization is carried out by network equipment and authentication by the application; the difference is only where each is implemented.
Authorization confirms who the person is, and the subsequent authentication decides the scope of operations they can perform.
Authentication confirms who the person is, and authorization decides the scope of operations permitted to that person.
AnswerD. Authentication confirms who the person is, and authorization decides the scope of operations permitted to that person.
Authentication confirms whether the party claiming an identity really is that person, and authorization decides what that confirmed person is permitted to do; authentication comes first and authorization follows. The first choice reverses the two, which is wrong. Being able to log in is not the same as being allowed to view every piece of information — drawing a line such as “HR information is for HR staff only” is the role of authorization. It is not a distinction determined by where something is implemented.
Q30 | RBAC
Which of the following correctly describes role-based access control (RBAC)?
A scheme in which permissions are determined by a confidentiality label, and not even the information's owner can change them.
A scheme in which permissions are set individually, file by file, for each user.
A scheme that bundles permissions into roles corresponding to job duties, and assigns users to those roles.
A scheme in which the owner of information can grant permissions to other users at their own discretion.
AnswerC. A scheme that bundles permissions into roles corresponding to job duties, and assigns users to those roles.
RBAC bundles the permissions needed for each job duty into a role and assigns people to roles, so a personnel transfer only requires reassigning the role, and a permissions review can also be done role by role. The first choice describes discretionary access control (DAC), and the second describes mandatory access control (MAC). The individual, file-by-file setup in the fourth choice does not use the concept of a role at all, so it is not RBAC, and it becomes unmanageable as the number of people grows.
Q31 | Least privilege
When deciding access rights for a new business system, which approach follows the principle of least privilege?
When unsure how to set rights, just grant administrator rights that allow use of every function.
Grant rights somewhat broader than what the job requires, so there is no hassle of applying for more later.
Grant only the rights needed to carry out the assigned duties, and remove them promptly once no longer needed.
Give everyone in the same department the same rights as the department head.
AnswerC. Grant only the rights needed to carry out the assigned duties, and remove them promptly once no longer needed.
The principle of least privilege means granting only the minimum rights necessary for the job and promptly removing them once no longer needed. The broader the rights, the greater the potential damage from an operating mistake or from internal fraud. Granting broader rights just in case, giving an entire department the same rights as a senior staff member, or defaulting to administrator rights when unsure are all cases of over-granted privilege and go against the principle.
Q32 | Segregation of duties
The person in charge of payment processing was found to be able to both register payment data and approve it themselves. Which of the following is the most appropriate reason this situation is a problem?
Processing volume is concentrated on a single staff member, raising that person's workload
Fraud or a mistake can be completed by one person alone, since no mutual check is in place
Two separate user IDs, one for registration and one for approval, are needed, increasing the management burden
The system's response speed drops when the same person carries out processing repeatedly
AnswerB. Fraud or a mistake can be completed by one person alone, since no mutual check is in place
Segregation of duties separates the person who applies for something from the person who approves it, so that splitting roles and permissions prevents fraud from being completed by one person alone and lets a mistake be caught by a second pair of eyes. In the situation described, this mutual check does not function. Workload, system response speed, and the burden of managing IDs are all matters of efficiency and do not explain the control problem.
Q33 | Privileged accounts
Which of the following is the most appropriate way to manage a privileged account used by a system administrator?
To work quickly, have administrators share a single privileged account.
Normally work under an ordinary user account, and use the privileged account, with a request and a record, only when it is actually needed.
To save effort, log in with the privileged account for everything, including ordinary daily tasks.
Since it is enough for the person who did the work to check the operation log themselves, skip having anyone else review it.
AnswerB. Normally work under an ordinary user account, and use the privileged account, with a request and a record, only when it is actually needed.
A privileged account can do almost anything, so the principle is to use it only when needed and to record its checkout, return, and the work performed. Sharing the account makes it impossible to trace whose action something was. Working under it at all times means an operating mistake or a malware infection can cause damage on a much larger scale at once. Operation logs only function as a check when reviewed by someone other than the person who did the work, so the person's own review alone is not sufficient.
Q34 | At a transfer
An employee transferred from the sales department to the accounting department. Which of the following must always be done as part of account management?
Because there is a handover period, review rights six months after the transfer, together with everyone else's.
Add the rights needed in the accounting department, and leave the rights used in the sales department as they are.
Make no change to rights unless the employee reports a work-related inconvenience.
Grant the rights needed for accounting work and, at the same time, remove the rights used in the sales department.
AnswerD. Grant the rights needed for accounting work and, at the same time, remove the rights used in the sales department.
At the time of a transfer, the rights for the new department must always be granted at the same time the rights from the previous department are removed. Granting without removing lets rights pile up (residual privilege), a state that violates the principle of least privilege. Deferring the review or waiting for the employee to report a problem leaves unnecessary rights in place the entire time. In the same way, when an employee leaves, the account must be disabled without delay.
Q35 | Zero trust
Which of the following is the most appropriate measure based on the idea of zero trust?
Regardless of whether access comes from inside or outside the company, verify the user and device every time, and grant the minimum rights necessary.
Remove the firewall and stop controlling traffic altogether.
Treat access from the internal network as trustworthy and skip authentication.
Ban all access from outside the company, allowing only employees who come into the office to use the system.
AnswerA. Regardless of whether access comes from inside or outside the company, verify the user and device every time, and grant the minimum rights necessary.
Zero trust does not assume “safe because it's internal”; it verifies every access, combining checks on the user and device, least privilege, encrypted communication, and continuous monitoring. The first choice is exactly the traditional assumption of trusting the inside of the perimeter. The third choice is a misunderstanding — it does not mean abandoning perimeter defense, but adding the assumption that the inside should not be trusted either. The fourth choice bans all external access entirely, a different idea from zero trust.
Practice: answer the questions on this page
This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.
* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.
This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original