On a business PC, the antivirus software shows a warning that it has “detected malware,” and the PC's behavior has also become unstable. What should the user do first?
Delete all of the antivirus software's detection history and warning logs so the warning stops appearing
Disconnect the PC from the network, for example by unplugging the LAN cable or turning off Wi-Fi
Press and hold the power button to immediately turn the PC off
Search the internet on their own for a removal tool, download it, run it, and try to remove the malware themselves
AnswerB. Disconnect the PC from the network, for example by unplugging the LAN cable or turning off Wi-Fi
For a device suspected of infection, the top priority is stopping the damage from spreading to other internal devices or servers, so it should be disconnected from the network first. Turning off the power is inappropriate because it erases volatile evidence, such as information in memory, needed to investigate the cause. Deleting logs destroys evidence and must never be done. Trying to remove the malware alone also risks making a mistaken judgment that spreads the damage further and delays reporting.
Q2 | Handling the power
For a device suspected of malware infection, the rule is to disconnect it from the network without turning off the power. Which of the following is the most appropriate reason for this?
To preserve volatile information, such as data in memory and the state of network connections, that would be lost if the power were turned off, so it can be used for investigating the cause
Because turning off the power would cause every file on the hard disk to be encrypted
Because turning off the power would reset the antivirus software's definition files
Because turning off the power would act as a signal that automatically spreads the malware across the internal network
AnswerA. To preserve volatile information, such as data in memory and the state of network connections, that would be lost if the power were turned off, so it can be used for investigating the cause
Volatile data such as malicious code loaded into memory or a connection that is still being established is lost the instant the power is turned off. This data is an important clue for tracing the intrusion route and its scope, so the power is left on while only the network is disconnected. There is no such thing as files being encrypted, definition files being reset, or malware spreading upon power-off; all of these are wrong.
Q3 | Events versus incidents
Under JIS Q 27000, which of the following most appropriately describes the relationship between an information security event and an information security incident?
An incident refers to a minor, everyday occurrence, and only the subset with a large enough loss to require reporting to management is separately called an event.
An event refers only to something caused by an attack from outside the organization, and an incident refers only to something caused by an internal person violating a regulation.
Event and incident are synonyms, differing only in which term is used when writing a report.
An event indicates the occurrence of something related to security, and among these, the ones judged highly likely to compromise business operations and threaten information security are incidents.
AnswerD. An event indicates the occurrence of something related to security, and among these, the ones judged highly likely to compromise business operations and threaten information security are incidents.
An event is a broad concept covering things like an alert or a suspicious communication where it is not yet known whether damage has occurred, and after investigation, the ones judged highly likely to compromise business operations and threaten information security become incidents. The distinction is not based on the size of the loss, nor on external attack versus internal violation, and the two are not simply different names for the same thing — they stand in a containment relationship as distinct concepts.
Q4 | The response flow
Which of the following correctly orders the stages of incident response in their typical sequence?
Analysis and investigation → detection and intake → reporting → initial response (triage) → prevention of recurrence → containment and recovery
Detection and intake → analysis and investigation → prevention of recurrence → initial response (triage) → containment and recovery → reporting
Detection and intake → initial response (triage) → analysis and investigation → containment and recovery → reporting → prevention of recurrence
Initial response (triage) → detection and intake → containment and recovery → prevention of recurrence → analysis and investigation → reporting
AnswerC. Detection and intake → initial response (triage) → analysis and investigation → containment and recovery → reporting → prevention of recurrence
An incident is first taken in at a contact point; triage estimates the scope of impact and urgency to set priority; the cause and scope are then investigated; the spread is stopped and the system recovered; those involved are reported to; and finally, a permanent fix (prevention of recurrence) addresses the root cause. Placing prevention of recurrence before analysis, triage before detection, or analysis before intake are all orderings that do not work.
Q5 | What to do after opening it
An employee opened an attachment from an email disguised as coming from a business partner. Nothing seemed to happen right after opening it, but the employee grew uneasy. What should this employee do first?
To find out whether the email was really suspicious, send an inquiry email to the sender's address and wait for a reply
Just to be sure, open the attachment again and carefully check every last detail themselves for anything unusual
Disconnect the device from the network and immediately report it to their supervisor and the information security team (CSIRT)
Since nothing in particular happened after opening the attachment, wait and see for a while, and only report it to the contact point once something abnormal appears
AnswerC. Disconnect the device from the network and immediately report it to their supervisor and the information security team (CSIRT)
Because infection is already possible from the moment the attachment was opened, disconnecting the device to stop the damage from spreading and immediately reporting it to the designated contact point are the first actions to take. Replying to the attack email would confirm to the attacker that the address is in use, which is inappropriate. Opening it again only makes any damage more certain and serves no purpose. Waiting until something abnormal appears only delays discovery and lets the damage spread.
Q6 | Triage
Which of the following most appropriately describes triage in incident response?
Quickly estimating the scope of impact and the urgency of a reported case, and deciding the priority and who will handle it
Taking time to identify the root cause of an incident and deciding and carrying out a permanent measure to prevent recurrence
Having each department's staff member confirm, one by one, that operations have returned to normal after recovery
Confirming, using hash values, that collected evidence has not been altered along the way, and recording that confirmation
AnswerA. Quickly estimating the scope of impact and the urgency of a reported case, and deciding the priority and who will handle it
Triage is the prioritization carried out at the initial-response stage to decide where limited staff should be assigned. Confirming with hash values is a task of evidence preservation, identifying the root cause and deciding a permanent measure spans activities from analysis and investigation through prevention of recurrence, and confirming recovery is a task of the recovery stage — none of these is triage itself.
Q7 | A misdirected email
An employee realizes that an email with a customer list attached was sent to the wrong recipient, a different outside company. What should be done first?
Call the recipient themselves to explain the situation, and if they promise to delete it, skip reporting the matter internally
Record the facts — the recipient, the time sent, and the content of the attachment — and immediately report it to their supervisor and the information security officer
Delete the email from their own Sent folder so that no record of it having been sent remains anywhere inside the company
To avoid causing trouble for customers, call every affected customer to apologize before telling their supervisor
AnswerB. Record the facts — the recipient, the time sent, and the content of the attachment — and immediately report it to their supervisor and the information security officer
Because this may constitute a leak of personal data, the organization needs to decide whether reporting to a supervisory authority or notifying the affected individuals is required, so recording the facts and reporting them is the correct first step. Contacting the recipient is necessary, but it is not a reason to skip reporting. Deleting the sent record destroys evidence and makes it impossible to confirm the facts or report them. Contact with the customer should happen only after the organization has decided its scope and content.
Q8 | Problem management
Which of the following most appropriately describes the difference between incident management and problem management?
Incident management aims to identify the root cause and prevent recurrence, while problem management aims to apply a temporary workaround.
Incident management aims to restore the service as quickly as possible, while problem management aims to identify the root cause and prevent recurrence.
Incident management is carried out by management, and problem management by the frontline department — the difference is who is in charge.
Incident management deals only with information security cases, and problem management deals only with system failures.
AnswerB. Incident management aims to restore the service as quickly as possible, while problem management aims to identify the root cause and prevent recurrence.
The main focus of incident management is to restore operations or the service as quickly as possible, even with a temporary workaround. Problem management, working behind the scenes, aims to identify the root cause and prevent recurrence through a permanent fix. The choices that reverse the purposes, or frame the difference as scope or who is in charge, are all wrong.
Q9 | Responding to a loss
An employee notices they have lost a company-issued laptop containing customer information while out of the office. What should this employee do first?
Since there is a chance it will turn up, look for it on their own that day and only report it the next morning if it is not found
Note the time and circumstances of noticing the loss, and immediately contact their supervisor and the information security team
First file a report with the nearest police station, and report it internally only if it is never found
Contact the customer on their own judgment and inform them first that there is a possibility their information has leaked
AnswerB. Note the time and circumstances of noticing the loss, and immediately contact their supervisor and the information security team
A loss is a case that can lead to an information leak, and only the organization can take steps such as remote locking, cutting off the line, or deciding whether reporting is required, so it should be reported internally the moment it is noticed. Searching alone and delaying the report is a classic way to let the damage spread. A police report is also needed, but it is not a reason to delay the internal report. Contact with the customer should happen only after the organization decides what to say.
Q10 | Finding a trace
A staff member reviewing server logs found a record showing repeated login attempts on an administrator account late at night, with one of them succeeding. What should be done first?
Just reinitialize the server for now, restore it from backup, and continue business as usual
Preserve the relevant log (save it so it cannot be overwritten) and report it to the CSIRT and their supervisor
Since the log entries are confusing, delete the relevant lines to tidy it up and make it easier to read
Connect on their own to the IP address that appears to be the source of the attack, investigate that party's system, and prepare to retaliate
AnswerB. Preserve the relevant log (save it so it cannot be overwritten) and report it to the CSIRT and their supervisor
The log is the only clue to the intrusion route and its scope, so preserving it before it is overwritten or deleted, and reporting it so the organization can decide how to respond, is the first action. Deleting the log destroys evidence. Reinitializing without knowing the cause also erases the evidence and leaves the same route open to a repeat intrusion. Investigating the other party's system risks constituting unauthorized access and must not be done.
Q11 | Preserving evidence
Which of the following is the most appropriate way to carry out evidence preservation in digital forensics?
Delete unnecessary files that would get in the way of analysis first, and narrow down the target before making a copy
Analyze the original target disk directly, and extract and save only the files that are needed
Since the investigation takes time, keep working across a rotation of staff members without keeping any record
Make a copy of the target disk, demonstrate that it is identical using a hash value, and then analyze the copy
AnswerD. Make a copy of the target disk, demonstrate that it is identical using a hash value, and then analyze the copy
Operating directly on the original changes its content and timestamps, destroying its value as evidence, so a copy is made, shown to be identical to the original using a hash value, and the copy is what gets analyzed. Both operating on the original directly and deleting files beforehand damage the evidence. A record of who handled what and when is also essential to show the chain of custody, so an operation that keeps no record cannot be accepted.
Q12 | CSIRT
Which of the following is the most appropriate role for a CSIRT set up within a company?
Accepting incident reports through a single contact point, deciding the triage and response policy, and coordinating communication both inside and outside the company
Auditing the company's information systems and, from an independent standpoint, submitting an audit report to management with recommendations for improvement
Taking on the development of information systems and handling everything from designing and implementing security functions through to maintenance after deployment
Continuously monitoring employees' work attendance and disciplining anyone who violates work rules
AnswerA. Accepting incident reports through a single contact point, deciding the triage and response policy, and coordinating communication both inside and outside the company
A CSIRT is the command center for incident response, handling intake, triage, coordinating the response, reporting, and liaising with outside organizations. Designing and implementing systems is the role of the development department and not the CSIRT's core mission. Monitoring attendance or disciplining staff belongs to human resources. Auditing from an independent standpoint is the role of a systems auditor, a different standpoint from the CSIRT, which is a party to the response itself.
Q13 | CSIRT versus SOC
Which of the following most appropriately describes the difference in roles between a CSIRT and a SOC?
A SOC handles only recovery work after an incident has occurred, and a CSIRT handles only the ongoing monitoring of logs and alerts during normal times, staying out of response coordination.
A SOC is responsible for reporting to management and handling public relations, and a CSIRT is responsible only for changing equipment configuration.
A SOC detects and analyzes signs of attack through continuous monitoring of logs and alerts, and a CSIRT decides the response policy for a detected case and coordinates it inside and outside the company.
A SOC responds to vulnerabilities in the products the company itself provides, and a CSIRT handles only inquiries from outside the company.
AnswerC. A SOC detects and analyzes signs of attack through continuous monitoring of logs and alerts, and a CSIRT decides the response policy for a detected case and coordinates it inside and outside the company.
The core of a SOC is detection and analysis, while the core of a CSIRT is deciding and coordinating the response to a detected case. The choice that swaps monitoring and response, and the one that assigns management reporting and public relations to the SOC, both get the roles reversed or overreach. Responding to vulnerabilities in the company's own products is the role of a PSIRT, not a SOC.
Q14 | PSIRT
Which of the following most appropriately describes a PSIRT?
A team that continuously monitors a company's own internal network and servers 24 hours a day, detecting communication anomalies at an early stage
An organization in which member companies within an industry bring threat information together, analyze it, and share the results widely among member companies
A team that accepts vulnerability information about the products or services a company itself provides, and handles releasing fixes and notifying customers
An organization that formulates a government-wide cybersecurity strategy and defines and publishes unified standards each ministry must follow
AnswerC. A team that accepts vulnerability information about the products or services a company itself provides, and handles releasing fixes and notifying customers
A PSIRT is a team responsible for product security, and it differs from a CSIRT in that what it protects is not the company's own internal network but the users of its products. Continuous monitoring of the internal network is the role of a SOC, formulating government-wide strategy is the role of the Cabinet Secretariat's National Cyber Security Office (NCO, reorganized from NISC in July 2025), and an industry-wide information-sharing organization is an ISAC; none of these describes a PSIRT.
Q15 | An outside organization
Which domestic organization accepts incident reports, coordinates among the parties involved, liaises with CSIRTs overseas, and issues alerts?
ISMS-AC
NISC
the Personal Information Protection Commission
JPCERT/CC
AnswerD. JPCERT/CC
JPCERT/CC is the organization that accepts incident reports, coordinates among the parties involved, liaises with CSIRTs overseas, and issues alerts. NISC (the National center of Incident readiness and Strategy for Cybersecurity) stood as the government's command center setting national strategy and standards, and it was reorganized in July 2025 into the Cabinet Secretariat's National Cyber Security Office (NCO). ISMS-AC is the body that accredits ISMS certification bodies. The Personal Information Protection Commission is the supervisory body under the Act on the Protection of Personal Information and is where reports of a personal data leak, among other things, are submitted.
Q16 | A sharing framework
Which of the following most appropriately describes the activity of J-CRAT?
Gathering vulnerability countermeasure information and publishing it for users on a portal site
Receiving consultations from organizations suspected of having suffered a targeted attack, and supporting them in stopping the damage from spreading and responding early
Accrediting certification bodies for information security management systems
Anonymizing information about targeted attacks that participating organizations bring together and sharing it, helping other organizations notice threats early
AnswerB. Receiving consultations from organizations suspected of having suffered a targeted attack, and supporting them in stopping the damage from spreading and responding early
J-CRAT (the Cyber Rescue Team) supports organizations suspected of having suffered a targeted attack, working to cut the attack chain and prevent the damage from spreading. The framework for sharing information among participating organizations is J-CSIP, the portal that publishes countermeasure information is JVN, and accrediting certification bodies is the role of ISMS-AC; each of these is something different.
Q17 | Reporting a vulnerability
You have found an undisclosed vulnerability in a software product your company uses. Which of the following is the most appropriate way to handle it under the Information Security Early Warning Partnership?
To check whether it can actually be exploited, try it out on another company's server that runs the same publicly available product.
Report the vulnerability information to IPA and wait for JPCERT/CC to coordinate with the developer and arrange disclosure.
If it does not affect your own company, keep it entirely in-house, take countermeasures internally, and tell no one.
To warn users of the danger immediately, publish the details of the vulnerability and how to reproduce it on social media right away.
AnswerB. Report the vulnerability information to IPA and wait for JPCERT/CC to coordinate with the developer and arrange disclosure.
Vulnerability-related information is received by IPA, and for a product vulnerability, JPCERT/CC coordinates with the developer and sets a disclosure date, with countermeasure information published on JVN. Publishing details before a fix exists is inappropriate because it would be exploited. Trying it against another company's system risks violating the Act on Prohibition of Unauthorized Computer Access. Leaving it unaddressed leads to harm for users at large.
Q18 | SIEM
Which of the following most appropriately describes SIEM?
A mechanism that centrally aggregates logs from various devices and software and detects, through correlation analysis, signs of an attack that would not be noticed from any single log alone
A mechanism that encrypts communication content so that even if it is intercepted in transit, it cannot be read
A mechanism that replicates important data to a remote site so that operations can resume quickly and continue even after a disaster
A mechanism that forces device users to change their password periodically and bans reuse across other services
AnswerA. A mechanism that centrally aggregates logs from various devices and software and detects, through correlation analysis, signs of an attack that would not be noticed from any single log alone
SIEM is a mechanism that performs detection through log aggregation and correlation analysis, serving as the core tool of a SOC. Forcing password changes is a function of account management, encrypting communications is a technology such as TLS, and replicating to a remote site is a backup or business-continuity measure; none of these describes SIEM.
Q19 | A tabletop drill
Which of the following most appropriately describes a tabletop exercise held to prepare for an information security incident?
A drill in which the system is actually taken offline, recovery work is carried out step by step in the production environment, and the time taken is measured and recorded
A drill in which training emails are sent to all users at once, tallying how many people opened them and how many reported them to the contact point
A drill in which an assumed damage scenario is presented on paper and the people involved gather to walk through the flow of decisions and communication, uncovering gaps in the procedure
An assessment in which outside experts actually attempt an attack to test whether they can break into the system, and report the results
AnswerC. A drill in which an assumed damage scenario is presented on paper and the people involved gather to walk through the flow of decisions and communication, uncovering gaps in the procedure
A tabletop exercise presents an assumed damage scenario on paper and has the people involved gather to walk through, in order, who decides what and who contacts whom, finding gaps in the procedures or overlapping roles. Stopping the production environment to carry out the drill is a hands-on recovery drill, sending training emails is a targeted-attack email drill, and actually attempting an attack is penetration testing; none of these is a tabletop exercise.
Q20 | Discovering a leak
A staff member in the sales department notices a case in which a file containing customers' personal data may have leaked outside. What should this staff member do first?
Follow the reporting route defined in internal regulations and immediately report it to the personal information protection manager or the information security officer
Investigate it within the department alone, and report it internally only once it becomes certain that a leak occurred
Since it is not yet confirmed whether a leak occurred, individually contact the customers who might be affected to check
Call the Personal Information Protection Commission directly under their own name to explain the situation, and report to their internal supervisor only after receiving the Commission's instructions
AnswerA. Follow the reporting route defined in internal regulations and immediately report it to the personal information protection manager or the information security officer
Reporting a leak and notifying affected individuals are actions the business itself must take, so the staff member's correct first step is to escalate it to a responsible manager through the internal reporting route. Even a mere possibility of a leak can be subject to reporting, so waiting for certainty only delays the response. Reporting to the Commission is something the business does, not something an individual should get ahead of. Contacting the customers directly would only cause confusion and anxiety.
Q21 | Preliminary and final reports
Regarding reporting a personal data leak to the Personal Information Protection Commission, which of the following is most appropriate?
Submit a preliminary report promptly after becoming aware of the situation, and submit the final report in principle within 30 days (within 60 days for a situation suspected of having been carried out with wrongful intent)
There is no need to submit either a preliminary or a final report until the investigation is finished and the cause and scope are confirmed; a single combined report can be submitted afterward
Reports are accepted only in writing and must be submitted to the Personal Information Protection Commission within three months of becoming aware of the situation
There is no distinction between a preliminary and a final report; a single report covering everything is submitted within one year of becoming aware of the situation
AnswerA. Submit a preliminary report promptly after becoming aware of the situation, and submit the final report in principle within 30 days (within 60 days for a situation suspected of having been carried out with wrongful intent)
Reporting happens in two stages: a preliminary report covering what is known so far is submitted promptly (roughly within 3 to 5 days of discovery is used as a guide), followed by a final report, in principle within 30 days, or within 60 days for the category involving wrongful intent. Withholding any report until the investigation is complete is not permitted. Deadlines of one year or three months, and a written-only restriction, are also wrong.
Q22 | What must be reported
Among cases of a personal data leak, which of the following is not a situation for which reporting to the Personal Information Protection Commission is mandatory?
A situation in which personal data containing credit card numbers leaked, creating a risk of financial harm from fraudulent use
A situation in which personal data held by the organization may have been taken outside due to unauthorized access from outside
A situation in which personal data containing special-care-required personal information, such as an employee's medical history, leaked outside
A situation in which an internal-only product development document was mistakenly sent outside, but it contained no personal data
AnswerD. A situation in which an internal-only product development document was mistakenly sent outside, but it contained no personal data
The subject of the reporting obligation is a leak of personal data, so mistakenly sending a document that contains no personal data falls outside it (though it should of course still be reported internally as a matter of internal management). A situation involving special-care-required personal information, one with a risk of financial harm, and one suspected of having been carried out with wrongful intent all fall under the four defined categories and require reporting. A situation affecting more than 1,000 individuals is also within scope.
Q23 | Notifying the individuals
Regarding notifying the affected individuals when a personal data leak occurs, which of the following is most appropriate?
Notifying the individuals is merely a best-effort goal, so deciding in advance through internal regulations not to notify them means nothing needs to be done at all, including a public announcement or an inquiry desk
Notify them promptly depending on the circumstances of the situation, but when notification is difficult, for example because contact information is unknown, alternative measures such as a public announcement or setting up an inquiry desk may be taken instead
The individuals may not be notified until after the final report has been submitted to the Personal Information Protection Commission and its content confirmed
As long as the report to the Personal Information Protection Commission is submitted within the deadline, notifying the individuals becomes unnecessary across the board
AnswerB. Notify them promptly depending on the circumstances of the situation, but when notification is difficult, for example because contact information is unknown, alternative measures such as a public announcement or setting up an inquiry desk may be taken instead
Notifying the affected individuals is an obligation and must be done promptly depending on the circumstances. When notification is difficult, for instance because contact information is unknown, it is permitted to substitute an alternative measure necessary to protect the individuals' rights and interests, such as a public announcement or setting up an inquiry desk. It cannot be waived by an internal decision, reporting to the Commission and notifying individuals are separate obligations, and there is no need to wait for the final report.
Q24 | Auditor independence
Regarding the independence of a systems auditor, which of the following is most appropriate?
An auditor must personally carry out the improvement work for a finding they raised, and personally confirm the result
An auditor must not audit an information system in whose design, development, or operation they themselves were involved
An auditor may audit the department they are being audited in while also handling that department's day-to-day work as one of its members
An auditor must be independent of management and must not submit the audit report to management
AnswerB. An auditor must not audit an information system in whose design, development, or operation they themselves were involved
An auditor is required to have both external independence, meaning no conflict of interest with the audited department, and internal independence, meaning a fair and objective mindset; self-auditing a system one was involved with is prohibited. Holding a role within the audited department is disallowed for the same reason. An auditor's position is to advise and recommend, with carrying out the countermeasure remaining the audited department's responsibility. The audit report is meant to be submitted to management, so a statement banning submission is also wrong.
Q25 | The audit procedure
Regarding how a systems audit should proceed, which of the following is most appropriate?
Because the auditor's own impression matters most, skip the work of gathering objective evidence such as an audit trail
Carry out the main survey first to gather facts, and only afterward draw up the audit plan and audit procedures to match what was found
The audit is complete once the audit report is submitted to management, so the follow-up that later confirms whether the raised findings were improved is omitted
Draw up an audit plan, grasp the overview through a preliminary survey, carry out the main survey, go through evaluation and conclusions, submit a report, and then confirm the improvement status through a follow-up
AnswerD. Draw up an audit plan, grasp the overview through a preliminary survey, carry out the main survey, go through evaluation and conclusions, submit a report, and then confirm the improvement status through a follow-up
A systems audit begins with planning, uses a preliminary survey to grasp the target's overview and key points, gathers and evaluates an audit trail during the main survey, conveys findings and recommendations in a report, and confirms the improvement status through a follow-up. Ending at the report is wrong. Drawing up the plan afterward cannot work, since it would leave the audit's purpose and scope undefined. An audit is based on objective evidence, and a conclusion must never rest on impression alone.
Practice: answer the questions on this page
This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.
* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.
This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original