Regarding the timing and content of information security training for new employees, which of the following is most appropriate?
Before they begin work, explain the company's information security policy and the regulations they must follow on the job
Have them experience the work of their assigned department for a year first, and only provide the training once they personally feel its necessity
Target it only at those assigned to the information systems department, explaining device configuration procedures in detail
Since separate annual training is given to the whole company, skip individual training for new employees and fold it into the annual training instead
AnswerA. Before they begin work, explain the company's information security policy and the regulations they must follow on the job
Starting work without knowing the regulations makes a violation almost unavoidable, so the principle is to convey the policy and the regulations to follow before work begins. Waiting a year or until the annual training is inappropriate because it creates a gap in the meantime. Explaining configuration procedures is additional training for a specific role and is no substitute for the basic training everyone who touches information needs.
Q2 | The purpose of the drill
Which of the following is the most appropriate purpose for carrying out a targeted-attack email drill?
Verifying whether the firewall's communication rules are configured correctly
Analyzing the malware samples collected through the drill to create new pattern files
Identifying and disciplining the employees who opened the drill email, to prevent recurrence
Establishing the behavior of not opening a suspicious email and immediately reporting it to the contact point
AnswerD. Establishing the behavior of not opening a suspicious email and immediately reporting it to the contact point
The goal of the drill is to establish the behavior of not opening a suspicious email and reporting it right away, and to confirm that the reporting contact point actually functions. Using it for discipline creates an atmosphere where reporting becomes difficult and backfires. The drill email is a harmless simulation, not a means of collecting malware samples. Verifying firewall rules is a task of checking configuration and has a different purpose from a drill that measures human behavior.
Q3 | NDAs
Regarding a non-disclosure agreement (NDA) signed with an employee, which of the following is appropriate?
Once the agreement is signed, there is no longer any need to check on the contractor's management practices
It is signed only with regular employees; temporary staff and part-time workers can be excluded from it
It is common to state that the duty of confidentiality continues for a set period even after leaving the company
It is valid only while the person remains employed, and the duty of confidentiality disappears the moment they leave
AnswerC. It is common to state that the duty of confidentiality continues for a set period even after leaving the company
Because secrets retain their value even after someone leaves, it is normal to state that the obligation continues for a set period after departure, and to reconfirm this at the time of leaving. A pledge should be obtained from anyone who has access to information regardless of employment type, so excluding temporary staff or part-timers is inappropriate. A contract is only a promise, and it is no basis for stopping checks on how it is actually being carried out.
Q4 | When an employee leaves
Regarding the information security procedures that accompany an employee's departure, which of the following is most appropriate?
Disable the business system account by the employee's last working day, and collect any loaned equipment
Do not collect loaned items such as an ID card or keys until the person offers to return them
Since the duty of confidentiality disappears upon departure, skip reconfirming it at the time of leaving
Leave the account usable even after departure, so business inquiries can still be answered
AnswerA. Disable the business system account by the employee's last working day, and collect any loaned equipment
If a departing employee's account is left usable, misuse by a third party would be recorded as if it were legitimate use, making it hard to detect, so the principle is to disable it and collect loaned items by the last working day. If someone is needed to handle follow-up inquiries, a successor can be designated for that. Leaving collection up to the individual, and denying that a duty of confidentiality continues after departure, are both wrong.
Q5 | Categories of countermeasure
Information security measures can be organized into human, technical, and physical measures. Which of the following falls under a human measure?
Encrypting important files before storing them
Managing entry and exit to the server room with IC cards
Using a firewall to block unnecessary communication from outside the company
Carrying out a targeted-attack email drill for all employees
AnswerD. Carrying out a targeted-attack email drill for all employees
A human measure works on people's behavior through education, training, regulations, and agreements, and carrying out a drill falls under this. IC-card-based entry and exit control is a physical measure protecting a location and its facilities, and blocking traffic with a firewall or encrypting files are technical measures relying on the functions of equipment or software.
Q6 | An outsourcing partner
Regarding how to handle a situation where business is outsourced and the contractor's staff handle the company's personal data, which of the following is most appropriate?
Set out confidentiality and subcontracting conditions in the contract, require a level of management equivalent to the company's own, and check on how it is actually being carried out
Since the contractor's staff are not the company's own employees, exclude them from information security training or pledges
Prioritize efficiency for subcontracting, and allow it based solely on an informal understanding between the frontline staff involved
Since management is the contractor's responsibility, stop checking on it from the company's own side once the contract is signed
AnswerA. Set out confidentiality and subcontracting conditions in the contract, require a level of management equivalent to the company's own, and check on how it is actually being carried out
Responsibility for data entrusted to a contractor remains with the party that handed it over, so the contract needs to define confidentiality, whether and under what conditions subcontracting is allowed, reporting in the event of an incident, and returning or erasing the data when the engagement ends, with implementation checked through reports or visits. Not checking after the contract is signed, allowing subcontracting on a verbal understanding, and excluding the contractor's staff from training are all inappropriate because each lets management fall out of reach.
Q7 | Internal fraud
Which of the following initiatives can be expected to be effective in deterring internal fraud?
Informing employees in advance that access logs are being taken for important data
Applying no restriction on privileges for management staff, letting them freely view all information at any time
Keeping the fact that logs are being taken hidden from employees, and rounding up and exposing violators later
Setting up no consultation channel for wrongdoing and instead having whoever notices it warn the person directly
AnswerA. Informing employees in advance that access logs are being taken for important data
Deterrence means discouraging the impulse to commit wrongdoing in the first place, and communicating in advance that logs are taken, creating an awareness of being watched, is effective. Hiding the fact that logs are taken has no deterrent effect and also breeds distrust once discovered. Broadening privileges for managers simply because of their position violates least privilege and increases potential damage. Handling matters directly between the parties without a consultation channel prevents both early detection and keeping a record.
Q8 | Training for managers
Which of the following is the most appropriate content for information security training aimed at managers?
The responsibility that comes with approving a subordinate's access rights, and the escalation procedure for when a report comes in
The procedure for identifying and disciplining a subordinate who opened an attachment during a targeted-attack email drill
Learning the concrete configuration procedures for servers and network equipment, so they can make configuration changes on their own judgment
Covering the same content as the training given to all employees, with nothing specific to managers
AnswerA. The responsibility that comes with approving a subordinate's access rights, and the escalation procedure for when a report comes in
A manager is in the position of approving a subordinate's access rights and being the first to receive a subordinate's report, so training needs to cover the responsibility of the approver and the escalation procedure for raising a report to a senior person or the CSIRT according to defined criteria. Configuration procedures are content for information systems department staff. Using a drill's results for discipline discourages reporting and delays discovery instead. Because different positions require different judgment, the same content given to all employees is not enough on its own.
Q9 | Combining classifications
Which of the following correctly classifies the following three measures as human, technical, or physical? (a) Signing a non-disclosure agreement with employees. (b) Securing a laptop to a desk with a security cable. (c) Encrypting communication with the file server using TLS.
(a) Physical, (b) Human, (c) Technical
(a) Human, (b) Technical, (c) Physical
(a) Technical, (b) Physical, (c) Human
(a) Human, (b) Physical, (c) Technical
AnswerD. (a) Human, (b) Physical, (c) Technical
(a) is a human measure that binds a person's behavior through a contract, (b) is a physical measure that secures equipment against the physical threat of theft, and (c) is a technical measure relying on the function of software or equipment to encrypt communication. Combinations that classify (b) as technical, (c) as physical, or (a) as technical or physical do not match the nature of each measure.
Q10 | Packets
Which of the following is the information a packet-filtering firewall uses to decide whether to allow or deny a communication?
The actual content of a value entered into a web application's input field
The parent-child relationship between processes run on a device, and when they were launched
The source and destination IP addresses, port numbers, and protocol
Words or expressions contained in the body of an email
AnswerC. The source and destination IP addresses, port numbers, and protocol
Packet filtering works by looking at the IP addresses, port numbers, and protocol in a packet's header and checking them against a set of rules. Words in an email body are the domain of a mail filter, values entered into a web application are the domain of a WAF, and the behavior of processes on a device is the domain of EDR; none of these is what a packet-filtering firewall bases its decision on.
Q11 | Stateful inspection
Which of the following correctly describes stateful inspection in a firewall?
It remembers the state of a connection and dynamically allows the response packets to communication that originated from inside
It is installed on each device, continuously monitors for suspicious behavior from unknown malware, and automatically isolates the device
It inspects the content of requests to a web server, detecting and blocking attacks such as SQL injection
It uses DNS information on the receiving side to verify whether an email's sending domain is genuine
AnswerA. It remembers the state of a connection and dynamically allows the response packets to communication that originated from inside
Stateful inspection keeps track of a connection's state and dynamically allows the return traffic for a connection that originated from inside, removing the need to leave a wide range of ports open in advance just to receive that return traffic. Verifying the sending domain is the role of sender domain authentication such as SPF, monitoring device behavior is the role of EDR, and inspecting request content is the role of a WAF; none of these is what state tracking in a firewall does.
Q12 | The DMZ
Which of the following is most appropriately placed in a DMZ?
The company's own web server, published to the internet
The application server for an accounting system used internally
An internal database server storing HR information
A directory server that only authenticates internal users
AnswerA. The company's own web server, published to the internet
A DMZ is a buffer zone separated by a firewall from both the internet and the internal LAN, and it holds servers such as a web server or mail server that need to be exposed externally. Placing them there means that even if a public-facing server is compromised, it does not lead directly into the internal LAN. An HR database, an authentication server, and an accounting system are used only from within the company, so they should be kept on the internal side, unreachable from outside.
Q13 | Firewall rules
The table below shows the connection-permission rules of a certain firewall. Rules are evaluated in order from the lowest number, and the action of the first matching rule is applied. Any traffic that matches no rule is denied at the end (implicit deny). When a PC on the internal LAN connects to a website on the internet over TCP/443, which combination of the rule number applied and the resulting outcome is correct?
Rule 1's destination is the DMZ web server, which does not match this traffic since its destination is the internet. Rule 2 matches, since its source is the internal LAN, its destination is the internet, and its service is TCP/80,443, so the traffic is allowed here and evaluation stops. Rule 3 does not match because its source is the internet, and evaluation never reaches rule 5, so it is never denied either.
Q14 | Implicit deny
A firewall has the rules shown in the table. Rules are evaluated in order from the top, and the action of the first matching rule is applied. Any traffic matching no rule is denied. When a device on the internet attempts a connection to the internal LAN's file server over TCP/445, how is it handled?
Rules 1 and 2 do not match because their source is the internal LAN. Rule 3's destination is the DMZ web server, which does not match this traffic since its destination is the internal LAN. Rule 4 matches on source (internet), destination (internal LAN), and service all at once, so it is denied. Even without rule 4, the catch-all deny in rule 5 would stop it, and traffic matching no rule is never allowed by default.
Q15 | Rule ordering
To block traffic from the IP address 203.0.113.9, identified as the source of an attack, to the DMZ web server, rule 3 in the table was added. Rules are evaluated in order from the lowest number, and the action of the first matching rule is applied. However, connections from that address continued even after the rule was added. Which of the following correctly identifies the cause and the fix?
Rule 1 matches first and allows the traffic, so rule 3 is never evaluated; move rule 3 to a position before rule 1
Rule 3 has the most specific condition and should be applied with priority, so the cause must be an equipment failure
It will eventually be blocked by the catch-all deny in rule 4, so the configuration is fine as it is
Rules 2 and 3 contradict each other, so deleting rule 2 will block the traffic
AnswerA. Rule 1 matches first and allows the traffic, so rule 3 is never evaluated; move rule 3 to a position before rule 1
Because rules are evaluated from the top and processing is decided at the first match, this traffic matches rule 1, a blanket allow to the DMZ for any source, before ever reaching rule 3, so rule 3 is never evaluated. The deny rule must therefore be placed before rule 1. Rules are not prioritized by how specific their condition is, and traffic already allowed earlier is never blocked by a deny rule that comes later. Rule 2 concerns traffic from the internal LAN outward and is unrelated to this case.
Q16 | WAF
Which of the following is what a WAF (web application firewall) mainly protects against?
A business device becoming infected by malware run from an email attachment
Attacks such as SQL injection that exploit a vulnerability in a web application
An outsider entering the server room and taking equipment out
Eavesdropping on communication content by intercepting the radio signal of unencrypted Wi-Fi
AnswerB. Attacks such as SQL injection that exploit a vulnerability in a web application
A WAF sits in front of a web server and inspects the content of HTTP traffic, blocking attacks such as SQL injection or cross-site scripting that target flaws in how an application is built. Malware in an attachment is handled by a mail filter or antivirus software, eavesdropping on Wi-Fi is handled by encryption such as WPA2 or WPA3, and an outsider's intrusion is handled by the physical measure of entry and exit control; none of these is a WAF's domain.
Q17 | IDS versus IPS
Which of the following correctly explains the difference between an IDS and an IPS?
An IDS is dedicated to web applications, and an IPS is dedicated to protecting email
An IDS can only be installed on a device, while an IPS can only be placed on a network
An IDS is a mechanism for encrypting communication, while an IPS is a mechanism for decrypting encrypted communication
An IDS only detects unauthorized traffic and reports it, while an IPS blocks the traffic it detects
AnswerD. An IDS only detects unauthorized traffic and reports it, while an IPS blocks the traffic it detects
The difference between the two lies in whether they stop at detection or go as far as blocking. An IDS detects a sign of an attack and notifies an administrator, while an IPS sits in the communication path and blocks the traffic it detects on the spot. Where each is installed depends on the use case and is not a device-only versus network-only distinction. Neither performs encryption or decryption, and neither is limited to a specific use case.
Q18 | EDR
Which of the following correctly describes EDR?
It is placed at the network perimeter and blocks unnecessary traffic
It sits between users and a cloud service, making usage visible and controlling it
It runs an unknown file in an environment isolated from production to judge whether it is dangerous
It records the behavior of endpoints such as PCs and servers, detecting suspicious activity after an intrusion to support isolation and investigation
AnswerD. It records the behavior of endpoints such as PCs and servers, detecting suspicious activity after an intrusion to support isolation and investigation
EDR continuously records the behavior of endpoints, detecting suspicious activity after an intrusion has occurred and helping with isolation and investigating the cause, making it a representative internal measure. Blocking traffic at the perimeter is a firewall, judging a file by running it in an isolated environment is a sandbox, and making cloud usage visible and controllable is a CASB; each of these has a different target and purpose from EDR.
Q19 | Entry-point measures
In defense in depth, measures are considered as entry-point measures, internal measures, and exit-point measures. Which of the following falls under an entry-point measure?
Inspecting the body and attachments of outgoing email for confidential information
Dividing the internal network by department so a server in one department cannot be reached directly from another
Recording each device's operation logs and periodically reviewing them for suspicious activity
Inspecting an incoming email's attachment in a sandbox before delivering it
AnswerD. Inspecting an incoming email's attachment in a sandbox before delivering it
Entry-point measures keep intrusion from outside or fraudulent email out of the organization in the first place, and inspecting an incoming attachment falls under this. Inspecting the content of outgoing email is an exit-point measure that stops information from leaving, and dividing the network or recording and reviewing operation logs are internal measures that assume an intrusion has already happened and work to limit the damage.
Q20 | Internal measures
Assuming a targeted attack has already breached the internal network, which of the following is the most appropriate internal measure?
Restrict outbound communication to go only through a proxy, and block traffic to suspicious destinations
Block suspicious email before users receive it, using a spam filter and attachment inspection
Use a firewall to block unnecessary traffic coming from outside into the company
Divide the internal network, require multi-factor authentication for access to important servers, and monitor device behavior
AnswerD. Divide the internal network, require multi-factor authentication for access to important servers, and monitor device behavior
Internal measures work to curb an attacker's lateral movement after an intrusion and to notice it early. Dividing the network, requiring multi-factor authentication for important servers, and monitoring device behavior fall under this. Blocking spam and blocking with a firewall are entry-point measures, and restricting and blocking outbound traffic is an exit-point measure that stops information from being taken out.
Q21 | Exit-point measures
Which of the following is the most appropriate exit-point measure to prepare for a malware-infected device attempting to send internal information out to an attacker's server?
Periodically review the server room's entry and exit records for suspicious activity
Apply patches for the OS and business software as soon as they are released
Restrict outbound traffic to go only through a proxy, log it, and block traffic to suspicious destinations
Verify the result of sender domain authentication (SPF) on received email to identify forgery
AnswerC. Restrict outbound traffic to go only through a proxy, log it, and block traffic to suspicious destinations
Exit-point measures keep stolen information from leaving and keep a device from communicating with an outside command-and-control server, and consolidating and logging outbound traffic while blocking suspicious destinations falls under this. Applying patches and verifying sender domain authentication are entry-point measures that prevent intrusion, and reviewing entry and exit records is a physical measure; none of these directly stops information from being taken out.
Q22 | Wi-Fi
Regarding the security of Wi-Fi used within a company, which of the following is appropriate?
Setting up MAC address filtering can prevent eavesdropping on communication content
Even with encryption disabled, hiding the SSID so it cannot be seen protects the content of the communication
WEP is highly compatible and secure, so it is still widely recommended today
WPA3 was standardized after WPA2 and has stronger encryption and authentication
AnswerD. WPA3 was standardized after WPA2 and has stronger encryption and authentication
WPA3 is newer than WPA2 and strengthens both encryption and authentication. WEP's method of being broken is widely known and it must not be used. Even with the SSID hidden, the radio signal itself is still being broadcast, and its content can be read if it is not encrypted. MAC address filtering only restricts which devices can connect and has nothing to do with encrypting the communication.
Q23 | Tailgating
Which combination correctly describes tailgating (piggybacking) in entry and exit control, along with its countermeasure?
Only an exit record being left with no entry record; prevented by synchronizing the time on entry and exit control devices
Entering by forging an ID card or borrowing someone else's; prevented by encrypting the information on the card to make copying difficult and by banning lending
Multiple users logging into the same device at the same time; prevented by introducing multi-factor authentication
An unauthenticated person following a legitimate user in through a door that person opened; prevented with anti-passback, a door structure that lets only one person through at a time, and employee training
AnswerD. An unauthenticated person following a legitimate user in through a door that person opened; prevented with anti-passback, a door structure that lets only one person through at a time, and employee training
Tailgating is when an unauthenticated person slips in right behind someone who has authenticated, which is dangerous because the record shows only one person entering. The countermeasure combines anti-passback, which prevents someone with no entry record from exiting, a door that lets only one person through at a time, monitoring, and training. The other choices describe card forgery, a missing record, and simultaneous login, none of which is tailgating.
Q24 | Physical measures
Which of the following measures falls under a physical measure?
Keeping antivirus software's pattern file up to date
Locking the server room door and recording who enters and exits
Carrying out information security training for employees
Setting a password for a user ID
AnswerB. Locking the server room door and recording who enters and exits
A physical measure protects the location and facilities where an information asset is kept, and locking a door and recording entry and exit fall under this. Carrying out training is a human measure that works on people's behavior, and setting a password or updating a pattern file are technical measures relying on the function of equipment or software.
Q25 | Tamper resistance
Which of the following correctly describes the tamper resistance required of something like an IC card?
The property of automatically switching to a backup system when a failure occurs, continuing processing without stopping
The property of encrypting the content of an exchange to prevent eavesdropping or reading the content while it is in transit
The property of becoming unable to operate, among other responses, if someone tries to unlawfully read out internal information, making analysis difficult
The property of protecting internal equipment and preserving operation even when a power abnormality such as a lightning strike or an outage occurs
AnswerC. The property of becoming unable to operate, among other responses, if someone tries to unlawfully read out internal information, making analysis difficult
Tamper resistance is the property of making internal information unreadable when the device is subjected to a physical attack such as disassembly or analysis. Preparing for a lightning strike or power outage is the domain of a UPS or surge protection, preventing eavesdropping is the domain of encrypting communication, and switching to a backup system is a property related to fault tolerance; each of these means something different from tamper resistance.
Q26 | Portable media
Which of the following is the most appropriate way to manage portable media such as USB drives?
Just to be safe, leave data that was taken out on the medium even after it has been returned
Require an application and approval for taking one out, record it in a log, and encrypt the data stored on it
As long as the data is encrypted, no application or record is needed for taking it out
Prioritize efficiency and let personal USB drives be freely used on business PCs without any application
AnswerB. Require an application and approval for taking one out, record it in a log, and encrypt the data stored on it
Portable media are a route for a leak through loss or theft, so operation should combine application and approval, a logged record, encrypting and minimizing the data, and reliably erasing it upon return. Free use of personal media invites both malware being brought in and unauthorized removal of data. Leaving data on the medium after it is returned only increases the chance of a leak, and encryption is no reason to skip the application.
Q27 | Disposing of paper
Which of the following is the most appropriate way to dispose of a paper document containing personal information?
Throw it out as-is together with general trash
Reuse it internally as scratch paper, since the back side is blank
Keep it in a collection box for a long period and put it out once a month together with combustible trash
Shred it or reliably dispose of it by outsourcing it for pulping
AnswerD. Shred it or reliably dispose of it by outsourcing it for pulping
To prevent scavenging, gathering information from discarded waste, a document must be put into a form that cannot be reconstructed before disposal, so shredding or pulping is appropriate. Reusing it internally as scratch paper risks unintended viewing or removal within the company. Throwing it out as-is, or accumulating it unshredded before putting it out, both leave it in a state a third party could read.
Q28 | Physical or technical
A company carries out the following measures (a) through (d). Which of the following lists exactly the ones that fall under physical measures? (a) Installing security cameras in the office. (b) Storing important documents in a lockable cabinet. (c) Encrypting the data on a USB drive. (d) Retaining entry and exit records for a set period.
(a), (c)
(a), (b), (c), (d)
(b), (c), (d)
(a), (b), (d)
AnswerD. (a), (b), (d)
Installing security cameras, storing documents in a lockable cabinet, and retaining entry and exit records are all physical measures directed at a location or facility. Encrypting data in (c) is a technical measure protecting content through a software function, and it does not by itself prevent the medium from being taken out, so it is not included among the physical measures.
Q29 | Zoning
Which of the following is the most appropriate way of thinking about managing an office by dividing it into zones such as reception, the general office, and the server room?
Impose stricter authentication for zones holding more important information assets, narrowing who may enter the further in one goes
Let both visitors and employees move along the same route, to reduce the effort of guiding and escorting people
Post signs in the building's corridors so visitors can easily find the server room's location
Leave the general office unlocked and it is enough to lock only the server room
AnswerA. Impose stricter authentication for zones holding more important information assets, narrowing who may enter the further in one goes
The key point of zoning is to build layers by importance, tightening authentication and narrowing who may enter the further in a zone sits. Not separating the routes for visitors and employees lets outsiders wander into the general office. Widely advertising the server room's location makes intrusion easier. The general office also holds information assets, so it is not acceptable to skip locking it or managing entry and exit there.
Q30 | Least privilege
The table shows access rights configured for a company's business system. The HR staff member registers and updates HR information; the payroll staff member handles payroll calculation (which requires viewing HR information); the sales staff member and the sales clerk (a temporary worker) enter orders; and the sales department handles neither HR nor payroll information. Which of the following settings should be revised in light of the principle of least privilege?
That the sales clerk (temporary) has view access to the HR database
That the sales staff member has update access to the order database
That the HR staff member has update access to the HR database
That the payroll staff member has view access to the HR database
AnswerA. That the sales clerk (temporary) has view access to the HR database
The sales clerk's job is entering orders, with no need to view HR information, so view access to the HR database is a privilege unnecessary for the job and should be removed. The HR staff member's update access to the HR database, the payroll staff member's view access to the HR database needed for payroll calculation, and the sales staff member's update access to the order database are each the minimum privilege necessary to carry out their assigned duties.
Q31 | Rights after a transfer
The table shows the access rights currently granted to Tanaka in the HR department. Tanaka is transferring to the sales department this month, where the job will involve entering orders and preparing documents shared within the sales department. Which of the following is the most appropriate way to configure access rights after the transfer?
For the handover, keep view access to the HR database for one year, and additionally grant update access to the order database and the sales department's shared folder
Leave the current settings unchanged until Tanaka submits a request
Revoke access to the HR database, the payroll database, and the HR department's shared folder, and grant update access to the order database and the sales department's shared folder
Leave the current settings as they are, and additionally grant update access to the order database and the sales department's shared folder
AnswerC. Revoke access to the HR database, the payroll database, and the HR department's shared folder, and grant update access to the order database and the sales department's shared folder
After a transfer, a person should hold only the rights needed for the new job, so the rights from the previous department should be removed before the rights for the new department are granted. Keeping the old rights for a long time under the guise of a handover, or only adding new rights, lets rights accumulate and violates the principle of least privilege. Waiting for a request creates a period where the person holds unnecessary rights while already working in the new role, so that is also inappropriate.
Q32 | Reviewing rights
The table lists the access rights to the payroll database. Only HR department staff in charge of payroll calculation use the payroll database for work. In an annual review, which of the following lists exactly the rights that should be removed?
B belongs to the sales department, which has no work that requires using the payroll database, so this right is unnecessary for the job and should be removed. D has already left the company, so the account itself should be disabled and removed along with the right. A and C are HR department staff who handle the payroll database and have used it recently, so their rights should remain. Removing a right that is still needed just because a last login is old, or the reverse, leaving a departed employee's right in place, are both wrong judgments.
Q33 | Privileged accounts
Which of the following is the most appropriate way to manage a system's privileged account (an account with administrator rights)?
For efficiency, have all administrators share a single account, including its password
Require an application and approval for each use, and keep a record of checkout, return, and the operations performed
To save the effort of switching, log in with the privileged account even for ordinary daily work
Since only trusted staff use the privileged account, skip capturing operation logs
AnswerB. Require an application and approval for each use, and keep a record of checkout, return, and the operations performed
Because a privileged account has a wide-reaching impact, requiring an application and approval for each use, recording checkout and return, and capturing operation logs make it possible to trace who did what. Sharing the account and its password makes it impossible to identify the individual. Routine use for ordinary work widens the potential damage from a mistake or malware infection. Skipping logs because of trust means the facts cannot be confirmed if an incident occurs.
Q34 | Log operations
Which of the following is the most appropriate way to capture and retain access logs?
Aggregate them onto a separate log server, store them in a form that cannot be altered, and review the content periodically
Leave the time setting on each device to the judgment of whoever is in charge of that device
Let an administrator freely edit the captured logs whenever needed
Deliberately exclude records of failed login attempts to save on storage capacity
AnswerA. Aggregate them onto a separate log server, store them in a form that cannot be altered, and review the content periodically
A log is a trail used to confirm the facts, so it only serves deterrence and early detection once it is preserved in a form that cannot be altered or deleted and is reviewed periodically. Being editable destroys its value as a trail. A failed login is itself a sign of unauthorized access and must always be kept. If the clocks differ, logs from multiple devices cannot be cross-referenced, so time synchronization is necessary.
Q35 | Applying patches
Regarding how to prioritize applying patches across a large number of systems, which of the following is most appropriate?
Skip verifying operation in a test environment, and apply the patch to every system at once the same day it is published
Prioritize a vulnerability where exploitation has actually been confirmed and which affects a server exposed to the internet
Apply them in order starting from the system with the fewest users, leaving the most-used system for last
Mechanically apply them in order from the oldest publication date
AnswerB. Prioritize a vulnerability where exploitation has actually been confirmed and which affects a server exposed to the internet
Priority should be judged from whether exploitation has occurred, whether the system is exposed externally, severity, and the importance of the affected asset, so a vulnerability with observed attacks that affects an externally exposed server takes top priority. Ordering by publication date or number of users does not correspond to the level of danger. Applying everything at once without verification risks halting operations; when a patch cannot be applied, an alternative such as restricting traffic should be used instead.
Q36 | PPAP
Which of the following is the most appropriate problem with the practice (sometimes called PPAP) of attaching a password-protected ZIP file to an email and then sending the password to the same recipient in a separate email immediately after?
The password for a ZIP file is limited to 8 characters, making it impossible to set a sufficiently strong password
The recipient must separately purchase and install paid, dedicated software to extract the file
Because a ZIP file has a low compression ratio, the volume of email traffic increases considerably, raising the load on the internal mail server
Because the file and the password travel over the same channel, it is weak against eavesdropping or misdirection, and encryption prevents the receiving side from running a virus scan
AnswerD. Because the file and the password travel over the same channel, it is weak against eavesdropping or misdirection, and encryption prevents the receiving side from running a virus scan
Because both are sent over the same email channel, intercepting that channel exposes both, and sending it to the wrong recipient delivers both the encrypted file and its password to the same wrong party. Furthermore, an encrypted ZIP cannot have its contents inspected by a gateway or antivirus software, letting malware slip through. The compression ratio, the need for dedicated software, and a character-length limit are not the essential problem with this practice.
Q37 | Preventing misdirected email
Which of the following is the most appropriate countermeasure against an information leak from a misdirected email?
When sending to many recipients at once, list them all in the To field so everyone can see who else received it
Use a mechanism that holds a message for a few minutes before sending, and use that time to check the recipients and attachments
Leave the recipient entry to the autocomplete feature and skip checking before sending, to send it quickly
If a misdirected email is noticed, wait and see for a while without telling the recipient
AnswerB. Use a mechanism that holds a message for a few minutes before sending, and use that time to check the recipients and attachments
Holding a message for a few minutes is effective because it can be recalled once the mistake is noticed, and it should be combined with checking the recipients and attachments. Listing many recipients who do not know each other in the To field exposes everyone's address to everyone else, so BCC should be used instead. Relying on autocomplete invites mixing up similar addresses. Leaving a noticed misdirected email unaddressed only lets the damage spread.
Q38 | Cloud settings
Regarding managing the sharing scope of cloud storage used for business, which of the following is most appropriate?
Keep using the default sharing scope and review it only if a problem occurs
Check the sharing scope when a file is created, and periodically take inventory to revoke unnecessary exposure
Since internal regulations prohibit sharing outside the company, there is no particular need to check the sharing settings
Setting it to “anyone with the link” is safe, because someone who does not know the URL cannot view it
AnswerB. Check the sharing scope when a file is created, and periodically take inventory to revoke unnecessary exposure
Unintended exposure from a cloud misconfiguration is a leading cause of leaks, so a check at creation time needs to be paired with a periodic inventory. Keeping the default setting, or reviewing only after a problem occurs, is too late. Sharing with anyone who has the link can be viewed by anyone the URL is forwarded to, and the mere existence of a regulation does not guarantee the actual settings are correct.
Q39 | Categorizing measures
The following (a) through (c) were carried out as information-leak countermeasures. Which combination correctly classifies each as human, technical, or physical? (a) A regulation banning business use of personal USB drives was established and communicated to all employees. (b) The USB ports on business PCs were disabled through configuration. (c) Important documents were decided to be stored in a lockable cabinet.
(a) Physical, (b) Technical, (c) Human
(a) Human, (b) Physical, (c) Technical
(a) Human, (b) Technical, (c) Physical
(a) Technical, (b) Human, (c) Physical
AnswerC. (a) Human, (b) Technical, (c) Physical
(a) is a human measure that governs people's behavior through a regulation and its communication, (b) is a technical measure that restricts through a device or software function, namely a device's configuration, and (c) is a physical measure that locks away a physical item, the documents. Note that even measures aimed at the same goal, preventing USB drives from being taken out, are classified differently depending on whether they are enforced through a regulation or through a configuration setting.
Q40 | Passwords
Which of the following is the most appropriate way for a user to manage their own password?
Since mixing in symbols is enough to be safe, a short password under 8 characters that is easy to remember can be set
Use a different, long passphrase for each service, and if they cannot all be remembered, use an approved password manager
So it is not forgotten, reuse the same password across every service and never change it
So it is not forgotten, write it on a sticky note and put it at the edge of the screen
AnswerB. Use a different, long passphrase for each service, and if they cannot all be remembered, use an approved password manager
Length has the biggest effect on a password's strength, and not reusing it prevents a leak in one place from spreading to other services. When too many to manage, an approved password manager should be used. Reuse lets damage from a credential-stuffing attack spread all at once. Mixing in symbols is not enough to make up for being short, and displaying it on a sticky note lets a third party see it easily.
Q41 | Phishing
An email arrives claiming to be from a bank, stating, “Your account will be suspended. Please check the link below immediately.” Which of the following is the most appropriate response for the user?
Open the link and judge based on whether the design of the displayed page looks the same as the real one
Since the Japanese wording is natural and error-free, judge it to be genuine and enter the ID and password on the linked page
Without using the link in the email, check the situation through the bookmark or official app already in regular use
Contact the phone number written in the email and follow that person's instructions
AnswerC. Without using the link in the email, check the situation through the bookmark or official app already in regular use
A phishing site is made to look just like the real one, so appearance or how natural the wording is cannot be used to judge it. Since a link or contact information in the email may have been prepared by the attacker, it should not be used; the correct approach is to check through a channel the person already uses regularly. Wording that rushes the reader is a classic technique for clouding judgment, and entering an ID must always be avoided.
Q42 | Public Wi-Fi
Regarding precautions when using public Wi-Fi for business while out of the office, which of the following is most appropriate?
It can also be used to log into internal company systems, as long as the session is kept short
Even unencrypted public Wi-Fi is safe if the SSID matches the name of the shop
Go through a VPN the company has provided, or use a smartphone's tethering
AnswerD. Go through a VPN the company has provided, or use a smartphone's tethering
Public Wi-Fi may not have its traffic encrypted, and fake access points made to resemble legitimate ones also exist, so protecting the traffic with a VPN or using tethering is the safe approach. An SSID name can be set to anything, so it is no proof of authenticity. Automatic connection increases the risk of connecting to a fake access point without meaning to, and the length of the session does not change the level of danger.
Q43 | Managing smartphones
Which of the following is the most appropriate way to manage a smartphone used for business?
A calculator app requests permission to access contacts, and it is granted because it is convenient
An app distributed somewhere other than the official app store is installed and used because users have given it good reviews
Since an OS update could make behavior unstable, postpone applying it for now and continue business on the version currently in use
Set a screen lock, install apps only from the official store, and check whether a requested permission is reasonable in light of the app's function
AnswerD. Set a screen lock, install apps only from the official store, and check whether a requested permission is reasonable in light of the app's function
The basics are a screen lock in case of loss, installing only from an official store whose source can be verified, and not granting a permission out of proportion to the app's function. A calculator requesting contact access is unnatural and suggests data is being taken out. An app from outside the official store cannot have its source or safety verified. Postponing updates means continuing to be exposed to attacks that target already-known vulnerabilities.
Q44 | Balancing with efficiency
Voices from the field say, “The information security regulations are too strict and work cannot get done.” Which of the following is the most appropriate response for the information security leader?
Leave it to the field's own judgment whether to apply the regulation, allowing it to be skipped whenever it feels unworkable
Decide not to punish violations, while leaving the regulation's current content unchanged
Listen to how work actually happens, consider whether the procedure can be simplified while keeping the level of risk unchanged, and revise the regulation if needed
Since regulations exist to be followed, ignore the feedback from the field and instruct that they be enforced strictly
AnswerC. Listen to how work actually happens, consider whether the procedure can be simplified while keeping the level of risk unchanged, and revise the regulation if needed
A regulation no one can follow gets ignored in the field, opening workarounds such as using a personal cloud service or sharing passwords, which is actually more dangerous. So the right approach is to listen to how things actually work, make the procedure easier to follow without lowering the level of risk, and revise the regulation itself if needed. Simply instructing strict enforcement does not change the underlying reality, and leaving application to the field's discretion or letting penalties go unenforced reduces the regulation to a dead letter.
Q45 | Measures for working from home
For working from home, the following (a) through (c) were carried out. Which combination correctly classifies them as human, technical, or physical measures? (a) The administrator password on the home Wi-Fi router was changed from its default value. (b) A privacy filter was applied to the display. (c) A regulation banning family members from using the business PC was established and communicated to all employees.
(a) Technical, (b) Human, (c) Physical
(a) Physical, (b) Technical, (c) Human
(a) Human, (b) Physical, (c) Technical
(a) Technical, (b) Physical, (c) Human
AnswerD. (a) Technical, (b) Physical, (c) Human
(a) is a technical measure that prevents unauthorized operation by changing a device's configuration, (b) is a physical measure using a device that physically blocks the view, and (c) is a human measure that governs people's behavior through a regulation and its communication. Combinations that treat (b) as human or technical, or (a) as human or physical, do not match the means each measure uses.
Practice: answer the questions on this page
This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.
* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.
This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original