Which of the following falls under an act of unauthorized access prohibited by the Act on Prohibition of Unauthorized Computer Access?
Taking a company's manufacturing know-how, managed as a secret, without permission and disclosing it to a competitor.
Directly operating a PC that is not connected to any network and logging in with a coworker's ID and password.
Entering someone else's ID and password without their permission and logging into a company server over the internet from outside the company.
Creating a virus that causes a computer to act contrary to the user's intent, and keeping it stored on one's own PC without distributing it.
AnswerC. Entering someone else's ID and password without their permission and logging into a company server over the internet from outside the company.
An act of unauthorized access is entering someone else's identification code without permission over a telecommunications line, among other means, to make a computer usable, and the first choice fits this. Creating and storing a virus is an offense under the Penal Code concerning unauthorized command electromagnetic records, and taking and disclosing a trade secret is a matter for the Unfair Competition Prevention Act. Direct operation without going through a network does not fall under an act of unauthorized access under this law.
Q2 | Facilitating unauthorized access
Asked by a coworker who says they are busy, a person tells that coworker their own business system ID and password without a legitimate reason. Which combination of a law and provision does this act raise a problem under?
The act of facilitating unauthorized access prohibited by the Act on Prohibition of Unauthorized Computer Access
The Penal Code's offense concerning unauthorized command electromagnetic records (the so-called virus offense)
The unlawful acquisition and disclosure of trade secrets prohibited by the Unfair Competition Prevention Act
Infringement of the reproduction right and the right of public transmission under the Copyright Act
AnswerA. The act of facilitating unauthorized access prohibited by the Act on Prohibition of Unauthorized Computer Access
Providing someone else's identification code to a third party without a legitimate reason related to business or otherwise falls under the facilitating act prohibited by the Act on Prohibition of Unauthorized Computer Access, and it can apply regardless of whether the other party actually logged in. An offense concerning a virus is a Penal Code matter, disclosing a trade secret is a matter for the Unfair Competition Prevention Act, and reproducing a copyrighted work is a matter for the Copyright Act; none of these corresponds to the act of telling someone an ID and password.
Q3 | A requirement for the law to apply
Someone directly operated a standalone PC not connected to the internal network, right there in person, and logged in by entering a coworker's ID and password. Which of the following is the appropriate reason this act does not fall under an act of unauthorized access under the Act on Prohibition of Unauthorized Computer Access?
Because the act was not carried out over a telecommunications line
Because that PC had no access control function configured on it
Because the person had been told the ID and password by the coworker
Because no file was viewed or taken out
AnswerA. Because the act was not carried out over a telecommunications line
An act of unauthorized access requires being carried out “over a telecommunications line,” so direct operation without going through a network falls outside its scope. An act of unauthorized access is established the moment the computer is made usable, so whether anything was viewed is not a requirement; an access control function is assumed to be configured in this case, and whether the credentials were told to the person does not affect whether the act qualifies either. That said, the possibility of being held liable for violating internal regulations or another offense remains separately.
Q4 | The virus offense
Which law can apply to someone who created a program that makes a computer act contrary to the user's intent, and kept it stored on their own PC without yet distributing it to anyone?
The Unfair Competition Prevention Act
The Act on Prohibition of Unauthorized Computer Access
The Basic Act on Cybersecurity
The Penal Code's offense concerning unauthorized command electromagnetic records
AnswerD. The Penal Code's offense concerning unauthorized command electromagnetic records
The Penal Code's offense concerning unauthorized command electromagnetic records (the so-called virus offense) makes acquiring and storing such a program punishable, in addition to creating, providing, and putting it into use, so it can apply even without distribution. The Act on Prohibition of Unauthorized Computer Access covers things like impersonation over a network, the Unfair Competition Prevention Act protects things like trade secrets, and the Basic Act on Cybersecurity sets out the national framework and responsibilities and provides no basis for a penalty.
Q5 | Computer fraud
Which of the following offenses can most appropriately apply to entering someone else's obtained credit card number into a shopping site and having merchandise purchased and delivered to oneself?
Unlawful acquisition of limited-provision data under the Unfair Competition Prevention Act
Infringement of the right of public transmission under the Copyright Act
The Penal Code's offense of fraud by means of an electronic computer
The Penal Code's offense of obstructing business by damaging a computer, and the like
AnswerC. The Penal Code's offense of fraud by means of an electronic computer
Giving a computer false information or an unauthorized command to create a false electromagnetic record concerning a property right and thereby obtain an unlawful gain falls under the offense of fraud by means of an electronic computer. The offense of obstructing business by damaging a computer, and the like, is an offense that obstructs business by damaging a computer or data; limited-provision data is a category protected by the Unfair Competition Prevention Act; and the right of public transmission is a right under the Copyright Act; none of these corresponds to this case.
Q6 | Business obstruction
Which of the following offenses can most appropriately apply to sending a flood of requests to another company's web server, making it unable to respond, and stopping that company's online sales business?
The Penal Code's offense of obstructing business by damaging a computer, and the like
The Penal Code's offense concerning unauthorized command electromagnetic records
Unlawful acquisition of a trade secret under the Unfair Competition Prevention Act
An act of unauthorized access under the Act on Prohibition of Unauthorized Computer Access
AnswerA. The Penal Code's offense of obstructing business by damaging a computer, and the like
Giving an unauthorized command, among other means, to a computer used for business, preventing it from operating as intended and thereby obstructing the business, falls under the offense of obstructing business by damaging a computer, and the like. No login using someone else's identification code occurred, so it is not an act of unauthorized access, and no virus was created, so it is not the offense concerning unauthorized command electromagnetic records either. No trade secret was acquired.
Q7 | The Basic Act
Which of the following correctly describes the content of the Basic Act on Cybersecurity?
It sets out the responsibilities of the national and local governments and the efforts expected of critical infrastructure operators, and establishes a Cybersecurity Strategic Headquarters within the Cabinet.
It contains provisions making it a punishable crime to log into a computer using someone else's ID and password without permission.
It provides that, when providing personal data to a third party, the individual's prior consent must in principle be obtained.
It defines the three requirements — being managed as a secret, usefulness, and non-public knowledge — for something to be legally protected as a trade secret.
AnswerA. It sets out the responsibilities of the national and local governments and the efforts expected of critical infrastructure operators, and establishes a Cybersecurity Strategic Headquarters within the Cabinet.
The Basic Act on Cybersecurity sets out the basic principles of national policy, the responsibilities of the national and local governments, and the effort expected of critical infrastructure operators and others to take voluntary measures, and it is a framework law that establishes a Cybersecurity Strategic Headquarters within the Cabinet; it contains no provisions punishing individual offenses. Punishing impersonation is a matter for the Act on Prohibition of Unauthorized Computer Access, the three requirements for a trade secret are a matter for the Unfair Competition Prevention Act, and the restriction on third-party provision is content found in the Act on the Protection of Personal Information.
Q8 | Trade secrets
Which combination correctly lists the three requirements needed for something to be protected as a trade secret under the Unfair Competition Prevention Act?
Accuracy, comprehensiveness, and being up to date
Confidentiality, integrity, and availability
Being limited-provision, being accumulated in a substantial quantity, and being managed electromagnetically
Being managed as a secret, usefulness, and non-public knowledge
AnswerD. Being managed as a secret, usefulness, and non-public knowledge
A trade secret must satisfy all three requirements: being managed as a secret (secret management), being technical or business information useful for business activity (usefulness), and not being publicly known (non-public knowledge). The first choice lists the requirements for limited-provision data, the second is the three elements of information security, and the third is a general perspective on the quality of information; none of these is the requirement set for a trade secret.
Q9 | Secret management
A departed employee copied and took out a customer list that had been kept in a shared folder viewable by anyone in the company, with no marking such as “internal use only.” Which of the following is the main reason it would be difficult to claim this as an infringement of a trade secret under the Unfair Competition Prevention Act?
The person who took it out had held legitimate access rights while employed
It would be hard to recognize that it was managed as a secret, so it lacks the requirement of secret management
The customer list is already publicly known information, so it lacks the requirement of non-public knowledge
A customer list cannot be said to be information useful for business activity, so it lacks the requirement of usefulness
AnswerB. It would be hard to recognize that it was managed as a secret, so it lacks the requirement of secret management
With no access restriction and no marking indicating it was a secret, it would be hard to recognize that the company had managed it as a secret, so it lacks secret management and is not protected as a trade secret. A customer list ordinarily satisfies usefulness, and as long as it was not disclosed outside the company, it also satisfies non-public knowledge. Whether the person held access rights while employed is not one of the requirements for something to qualify as a trade secret. Routine access restriction and marking are the precondition for legal protection.
Q10 | Limited-provision data
A company accumulates and manages, electromagnetically, a large volume of weather observation data that it provides to member companies for a fee, but it does not manage this data as a secret. Under which category of the Unfair Competition Prevention Act is this data protected?
A trade secret under the Unfair Competition Prevention Act
Special-care-required personal information under the Act on the Protection of Personal Information
Limited-provision data under the Unfair Competition Prevention Act
Anonymized information under the Act on the Protection of Personal Information
AnswerC. Limited-provision data under the Unfair Competition Prevention Act
Technical or business information that is accumulated and managed in a substantial quantity by electromagnetic means, and provided to specific parties as a business, is protected as limited-provision data under the Unfair Competition Prevention Act. Since it is not managed as a secret, it does not fall under a trade secret under the same act. Special-care-required personal information and anonymized information are both concepts under the Act on the Protection of Personal Information, a different law covering a different subject.
Q11 | Personal information
Which of the following falls under personal information as defined by the Act on the Protection of Personal Information?
A statistic of visitor counts aggregated so that no specific individual can be identified
The name and last known address of someone who has already died
The driver's license number of a living individual
The head office address and main phone number of a corporation
AnswerC. The driver's license number of a living individual
A driver's license number is an individual identification code and constitutes personal information on its own. Personal information concerns information about a living individual, so information about someone who has died is not included, and information about a corporation itself is also not personal information. A statistical value aggregated so no specific individual can be identified likewise does not fall under personal information.
Q12 | A disclosure request
Which of the following is the subject an individual can request a personal information handling business operator to disclose, correct the content of, or stop using?
Pseudonymized information
Anonymized information
A personal information database, etc.
Retained personal data
AnswerD. Retained personal data
What an individual can request disclosure, correction, or a stop of use for is retained personal data, meaning personal data over which the business operator has the authority to respond to such requests. “A personal information database, etc.” refers to the systematic structure that makes personal information searchable, not something positioned as the object of a request. Both anonymized information and pseudonymized information are explicitly outside the scope of a request from the individual.
Q13 | Special-care-required information
Which of the following falls under special-care-required personal information under the Act on the Protection of Personal Information?
An employee's company email address
Information about an employee's nationality
An employee's annual income for the past year
The results of an employee's health checkup
AnswerD. The results of an employee's health checkup
The results of a health checkup are designated as special-care-required personal information by cabinet order. Special-care-required personal information covers things like race, creed, social status, medical history, criminal record, and the fact of having suffered harm from a crime; an email address or annual income is not included. Nationality by itself does not amount to race either and is not treated as special-care-required. Because this is easy to confuse, it helps to remember that the category is an exhaustive list.
Q14 | Handling special-care-required information
Regarding the handling of special-care-required personal information, which of the following is appropriate?
Even when passing it to a contractor within the scope necessary to achieve the purpose of use, the individual's prior consent is always required.
Once processed into pseudonymized information, it can be provided to a third party without the individual's consent.
Obtaining it requires the individual's prior consent in principle, and third-party provision through opt-out is not permitted.
If it is information the individual has published themselves, there is no longer any need to treat it as special-care-required personal information once obtained.
AnswerC. Obtaining it requires the individual's prior consent in principle, and third-party provision through opt-out is not permitted.
Obtaining special-care-required personal information requires the individual's consent in principle, and it is excluded from third-party provision via opt-out. It remains special-care-required personal information even if the individual has published it themselves. Pseudonymized information cannot in principle be provided to a third party, and processing it does not mean it can be freely provided. Providing data to a contractor does not count as third-party provision, so the individual's consent is not required for that.
Q15 | Opt-out
Which of the following is required to carry out third-party provision of personal data through opt-out?
Reporting the content of the personal data provided and the name and address of the recipient to the Personal Information Protection Commission in writing every single time it is provided
Processing the personal data to be provided into anonymized information that cannot identify a specific individual and cannot be restored
Notifying the individual of the prescribed matters, or placing them where the individual can easily learn of them, and filing a notification with the Personal Information Protection Commission
Obtaining individual consent from each person in advance for every destination the data is provided to
AnswerC. Notifying the individual of the prescribed matters, or placing them where the individual can easily learn of them, and filing a notification with the Personal Information Protection Commission
Opt-out is a mechanism that allows third-party provision without the individual's consent, provided that provision will be stopped upon the individual's request, the prescribed matters are notified to the individual or placed where they can easily learn of them, and a notification is filed with the Personal Information Protection Commission. If individual consent is being obtained, there is no need to use opt-out in the first place, and processing into anonymized information is not a condition either. There is also no requirement to report every single instance of provision.
Q16 | Joint use
Which of the following correctly describes the difference between joint use of personal data and third-party provision through opt-out?
Joint use requires no notification to the Personal Information Protection Commission, while opt-out requires such a notification.
Joint use cannot cover special-care-required personal information, while opt-out can.
Joint use falls under third-party provision, while opt-out is excluded from third-party provision.
Joint use requires no notification to the individual at all, while opt-out requires notifying the individual.
AnswerA. Joint use requires no notification to the Personal Information Protection Commission, while opt-out requires such a notification.
For joint use, it is enough to notify the individual in advance, or place where they can easily learn of, the fact of joint use, the items involved, the scope of joint users, the purpose of use, and the name of the party responsible for management; no notification to the Commission is required. Opt-out, on the other hand, requires a notification and cannot cover special-care-required personal information. The other party in joint use is treated as not being a third party, and it is opt-out that is a form of third-party provision, so the third choice also has it backward.
Q17 | Pseudonymized versus anonymized
Which of the following correctly describes the difference between pseudonymized information and anonymized information?
Both require notifying the recipient of the individual's contact information when providing them to a third party.
Anonymized information can be provided to a third party without the individual's consent, while pseudonymized information cannot be provided to a third party except for outsourcing, business succession, or joint use.
Both can be provided to a third party with the individual's consent and cannot be provided without it.
Pseudonymized information can be provided to a third party without the individual's consent, while anonymized information cannot be provided to a third party even with the individual's consent.
AnswerB. Anonymized information can be provided to a third party without the individual's consent, while pseudonymized information cannot be provided to a third party except for outsourcing, business succession, or joint use.
Anonymized information is processed so that no individual can be identified and it cannot be restored, and it can be provided to a third party without the individual's consent once the prescribed publication and disclosure are made. Pseudonymized information still leaves open the possibility of identification when cross-referenced with other information, so third-party provision is not permitted except for outsourcing, business succession, or joint use. The two run in opposite directions from what the second choice states. Cross-referencing for the purpose of identifying an individual is prohibited for both, and neither carries an obligation to notify the recipient of the individual's contact information.
Q18 | In-house analysis
A company wants its internal marketing department alone to analyze its member data. After deleting names and processing the data so that individuals cannot be identified unless cross-referenced with other information, and then using it that way, which of the following correctly describes the status and restrictions of the processed information?
It is pseudonymized information, and because it stops being personal information once processed, it becomes entirely outside the scope of the Act on the Protection of Personal Information.
It is pseudonymized information; it must not be cross-referenced with other information for the purpose of identifying an individual, and in principle it cannot be provided to a third party either.
It is anonymized information, and the processed information can be used to contact the individuals.
It is anonymized information, and requests from the individual for disclosure or a stop of use must be honored.
AnswerB. It is pseudonymized information; it must not be cross-referenced with other information for the purpose of identifying an individual, and in principle it cannot be provided to a third party either.
Information processed so that an individual cannot be identified unless cross-referenced with other information is pseudonymized information, which suits in-house analysis. Cross-referencing for the purpose of identifying an individual and contacting the individual are both prohibited, and third-party provision is also not permitted except for outsourcing, business succession, or joint use. Information processed to the point where it cannot be restored is anonymized information, which can be provided to a third party. Pseudonymized information also remains subject to the Act, and it is outside the scope of requests such as disclosure.
Q19 | Third-party provision
Which of the following does not violate the restriction on third-party provision even though personal data is passed to another business operator without the individual's consent?
Providing it after confirming that the recipient is a business operator that has made the necessary filing with the Personal Information Protection Commission
Providing it to another company in the same corporate group, on the grounds that they belong to the same group
Providing it to a contractor to whom work is outsourced, within the scope necessary to achieve the purpose of use, for that work
Providing it to a company whose business card was exchanged at a trade show, for the purpose of later sales activity
AnswerC. Providing it to a contractor to whom work is outsourced, within the scope necessary to achieve the purpose of use, for that work
Provision to a contractor within the scope necessary to achieve the purpose of use, business succession, and provision accompanying joint use do not fall under third-party provision, so the individual's consent is not required. That said, the outsourcing party retains a duty to supervise the contractor. Even a company in the same corporate group is a separate legal entity and counts as a third party, and neither exchanging business cards nor whether the recipient has filed a notification is a reason it is acceptable to provide data without consent.
Q20 | Reporting a leak
Regarding when a report to the Personal Information Protection Commission and notification to the individuals become mandatory upon a personal data leak, which of the following is appropriate?
Only when an inquiry has actually been received from an affected individual
Cases such as where special-care-required personal information is involved, where there is a risk of wrongful intent, or where the number of affected individuals exceeds 1,000
Only the contractor needs to report a leak that occurred at the contractor, and the outsourcing party bears no obligation to report to the Personal Information Protection Commission
Every single case of a leak, loss, or damage that occurs at the business operator, regardless of the number of records or the content leaked
AnswerB. Cases such as where special-care-required personal information is involved, where there is a risk of wrongful intent, or where the number of affected individuals exceeds 1,000
Reporting and notifying the individuals become mandatory in cases such as where special-care-required personal information is involved, where there is a risk of financial harm, where there is a risk of wrongful intent, or where the number of affected individuals exceeds 1,000. Not every case is covered regardless of number, and whether an inquiry was received from an individual is not a requirement either. Even for a leak occurring at a contractor, the outsourcing party is not relieved of responsibility.
Q21 | Which law applies
A customer list entrusted by a business partner was used without permission for the company's own sales activity, a purpose different from what the contract specified. Which law is most directly implicated?
The Act on the Protection of Personal Information
The Penal Code's offense concerning unauthorized command electromagnetic records
The Copyright Act
The Act on Prohibition of Unauthorized Computer Access
AnswerA. The Act on the Protection of Personal Information
Personal information may only be handled within the specified purpose of use, and using it for a purpose other than that without the individual's consent violates the Act on the Protection of Personal Information. The Copyright Act covers things like reproducing a copyrighted work, the Act on Prohibition of Unauthorized Computer Access covers things like impersonation over a network, and the offense concerning unauthorized command electromagnetic records covers things like creating a virus; none of these directly governs using entrusted data for an unauthorized purpose.
Q22 | The Information Distribution Platform Act
What is the name of the law that came into force on April 1, 2025 (Reiwa 7), the result of a revision to the former Provider Liability Limitation Act?
The Act on Improving Transparency of Specified Digital Platforms
The Act on the Prevention of Internet Rights Infringement
The Telecommunications Carrier Information Disclosure Act
The Act on Countermeasures against Information Distribution Platforms
AnswerD. The Act on Countermeasures against Information Distribution Platforms
Under a 2024 revision, the Provider Liability Limitation Act was renamed the Act on Countermeasures against Information Distribution Platforms, taking effect on April 1, 2025. It carries forward the existing mechanisms limiting liability for damages and disclosing sender information, while adding obligations for large-scale platform operators. The other three are not names created by this revision, and the syllabus also treats this as the replacement for the Provider Liability Limitation Act.
Q23 | Large-scale operators
Which of the following is an obligation the Act on Countermeasures against Information Distribution Platforms imposes on a large-scale specified telecommunications service provider?
Publishing the sender information of a post suspected of infringing rights, even without a request from the victim
Publishing the method for accepting takedown requests, investigating a request and notifying the result within a set period, and establishing and publishing the criteria for takedown
Following an individual takedown order issued by an administrative agency for a post about which a rights-infringement claim has been made, and immediately deleting that post
Reviewing the content of every single posted piece of information before publication and refraining from posting anything with a risk of infringing rights
AnswerB. Publishing the method for accepting takedown requests, investigating a request and notifying the result within a set period, and establishing and publishing the criteria for takedown
This law imposes obligations on large-scale platform operators such as publishing the method for accepting requests, appointing a specialist to investigate infringement claims, notifying the investigation result within a set period, establishing and publishing takedown criteria, and publishing their response status once a year, aimed at making the response faster and more transparent. It is not a system that requires pre-screening every post, nor a mechanism where an administrative agency orders a takedown. Sender information is disclosed through a procedure based on the individual's own request, not something published proactively.
Q24 | Secrecy of communications
Which law provides that a telecommunications carrier must not disclose the secrecy of another person's communications that it comes to know in the course of its handling?
The Act on Prohibition of Unauthorized Computer Access
The Act on the Protection of Personal Information
The Penal Code's offense of unlawfully creating a private electromagnetic record
The Telecommunications Business Act
AnswerD. The Telecommunications Business Act
Protection of the secrecy of communications and the ban on censorship are set out in the Telecommunications Business Act, and what is protected extends not only to the content of a communication but also to elements such as who communicated with whom and when. The Act on the Protection of Personal Information governs the handling of personal information, and the Act on Prohibition of Unauthorized Computer Access governs things like impersonation over a network; the offense of unlawfully creating a private electromagnetic record is a Penal Code offense punishing the unlawful creation of an electromagnetic record. None of these is the basis for the secrecy of communications.
Q25 | Advertising email
Which law establishes the principle that email sent for advertising or promotional purposes may only be sent to those who have given prior consent?
The Act on the Protection of Personal Information
The Act on Regulation of Transmission of Specified Electronic Mail
The Act on Prohibition of Unauthorized Computer Access
The Copyright Act
AnswerB. The Act on Regulation of Transmission of Specified Electronic Mail
The opt-in regulation for advertising and promotional email is set out in the Act on Regulation of Transmission of Specified Electronic Mail. The Act on the Protection of Personal Information governs situations where an email address is treated as personal data and does not directly regulate whether sending is permitted, the Act on Prohibition of Unauthorized Computer Access covers things like impersonation over a network, and the Copyright Act covers the use of copyrighted works; none of these is the basis for regulating the sending of advertising email.
Q26 | What an email must show
Under the Act on Regulation of Transmission of Specified Electronic Mail, which of the following must a sender do when sending advertising and promotional email?
Give prior notice to each individual recipient at least three days before sending the advertising email.
Display the sender's name or designation, along with contact information for receiving a notice that the recipient does not wish to receive further mail.
State, at the start of the body, the filing number received when a notification was made in advance to the Personal Information Protection Commission.
Change the sending email address every time, and never reuse the same address.
AnswerB. Display the sender's name or designation, along with contact information for receiving a notice that the recipient does not wish to receive further mail.
The Act on Regulation of Transmission of Specified Electronic Mail requires displaying the sender's name or designation along with an email address or URL for receiving an opt-out notice, and it bans sending with falsified sender information. Keeping a record that consent was obtained is also required. There is no requirement for prior notice or for changing the sending address; falsifying the address is in fact prohibited. There is also no such system of stating a filing number from the Commission.
Q27 | The Electronic Signatures Act
Which of the following correctly describes the content of the Act on Electronic Signatures and Certification Business?
For an electromagnetic record with an electronic signature attached, not only that the creator is genuine but also the truthfulness of its content is legally guaranteed.
An electromagnetic record bearing an electronic signature that satisfies certain requirements which only the person themselves could have made is presumed to have been established genuinely.
A certificate used for an electronic signature can only be one issued directly by the government.
To use an electronic signature, the other party's written consent must be obtained in advance.
AnswerB. An electromagnetic record bearing an electronic signature that satisfies certain requirements which only the person themselves could have made is presumed to have been established genuinely.
The Act on Electronic Signatures and Certification Business provides that an electromagnetic record bearing an electronic signature satisfying certain requirements which only the person themselves could have made is presumed to have been established genuinely, giving an electronic document the same evidentiary weight as a paper document bearing a seal. What is presumed is that the document was made by the person's own intent, not the truthfulness of its content. No written consent is needed to use it, and an accredited private certification business can also issue the certificates.
Q28 | Copying software
Commercially sold software was installed and used on company PCs without authorization, exceeding the number of licenses purchased. Which law is most directly implicated?
The Unfair Competition Prevention Act
The Act on the Protection of Personal Information
The Act on Prohibition of Unauthorized Computer Access
The Copyright Act
AnswerD. The Copyright Act
A program is a copyrighted work, and reproducing and using it beyond the permitted scope infringes the reproduction right, among other rights, under the Copyright Act. The Unfair Competition Prevention Act protects things like trade secrets and limited-provision data, the Act on Prohibition of Unauthorized Computer Access covers things like impersonation over a network, and the Act on the Protection of Personal Information covers the handling of personal information; none of these directly governs installation exceeding the license count.
Q29 | What falls outside protection
Which of the following is not a subject of protection under the Copyright Act?
A photograph taken by an employee for publication in the company newsletter
The underlying algorithm of a program, or a communication protocol itself
A macro program that runs on top of spreadsheet software, written by an employee for business use
An internal database whose selection or systematic arrangement of information is recognized as creative
AnswerB. The underlying algorithm of a program, or a communication protocol itself
What the Copyright Act protects is the creative expression of thoughts or feelings; the algorithm (method of solving a problem) behind it, the programming language, and a communication protocol are not protected. A program, including a macro, is protected as a copyrighted work, and a database is also protected if there is creativity in the selection or systematic arrangement of the information. A photograph is a copyrighted work too. It helps to remember that an idea is not protected — only its expression is.
Q30 | AI training
A company wants to collect a large volume of text published on the web to develop generative AI in-house, analyzing it as training data. Which of the following is the correct way of thinking under copyright law?
Use for information analysis that does not aim to enjoy the thoughts or feelings expressed in a copyrighted work may be carried out without permission, to the extent recognized as necessary, except where it would unreasonably harm the copyright holder's interests.
As long as it was used for training, no copyright infringement occurs even if the generated text resembles an existing copyrighted work and is found to be based on it.
Information published on the internet is not subject to the Copyright Act even if it is a copyrighted work, so it can be freely collected, analyzed, and its output freely published.
When used as training data, even use for information analysis not aimed at enjoying thoughts or feelings requires individual permission from the copyright holder for every collected work, with no use permitted otherwise.
AnswerA. Use for information analysis that does not aim to enjoy the thoughts or feelings expressed in a copyrighted work may be carried out without permission, to the extent recognized as necessary, except where it would unreasonably harm the copyright holder's interests.
Under Article 30-4 of the Copyright Act, use for information analysis not aimed at enjoying the thoughts or feelings expressed can be carried out without permission, to the extent recognized as necessary, except where it would unreasonably harm the copyright holder's interests. A copyrighted work remains protected even if published, and individual permission is not always required either. Furthermore, if the generated output resembles an existing copyrighted work and is found to be based on it, infringement can occur at the stage of generating or using that output.
Q31 | No permission needed
Which of the following is a use recognized under the Copyright Act without needing the copyright holder's permission?
Downloading and saving a paid manga while knowing it was uploaded illegally.
Quoting part of a published paper, citing the source, clearly distinguishing it from one's own writing, and keeping one's own writing as the main body with the quotation as a subordinate part.
Copying the necessary portion of a commercially published book, one copy per participant, to distribute as material for in-house training, with each person keeping their own copy.
Bypassing copy protection to duplicate a commercially sold DVD for personal viewing at home.
AnswerB. Quoting part of a published paper, citing the source, clearly distinguishing it from one's own writing, and keeping one's own writing as the main body with the quotation as a subordinate part.
A quotation may be made without permission if it satisfies being from a published work, conforming to fair practice, being within a justifiable scope, having the quoted part clearly distinguished with one's own writing as the main body and the quotation as subordinate, and citing the source. Copying enough for the number of participants in in-house training exceeds the scope of private use, and downloading while knowing it was illegally distributed, or copying by bypassing copy protection, are both excluded from the exception for reproduction for private use.
Q32 | Direction and supervision
Which of the following correctly describes the difference between a subcontract (ukeoi) arrangement and a worker dispatch (haken) arrangement?
Under a subcontract, the ordering party cannot, and under dispatch, the client company also cannot, directly direct and supervise the workers it receives.
Under a subcontract, the ordering party cannot directly direct and supervise the other party's workers, while under dispatch, the client company can direct and supervise the dispatched workers.
Under both a subcontract and dispatch, the workers are employed by the company that takes on the work, and that company also directs and supervises them.
Under a subcontract, the ordering party can directly direct and supervise the other party's workers, while under dispatch, the client company cannot direct and supervise the dispatched workers.
AnswerB. Under a subcontract, the ordering party cannot directly direct and supervise the other party's workers, while under dispatch, the client company can direct and supervise the dispatched workers.
A subcontract is a contract aimed at completing a piece of work, and the client cannot directly direct or supervise the contractor's workers; instructions must go through the contractor's own responsible person. Under worker dispatch, the decisive difference is that the dispatching agency employs the workers, while it is the client company that directs and supervises them. The first choice swaps the parties who direct and supervise under a subcontract and under dispatch, and the second and third choices are wrong on the point that the client company directs and supervises the dispatched workers.
Q33 | Disguised subcontracting
Under a subcontract (ukeoi) agreement, a partner company's engineer is stationed at the company, and a manager at the company directly instructs that engineer's daily work content and procedures. What is this situation called, and which law does it primarily violate?
Unauthorized reproduction, which primarily violates the Copyright Act.
Use outside the stated purpose, which primarily violates the Act on the Protection of Personal Information.
Unlawful use of a trade secret, which primarily violates the Unfair Competition Prevention Act.
Disguised subcontracting, which primarily violates the Worker Dispatch Act.
AnswerD. Disguised subcontracting, which primarily violates the Worker Dispatch Act.
A situation where the ordering party directly directs and supervises the other party's workers despite the arrangement being a subcontract is called disguised subcontracting, and it violates laws such as the Worker Dispatch Act. The arrangement needs to be corrected so that instructions go through the partner company's own responsible person, or switched to a proper worker dispatch contract. Using personal information outside its stated purpose, unlawful use of a trade secret, and unauthorized reproduction are matters under the Act on the Protection of Personal Information, the Unfair Competition Prevention Act, and the Copyright Act respectively, and none corresponds to this case.
Q34 | The Subcontracting Fairness Act
The Subcontract Act was renamed effective January 1, 2026 (Reiwa 8). Which of the following correctly combines the new law's abbreviated name with the changes made alongside it?
The Fair Trade Fairness Act. The scope is limited to manufacturing, excluding outsourced transport or the creation of information-based deliverables, and no name change was made.
The Small and Medium Enterprise Support Act. The capital-based threshold was abolished, and a business operator's size is now judged solely by employee count, while the ban on payment by promissory note was postponed.
The Small and Medium Subcontracting Fairness Act (Torikitekihou). The main contractor is renamed the outsourcing business operator and the subcontractor the small and medium subcontracting business operator, and payment by promissory note is banned.
The Outsourcing Transaction Transparency Act. It requires the content of an outsourcing arrangement to be filed with the Japan Fair Trade Commission in advance.
AnswerC. The Small and Medium Subcontracting Fairness Act (Torikitekihou). The main contractor is renamed the outsourcing business operator and the subcontractor the small and medium subcontracting business operator, and payment by promissory note is banned.
According to the Japan Fair Trade Commission, the Subcontract Act, effective January 1, 2026, becomes the Small and Medium Subcontracting Fairness Act (abbreviated Torikitekihou), with the main contractor renamed the outsourcing business operator and the subcontractor the small and medium subcontracting business operator. Alongside this, an employee-count threshold was added to the capital-based one, dispatch of specified transport was brought into scope, payment by promissory note was banned, and unilaterally setting a price without consultation was banned. Abolishing the capital-based threshold, limiting the scope, and introducing an advance filing system were not part of this change.
Q35 | Managing a contractor
A company outsourced data-entry work involving personal data, and an employee of the contractor took the data out and sold it to a list broker. Regarding the outsourcing party's responsibility, which of the following is appropriate?
Third-party provision was already complete the moment the data was provided to the contractor, so no responsibility remains with the outsourcing party.
The outsourcing party retains an obligation to exercise necessary and appropriate supervision over the contractor, and can be held responsible under the Act on the Protection of Personal Information.
Since this occurred at the contractor, the obligation to report to the Personal Information Protection Commission falls only on the contractor, not on the outsourcing party.
As long as a non-disclosure agreement was signed with the contractor, no responsibility reaches the outsourcing party.
AnswerB. The outsourcing party retains an obligation to exercise necessary and appropriate supervision over the contractor, and can be held responsible under the Act on the Protection of Personal Information.
When the handling of personal data is outsourced, the outsourcing party retains an obligation to exercise necessary and appropriate supervision over the contractor, including selecting the contractor, setting terms in the contract, and tracking how it is actually being carried out. Signing a non-disclosure agreement is necessary but does not by itself relieve the outsourcing party of responsibility. Provision accompanying outsourcing does not count as third-party provision, and even for a leak occurring at the contractor, the outsourcing party is not relieved of the reporting obligation.
Q36 | Work rules
Which of the following is a necessary precondition for disciplining an employee who violated the information security regulations?
That the types and grounds of discipline are set out in the work rules and communicated to employees
That the information security regulations have been filed in advance with the Personal Information Protection Commission
That the violation is also recognized as constituting a crime under the Penal Code
That a written non-disclosure agreement has been signed with each individual employee in advance
AnswerA. That the types and grounds of discipline are set out in the work rules and communicated to employees
To carry out discipline, it is a precondition that the types and grounds of discipline have been set out in the work rules in advance and communicated to employees. Even with information security regulations in place, they lack real effect if not tied to the work rules. There is no system for filing regulations with the Commission, and being a crime under the Penal Code is not a requirement for discipline either. A non-disclosure agreement is useful but is not by itself grounds for discipline.
Q37 | Whistleblower protection
Regarding the Whistleblower Protection Act, which of the following is appropriate?
A report must always be made to a government agency; a report to an internal contact point is outside the law's protection, so disadvantageous treatment is not prohibited in that case either.
Regardless of a business operator's size, establishing an internal reporting contact point remains only a best-effort obligation.
Dismissal or other disadvantageous treatment on the grounds of having made a public-interest report is prohibited, and business operators above a certain size are required to establish a system for handling internal public-interest reports.
The whistleblower's name can be widely shared with relevant departments to smooth the internal investigation.
AnswerC. Dismissal or other disadvantageous treatment on the grounds of having made a public-interest report is prohibited, and business operators above a certain size are required to establish a system for handling internal public-interest reports.
The Whistleblower Protection Act prohibits dismissal or disadvantageous treatment on the grounds of a report, and requires business operators whose regularly employed workers exceed a certain size to establish a system for handling internal public-interest reports. An internal public-interest report to an internal contact point is also protected. The staff who receive reports are designated as personnel engaged in handling public-interest reports and bear a duty of confidentiality regarding information that could identify the whistleblower, so it must not be shared carelessly.
Q38 | CVSS
Which of the following correctly describes CVSS, the common metric for evaluating a vulnerability's severity?
An evaluation method that scores a vulnerability's severity on a common scale, expressed as a value from 0.0 to 10.0
The name of a database of vulnerability countermeasure information that gathers and publishes vulnerabilities reported domestically
A list of which software components a product contains, down to their names and versions
A globally common identification number assigned to each individual vulnerability, used in common by everyone involved
AnswerA. An evaluation method that scores a vulnerability's severity on a common scale, expressed as a value from 0.0 to 10.0
CVSS (the Common Vulnerability Scoring System) is an evaluation method that scores a vulnerability's severity on a common scale from 0.0 to 10.0, used for prioritizing responses. An identification number for each individual vulnerability is CVE, a domestic vulnerability information database is JVN, and a list of software components is an SBOM; each of these is something different from CVSS.
Q39 | CVSS and CVE
Which of the following correctly describes terms related to vulnerabilities?
JVN is merely a list classifying types of vulnerability and does not carry information about individual vulnerabilities or countermeasures.
CVE is a common scale for numerically evaluating a vulnerability's severity.
CVSS is a common identification number assigned to uniquely identify an individual vulnerability.
CVSS is a common scale for evaluating a vulnerability's severity, and CVE is a common number for identifying an individual vulnerability.
AnswerD. CVSS is a common scale for evaluating a vulnerability's severity, and CVE is a common number for identifying an individual vulnerability.
CVSS is a common scoring system expressing a vulnerability's severity numerically (CVSS v3 scores it using base, temporal, and environmental metrics), and CVE is a common identification number assigned to an individual vulnerability; the first and second choices mix these two up. JVN is a Japanese vulnerability countermeasure information portal jointly operated by JPCERT Coordination Center and IPA, providing information on individual vulnerabilities and their countermeasures. What classifies types of vulnerability is CWE.
Q40 | The management guidelines
Which of the following correctly describes the content of the Cybersecurity Management Guidelines published by the Ministry of Economy, Trade and Industry and IPA?
It defines, as a standard, the examination criteria for obtaining ISMS certification.
It presents concrete criteria for interpreting the legal obligations concerning security control measures for personal data.
It presents three principles executives should be aware of and ten important items executives should direct a responsible executive such as the CISO to carry out.
It specifically names products to designate the minimum technical measures a small or medium-sized enterprise must carry out.
AnswerC. It presents three principles executives should be aware of and ten important items executives should direct a responsible executive such as the CISO to carry out.
The Cybersecurity Management Guidelines are guidance for management presenting three principles executives should be aware of and ten important items executives should direct a responsible executive to carry out. It does not designate specific products, and the examination standard for certification is JIS Q 27001. Interpreting security control measures for personal data is shown in guidelines from the Personal Information Protection Commission, and a separate guide for small and medium-sized enterprises, IPA's information security countermeasure guidelines for SMEs, exists on its own.
Practice: answer the questions on this page
This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.
* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.
This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original