A firewall should allow only traffic connecting from inside the company to an external website over HTTPS. Which destination port number should be allowed?
80
443
23
25
AnswerB. 443
HTTPS uses TCP port 443, so only 443 should be allowed. Port 80 is HTTP, where traffic flows unencrypted, which does not fit the goal here of allowing only encrypted connections. Port 25 is SMTP (sending email) and port 23 is Telnet (remote login), both unrelated to browsing the web. The principle for a firewall is to allow only the traffic that is needed and deny everything else.
Q2 | Zoning the network
An internal network was divided into subnets by department, with communication between subnets controlled by a router. What is the main aim of this measure?
To encrypt all communication crossing between subnets, so its content cannot be read even if intercepted in transit
To assign the same IP address to every internal device at once, greatly reducing the effort of address management
To block all unauthorized access from the outside internet at the perimeter, so no internal device can ever be breached
So that even if one device is infected with malware, the damage stays contained within its zone and the communication can be blocked at the boundary
AnswerD. So that even if one device is infected with malware, the damage stays contained within its zone and the communication can be blocked at the boundary
The purpose of dividing a network into zones is to curb lateral spread after an intrusion or infection has occurred, and to make it easier to contain by blocking traffic at boundary equipment. It is not a mechanism that completely blocks intrusion from outside; it is a measure that limits the spread of damage internally. An IP address must be unique per device for communication to work, so the same address cannot be assigned to every device. Encryption is the role of a VPN or TLS and is not achieved by subnetting.
Q3 | A misunderstanding about NAPT
Internal devices are assigned private IP addresses and connect to the internet through NAPT translation to a global IP address. Which of the following is the most appropriate description of this setup?
The main purpose of NAPT is conserving global IP addresses; controlling communication from outside must be handled separately with a firewall
Using NAPT automatically encrypts communication content, making a VPN unnecessary
Because NAPT is a mechanism that hides the source address, unauthorized communication from inside to outside is also automatically blocked entirely
As long as internal devices use private IP addresses, they cannot be reached directly from outside, so they can never become infected with malware
AnswerA. The main purpose of NAPT is conserving global IP addresses; controlling communication from outside must be handled separately with a firewall
NAT/NAPT is an address translation mechanism whose purpose is conserving global IP addresses. It has the side effect of being harder to reach directly from outside, but it has no function for selecting which traffic to allow, so it is no substitute for a firewall. It also has no encryption function, so it is no substitute for a VPN either. Even with private IP addresses, a device can still become infected through email or web browsing, and it does not prevent an infected device from communicating out to an external command-and-control server.
Q4 | The limits of a VPN
A remote employee connects from home to the company system over a VPN. Which of the following most appropriately describes a VPN?
A VPN encrypts and protects the communication path, but it does not guarantee that the connecting device itself is safe, so measures on the device side are also needed
Using a VPN automatically encrypts files stored on the connecting device
As long as the communication path is encrypted with a VPN, an infection on the connecting device cannot affect the internal company systems
A VPN is a physical dedicated line that does not use the internet and does not pass through a telecommunications carrier's facilities
AnswerA. A VPN encrypts and protects the communication path, but it does not guarantee that the connecting device itself is safe, so measures on the device side are also needed
A VPN is a technology that creates an encrypted virtual dedicated line over a public network, and what it protects is the confidentiality and integrity of the communication path. If an infected device connects over a VPN, malware can travel into the company through the encrypted path, so patching, malware countermeasures, and multi-factor authentication are still separately needed on the device side. It uses a public network such as the internet rather than a physical dedicated line, and it has no function to encrypt files stored on the device.
Q5 | Wi-Fi
Regarding security measures for an office's Wi-Fi, which of the following is most appropriate?
Use WPA2 or WPA3 for encryption and authentication, and treat SSID stealth and MAC address filtering as merely supplementary measures
As long as MAC address filtering is configured, no other measures, including encryption, are needed
Connect the guest Wi-Fi and the internal business Wi-Fi to the same network, and manage the access point equipment and settings together centrally
Enabling SSID stealth to hide the SSID from outsiders is enough to make WEP sufficiently safe as the encryption method
AnswerA. Use WPA2 or WPA3 for encryption and authentication, and treat SSID stealth and MAC address filtering as merely supplementary measures
The core of Wi-Fi security is encryption and authentication, using WPA2 or WPA3. WEP must not be used because it can be broken quickly. Both SSID stealth and MAC address filtering can be defeated because the SSID or MAC address becomes visible from observing the traffic, so neither can be relied on as a standalone measure. The principle is to keep guest Wi-Fi separate from the business network; connecting them to the same network risks letting a guest's device reach into the company.
Q6 | Sender domain authentication
To reduce damage from spoofed email impersonating the company's own domain, sender domain authentication is being introduced. Which of the following most appropriately describes SPF, DKIM, and DMARC?
DMARC is a mechanism that encrypts the body of an email so its content cannot be read by a third party in transit.
SPF is a mechanism for verifying an electronic signature, DKIM is a mechanism that publishes the IP addresses of authorized sending servers in DNS for comparison, and DMARC is a mechanism where the sending side publishes a policy for how to handle email that fails authentication.
SPF is a mechanism that publishes the IP addresses of authorized sending servers in DNS for comparison, DKIM is a mechanism for verifying an electronic signature, and DMARC is a mechanism that publishes a policy for how to handle email that fails authentication.
All three only need to be configured on the receiving mail server; nothing needs to be configured on the sending domain.
AnswerC. SPF is a mechanism that publishes the IP addresses of authorized sending servers in DNS for comparison, DKIM is a mechanism for verifying an electronic signature, and DMARC is a mechanism that publishes a policy for how to handle email that fails authentication.
SPF publishes, in DNS, the IP addresses of servers authorized to send mail for a domain, and the receiving side checks against it. DKIM has the sending side attach an electronic signature, which the receiving side verifies using a key published in DNS. DMARC takes the SPF and DKIM results into account and has the sending domain publish a policy for whether email that fails authentication should be handled as “none, quarantine, or reject,” while also receiving reports on the results. The description that swaps SPF and DKIM, and the one that describes DMARC as encrypting the body, are both wrong. All of these depend on configuration on the sending domain's side, such as DNS records.
Q7 | Time synchronization
Internal servers and network equipment are synchronized to an NTP server to keep their clocks aligned. Which of the following is the most appropriate reason this matters for information security?
Because it makes it possible to cross-reference logs from multiple devices in chronological order, accurately tracing the course of an incident and preserving their value as an audit trail
Because having the clocks aligned automatically encrypts communication so it cannot be eavesdropped on
Because having the clocks aligned makes it possible to predict in advance the time malware will start acting, so communication at that time can be blocked beforehand
Because having the clocks aligned shrinks the size of the log files output by each device, extending how long logs can be retained on the same equipment
AnswerA. Because it makes it possible to cross-reference logs from multiple devices in chronological order, accurately tracing the course of an incident and preserving their value as an audit trail
If each device's clock is off, lining up multiple logs still leaves the order of events unclear, making it impossible to trace what happened when, and it also undermines their reliability as evidence. That is why aligning the time through a common NTP server is a precondition for incident investigation and for their value as an audit trail. Time synchronization has nothing to do with log volume, provides no communication-encryption function, and does not make it possible to predict when malware will act.
Q8 | IaaS responsibility
A company built its business server using IaaS. In light of the shared responsibility model, which of the following is something the user should do?
Carry out patching of the guest OS and middleware they themselves installed, as the user's own planned responsibility
Carry out vulnerability countermeasures and patching for the virtualization platform (hypervisor) itself, as the user's own planned responsibility
Carry out entry and exit control and physical security for the data center by physically visiting the site themselves, including keeping records of it
Travel to the data center and personally carry out parts replacement when physical server hardware fails
AnswerA. Carry out patching of the guest OS and middleware they themselves installed, as the user's own planned responsibility
With IaaS, the provider covers up through the facility, hardware, network, and virtualization platform, while everything above the guest OS the user installed — the OS, middleware, applications, data, and accounts — falls within the user's area of responsibility. Patching the guest OS is therefore something the user does. Entry and exit control for the data center, replacing physical hardware, and securing the virtualization platform are all within the provider's area of responsibility, and the user cannot carry these out.
Q9 | SaaS responsibility
A SaaS file-sharing service used for business had its sharing scope set by a staff member to “anyone with the link,” leaving a confidential file viewable from outside the company. Which of the following is the most appropriate explanation in light of the shared responsibility model?
In SaaS, the service provider is supposed to protect everything, so this event is also the provider's responsibility
The sharing-scope setting while using SaaS is automatically optimized by the service provider, so neither the user nor the provider bears responsibility
Setting access rights and the sharing scope, and managing the data placed there, fall within the user's area of responsibility, so this is the user's responsibility
Because SaaS gives the user no authority over sharing settings, this kind of situation cannot occur
AnswerC. Setting access rights and the sharing scope, and managing the data placed there, fall within the user's area of responsibility, so this is the user's responsibility
With SaaS, running the application and its vulnerability countermeasures are the provider's responsibility, but the data itself, user accounts, and setting access rights and the sharing scope remain within the user's area of responsibility. Using the cloud does not shift this part of the responsibility to the provider. The provider does not automatically optimize the settings, and it is precisely because the user has the authority over sharing settings that leaks from a misconfiguration like this actually occur frequently in practice.
Q10 | PaaS responsibility
A company runs a business application it developed in-house on top of PaaS. If a SQL injection vulnerability is found in this application, which of the following is the most appropriate response?
Since this is a vulnerability in the OS itself, address it by having the user apply a patch to the guest OS
Since the application developed in-house falls within the user's area of responsibility, fix the program in-house
Since PaaS does not let a user develop an application, this vulnerability cannot occur
Since this is a problem with the runtime environment provided by the PaaS provider, simply wait for a fix from the provider
AnswerB. Since the application developed in-house falls within the user's area of responsibility, fix the program in-house
With PaaS, the provider manages up through the OS, middleware, and runtime environment, while the application and data the user developed and deployed on top of it, along with account management, fall within the user's area of responsibility. SQL injection is a vulnerability arising from how the company's own application was built, so the company fixes the program itself. It is not something to wait on the provider for, nor something fixed by an OS patch. PaaS is precisely a platform for the user to develop and run applications on, so the claim that development is not possible is also wrong.
Q11 | Availability in series
Device A, with an availability of 0.95, and device B, with an availability of 0.90, are connected in series so that the whole system operates only when both A and B are operating. What is the overall system's availability? Assume the failures of A and B are independent of each other.
0.990
0.855
0.900
0.925
AnswerB. 0.855
In a series configuration, every device must be operating at the same time, so the overall availability is the product of each device's availability: 0.95 × 0.90 = 0.855. 0.925 is the simple average of the two availabilities ((0.95 + 0.90) ÷ 2), and 0.900 is device B's availability alone; neither is the value for a series configuration. 0.990 is also an unfounded value; for reference, a parallel configuration where only one of the two needs to work would give 1 − (1 − 0.95) × (1 − 0.90) = 0.995. Because overall availability drops the more devices are added in series, the parts that need availability should instead be made redundant.
Q12 | Availability in parallel
Two devices, each with an availability of 0.90, are set up in a redundant configuration where the overall system operates as long as either one is operating. What is the overall system's availability? Assume the failures of the two devices are independent of each other.
0.90
0.95
0.81
0.99
AnswerD. 0.99
The availability of a parallel (redundant) configuration is found by subtracting from 1 the probability that all devices stop at the same time: 1 − (1 − 0.90) × (1 − 0.90) = 1 − 0.10 × 0.10 = 1 − 0.01 = 0.99. 0.81 is the value for a series configuration requiring both to be operating (0.90 × 0.90), and 0.90 is the value for a single device. 0.95 is an unfounded value that does not come from any of these calculations; none of these is the result for a redundant configuration. The numbers confirm that redundancy raises overall availability and contributes to business continuity.
Q13 | RAID and offsite copies
A file server's disks are configured as RAID 1 (mirroring). Which of the following is the most appropriate evaluation of this as a countermeasure against ransomware?
RAID 1 is effective against a disk failure, but because encryption is reflected onto both disks, generational backups also need to be kept offline or at a remote location
Expanding RAID 1 to a five-disk configuration would prevent ransomware damage
RAID 1 is a mechanism that always prohibits writing to the disk, so even if ransomware tries to encrypt a file, it cannot rewrite it and no damage occurs
With RAID 1, even an encrypted file can be automatically restored from the content of the other disk, so no additional measure such as taking backups is particularly necessary
AnswerA. RAID 1 is effective against a disk failure, but because encryption is reflected onto both disks, generational backups also need to be kept offline or at a remote location
What RAID protects against is physical disk failure; encryption or accidental deletion carried out as a legitimate write is reflected onto every disk just the same. RAID is therefore no substitute for backups. Multiple generations of backups need to be taken, with at least one kept at a location disconnected from the network or at a remote site, and the ability to restore from them needs to be checked periodically. RAID has no function to prohibit writing, and adding more disks does not change how encryption gets reflected.
Q14 | Using a view
An HR database's employee table has columns for employee number, name, department, title, salary, and individual number. General employees should be able to reference only name, department, and title, as an employee directory. Which of the following is the most appropriate method?
Define a view that pulls out only the name, department, and title columns, and grant view access only to that view for general employees
Grant view access to the employee table itself to all employees, and tell everyone internally not to look at the salary and individual number columns
Change the employee table so all employees can update it, and operate it with the salary and individual number columns left permanently blank
Place a backup of the employee table in a shared folder for everyone to find and use the information they need from there
AnswerA. Define a view that pulls out only the name, department, and title columns, and grant view access only to that view for general employees
A view is a virtual table that pulls out only the needed columns or rows from the original table, and granting view access only to the view keeps the salary and individual number columns untouched. This fits the principle of least privilege, granting only the minimum necessary access. Relying on telling people not to look provides no technical restriction and cannot prevent a leak. Leaving the columns blank destroys the data itself, and granting all employees update access is out of the question. Placing a backup in a shared folder creates an unmanaged copy and widens the route through which a leak could occur.
Q15 | Recovering a database
A database server's disk failed and became unusable, and it was replaced with another disk. A backup from the previous night and the after-image log taken since then are both available. Which method restores the system to the state immediately before the failure occurred?
Restore only the backup, and resume operation from the state as of the previous night
Restore the backup and then perform a roll-forward that applies the after-image log
Recover by performing only a rollback that undoes a transaction that was interrupted mid-process
Use only the before-image log to go back to a state earlier than when the backup was taken
AnswerB. Restore the backup and then perform a roll-forward that applies the after-image log
Recovering from a media failure is done by restoring the backup and then performing a roll-forward that applies the subsequent after-image log in order, bringing the system up to the state immediately before the failure. Restoring only the backup loses all the updates made afterward. A rollback undoes a transaction that was interrupted mid-process back to before it started and does not recover the updates made since the backup. Using the before-image log to go back to a point earlier than the backup is not recovery at all. Either kind of recovery depends on the logs having been preserved.
Q16 | Requirements definition
In developing a new business system, which approach follows the idea of security by design?
Go back to the design stage only when a vulnerability is found during testing, considering and adding whatever security measure is needed at that point
Since security is work for operations staff, give it no consideration whatsoever, whether as a requirement or in the design, during the development phase
Define security requirements such as how access rights are divided, the scope of logs to capture, encryption, and the authentication method at the planning and requirements-definition stage
Prioritize implementing functionality first and proceed with development, adding necessary security functions one by one after the system goes live
AnswerC. Define security requirements such as how access rights are divided, the scope of logs to capture, encryption, and the authentication method at the planning and requirements-definition stage
Security by design is the idea of building security into the design starting from the planning and requirements-definition stage. Trying to add it in a later phase leads to large rework involving design changes, driving up both cost and time, and often leaves things not fully fixed once operation has begun. Adding it after going live, considering it only once a vulnerability is found, or giving it no consideration during development all invite this kind of rework and inadequate countermeasures.
Q17 | Penetration testing
Which of the following most appropriately describes penetration testing carried out before a web system is published?
A test that examines the program's internal structure to confirm that every branch of its logic is executed at least once, measuring quality by degree of coverage
A test that actually attempts an intrusion from an attacker's standpoint to check whether the defenses can be broken through, requiring the prior consent of the target system's administrator to carry out
A test that checks, from the outside without looking at the program's internal structure, whether the output matches the specification for a given input, also doubling as an assessment of intrusion possibility as a final check before release
A test that has actual users operate the system to evaluate how clear and easy to use the screens are
AnswerB. A test that actually attempts an intrusion from an attacker's standpoint to check whether the defenses can be broken through, requiring the prior consent of the target system's administrator to carry out
Penetration testing checks intrusion possibility from an attacker's viewpoint, a different purpose from a test that checks whether functions work as specified. Even if every functional test passes, intrusion can sometimes still succeed. Examining internal structure to confirm branch coverage is white-box testing, checking input and output without looking at internal structure is black-box testing, and evaluating ease of use is usability testing; each of these is something different. Note also that attempting to intrude into someone else's system without permission risks violating the Act on Prohibition of Unauthorized Computer Access, which is why prior consent is indispensable.
Q18 | Problem management
In service management, which of the following most appropriately describes the difference between incident management and problem management?
Incident management aims to identify the root cause and prevent recurrence, while problem management aims to restore the service to its normal state as quickly as possible
Incident management aims to restore the service to its normal state as quickly as possible, while problem management aims to identify the root cause and prevent recurrence
Incident management deals only with information-security-related incidents, and problem management deals with every other kind of failure or incident — a distinction by scope
Incident management and problem management refer to exactly the same activity, sharing the same subject, purpose, and procedure, differing only in what they are called in a report
AnswerB. Incident management aims to restore the service to its normal state as quickly as possible, while problem management aims to identify the root cause and prevent recurrence
The purpose of incident management is quick recovery of the service, and it is fine to restore operations with a temporary workaround even without knowing the root cause. The purpose of problem management is identifying the root cause and preventing recurrence through a permanent fix. Because their purposes differ, they are managed as separate processes. The description that swaps the two purposes, and the one that treats them as the same activity, are both wrong, and the distinction is not based on whether it is a security incident or not.
Q19 | SLAs
When outsourcing the operation of a business system, an SLA is agreed upon. Which of the following most appropriately describes an SLA?
An SLA is a document in which the provider and the user agree on numeric service quality levels, defining not only uptime and target recovery time but also security matters such as the reporting deadline in the event of an incident and the log retention period
An SLA is an internal regulation of the service provider and is not to be disclosed to the user
An SLA should record only availability-related targets such as uptime and target recovery time, and must never record security-related matters such as the reporting deadline in the event of an incident or the log retention period
Once agreed upon, an SLA must never be reviewed, and achievement against it is not measured during the contract period either
AnswerA. An SLA is a document in which the provider and the user agree on numeric service quality levels, defining not only uptime and target recovery time but also security matters such as the reporting deadline in the event of an incident and the log retention period
An SLA is a document agreed upon by the provider and the user, defining numeric targets such as uptime, target recovery time in the event of a failure, and response time. Setting out security-related matters as well — the reporting deadline in the event of an incident, the log retention period, the response time for a vulnerability, and so on — makes clear what will be done for the user when an incident occurs. It is not an internal regulation for the provider alone; the agreed level is continually measured, evaluated, and improved (SLM), and revised as needed.
Q20 | Change and configuration
Which combination most appropriately describes change management and configuration management in service management?
Change management is the activity of serving as a single contact point that accepts inquiries and failure reports from users, and configuration management is the activity aimed at restoring the service from an occurred failure as quickly as possible
Change management is the activity of identifying the root cause of a failure, and configuration management is the activity of securing the processing capacity needed for business
Change management is the activity of evaluating the impact of a change to a system, obtaining approval, and then carrying it out and recording it; configuration management is the activity of continuously and accurately keeping track of configuration items such as equipment, software, and settings, and the relationships among them
Change management is the activity of an auditor instructing the audited department to make improvements, and configuration management is the activity of management deciding whether to make an investment
AnswerC. Change management is the activity of evaluating the impact of a change to a system, obtaining approval, and then carrying it out and recording it; configuration management is the activity of continuously and accurately keeping track of configuration items such as equipment, software, and settings, and the relationships among them
Change management is a mechanism that prevents disorderly changes by evaluating their impact, obtaining approval before carrying them out, and keeping a record — the very act of preventing an unapproved change is itself a security measure. Configuration management is the activity of continuously and accurately keeping track of equipment and software versions and settings and how they relate to each other, so that when a vulnerability is announced the affected assets can be identified right away. A single contact point for inquiries is the service desk, quick recovery is incident management, identifying root cause is problem management, and securing processing capacity is capacity management; each of these is a separate process.
Q21 | Audit independence
A company has decided to carry out a systems audit internally. From the standpoint of the systems auditor's independence, which of the following is most appropriate?
An internal audit department staff member who is organizationally independent of the audited department, or an outside auditor, carries out the audit
The head of the department being audited audits their own department's work and creates and submits the audit report
An operations staff member in the information systems department audits the very business system they operate day to day
The project leader who was in charge of developing the audited system audits that system themselves
AnswerA. An internal audit department staff member who is organizationally independent of the audited department, or an outside auditor, carries out the audit
A systems auditor is required to be organizationally independent of the audited department (external independence) and to be able to judge fairly and objectively (internal independence). Auditing something one built or operated oneself risks overlooking, or being suspected of overlooking, inconvenient facts, which does not satisfy independence. An operations staff member, the development project leader, and the head of the audited department would each be auditing their own work and are all inappropriate; the audit should instead be carried out by an independent internal audit department or an outside auditor.
Q22 | Audit trails
Regarding an audit trail and follow-up in a systems audit, which of the following most appropriately describes them?
An audit trail is the audit report itself created by the auditor, which is not disclosed to the audited department to maintain independence, and in follow-up the audited department evaluates its own improvement status and closes it out
An audit trail is a mechanism or set of records that lets processing be traced back after the fact, showing when, by whom, and how it was carried out; in follow-up, the auditor confirms the status of improvement on the raised findings
An audit trail is only captured during the audit period and can be skipped during normal operation
In follow-up, the auditor devises and carries out the improvement measures themselves, resolving the issue
AnswerB. An audit trail is a mechanism or set of records that lets processing be traced back after the fact, showing when, by whom, and how it was carried out; in follow-up, the auditor confirms the status of improvement on the raised findings
An audit trail refers to a mechanism or record, such as access logs, operation history, or approval records, that lets the course of processing be traced back afterward, and it is precisely because it is captured and retained continuously, even in normal times, that verification after the fact becomes possible. Follow-up is the activity in which the auditor confirms whether improvement has actually been carried out on the items raised in the audit report. Carrying out the improvement itself is the audited department's job; if the auditor carried it out themselves, the next audit would mean auditing their own work, undermining independence. An audit trail is a separate thing from the audit report.
Q23 | CISO
Which of the following most appropriately describes the role of a CISO at a company?
Drawing up sales and pricing strategy for the company's own products, and being responsible for achieving sales targets
Preparing financial statements and being responsible for explaining accounting matters at the shareholders' meeting
Being responsible for formulating the information security policy, deciding the risk-treatment policy, directing the response to an incident, and reporting to management
Personally carrying out the setup and wiring of internal PCs and network equipment, and handling day-to-day maintenance and responding to failures
AnswerC. Being responsible for formulating the information security policy, deciding the risk-treatment policy, directing the response to an incident, and reporting to management
A CISO (chief information security officer) is the top management-level person responsible for information security, handling formulating policy, deciding the risk-treatment policy, directing the response to a major incident, and reporting to management and outside parties. Sales strategy belongs to the sales department, preparing and explaining financial statements belongs to a CFO or the finance department, and setting up equipment or day-to-day maintenance is practical work for the information systems department; none of these is the CISO's role. There is value in itself in placing a responsible person at the management level rather than leaving security to individual staff.
Q24 | Segregation of duties
From the standpoint of internal control, which of the following practice follows the idea of segregation of duties?
Separating the staff member who places a purchase order from the one who inspects the delivered goods
Prioritizing efficiency and also granting the system development staff the authority to change the production environment
Granting every employee administrator rights so anyone can carry out whatever task is needed
Having one staff member consistently carry out everything from application through approval, execution, and recording, to make responsibility clear
AnswerA. Separating the staff member who places a purchase order from the one who inspects the delivered goods
Segregation of duties is a basic principle of internal control that splits roles such as application, approval, execution, and recording among multiple people, building a structure where mutual checking makes fraud or mistakes less likely to occur. Separating the person who places an order from the person who inspects the delivery is a typical example. A situation where one person can complete an entire sequence of processing on their own makes fraud hard to discover and violates segregation of duties. Granting development staff the authority to change the production environment should also be avoided, since it enables a change without going through approval. Granting administrator rights to everyone also violates the principle of least privilege.
Q25 | RFI and RFP
Which of the following most appropriately describes the procurement flow when ordering a business system from an outside vendor?
Request for Information (RFI) → Request for Proposal (RFP) → receiving and evaluating proposals → contract
Contract → Request for Proposal (RFP) → receiving and evaluating proposals → Request for Information (RFI)
Request for Proposal (RFP) → Request for Information (RFI) → contract → receiving and evaluating proposals
Receiving and evaluating proposals → Request for Information (RFI) → contract → Request for Proposal (RFP)
AnswerA. Request for Information (RFI) → Request for Proposal (RFP) → receiving and evaluating proposals → contract
First, an RFI (request for information) gathers information from vendors about what products, services, and technologies exist in the market. Based on that information, requirements are organized into an RFP (request for proposal), and multiple vendors are asked for concrete proposals. The submitted proposals and quotes are evaluated against predetermined criteria to select a vendor, and a contract is concluded. The stage of gathering information comes first, and requesting proposals comes later; the other choices reverse this order and are wrong. Security requirements need to be spelled out in the RFP.
Q26 | Selecting a contractor
A company is outsourcing work involving customers' personal data. Regarding selecting and managing the contractor, which of the following is most appropriate?
Even if the contractor further subcontracts to yet another business operator, there is no need to inform the outsourcing party
It is enough to select the vendor with the best price and delivery time; certification status, security matters, and arrangements for an incident can be discussed after the contract is signed
Once the work is outsourced, responsibility for managing the personal data fully shifts to the contractor, and the outsourcing party steps entirely away from managing or supervising it after selection
Spell out in the selection criteria and contract things such as certification status, how subcontracting will be handled, the obligation to report an incident, accepting an audit, and erasing data at the end of the engagement, and continue to receive periodic reports and supervise even after outsourcing
AnswerD. Spell out in the selection criteria and contract things such as certification status, how subcontracting will be handled, the obligation to report an incident, accepting an audit, and erasing data at the end of the engagement, and continue to receive periodic reports and supervise even after outsourcing
When selecting a contractor, security should be included as an evaluation item alongside price and delivery time. ISMS or Privacy Mark certification status, whether subcontracting is allowed and how any subcontractor will be managed, the obligation and deadline for reporting an incident, a clause accepting an audit, and the method for returning or erasing data at the end of the contract should all be spelled out in the selection criteria and the contract. Even after outsourcing the handling of personal data, the outsourcing party retains an obligation to exercise necessary and appropriate supervision over the contractor, and responsibility does not shift away. Letting the contractor subcontract without telling the outsourcing party is also inappropriate.
Q27 | Generative AI and confidentiality
An employee has asked to use a generative AI service for work. From the standpoint of preventing an information leak, which rule should the organization establish?
Since entered content is always deleted by the provider, let confidential information be entered freely too
Since generative AI is dangerous, ban its use on internal devices across the board, but leave use through a personal device or personal account to each individual's own judgment
Let each employee freely choose whatever generative AI service they personally prefer, and let them freely enter any work data into it without restriction
Limit usable services to ones the organization has approved, and explicitly state in the rules that customer personal information and unpublished management information must not be entered
AnswerD. Limit usable services to ones the organization has approved, and explicitly state in the rules that customer personal information and unpublished management information must not be entered
Content entered into generative AI may be stored by the provider or used for training, so entering confidential information risks it leaking outward from there. The organization should therefore limit usable services to ones it has approved, and explicitly state in the rules what information may and may not be entered. There is no guarantee that entered content is always deleted. Letting employees choose freely, or banning it internally while leaving use on personal devices to individual judgment, both create shadow IT beyond the organization's control and actually increase the risk of a leak.
Q28 | AI output
A generative AI was used to draft an explanatory document intended for release outside the company. Which of the following is the most appropriate way to handle this draft?
Because generative AI can output plausible-sounding content that is not factual, and its output may resemble an existing copyrighted work, have a person verify the facts and check the rights situation before publishing it
As long as a source is cited, it can be published as-is without fact-checking the content
Because generative AI output is based on a huge volume of training data, its content is always accurate and never resembles an existing copyrighted work, so it can be published as-is without checking
Because text created by generative AI can never raise a copyright problem, checking the rights situation is unnecessary
AnswerA. Because generative AI can output plausible-sounding content that is not factual, and its output may resemble an existing copyrighted work, have a person verify the facts and check the rights situation before publishing it
Generative AI can produce hallucinations, plausible-sounding sentences not grounded in fact, so its output must never be treated as correct as-is. It can also happen that the output resembles an existing copyrighted work, and publishing or selling it as-is risks infringing rights. A person should therefore verify the facts and check the rights and terms of use before publishing. Being based on training data does not make it accurate, and citing a source is no substitute for fact-checking.
Q29 | An investment decision
For a certain information asset, the loss from an incident is estimated at 20 million yen per occurrence, with an annual probability of 10%. Which of the following is the most appropriate way of thinking, from a management standpoint, about the cost of a countermeasure to prevent this incident?
The expected annual loss comes to 2 million yen, so this should be compared against the countermeasure's annual cost to judge whether the investment is worthwhile — except that anything involving human life or legal compliance should not be decided on cost-effectiveness alone
The expected annual loss comes to 2 million yen, but regardless of the amount, the cost of the countermeasure should always be set at the full 20 million yen, the same as the per-occurrence loss, without considering cost-effectiveness
As long as the probability of occurrence is not 100%, the incident can be treated as not happening, so no countermeasure is needed
Since security measures are a cost that generates no revenue, no cost should be spent on them at all
AnswerA. The expected annual loss comes to 2 million yen, so this should be compared against the countermeasure's annual cost to judge whether the investment is worthwhile — except that anything involving human life or legal compliance should not be decided on cost-effectiveness alone
The expected annual loss can be roughly estimated as the per-occurrence loss multiplied by the annual probability of occurrence: 20,000,000 × 10% = 2,000,000 yen. The basic approach is to compare how much this expected loss would be reduced by a countermeasure against that countermeasure's annual cost to judge whether the investment is worthwhile. Always spending the full loss amount, or spending nothing at all, is not rational either way, and judging it unnecessary just because the probability is not 100% is also wrong. That said, a countermeasure involving human life or legal compliance must not be decided on cost-effectiveness alone.
Q30 | KGI and KPI
To report the state of information security efforts to management in numeric form, a KGI, CSF, and KPI are set. Which combination is most appropriate?
The KPI is a secret indicator known only to management and is not shown to the department in charge
Set the KGI as “zero major incidents,” the CSF as “raising security awareness across all employees,” and the KPI as things like “the drill's open rate” or “the average number of days to fix a vulnerability”
KGI, CSF, and KPI are all ultimate outcome indicators, so the same content is written three times to express them
Set the KGI as “a targeted-attack email drill open rate of 5% or below,” the CSF as “repeating the drill every year,” and the KPI as “bringing the number of major incidents to zero”
AnswerB. Set the KGI as “zero major incidents,” the CSF as “raising security awareness across all employees,” and the KPI as things like “the drill's open rate” or “the average number of days to fix a vulnerability”
A KGI is the ultimate outcome indicator to be achieved, a CSF is the critical success factor decisive to achieving it, and a KPI is an intermediate indicator that measures progress. Accordingly, “zero major incidents” as the ultimate outcome is placed as the KGI, raising awareness as the success factor is placed as the CSF, and the drill's open rate or the average number of days to fix a vulnerability, which measure how that progress is going, are placed as the KPIs. The combination that swaps the KGI and KPI is wrong. The three are separate indicators with different roles, and the KPI is something that should be shared with the department in charge so they can improve their day-to-day activity.
Practice: answer the questions on this page
This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.
* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.
This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original