B, who serves as information security leader for Company A's accounting department, is in charge of the annual review of access rights to the department's shared folders. B received the current settings list from the information systems department. The sales department needs to view the invoice folder to check the billing status of the customers each staff member handles. The payroll person in the human resources department needs write access to the payroll folder for payroll calculation. The accounting department creates invoices and journal entries, each requiring write access. The payroll folder stores every employee's salary amount and documents related to their individual number. In light of the principle of least privilege, which setting should B ask to have corrected first?
Row 3. Change the accounting department's read/write access to the journal-entry folder so it is only active at the end of the month
Row 5. Abolish every employee's ability to view the payroll folder, restricting it to the human resources payroll staff who need it for their work
Row 1. The accounting department having read/write access to the invoice folder is too strong a privilege, so change it to read-only
Row 2. Abolish the sales department's ability to view the invoice folder, and have them ask the accounting department each time it is needed
AnswerB. Row 5. Abolish every employee's ability to view the payroll folder, restricting it to the human resources payroll staff who need it for their work
Row 5 leaves every employee able to read other people's salary amounts and individual-number-related documents, a privilege with no business need, so it should be removed right away. Rows 1 and 3 are write privileges the accounting department genuinely needs for its own work, and row 2 is a view privilege the sales department needs for its own work; each has a justification and is not the one that needs correcting. Least privilege does not mean uniformly weakening every privilege — it means removing privileges that have no need behind them.
Q2 | Segregation of duties
At Company A, issuing user IDs for the business system is handled by a single person, C, in the information systems department. Under the current procedure, when a request arrives by email from a department, C looks at it, judges it necessary, and registers it directly into the system. Request emails arrive addressed to C personally, and there is no rule requiring a record to be kept. A recent internal audit found that an ID for a nonexistent user had been registered, but it could not be traced back to whose request led to it. C has worked diligently for many years, and no one suspects C personally. When reviewing this procedure, which response is most appropriate?
Revise the procedure for issuing user IDs so that a department head applies, an information management manager approves, and a different staff member carries out the registration, keeping a record of the application, approval, and registration
Change request emails to be addressed to the information systems department's shared mailbox instead of an individual, and retain incoming email for one year in a searchable form
Have C submit a pledge concerning confidentiality and proper conduct of duties, and take information security training once a year
To reduce C's workload, increase the number of registration staff to two, having them alternate judging whether a request is valid and carrying out the registration
AnswerA. Revise the procedure for issuing user IDs so that a department head applies, an information management manager approves, and a different staff member carries out the registration, keeping a record of the application, approval, and registration
The essence of the problem is that the same person judges whether a request is valid and carries out the registration, with no record kept at all. Splitting application, approval, and registration into separate roles and keeping a record would keep a groundless registration from slipping through and would allow it to be traced afterward (segregation of duties). Increasing staff to two does not change the structure where one person can complete the whole process alone, and a pledge or training does not reduce the opportunity for wrongdoing itself. Switching to a shared mailbox and retaining messages only improves traceability and does not fix the missing approval step.
Q3 | A shared ID
At a Company A retail store, POS register operations use a store-wide ID, “shop01,” whose password is known to all eight employees, including the store manager. One day, headquarters' sales check found that sale voids, which normally almost never happen, had been recorded repeatedly on the same day. When headquarters requested the store's operation log, the following record was obtained. The store has no security camera, and the shift schedule only records working hours, not who was on the register. Headquarters was unable to identify who performed this operation. What should be done first to prevent recurrence?
Reduce the POS terminals to just one, POS-1, and narrow in advance the location and time window in which register operations may be performed
Extend the log retention period from the current three months to three years, and go back through past records to find every similar operation
Issue an individual ID to each employee, abolish the shared ID, and make it possible to trace who performed which operation from the logs
Require the shared ID “shop01” password to be changed every month, with the store manager telling all employees the new one verbally
AnswerC. Issue an individual ID to each employee, abolish the shared ID, and make it possible to trace who performed which operation from the logs
Because only the shared ID appears in the log, even with a record kept, the person who performed the operation cannot be identified (a lack of accountability). Switching to individual IDs makes it possible to identify the operator, and it also creates a deterrent effect from the awareness of being watched. Extending the retention period, reducing terminals, or changing the password periodically do not solve the underlying cause — that whose operation it was cannot be identified while the shared ID remains in place.
Q4 | Managing a privileged account
At Company A, a privileged account with administrator rights on the business system is permanently assigned to three staff members in the information systems department. All three also check routine email and prepare documents from devices logged in under this privileged account. Recently, one of the three made an operating mistake and deleted part of the production data. It was recovered from backup, but the audit department pointed out that how the privileged account is managed needs to be reviewed. All three need administrator rights for maintenance work, but that work happens only a few times a month. Which of the following is the most appropriate way to operate the privileged account?
Keep the privileged account under the joint management of the three as before, but change the practice so that whenever administrator work is performed, at least two people are present together to check each other's actions, and record that fact in a work log
Keep the privileged account assigned to the three as it is, and have each of them self-report and record the administrator work they carried out at the end of each month
Assign the privileged account to no one in normal times; lend it out only after an application and approval for each maintenance task; have it returned and the password changed afterward; and check the checkout record against the operation log
Change the privileged account's password to a complex 32-character string, and store it somewhere only the three staff members can view
AnswerC. Assign the privileged account to no one in normal times; lend it out only after an application and approval for each maintenance task; have it returned and the password changed afterward; and check the checkout record against the operation log
Lending it out only when needed, and having it returned with the password changed afterward, removes the opportunity for an operating mistake during routine work, and cross-checking the checkout record against the operation log can also surface privileged operations that were never recorded. A longer password does not change the fact that it remains constantly usable and does not prevent an operating mistake. Cross-checking by being present together is only a supplementary measure and leaves the permanent-assignment problem in place. Self-reporting risks an operation inconvenient to the person going unrecorded and does not amount to a real check.
Q5 | Rights after a transfer
D, who had belonged to Company A's sales department, transferred to the accounting department effective April 1. On a request from the accounting section chief, the information systems department granted D input rights to the accounting system. Meanwhile, no one requested that D's rights to the customer management system used in the sales department be removed, so they were left as they were. D has no need to use the customer management system in accounting work. Company A has continued the same practice in the past too, and among employees with over ten years of service, some hold rights spanning five different departments. Which of the following is the most appropriate response to this situation?
Since there is no actual harm from the previous department's rights as long as the person does not use them, leave things as they are until the next annual inventory-taking
For an employee whose rights have accumulated, hand them a list of the rights they currently hold and have them self-report which ones they think are unnecessary
Keep the rights from the previous department for three months after the transfer in case they are needed for a handover, and remove them after three months if the person requests it
Establish a rule that the transfer procedure must bundle removing rights from the previous department together with granting rights for the new department, changing the practice so that removal is confirmed before granting takes place
AnswerD. Establish a rule that the transfer procedure must bundle removing rights from the previous department together with granting rights for the new department, changing the practice so that removal is confirmed before granting takes place
Continuing to grant rights without a matching removal at the time of a transfer lets rights accumulate, widening the potential damage from a mistake or internal fraud. Bundling removal and granting into a single procedure reliably drops the old rights without depending on someone remembering to request it. A practice of keeping them for a handover, or the idea that it is fine as long as they are not used, both go against the principle of least privilege. Leaving it to the person's self-report is no substitute for an inventory-taking, since the responsibility for judging this does not lie with the individual but with the business department's manager.
Q6 | Rights Inventory
Company A conducts an inventory of access rights to its accounting system every six months. E, the information security leader in the accounting department, reviews the list prepared by the information systems department. This time's list is as follows. "Otsu" transferred from the accounting department to the sales department in June, and the accounting system rights were already removed at that time; Otsu now uses only the sales department's system. "Hei" retired effective May 31, but the list still shows the rights as active. "Tei" remains in the accounting department but has been on maternity leave and childcare leave since February, with a planned return to work. Which of the following should E address first?
Since u101 logs in every day and is proficient in operations, newly grant approval rights in addition to input rights
Disable u103, and identify and correct the reason the account deletion procedure was not carried out upon retirement
Since u102's last login date is old and no recent usage can be confirmed, delete the account itself
Since u104 has no login record for over six months, remove all held rights and notify the person
AnswerB. Disable u103, and identify and correct the reason the account deletion procedure was not carried out upon retirement
If a retired employee's account remains active, misuse by a third party can look like legitimate use and go undetected longer. The purpose of the inventory is to disable u103 first and then fix the reason the retirement procedure failed to function. u104 has a planned return to work, so uniformly removing rights on the grounds of leave is not appropriate. u102's accounting rights have already been removed and the person is an active employee using the sales department's system, so it is not a deletion target. Adding approval rights to u101 increases rights, which runs counter to the purpose of the inventory.
Q7 | Password
Company A requires all employees to change their internal system password every 90 days. A review of operations found that many employees simply increment the last digit by one each time, and inquiries about "forgotten passwords" flood the information systems department with every change. Company A also recently migrated expense reimbursement to a cloud service, allowing login from outside the company with just an ID and password. A competitor has reported unauthorized logins from outside caused by a credential-stuffing attack using ID/password combinations leaked from other sites. Which of the following is the most appropriate revision of password operations?
Shorten the change cycle from 90 days to 30 days, and automatically suspend the accounts of users who do not change their password by the deadline
Add a requirement that passwords include at least one symbol, keep the 90-day periodic change as is, and continue to allow external use of the cloud service with just an ID and password
Abolish mandatory periodic changes, require a sufficiently long password that is not reused, introduce multi-factor authentication for the cloud service accessed from outside, and require immediate change if a leak is suspected
Have each person write down their password on paper and keep it in their own locked drawer, to be checked there if forgotten
AnswerC. Abolish mandatory periodic changes, require a sufficiently long password that is not reused, introduce multi-factor authentication for the cloud service accessed from outside, and require immediate change if a leak is suspected
Forced changes on a short cycle invite careless changes and have little effect against credential-stuffing attacks. Combining a long, non-reused password with a possession-based factor for multi-factor authentication can prevent unauthorized login even if the password leaks. Shortening the cycle or adding symbols only reinforces the same problem and is powerless against attacks using passwords leaked elsewhere. Writing it down on paper only reduces the burden of memorization and improves neither the strength of authentication nor the risk from outside.
Q8 | Log Operations
F, the information security leader at Company A, received materials from the information systems department showing the current state of log operations for the business system. Company A wants to use logs to deter internal fraud and to investigate causes when incidents occur. The log items collected and the retention period satisfy the requirements set out in internal regulations. Inspections are performed not by the staff who carry out system operations but by staff in the internal audit department. All employees have been informed, via work rules and the information security regulations, that logs are collected. Which item in these materials is inappropriate as a safeguard against internal fraud?
Collection scope. Records of failed logins and permission changes are also collected, and the number of items collected is excessive
Inspection. Once a month is too infrequent, and in addition all log inspection must be judged automatically by a mechanism
Retention period. The regulation requires at least 6 months, yet logs are kept for a full year, which is an excessive retention period
Storage location. If the system administrator can edit or delete the logs themselves, they cannot serve as evidence of fraud by the administrator
AnswerD. Storage location. If the system administrator can edit or delete the logs themselves, they cannot serve as evidence of fraud by the administrator
Logs only become evidence once they are protected from tampering and deletion, not merely collected. If storage is local and the administrator can edit or delete the logs themselves, that administrator's own fraud cannot be traced, so the logs must be consolidated elsewhere and protected from alteration. The collection scope consists of items necessary for tracing internal fraud and is not excessive. The retention period exceeds the regulatory requirement and is not a problem. Inspections are performed by the internal audit department, separate from the operating staff, and a monthly frequency by itself is not inappropriate.
Q9 | Division of Responsibility
Company A decided to discontinue the sales support system it had been running on an in-house server and migrate to an external SaaS. Prior to signing the contract, it received materials from the provider showing the division of responsibility. G, Company A's information security leader, heard an opinion at an internal meeting that "since we are moving to the cloud, security measures from now on can be left to the provider," and felt the need to align everyone's understanding. After migration, about 200 Company A sales staff will each hold a user ID, register customer information files, and share them with parties inside and outside the company. The materials state the following division of responsibility. Under this division of responsibility, what should Company A itself regularly carry out?
Create its own patch application plan for the server OS and apply patches itself in place of the service provider
Obtain the data center's entry and exit records once a month, retain them in-house, and prepare for external audits
Regularly inventory user IDs and the settings for file access rights and sharing scope, and remove those that are unnecessary
Regularly diagnose vulnerabilities in the application operated by the provider itself, and notify the provider of the results in writing
AnswerC. Regularly inventory user IDs and the settings for file access rights and sharing scope, and remove those that are unnecessary
According to the materials, management of user IDs, the settings for access rights and sharing scope, and the content of registered data are defined as Company A's responsibility. Therefore, continuing the inventory and inspection, just as with an in-house system, is Company A's role. OS patching, data center management, and application vulnerability response fall within the provider's area of responsibility and are not something Company A should perform in its place. Moving to the cloud does not eliminate the user side's responsibility.
Q10 | Sharing Settings
Company A's marketing department uses cloud storage to exchange files with an outside production company. How sharing is done is left to each staff member, and H, the department's information security leader, inspects the list of sharing settings once a quarter. This time's list is as follows. Row 1 is a product catalog already published on the website. Row 2 is a customer list containing the names, phone numbers, and email addresses of client contacts. Row 3 is a share designated to two named staff members at the production company, with an expiration date also set. Which item in this list should H correct first?
Row 1. Even for material that is already publicly available, a setting allowing anyone with the link to view it should be prohibited, so it should be restricted to internal use only
Row 3. Since this is shared with an outside party, cancel it immediately without waiting for the expiration date
Row 2. Since the client contacts' personal information is viewable by anyone who simply knows the link, cancel this sharing immediately
Row 4. Even for internal use, the meeting minutes' sharing scope should be limited to the author alone
AnswerC. Row 2. Since the client contacts' personal information is viewable by anyone who simply knows the link, cancel this sharing immediately
Row 2 puts an internal sales customer list into a state where anyone outside the company can view it simply by forwarding the link, directly leading to a personal information leak, so it should be cancelled with the highest priority. Row 1 is already publicly available material, so link sharing does not create a new leak. Row 3 is an appropriate share with named recipients, authentication, and an expiration date, and is needed for business purposes. Restricting Row 4 to the author alone would make the departmental sharing needed for the work impossible.
Q11 | Shadow IT
When Company A's information systems department tabulated the logs of the proxy that relays communications from inside the company to the internet, it found use of services the company had not approved. The tabulation results are as follows. Interviews found that the PDF conversion site was used by sales administration staff to merge and split contract PDFs, and that the approved in-house software could not do the same work. The translation site was used to translate emails from an overseas business partner. Neither staff member was aware that this was prohibited by regulation. As the information security leader, what should be done first?
Check the actual usage and business need, prepare a safe means as a company to do the same work, define in regulation which services may be used, and communicate this
For the approved cloud storage service with the largest volume of outbound traffic, set an upper limit on usage volume by department
Identify the users one by one, take disciplinary action under the work rules, and announce this fact company-wide so the same thing is not repeated
Immediately block all unapproved destinations, without specifically providing the reasons for blocking or guidance on alternative means
AnswerA. Check the actual usage and business need, prepare a safe means as a company to do the same work, define in regulation which services may be used, and communicate this
Much shadow IT begins in order to get work done, so unless the need is checked and an alternative is provided, blocking or discipline alone will just create another workaround. Grasping the actual situation, providing an alternative, and positioning it in regulation with communication is the proper approach. Leading with discipline makes it harder to report or consult, and blocking immediately with no alternative halts business. Limiting usage volume for an approved service is unrelated to the problem of use of unapproved services.
Q12 | Firewall Rules
In introducing telework, Company A made it possible to connect from outside the company via a VPN device to an internal business server (192.168.10.20). Telework users are assigned an address in the 10.8.0.0/24 range when connecting via VPN, and use of the business server is limited to HTTPS (tcp/443) via browser. Remote desktop (tcp/3389) on the business server is operated so that it is used only by maintenance staff on the internal LAN (192.168.10.0/24). The firewall rules placed at the boundary of the internal LAN, VPN, and internet are as follows, evaluated in order from the top, with any traffic matching no rule blocked by the implicit deny at the end. In light of the principle of least privilege, which rule should be reviewed first?
ファイアウォールのルール(上から順に評価。最後は暗黙の拒否)
番号 送信元 宛先 プロトコル/ポート 動作1 192.168.10.0/24 インターネット tcp/443 許可2 10.8.0.0/24 192.168.10.20 tcp/443 許可3 any 192.168.10.20 tcp/3389 許可4 10.8.0.0/24 192.168.10.30 tcp/445 拒否5 any any any 拒否(暗黙)
Rule 2. It does not identify telework users individually but grants a blanket allow at the network level, so this rule should be deleted immediately
Rule 1. It allows all HTTPS from the internal LAN to the internet, so there is a risk that traffic unnecessary for business could also go out
Rule 4. It denies file sharing (tcp/445) from telework users to another internal server (192.168.10.30), but since this is also needed for telework, change it to allow
Rule 3. Since the source is 'any,' it also accepts remote desktop from the internet side. Restrict the source to the internal LAN
AnswerD. Rule 3. Since the source is 'any,' it also accepts remote desktop from the internet side. Restrict the source to the internal LAN
Rule 3 has a source of 'any,' and since rules are evaluated in order from the top, this allows the internet side to reach the business server's remote desktop. Since operations dictate that only internal LAN maintenance staff should use it, restricting the source to 192.168.10.0/24 is the top priority. Rule 1 is needed for viewing the web from inside the company, and Rule 2 is the minimum allowance needed for telework. Changing Rule 4 to allow would widen the range reachable from outside the company, contrary to the decision that business server use is HTTPS only, running counter to least privilege.
Q13 | At Contract Termination
Company A is cancelling the cloud attendance management service it has used for 3 years and switching to another provider's service. The current service stores the names, affiliations, working hours, and payroll-calculation source data of about 400 employees. The contract includes a clause on the handling of data at contract termination. I, the information security leader in the general affairs department, has been put in charge of the cancellation procedure. Three years of attendance records must be carried over to the new service. What should I do when cancelling?
In accordance with the contract clause, receive the return of the company's own data in a format usable for migration, and confirm via a document such as a certificate of destruction that the data, including backups, has been erased on the provider's side
Assume that cancelling automatically erases the provider's data along with the account, and proceed only with the cancellation procedure without any special confirmation of return or erasure
Have the data left as is on the provider's side even after cancellation, and have it made available again by re-contracting whenever the 3 years of records are needed
Open the admin screens in order, save screenshots of all of them, treat that as the 3 years of records, and skip both the request for data return to the provider and confirmation of erasure
AnswerA. In accordance with the contract clause, receive the return of the company's own data in a format usable for migration, and confirm via a document such as a certificate of destruction that the data, including backups, has been erased on the provider's side
At contract termination, both return of data in a format the company can use and confirmation of reliable erasure on the provider's side (including backups) are needed, and this should be documented via something like a certificate of destruction. Assuming it disappears automatically leaves the danger of personal information remaining on another company's servers unaddressed. Screenshots cannot be used to migrate to the new service and are insufficient as records. Having the data remain with the provider after cancellation means continuing to leave personal information in a place beyond the company's control, which is inappropriate.
Q14 | Telework
Company A permits work from home and work while out of the office, and issues company-owned laptops to employees. VPN is mandated for connecting to internal systems, but specific behavioral guidance was left to each individual's judgment. J, the information security leader, has been writing down actual working practices reported by employees to reflect them in regulations. The items written down concern working at home, working at a cafe while out, and the operation of web conferencing. Which of the following is inappropriate as telework behavior?
At home, use only the company-issued laptop for work, and do not save business data on a PC shared with family
Lock the screen even for a brief absence, and use a privacy filter in places where other people are nearby
Record web conferences only after confirming the need in advance, and limit where recorded data is stored and who it can be shared with
While out at a cafe, connect to the shop's public Wi-Fi and connect directly to the internal system without using VPN to work
AnswerD. While out at a cafe, connect to the shop's public Wi-Fi and connect directly to the internal system without using VPN to work
Public Wi-Fi carries the risk of communications being intercepted, and connecting directly to an internal system without using an encrypted route such as VPN leads directly to an information leak, so it is inappropriate. Using a company-issued device, locking the screen when stepping away with a privacy filter, and confirming the need for recording along with limiting the storage location and sharing scope are all basic behaviors required for telework.
Q15 | BYOD
In Company A's sales department, there is a strong desire to check company email while out, and several employees, on their own judgment, had set up their company email account on their personal smartphones. The company was unaware of this situation and has no regulation on the business use of personally owned devices. Since sales department employees spend most of the day outside the office, uniformly prohibiting the use of personal devices would delay responses to customer inquiries and disrupt business. On the other hand, some personal devices do not have a screen lock set, and the company has no means to remotely wipe them if lost. Of the responses proposed by the information security leader, which is most appropriate?
Without the company deciding whether to permit business use of personal devices, notify all employees to report only when a device is lost, leaving all subsequent handling to each individual's judgment
Define in regulation the conditions for permitting business use of personal devices (screen lock setting, MDM installation, consent to remote lock/wipe, scope of business data storage), and permit use only for devices that have been applied for and approved
Since personal devices are not company assets, continue to leave the screen lock setting and usage to each employee's judgment
For employees who can verbally confirm that they do not store business data on the device, permit use of company email on a personal device without any application or regulation, and leave the screen lock setting to the individual's judgment
AnswerB. Define in regulation the conditions for permitting business use of personal devices (screen lock setting, MDM installation, consent to remote lock/wipe, scope of business data storage), and permit use only for devices that have been applied for and approved
A situation where there is a business need but no regulation breeds shadow IT that cannot be tracked. Defining the conditions for permission in regulation and limiting it to devices that have applied and been approved allows business to continue without interruption while enabling safeguards such as remote wipe upon loss. Leaving it to individual judgment, settling for verbal confirmation, or requiring only a loss report without deciding on permission all leave the company unable to grasp or manage the state of the devices, with no recourse when one is lost.
Q16 | Device Loss
K, an employee of Company A, left his bag containing his company-issued laptop on the luggage rack of a train on the way back from a business trip, and only noticed after leaving the station. The laptop stores materials for negotiations with customers and also has VPN settings for connecting to the internal system. It is 8 p.m. on a weekday, and the information systems department staff have already left for the day, but Company A has a 24-hour emergency contact point, which K knows how to reach. The laptop has screen lock and disk encryption set, and supports remote lock and remote wipe via MDM. What should K do first?
Since there is a chance it will be found by the next morning, limit himself that day to inquiring with the railway company, and report to his supervisor at the next morning's meeting
To avoid causing trouble for the company, purchase the same model of laptop at his own expense so he can continue working, then report everything together at a later date
Do not report to the company until it is certain the device is lost, and focus first on filing a lost-property report with the police
Report immediately to the designated emergency contact point and request remote lock or remote wipe of the device and suspension of the account
AnswerD. Report immediately to the designated emergency contact point and request remote lock or remote wipe of the device and suspension of the account
In the event of loss, time is of the essence; reporting to the contact point the moment it is noticed and carrying out remote lock/wipe and account suspension minimizes the damage. If the device is found, it can simply be returned, so there is no benefit to waiting. Reporting the next morning or not reporting until loss is certain allows misuse in the meantime. Buying a replacement at one's own expense does nothing to protect the information on the lost device and only worsens the biggest problem, which is delayed reporting.
Q17 | Misdirected-Email Prevention
A sales staff member at Company A sent an email announcing the company's seminar to contacts at 42 client companies. In doing so, all 42 email addresses were entered in the To field for a single batch send, so each recipient could see the names and email addresses of the contacts at the other companies. One client pointed this out, and it was reported as an incident. Company A had no written rule on the method for mass mailing to outside parties, and pre-send checking was left to each individual. Similar incidents have occurred twice before, and a caution notice was issued each time, but the problem has recurred. Which of the following is the most appropriate recurrence-prevention measure?
Define in internal regulation a procedure that, upon noticing a misdirected send, immediately sends a deletion request email to the same recipients and confirms by phone that it was deleted
Have the staff member who caused the misdirected send submit a written apology, and distribute a caution notice describing the incident to the whole company
Notify company-wide that the email software's address auto-complete feature should be enabled for everyone, to prevent address entry mistakes
Define in regulation that BCC must be used for mass sends to multiple outside recipients, and combine this with a mechanism holding sends for a few minutes and requiring supervisor confirmation when the number of recipients exceeds a set threshold
AnswerD. Define in regulation that BCC must be used for mass sends to multiple outside recipients, and combine this with a mechanism holding sends for a few minutes and requiring supervisor confirmation when the number of recipients exceeds a set threshold
Since caution notices alone have not stopped recurrence, a mechanism combining a written BCC rule with a send-hold and supervisor confirmation is needed to actually stop it. A deletion-request email cannot erase information already in the recipient's hands and is merely an after-the-fact response. Address auto-complete is a cause of misdirected sends by picking a different person with a similar name, and is counterproductive as a measure. A written apology and caution notice are simply a repeat of responses that have already proven ineffective.
Q18 | PPAP
Company A has for years followed the practice of always compressing attached files into a password-protected ZIP when sending files to outside parties, and immediately afterward sending a second email to the same recipient containing only the password. Last month, a staff member sent to the wrong recipient by mistake, and then also sent the password email to the same wrong recipient, resulting in the file reaching a third party in a readable state. Also, several client companies have reported that "for security reasons, we have set our system not to accept attached password-protected ZIP files." Company A's information security leader is considering revising this practice. Which of the following is the most appropriate direction for the revision?
Since the problems are that the file and password are sent over the same channel and that an encrypted ZIP evades the recipient's virus scanning, switch to a different delivery method, such as shared storage that designates and authenticates the recipient
Decide a fixed password in advance with each client and share it, while continuing to send files attached to email as before
Increase the password length from 8 to 16 characters, and otherwise continue the current practice of sending in two separate emails
Have the password conveyed verbally by phone, discontinue the second email, continue attaching encrypted ZIP files going forward, but for recipients whose systems cannot accept encrypted ZIP files, attach the file to the email without encryption
AnswerA. Since the problems are that the file and password are sent over the same channel and that an encrypted ZIP evades the recipient's virus scanning, switch to a different delivery method, such as shared storage that designates and authenticates the recipient
Sending the password over the same email channel is ineffective against both eavesdropping and misdirection, and an encrypted ZIP fails to pass the recipient's virus scanning, causing inconvenience to clients as well. Switching to a shared method that designates and authenticates the recipient is the fundamental solution. Making the password longer does not change the flaw of using the same channel. Sending unencrypted attachments only makes things worse by dropping encryption altogether. A fixed password is dangerous because once it leaks, every subsequent file becomes readable.
Q19 | Targeted Email
L, in Company A's accounting department, received an email under the name of a contact at a business partner, with the subject "There was an error in the invoice. The corrected version is attached." The body referenced past exchanges, so L opened the attached file, at which point something like a warning briefly appeared and then nothing further happened. Feeling uneasy, L checked the sender's address again and noticed it was a different domain closely resembling the client's domain. Company A has a reporting point for information security matters, and its extension number is well known. L's terminal is connected to the internal LAN by wire, and wireless LAN is also enabled. What should L do first?
Run a full scan of the device with antivirus software oneself, and if nothing is detected, do not report to the reporting point
To prevent the same harm to others, forward the received email as-is to everyone in the department, cautioning them not to open it
To prevent the damage from spreading, shut down the device immediately, and bring it to the information systems department the next morning to consult
Disconnect the device from the network, both wired and wireless, without turning off the power, and contact the designated reporting point immediately
AnswerD. Disconnect the device from the network, both wired and wireless, without turning off the power, and contact the designated reporting point immediately
For a device that may be infected, communications should first be cut to prevent the damage from spreading and information from being sent outside, and the power should be left on so information needed for investigation is not lost, before reporting to the reporting point. Deciding not to report if a self-run scan detects nothing risks missing malware the scan cannot detect. Shutting down loses traces in memory, and leaving it until the next morning is too slow. Forwarding a suspicious email increases the number of people who might open it.
Q20 | Choosing a Delivery Method
Company A needs to hand a roster file containing respondents' names, addresses, and phone numbers to two staff members at a production company to which it has outsourced survey tabulation. Company A's regulations state that when providing personal information to an outside party, a method must be used that can limit who receives it and that leaves a record under the company's control, and using a service an individual has personally contracted for business purposes is prohibited. The staff compared the following four methods. D is an online storage service the staff member has personally contracted, and the company cannot track its usage. B's public link can be downloaded by anyone who knows the URL. Based on this comparison table, which is the most appropriate way to hand over the roster file?
A. Since the file is encrypted, it is safe regardless of the route, and it is better that no record of retrieval remains, so as not to leave unnecessary information behind
B. Since both an expiration date and a retrieval record remain, it is enough to notify the two staff members of the shared link by email
C. It can limit recipients to the two named staff members, and both an expiration date and a retrieval record remain under the company's control, satisfying the regulatory requirements
D. The staff member is used to it, and both an expiration date and a retrieval record can be kept, making it the most reliable way to deliver it
AnswerC. C. It can limit recipients to the two named staff members, and both an expiration date and a retrieval record remain under the company's control, satisfying the regulatory requirements
The regulation requires both the ability to limit recipients and that the record of the handover remain under the company's control, and only C satisfies both. A cannot limit recipients and leaves no record. B can be retrieved by anyone if the link is forwarded, so recipients cannot be limited. D can limit recipients and keep a record, but it is not under the company's control, and using a personally contracted service for business is prohibited by regulation, so it cannot be chosen.
Q21 | Provision to Outside Parties
Company A's sales department received a phone call from someone claiming to be a contact at client company B. The caller said, "I accidentally deleted the customer list file you sent us last month. I need it today, so please call me back at this number and resend it to my email address." The staff member who answered does recall that materials were indeed provided to Company B, but this was not a case the staff member personally handled. Company A's regulation requires obtaining approval from the information manager when providing information containing personal data to outside parties. The caller repeatedly stresses that this is urgent. What is the most appropriate response for this staff member to take?
Do not send it on the spot; call back not the number given over the phone but Company B's known contact point to confirm whether the request is genuine, and respond after obtaining approval from the information manager in accordance with regulation
Since this is the same content that has been provided before, resend it on the spot at the staff member's own discretion
Since the other party is in a hurry, send the file first and obtain the information manager's approval afterward
Since sending it with a password protects the content, call back at the number given over the phone and send it, omitting the approval procedure from the information manager
AnswerA. Do not send it on the spot; call back not the number given over the phone but Company B's known contact point to confirm whether the request is genuine, and respond after obtaining approval from the information manager in accordance with regulation
Since there are schemes that extract information by impersonating a business partner, the fact of the request must be confirmed through the company's own known, legitimate contact point rather than the contact point specified by the caller. Obtaining approval as required by regulation afterward is the correct order. Sending it on the spot because of past dealings, deferring approval because of urgency, or skipping approval because a password was added all leave the risk of both impersonation and a regulatory violation.
Q22 | Taking Out Media
Company A requires that, when taking electronic data outside the company, prior approval must be obtained from a supervisor, an encryption-capable USB drive or laptop issued by the company must be used, and the removal must be recorded in a removal log. Business use of personally owned storage media is prohibited, and the rule is that removed media must be returned as soon as the work is finished, with the return date entered in the log. The approver is defined as the department head (section chief or department manager), and the approver does not change depending on the content of the information taken out. Last month, in the sales department, a USB drive storing a customer list went missing, and it was decided to inspect the removal log every month. When the general affairs department's information security leader inspected this month's removal log, the following records were found. Which record in this log is inappropriate under the regulation?
No.2. It uses a personally owned medium, which is prohibited, has neither encryption nor supervisor approval, and has no return record
No.1. Even for material to be distributed at an exhibition, if it is being taken outside the company it must be sent by mail rather than on media
No.4. Since the quotation copy is confidential, it must not be taken out even if encrypted
No.3. A section chief approved the removal of meeting slides, but the approver must always be a department manager
AnswerA. No.2. It uses a personally owned medium, which is prohibited, has neither encryption nor supervisor approval, and has no return record
No.2 fails to satisfy any of the regulatory requirements — prohibition of personal media, encryption, prior supervisor approval, and a return record in the log — and moreover what was taken out was a customer list. No.1, No.3, and No.4 all have an issued medium, encryption, supervisor approval, and a return record in place, and do not violate the regulation. There is no rule in this regulation limiting the approver to a department manager or uniformly banning the removal of confidential material.
Q23 | Paper and Visitors
Company A holds meetings with outside business partners in a meeting room in a corner of the office floor. The route to the meeting room runs from reception through the office floor, passing rows of employees' desks along the way. Recently, a visitor noticed and commented on the estimated amount for an unrelated matter left on the meeting room whiteboard, prompting the information security leader to review operations. At the same time, the department is reviewing the storage and disposal of paper documents and the procedure for receiving visitors. The office floor has a shredder installed and also a collection box for outsourced pulping of confidential documents. Which of the following practices is inappropriate?
When taking paper documents outside the company, put them in an envelope that hides the contents and carry them in a lockable bag
Tear an unneeded customer list by hand into small pieces and throw it into the general waste bin on the office floor
Issue and record a visitor pass at reception, and always have an employee accompany the visitor throughout the office area
Before receiving a visitor, erase what is written on the meeting room whiteboard and tidy up materials left out on the desk
AnswerB. Tear an unneeded customer list by hand into small pieces and throw it into the general waste bin on the office floor
Paper merely torn by hand can be reconstructed, and general waste carries the risk of being taken away, so personal information such as a customer list must be disposed of via a shredder or a pulping collection box. Issuing a visitor pass with employee escort, clearing the whiteboard and desks before receiving visitors (clear desk), and carrying documents in a sealed envelope inside a lockable bag are all appropriate practices.
Q24 | Social Media Post
An employee of Company A posted photos of a departmental get-together on a personal social media account. In the background of the photos, an unannounced new product's code name and planned launch timing written on the meeting room whiteboard, and documents bearing a client's name left on a desk, were inadvertently visible. The post came to light after a tip from an outside third party and was quickly deleted, but by then it had already been reposted elsewhere. Company A does not prohibit personal social media use and has no rules regarding posts. The employee had no malicious intent and had not noticed the items in the background. What is the most appropriate measure going forward?
Establish rules requiring that photos taken inside the company be checked for background items before posting, and that business-related posts obtain prior approval from the public relations department, and provide education using this actual case as an example
As long as company names, client names, and individual names are omitted, business-related matters, including content about the unannounced product, may continue to be posted freely on personal social media as before
Since posting on a personal account is a matter of individual freedom, the company should not set rules on photography or posting and should not get involved
Since a post stops spreading once deleted, define and communicate only a practice of having the person delete it upon discovery
AnswerA. Establish rules requiring that photos taken inside the company be checked for background items before posting, and that business-related posts obtain prior approval from the public relations department, and provide education using this actual case as an example
Since the cause this time was not malice but a lack of awareness about background items and the absence of rules, it is effective to establish rules for a pre-post background check and approval for business-related posts, and to educate staff using this actual case. A policy of non-involvement will not stop recurrence. Omitting names does not solve the problem, since the content of the unannounced information itself is the leak. A once-published post can be reposted, so relying only on deletion afterward is insufficient.
Q25 | Generative AI Use
At Company A, there were many complaints that preparing meeting minutes and drafting documents takes a long time, and several departments had begun using free conversational generative AI services under individual accounts. In one department, meeting minutes containing customer names, transaction prices, and an unannounced rollout schedule were pasted in as-is to be summarized. This service's terms state that input content may be used to improve the service. There is no company-wide usage rule, neither prohibiting nor permitting it. Expectations for efficiency gains are high, and a simple ban risks people continuing to use it anyway. Of the responses proposed by the information security leader, which is the most appropriate?
Since it helps improve efficiency, continue to leave the choice of service and the scope of information entered to each individual's judgment
Set only the masking of customer names as a company-wide rule, allow transaction prices and unannounced rollout schedules to continue to be entered as before, and let each individual freely choose which service to use
Define in regulation the scope of information that may be entered, prohibiting entry of confidential and personal information, provide as a company a corporate-grade service under a contract in which input content is not used for training, and require that output always be checked by the person in charge
Notify the whole company by email of a complete ban on using generative AI, and leave subsequent handling to each department's judgment
AnswerC. Define in regulation the scope of information that may be entered, prohibiting entry of confidential and personal information, provide as a company a corporate-grade service under a contract in which input content is not used for training, and require that output always be checked by the person in charge
Since input to generative AI is equivalent to providing information to an outside party, it is effective to draw a clear line in regulation on what information may be entered, and to provide a corporate service, arranged by the company, that does not use input for training, creating a safe path. Requiring a check of output also prevents errors from creeping in. Leaving it to individual judgment merely ratifies the status quo. Masking only customer names still leaves prices and unannounced schedules as confidential information. A blanket ban with only a notice, lacking an alternative, drives use underground into unmanageable shadow IT.
Practice: answer the questions on this page
This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.
* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.
This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original