Free Practice Questions for Engineer Information Security
Exam-style questions and explanations by OpenExamPrep.
Loading practice questions...
Key Facts: Engineer Information Security Exam
100 items
Official written paper length (5 subjects × 20)
KCA CQ examination specification
150 minutes
Written timing at 30 minutes per subject
KCA CQ Engineer-grade test regulations
40 / 60
Written per-subject floor (과락) and overall average
National Technical Qualifications Act Enforcement Decree
KRW 19,400
Written registration fee on KCA CQ portal
KCA CQ portal fee schedule (checked 2026)
KRW 22,600
Practical registration fee on KCA CQ portal
KCA CQ portal fee schedule (checked 2026)
2 years
Written-pass exemption period from pass announcement
National Technical Qualifications Act Enforcement Decree Article 21
정보보안기사 is South Korea's national technical qualification for information security engineers, administered by KCA on the KCA CQ portal under MSIT. The 2026 written CBT consists of 100 four-option MCQs across 5 subjects (150 minutes) requiring a 40-point subject floor and a 60-point overall average, followed by a 3-hour descriptive practical exam in 정보보안 실무. Official fees are KRW 19,400 written and KRW 22,600 practical on the KCA CQ portal. OpenExamPrep provides independent English MCQ study practice, not an official translation or practical subjective simulation.
Sample Engineer Information Security Practice Questions
Try these sample questions to review concepts for the Engineer Information Security exam. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1In Unix and Linux file permission architectures, what is the primary operational effect and security implication when the SetUID (Set User ID, 4000) permission bit is configured on an executable binary file?
2In modern Linux distributions, what does the identifier prefix `$6$` in the password field of the `/etc/shadow` file signify?
3In Linux Pluggable Authentication Modules (PAM) configuration, what is the precise behavior of a module designated with the `required` control flag if its authentication check fails?
4Which Linux system log file records all bad (failed) login attempts and must be inspected using the specialized `lastb` binary reader command?
5How does the Stack Canary (StackGuard) compiler mitigation mechanism detect and prevent stack-based buffer overflow exploitation?
6In the Windows security architecture, what is the core functional difference between a Discretionary Access Control List (DACL) and a System Access Control List (SACL) within an object's security descriptor?
7In standard Linux cron daemon security administration, how is user access evaluated when both `/etc/cron.allow` and `/etc/cron.deny` exist on the system?
8A privileged root daemon checks if `/tmp/report.tmp` exists using `access()`, and if absent, creates it using `open("/tmp/report.tmp", O_WRONLY | O_CREAT, 0644)`. How can a local unprivileged attacker exploit this Time-of-Check to Time-of-Use (TOCTOU) race condition?
9An administrator wants to ensure that a Linux security audit log file can only have new records appended, preventing any user—including root—from modifying, truncating, or deleting existing entries. Which command achieves this?
10In modern Windows Server operating systems, which Event ID in the Security log specifically identifies a failed user account logon attempt?
About the Engineer Information Security Exam
Engineer Information Security (정보보안기사) is South Korea's premier Engineer-grade national technical qualification in cybersecurity and information protection, administered by the Korea Communications Agency (KCA / 한국방송통신전파진흥원) on the KCA CQ portal under the Ministry of Science and ICT (MSIT). The written CBT paper tests candidates across five 20-question subjects: System Security, Network Security, Application Security, Information Security Fundamentals, and Security Management & Regulations. Candidates clearing the written stage undertake a demanding 3-hour descriptive practical examination in working-level cybersecurity practice (정보보안 실무). Note that administration was transferred from KISA to KCA in 2022 onto the KCA CQ portal. The practice bank provided here consists of independent English-language multiple-choice questions designed for study and review; it is not an official translation or practical subjective examination simulation.
Exam sponsor: Korea Communications Agency (KCA / 한국방송통신전파진흥원) / Ministry of Science and ICT. The requirements and fees below concern the certification or admission exam, separate from our free practice resources.
Assessment
Written paper covering 시스템 보안, 네트워크 보안, 어플리케이션 보안, 정보보안 일반, and 정보보안 관리 및 법규 (20 items and 30 minutes each, totaling 150 minutes), followed by a 3-hour written descriptive practical examination in 정보보안 실무. Administration was transferred from KISA to KCA in 2022 on the KCA CQ portal.
Time Limit
150 minutes written; 3 hours practical
Passing Score
Written: 40+ per subject floor and 60 average; practical: 60/100
Exam / Certification Fees
KRW 19,400 written / KRW 22,600 practical (KCA CQ portal (cq.or.kr), 2026)
Exam sponsor websiteFees, eligibility, and exam policies can change. Confirm them with the exam sponsor before applying or paying.
Official sources
- KCA CQ Portal (한국방송통신전파진흥원 국가기술자격검정) · Source checked 2026-09-21Official qualifications portal for Engineer Information Security (정보보안기사), covering exam schedules, eligibility review, written CBT booking, and practical registration.
- Ministry of Science and ICT (과학기술정보통신부 / MSIT) · Source checked 2026-09-21Supervising government ministry establishing national technical qualification standards and cybersecurity legal frameworks in South Korea.
- KISA ISMS-P Certification Portal · Source checked 2026-09-21Official criteria, guidelines, and certification requirements for the Korea Information Security Management System & Personal Information Protection Management System (ISMS-P).
- National Law Information Center (국가법령정보센터) · Source checked 2026-09-21Full statutory texts for the Personal Information Protection Act, Information and Communications Network Act, and Infrastructure Protection Act.
- National Technical Qualifications Act Enforcement Decree Article 21 · Source checked 2026-09-21Two-year exemption rule from the date of written examination pass announcement.
Our practice resources: topics covered
We aim to reflect publicly available exam outlines and topic information in our study resources. Coverage, format, and difficulty may differ from the actual exam, and we cannot guarantee that every detail is accurate or current. Confirm exam requirements, fees, and policies with the official exam sponsor.
System Security (시스템 보안)
Operating system architecture, OS hardening, Linux and Windows security administration, account and privilege management, access control matrices, system vulnerabilities, malware analysis, and system audit logging.
Network Security (네트워크 보안)
OSI and TCP/IP protocol security, network attack vectors (DoS/DDoS, spoofing, sniffing, scanning), firewalls, IDS/IPS, UTM, VPN (IPsec, SSL/TLS), wireless network security (WPA2/WPA3, 802.1X), and network monitoring.
Application Security (어플리케이션 보안)
OWASP Top 10 vulnerabilities (SQLi, XSS, CSRF, SSRF), secure software development lifecycle (Secure SDLC), database security controls, web server configuration, email security protocols (SPF, DKIM, DMARC, S/MIME, PGP), and electronic commerce security.
Information Security Fundamentals (정보보안 일반)
Information security CIA triad, classical ciphers, symmetric key cryptography (DES, AES, SEED, ARIA), asymmetric cryptography (RSA, ECC, Diffie-Hellman), cryptographic hash functions and MAC, PKI and digital certificates, and access control models (DAC, MAC, RBAC, Bell-LaPadula, Biba).
Security Management and Regulations (정보보안 관리 및 법규)
Information security management systems (ISMS-P, ISO/IEC 27001), risk assessment methodologies, business continuity planning and disaster recovery (BCP/DRP), Personal Information Protection Act (개인정보 보호법), Information and Communications Network Act (정보통신망법), and related Korean cybersecurity regulations.
Preparing for the Engineer Information Security Exam
What You Need to Know
- Passing score: Written: 40+ per subject floor and 60 average; practical: 60/100
- Assessment: Written paper covering 시스템 보안, 네트워크 보안, 어플리케이션 보안, 정보보안 일반, and 정보보안 관리 및 법규 (20 items and 30 minutes each, totaling 150 minutes), followed by a 3-hour written descriptive practical examination in 정보보안 실무. Administration was transferred from KISA to KCA in 2022 on the KCA CQ portal.
- Time limit: 150 minutes written; 3 hours practical
- Exam / certification fees: KRW 19,400 written / KRW 22,600 practical (KCA CQ portal (cq.or.kr), 2026) Official sources
Using Our Practice Resources
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
Engineer Information Security: Suggested Study Strategy
Frequently Asked Questions
What is Engineer Information Security (정보보안기사)?
Engineer Information Security (정보보안기사) is South Korea's highest technical-level cybersecurity qualification under the National Technical Qualifications Act, certified under the Ministry of Science and ICT (MSIT). It validates expertise in safeguarding critical operating systems, network perimeters, enterprise applications, cryptographic implementations, and institutional compliance with Korean privacy and cyber laws.
Who administers the examination in 2026, and how was it transitioned?
The examination was originally developed and administered by the Korea Internet & Security Agency (KISA). Effective 2022, administration of both the Engineer Information Security and Industrial Engineer Information Security examinations was officially transferred to the Korea Communications Agency (KCA / 한국방송통신전파진흥원), with registrations and score records processed through the CQ portal (www.cq.or.kr).
How is the written CBT examination structured and scored?
The written paper consists of 100 multiple-choice questions divided equally across five subjects (20 items each): System Security, Network Security, Application Security, Information Security Fundamentals, and Security Management & Regulations. The test duration is 150 minutes (30 minutes per subject). To pass, candidates must score at least 40 points out of 100 in every single subject (avoiding 과락) and achieve an overall mean score of 60 points or higher.
What is the format of the practical stage (실기시험)?
The practical stage is a demanding 3-hour descriptive and short-answer written examination (필답형) in Information Security Practice (정보보안 실무). It consists of single-answer identification questions, short-answer technical scenario questions, and in-depth working-level essay questions covering log analysis, packet analysis, firewall/snort configuration, attack mitigation, and legal compliance procedures. A score of 60 out of 100 is required to pass.
How long is a passing written score valid, and what is this English practice bank?
Under National Technical Qualifications Act Enforcement Decree Article 21, a written pass exempts the candidate from the written examination for 2 years from the date the pass is announced. The questions on this platform are an independent English-language MCQ practice bank created to help candidates master core technical concepts and Korean regulatory frameworks. It is not an official translation, not a CBT simulation, and not a substitute for the practical written examination.