Oct 10, 2023

Skill Assessment - AWS Q3

過去問ソース

https://www.chase2learn.com/amazon-web-services-linkedin-assessment/

ネットで見つけた過去問の解答にひっかかりを感じたら、ChatGPT解答を比較し、学習を深めることにする。


Q2. Which database is a NoSQL database type that can quickly store and retrieve key-value pairs?

Aurora

Neptune

RDS for MySQL

DynamoDB

 

ChatGPT

The NoSQL database type that can quickly store and retrieve key-value pairs is DynamoDB.


What do you describe other database systems?

 

ChatGPT

Other database systems typically refer to a broad category of database management systems (DBMS) that are not specifically NoSQL databases. Here's an overview of different types of database systems:


1.     
Relational Databases (RDBMS): These databases use a structured, tabular format to store data. They are based on the relational model and use SQL (Structured Query Language) to query and manipulate data. Examples include MySQL, PostgreSQL, Microsoft SQL Server, and Oracle Database.

2.     Document Stores: Document databases are NoSQL databases that store data in a semi-structured format, usually as JSON or XML documents. Each document can have a different structure, making them flexible for unstructured or semi-structured data. Examples include MongoDB and Couchbase.

3.     Key-Value Stores: These databases store data as a collection of key-value pairs, making them simple and efficient for basic read and write operations. Examples include Redis, Riak, and Amazon DynamoDB.

4.     Column-Family Stores: Column-family databases are NoSQL databases optimized for storing and retrieving large volumes of data with high write and read performance. They are used for time-series data, sensor data, and other use cases. Examples include Apache Cassandra and HBase.

5.     Graph Databases: These databases are designed for managing and querying data with complex relationships. They use graph structures to represent and navigate data, making them suitable for applications like social networks, recommendation engines, and fraud detection. Examples include Neo4j and Amazon Neptune.

6.     In-Memory Databases: These databases store data primarily in memory (RAM) for extremely fast data access and low-latency operations. Examples include Redis and Memcached.

7.     Time-Series Databases: Time-series databases are optimized for storing and querying time-stamped data, making them suitable for applications that need to analyze data over time, such as IoT, monitoring, and analytics. Examples include InfluxDB and TimescaleDB.

8.     NewSQL Databases: NewSQL databases aim to combine the scalability benefits of NoSQL databases with the transactional and consistency guarantees of traditional RDBMS. Examples include Google Spanner and CockroachDB.

9.     Search Engines: While not traditional databases, search engines like Elasticsearch and Apache Solr are used to index and search large volumes of text and structured data efficiently.

10.   Columnar Databases: These databases are designed for analytical workloads and store data in columnar formats, optimizing them for analytical queries and data warehousing. Examples include Amazon Redshift and ClickHouse.

The choice of database system depends on the specific requirements of an application, including data structure, query patterns, scalability, and performance considerations. Different database systems are optimized for different use cases and data models.


What do you describe these 3 databases?

1. Aurora

2. Neptune

3. RDS for MySQL

 

ChatGPT

Certainly, I can provide descriptions for each of these three database services offered by Amazon Web Services (AWS):

1.     Amazon Aurora:

·  Amazon Aurora is a fully managed, relational database service provided by AWS.

·  It is compatible with both MySQL and PostgreSQL, meaning it can be used as a drop-in replacement for these database engines.

·  Aurora is known for its high performance and availability, with capabilities for automatic failover, replication, and automated backups.

·  It offers features like read replicas and global databases to distribute workloads and enable cross-region replication.

·  Aurora is designed to deliver performance that is typically greater than standard MySQL or PostgreSQL databases while maintaining high availability and reliability.

2.     Amazon Neptune:

·  Amazon Neptune is a fully managed graph database service by AWS.

·  It is optimized for storing and querying data with complex relationships, making it well-suited for applications that require graph-based modeling, such as social networks, recommendation systems, and knowledge graphs.

·  Neptune supports two popular graph query languages: Apache TinkerPop Gremlin and W3C's SPARQL.

·  It is highly available and allows for read replicas, automatic backups, and data encryption at rest and in transit.

·  Neptune is compatible with both property graph and RDF (Resource Description Framework) data models.

3.     Amazon RDS for MySQL:

·  Amazon RDS (Relational Database Service) for MySQL is a managed relational database service that focuses on MySQL, one of the most widely used open-source relational database management systems.

·  RDS for MySQL simplifies database administration tasks like patching, backups, and scaling, making it easier to operate MySQL databases in the AWS cloud.

·  It provides features such as automated backups, Multi-AZ (Availability Zone) deployments for high availability, and read replicas for offloading read traffic.

·  RDS for MySQL is a suitable choice when you need a MySQL database in a managed environment without the overhead of handling infrastructure and administrative tasks.

These services cater to different database needs. Aurora and RDS for MySQL are relational database services, while Neptune is a graph database service. The choice between them depends on the specific requirements of your application, such as data model, query patterns, scalability, and performance considerations.

 

Q3. Your database is an RDS instance running SQL Server with Multi-AZ replication 

and you have several older .NET console utilities that perform database operations every 15 seconds. 

When the cluster has to switch the primary database server to the secondary AZ, the .NET utilities start to report connection failures to the database although other applications are able to access the database. How do you correct this problem?

1.       Use the RDS console to force a reboot of the database instance so that the primary server becomes the master server again.

2.       The server running the .NET utilities is caching the DNS lookup on the database cluster address.

3.       Flush the DNS cache of the server and force the C# utilities to open new connections to the database. A.NET application will retain the IP address of a connection string until the host machine is rebooted.

4.      The NET utilities need to change the SQL Server endpoint in the connection strings to read from the secondary database server using a try/catch.

 

過去問解答は上記4。一方で3とするChatGPTの以下の説明に説得力を感じる。

 

ChatGPT

The issue with the .NET utilities reporting connection failures after a Multi-AZ failover in Amazon RDS can often be related to DNS caching. To address this problem, you should consider flushing the DNS cache on the server running the .NET utilities so that they can connect to the new primary server after the failover.

The correct option is:

B. The server running the .NET utilities is caching the DNS lookup on the database cluster address. Flush the DNS cache of the server and force the C# utilities to open new connections to the database.

Explanation:

When an RDS Multi-AZ failover occurs, the primary server's DNS record is updated to point to the new primary server in the secondary Availability Zone. However, some applications and services may cache DNS information, and they continue to attempt to connect to the old primary server. Flushing the DNS cache on the server running the .NET utilities will force it to re-resolve the DNS name, and it should be able to connect to the new primary server without issues.

Options 1 and 3 are not recommended:

1. Using the RDS console to force a reboot of the database instance is not a good solution because it's a disruptive action that could impact other applications. It's better to address the DNS caching issue on the server side.

3. The statement about .NET applications retaining the IP address of a connection string until the host machine is rebooted is not entirely accurate. It's the DNS cache on the server that needs to be refreshed, not the entire machine.

Option 4 is not a recommended solution for this problem:

4. Changing the SQL Server endpoint in the connection strings to read from the secondary database server using a try/catch is not a best practice for handling Multi-AZ failovers. DNS caching is a more common issue, and fixing it at the server level is a better approach. Additionally, using try/catch for this purpose may lead to inefficient error handling and a lack of automatic failover support.

上記4ChatGPT曰く「推奨しない」との事。かなり自信満々である。



前記Q3を改めて尋ねた(↓)

質問文は括弧箇所を省き下線部を加えた)。過去問解答とChatGPT解答に差異が有ったが、その後 別のQ&Aの後、ChatGPTの論旨に揺らぎが出るか見るためである。

 

Q3. (Your database is an RDS instance running SQL Server with Multi-AZ replication 

and you have several older .NET console utilities that perform database operations every 15 seconds.)
When the cluster has to switch the primary database server to the secondary AZ, the .NET utilities start to report connection failures to the database although other applications are able to access the database.
An operator used the NET utilities to change the SQL Server endpoint in the connection strings and to read from the secondary database server using a try/catch. Was that right action?

 

ChatGPT

Changing the SQL Server endpoint in the connection strings to read from the secondary database server and using a try/catch mechanism to handle connection failures is not the ideal solution to address the issue of .NET utilities reporting connection failures during a Multi-AZ failover in Amazon RDS. Here's why:

1.     Lack of Automatic Failover Handling: By manually changing the connection endpoint and using try/catch, you are essentially bypassing the built-in high availability features provided by Amazon RDS. RDS is designed to handle failovers automatically by promoting the secondary to the primary when necessary. Manually switching to the secondary server and catching exceptions may work temporarily but does not provide a robust, automatic failover solution.

2.     Loss of Real-Time Data: Depending on the nature of your application, manually switching to the secondary server can result in data inconsistencies. During a failover, the secondary may not be fully up to date with the primary, leading to potential data loss or inconsistencies.

3.     Maintenance Overhead: Manually managing database failovers can introduce operational complexity. You would need to monitor the health of the primary server, initiate the failover process, and ensure the secondary is synchronized and promoted to the primary when appropriate.

Instead, you should address the issue at the root cause, which is typically related to DNS caching on the server running the .NET utilities. Here's what you should do:

·  Flush DNS Cache: On the server running the .NET utilities, flush the DNS cache. This can often be done using system commands specific to the operating system (e.g., ipconfig /flushdns on Windows or systemd-resolve --flush-caches on Linux).

·  Proper Connection Handling: Ensure that your .NET utilities are using connection strings with the DNS endpoint or load balancer provided by Amazon RDS. These endpoints automatically switch to the current primary server during a failover without requiring manual intervention.

·  Error Handling: Implement proper error handling in your .NET applications to handle database connection errors gracefully. You can catch exceptions and retry connections if necessary, but avoid hardcoding the endpoint to a specific server.

By addressing the DNS caching issue and allowing Amazon RDS to handle failovers automatically, you can ensure the robustness and high availability of your database while minimizing the risk of data inconsistencies and operational overhead.

 

今回のQ3解答も前回同様で論旨に揺らぎは見られない。


Q7. For your AWS root account, 

you have generated a random password of the maximum allowed length and included special characters. Which additional steps should you take to secure your AWS root account?

1. Create an AM role for the account administrator with the highest privileges. Do not store the root password, but when the root account is needed reset the password on the root account via email confirmation and repeat this procedure.

2. Store your randomly generated password in your organizational secrets database using a service such as 1Password or LastPass, and only grant access to this secret to the DevOps team.

3. Create IAM accounts for your administrators and attach the AdministratorAccess policy to their accounts. Disable the root account in the user settings.

4. Create an IAM role for the account administrator with the highest privileges and do not use the root account in day-today operations. Enable two-factor authentication on the root account

 

ChatGPT

To secure your AWS root account, you should follow best practices that prioritize its protection and restrict its use. Let's evaluate the options:

1.     Create an AM role for the account administrator with the highest privileges. Do not store the root password, but when the root account is needed reset the password on the root account via email confirmation and repeat this procedure.

·  This approach suggests not storing the root password, but resetting it via email confirmation when needed. However, this method is not a recommended best practice for securing the root account, as it introduces operational inefficiencies and security risks.

2.     Store your randomly generated password in your organizational secrets database using a service such as 1Password or LastPass, and only grant access to this secret to the DevOps team.

·  This option is a more secure approach. Storing the root password securely in an organizational password manager and limiting access to the DevOps team is a good practice. However, additional steps are needed, such as enabling multi-factor authentication (MFA) on the root account.

3.     Create IAM accounts for your administrators and attach the AdministratorAccess policy to their accounts. Disable the root account in the user settings.

·  This is a strong security practice. By creating IAM accounts for administrators, you can better manage access control. Disabling the root account is a good security measure as well. However, it's essential to also enable MFA on the root account.

4.     Create an IAM role for the account administrator with the highest privileges and do not use the root account in day-to-day operations. Enable two-factor authentication on the root account.

·  This is the most secure and recommended approach. Using IAM roles for day-to-day operations is a best practice to minimize the use of the root account, and enabling MFA on the root account adds an extra layer of security.

Given the options, Option 4 is the best approach:

·  Use IAM roles for administrators for day-to-day operations to avoid relying on the root account.

·  Enable two-factor authentication (MFA) on the root account for an additional layer of security.

Options 2 and 3 provide some level of security, but Option 4 is the most comprehensive and aligns with AWS security best practices.


Q9. How do you architect a solution for an SQL Server database 

to be replicated across AWS regions in an active-active architecture?

  1. Use RDS for SQL Server and create the same instance in two different regions. Use Database Migration Service to keep each database in sync.
  2. Use a VPN or VPC peering to establish a connection between the VPCs in each region. Install SQL Server Enterprise Edition on EC2 instances in each region and configure an Always On availability group.
  3. Use RDS for SQL Server 2016 or 2017 Enterprise Edition. Enable Multi-AZ support and select the Mirroring/Always On option. Select another region for the mirroring option.
  4. You can not set up an active-active architecture for SQL Server that spans geographic regions.

 

ChatGPT

Setting up an active-active architecture for an SQL Server database across AWS regions requires careful consideration. Each option has its own merits and considerations. Let's evaluate the options:

1.     Use RDS for SQL Server and create the same instance in two different regions. Use Database Migration Service to keep each database in sync.

·  This approach involves using RDS in two regions but doesn't provide true active-active capabilities. It's more like an active-passive setup with data replication. Active-active means both regions actively serve traffic.

2.     Use a VPN or VPC peering to establish a connection between the VPCs in each region. Install SQL Server Enterprise Edition on EC2 instances in each region and configure an Always On availability group.

·  This approach is a feasible option for creating an active-active SQL Server setup. It involves setting up SQL Server Always On availability groups across regions, which allows for read-write operations in both regions.

3.     Use RDS for SQL Server 2016 or 2017 Enterprise Edition. Enable Multi-AZ support and select the Mirroring/Always On option. Select another region for the mirroring option.

·  This option is not accurate as RDS for SQL Server does not support cross-region active-active configurations. Multi-AZ support in RDS is for high availability within a single region, not for active-active deployments across regions. (*Q9-3-1)

4.     You cannot set up an active-active architecture for SQL Server that spans geographic regions.

·  This statement is not entirely accurate. While SQL Server active-active configurations across regions can be complex, it is possible through technologies like Always On Availability Groups or custom replication solutions.

Option 2 is the most appropriate for achieving an active-active SQL Server setup across AWS regions using SQL Server Enterprise Edition on EC2 instances. This method provides the necessary redundancy, high availability, and load balancing across regions. However, it also introduces complexity in terms of network configuration and synchronization between the regions. Always ensure you have a strong understanding of the specific requirements and challenges when implementing such architectures.

 

Q9-3-1.  上記Q9で、過去問解答とChatGPT解答が異なるのでググってみた(↓)。

今回はChatGPTに軍配が上がるようだ。

 

Can we enable a Active Active Cross Region DR strategy for AWS RDS SQL Server , If so how?

https://repost.aws/questions/QUf5JUPirSTsaZ3BMHCLoiRw/can-we-enable-a-active-active-cross-region-dr-strategy-for-aws-rds-sql-server-if-so-how

Answer: AWS RDS SQL Server does not natively support an active-active cross-region replication topology.

  .. snip ..

 

Q12. What in-memory caching server is not supported by ElastiCache?

Redis 5

Memcached

Elasticsearch

Redis 3

 

ChatGPT

As of my last knowledge update in September 2021, Elasticsearch is not supported by Amazon ElastiCache. ElastiCache primarily supports in-memory caching solutions like Redis and Memcached.

Please note that the availability of specific versions and services may have changed since then, so I recommend checking the most up-to-date AWS documentation or the AWS Management Console for the latest information on supported services and versions in Amazon ElastiCache.


Q18. Which communication channel does SNS not support natively?

OSMS text message

push notification

email

automated phone call

 

ChatGPT

As of my last knowledge update in September 2021, Amazon Simple Notification Service (SNS) natively supports the following communication channels:

1.     Push Notification: SNS supports push notifications to mobile devices using platforms like Apple iOS, Google Android, and more.

2.     Email: SNS supports sending messages via email, including both SMS (Short Message Service) and email notifications.

3.     Automated Phone Call: SNS supports automated voice calls, allowing you to deliver important messages to recipients via phone calls.

However, SNS does not natively support sending OSMS (Over-the-Top Messaging Service) text messages. It primarily focuses on the channels mentioned above. If you need to send OSMS text messages, you may need to use additional services or providers that offer such functionality, or you can implement custom solutions as needed.

Please note that the availability of communication channels and features may change over time, so it's a good practice to consult the latest AWS documentation for any updates regarding SNS capabilities.

 

 

Oct 3, 2023

Skill Assessment - Windows Server


過去問題ソース

 https://www.chase2learn.com/windows-server-linkedin-assessment-answers/


以下、学習を深めるため、過去問ソース記載の解答を太字で、その下にChatGPT解答を記しておく。


Q1. You need to create a file share for your company 

that must be accessible from all branch offices and its share path must have the name Work Share. Which server role do you install?

1. BranchCache for Network Files

2. File Server

3. Work Folders

4. DFS Namespaces

 

ChatGPT解答

To create a file share for your company that is accessible from all branch offices with the share path named "Work Share," you should install the DFS Namespaces server role.

DFS (Distributed File System) Namespaces allows you to create a unified namespace that spans multiple servers and locations, making it easier to manage and access files across different branch offices.
You can use DFS Namespaces to create a share path like "\contoso.com\Work Share" that can be accessed from multiple locations seamlessly.

So, the correct answer is: 4. DFS Namespaces


次の下線部を追加して、再び尋ねてみた。過去問との食い違いが気になったし、"4. DFS Namespaces"は違和感があったので。


Q1. You need to create a file share on Microsoft Windows server 

for your company that must be accessible from all branch offices and its share path must have the name Work Share. Which server role do you install?

1. BranchCache for Network Files

2. File Server

3. Work Folders

4. DFS Namespaces

 

ChatGPT

To create a file share on a Microsoft Windows Server that is accessible from all branch offices with the share path named "Work Share," you should install the File Server role. The File Server role allows you to share files and folders on a Windows Server, making them accessible to users across your organization.

So, the correct answer is: 2. File Server


In this senario, what is the biggest difference between installing File Server role and DFS Namespaces?

 

ChatGPT

In the scenario of creating a file share accessible from all branch offices with the share path named "Work Share," the biggest difference between installing the File Server role and DFS Namespaces lies in their purpose and functionality:

1.     File Server Role:

    • The File Server role primarily focuses on sharing files and folders on a Windows Server.
    • It provides a straightforward way to create and manage file shares on a single server.
    • File Server role does not inherently provide advanced features for load balancing, redundancy, or easy access to files across multiple servers or locations.

2.     DFS Namespaces:

    • DFS Namespaces, or Distributed File System Namespaces, is a feature that allows you to create a unified namespace that spans multiple servers and locations.
    • It enables you to create a single share path (like "\contoso.com\Work Share") that abstracts the underlying server structure, making it appear as if all files are in one location, even if they are distributed across different servers.
    • DFS Namespaces provides advanced features like load balancing, fault tolerance, and the ability to easily access files from multiple servers, which is particularly useful in scenarios with branch offices.

In summary, the File Server role is suitable for simple file sharing on a single server, while DFS Namespaces is designed for more complex scenarios where you need to provide access to files across multiple servers and locations with advanced features for load balancing and redundancy. For the scenario you mentioned, where the goal is to make the share accessible from all branch offices, DFS Namespaces would be the more appropriate choice.


In this senario, how BranchCache for Network Files can contribute?

 

ChatGPT

In the scenario of creating a file share that must be accessible from all branch offices with the share path named "Work Share," BranchCache for Network Files can contribute by enhancing the performance and efficiency of accessing files over a wide area network (WAN) or slow network links, such as those connecting branch offices to the central server. Here's how BranchCache can be beneficial:

1.     Caching Content Locally: BranchCache allows branch office clients to cache a copy of frequently accessed files locally. When a user accesses a file from the central server for the first time, BranchCache can store a copy of that file on the local branch office client.

2.     Subsequent Faster Access: When other users in the same branch office need to access the same file, they can retrieve it from the local cache rather than downloading it again from the central server. This reduces WAN traffic and improves file access times for branch office users.

3.     Reduces WAN Bandwidth Utilization: By caching files locally, BranchCache helps reduce the load on the WAN link between branch offices and the central server. This is especially valuable in scenarios where bandwidth is limited or expensive.

4.     Automatic Synchronization: BranchCache can be configured to automatically synchronize cached content with the central server to ensure that users have access to up-to-date files while still benefiting from local caching.

5.     Security and Authentication: BranchCache maintains security and access controls, ensuring that only authorized users can access cached files.

In summary, BranchCache for Network Files is a technology that can significantly improve the performance and efficiency of accessing files over WAN or slow network links by caching frequently accessed files locally in branch offices. While DFS Namespaces focuses on providing a unified namespace for file access across multiple servers and locations, BranchCache complements it by optimizing the actual file access process, especially in scenarios where bandwidth constraints or latency are issues.


In that senario, what is the biggest difference between BranchCache for Network Files and DFS Namespaces?

 

ChatGPT

The biggest difference between BranchCache for Network Files and DFS (Distributed File System) Namespaces lies in their primary purposes and how they address different aspects of file access and optimization:

1.     BranchCache for Network Files:

·       Purpose: BranchCache is primarily designed to optimize the efficiency of file access over slow or bandwidth-constrained WAN links, especially in scenarios where branch offices need to access files from a central server.

·       Functionality: It accomplishes this by caching frequently accessed files locally in branch offices, allowing subsequent users to retrieve those files from the local cache instead of repeatedly downloading them over the WAN. This reduces WAN traffic and improves file access times.

·       Optimization Focus: BranchCache is focused on optimizing the actual file transfer process and minimizing the impact of WAN latency and bandwidth limitations.

2.     DFS Namespaces:

·       Purpose: DFS Namespaces is designed to provide a unified namespace for file access across multiple servers and locations. It abstracts the underlying server structure and presents a single share path to users, making it easier to manage and access files distributed across different servers.

·       Functionality: It offers features like load balancing, fault tolerance, and the ability to distribute files across multiple servers. DFS Namespaces enhances the scalability, availability, and organization of file shares.

·       Optimization Focus: DFS Namespaces optimizes the organization and accessibility of files across a network by providing a consistent, logical structure for file shares, but it does not directly address the optimization of file transfer over WAN links.

In summary, the key difference is that BranchCache focuses on optimizing the performance of file access over WAN links by caching files locally in branch offices, while DFS Namespaces focuses on creating a unified namespace for file access across multiple servers and locations. These technologies serve complementary roles in improving file access and management in networked environments, with BranchCache addressing the WAN optimization aspect and DFS Namespaces addressing the organization and accessibility of files across multiple servers.

 

以上から、Q1については過去問解答が正しいと考える(冒頭参照)。


Jul 1, 2023

マイナポイント環境チェックエラーでハマった件

準備からポイント申請までの手順を示す。 注意すべきポイントは●印箇所 

1.マイナンバーカードの読み取り装置を購入

ソニー NFC通信リーダー usb2.0 "PaSoRi" RC-S380/S パソコン用

2.読み取りソフトを導入

前述装置には同梱されてないので ...

2-1.「NFCポートソフトウェア」を入手

ドライバと自己診断ソフトからなる模様。 
『NFCポートソフトウェアは、NFCポート/パソリで動作するアプリケーションソフトウェア、ユーティリティソフトウェアを利用するために必要なソフトウェアです。
※ FeliCaポートソフトウェアは、NFCポートソフトウェア へ名称変更しました。
 ..  Version 6.2.1 / 約43MB / 2022年12月1日』 
VirusTotalでのチェックも忘れずに。 
・NFCPortWithDriver.exe    ac2b4129ed242af8c412e5a03ca9cb1f78a6db452f8bc501a788026ccc6d271a 
  Size 43.32 MB (エクスプローラでは44,359 KBと表示)

問題無ければ、インストールして次へ。

Windowsメニューから「NFCポート自己診断」を選択、起動して診断しておくと良い。

 

2-2.非接触ICカードリーダー/ライター PaSoRi(パソリ)のアプリケーション

インストールしておくと交通系ICカードの使用履歴が見れたりするらしい。
執筆時点では、特に何もダウンロード・インストールしなかった。

3.マイナポイント申込サイトでの準備 

次のサイトで申し込みに必要なソフトをさらに入手・導入と、情報登録など。
「自身の端末でマイナポイント申込み」→「パソコンで申込み」→「申込みがはじめての方」から、下記『「マイキーID作成・登録準備ソフト」をインストール』へ。

3-1.マイキーID作成・登録準備ソフト​​  

「インストール」ボタンを押して、ソフトをダウンロード、VirusTotalでチェック、インストールする。

・MKJSsetup.exe    
Size 22.61 MB dfa218fa1287d906c413a7ba3907891924a3d76af92edb47e5b373b672577e74

・次のコメントが見えたらひとまず無視。
『※ 2020年7月以前にインストールされた方は、再度インストールを行ってください。アンインストールは不要です。』  

・電子証明書の有効期限チェックを有効にした。
 ※ 次の有効期限差異に注意。
a.マイナカードは10年間、
b.電子証明書は5年間。
更新を忘れると面倒そう、と容易に想像できる。従って、この自動チェックはデフォルトでは無効になっているように見えるが、有効にしておくと有用だろう。  

 

3-2.ブラウザ拡張機能「マイナポイント」

まずは管理者権限でブラウザを起動
拡張機能「マイナポイント」をインストール

ここまでの手順で思い当たる事が無くても、下図の「事前セットアップ ×」ループになるなら、管理者権限でのブラウザ起動を試してみると良い。

※ 一般ユーザ権限のブラウザでも「マイナンバーカードを読み取ります」と表示され、なにやら機能している雰囲気なのだが・・・

※ そういえば「NFCポート自己診断」は起動の度に管理者パスワードを求めてくるのだった。下記参考サイトのおかげで気づけた。 


○普段使いのアカウントのブラウザの拡張機能「マイナポイント」が
 何故かインストール済み。 

 試行過程では念のため削除してインストールやり直したが、削除しても良いだろう。

○インストール後に、「JPKI利用者ソフト」を起動し、バージョンを確認する。
 ver3.3の場合、念のためアップデートすることに。
 最新版は次のサイトで入手可。    
  https://www.jpki.go.jp/download/win.html

 ・JPKIAppli03-05.exe

8123fa09046a9b1458cc77256a34dbceebd09759aa3d5548b181b08f4e55dd97
Size 25.95 MB 
Last Analysis Date 12 days ago 

起動して、「自分の証明書」で、証明書に氏名、住所等が正しく登録されているか確認もしておくと良い。

3-3.拡張機能「マイナポータル」

マイナポイント申請には不要な拡張機能のようだが、一連の手順でダウンロードしてしまったので、メモしておく。

次のサイトからダウンロード

VirusTotalでチェック

 ・MPASetup_Chrome.exe

879d4eb317ea2169a2b993d103ccab5d6bd90248140135eafe60199c2831417f
Size 5.05 MB
Last Analysis Date 11 days ago


4.マイナポイント申込  

健康保険証や公金受取口座など全部合わせて申し込むと20,000ポイントもらえる(執筆時)。

電子マネーはこんなにあるよ(執筆時)。

公金受取口座に支払ってくれるとか、いっそ日本円も電子化して互換性のある様々なデバイスで使えるようにしてくれば良いのだがなぁ。

使おうと思っていた電子マネーは、事前に利用者登録が必要。
利用者登録後、以降のマイナポイント申込手続きに使えるようになるのは翌日との事。

07/03 追記→

改めてマイナポイントのページへ。
 https://id.mykey.soumu.go.jp/mypage/MKCAS010/


※ 以降の手続きは「ブラウザをシステム管理者権限で起動」に比べれば、
  特に苦労もしないだろう。概略をメモしておく。


同ページの「はじめる」から ..

「カード登録」健康保険証と一体化公金受取口座」の三つを選んで申込み。

画面の指示に従い手続きを終えると、「公金受取口座を登録してください」と促される。

「マイナポータルアプリとブラウザ拡張機能を、両方インストールしてください。」との指示の通りに。

  ・MPASetup_Chrome.exe

879d4eb317ea2169a2b993d103ccab5d6bd90248140135eafe60199c2831417f
Size 5.05 MB
Last Analysis Date 11 days ago

前述インストール後、ブラウザの新しい Windowが開いて、ブラウザ拡張機能の「追加」を促される(下図)。


ブラウザ拡張機能追加を終え、以前の画面で「利用者登録/ログイン」の指示文通りに。

初回ログインの後、「利用者登録」に誘導される。

メール通知の設定他の後、「利用者登録」ボタンを押して完了。


「申請入力補助情報の登録」もお好みで。

※ リスク(カード紛失や更新手続きミスでの失効時にどうなるか)が簡潔に示されると良かったのだが。

「口座情報の登録完了」の画面の「マイナポイントサイトへ」を押下げ。

キャンペーン申込み状況を確認する。

「公金受取口座の登録」のみ「条件未達成」と表示されているが、「登録状況の反映には1日程かかる場合があります」との事で、明日再確認することにして、ひとまず終了。


Apr 14, 2023

Zero Trust Maturity Model

以下、末尾 Ref のサイトの機械翻訳である。


ゼロトラストは、ネットワークが危険にさらされているとみなされる中で、情報システムやサービスにおいて、正確で最小限の権限によるリクエストごとのアクセス決定を実施する際の不確実性を最小限に抑えるために設計された概念とアイデアの集合体です。その目的は、データやサービスへの不正アクセスを防止し、アクセス制御の実施を可能な限り細かくすることです。ゼロトラストは、時間と共に変化するユーザー、システム、データ、資産間のきめ細かなセキュリティ制御のために、場所中心のモデルから、よりデータ中心のアプローチへの移行を提示しています。これにより、セキュリティポリシーの開発、実装、実施、および進化をサポートするために必要な可視性が提供されます。より根本的には、ゼロトラストは、サイバーセキュリティをめぐる組織の哲学と文化を変える必要があるかもしれません。

 

CISA's Zero Trust Maturity Model Version 2.0

CISAのゼロ・トラスト成熟度モデルは、各省庁がゼロ・トラスト・アーキテクチャに移行する際に参照できる多くのロードマップの1つである。成熟度モデルは、ゼロトラスト戦略や実施計画の策定を支援し、CISAの各種サービスが機関全体のゼロトラストソリューションを支援する方法を提示することを目的としています。

 

成熟度モデルは、5つの柱と3つの横断的な能力を含み、ゼロトラストの基礎に基づいている。各柱の中で、成熟度モデルは、従来型、初期型、先進型、最適型のゼロ・トラスト・アーキテクチャの具体例を示しています。

 

ZTMMのバージョン1.0は、20219月にパブリックコメントの募集を開始しました。ゼロ・トラスト成熟度モデルのコメントへの応答は、バージョン1.0フィードバックに対応したコメントと修正を要約しています。

 

バージョン2.0は、20221月に発行されたOMB M-22-09へのアライメントを組み込んでいます。

 

ゼロトラスト成熟度モデル V2.0 をダウンロードするには、ここをクリックしてください

 

Federal Zero Trust Resource Hub

行政管理予算局(OMB)とCISAは、連邦政府民間行政機関(FCEB)向けの連邦ゼロ・トラストガイダンスに関する中央リポジトリを維持しています。このウェブサイトには、連邦ゼロ・トラスト戦略を含むゼロ・トラストに関する最新情報および追加リソースが含まれています。

 

Zerotrust.cyber.gov を調べるには、ここをクリックしてください

 

Applying Zero Trust Principles to Enterprise Mobility

CISAは、連邦政府機関やその他の組織がゼロ・トラストへの道を歩むのを支援するため、「Applying Zero Trust Principles to Enterprise Mobility」を発行しました。この新しい出版物は、モバイルデバイスの技術的進化とユビキタスな使用により、モバイルデバイスと関連する企業のセキュリティ管理機能に対する特別な配慮の必要性を強調しています。

 

このガイダンスは、最近発表されたOMBゼロトラスト実施テンプレートとCISAゼロトラスト成熟度モデルを補完するものであることを意図しています。

 

CISAは、連邦企業のモビリティプログラムの一部である可能性が高い、現在利用可能なモバイルセキュリティ技術にZT原則をどのように適用できるかを機関に知らせるために、エンタープライズモビリティへのゼロトラスト原則の適用を起草しました。CISAは、この文書を202237日から2022420日までパブリックコメントのために公開しました。CISAは、すべての回答者のコメントに感謝し、コメントの裁定とドキュメントの更新版の作成に取り組んでいます

 

エンタープライズモビリティへのゼロトラスト原則適用の文書を入手するには、ここをクリックしてください

 

Ref. Zero Trust Maturity Model | CISA


Mar 25, 2023

Windows 11標準ツールで編集した画像から元画像を復元できる

【参考】 

Pixelより影響大? Windows 11標準ツールで編集した画像から元画像を復元できると判明 (03/23)

https://internet.watch.impress.co.jp/docs/yajiuma/1487728.html


 Snipping Toolの過去情報消去不備の件、いかにもプログラマーがデバッグ目的でうっかりやってしまいそう。
 いやらしいことに、問題がパッチで修正された後も、それ以前にブログ等に投稿した画像は自動修正されない点に要注意。
とすると、win7, 8.x, 10では問題無いのかまで含めた検証が欲しいところ。
元記事英語にも触れられていないのが気がかりである。


・関連を連想させる記事

Pixelで編集した画像→元画像を復元できることが判明して騒動に。実証ツールも公開 (03/20)

https://internet.watch.impress.co.jp/docs/yajiuma/1487012.html


『Pixelシリーズに標準搭載されているスクリーンショット編集ツール「マークアップ」で行った塗りつぶしや切り抜きについて、加工後のPNGファイルを保存するときに元データが削除されない不具合 .. 

加工後のPNGファイルを手に入れた第三者が、オリジナルの内容を復元できてしまう .. 不具合自体は2021年に修正されているが、それ以前に加工された画像は今も復元が可能 .. 』


Google Pixelのスクリーンショット編集機能に脆弱性、個人情報の漏えいにつながる危険も (03/20)

https://gigazine.net/news/20230320-google-pixel-markup-vulnerability-acropalypse/


『同脆弱性は「aCropalypse」(CVE-2023-21036)と呼ばれており、Android向けの最新アップデートであるAndroid 13 QPRで修正 .. 

マークアップが搭載されたのは2018年にリリースされたAndroid 9から。

例えば、お財布アプリなどに表示されるクレジットカード情報を含むスクリーンショットを撮影し、個人情報を伏せるためにカード番号部分を黒塗り編集してSNSなどで共有したとします。マークアップの脆弱性を突けば、この編集済みのスクリーンショットを編集前の状態に復元することが可能です。

マークアップで編集した画像を復元することができる理由は、編集されたバージョンの画像が元のファイルと同じ場所に保存されるためです。


少なくともPixelシリーズの場合は、デバッグ目的でうっかりというのとは違う。

だからといって win 7, 8.x, 10での検証も依然望ましい。