ISO/IEC 19770-3:2016 Information technology Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

NationSecure, a government agency, is launching a new national identification card program. To expedite the rollout, the card personalization process is outsourced to CardTrust, a certified third-party vendor specializing in secure card issuance. NationSecure is deeply concerned about maintaining the highest levels of data security and preventing unauthorized access to citizen information during the personalization phase. Considering the requirements outlined in ISO/IEC 7816-4:2020 regarding secure card management and data protection, which of the following strategies would provide the MOST robust security framework for ensuring the integrity and confidentiality of sensitive citizen data during the card personalization process performed by CardTrust? Assume all options adhere to basic compliance standards.

Implementing a split-key management system where NationSecure retains a portion of the cryptographic key and CardTrust holds the other, combined with a multi-party authorization protocol requiring approval from both NationSecure and CardTrust representatives for any sensitive card personalization operation.
Relying primarily on CardTrust's existing ISO 27001 certification and conducting quarterly audits of their personalization facilities to verify compliance with data security protocols and adherence to contractual obligations.
Providing CardTrust with temporary, time-limited access to a dedicated secure enclave containing all necessary cryptographic keys and citizen data, and revoking access immediately upon completion of each batch of card personalization.
Implementing a comprehensive data masking and anonymization technique on all citizen data before transmitting it to CardTrust, ensuring that the vendor only handles pseudonymized information during the personalization process.

About the ISO/IEC 19770-3:2016 Information technology Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC 19770-3:2016 Information technology exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.