ISO/IEC/IEEE 29119-1:2022 Software and systems engineering Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

Imagine a consortium of historical archives, \"Historia Unida,\" spanning five nations, each maintaining its own extensive database of digitized manuscripts and artifacts. They aim to establish a unified search portal for researchers worldwide, leveraging the Z39.50 protocol for interoperability. However, their security audit reveals critical vulnerabilities in their existing Z39.50 implementations, particularly concerning sensitive historical records that contain personal information subject to varying national data protection laws. Given the inherent limitations of Z39.50\'s core specification regarding security, which of the following strategies represents the MOST comprehensive and effective approach to mitigate these vulnerabilities and ensure secure data exchange within the \"Historia Unida\" network, while adhering to diverse international data protection regulations? Assume all archives are using different Z39.50 compliant software.

Implement a layered security approach incorporating strong authentication mechanisms (e.g., digital certificates), role-based access control, end-to-end data encryption using TLS/SSL, data integrity checks via checksums, and adherence to relevant data protection regulations like GDPR and CCPA across all participating archives.
Rely solely on the inherent security features of the individual Z39.50 compliant software packages used by each archive, ensuring that each system is configured with the strongest password policies available and regularly updated with the latest security patches.
Establish a centralized firewall and intrusion detection system at the main Historia Unida server to monitor and filter all Z39.50 traffic, coupled with regular vulnerability scans of the network infrastructure to identify and address potential weaknesses.
Implement a data anonymization and pseudonymization strategy for all sensitive historical records before transmitting them over the Z39.50 network, ensuring that personal information is effectively masked or replaced with unique identifiers to protect individual privacy.

About the ISO/IEC/IEEE 29119-1:2022 Software and systems engineering Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC/IEEE 29119-1:2022 Software and systems engineering exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.