UPDATE WITH COMPLETE SOLUTIONS.
149 QUESTIONS
TABLE OF CONTENTS
# TOPIC
1 Evaluate and design secure authentication and authorization mechanisms for distributed systems
2 Analyze and optimize concurrency control and recovery protocols in relational and NoSQL databases
3 Apply enterprise architecture frameworks to align IT strategy with business objectives
4 Assess compliance, risk, and ethical implications of emerging technologies in information systems
5 IS 5403 Bundled Weekly Quizzes 2026 Update with complete solutions.
6 Foundations of Information Systems Security, Data Management, and Enterprise Architecture
7 Applied Information Systems Security, Data Management, and Enterprise Architecture
8 Advanced Information Systems Security, Data Management, and Enterprise Architecture
9 Information Systems Security, Data Management, and Enterprise Architecture Review
ABSTRACT
This study document brings together 149 carefully worded exam questions drawn from IS 5403
Bundled Weekly Quizzes 2026 Update with complete solutions., with the strongest emphasis
placed on Evaluate and design secure authentication and authorization mechanisms for distributed
systems, Analyze and optimize concurrency control and recovery protocols in relational and
NoSQL databases and Apply enterprise architecture frameworks to align IT strategy with business
objectives. Every item follows the wording style and level of reasoning you meet in the real paper,
and each one is paired with a clear rationale so the correct choice is never a guess. Work through
the set at your own pace, mark the questions that slow you down, then come back to them until the
reasoning feels automatic. Learners who revise this way walk into the exam room recognising the
pattern behind the questions instead of meeting them for the first time. Keep going - steady, honest
practice is what turns a difficult paper into a comfortable pass.
Page 1
,Q1 EVALUATE AND DESIGN SECURE AUTHENTICATION AND AUTHORIZATION
MECHANISMS FOR DISTRIBUTED SYSTEMS
In a zero-trust architecture, a policy engine evaluates an access request and
returns 'deny' despite the user presenting a valid FIDO2 token. Which principle
most directly explains this outcome?
A. Implicit trust based on network location
B. Continuous verification of device posture and context CORRECT
C. Single sign-on session persistence
D. Role-based access control with static permissions
RATIONALE: Zero-trust requires continuous verification of both identity and device/context
signals; a valid token alone is insufficient if device posture or context fails. Options A and D
reflect legacy perimeter or static models, while C is unrelated to the denial.
Q2 EVALUATE AND DESIGN SECURE AUTHENTICATION AND AUTHORIZATION
MECHANISMS FOR DISTRIBUTED SYSTEMS
A database system uses snapshot isolation. A transaction reads a set of rows,
then another transaction commits an update to one of those rows. The first
transaction then updates a different row in the same set. What anomaly can
occur?
A. Dirty read
B. Phantom read
C. Write skew CORRECT
D. Lost update
RATIONALE: Write skew occurs under snapshot isolation when two transactions read
overlapping data and update disjoint items, violating a global invariant. Dirty reads are prevented,
phantom reads are handled by snapshots, and lost updates are typically blocked by
first-committer-wins.
Page 2
,Q3 EVALUATE AND DESIGN SECURE AUTHENTICATION AND AUTHORIZATION
MECHANISMS FOR DISTRIBUTED SYSTEMS
In TOGAF ADM, which phase is responsible for defining the architecture vision
and obtaining stakeholder buy-in?
A. Phase A CORRECT
B. Phase B
C. Phase C
D. Phase D
RATIONALE: Phase A (Architecture Vision) establishes the scope, vision, and stakeholder
approval. Phases B, C, and D focus on business, information systems, and technology
architectures respectively.
Q4 EVALUATE AND DESIGN SECURE AUTHENTICATION AND AUTHORIZATION
MECHANISMS FOR DISTRIBUTED SYSTEMS
A company must comply with GDPR for EU customers and CCPA for California
residents. Which data governance mechanism best ensures consistent
enforcement across both jurisdictions?
A. Data localization in a single region
B. Unified consent management platform with policy mapping CORRECT
C. Anonymization of all personal data
D. Annual third-party audits only
RATIONALE: A unified consent platform maps policies to each regulation's requirements,
enabling consistent enforcement. Localization may conflict with cross-border needs,
anonymization may not be feasible, and audits alone are reactive.
Page 3
, Q5 EVALUATE AND DESIGN SECURE AUTHENTICATION AND AUTHORIZATION
MECHANISMS FOR DISTRIBUTED SYSTEMS
In a microservices architecture, a service mesh is introduced to handle mutual
TLS, retries, and circuit breaking. Which concern is primarily addressed by the
mesh's control plane?
A. Service discovery and load balancing
B. Policy configuration and certificate rotation CORRECT
C. Application business logic
D. Database sharding
RATIONALE: The control plane manages policies and distributes certificates, while the data
plane handles traffic. Service discovery and load balancing are data plane functions; business
logic and sharding are not mesh responsibilities.
Q6 EVALUATE AND DESIGN SECURE AUTHENTICATION AND AUTHORIZATION
MECHANISMS FOR DISTRIBUTED SYSTEMS
A company uses a blockchain for supply chain provenance. Which property is
most critical to ensure that recorded transactions cannot be altered retroactively?
A. Smart contract upgradability
B. Consensus mechanism security
C. Immutable ledger with cryptographic hashing CORRECT
D. Permissioned network membership
RATIONALE: Immutability via cryptographic chaining prevents retroactive changes. Consensus
security and permissioning affect trust but do not alone guarantee immutability; upgradability can
introduce mutability.
Page 4