WGU C795 ACTUAL 2026 STUDY GUIDE QUESTIONS AND
SOLUTIONS RATED A+
✔✔An organization is creating a security policy that will be able to audit the use of
✔✔you are investigating possible unauthorized access to a Windows Server 2003
computer. The first step in your company's investigation policy states that the current
network connections must be documented.
Which command should you use?
A ping
B ipconfig
C tracert
D netstat - ✔✔D
✔✔Which programs are tools used to obtain user passwords? (Choose 3)
A L0phtCrack
B John the Ripper
C Tripwire
D Crack - ✔✔ABD
✔✔What is the correct definition of penetration testing?
A security response procedures undertaken for system and application hardening.
B security response procedures undertaken to detect brute force attacks.
C intrusion by hackers.
D test procedure performed by security professionals with management approval. -
✔✔D
✔✔You have been asked to manage your company's information security continuous
monitoring (ISCM) program.
Which of the following statements regarding automated versus manual reporting is
FALSE?
A Automated tools recognize patterns and relationships that may escape the notice of
human analysts or manual monitoring.
B Manual tools are more thorough in their reporting than automated methods.
C Automated tools improve the reliability of monitoring security-related information.
D Automated tools lower the costs of monitoring security-related information. - ✔✔B
,✔✔Which statement is TRUE of event logging?
A Only system administration, internal audit, and security staff should have access to
the log files.
B System and application logs should be delivered over the network in plain text.
C Logging should be performed once a day.
D System and application logs should permit modification of the existing entries. - ✔✔A
✔✔You have been asked to carry out a penetration test on your organization's network.
You obtain a footprint of the network.
What should you do next?
A Report to management.
B Perform port scans and resource identification.
C Attempt to gain unauthorized access by exploiting the vulnerabilities.
D Identify vulnerabilities in systems and resources. - ✔✔B
✔✔You have been hired as a security engineer for a new federal government agency.
you have been asked to implement an information security continuous monitoring
(ISCM) program for the agency.
Which standard should you consult?
A NIST SP 800-137
B NIST SP 800-53
C NIST SP 800-121
D NIST SP 800-92 - ✔✔A
✔✔Your company's security policy states that passwords should never be transmitted in
plain text. you need to determine if this policy is being followed.
Which tool should you use?
A protocol analyzer
B vulnerability scanner
C network mapper
D password cracker - ✔✔A
✔✔Your company has implemented a Security Assessment and Testing, strategy that
includes an information security continuous monitoring (SCM) program. As part of the
program, you must provide a detailed report for users, auditors, and other stakeholders
that focuses on security, availability, confidentiality, processing integrity, and privacy.
Which report should you provide?
,A SOC 2
B SAS 70
C SOC 3
D SOC 1 - ✔✔A
✔✔You must provide SOC 2 and SOC 3 reports on the security, availability,
confidentiality, processing integrity, and privacy of operational controls. As part of these
reports, you must provide information regarding the disclosure of data to third parties.
To which tenet of SOC 2 and SOC 3 does this information apply?
A availability
B security
C privacy
D confidentiality - ✔✔C
✔✔You are defining and implementing an information security continuous monitoring
(ISCM) program for your organization according to NIST SP 800-137. You are currently
collecting the security-related information required for metrics, assessments, and
reporting.
Which step of NIST SP 800-137 are you completing?
A Implement an ISCM program.
B Define an ISCM strategy.
C Establish an ISCM program.
D Analyze the data collected, and report findings. - ✔✔A
✔✔Which type of intrusion detection system (IDS) is a misuse detector?
A time-based IDS
B signature-based IDS
C behavior-based IDS
D access control IDS - ✔✔B
✔✔Which type of security identifies the process of safeguarding information assets after
the implementation of security?
A access control security
B operations security
C physical security
D application security - ✔✔B
, ✔✔Which operating system failure requires intervention of system administrator for
system restoration?
A system reboot
B trusted recovery
C system cold start
D emergency restart - ✔✔C
✔✔Your company has a backup solution that performs a full backup each Saturday
evening and an incremental backup all other evenings. A vital system crashes on
Monday morning.
How many backups will need to be restored?
A4
B3
C1
D 2 - ✔✔D
✔✔Your organization's network was recently attacked. During the attack, hackers stole
valuable proprietary information. you have been asked to supply information that is
admissible as evidence in a court of law to prosecute the suspects.
What should you provide?
A hard disk data copies
B user login names
C passwords
D memory dumps - ✔✔D
✔✔You are performing embedded device analysis on a GPS chip in a mobile phone.
You perform cryptographic hashing, create checksums, and document all the evidence.
Which phase of embedded device analysis are you performing?
A Preservation
B Presentation
C Analysis
D Collection - ✔✔A
✔✔You have been asked to reduce the surface area of a Windows Server 2012
computer that acts as a Web server.
Which step is NOT included in reducing surface area attacks?
SOLUTIONS RATED A+
✔✔An organization is creating a security policy that will be able to audit the use of
✔✔you are investigating possible unauthorized access to a Windows Server 2003
computer. The first step in your company's investigation policy states that the current
network connections must be documented.
Which command should you use?
A ping
B ipconfig
C tracert
D netstat - ✔✔D
✔✔Which programs are tools used to obtain user passwords? (Choose 3)
A L0phtCrack
B John the Ripper
C Tripwire
D Crack - ✔✔ABD
✔✔What is the correct definition of penetration testing?
A security response procedures undertaken for system and application hardening.
B security response procedures undertaken to detect brute force attacks.
C intrusion by hackers.
D test procedure performed by security professionals with management approval. -
✔✔D
✔✔You have been asked to manage your company's information security continuous
monitoring (ISCM) program.
Which of the following statements regarding automated versus manual reporting is
FALSE?
A Automated tools recognize patterns and relationships that may escape the notice of
human analysts or manual monitoring.
B Manual tools are more thorough in their reporting than automated methods.
C Automated tools improve the reliability of monitoring security-related information.
D Automated tools lower the costs of monitoring security-related information. - ✔✔B
,✔✔Which statement is TRUE of event logging?
A Only system administration, internal audit, and security staff should have access to
the log files.
B System and application logs should be delivered over the network in plain text.
C Logging should be performed once a day.
D System and application logs should permit modification of the existing entries. - ✔✔A
✔✔You have been asked to carry out a penetration test on your organization's network.
You obtain a footprint of the network.
What should you do next?
A Report to management.
B Perform port scans and resource identification.
C Attempt to gain unauthorized access by exploiting the vulnerabilities.
D Identify vulnerabilities in systems and resources. - ✔✔B
✔✔You have been hired as a security engineer for a new federal government agency.
you have been asked to implement an information security continuous monitoring
(ISCM) program for the agency.
Which standard should you consult?
A NIST SP 800-137
B NIST SP 800-53
C NIST SP 800-121
D NIST SP 800-92 - ✔✔A
✔✔Your company's security policy states that passwords should never be transmitted in
plain text. you need to determine if this policy is being followed.
Which tool should you use?
A protocol analyzer
B vulnerability scanner
C network mapper
D password cracker - ✔✔A
✔✔Your company has implemented a Security Assessment and Testing, strategy that
includes an information security continuous monitoring (SCM) program. As part of the
program, you must provide a detailed report for users, auditors, and other stakeholders
that focuses on security, availability, confidentiality, processing integrity, and privacy.
Which report should you provide?
,A SOC 2
B SAS 70
C SOC 3
D SOC 1 - ✔✔A
✔✔You must provide SOC 2 and SOC 3 reports on the security, availability,
confidentiality, processing integrity, and privacy of operational controls. As part of these
reports, you must provide information regarding the disclosure of data to third parties.
To which tenet of SOC 2 and SOC 3 does this information apply?
A availability
B security
C privacy
D confidentiality - ✔✔C
✔✔You are defining and implementing an information security continuous monitoring
(ISCM) program for your organization according to NIST SP 800-137. You are currently
collecting the security-related information required for metrics, assessments, and
reporting.
Which step of NIST SP 800-137 are you completing?
A Implement an ISCM program.
B Define an ISCM strategy.
C Establish an ISCM program.
D Analyze the data collected, and report findings. - ✔✔A
✔✔Which type of intrusion detection system (IDS) is a misuse detector?
A time-based IDS
B signature-based IDS
C behavior-based IDS
D access control IDS - ✔✔B
✔✔Which type of security identifies the process of safeguarding information assets after
the implementation of security?
A access control security
B operations security
C physical security
D application security - ✔✔B
, ✔✔Which operating system failure requires intervention of system administrator for
system restoration?
A system reboot
B trusted recovery
C system cold start
D emergency restart - ✔✔C
✔✔Your company has a backup solution that performs a full backup each Saturday
evening and an incremental backup all other evenings. A vital system crashes on
Monday morning.
How many backups will need to be restored?
A4
B3
C1
D 2 - ✔✔D
✔✔Your organization's network was recently attacked. During the attack, hackers stole
valuable proprietary information. you have been asked to supply information that is
admissible as evidence in a court of law to prosecute the suspects.
What should you provide?
A hard disk data copies
B user login names
C passwords
D memory dumps - ✔✔D
✔✔You are performing embedded device analysis on a GPS chip in a mobile phone.
You perform cryptographic hashing, create checksums, and document all the evidence.
Which phase of embedded device analysis are you performing?
A Preservation
B Presentation
C Analysis
D Collection - ✔✔A
✔✔You have been asked to reduce the surface area of a Windows Server 2012
computer that acts as a Web server.
Which step is NOT included in reducing surface area attacks?