WGU D385 OA CERTIFICATION SCRIPT
2026 QUESTIONS WITH SOLUTIONS
GRADED A+
◍ 201 Created.
Answer: Your request was accepted, and the resource was created.
◍ Status Code 400.
Answer: Bad Request
◍ Disaster Recovery Planning (DRP).
Answer: The plans we put in place in preparation for a potential disaster,
and what exactly we will do during and after a particular disaster strikes to
replace infrastructure
◍ Authentication Attacks.
Answer: Targets and attempts to exploit the authentication process a web
site uses to verify the identity of a user, service, or application.
◍ Deterrent.
Answer: Discourage those who might seek to violate our security controls
from doing so, whether the threat is external or internal.Violation of a policy
could result in the employing being disciplined or fired.Violation of a
regulation or law could result in criminal or civil prosecution
◍ The access control allow origin client sends a request to the server
(www.client.url). What does the server send back?.
Answer: ACAO client.url(Access Control Allow Origin)
◍ Vulnerability.
Answer: Weaknesses that can be used to harm us
◍ Nonrepudiation.
, Answer: A situation in which sufficient evidence exists as to prevent an
individual from successfully denying that he or she has made a statement, or
taken an action
◍ Hash Function.
Answer: Create a largely unique and fixed-length hash value based on the
original messageHashes provide integrity, but not confidentiality. It can't
un-hash a message. Hashes are very useful when distributing files or
sending communications, as the hash can be sent with the message so that
the receiver can verify its integrity
◍ What is returned when using response.content?.
Answer: The raw binary content of the HTTP response is returned as bytes
◍ Intrusion Detection System (IDS).
Answer: Monitor the networks, hosts, or applications to which they are
connected for unauthorized activity
◍ Cryptographic Machines.
Answer: 1. The Jefferson Disk by Thomas Jefferson2. The Enigma by
Arthur Scherbius
◍ Preventive.
Answer: Physically prevent unauthorized entities from breaching our
physical security
◍ Race conditions.
Answer: A vulnerability that occurs when an ordered or timed set of
processes is disrupted or altered by an exploitOccur when multiple
processes or multiple threads within a process control or share access to a
particular resource, and the correct handling of that resource depends on the
proper ordering or timing of transactionsCan be very difficult to detect in
existing software, as they are hard to reproduce
◍ CIA Triad.
Answer: Confidentiality, Integrity, Availability
, ◍ 200 OK.
Answer: Your request was successful
◍ Secure Protocols.
Answer: SFTP
◍ Integrity.
Answer: Refers to the ability to prevent our data from being changed in an
unauthorized or undesirable manner. This could mean the unauthorized
change or deletion of our data or portions of our data, or it could mean an
authorized, but undesirable, change or deletion of our data. To maintain
integrity, we not only need to have the means to prevent unauthorized
changes to our data but also need the ability to reverse authorized changes
that need to be undone.
◍ BinScope Binary Analyzer.
Answer: A tool developed by Microsoft to examine source code for general
good practices
◍ Port 443.
Answer: HTTPS
◍ A user masquerades as (or pretends to be) another user. What type of attack
is this?.
Answer: Cross-Site Scripting
◍ Something you know.
Answer: Password or PIN
◍ Symmetric Key Algorithms: AES.
Answer: Uses three different ciphers: one with a 128-bit key, one with a
192-bit key, and one with a 256-bit key, all having a block length of 128 bits
◍ Bring Your Own Device (BYOD).
Answer: Policy allows employees to use their personal mobile devices and
computers to access enterprise data and applications
◍ Application Protocol Intrusion Detection System (APIDS).
2026 QUESTIONS WITH SOLUTIONS
GRADED A+
◍ 201 Created.
Answer: Your request was accepted, and the resource was created.
◍ Status Code 400.
Answer: Bad Request
◍ Disaster Recovery Planning (DRP).
Answer: The plans we put in place in preparation for a potential disaster,
and what exactly we will do during and after a particular disaster strikes to
replace infrastructure
◍ Authentication Attacks.
Answer: Targets and attempts to exploit the authentication process a web
site uses to verify the identity of a user, service, or application.
◍ Deterrent.
Answer: Discourage those who might seek to violate our security controls
from doing so, whether the threat is external or internal.Violation of a policy
could result in the employing being disciplined or fired.Violation of a
regulation or law could result in criminal or civil prosecution
◍ The access control allow origin client sends a request to the server
(www.client.url). What does the server send back?.
Answer: ACAO client.url(Access Control Allow Origin)
◍ Vulnerability.
Answer: Weaknesses that can be used to harm us
◍ Nonrepudiation.
, Answer: A situation in which sufficient evidence exists as to prevent an
individual from successfully denying that he or she has made a statement, or
taken an action
◍ Hash Function.
Answer: Create a largely unique and fixed-length hash value based on the
original messageHashes provide integrity, but not confidentiality. It can't
un-hash a message. Hashes are very useful when distributing files or
sending communications, as the hash can be sent with the message so that
the receiver can verify its integrity
◍ What is returned when using response.content?.
Answer: The raw binary content of the HTTP response is returned as bytes
◍ Intrusion Detection System (IDS).
Answer: Monitor the networks, hosts, or applications to which they are
connected for unauthorized activity
◍ Cryptographic Machines.
Answer: 1. The Jefferson Disk by Thomas Jefferson2. The Enigma by
Arthur Scherbius
◍ Preventive.
Answer: Physically prevent unauthorized entities from breaching our
physical security
◍ Race conditions.
Answer: A vulnerability that occurs when an ordered or timed set of
processes is disrupted or altered by an exploitOccur when multiple
processes or multiple threads within a process control or share access to a
particular resource, and the correct handling of that resource depends on the
proper ordering or timing of transactionsCan be very difficult to detect in
existing software, as they are hard to reproduce
◍ CIA Triad.
Answer: Confidentiality, Integrity, Availability
, ◍ 200 OK.
Answer: Your request was successful
◍ Secure Protocols.
Answer: SFTP
◍ Integrity.
Answer: Refers to the ability to prevent our data from being changed in an
unauthorized or undesirable manner. This could mean the unauthorized
change or deletion of our data or portions of our data, or it could mean an
authorized, but undesirable, change or deletion of our data. To maintain
integrity, we not only need to have the means to prevent unauthorized
changes to our data but also need the ability to reverse authorized changes
that need to be undone.
◍ BinScope Binary Analyzer.
Answer: A tool developed by Microsoft to examine source code for general
good practices
◍ Port 443.
Answer: HTTPS
◍ A user masquerades as (or pretends to be) another user. What type of attack
is this?.
Answer: Cross-Site Scripting
◍ Something you know.
Answer: Password or PIN
◍ Symmetric Key Algorithms: AES.
Answer: Uses three different ciphers: one with a 128-bit key, one with a
192-bit key, and one with a 256-bit key, all having a block length of 128 bits
◍ Bring Your Own Device (BYOD).
Answer: Policy allows employees to use their personal mobile devices and
computers to access enterprise data and applications
◍ Application Protocol Intrusion Detection System (APIDS).