Page 1 of 95
WGU D430 Fundamentals of Information Security Exam
Questions & Answers | Latest 2026 Update PDF
1. An ATM user wants to ensure their personal identification number remains
private during transactions. Which security principle is primarily being addressed
in this scenario?
A) Integrity
B) Availability
C) Confidentiality
D) Authentication
Correct Answer: C) Confidentiality
Confidentiality protects sensitive information from unauthorized access, exactly as
demonstrated by the need to keep a PIN number private during ATM transactions.
2. A hospital's electronic health record system experiences a power outage,
preventing doctors from accessing patient data needed for emergency treatment.
Which component of the CIA triad has been violated?
A) Confidentiality
B) Integrity
C) Availability
D) Nonrepudiation
Correct Answer: C) Availability
Availability ensures data is accessible when needed, and a power outage that
prevents access to critical medical records directly violates this principle.
,Page 2 of 95
3. A database administrator restricts user permissions to prevent unauthorized
modifications to financial records. Which security goal is being directly supported
through this control?
A) Confidentiality
B) Integrity
C) Availability
D) Authentication
Correct Answer: B) Integrity
Integrity involves preventing unauthorized changes to data, and permissions
restricting what users can modify directly support maintaining data integrity.
4. An attacker gains access to sensitive company data by looking over an
employee's shoulder while they work on a laptop in a coffee shop. This scenario
best illustrates which type of attack?
A) Interruption
B) Fabrication
C) Modification
D) Interception
Correct Answer: D) Interception
Interception attacks involve unauthorized viewing of data, such as an attacker
observing confidential information displayed on a laptop screen.
5. An employee sends an important email and later claims they never sent it,
despite evidence of the message in the sent folder. Which security principle would
prevent this denial of action?
A) Confidentiality
B) Integrity
C) Availability
D) Nonrepudiation
,Page 3 of 95
Correct Answer: D) Nonrepudiation
Nonrepudiation ensures someone cannot deny sending a message, typically
implemented through digital signatures that provide proof of origin.
6. A government agency must implement security programs and document their
procedures to comply with federal requirements. Which regulation mandates this
compliance?
A) GLBA
B) HIPAA
C) FISMA
D) SOX
Correct Answer: C) FISMA
FISMA requires federal agencies to create, document, and implement
comprehensive security programs to protect their information systems.
7. A credit card processing company must adhere to specific security standards to
continue conducting business with major financial institutions. Which compliance
framework applies to this situation?
A) SOX
B) FERPA
C) PCI DSS
D) GLBA
Correct Answer: C) PCI DSS
PCI DSS applies specifically to organizations handling credit card information and
is required to maintain business relationships in the payment card industry.
, Page 4 of 95
8. During a security audit, an organization implements controls to make it
physically impossible for users to deny sending certain communications. Which
security service is being established?
A) Authentication
B) Authorization
C) Nonrepudiation
D) Availability
Correct Answer: C) Nonrepudiation
Nonrepudiation ensures users cannot deny their actions, typically through digital
signatures and audit logs that provide proof of activity.
9. A doctor relies on patient laboratory results to make a critical treatment
decision. If these results were altered, the patient could suffer serious harm. This
scenario emphasizes which security principle?
A) Confidentiality
B) Integrity
C) Availability
D) Possession
Correct Answer: B) Integrity
Integrity ensures data is accurate and trustworthy; when medical decisions depend
on data correctness, integrity becomes critically important.
10. An organization implements multiple layers of security controls including
firewalls, intrusion detection systems, and access controls to avoid any single point
of failure. What strategy is being employed?
A) Risk avoidance
B) Defense in depth
C) Risk transference
D) Compensating controls
WGU D430 Fundamentals of Information Security Exam
Questions & Answers | Latest 2026 Update PDF
1. An ATM user wants to ensure their personal identification number remains
private during transactions. Which security principle is primarily being addressed
in this scenario?
A) Integrity
B) Availability
C) Confidentiality
D) Authentication
Correct Answer: C) Confidentiality
Confidentiality protects sensitive information from unauthorized access, exactly as
demonstrated by the need to keep a PIN number private during ATM transactions.
2. A hospital's electronic health record system experiences a power outage,
preventing doctors from accessing patient data needed for emergency treatment.
Which component of the CIA triad has been violated?
A) Confidentiality
B) Integrity
C) Availability
D) Nonrepudiation
Correct Answer: C) Availability
Availability ensures data is accessible when needed, and a power outage that
prevents access to critical medical records directly violates this principle.
,Page 2 of 95
3. A database administrator restricts user permissions to prevent unauthorized
modifications to financial records. Which security goal is being directly supported
through this control?
A) Confidentiality
B) Integrity
C) Availability
D) Authentication
Correct Answer: B) Integrity
Integrity involves preventing unauthorized changes to data, and permissions
restricting what users can modify directly support maintaining data integrity.
4. An attacker gains access to sensitive company data by looking over an
employee's shoulder while they work on a laptop in a coffee shop. This scenario
best illustrates which type of attack?
A) Interruption
B) Fabrication
C) Modification
D) Interception
Correct Answer: D) Interception
Interception attacks involve unauthorized viewing of data, such as an attacker
observing confidential information displayed on a laptop screen.
5. An employee sends an important email and later claims they never sent it,
despite evidence of the message in the sent folder. Which security principle would
prevent this denial of action?
A) Confidentiality
B) Integrity
C) Availability
D) Nonrepudiation
,Page 3 of 95
Correct Answer: D) Nonrepudiation
Nonrepudiation ensures someone cannot deny sending a message, typically
implemented through digital signatures that provide proof of origin.
6. A government agency must implement security programs and document their
procedures to comply with federal requirements. Which regulation mandates this
compliance?
A) GLBA
B) HIPAA
C) FISMA
D) SOX
Correct Answer: C) FISMA
FISMA requires federal agencies to create, document, and implement
comprehensive security programs to protect their information systems.
7. A credit card processing company must adhere to specific security standards to
continue conducting business with major financial institutions. Which compliance
framework applies to this situation?
A) SOX
B) FERPA
C) PCI DSS
D) GLBA
Correct Answer: C) PCI DSS
PCI DSS applies specifically to organizations handling credit card information and
is required to maintain business relationships in the payment card industry.
, Page 4 of 95
8. During a security audit, an organization implements controls to make it
physically impossible for users to deny sending certain communications. Which
security service is being established?
A) Authentication
B) Authorization
C) Nonrepudiation
D) Availability
Correct Answer: C) Nonrepudiation
Nonrepudiation ensures users cannot deny their actions, typically through digital
signatures and audit logs that provide proof of activity.
9. A doctor relies on patient laboratory results to make a critical treatment
decision. If these results were altered, the patient could suffer serious harm. This
scenario emphasizes which security principle?
A) Confidentiality
B) Integrity
C) Availability
D) Possession
Correct Answer: B) Integrity
Integrity ensures data is accurate and trustworthy; when medical decisions depend
on data correctness, integrity becomes critically important.
10. An organization implements multiple layers of security controls including
firewalls, intrusion detection systems, and access controls to avoid any single point
of failure. What strategy is being employed?
A) Risk avoidance
B) Defense in depth
C) Risk transference
D) Compensating controls