EXAM BANK LATEST COMPLETE
SOLUTION PASS ON FIRST ATTEMPT
This comprehensive question practice exam bank is
specifically engineered to help you pass the WGU C845
(VUN1) performance and objective assessments on your
very first attempt. Every multiple-choice question features a
direct answer key and a highly detailed, bolded rationale
mapping directly to the Systems Security Certified
Practitioner (SSCP) common body of knowledge. Master
critical course concepts including access control models,
the NIST incident response lifecycle, and data-at-rest
cryptographic protections to secure an easy pass.
Question 1
An IT security analyst notices that a junior database administrator has been
granted full Domain Admin rights, violating company policy. Which security
principle is most directly violated in this scenario?
A. Separation of Duties
B. Principle of Least Privilege
C. Non-repudiation
D. Mandatory Access Control
Answer: B
Rationale: The Principle of Least Privilege dictates that users should
only be granted the minimum level of access necessary to complete
,their job functions. Granting full administrative rights to a junior
employee creates unnecessary security risks, such as accidental or
malicious privilege escalation and unauthorized data manipulation.
Question 2
During an internal audit, a security analyst discovers that the account of an
employee who resigned three months ago is still active and has logged in
recently. What type of threat does this situation represent?
A. Privilege escalation
B. Insider threat / Orphaned account exploitation
C. Brute-force attack
D. Phishing injection
Answer: B
Rationale: An active account belonging to a departed employee is
known as an orphaned account. If it shows recent activity, it indicates
either a post-employment access failure or an unauthorized entity
exploiting weak de-provisioning processes to gain persistent access.
Question 3
An analyst wants to implement a containment strategy for a compromised
user workstation. According to NIST SP 800-61 Rev. 2, which action should
be taken first?
A. Wipe the hard drive and restore from backup.
B. Disconnect the workstation from the local network.
C. Review the SIEM logs for the past 90 days.
D. Conduct a post-incident lessons-learned meeting.
Answer: B
Rationale: Disconnecting the workstation from the network isolates
the system, preventing lateral movement of malware or active threat
actors to other corporate assets. This directly fulfills the containment
phase of the incident response lifecycle before moving to eradication.
,Question 4
A healthcare organization stores unencrypted patient health records on an
internal network file share. Which specific data state and risk category does
this scenario describe?
A. Data in transit; interception risk
B. Data in use; unauthorized modification risk
C. Data at rest; unauthorized exfiltration risk
D. Data in flight; spoofing risk
Answer: C
Rationale: Data stored on file shares, hard drives, or databases is
classified as data at rest. Leaving sensitive information like patient
health records unencrypted exposes the organization to catastrophic
mass data breaches and compliance violations if a threat actor gains
server access.
Question 5
Which cryptographic protocol should a security administrator enforce to
protect sensitive administrative payloads while they are actively being
transmitted across an untrusted network?
A. AES-256 (TDE)
B. TLS 1.3
C. SHA-256
D. WPA2 Personal
Answer: B
Rationale: Transport Layer Security (TLS) 1.3 is designed to secure
data in transit by encrypting network communication sessions. AES-
256 Transparent Data Encryption (TDE) secures data at rest, while
SHA-256 is a hashing algorithm used for integrity, not session
encryption.
, Question 6
An organization implements a policy where one employee initiates a wire
transfer, but a supervisor must log in to approve and finalize the
transaction. Which CIS Control or NIST framework concept does this
practice embody?
A. Role-Based Access Control
B. Separation of Duties
C. Discretionary Access Control
D. Least Privilege Enforcement
Answer: B
Rationale: Separation of Duties splits a critical, high-risk task among
multiple individuals to prevent fraud and errors. Requiring an initiator
and an approver ensures that no single user has total control over a
high-impact financial or administrative transaction.
Question 7
While reviewing incident logs, an analyst discovers that a threat actor
gained initial access to the corporate network via a highly targeted email
containing a malicious link sent to the CFO. What specific type of attack
occurred?
A. Whaling
B. Vishing
C. Smishing
D. Ransomware
Answer: A
Rationale: Whaling is a specific type of spear-phishing attack targeted
directly at high-profile executives, such as CEOs, CFOs, or board
members. It aims to exploit their elevated access levels and authority
to steal credentials or sensitive financial data.
Question 8