• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 91 pages
Exam (elaborations)

Wgu C845 Vun1 Task 1 2 3 Practice Exam Bank Latest Complete Solution Pass On First Attempt

Document preview thumbnail
Preview 4 out of 91 pages

This comprehensive question practice exam bank is specifically engineered to help you pass the WGU C845 (VUN1) performance and objective assessments on your very first attempt. Every multiple-choice question features a direct answer key and a highly detailed, bolded rationale mapping directly to the Systems Security Certified Practitioner (SSCP) common body of knowledge. Master critical course concepts including access control models, the NIST incident response lifecycle, and data-at-rest cryptographic protections to secure an easy pass.

Content preview

WGU C845 VUN1 TASK 1 2 3 PRACTICE
EXAM BANK LATEST COMPLETE
SOLUTION PASS ON FIRST ATTEMPT


This comprehensive question practice exam bank is
specifically engineered to help you pass the WGU C845
(VUN1) performance and objective assessments on your
very first attempt. Every multiple-choice question features a
direct answer key and a highly detailed, bolded rationale
mapping directly to the Systems Security Certified
Practitioner (SSCP) common body of knowledge. Master
critical course concepts including access control models,
the NIST incident response lifecycle, and data-at-rest
cryptographic protections to secure an easy pass.




Question 1
An IT security analyst notices that a junior database administrator has been
granted full Domain Admin rights, violating company policy. Which security
principle is most directly violated in this scenario?
A. Separation of Duties
B. Principle of Least Privilege
C. Non-repudiation
D. Mandatory Access Control
Answer: B
Rationale: The Principle of Least Privilege dictates that users should
only be granted the minimum level of access necessary to complete

,their job functions. Granting full administrative rights to a junior
employee creates unnecessary security risks, such as accidental or
malicious privilege escalation and unauthorized data manipulation.


Question 2
During an internal audit, a security analyst discovers that the account of an
employee who resigned three months ago is still active and has logged in
recently. What type of threat does this situation represent?
A. Privilege escalation
B. Insider threat / Orphaned account exploitation
C. Brute-force attack
D. Phishing injection
Answer: B
Rationale: An active account belonging to a departed employee is
known as an orphaned account. If it shows recent activity, it indicates
either a post-employment access failure or an unauthorized entity
exploiting weak de-provisioning processes to gain persistent access.


Question 3
An analyst wants to implement a containment strategy for a compromised
user workstation. According to NIST SP 800-61 Rev. 2, which action should
be taken first?
A. Wipe the hard drive and restore from backup.
B. Disconnect the workstation from the local network.
C. Review the SIEM logs for the past 90 days.
D. Conduct a post-incident lessons-learned meeting.
Answer: B
Rationale: Disconnecting the workstation from the network isolates
the system, preventing lateral movement of malware or active threat
actors to other corporate assets. This directly fulfills the containment
phase of the incident response lifecycle before moving to eradication.

,Question 4
A healthcare organization stores unencrypted patient health records on an
internal network file share. Which specific data state and risk category does
this scenario describe?
A. Data in transit; interception risk
B. Data in use; unauthorized modification risk
C. Data at rest; unauthorized exfiltration risk
D. Data in flight; spoofing risk
Answer: C
Rationale: Data stored on file shares, hard drives, or databases is
classified as data at rest. Leaving sensitive information like patient
health records unencrypted exposes the organization to catastrophic
mass data breaches and compliance violations if a threat actor gains
server access.


Question 5
Which cryptographic protocol should a security administrator enforce to
protect sensitive administrative payloads while they are actively being
transmitted across an untrusted network?
A. AES-256 (TDE)
B. TLS 1.3
C. SHA-256
D. WPA2 Personal
Answer: B
Rationale: Transport Layer Security (TLS) 1.3 is designed to secure
data in transit by encrypting network communication sessions. AES-
256 Transparent Data Encryption (TDE) secures data at rest, while
SHA-256 is a hashing algorithm used for integrity, not session
encryption.

, Question 6
An organization implements a policy where one employee initiates a wire
transfer, but a supervisor must log in to approve and finalize the
transaction. Which CIS Control or NIST framework concept does this
practice embody?
A. Role-Based Access Control
B. Separation of Duties
C. Discretionary Access Control
D. Least Privilege Enforcement
Answer: B
Rationale: Separation of Duties splits a critical, high-risk task among
multiple individuals to prevent fraud and errors. Requiring an initiator
and an approver ensures that no single user has total control over a
high-impact financial or administrative transaction.


Question 7
While reviewing incident logs, an analyst discovers that a threat actor
gained initial access to the corporate network via a highly targeted email
containing a malicious link sent to the CFO. What specific type of attack
occurred?
A. Whaling
B. Vishing
C. Smishing
D. Ransomware
Answer: A
Rationale: Whaling is a specific type of spear-phishing attack targeted
directly at high-profile executives, such as CEOs, CFOs, or board
members. It aims to exploit their elevated access levels and authority
to steal credentials or sensitive financial data.


Question 8

Document information

Uploaded on
June 28, 2026
Number of pages
91
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$29.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
munenenjeri37
4.3
(3)
Sold
9
Followers
0
Items
833
Last sold
1 week ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions