WGU C954 Information Technology Management
Objective Assessment Final Exam
Questions & ANSWERs Verified Actual Exam
2026/2027
Question 1
An organization is migrating its local databases to a cloud infrastructure to gain on-demand computing
power. The CIO wants to make sure that the system can automatically handle sudden traffic spikes
without manual resource allocation. Which cloud computing characteristic best describes this
capability?
A. Rapid elasticity
B. Resource pooling
C. Measured service
D. Broad network access
Correct ANSWER: A
Rationale: Rapid elasticity allows cloud resources to be dynamically and automatically scaled up or down
based on demand, ensuring sudden spikes are handled. Resource pooling refers to sharing physical
hardware among multiple customers, while measured service tracks resource usage for billing, and
broad network access refers to accessibility over standard networks.
Question 2
,A manufacturing company is implementing an enterprise resource planning (ERP) system to integrate its
supply chain and financial data. The IT manager wants to establish a system that allows different
systems to communicate and share data seamlessly. Which technology represents the standard for
enabling this integration?
A. Application Programming Interface (API)
B. Simple Mail Transfer Protocol (SMTP)
C. File Transfer Protocol (FTP)
D. Domain Name System (DNS)
Correct ANSWER: A
Rationale: An Application Programming Interface (API) is a set of protocols and definitions that allows
different software applications to communicate and share data with each other. SMTP is for email
transmission, FTP is for basic file transfers, and DNS translates domain names to IP addresses. APIs are
specifically designed for system-to-system integration and data sharing.
Question 3
A retail company is considering implementing a customer relationship management (CRM) system. The
IT director emphasizes the importance of ensuring that customer data is protected from unauthorized
access. Which security principle is primarily concerned with ensuring that only authorized users can
access specific data?
A. Integrity
B. Availability
C. Confidentiality
D. Non-repudiation
Correct ANSWER: C
Rationale: Confidentiality ensures that data is accessible only to authorized users and prevents
unauthorized access. Integrity ensures data accuracy and prevents unauthorized modification.
,Availability ensures systems and data are accessible when needed. Non-repudiation prevents users from
denying their actions.
Question 4
A hospital is digitizing its patient records and wants to ensure that medical data remains accurate and
unaltered throughout its lifecycle. Which security principle addresses this concern?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Correct ANSWER: B
Rationale: Integrity ensures that data remains accurate, complete, and unaltered throughout its
lifecycle. Confidentiality protects against unauthorized access, availability ensures data accessibility
when needed, and authentication verifies user identity. Medical records require strong integrity controls
to ensure patient safety.
Question 5
A financial institution is deploying a new online banking system. The security team is concerned about
ensuring the system remains operational even during cyberattacks. Which security principle is most
directly related to this concern?
A. Confidentiality
B. Integrity
C. Availability
D. Accountability
Correct ANSWER: C
, Rationale: Availability ensures that systems and data are accessible to authorized users when needed,
even during attacks. Confidentiality prevents unauthorized access, integrity ensures data accuracy, and
accountability tracks user actions. Banking systems must maintain high availability to serve customers.
Question 6
A company is implementing a bring-your-own-device (BYOD) policy. The IT department wants to ensure
that company data on personal devices can be remotely wiped if the device is lost or stolen. Which
security mechanism provides this capability?
A. Virtual Private Network (VPN)
B. Mobile Device Management (MDM)
C. Intrusion Detection System (IDS)
D. Firewall
Correct ANSWER: B
Rationale: Mobile Device Management (MDM) allows organizations to remotely manage, monitor, and
wipe data on mobile devices. VPNs secure network connections, IDS detects intrusions, and firewalls
control network traffic. MDM is specifically designed for managing corporate data on personal devices.
Question 7
An e-commerce company experiences a Distributed Denial of Service (DDoS) attack that overwhelms its
web servers. Which security technology is specifically designed to detect and prevent such attacks?
A. Anti-malware software
B. Intrusion Prevention System (IPS)
C. Encryption software
D. Data Loss Prevention (DLP)
Correct ANSWER: B
Objective Assessment Final Exam
Questions & ANSWERs Verified Actual Exam
2026/2027
Question 1
An organization is migrating its local databases to a cloud infrastructure to gain on-demand computing
power. The CIO wants to make sure that the system can automatically handle sudden traffic spikes
without manual resource allocation. Which cloud computing characteristic best describes this
capability?
A. Rapid elasticity
B. Resource pooling
C. Measured service
D. Broad network access
Correct ANSWER: A
Rationale: Rapid elasticity allows cloud resources to be dynamically and automatically scaled up or down
based on demand, ensuring sudden spikes are handled. Resource pooling refers to sharing physical
hardware among multiple customers, while measured service tracks resource usage for billing, and
broad network access refers to accessibility over standard networks.
Question 2
,A manufacturing company is implementing an enterprise resource planning (ERP) system to integrate its
supply chain and financial data. The IT manager wants to establish a system that allows different
systems to communicate and share data seamlessly. Which technology represents the standard for
enabling this integration?
A. Application Programming Interface (API)
B. Simple Mail Transfer Protocol (SMTP)
C. File Transfer Protocol (FTP)
D. Domain Name System (DNS)
Correct ANSWER: A
Rationale: An Application Programming Interface (API) is a set of protocols and definitions that allows
different software applications to communicate and share data with each other. SMTP is for email
transmission, FTP is for basic file transfers, and DNS translates domain names to IP addresses. APIs are
specifically designed for system-to-system integration and data sharing.
Question 3
A retail company is considering implementing a customer relationship management (CRM) system. The
IT director emphasizes the importance of ensuring that customer data is protected from unauthorized
access. Which security principle is primarily concerned with ensuring that only authorized users can
access specific data?
A. Integrity
B. Availability
C. Confidentiality
D. Non-repudiation
Correct ANSWER: C
Rationale: Confidentiality ensures that data is accessible only to authorized users and prevents
unauthorized access. Integrity ensures data accuracy and prevents unauthorized modification.
,Availability ensures systems and data are accessible when needed. Non-repudiation prevents users from
denying their actions.
Question 4
A hospital is digitizing its patient records and wants to ensure that medical data remains accurate and
unaltered throughout its lifecycle. Which security principle addresses this concern?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Correct ANSWER: B
Rationale: Integrity ensures that data remains accurate, complete, and unaltered throughout its
lifecycle. Confidentiality protects against unauthorized access, availability ensures data accessibility
when needed, and authentication verifies user identity. Medical records require strong integrity controls
to ensure patient safety.
Question 5
A financial institution is deploying a new online banking system. The security team is concerned about
ensuring the system remains operational even during cyberattacks. Which security principle is most
directly related to this concern?
A. Confidentiality
B. Integrity
C. Availability
D. Accountability
Correct ANSWER: C
, Rationale: Availability ensures that systems and data are accessible to authorized users when needed,
even during attacks. Confidentiality prevents unauthorized access, integrity ensures data accuracy, and
accountability tracks user actions. Banking systems must maintain high availability to serve customers.
Question 6
A company is implementing a bring-your-own-device (BYOD) policy. The IT department wants to ensure
that company data on personal devices can be remotely wiped if the device is lost or stolen. Which
security mechanism provides this capability?
A. Virtual Private Network (VPN)
B. Mobile Device Management (MDM)
C. Intrusion Detection System (IDS)
D. Firewall
Correct ANSWER: B
Rationale: Mobile Device Management (MDM) allows organizations to remotely manage, monitor, and
wipe data on mobile devices. VPNs secure network connections, IDS detects intrusions, and firewalls
control network traffic. MDM is specifically designed for managing corporate data on personal devices.
Question 7
An e-commerce company experiences a Distributed Denial of Service (DDoS) attack that overwhelms its
web servers. Which security technology is specifically designed to detect and prevent such attacks?
A. Anti-malware software
B. Intrusion Prevention System (IPS)
C. Encryption software
D. Data Loss Prevention (DLP)
Correct ANSWER: B