WGU C484 pretest: Exam Questions and Answers with Verified
Solutions | Latest 2026 Update
Q: Hyperjacking
Answer:
Hyperjacking is when a malicious actor takes control of the hypervisor that
manages a virtual environment and then has all the required privileges to take full
control of the environment.
Q: VM escape
Answer:
VM escape is an attack where malware running in a VM is able to interact directly
with the hypervisor or host kernel.
Q: VM sprawl
Answer:
is a configuration vulnerability where provisioning and de-provisioning of virtual
assets is not properly authorized and monitored.
Q: SAN
Answer:
Storage Area Network (SAN) is a separate subnetwork typically consisting of
storage devices and servers that house a large amount of data.
Q: DAS
Answer:
Direct Attached Storage (DAS) is storage attached to a system such as a hard drive
in a server, instead of clients accessing it over the network.
Q: NAS
Answer:
Network Attached Storage (NAS) which is a group of file servers attached to the
network dedicated to provisioning data access.
Q: MQTT
,Answer:
protocol which carries messages between IoT devices, but the protocol does not
encrypt the data which makes it vulnerable to attacks.
Q: IIoT
Answer:
the Industrial Internet of Things (IIoT) or Industry 4.0, which is a complement to a
SCADA system and merges the control functionality with the data collecting
ability of an IoT device.
Q: SCADA
Answer:
A Supervisory control and data acquisition (SCADA) system is a type of ICS that
manages large-scale, multiple-site devices and equipment spread over
geographically large areas from a host computer.
Q: ICS
Answer:
An industrial control system (ICS) is any system that enables users to control
industrial and critical infrastructure assets over a network.
Q: BLE
Answer:
Bluetooth Low Energy (BLE) connection which many IoT devices use to
communicate wirelessly over short distances; however, it uses less energy than
Bluetooth.
Q: class 3 virtual environment attack
Answer:
is when the attack originates within the virtual machine and the virtual machine is
the attack source.
Q: class 1 virtual environment attack
Answer:
in which the attack happens outside of the virtual machine and can affect the entire
virtual environment.
, Q: hyperjacking
Answer:
is when a malicious actor takes control of the hypervisor that manages avirtual
environment and then has all the required privileges to take full control of the
environment.
Q: OWASP top 10
Answer:
Broken Access Control Cryptographic Failures
Injection Insecure Design
Security Misconfiguration
Vulnerable and Outdated Components Identification and Authentication Failures
Software and Data Integrity Failures Security Logging and Monitoring Failures
Server-Side Request Forgery
Q: Session fixation
Answer:
attack which requires the user to authenticate with a known session identifier that
the threat actor will then use for impersonation.
Q: cross-site request forgery (XSRF/CSRF)
Answer:
an attacker takes advantage of the trust established between an authorized user of a
website and the website itself.
Q: server-side request forgery (SSRF) attack
Answer:
an attacker takes advantage of the trust established between the server and the
resources it can access, including itself.
Q: Session replay
Answer:
requires having access to the user authentication process itself so that the threat
actor can intercept it and repeat it.
Q: Command injection
Solutions | Latest 2026 Update
Q: Hyperjacking
Answer:
Hyperjacking is when a malicious actor takes control of the hypervisor that
manages a virtual environment and then has all the required privileges to take full
control of the environment.
Q: VM escape
Answer:
VM escape is an attack where malware running in a VM is able to interact directly
with the hypervisor or host kernel.
Q: VM sprawl
Answer:
is a configuration vulnerability where provisioning and de-provisioning of virtual
assets is not properly authorized and monitored.
Q: SAN
Answer:
Storage Area Network (SAN) is a separate subnetwork typically consisting of
storage devices and servers that house a large amount of data.
Q: DAS
Answer:
Direct Attached Storage (DAS) is storage attached to a system such as a hard drive
in a server, instead of clients accessing it over the network.
Q: NAS
Answer:
Network Attached Storage (NAS) which is a group of file servers attached to the
network dedicated to provisioning data access.
Q: MQTT
,Answer:
protocol which carries messages between IoT devices, but the protocol does not
encrypt the data which makes it vulnerable to attacks.
Q: IIoT
Answer:
the Industrial Internet of Things (IIoT) or Industry 4.0, which is a complement to a
SCADA system and merges the control functionality with the data collecting
ability of an IoT device.
Q: SCADA
Answer:
A Supervisory control and data acquisition (SCADA) system is a type of ICS that
manages large-scale, multiple-site devices and equipment spread over
geographically large areas from a host computer.
Q: ICS
Answer:
An industrial control system (ICS) is any system that enables users to control
industrial and critical infrastructure assets over a network.
Q: BLE
Answer:
Bluetooth Low Energy (BLE) connection which many IoT devices use to
communicate wirelessly over short distances; however, it uses less energy than
Bluetooth.
Q: class 3 virtual environment attack
Answer:
is when the attack originates within the virtual machine and the virtual machine is
the attack source.
Q: class 1 virtual environment attack
Answer:
in which the attack happens outside of the virtual machine and can affect the entire
virtual environment.
, Q: hyperjacking
Answer:
is when a malicious actor takes control of the hypervisor that manages avirtual
environment and then has all the required privileges to take full control of the
environment.
Q: OWASP top 10
Answer:
Broken Access Control Cryptographic Failures
Injection Insecure Design
Security Misconfiguration
Vulnerable and Outdated Components Identification and Authentication Failures
Software and Data Integrity Failures Security Logging and Monitoring Failures
Server-Side Request Forgery
Q: Session fixation
Answer:
attack which requires the user to authenticate with a known session identifier that
the threat actor will then use for impersonation.
Q: cross-site request forgery (XSRF/CSRF)
Answer:
an attacker takes advantage of the trust established between an authorized user of a
website and the website itself.
Q: server-side request forgery (SSRF) attack
Answer:
an attacker takes advantage of the trust established between the server and the
resources it can access, including itself.
Q: Session replay
Answer:
requires having access to the user authentication process itself so that the threat
actor can intercept it and repeat it.
Q: Command injection