WGU D837 OBJECTIVE ASSESSMENT –
CYBERSECURITY 2026 COMPLETE (115)
CURRENT TESTING QUESTIONS AND
CORRECT ANSWERS WITH DAETAILED
RATIONALES.
CYBERSECURITY
Prepare for the WGU D837 Objective Assessment – Cybersecurity with
focused review materials covering foundational cybersecurity principles,
network security, risk management, cryptography basics, access control
models, authentication methods, security policies, threat types
(malware, phishing, social engineering), and incident response
procedures. This study guide reinforces essential cybersecurity
knowledge, strengthens analytical and problem-solving skills, and
supports the application of security best practices to protect systems and
data. Suitable for WGU students preparing for the D837 cybersecurity
objective assessment.
MULTIPLE CHOICE.
Domain 1: Foundational Cybersecurity Concepts (Questions 1–
20)
1. What is the primary objective of cybersecurity in a business
organization?
A. To eliminate all cyber threats permanently
B. To protect the confidentiality, integrity, and availability of
information assets
, Page 2 of 48
C. To ensure the organization's social media presence is secure
D. To maximize profits through reduced IT spending
Correct answer: B. To protect the confidentiality, integrity, and
availability of information assets
Rationale: The core objective of cybersecurity is to safeguard the
CIA triad—confidentiality, integrity, and availability—of an
organization's information and systems.
2. Which of the following best describes the concept of "defense
in depth"?
A. Relying on a single, strong firewall to protect the network
B. Implementing multiple layers of security controls to protect
assets
C. Focusing all security efforts on physical security only
D. Using only open-source security tools
Correct answer: B. Implementing multiple layers of security
controls to protect assets
Rationale: Defense in depth is a strategy that employs multiple,
overlapping layers of security (physical, technical, administrative)
so that if one layer fails, others continue to provide protection.
3. In the context of cybersecurity, what is a "vulnerability"?
A. A person who attempts to gain unauthorized access to systems
B. A weakness in a system that could be exploited by a threat
C. An action taken to prevent a cyberattack
D. A type of malicious software
Correct answer: B. A weakness in a system that could be
exploited by a threat
Rationale: A vulnerability is a flaw or weakness in a system's design,
, Page 3 of 48
implementation, or operation that could be exploited to violate the
system's security policy.
4. What is the difference between a threat and a risk?
A. A threat is a potential danger; risk is the likelihood and impact of
that danger
B. A threat is always malicious; risk is always accidental
C. There is no difference between the two terms
D. A threat is a type of vulnerability
Correct answer: A. A threat is a potential danger; risk is the
likelihood and impact of that danger
Rationale: A threat is any potential danger to an asset (e.g., a
hacker, a natural disaster). Risk is the potential for loss or damage
when a threat exploits a vulnerability, calculated as the likelihood of
occurrence times the impact.
5. Which of the following is a key principle of the CIA triad?
A. Confidentiality, Integrity, Availability
B. Confidentiality, Identity, Access
C. Control, Integrity, Authentication
D. Compliance, Identity, Availability
Correct answer: A. Confidentiality, Integrity, Availability
Rationale: The CIA triad—Confidentiality, Integrity, and
Availability—is the foundational model for information security,
guiding the development of security policies and controls.
6. What is social engineering in the context of cybersecurity?
A. The use of technical hacking tools to breach systems
B. The manipulation of people to divulge confidential information or
perform actions
, Page 4 of 48
C. The process of engineering secure social media platforms
D. A type of firewall configuration
Correct answer: B. The manipulation of people to divulge
confidential information or perform actions
Rationale: Social engineering exploits human psychology rather
than technical vulnerabilities to gain unauthorized access to
information or systems.
7. Which of the following is an example of a physical security
control?
A. A firewall
B. An intrusion detection system
C. A biometric access reader at a building entrance
D. An encryption algorithm
Correct answer: C. A biometric access reader at a building
entrance
Rationale: Physical security controls are measures that protect
physical assets, such as buildings and hardware. Biometric readers,
locks, and surveillance cameras are examples.
8. What is the primary purpose of the "least privilege" principle?
A. To give all users maximum access to perform their jobs
B. To grant users only the minimum access necessary to perform
their duties
C. To ensure all users have equal access to all systems
D. To eliminate the need for passwords
Correct answer: B. To grant users only the minimum access
necessary to perform their duties
Rationale: The principle of least privilege limits access rights to the