WGU Penetration Testing
Planning and scoping
D484 – Questions and
answers 100% correct Information gathering and vulnerability
2026/2027 scan-ning
Attacks and exploits
When using a structured Reporting and communication
approach to PenTesting, each
step will serve a pur-pose with
the goal of testing an in-
frastructure's defenses by 1) Planning and scoping along with 3)
identifying and exploiting any Analysis and reporting.
known vulnerabil-ities. List the
four main steps of the CompTIA
Pen Testing process.
1. Threat actors follow the same main
process of hacking as a professional
PenTester: Reconnaissance, Payment Card Industry Data Security Standard
Scanning, Gain Access, Maintain
Access, and Cov-er Tracks. What
steps are added during a structured
PenTest?
2. Part of completing a PenTesting
exer-
cise is following the imposed guidelines (PCI DSS) specifies the controls that
must be in
of various controls, laws, and regula- place to securely handle credit card
data. Con-
tions. Summarize Key takeaways of PCI trols include methods to minimize
vulnerabili-
DSS. of transactions
completed in a year.
Describe a Level 1
merchant.
3. With PCI DSS a merchant is
ranked ac-cording to the number 4. With PCI DSS, a Level 1
, merchant must have an external ties, employ strong access control, along
auditor perform the assessment with consistently testing and
by an approved . monitoring the infra-structure.
A Level 1 merchant is a large merchant
with over six million transactions a year.
Qualified Security Assessor (QSA).
5.
, WGU Penetration Testing D484 - Questions
Another regulation that affects data Require consent means a company must
obtain
privacy is GDPR, which outlines specific your permission to share your
information.
requirements on how consumer Rescind consent allows a consumer to opt
data is protected. List two to out at any time.
three compo-nents of GDPR. Global reach—GDPR attects anyone who
does business with residents of the EU
and Britain. Restrict data collection to only
what is needed to interact with the site.
Violation reporting—a company must
report a data breach within 72 hours.
6. What should a company with Under GDPR, any company with over 250 em-
over 250
employees do to be compliant with the ployees will need to audit their
systems and
GDPR? techniques specific to
PenTesting.
7. Describe some of the resources
avail-able at NIST.
8. Discuss the significance of NIST
SP 800-115.
9. Explain how the MITRE ATT&CK
Frame-work provides tools and
, take rigorous steps to protect any data that is Security Testing and Assessment" and
processed within their systems, either locally contains a great deal of relevant
managed or in the cloud. information about PenTesting planning,
techniques, and re-lated activities.
NIST has many resources for the cybersecurity
professional that include the Special Publication 800 Once in the MITRE ATT&CK framework,
series, that deals with cyber security policies, you will see many columns in the matrix
procedures, and guidelines. that describe various tasks that are
completed during the Pen-Test.
NIST SP 800-115 is the "Technical Guide to In-formation
Planning and scoping
D484 – Questions and
answers 100% correct Information gathering and vulnerability
2026/2027 scan-ning
Attacks and exploits
When using a structured Reporting and communication
approach to PenTesting, each
step will serve a pur-pose with
the goal of testing an in-
frastructure's defenses by 1) Planning and scoping along with 3)
identifying and exploiting any Analysis and reporting.
known vulnerabil-ities. List the
four main steps of the CompTIA
Pen Testing process.
1. Threat actors follow the same main
process of hacking as a professional
PenTester: Reconnaissance, Payment Card Industry Data Security Standard
Scanning, Gain Access, Maintain
Access, and Cov-er Tracks. What
steps are added during a structured
PenTest?
2. Part of completing a PenTesting
exer-
cise is following the imposed guidelines (PCI DSS) specifies the controls that
must be in
of various controls, laws, and regula- place to securely handle credit card
data. Con-
tions. Summarize Key takeaways of PCI trols include methods to minimize
vulnerabili-
DSS. of transactions
completed in a year.
Describe a Level 1
merchant.
3. With PCI DSS a merchant is
ranked ac-cording to the number 4. With PCI DSS, a Level 1
, merchant must have an external ties, employ strong access control, along
auditor perform the assessment with consistently testing and
by an approved . monitoring the infra-structure.
A Level 1 merchant is a large merchant
with over six million transactions a year.
Qualified Security Assessor (QSA).
5.
, WGU Penetration Testing D484 - Questions
Another regulation that affects data Require consent means a company must
obtain
privacy is GDPR, which outlines specific your permission to share your
information.
requirements on how consumer Rescind consent allows a consumer to opt
data is protected. List two to out at any time.
three compo-nents of GDPR. Global reach—GDPR attects anyone who
does business with residents of the EU
and Britain. Restrict data collection to only
what is needed to interact with the site.
Violation reporting—a company must
report a data breach within 72 hours.
6. What should a company with Under GDPR, any company with over 250 em-
over 250
employees do to be compliant with the ployees will need to audit their
systems and
GDPR? techniques specific to
PenTesting.
7. Describe some of the resources
avail-able at NIST.
8. Discuss the significance of NIST
SP 800-115.
9. Explain how the MITRE ATT&CK
Frame-work provides tools and
, take rigorous steps to protect any data that is Security Testing and Assessment" and
processed within their systems, either locally contains a great deal of relevant
managed or in the cloud. information about PenTesting planning,
techniques, and re-lated activities.
NIST has many resources for the cybersecurity
professional that include the Special Publication 800 Once in the MITRE ATT&CK framework,
series, that deals with cyber security policies, you will see many columns in the matrix
procedures, and guidelines. that describe various tasks that are
completed during the Pen-Test.
NIST SP 800-115 is the "Technical Guide to In-formation