FINAL EXAMINATION PAPER dd dd
dd WGU IT SECURITY FUNDAMENTALS EXAM
dd dd dd dd
STUDENT NAME: ________________________________
dd dd DATE: _____________ dd
COURSE: WGU Course C836 Fundamentals of Information Sec
dd dd dd dd dd dd dd TIME: _____________ dd
urity Quizlet by Brian MacFarlane
dd dd dd dd
EXAM CODE: WGU IT SECURITY FUNDAMENTALS EXA
dd dd dd dd dd dd
M-101
EXAM INSTRUCTIONS: dd
1. Print your full name and date clearly in the header above.
dd dd dd dd dd dd dd dd dd dd dd
2. This exam booklet contains both Test Questions (Part I) and Verified Solutions (Part II).
dd dd dd dd dd dd dd dd dd dd dd dd dd dd
3. Answer all multiple-choice questions clearly. Double-check your work.
dd dd dd dd dd dd dd dd
4. Do not break the seal or open this booklet until instructed to do so by the proctor.
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
Q1. Term
dddd
[Verified Solution]: Definition dd dddd
Q2. Which cybersecurity term is defined as the potential for an attack on a resource? A Impa
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
ct B Vulnerability C Risk D Threat
dd dd dd dd dd dd
[Verified Solution]: D dd dddd
Q3. Which security type deliberately exposes a system's vulnerabilities or resources to an atta
dddd dd dd dd dd dd dd dd dd dd dd dd dd
cker? A Intrusion detection B Firewalls C Honeypots D Intrusion prevention
dd dd dd dd dd dd dd dd dd dd
[Verified Solution]: C dd dddd
Q4. Which tool can be used to map devices on a network, along with their operating system t
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
ypes and versions? A Packet sniffer B Packet filter C Port scanner D Stateful firewall
dd dd dd dd dd dd dd dd dd dd dd dd dd dd
[Verified Solution]: C dd dddd
Q5. Which web attack is a server-side attack? A Clickjacking B Cross-
dddd dd dd dd dd dd dd dd dd dd dd
site scripting C SQL injection D Cross-site request forgery
dd dd dd dd dd dd dd dd
[Verified Solution]: C dd dddd
,Q6. An organization employs a VPN to safeguard its information. Which security principle is
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd
protected by a VPN? A Data in motion B Data at rest C Data in use D Data in storage
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
[Verified Solution]: A dd dddd
Q7. A malicious hacker was successful in a denial of service (DoS) attack against an institutio
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
n's mail server. Fortunately, no data was lost or altered while the server was offline. Which ty
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
pe of attack is this? A Modification B Fabrication C Interception D Interruption
dd dd dd dd dd dd dd dd dd dd dd dd
[Verified Solution]: D dd dddd
Q8. A company has had several successful denial of service (DoS) attacks on its email server.
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
Which security principle is being attacked? A Possession B Integrity C Confidentiality D Avail
dd dd dd dd dd dd dd dd dd dd dd dd dd
ability
[Verified Solution]: D dd dddd
Q9. A new start-
dddd dd dd
up company has started working on a social networking website. The company has moved all i
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
ts source code to a cloud provider and wants to protect this source code from unauthorized ac
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
cess. Which cyber defense concept should the start-
dd dd dd dd dd dd dd
up company use to maintain the confidentiality of its source code? A Alarm systems B Accoun
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
t permissions C Antivirus software D File encryption
dd dd dd dd dd dd dd
[Verified Solution]: D dd dddd
Q10. A company has an annual audit of installed software and data storage systems. During t
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
he audit, the auditor asks how the company's most critical data is used. This determination hel
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
ps the auditor ensure that the proper defense mechanisms are in place to protect critical data.
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
Which principle of the Parkerian hexad is the auditor addressing? A Possession B Integrity C
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
Authenticity D Utility dd dd
[Verified Solution]: D dd dddd
Q11. Which web attack is possible due to a lack of input validation? A Extraneous files B Clic
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
kjacking C SQL injection D Cross-site request forgery
dd dd dd dd dd dd dd
[Verified Solution]: C dd dddd
, Q12. Which file action implements the principle of confidentiality from the CIA triad? A Co
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd
mpression B Hash C Backup D Encryption dd dd dd dd dd dd
[Verified Solution]: D dd dddd
Q13. Which cyber defense concept suggests limiting permissions to only what is necessary to p
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd
erform a particular task? A Authentication B Authorization C Defense in depth D Principle of
dd dd dd dd dd dd dd dd dd dd dd dd dd dd d
least privilege
d dd
[Verified Solution]: D dd dddd
Q14. A company institutes a new policy that "All office computer monitors must face toward
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
employees and must face away from doorways. The monitor screens must not be visible to peo
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
ple visiting the office." Which principle of the CIA triad is this company applying? A Availabi
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
lity B Confidentiality C Utility D Integrity
dd dd dd dd dd dd
[Verified Solution]: B dd dddd
Q15. At a small company, an employee makes an unauthorized data alteration. Which compo
dddd dd dd dd dd dd dd dd dd dd dd dd dd
nent of the CIA triad has been compromised? A Confidentiality B Authenticity C Integrity D
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
Availability
[Verified Solution]: C dd dddd
Q16. An organization plans to encrypt data in transit on a network. Which aspect of data is t
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
he organization attempting to protect? A Integrity B Possession C Availability D Authenticity
dd dd dd dd dd dd dd dd dd dd dd dd
[Verified Solution]: A dd dddd
Q17. Which aspect of the CIA triad is violated by an unauthorized database rollback or undo
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
? A Availability B Identification C Integrity D Confidentiality
dd dd dd dd dd dd dd dd
[Verified Solution]: C dd dddd
Q18. A company's website has suffered several denial of service (DoS) attacks and wishes to t
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
hwart future attacks. Which security principle is the company addressing? A Availability B A
dd dd dd dd dd dd dd dd dd dd dd dd dd
uthenticity C Confidentiality D Possession dd dd dd dd
[Verified Solution]: A dd dddd
dd WGU IT SECURITY FUNDAMENTALS EXAM
dd dd dd dd
STUDENT NAME: ________________________________
dd dd DATE: _____________ dd
COURSE: WGU Course C836 Fundamentals of Information Sec
dd dd dd dd dd dd dd TIME: _____________ dd
urity Quizlet by Brian MacFarlane
dd dd dd dd
EXAM CODE: WGU IT SECURITY FUNDAMENTALS EXA
dd dd dd dd dd dd
M-101
EXAM INSTRUCTIONS: dd
1. Print your full name and date clearly in the header above.
dd dd dd dd dd dd dd dd dd dd dd
2. This exam booklet contains both Test Questions (Part I) and Verified Solutions (Part II).
dd dd dd dd dd dd dd dd dd dd dd dd dd dd
3. Answer all multiple-choice questions clearly. Double-check your work.
dd dd dd dd dd dd dd dd
4. Do not break the seal or open this booklet until instructed to do so by the proctor.
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
Q1. Term
dddd
[Verified Solution]: Definition dd dddd
Q2. Which cybersecurity term is defined as the potential for an attack on a resource? A Impa
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
ct B Vulnerability C Risk D Threat
dd dd dd dd dd dd
[Verified Solution]: D dd dddd
Q3. Which security type deliberately exposes a system's vulnerabilities or resources to an atta
dddd dd dd dd dd dd dd dd dd dd dd dd dd
cker? A Intrusion detection B Firewalls C Honeypots D Intrusion prevention
dd dd dd dd dd dd dd dd dd dd
[Verified Solution]: C dd dddd
Q4. Which tool can be used to map devices on a network, along with their operating system t
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
ypes and versions? A Packet sniffer B Packet filter C Port scanner D Stateful firewall
dd dd dd dd dd dd dd dd dd dd dd dd dd dd
[Verified Solution]: C dd dddd
Q5. Which web attack is a server-side attack? A Clickjacking B Cross-
dddd dd dd dd dd dd dd dd dd dd dd
site scripting C SQL injection D Cross-site request forgery
dd dd dd dd dd dd dd dd
[Verified Solution]: C dd dddd
,Q6. An organization employs a VPN to safeguard its information. Which security principle is
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd
protected by a VPN? A Data in motion B Data at rest C Data in use D Data in storage
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
[Verified Solution]: A dd dddd
Q7. A malicious hacker was successful in a denial of service (DoS) attack against an institutio
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
n's mail server. Fortunately, no data was lost or altered while the server was offline. Which ty
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
pe of attack is this? A Modification B Fabrication C Interception D Interruption
dd dd dd dd dd dd dd dd dd dd dd dd
[Verified Solution]: D dd dddd
Q8. A company has had several successful denial of service (DoS) attacks on its email server.
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
Which security principle is being attacked? A Possession B Integrity C Confidentiality D Avail
dd dd dd dd dd dd dd dd dd dd dd dd dd
ability
[Verified Solution]: D dd dddd
Q9. A new start-
dddd dd dd
up company has started working on a social networking website. The company has moved all i
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
ts source code to a cloud provider and wants to protect this source code from unauthorized ac
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
cess. Which cyber defense concept should the start-
dd dd dd dd dd dd dd
up company use to maintain the confidentiality of its source code? A Alarm systems B Accoun
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
t permissions C Antivirus software D File encryption
dd dd dd dd dd dd dd
[Verified Solution]: D dd dddd
Q10. A company has an annual audit of installed software and data storage systems. During t
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
he audit, the auditor asks how the company's most critical data is used. This determination hel
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
ps the auditor ensure that the proper defense mechanisms are in place to protect critical data.
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
Which principle of the Parkerian hexad is the auditor addressing? A Possession B Integrity C
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
Authenticity D Utility dd dd
[Verified Solution]: D dd dddd
Q11. Which web attack is possible due to a lack of input validation? A Extraneous files B Clic
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
kjacking C SQL injection D Cross-site request forgery
dd dd dd dd dd dd dd
[Verified Solution]: C dd dddd
, Q12. Which file action implements the principle of confidentiality from the CIA triad? A Co
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd
mpression B Hash C Backup D Encryption dd dd dd dd dd dd
[Verified Solution]: D dd dddd
Q13. Which cyber defense concept suggests limiting permissions to only what is necessary to p
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd
erform a particular task? A Authentication B Authorization C Defense in depth D Principle of
dd dd dd dd dd dd dd dd dd dd dd dd dd dd d
least privilege
d dd
[Verified Solution]: D dd dddd
Q14. A company institutes a new policy that "All office computer monitors must face toward
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
employees and must face away from doorways. The monitor screens must not be visible to peo
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
ple visiting the office." Which principle of the CIA triad is this company applying? A Availabi
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
lity B Confidentiality C Utility D Integrity
dd dd dd dd dd dd
[Verified Solution]: B dd dddd
Q15. At a small company, an employee makes an unauthorized data alteration. Which compo
dddd dd dd dd dd dd dd dd dd dd dd dd dd
nent of the CIA triad has been compromised? A Confidentiality B Authenticity C Integrity D
dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
Availability
[Verified Solution]: C dd dddd
Q16. An organization plans to encrypt data in transit on a network. Which aspect of data is t
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
he organization attempting to protect? A Integrity B Possession C Availability D Authenticity
dd dd dd dd dd dd dd dd dd dd dd dd
[Verified Solution]: A dd dddd
Q17. Which aspect of the CIA triad is violated by an unauthorized database rollback or undo
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
? A Availability B Identification C Integrity D Confidentiality
dd dd dd dd dd dd dd dd
[Verified Solution]: C dd dddd
Q18. A company's website has suffered several denial of service (DoS) attacks and wishes to t
dddd dd dd dd dd dd dd dd dd dd dd dd dd dd dd
hwart future attacks. Which security principle is the company addressing? A Availability B A
dd dd dd dd dd dd dd dd dd dd dd dd dd
uthenticity C Confidentiality D Possession dd dd dd dd
[Verified Solution]: A dd dddd