Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 93 pages
Exam (elaborations)

WGU C836 Fundamentals of Information Security OA 2026-180 QUESTIONS AND ANSWERS ALREADY GRADED A+. 100% Verified Solutions | Updated Per Latest Guidelines | Graded A+

Document preview thumbnail
Preview 4 out of 93 pages

The WGU C836 Fundamentals of Information Security course provides a comprehensive overview of the principles and practices essential for safeguarding information assets. This review document systematically addresses the core domains of information security, including risk management, security architecture, network security, identity and access management, and security operations. It emphasizes the application of security concepts in real-world scenarios, preparing students for the Objective Assessment. The content is aligned with industry standards and frameworks, ensuring relevance and currency. Each of the 200 questions is designed to test critical thinking and practical knowledge, with detailed rationales that explain both correct and incorrect answers. This guide serves as an indispensable resource for students seeking to excel in the course and in their future careers in information security. By mastering the material presented, students will gain a solid foundation in protecting organizational assets from a wide array of threats.

Content preview

, WGU C836 Fundamentals of Information Security
Comprehensive OA Review | 2026/2027 Edition | 200 Verified
Questions - 180 Questions with Answers
WGU C836 Fundamentals of Information Security OA 2026-180 QUESTIONS AND ANSWERS ALREADY
GRADED A+. 100% Verified Solutions | Updated Per Latest Guidelines | Graded A+

This comprehensive review document is meticulously crafted for Western Governors University's C836
Fundamentals of Information Security course, targeting the 2026/2027 academic year. It contains 200
verified questions that mirror the format and rigor of the Objective Assessment (OA), ensuring
thorough preparation. Each question is accompanied by detailed rationales and explanations to
reinforce key concepts. This guide is an essential tool for mastering the fundamental principles of
information security and achieving a passing score on the OA.


Key Features:
Introduction to Information Security: Core principles, threats, vulnerabilities, and risk management
Security Architecture and Design: Security models, frameworks, and enterprise architecture
Network Security: Network protocols, attacks, and defense mechanisms
Identity and Access Management (IAM): Authentication, authorization, and accounting
Security Operations: Monitoring, incident response, and business continuity
Cryptography: Encryption, hashing, digital signatures, and PKI
Physical Security: Facility controls, environmental controls, and personnel security
Legal, Regulations, and Compliance: Laws, standards, and ethical practices
Risk Management: Risk assessment, mitigation, and risk treatment strategies
Security Policies and Procedures: Development, implementation, and enforcement
Software Development Security: Secure coding, application security, and DevSecOps
Cloud Security: Cloud architecture, shared responsibility model, and cloud-specific threats
Updates for 2026:
- Updated to reflect the latest CompTIA Security+ and ISC2 CISSP exam objectives
- Incorporates recent changes in NIST and ISO 27001 frameworks
- Includes new questions on emerging threats like ransomware and supply chain attacks
- Revised rationales to align with current best practices in information security
- Enhanced coverage of cloud security and zero trust architecture
Abstract:
The WGU C836 Fundamentals of Information Security course provides a comprehensive overview of the principles
and practices essential for safeguarding information assets. This review document systematically addresses the
core domains of information security, including risk management, security architecture, network security, identity
and access management, and security operations. It emphasizes the application of security concepts in real-world
scenarios, preparing students for the Objective Assessment. The content is aligned with industry standards and
frameworks, ensuring relevance and currency. Each of the 200 questions is designed to test critical thinking and
practical knowledge, with detailed rationales that explain both correct and incorrect answers. This guide serves as
an indispensable resource for students seeking to excel in the course and in their future careers in information
security. By mastering the material presented, students will gain a solid foundation in protecting organizational
assets from a wide array of threats.
Keywords:
Information Security Fundamentals, WGU C836, Objective Assessment, Risk Management, Network Security,




Page 1

,Cryptography, Security Operations, Compliance
Answer Format:
Each question is presented in multiple-choice format, followed by the correct answer and a comprehensive
rationale. Rationales explain why the correct answer is right and why the distractors are incorrect, reinforcing key
concepts. Additionally, some questions include scenario-based explanations to illustrate practical application.
Compliance Checklist:
Aligned with WGU C836 course of study and OA blueprint
Updated for 2026/2027 academic year
Includes 200 verified questions with detailed rationales
Covers all domains as per the latest CompTIA Security+ and ISC2 CISSP objectives
Formatted for easy navigation and self-assessment
Content Area Overview:

Content Area Questions Key Topics Weight

Introduction to Information 1-20 CIA triad, threats, vulnerabilities, risk 10%
Security management basics
Security Architecture and Design 21-40 Security models, frameworks, enterprise 10%
architecture
Network Security 41-70 Network protocols, attacks, defense 15%
mechanisms
Identity and Access 71-90 Authentication, authorization, accounting 10%
Management (IAM)
Security Operations 91-110 Monitoring, incident response, business 10%
continuity
Cryptography 111-130 Encryption, hashing, digital signatures, PKI 10%

Physical Security 131-145 Facility controls, environmental controls, 7.5%
personnel security
Legal, Regulations, and 146-160 Laws, standards, ethical practices 7.5%
Compliance
Risk Management 161-175 Risk assessment, mitigation, risk treatment 7.5%
strategies
Security Policies and Procedures 176-185 Development, implementation, enforcement 5%

Software Development Security 186-195 Secure coding, application security, 5%
DevSecOps
Cloud Security 196-200 Cloud architecture, shared responsibility 2.5%
model, cloud-specific threats




Page 2

, Q1. During a risk assessment, a vulnerability is identified in a legacy system that
stores sensitive customer data. The system is critical to operations and cannot be
patched immediately. Which risk treatment strategy is most appropriate to
implement first?
A. Risk acceptance
B. Risk mitigation
C. Risk transfer
D. Risk avoidance
Correct Answer: B. Risk mitigation
Rationale: Risk mitigation involves implementing controls to reduce the likelihood or
impact of a vulnerability. Since the system cannot be patched immediately, compensating
controls (e.g., network segmentation, enhanced monitoring) are the first step. Acceptance
is not ideal because the risk is avoidable. Transfer (e.g., cyber insurance) does not reduce
the actual vulnerability. Avoidance would require decommissioning the system, which is
not possible due to operational criticality.
Why Wrong:
A - Accepting the risk without action is inappropriate when mitigation options exist.
C - Transferring risk via insurance does not reduce the technical vulnerability.
D - Avoidance would require removing the system, which is not feasible due to
operational needs.
Reference: Whitman, M.E., & Mattord, H.J. (2021). Principles of Information Security,
7th ed., Ch. 4.

Q2. In a zero-trust architecture, which control is primarily used to enforce
least-privilege access to applications and data?
A. Micro-segmentation
B. Network access control (NAC)
C. Perimeter firewall
D. Single sign-on (SSO)
Correct Answer: A. Micro-segmentation
Rationale: Micro-segmentation creates isolated zones within the network, enabling
granular access controls and limiting lateral movement. NAC controls device access but
does not enforce per-application least privilege. Perimeter firewalls are insufficient in
zero-trust because they assume trust inside the network. SSO simplifies authentication but
does not enforce least privilege.
Why Wrong:
B - NAC focuses on device compliance at network entry, not per-application access.
C - Perimeter firewalls are considered inadequate in zero-trust due to assumed internal
trust.




Page 3

Document information

Uploaded on
August 10, 2026
Number of pages
93
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$30.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
PremiumExamBank
4.8
(1058)
Sold
443
Followers
71
Items
6914
Last sold
7 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions