INFORMATION SECURITY EXAM LATEST
UPDATE 2026|2027| A COMPREHENSIVE
REVIEW OF 300 PRACTICE QUESTIONS
WITH ANSWERS AND RATIONALES
|ASSURED PASS!!!
Introduction
This practice exam is designed to help you prepare for the WGU D430
Fundamentals of Information Security assessment. It contains 300 unique, non-
duplicated multiple-choice questions covering all major exam domains:
• The CIA Triad & Foundational Security Principles (Confidentiality,
Integrity, Availability, Pinkerian Hexad, attack categories)
• Risk Management (risk identification, assessment, mitigation,
ALE/SLE/ARO calculations, risk response strategies)
• Access Control & Authentication (least privilege, separation of duties,
authentication factors, AAA)
• Cryptography (symmetric/asymmetric encryption, hashing, digital
signatures, PKI, salting)
• Security Controls & Architecture (physical, technical, administrative
controls, defense in depth, Zero Trust)
• Threats & Vulnerabilities (malware, phishing, social engineering, SQL
injection, insider threats)
, • Incident Response, Business Continuity & Disaster Recovery (BCP, DRP,
RTO, RPO, forensics)
• Governance, Compliance & Policies (laws, regulations, frameworks,
security policies)
• Network & Application Security (firewalls, IDS/IPS, VPNs, OWASP,
secure coding)
• Physical Security & Emerging Topics (cloud security, IoT, mobile security,
AI threats)
SECTION 1: FOUNDATIONAL PRINCIPLES & CIA TRIAD (Questions 1–
30)
1. Which principle of the CIA Triad ensures that data is accessible only to
authorized users?
A. Integrity
B. Confidentiality
C. Availability
D. Non-repudiation
Rationale: Confidentiality ensures information is not disclosed to unauthorized
individuals, entities, or processes. Integrity ensures data is not modified;
Availability ensures data is accessible when needed; non-repudiation is a separate
concept ensuring a party cannot deny an action.
2. A hospital's patient records system goes down for 8 hours, preventing
doctors from accessing critical information. Which element of the CIA Triad is
primarily affected?
A. Confidentiality
B. Integrity
,C. Availability
D. Authentication
Rationale: Availability ensures systems and data are accessible to authorized users
when needed. An 8-hour outage directly impacts availability, even if confidentiality
and integrity remain intact.
3. Which of the following best describes the Pinkerian Hexad?
A. A six-element security model adding Possession, Authenticity, and Utility to the
CIA Triad
B. A six-step risk management framework
C. A six-layer network defense architecture
D. A six-factor authentication model
Rationale: The Pinkerian Hexad extends the CIA Triad by adding Possession
(control of data), Authenticity (data is genuine), and Utility (data is useful), making
six total elements.
4. An attacker intercepts a message between two parties and reads its
contents. Which attack category does this represent?
A. Interruption
B. Modification
C. Interception
D. Fabrication
Rationale: Interception involves unauthorized access to data in transit or at rest.
Interruption disrupts availability; Modification alters data; Fabrication creates false
data.
5. A hacker alters a bank transfer amount from $100 to $10,000 during
transmission. Which attack category is this?
, A. Interception
B. Modification
C. Fabrication
D. Interruption
Rationale: Modification involves unauthorized alteration of data. The attacker
changed the data's integrity, which is a classic modification attack.
6. Which of the following is an example of a Fabrication attack?
A. Reading an encrypted email
B. Deleting a database
C. Creating a fake employee record in an HR system
D. Overloading a web server
Rationale: Fabrication involves creating false data or transactions. Adding a fake
employee record is fabrication. Deleting data is interruption; overloading is
interruption/DoS.
7. Which element of the Pinkerian Hexad ensures that data is in the control of
the correct party?
A. Authenticity
B. Utility
C. Possession
D. Integrity
Rationale: Possession ensures that data is controlled or held by the authorized
party, even if confidentiality is not breached (e.g., stolen encrypted laptop).
8. A company's website is defaced, but the underlying data remains
unchanged. Which element of the Pinkerian Hexad is most affected?
A. Confidentiality
B. Integrity