WGU D118 NETWORK AND SECURITY -
APPLICATIONS COMPREHENSIVE
ASSESSMENT QUESTIONS AND
CORRECT DETAILED ANSWERS
(VERIFIED ANSWERS)
1. In the context of the Diffie-Hellman key exchange protocol, what is the primary security
objective addressed during the initial handshake?
A. Securely establishing a shared secret over an insecure channel
B. Providing non-repudiation for the session initiation
C. Ensuring the integrity of the messages exchanged
D. Encrypting the payload using asymmetric encryption
Answer: A
Conceptual Explanation: Diffie-Hellman is designed to allow two parties to establish a
shared secret key over an unsecure medium, which can then be used for symmetric
encryption.
2. A security administrator is configuring a firewall to block all traffic by default and only
allow specific services. Which security principle is being applied?
A. Defense in Depth
,B. Separation of Duties
C. Least Privilege
D. Implicit Deny
Answer: D
Conceptual Explanation: Implicit Deny is a principle where any traffic that is not explicitly
permitted is blocked by default.
3. Which authentication protocol uses a ‘ticket-granting’ system to provide single sign-on
(SSO) capabilities within a Windows domain environment?
A. Kerberos
B. LDAP
C. RADIUS
D. TACACS+
Answer: A
Conceptual Explanation: Kerberos uses a Key Distribution Center (KDC) to issue Ticket-
Granting Tickets (TGT) and service tickets for SSO functionality.
4. Which type of certificate involves the highest level of vetting and provides a visual cue,
such as a green address bar, in some legacy browsers?
A. Domain Validated (DV)
B. Organization Validated (OV)
, C. Extended Validation (EV)
D. Wildcard Certificate
Answer: C
Conceptual Explanation: Extended Validation (EV) certificates require the most rigorous
identity verification process by the Certificate Authority.
5. When using IPsec, which protocol provides data confidentiality in addition to
authentication and integrity?
A. ESP (Encapsulating Security Payload)
B. AH (Authentication Header)
C. IKE (Internet Key Exchange)
D. L2TP (Layer 2 Tunneling Protocol)
Answer: A
Conceptual Explanation: ESP provides encryption for confidentiality, whereas AH only
provides authentication and integrity but no encryption.
6. Which hashing algorithm is currently considered collision-resistant and suitable for
verifying digital signatures?
A. SHA-256
B. SHA-1
C. MD5
APPLICATIONS COMPREHENSIVE
ASSESSMENT QUESTIONS AND
CORRECT DETAILED ANSWERS
(VERIFIED ANSWERS)
1. In the context of the Diffie-Hellman key exchange protocol, what is the primary security
objective addressed during the initial handshake?
A. Securely establishing a shared secret over an insecure channel
B. Providing non-repudiation for the session initiation
C. Ensuring the integrity of the messages exchanged
D. Encrypting the payload using asymmetric encryption
Answer: A
Conceptual Explanation: Diffie-Hellman is designed to allow two parties to establish a
shared secret key over an unsecure medium, which can then be used for symmetric
encryption.
2. A security administrator is configuring a firewall to block all traffic by default and only
allow specific services. Which security principle is being applied?
A. Defense in Depth
,B. Separation of Duties
C. Least Privilege
D. Implicit Deny
Answer: D
Conceptual Explanation: Implicit Deny is a principle where any traffic that is not explicitly
permitted is blocked by default.
3. Which authentication protocol uses a ‘ticket-granting’ system to provide single sign-on
(SSO) capabilities within a Windows domain environment?
A. Kerberos
B. LDAP
C. RADIUS
D. TACACS+
Answer: A
Conceptual Explanation: Kerberos uses a Key Distribution Center (KDC) to issue Ticket-
Granting Tickets (TGT) and service tickets for SSO functionality.
4. Which type of certificate involves the highest level of vetting and provides a visual cue,
such as a green address bar, in some legacy browsers?
A. Domain Validated (DV)
B. Organization Validated (OV)
, C. Extended Validation (EV)
D. Wildcard Certificate
Answer: C
Conceptual Explanation: Extended Validation (EV) certificates require the most rigorous
identity verification process by the Certificate Authority.
5. When using IPsec, which protocol provides data confidentiality in addition to
authentication and integrity?
A. ESP (Encapsulating Security Payload)
B. AH (Authentication Header)
C. IKE (Internet Key Exchange)
D. L2TP (Layer 2 Tunneling Protocol)
Answer: A
Conceptual Explanation: ESP provides encryption for confidentiality, whereas AH only
provides authentication and integrity but no encryption.
6. Which hashing algorithm is currently considered collision-resistant and suitable for
verifying digital signatures?
A. SHA-256
B. SHA-1
C. MD5