WGU C845 Information Systems Security Questions with Verified
Answers (Correct Update)
Question 1: AAA, Triple A
Answer: Ans-Referred to as the AAA of access control: authentication, authorization,
and accounting
Question 2: Algorithm
Answer: Ans-A mathematical function cryptographic algorithm that encrypts or decrypts
text
Question 3: Authentication
Answer: Ans-Method used to verify the identity claim of a user
Question 4: Authorization
Answer: Ans-The act of defining the network resources, applications, and data that
may be accessed by a user
Question 5: Availability
Answer: Ans-One of the central principles of the AIC triad. A core goal of a security
professional is to ensure that data and hardware are available when the user requires them
Question 6: Confidentiality
Answer: Ans-One of the central principles of the AIC triad; represents a core goal of
the security professional to ensure, possibly through encryption, that sensitive information is
protected from exposure
Question 7: Due care
Answer: Ans-The taking of actions that a reasonable and prudent person would take in a
given situation
Question 8: Due diligence
Answer: Ans-Refers to taking actions that prevent harm to persons or their property
Page 1
,Question 9: Identification
Answer: Ans-A unique designation assigned to a member of a group. A claim presented
when desiring access
Question 10: Integrity
Answer: Ans-One of the central principles of the AIC triad; represents a core goal of a
security professional, to ensure that no changes have occurred to data or a system, thus
ensuring the data's integrity
Question 11: Job rotation
Answer: Ans-The act of shifting individuals between roles and responsibilities to prohibit
security violations
Question 12: Least privilege
Answer: Ans-Security principle that individuals are provided with the least amount of
information required to perform their jobs or duties
Question 13: Mandatory vacation
Answer: Ans-A security control that allows the monitoring of business functions
without the availability of a principal or responsible individual
Question 14: Separation of duties
Answer: Ans-A security program in which two or more people are required to
independently perform activities to complete an action
Question 15: User ID
Answer: Ans-An assigned identification. Every user of the system should have a unique user
ID. Its use must still be authenticated
Question 16: Certification
Answer: Ans-The successful conclusion after a system or application has been tested
against preestablished standards
Page 2
, Question 17: Vulnerability assessment
Answer: Ans-The organized set of steps used to identify and analyse threats
and vulnerabilities to determine an organization's overall risk
Question 18: Access control list (ACL)
Answer: Ans-A list of subjects and assigned rights used in access control.
Question 19: Administrative controls
Answer: Ans-Controls put in place to enforce policies and directives as
dictated by the organization
Question 20: Biometrics
Answer: Ans-Hardware or software used to measure human characteristics as part of an
authentication system
Question 21: Data at rest
Answer: Ans-Any data in a storage location and not moving between locations or being
processed by an application.
Question 22: Defense diversity
Answer: Ans-The use of two devices from separate vendors. For instance, the use
of two firewalls that provide slightly different services or rules in order to support the defense
in-depth strategy
Question 23: Defense in depth
Answer: Ans-A layered approach to defense. The placement of several controls in a
series in an effort to slow down, discourage, or eliminate an attacker
Question 24: False acceptance rate (FAR)
Answer: Ans-An authentication error rate in which an unknown user is
identified as a known user and is mistakenly allowed access. Also referred to as a Type II
biometric error
Page 3
Answers (Correct Update)
Question 1: AAA, Triple A
Answer: Ans-Referred to as the AAA of access control: authentication, authorization,
and accounting
Question 2: Algorithm
Answer: Ans-A mathematical function cryptographic algorithm that encrypts or decrypts
text
Question 3: Authentication
Answer: Ans-Method used to verify the identity claim of a user
Question 4: Authorization
Answer: Ans-The act of defining the network resources, applications, and data that
may be accessed by a user
Question 5: Availability
Answer: Ans-One of the central principles of the AIC triad. A core goal of a security
professional is to ensure that data and hardware are available when the user requires them
Question 6: Confidentiality
Answer: Ans-One of the central principles of the AIC triad; represents a core goal of
the security professional to ensure, possibly through encryption, that sensitive information is
protected from exposure
Question 7: Due care
Answer: Ans-The taking of actions that a reasonable and prudent person would take in a
given situation
Question 8: Due diligence
Answer: Ans-Refers to taking actions that prevent harm to persons or their property
Page 1
,Question 9: Identification
Answer: Ans-A unique designation assigned to a member of a group. A claim presented
when desiring access
Question 10: Integrity
Answer: Ans-One of the central principles of the AIC triad; represents a core goal of a
security professional, to ensure that no changes have occurred to data or a system, thus
ensuring the data's integrity
Question 11: Job rotation
Answer: Ans-The act of shifting individuals between roles and responsibilities to prohibit
security violations
Question 12: Least privilege
Answer: Ans-Security principle that individuals are provided with the least amount of
information required to perform their jobs or duties
Question 13: Mandatory vacation
Answer: Ans-A security control that allows the monitoring of business functions
without the availability of a principal or responsible individual
Question 14: Separation of duties
Answer: Ans-A security program in which two or more people are required to
independently perform activities to complete an action
Question 15: User ID
Answer: Ans-An assigned identification. Every user of the system should have a unique user
ID. Its use must still be authenticated
Question 16: Certification
Answer: Ans-The successful conclusion after a system or application has been tested
against preestablished standards
Page 2
, Question 17: Vulnerability assessment
Answer: Ans-The organized set of steps used to identify and analyse threats
and vulnerabilities to determine an organization's overall risk
Question 18: Access control list (ACL)
Answer: Ans-A list of subjects and assigned rights used in access control.
Question 19: Administrative controls
Answer: Ans-Controls put in place to enforce policies and directives as
dictated by the organization
Question 20: Biometrics
Answer: Ans-Hardware or software used to measure human characteristics as part of an
authentication system
Question 21: Data at rest
Answer: Ans-Any data in a storage location and not moving between locations or being
processed by an application.
Question 22: Defense diversity
Answer: Ans-The use of two devices from separate vendors. For instance, the use
of two firewalls that provide slightly different services or rules in order to support the defense
in-depth strategy
Question 23: Defense in depth
Answer: Ans-A layered approach to defense. The placement of several controls in a
series in an effort to slow down, discourage, or eliminate an attacker
Question 24: False acceptance rate (FAR)
Answer: Ans-An authentication error rate in which an unknown user is
identified as a known user and is mistakenly allowed access. Also referred to as a Type II
biometric error
Page 3