WGU D430 FUNDAMENTALS OF
INFORMATION SECURITY VERIFIED
EXAM 2025
Define the confidentiality in the CIA triad. - Correct Answer-Our ability to protect data
from those who are not authorized to view it. (Hiding atm pin, covering comp screen,
keep track of devices)
Define integrity in the CIA triad. - Correct Answer-The ability to prevent people from
changing your data and the ability to reverse unwanted changes. (Access control, read
and write permissions, info correct)
Define the availability in the CIA triad. - Correct Answer-Our data needs to be
accessible when we need it.(because of power loss and such)
Define information security. - Correct Answer-The protection of information and
information systems from unauthorized access, use, disclosure, disruption, modification,
or destruction in order to provide confidentiality, integrity, and availability.
Define the Parkerian Hexad and its principles. - Correct Answer-The Parkerian Hexad
includes confidentiality, integrity, and availability from the CIA triad. It also includes
possession (or control), authenticity, and utility.
Authenticity - Correct Answer-Whether the data in question comes from who or where it
says it comes from (i.e. did this person actually send this email?)
Confidentiality is affected by what type of attack? - Correct Answer-Interception (eaves
dropping)
Integrity is affected by what type of attacks? - Correct Answer-Interruption (assets are
unusable), modification (tampering with an asset), fabrication (generating false data)
Authenticity is affected by what type of attacks? - Correct Answer-Interruption (assets
are unusable), modification (tampering with an asset), fabrication (generating false data)
Utility - Correct Answer-How useful the data is to you (can be a spectrum, not just yes
or no)
Possession - Correct Answer-Do you physically have the data in question? Used to
describe the scope of a loss
Identify the four types of attacks - Correct Answer-interception, interruption,
modification, and fabrication
Interception attacks - Correct Answer-Make your assets unusable or unavailable
Interruption attacks - Correct Answer-cause assets to become unusable or unavailable
for our use, on a temporary or permanent basis
Modification attacks - Correct Answer-Tampering with an asset
Fabrication attacks - Correct Answer-Generating data, process, and communications
Define the risk management process(car) - Correct Answer-1. Identify assets
2. Identify threats
3. Assess vulnerabilities
4. Assess risks
5. Mitigate risks
WGU D430
, WGU D430
Define the incident response process and its stages.(zombie) - Correct Answer-
Preparation
Detection and analysis
Containment
Eradication
Recovery
Preparation in incident response - Correct Answer-creating policies and procedures
Detection in incident response - Correct Answer-Using tools and humans to decide if an
incident is an incident
Defense in Depth - Correct Answer-employing multiple layers of controls to avoid a
single point of failure
Identify types of controls to mitigate risk - Correct Answer-physical, logical,
administrative
Identify elements of risk management in policies and procedures. - Correct Answer-
Development of robust policies
Identification of emergent recent
Identify elements of internal weakness
Identify the layers of a defense-in-depth strategy.(body) - Correct Answer-External
network
Internal network
Host
Application
Data
Define identification - Correct Answer-The claim of who we/networks are
Define identity verification. - Correct Answer-Someone claims who they are and you
take it one step father and ask for ID
Define authentication - Correct Answer-A set of methods used to determine if a claim of
identity is true.
Compare authentication types. - Correct Answer-Multifactor authentication
Mutual authentication
Identify password security best practices. - Correct Answer-Upper case
Lower case
Numbers
Symbols
Identify the factors involved in a multifactor authentication technique. - Correct Answer-
Something you do
Something you have
Where you are
Define accountability and its benefits - Correct Answer-nonrepudiation, deterrence,
intrusion detection and prevention, and admissibility of records
Auditing - Correct Answer-Hold users of your system accountable. A methodical
examination and review of an organization's records.
nonrepudiation measures - Correct Answer-make it so that someone can't send an
email and then deny sending it. usually with a digital signature.
Which standards apply to any financial entity policies? - Correct Answer-Gramm-Leech-
Bliley
WGU D430