NEW (2025/2026) WGU C795 PRACTICE EXAM QUESTIONS
AND ANSWERS
Which one of the following tools is used primarily to perform network
discovery scans?
Nmap
Adam recently ran a network port scan of a web server running in his
organization. He ran the scan from an external network to get an attacker's
perspective on the scan. Which one of the following results is the greatest cause
for alarm?
1433/open
Which one of the following factors should not be taken into consideration when
planning a security testing schedule for a particular system?
Desire to experiment with new testing tools
Which one of the following is not normally included in a security assessment?
mitigation of vulnerabilities
Who is the intended audience for a security assessment report?
Management
Wendy is considering the use of a vulnerability scanner in her organization.
What is the proper role of a vulnerability scanner?
they locate known security holes
Alan ran an nmap scan against a server and determined that port 80 is open on
the server. What tool would likely provide him the best additional information
about the server's purpose and the identity of the server's operator?
Web browser
, What port is typically used to accept administrative connections using the SSH
utility?
22
Which one of the following tests provides the most accurate and detailed
information about the security state of a server?
authenticated scan
What type of network discovery scan only uses the first two steps of the TCP
handshaked?
TCP SYN scan
Matthew would like to test systems on his network for SQL injection
vulnerabilities. Which one of the following tools would be best suited to this
task?
Web vulnerability scanner
Badin Industries runs a web application that processes e-commerce orders and
handles credit card transactions. As such, it is subject to the Payment Card
Industry Data Security Standard (PCI DSS). The company recently performed a
web vulnerability scan of the application and it had no unsatisfactory findings.
How often must Badin rescan the application?
At least annually
Grace is performing a penetration test against a client's network and would like
to use a tool to assist in automatically executing common exploits. Which one
of the following security tools will best meet her needs?
Metasploit Framework
Paul would like to test his application against slightly modified versions of
previously used input. What type of test does Paul intend to perform?
Mutation fuzzing
Users of a banking application may try to withdraw funds that don't exist from
their account. Developers are aware of this threat and implemented code to
protect against it. What type of software testing would most likely catch this
type of vulnerability if the developers have not already remediated it?
AND ANSWERS
Which one of the following tools is used primarily to perform network
discovery scans?
Nmap
Adam recently ran a network port scan of a web server running in his
organization. He ran the scan from an external network to get an attacker's
perspective on the scan. Which one of the following results is the greatest cause
for alarm?
1433/open
Which one of the following factors should not be taken into consideration when
planning a security testing schedule for a particular system?
Desire to experiment with new testing tools
Which one of the following is not normally included in a security assessment?
mitigation of vulnerabilities
Who is the intended audience for a security assessment report?
Management
Wendy is considering the use of a vulnerability scanner in her organization.
What is the proper role of a vulnerability scanner?
they locate known security holes
Alan ran an nmap scan against a server and determined that port 80 is open on
the server. What tool would likely provide him the best additional information
about the server's purpose and the identity of the server's operator?
Web browser
, What port is typically used to accept administrative connections using the SSH
utility?
22
Which one of the following tests provides the most accurate and detailed
information about the security state of a server?
authenticated scan
What type of network discovery scan only uses the first two steps of the TCP
handshaked?
TCP SYN scan
Matthew would like to test systems on his network for SQL injection
vulnerabilities. Which one of the following tools would be best suited to this
task?
Web vulnerability scanner
Badin Industries runs a web application that processes e-commerce orders and
handles credit card transactions. As such, it is subject to the Payment Card
Industry Data Security Standard (PCI DSS). The company recently performed a
web vulnerability scan of the application and it had no unsatisfactory findings.
How often must Badin rescan the application?
At least annually
Grace is performing a penetration test against a client's network and would like
to use a tool to assist in automatically executing common exploits. Which one
of the following security tools will best meet her needs?
Metasploit Framework
Paul would like to test his application against slightly modified versions of
previously used input. What type of test does Paul intend to perform?
Mutation fuzzing
Users of a banking application may try to withdraw funds that don't exist from
their account. Developers are aware of this threat and implemented code to
protect against it. What type of software testing would most likely catch this
type of vulnerability if the developers have not already remediated it?