WGU C795 Master's Course -
Cybersecurity Management II Tactical
Questions and Answers
A chief information officer (CIO) recently read an article involving a similar
company that was hit with ransomware due to ineffective patch-management
practices. The CIO tasks a security professional with gathering metrics on the
effectiveness of the company's patch-management program to avoid a similar
incident.
Which method enables the security professional to gather current, accurate
metrics?
A Review authenticated vulnerability scan reports
B Review reports from Windows Update
C Review patch history on nonproduction systems
©COPYRIGHT 2025 ALL RIGHTS RESERVED 1
,D Review patch tickets in the change control system - Correct answer-A
A combined mail server and calendaring server environment contains no secure
sockets layer (SSL) certificate.
Which security principle of the CIA triad is affected by the lack of an SSL
certificate?
A Confidentiality
B Integrity
C Authentication
D Availability - Correct answer-A
A company develops a business continuity plan in addition to an emergency
communication plan.
What should be included in the company's emergency communication plan?
(Choose 2)
©COPYRIGHT 2025 ALL RIGHTS RESERVED 2
,A Alternate means of contact
B Backup people for each role
C The best time to call each person
D Employee's phone service providers - Correct answer-AB
A company does not have a disaster recovery plan (DRP) and suffers a multiday
power outage.
Which provisioning should the company perform to provide stable power for a
long period of time?
A Purchase generators
B Purchase additional servers
C Create a RAID array
D Create a failover cluster - Correct answer-A
A company has identified a massive security breach in its healthcare records
department. Over 50% of customers' personally identifiable information (PII) has
been stolen. The customers are aware of the breach, and the company is taking
©COPYRIGHT 2025 ALL RIGHTS RESERVED 3
, actions to protect customer assets through the personal security policy, which
addresses PII data.
Which preventive measure should the company pursue to protect against future
attacks?
A Require cognitive passwords
B Employ password tokens
C Use network-based and host-based firewalls
D Install auditing tools - Correct answer-C
A company has signed a contract with a third-party vendor to use the vendor's
inventory management system hosted in a cloud. For convenience, the vendor set
up the application to use Lightweight Directory Access Protocol (LDAP) queries
but did not enable secure LDAP queries or implement a secure sockets layer (SSL)
on the application's web server. The vendor does not have the ability to secure the
system, and company management insists on using the application.
©COPYRIGHT 2025 ALL RIGHTS RESERVED 4
Cybersecurity Management II Tactical
Questions and Answers
A chief information officer (CIO) recently read an article involving a similar
company that was hit with ransomware due to ineffective patch-management
practices. The CIO tasks a security professional with gathering metrics on the
effectiveness of the company's patch-management program to avoid a similar
incident.
Which method enables the security professional to gather current, accurate
metrics?
A Review authenticated vulnerability scan reports
B Review reports from Windows Update
C Review patch history on nonproduction systems
©COPYRIGHT 2025 ALL RIGHTS RESERVED 1
,D Review patch tickets in the change control system - Correct answer-A
A combined mail server and calendaring server environment contains no secure
sockets layer (SSL) certificate.
Which security principle of the CIA triad is affected by the lack of an SSL
certificate?
A Confidentiality
B Integrity
C Authentication
D Availability - Correct answer-A
A company develops a business continuity plan in addition to an emergency
communication plan.
What should be included in the company's emergency communication plan?
(Choose 2)
©COPYRIGHT 2025 ALL RIGHTS RESERVED 2
,A Alternate means of contact
B Backup people for each role
C The best time to call each person
D Employee's phone service providers - Correct answer-AB
A company does not have a disaster recovery plan (DRP) and suffers a multiday
power outage.
Which provisioning should the company perform to provide stable power for a
long period of time?
A Purchase generators
B Purchase additional servers
C Create a RAID array
D Create a failover cluster - Correct answer-A
A company has identified a massive security breach in its healthcare records
department. Over 50% of customers' personally identifiable information (PII) has
been stolen. The customers are aware of the breach, and the company is taking
©COPYRIGHT 2025 ALL RIGHTS RESERVED 3
, actions to protect customer assets through the personal security policy, which
addresses PII data.
Which preventive measure should the company pursue to protect against future
attacks?
A Require cognitive passwords
B Employ password tokens
C Use network-based and host-based firewalls
D Install auditing tools - Correct answer-C
A company has signed a contract with a third-party vendor to use the vendor's
inventory management system hosted in a cloud. For convenience, the vendor set
up the application to use Lightweight Directory Access Protocol (LDAP) queries
but did not enable secure LDAP queries or implement a secure sockets layer (SSL)
on the application's web server. The vendor does not have the ability to secure the
system, and company management insists on using the application.
©COPYRIGHT 2025 ALL RIGHTS RESERVED 4