WGU D482 2025 EXAM QUESTIONS AND VERIFIED A
CORRECT ANSWERS) A+ GRADED | ALREADY
A claptop chas cbeen cstolen, cand cthe cdata chas cbeen cseen cfor csale con cthe cdarknet. cWhich cproc
cconfidentiality cof cthe cdata? c- cCORRECT cANS✔✔Hard cDrive cEncryption
Classify ceach cattack cmethod cin crelation cto cits cdirect cimpact con cthe cCIA ctriad. c- cCORRECT cA
cConfidentiality
DNS cPoisoning: cIntegrity
Covert cChannels: cConfidentiality
DDoS: cAvailability
A csecurity cadministrator chas cconfigured ca csmall ckeysize cto cprotect cthe cVPN.
Which csecurity cobjective cdoes cthis caffect? c- cCORRECT cANS✔✔Confidentiality
A claptop chas cbeen cstolen, cand cthe cdata chas cbeen cseen cfor csale con cthe cdarknet.
Which cprocess ccould chave cprotected cthe cconfidentiality cof cthe cdata? c- cCORRECT cANS✔✔Ha
When cbrowsing cto ca cfinancial cwebsite, ca cuser creceives can cerror con cthe cbrowser cthat cpoints ct
on cthe cwebsite. cThe cuser creviews cthe ccertificate cand cmaps cit cto ca cknown ccertificate cauthority
Why cdid cthe cuser cneed cto cperform cthese cactions? c- cCORRECT cANS✔✔To cestablish ca ctrust c
A cteam cof cscientists cis cworking con ca csecure cproject. cThe cnetwork cadministrator cneeds cto ccon
network cfor cthe cteam cthat cis cnot croutable cfrom cthe cInternet. cA cfirewall cis cprotecting cthe cscien
and cis cusing cnetwork caddress ctranslation c(NAT) cto ctranslate cthe cinternal cIP caddresses cto cpub
addresses.
Which cIP caddress cshould cthe cnetwork cadministrator cconfigure con cthe cinside cinterface cof cthe cf
cANS✔✔10.14.15.16
An cad choc cnetwork cdesign cteam chas cjust cfinished ca cpresentation con cthe clatest cupdates cto cth
, security cadministrator cdiscovers cthat cthe cencryption cprotocol cthe cdevices cuse cis cnot cvery csecu
cbe cdiscovered cby ca cmalicious chacker cin conly ca cfew cminutes. cAfter cdiscussions cwith cother
security cprofessionals, cthe cadministrator clearns cthe cAPs ccan cimplement ca ckey cprotocol cthat cca
encryption ckey cevery cfew cseconds cand cprovide ca cper-packet cverification cat ceach cside cof cthe
communication.
Which csecurity cmeasure cis cthe ckey cprotocol cimplemented cto cprotect? c- cCORRECT cANS✔✔In
A crecently cterminated cemployee cfrom caccounting cused cseveral cwidely cavailable cprograms cin ca
attempt cto cexploit ca ccompany's cdatabase.
Which cterm cdescribes cthe cterminated cemployee? c- cCORRECT cANS✔✔Script ckiddies
An corganization chas crecently cundergone ca cperiod cof cgrowth, cboth cin cterms cof cbusiness copera
personnel. cThe cnetwork cinfrastructure chas ckept cpace, cgrowing cto caccommodate cthe cnew csize
structure. cMapping cand cauditing cof cthe cexpanded cnetwork cneeds cto cbe cdone. cOne cof cthe cfirs
that cthe crouter chas cpermissive crights cto call cunassigned cports.
What cis cthis cfinding can cexample cof? c- cCORRECT cANS✔✔A cvulnerability
A ccompany chas cbeen cthe ctarget cof cmultiple csocial cengineering cattacks cand cis cimplementing ca
mandatory csecurity cawareness ctraining cprogram cto creduce cthe crisk cof ca cfuture ccompromise. cT
administrator cis cmainly cconcerned cwith cthe cfollowing cattack cvectors:
Spoofed cemails ccontaining cfake cpassword creset clinks caimed cat charvesting cemployees' cpasswo
Phone ccalls cto cthe chelpdesk cby ca cmalicious cuser cpretending cto cbe can cemployee cneeding ca cp
A cmalicious cuser ctailgating cwhile cimpersonating ca ccontractor cto csteal cemployees' cmobile cdevic
What care cthe ctwo cvulnerabilities cthat cthe ccompany cneeds cto caddress cto cmeet cthe cabove crequ
cANS✔✔Untrained cusers cand cLack cof cSecure caccess ccontrol
An cemail clink ctakes ca cuser cto can conline cstore. cAfter cclicking cthe clink, cthe cuser cis credirected ct
online cstore.
Which ctype cof cattack cis coccurring? c- cCORRECT cANS✔✔Cross-site cscripting
Which cdevice cis cresponsible cfor cperforming cstateful cpacket cinspection con ctraffic ctraversing ccon
segments? c- cCORRECT cANS✔✔Firewall
Which cdevice cis cLayer c7 caware cand cprovides cboth cfiltering cof cunwanted csource cIP ctraffic cfrom
network cand cpolicy con cwhich cports cmay cbe cused? c- cCORRECT cANS✔✔Application cfirewall
A csoftware ccircuit cfirewall cis con cthe cnetwork cproviding cprotection cfor ca cweb cserver. cThere cis c
scripting cvulnerability con cthe cweb cserver.
How cwill cthe csoftware ccircuit cfirewall creact cto can cexploit cof cthis cvulnerability? c- cCORRECT cAN
con cinitial csession csetup.
During cpreproduction ctesting, ca ckey csecurity ccontrol cis cfound cto cbe cmissing. cThis coversight cin
allows cusers cto cview cdata cthey care cnot cauthorized cto caccess. cUpon creview cof cthe cinitial csecu
requirements, cit cwas cstated cthat cauthentication, cauthorization, cand caccounting c(AAA) cof cusers
required cin cthe cdesign cof cthe csystem.
What coccurred cduring cthe csystems cdevelopment clife ccycle c(SDLC) cthat ccaused cthis cproblem?
cobjective csecurity creviews cwere cconducted cto censure csecurity crequirements
were cbeing cmet cduring cthe cdevelopment cphase.
Many cof cthe cdevices ca ccompany cuses care cstand-alone, cthird-party cappliances. cWhile cthe capp
evaluated cfor csecurity cconcerns cat cthe ctime cof cpurchase, cmany chave creached cthe cend cof cthe
creplaced csoon.
What cshould ca csecurity cadministrator cdo cto cprotect cthese cassets cbefore cthey care cdisposed cof
cANS✔✔Use ca cdefense-in-depth cstrategy
CORRECT ANSWERS) A+ GRADED | ALREADY
A claptop chas cbeen cstolen, cand cthe cdata chas cbeen cseen cfor csale con cthe cdarknet. cWhich cproc
cconfidentiality cof cthe cdata? c- cCORRECT cANS✔✔Hard cDrive cEncryption
Classify ceach cattack cmethod cin crelation cto cits cdirect cimpact con cthe cCIA ctriad. c- cCORRECT cA
cConfidentiality
DNS cPoisoning: cIntegrity
Covert cChannels: cConfidentiality
DDoS: cAvailability
A csecurity cadministrator chas cconfigured ca csmall ckeysize cto cprotect cthe cVPN.
Which csecurity cobjective cdoes cthis caffect? c- cCORRECT cANS✔✔Confidentiality
A claptop chas cbeen cstolen, cand cthe cdata chas cbeen cseen cfor csale con cthe cdarknet.
Which cprocess ccould chave cprotected cthe cconfidentiality cof cthe cdata? c- cCORRECT cANS✔✔Ha
When cbrowsing cto ca cfinancial cwebsite, ca cuser creceives can cerror con cthe cbrowser cthat cpoints ct
on cthe cwebsite. cThe cuser creviews cthe ccertificate cand cmaps cit cto ca cknown ccertificate cauthority
Why cdid cthe cuser cneed cto cperform cthese cactions? c- cCORRECT cANS✔✔To cestablish ca ctrust c
A cteam cof cscientists cis cworking con ca csecure cproject. cThe cnetwork cadministrator cneeds cto ccon
network cfor cthe cteam cthat cis cnot croutable cfrom cthe cInternet. cA cfirewall cis cprotecting cthe cscien
and cis cusing cnetwork caddress ctranslation c(NAT) cto ctranslate cthe cinternal cIP caddresses cto cpub
addresses.
Which cIP caddress cshould cthe cnetwork cadministrator cconfigure con cthe cinside cinterface cof cthe cf
cANS✔✔10.14.15.16
An cad choc cnetwork cdesign cteam chas cjust cfinished ca cpresentation con cthe clatest cupdates cto cth
, security cadministrator cdiscovers cthat cthe cencryption cprotocol cthe cdevices cuse cis cnot cvery csecu
cbe cdiscovered cby ca cmalicious chacker cin conly ca cfew cminutes. cAfter cdiscussions cwith cother
security cprofessionals, cthe cadministrator clearns cthe cAPs ccan cimplement ca ckey cprotocol cthat cca
encryption ckey cevery cfew cseconds cand cprovide ca cper-packet cverification cat ceach cside cof cthe
communication.
Which csecurity cmeasure cis cthe ckey cprotocol cimplemented cto cprotect? c- cCORRECT cANS✔✔In
A crecently cterminated cemployee cfrom caccounting cused cseveral cwidely cavailable cprograms cin ca
attempt cto cexploit ca ccompany's cdatabase.
Which cterm cdescribes cthe cterminated cemployee? c- cCORRECT cANS✔✔Script ckiddies
An corganization chas crecently cundergone ca cperiod cof cgrowth, cboth cin cterms cof cbusiness copera
personnel. cThe cnetwork cinfrastructure chas ckept cpace, cgrowing cto caccommodate cthe cnew csize
structure. cMapping cand cauditing cof cthe cexpanded cnetwork cneeds cto cbe cdone. cOne cof cthe cfirs
that cthe crouter chas cpermissive crights cto call cunassigned cports.
What cis cthis cfinding can cexample cof? c- cCORRECT cANS✔✔A cvulnerability
A ccompany chas cbeen cthe ctarget cof cmultiple csocial cengineering cattacks cand cis cimplementing ca
mandatory csecurity cawareness ctraining cprogram cto creduce cthe crisk cof ca cfuture ccompromise. cT
administrator cis cmainly cconcerned cwith cthe cfollowing cattack cvectors:
Spoofed cemails ccontaining cfake cpassword creset clinks caimed cat charvesting cemployees' cpasswo
Phone ccalls cto cthe chelpdesk cby ca cmalicious cuser cpretending cto cbe can cemployee cneeding ca cp
A cmalicious cuser ctailgating cwhile cimpersonating ca ccontractor cto csteal cemployees' cmobile cdevic
What care cthe ctwo cvulnerabilities cthat cthe ccompany cneeds cto caddress cto cmeet cthe cabove crequ
cANS✔✔Untrained cusers cand cLack cof cSecure caccess ccontrol
An cemail clink ctakes ca cuser cto can conline cstore. cAfter cclicking cthe clink, cthe cuser cis credirected ct
online cstore.
Which ctype cof cattack cis coccurring? c- cCORRECT cANS✔✔Cross-site cscripting
Which cdevice cis cresponsible cfor cperforming cstateful cpacket cinspection con ctraffic ctraversing ccon
segments? c- cCORRECT cANS✔✔Firewall
Which cdevice cis cLayer c7 caware cand cprovides cboth cfiltering cof cunwanted csource cIP ctraffic cfrom
network cand cpolicy con cwhich cports cmay cbe cused? c- cCORRECT cANS✔✔Application cfirewall
A csoftware ccircuit cfirewall cis con cthe cnetwork cproviding cprotection cfor ca cweb cserver. cThere cis c
scripting cvulnerability con cthe cweb cserver.
How cwill cthe csoftware ccircuit cfirewall creact cto can cexploit cof cthis cvulnerability? c- cCORRECT cAN
con cinitial csession csetup.
During cpreproduction ctesting, ca ckey csecurity ccontrol cis cfound cto cbe cmissing. cThis coversight cin
allows cusers cto cview cdata cthey care cnot cauthorized cto caccess. cUpon creview cof cthe cinitial csecu
requirements, cit cwas cstated cthat cauthentication, cauthorization, cand caccounting c(AAA) cof cusers
required cin cthe cdesign cof cthe csystem.
What coccurred cduring cthe csystems cdevelopment clife ccycle c(SDLC) cthat ccaused cthis cproblem?
cobjective csecurity creviews cwere cconducted cto censure csecurity crequirements
were cbeing cmet cduring cthe cdevelopment cphase.
Many cof cthe cdevices ca ccompany cuses care cstand-alone, cthird-party cappliances. cWhile cthe capp
evaluated cfor csecurity cconcerns cat cthe ctime cof cpurchase, cmany chave creached cthe cend cof cthe
creplaced csoon.
What cshould ca csecurity cadministrator cdo cto cprotect cthese cassets cbefore cthey care cdisposed cof
cANS✔✔Use ca cdefense-in-depth cstrategy