Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 53 pages
Exam (elaborations)

WGU D430 Fundamentals of Information Security Complete Exam Study Guide with Verified Answers | Latest Edition

Document preview thumbnail
Preview 4 out of 53 pages

WGU D430 Fundamentals of Information Security Complete Exam Study Guide with Verified Answers | Latest Edition 1. CIA Triad - ANSWER Confidential - allowing only those authorized to access the data requested Integrity - keeping data unaltered in an unauthorized manner and reliable Availability - the ability for those authorized to access data when needed 2. Parkerian Hexad - ANSWER Confidentiality Integrity Availability Possession - physical deposition of the media on which the data is stored Authenticity - allows us to talk about the proper attribution as to the owner or creator of the data in question Utility - how useful the data is to us 3. Incident response process - ANSWER Preparation Detection and Analysis Identification Containment Eradication Recovery Post - incident activity 4. Preparation - ANSWER the activities that we can perform , in advance of the incident itself in order to better enable us to handle it . 5. Detection and Analysis (Identification) - ANSWER detect the occurrence of an issue and decide whether or not it is actually an incident so that we can respond appropriately to it. 6. Containment - ANSWER involves taking steps to ensure that the situation does not cause any more damage than it already has, or to at least lessen any ongoing harm 7. Eradication - ANSWER attempt to remove the effects of the issue from our environment 8. Recovery - ANSWER restoring devices or data to pre - incident state (rebuilding systems , reloading applications , backup media , etc. ) 9. Post - incident activity - ANSWER determine specifically what happened, why it happened, and what we can do to keep it from happening again . (postmortem) . 10. Authorization - ANSWER what the user can access , modify , and delete 11. Least Privilege - ANSWER giving the bare minimum level of access it needs to perform its job / functionality 12. Access Control - ANSWER Allowing - lets us give a particular party access to a given source Denying - opposite of gaining access Limiting - allowing some access to our resource, only up to a certain point Revoking - takes access away from former user 13. Access Control List - ANSWER info about what kind of access certain parties are allowed to have to a given system Read, write, execute 14. Network ACL - ANSWER filter access rules for incoming and outgoing network transactions, such as Internet Protocol ( IP ) addresses , Media Access Control ( MAC ) addresses , and ports 15. Attack Types - ANSWER Interception Interruption Modification Fabrication 16. Interception - ANSWER an attacker has access to data , applications or environment 17. Interruption - ANSWER attacks cause our assets to become unusable or unavailable 18. Modification - ANSWER attacks involve tampering with our asset 19. Fabrication - ANSWER attacks that create false information 20. Threat - ANSWER something that has potential to cause harm 21. Vulnerability - ANSWER weaknesses that can be used to harm us 22. Something you know - ANSWER username , password , PIN 23. Something you have - ANSWER ID badge , swipe card , OTP 24. Something you are - ANSWER fingerprint, Iris Retina scan 25. Somewhere you are - ANSWER geolocation 26. Something you do - ANSWER handwriting , typing , walking 27. Authentication - ANSWER verifying that a person is who they claim to be 28. Mutual authentication - ANSWER Both parties in a transaction to authenticate each other - Has digital certificates - Prevents man in the middle attacks - The man in the middle is where the attacker inserts themselves into the traffic flow - Ex . Both the PC and server authenticate each other before data is sent in either direction 29. Risk management process - ANSWER 1. Identify Asset - identifying and categorizing assets that we're protecting 2. Identify Threats - identify threats 3. Assess Vulnerabilities - look for impacts 4. Assess Risk - asses the risk overall 5. Mitigate Risk - ensure that a given type of threat is accounted for

Content preview

WGU D430 Fundamentals of Information
Security Complete Exam Study Guide with
Verified Answers | Latest Edition

1. CIA Triad - ANSWER Confidential - allowing only those authorized to
access the data requested
Integrity - keeping data unaltered in an unauthorized manner and reliable
Availability - the ability for those authorized to access data when needed


2. Parkerian Hexad - ANSWER Confidentiality Integrity Availability
Possession - physical deposition of the media on which the data is stored
Authenticity - allows us to talk about the proper attribution as to the owner or
creator of the data in question
Utility - how useful the data is to us


3. Incident response process - ANSWER Preparation Detection and Analysis
Identification
Containment
Eradication Recovery
Post - incident activity


4. Preparation - ANSWER the activities that we can perform , in advance of
the incident itself in order to better enable us to handle it .

,5. Detection and Analysis (Identification) - ANSWER detect the occurrence of
an issue and decide whether or not it is actually an incident so that we can
respond appropriately to it.


6. Containment - ANSWER involves taking steps to ensure that the situation
does not cause any more damage than it already has, or to at least lessen any
ongoing harm


7. Eradication - ANSWER attempt to remove the effects of the issue from our
environment


8. Recovery - ANSWER restoring devices or data to pre - incident state
(rebuilding systems , reloading applications , backup media , etc. )


9. Post - incident activity - ANSWER determine specifically what happened,
why it happened, and what we can do to keep it from happening again .
(postmortem) .


10.Authorization - ANSWER what the user can access , modify , and delete


11.Least Privilege - ANSWER giving the bare minimum level of access it
needs to perform its job / functionality


12.Access Control - ANSWER Allowing - lets us give a particular party access
to a given source
Denying - opposite of gaining access
Limiting - allowing some access to our resource, only up to a certain point
Revoking - takes access away from former user

,13.Access Control List - ANSWER info about what kind of access certain
parties are allowed to have to a given system
Read, write, execute


14.Network ACL - ANSWER filter access rules for incoming and outgoing
network transactions, such as Internet Protocol ( IP ) addresses , Media
Access Control ( MAC ) addresses , and ports


15.Attack Types - ANSWER Interception
Interruption
Modification
Fabrication
16.Interception - ANSWER an attacker has access to data , applications or
environment


17.Interruption - ANSWER attacks cause our assets to become unusable or
unavailable


18.Modification - ANSWER attacks involve tampering with our asset


19.Fabrication - ANSWER attacks that create false information


20.Threat - ANSWER something that has potential to cause harm


21.Vulnerability - ANSWER weaknesses that can be used to harm us


22.Something you know - ANSWER username , password , PIN

, 23.Something you have - ANSWER ID badge , swipe card , OTP


24.Something you are - ANSWER fingerprint, Iris Retina scan


25.Somewhere you are - ANSWER geolocation


26.Something you do - ANSWER handwriting , typing , walking


27.Authentication - ANSWER verifying that a person is who they claim to be


28.Mutual authentication - ANSWER Both parties in a transaction to
authenticate each other
- Has digital certificates
- Prevents man in the middle attacks
- The man in the middle is where the attacker inserts themselves into
the traffic flow
- Ex . Both the PC and server authenticate each other before data is sent
in either direction


29.Risk management process - ANSWER 1. Identify Asset - identifying and
categorizing assets that we're protecting
2. Identify Threats - identify threats
3. Assess Vulnerabilities - look for impacts
4. Assess Risk - asses the risk overall
5. Mitigate Risk - ensure that a given type of threat is accounted for


30.Access Control Models - ANSWER Discretionary (DAC)

Document information

Uploaded on
July 14, 2026
Number of pages
53
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
CA$17.23

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
7
Followers
0
Items
907
Last sold
2 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions