WGU D635 OBJECTIVE ASSESSMENT EXAM – QUESTIONS AND ANSWERS |
EXAM TESTBANK WITH VERIFIED AND WELL DETAILED ANSWERS | PLUS
RATIONALES | DOWNLOAD AND PASS | LATEST EXAM UPDATE 2026/2027
Core Domains
- Data Governance and Management Principles
- Information Security and Compliance Frameworks
- Ethical Decision-Making in Technology
- Risk Assessment and Mitigation Strategies
- Regulatory Landscape (e.g., GDPR, CCPA, HIPAA)
- Business Continuity and Disaster Recovery Planning
- IT Auditing and Control Practices
- Professional Communication and Stakeholder Management
Introduction
This comprehensive Objective Assessment is designed to rigorously evaluate a
candidate's mastery of the essential principles and practices required for the WGU
D635 certification. The exam assesses both foundational theoretical knowledge and
its practical application in complex, real-world scenarios. It emphasizes critical
thinking, ethical judgment, and the ability to navigate regulatory and compliance
challenges inherent in modern data-driven environments. The assessment is
structured as a series of multiple-choice questions and scenario-based items,
challenging candidates to demonstrate their decision-making capabilities and
professional readiness. This testbank serves as a definitive resource for exam
preparation, ensuring candidates are well-versed in the core competencies
necessary for success and professional advancement in the field.
,SECTION ONE: QUESTIONS 1-100
Question 1
What is the primary objective of a Data Governance program?
A. To maximize the financial value derived from all corporate data.
B. To ensure data is managed effectively to support business strategy and
compliance.
C. To implement the most advanced technological solutions for data storage.
D. To restrict access to data to only the most senior executives.
🟢B
🔴 Explanation: The core purpose of Data Governance is to establish a framework
of policies, processes, and standards to ensure data is managed effectively,
supporting an organization's overall strategy while ensuring compliance with
regulations. While value maximization (A) is a benefit, it's not the primary
governance objective. Options C and D are too narrow and prescriptive.
Question 2
Under the GDPR, what is the maximum fine an organization can face for the most
severe violations?
A. €10 million or 2% of global annual turnover, whichever is higher.
B. €20 million or 4% of global annual turnover, whichever is higher.
C. €50 million or 5% of global annual turnover, whichever is higher.
D. A fixed penalty of €30 million.
,🟢B
🔴 Explanation: The GDPR allows for tiered fines. The most severe violations (e.g.,
non-compliance with basic principles for processing, insufficient consent, or data
subject rights) can result in a fine of up to €20 million or 4% of total global annual
turnover, whichever is higher.
Question 3
An IT manager discovers a significant vulnerability in a widely used software
application that the company relies on. What is the FIRST ethical step they should
take?
A. Immediately publish the vulnerability on a public forum to force the vendor to
act.
B. Document the vulnerability and report it directly to the software vendor.
C. Exploit the vulnerability to demonstrate its potential impact to senior
management.
D. Ignore the vulnerability to avoid creating unnecessary panic.
🟢B
🔴 Explanation: The first and most ethical step in responsible disclosure is to
report the vulnerability to the vendor, giving them the opportunity to develop
and release a patch before the information becomes public. This protects the
vendor's users and limits potential harm.
Question 4
Which of the following is a key component of a Business Continuity Plan (BCP)?
, A. A detailed plan for increasing market share.
B. A strategy for maintaining critical business functions during a disruption.
C. A guide for developing new software products.
D. A policy for employee performance reviews.
🟢B
🔴 Explanation: A BCP's core focus is on ensuring that an organization can
continue to deliver its most critical products and services during and after a
disruptive event, such as a natural disaster, cyberattack, or system failure.
Question 5
What does the "P" in the CIA triad stand for?
A. Privacy
B. Protection
C. Prevention
D. Integrity
🟢D
🔴 Explanation: Wait, this question is designed to test attention. The CIA triad
stands for Confidentiality, Integrity, and Availability. The 'I' stands for Integrity, not
Privacy, Protection, or Prevention. The "P" is not part of the CIA triad. This
question tests understanding of the core model.
Question 6
Which of the following scenarios represents a violation of the principle of "least
privilege"?
EXAM TESTBANK WITH VERIFIED AND WELL DETAILED ANSWERS | PLUS
RATIONALES | DOWNLOAD AND PASS | LATEST EXAM UPDATE 2026/2027
Core Domains
- Data Governance and Management Principles
- Information Security and Compliance Frameworks
- Ethical Decision-Making in Technology
- Risk Assessment and Mitigation Strategies
- Regulatory Landscape (e.g., GDPR, CCPA, HIPAA)
- Business Continuity and Disaster Recovery Planning
- IT Auditing and Control Practices
- Professional Communication and Stakeholder Management
Introduction
This comprehensive Objective Assessment is designed to rigorously evaluate a
candidate's mastery of the essential principles and practices required for the WGU
D635 certification. The exam assesses both foundational theoretical knowledge and
its practical application in complex, real-world scenarios. It emphasizes critical
thinking, ethical judgment, and the ability to navigate regulatory and compliance
challenges inherent in modern data-driven environments. The assessment is
structured as a series of multiple-choice questions and scenario-based items,
challenging candidates to demonstrate their decision-making capabilities and
professional readiness. This testbank serves as a definitive resource for exam
preparation, ensuring candidates are well-versed in the core competencies
necessary for success and professional advancement in the field.
,SECTION ONE: QUESTIONS 1-100
Question 1
What is the primary objective of a Data Governance program?
A. To maximize the financial value derived from all corporate data.
B. To ensure data is managed effectively to support business strategy and
compliance.
C. To implement the most advanced technological solutions for data storage.
D. To restrict access to data to only the most senior executives.
🟢B
🔴 Explanation: The core purpose of Data Governance is to establish a framework
of policies, processes, and standards to ensure data is managed effectively,
supporting an organization's overall strategy while ensuring compliance with
regulations. While value maximization (A) is a benefit, it's not the primary
governance objective. Options C and D are too narrow and prescriptive.
Question 2
Under the GDPR, what is the maximum fine an organization can face for the most
severe violations?
A. €10 million or 2% of global annual turnover, whichever is higher.
B. €20 million or 4% of global annual turnover, whichever is higher.
C. €50 million or 5% of global annual turnover, whichever is higher.
D. A fixed penalty of €30 million.
,🟢B
🔴 Explanation: The GDPR allows for tiered fines. The most severe violations (e.g.,
non-compliance with basic principles for processing, insufficient consent, or data
subject rights) can result in a fine of up to €20 million or 4% of total global annual
turnover, whichever is higher.
Question 3
An IT manager discovers a significant vulnerability in a widely used software
application that the company relies on. What is the FIRST ethical step they should
take?
A. Immediately publish the vulnerability on a public forum to force the vendor to
act.
B. Document the vulnerability and report it directly to the software vendor.
C. Exploit the vulnerability to demonstrate its potential impact to senior
management.
D. Ignore the vulnerability to avoid creating unnecessary panic.
🟢B
🔴 Explanation: The first and most ethical step in responsible disclosure is to
report the vulnerability to the vendor, giving them the opportunity to develop
and release a patch before the information becomes public. This protects the
vendor's users and limits potential harm.
Question 4
Which of the following is a key component of a Business Continuity Plan (BCP)?
, A. A detailed plan for increasing market share.
B. A strategy for maintaining critical business functions during a disruption.
C. A guide for developing new software products.
D. A policy for employee performance reviews.
🟢B
🔴 Explanation: A BCP's core focus is on ensuring that an organization can
continue to deliver its most critical products and services during and after a
disruptive event, such as a natural disaster, cyberattack, or system failure.
Question 5
What does the "P" in the CIA triad stand for?
A. Privacy
B. Protection
C. Prevention
D. Integrity
🟢D
🔴 Explanation: Wait, this question is designed to test attention. The CIA triad
stands for Confidentiality, Integrity, and Availability. The 'I' stands for Integrity, not
Privacy, Protection, or Prevention. The "P" is not part of the CIA triad. This
question tests understanding of the core model.
Question 6
Which of the following scenarios represents a violation of the principle of "least
privilege"?