100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

WGU D430 Fundamentals of Information Security OA Actual Exam 2026 | Questions with Verified Answers | 100% Correct | Pass Guaranteed

Rating
-
Sold
-
Pages
12
Grade
A+
Uploaded on
06-01-2026
Written in
2025/2026

WGU D430 Fundamentals of Information Security OA Actual Exam 2026 | Questions with Verified Answers | 100% Correct | Pass Guaranteed

Institution
WGU D430
Course
WGU D430









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
WGU D430
Course
WGU D430

Document information

Uploaded on
January 6, 2026
Number of pages
12
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

WGU D430 Fundamentals of Information Security OA
Actual Exam 2026 | Questions with Verified Answers |
100% Correct | Pass Guaranteed

SECTION 1: Security Concepts & Governance
Q1: Which primary goal of the CIA triad is violated when a database record is modified by an
unauthorized user?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Correct Answer: B
Rationale: Integrity ensures that data remains accurate and unaltered without authorization;
unauthorized modification directly violates this principle. Confidentiality (A) is concerned with
disclosure, not alteration. Availability (C) relates to timely access. Non-repudiation (D) prevents
denial of an action but does not address data alteration.
Q2: A company must decide whether to accept, transfer, mitigate, or avoid a risk with an
annualized loss expectancy (ALE) of $45,000 and mitigation cost of $60,000. Which risk
response is MOST aligned with NIST SP 800-30 guidance?
A. Accept the risk
B. Transfer the risk
C. Avoid the risk
D. Mitigate the risk
Correct Answer: A
Rationale: When mitigation cost exceeds the ALE, accepting the risk is usually justified unless
regulatory or reputational factors dictate otherwise. Transfer (B) via insurance still costs
premiums near or above ALE. Avoid (C) would eliminate the asset/process, which is extreme.
Mitigate (D) is uneconomical here.
Q3: Which governance document is MOST appropriate for high-level statements such as “All
customer PII must be encrypted at rest”?
A. Policy
B. Standard
C. Procedure
D. Guideline
Correct Answer: A
Rationale: Policies are executive-level documents that set mandatory requirements. Standards
(B) define specific technologies or parameters, procedures (C) give step-by-step instructions,
and guidelines (D) are non-mandatory recommendations.

, Q4: The ISO 27001 certification process requires which phase to be completed BEFORE
conducting the Stage 2 audit?
A. Risk assessment
B. Statement of Applicability
C. Management review
D. Stage 1 audit (readiness review)
Correct Answer: D
Rationale: ISO 27001 mandates a Stage 1 readiness review to verify that the ISMS is
sufficiently implemented before the Stage 2 certification audit. Risk assessment (A), SoA (B),
and management review (C) are all required but occur earlier within the ISMS build, not the
certification sequence.
Q5: Which document provides a mapping between NIST SP 800-53 controls and PCI DSS
requirements?
A. NIST SP 800-37 Rev. 2
B. NIST Cybersecurity Framework
C. NIST SP 800-53A
D. NIST Interagency Report (NISTIR) 8097
Correct Answer: B
Rationale: The CSF includes Informative References that map 800-53 controls to sector-specific
standards such as PCI DSS. 800-37 (A) is Risk Management Framework; 800-53A (C) is
assessment guidance; NISTIR 8097 (D) addresses mobile threat catalog, not mappings.
Q6: A startup stores health records in AWS. Which regulation MOST directly requires a
documented Business Associate Agreement (BAA) with AWS?
A. HIPAA
B. HITECH
C. GDPR
D. SOX
Correct Answer: A
Rationale: HIPAA mandates BAAs when a covered entity shares PHI with a cloud provider.
HITECH (B) strengthens HIPAA but does not create new agreement types. GDPR (C) requires
data-processing agreements, not BAAs. SOX (D) focuses on financial reporting.
Q7: In quantitative risk analysis, which variable is multiplied by Exposure Factor to derive Single
Loss Expectancy (SLE)?
A. Annualized Rate of Occurrence (ARO)
B. Asset Value (AV)
C. Safeguard cost
D. Residual risk
Correct Answer: B
Rationale: SLE = AV × EF. ARO (A) is used later to compute ALE. Safeguard cost (C) and
residual risk (D) are not components of SLE.
Q8: Which of the following BEST exemplifies the concept of “due care” from a legal
perspective?
A. Installing the latest firewall after a breach
B. Performing annual penetration tests aligned with industry norms
$15.99
Get access to the full document:

100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached

Get to know the seller
Seller avatar
TommyRicks

Get to know the seller

Seller avatar
TommyRicks Chamberlain College Of Nursing
View profile
Follow You need to be logged in order to follow users or courses
Sold
New on Stuvia
Member since
1 month
Number of followers
0
Documents
480
Last sold
-
TommyRicks

One stop shop for all all study materials, Study guides,Exams and all assignments and homeworks.

0.0

0 reviews

5
0
4
0
3
0
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions