WGU D430 Final Exam Study Guide |2026 Latest
Update with Complete Solution
What was on the OA:
Be competent with ALL of these terms and concepts. The ones highlighted in red are
the ones that appeared on the OA the most.
Fundamentals of Information Security
CIA Triad
Parkerian Hexad
Attack Types
Threat
Vulnerability
Authentication
Mutual Authentication
Risk Management Process
Incident Response Process
Key Concepts, Identification, and Authorization
Authorization
Least Privilege
Access Control
Access Control Models
Network ACL
Accountability
Intrusion Detection (IDS)
Intrusion Prevention (IPS)
Auditing
Auditing, Cryptography, and Legal Issues
Symmetric and Asymmetric Encryption
Symmetric and Assymetric Key Algorithms
Hash Functions
Keyless Cryptography
Digital Signature
Certificates
Secure Socket Layer (SSL)
Transport Layer Security (TLS)
IPsec and SSL VPN
Protecting data at rest/motion/use
DDos
Man-in-the-middle attacks
FISMA, FERPA, HIPPA, HITECH, SOX, GLBA, PCI DSS, COPPA
Compliance
, Operations and Human Element Study
Phishing
Tailgating
Brute Force
Physical and Network Security
Physical Threats
Defense-in-depth
Raid
NIDS/HIDS
Network Segmentation
Firewalls
VPN
Packet Filtering
Stateful Firewall
Deep Packet Inspection
Proxy Servers
DMZ
Port Scanners
• Nmap
Packet Sniffers
• Wireshark
• Tcpdump
Honeypots
Burp Suite
Operating System and Application Security
OS Hardening
Nessus
Buffer Overflows
Race Conditions
SQL Injections
Cross-Site Scripting
Fuzzers
Tips/Advice:
When you’re applying CIA to situations, remember:
Confidentiality - WHO can access the data
Integrity - keeping data UNALTERED
Availability - for ones AUTHORIZED to ACCESS data when needed
Attack types and their effect:
Update with Complete Solution
What was on the OA:
Be competent with ALL of these terms and concepts. The ones highlighted in red are
the ones that appeared on the OA the most.
Fundamentals of Information Security
CIA Triad
Parkerian Hexad
Attack Types
Threat
Vulnerability
Authentication
Mutual Authentication
Risk Management Process
Incident Response Process
Key Concepts, Identification, and Authorization
Authorization
Least Privilege
Access Control
Access Control Models
Network ACL
Accountability
Intrusion Detection (IDS)
Intrusion Prevention (IPS)
Auditing
Auditing, Cryptography, and Legal Issues
Symmetric and Asymmetric Encryption
Symmetric and Assymetric Key Algorithms
Hash Functions
Keyless Cryptography
Digital Signature
Certificates
Secure Socket Layer (SSL)
Transport Layer Security (TLS)
IPsec and SSL VPN
Protecting data at rest/motion/use
DDos
Man-in-the-middle attacks
FISMA, FERPA, HIPPA, HITECH, SOX, GLBA, PCI DSS, COPPA
Compliance
, Operations and Human Element Study
Phishing
Tailgating
Brute Force
Physical and Network Security
Physical Threats
Defense-in-depth
Raid
NIDS/HIDS
Network Segmentation
Firewalls
VPN
Packet Filtering
Stateful Firewall
Deep Packet Inspection
Proxy Servers
DMZ
Port Scanners
• Nmap
Packet Sniffers
• Wireshark
• Tcpdump
Honeypots
Burp Suite
Operating System and Application Security
OS Hardening
Nessus
Buffer Overflows
Race Conditions
SQL Injections
Cross-Site Scripting
Fuzzers
Tips/Advice:
When you’re applying CIA to situations, remember:
Confidentiality - WHO can access the data
Integrity - keeping data UNALTERED
Availability - for ones AUTHORIZED to ACCESS data when needed
Attack types and their effect: