WGU D430 FUNDAMENTALS OF INFORMATION
SECURITY OA PA 2 COMPREHENSIVE TEST
2026 QUESTIONS WITH SOLUTIONS
◉ impact. Answer: THIS takes into account the value of the asset
being threatened and uses it to calculate risk.
ex; if the asset is your journal, you can say there is no risk. if the
asset is your bank account information, you can say the risk is very
high.
m; the US national security agency (NSA) added THIS factor to the
threat/vulnerability/risk equation.
◉ risk management process. Answer: identify assets > identify
threats > assess vulnerabilities > assess risks > mitigate risks.
identify important assets, figure potential threats against them,
assess vulnerabilities, then take steps to mitigate these risks.
◉ identify assets (risk management process). Answer: THIS is one of
the first and most important parts of risk management. if you can't
identify the impact, then protection becomes a difficult task.
,ex; acquisition of another company leads to THIS possibly being
required to keep the business functional.
◉ identify threats (risk management process). Answer: once the
impact of assets are assessed, THIS is required to see how potential
attacks might affect the assets.
m; being concerned with losing control of data, maintaining accurate
data, and keeping the system up and running allows you to be able
to look at areas of vulnerability and potential risk.
◉ assess vulnerabilities (risk management process). Answer: assets
can have millions of threats, but only a fraction will be relevant; THIS
is done to see if those relevant threats pose a risk.
ex; if data is exposed, it could lead to a breach. if your data is
encrypted, this is not a risk.
ex; if the system goes down, business operations will also go down,
this is a risk.
◉ assess risks (risk management process). Answer: once the threats
and vulnerabilities are identified, THIS is done to have an overall
idea of the risk so you can start to mitigate them.
,m; a vulnerability with no matching threat or a threat with no
matching vulnerability does not constitute a risk.
◉ mitigate risks (risk management process). Answer: THIS is
putting measures (called controls) in place to account for each
threat. there are three categories of control: physical, logical, and
administrative.
◉ physical controls/measures (mitigate risks). Answer: THIS
protects the physical environment in which your systems sit or
where your data is stored. also controls access of such
environments.
ex; includes fences, gates, locks, bollards, guards, and cameras, but
also systems that maintain the physical environment, such as
heating and air-conditioning systems, fire suppression systems, and
backup power generators.
m; one of the most critical controls. makes other controls useless if
an attacker has direct access to your system.
◉ logical (or technical) controls/measures (mitigate risks). Answer:
THIS protects the systems, networks, and environments that
process, transmit, and store your data.
, ex; THIS can be things such as passwords, encryption, access
controls, firewalls, and intrusion detection systems.
m; enables the prevention of unauthorized activities unless the
attacker is able to subvert the controls.
◉ administrative controls/measures (mitigate risks). Answer: THIS
dictates how the users of your environment should behave; the
rules, laws, policies, procedures, guidelines, and other items that are
"paper" in nature.
m; an important aspect of THIS is the ability to enforce it. can cause
threats and vulnerabilities if left unchecked.
◉ incident response. Answer: something to be done in the event of
an attack and should be directed in a way that is based on the impact
the attack has towards the organization.
m; steps in THIS process: preparation, detection and analysis,
containment, eradication, recovery, post-incident activity.
◉ preparation (incident response). Answer: the phase where things
are done before an incident occurs.
SECURITY OA PA 2 COMPREHENSIVE TEST
2026 QUESTIONS WITH SOLUTIONS
◉ impact. Answer: THIS takes into account the value of the asset
being threatened and uses it to calculate risk.
ex; if the asset is your journal, you can say there is no risk. if the
asset is your bank account information, you can say the risk is very
high.
m; the US national security agency (NSA) added THIS factor to the
threat/vulnerability/risk equation.
◉ risk management process. Answer: identify assets > identify
threats > assess vulnerabilities > assess risks > mitigate risks.
identify important assets, figure potential threats against them,
assess vulnerabilities, then take steps to mitigate these risks.
◉ identify assets (risk management process). Answer: THIS is one of
the first and most important parts of risk management. if you can't
identify the impact, then protection becomes a difficult task.
,ex; acquisition of another company leads to THIS possibly being
required to keep the business functional.
◉ identify threats (risk management process). Answer: once the
impact of assets are assessed, THIS is required to see how potential
attacks might affect the assets.
m; being concerned with losing control of data, maintaining accurate
data, and keeping the system up and running allows you to be able
to look at areas of vulnerability and potential risk.
◉ assess vulnerabilities (risk management process). Answer: assets
can have millions of threats, but only a fraction will be relevant; THIS
is done to see if those relevant threats pose a risk.
ex; if data is exposed, it could lead to a breach. if your data is
encrypted, this is not a risk.
ex; if the system goes down, business operations will also go down,
this is a risk.
◉ assess risks (risk management process). Answer: once the threats
and vulnerabilities are identified, THIS is done to have an overall
idea of the risk so you can start to mitigate them.
,m; a vulnerability with no matching threat or a threat with no
matching vulnerability does not constitute a risk.
◉ mitigate risks (risk management process). Answer: THIS is
putting measures (called controls) in place to account for each
threat. there are three categories of control: physical, logical, and
administrative.
◉ physical controls/measures (mitigate risks). Answer: THIS
protects the physical environment in which your systems sit or
where your data is stored. also controls access of such
environments.
ex; includes fences, gates, locks, bollards, guards, and cameras, but
also systems that maintain the physical environment, such as
heating and air-conditioning systems, fire suppression systems, and
backup power generators.
m; one of the most critical controls. makes other controls useless if
an attacker has direct access to your system.
◉ logical (or technical) controls/measures (mitigate risks). Answer:
THIS protects the systems, networks, and environments that
process, transmit, and store your data.
, ex; THIS can be things such as passwords, encryption, access
controls, firewalls, and intrusion detection systems.
m; enables the prevention of unauthorized activities unless the
attacker is able to subvert the controls.
◉ administrative controls/measures (mitigate risks). Answer: THIS
dictates how the users of your environment should behave; the
rules, laws, policies, procedures, guidelines, and other items that are
"paper" in nature.
m; an important aspect of THIS is the ability to enforce it. can cause
threats and vulnerabilities if left unchecked.
◉ incident response. Answer: something to be done in the event of
an attack and should be directed in a way that is based on the impact
the attack has towards the organization.
m; steps in THIS process: preparation, detection and analysis,
containment, eradication, recovery, post-incident activity.
◉ preparation (incident response). Answer: the phase where things
are done before an incident occurs.