WGU D430 FUNDAMENTALS OF INFORMATION
SECURITY OA PA 2 FINAL SCRIPT 2026
QUESTIONS WITH ANSWERS GRADED A+
◉ family educational rights and privacy act (FERPA). Answer:
defines how institutions must handle student records to protect
their privacy and how people can view or share them.
◉ international organization for standardization (ISO). Answer: a
body first created in 1926 to set standards between nations.
the 27000/27k series of THIS covers information security; 27000,
27001, 27002. these documents lay out best practices for managing
risk, controls, privacy, technical issues, and a wide array of other
specifics.
◉ national institute of standards and technology (NIST). Answer:
provides guidelines for many topics in computing and technology,
including risk management.
m; two commonly referenced publications on risk management are
SP 800-37 and SP 800-53.
,SP 800-37 lays out the risk management framework in six steps:
categorize, select, implement, assess, authorize, and monitor.
◉ confidentiality (CIA triad). Answer: refers to our ability to protect
data from those who are not authorized to view it.
m; can be compromised in a number of ways; losing laptop with
data, someone looking over your shoulder while entering password,
email attachments sent to wrong people, attackers could penetrate
your system.
◉ integrity (CIA triad). Answer: the ability to prevent people from
changing your data in an unauthorized or undesirable manner.
m; must have the means to prevent unauthorized changes to data
and the ability to reverse unauthorized changes.
is particularly important when it concerns data that provides the
foundation for other decisions; an attacker could alter data from
medical tests which can harm the patient.
◉ availability (CIA triad). Answer: the ability to access our data
when we need it.
,m; THIS can be be lost due to power outages, operating system or
application problems, network attacks, or compromising of a
system.
when the issues are caused by an attacker it is called a denial-of-
service (DoS) attack.
◉ integrity (parkerian hexad). Answer: THIS is the same as from the
CIA triad, however this version doesn't account for authorized, but
incorrect, modification of data; the data must be whole and
completely unchanged.
◉ possession/control (parkerian hexad). Answer: in the parkerian
hexad, THIS refers to the physical disposition of the media on which
the data is stored; enabling you to discuss the loss of data in the
physical sense.
ex; an encrypted hard-drive is stolen, it is considered a loss of THIS
because you no longer physically have the hard-drive.
◉ authenticity (parkerian hexad). Answer: in the parkerian hexad,
THIS allows you to say whether you've attributed the data in
question to the proper owner or creator.
, ex; if something is altered to appear to have come from someone
other than the proper owner or creator, then it violates THIS.
◉ utility (parkerian hexad). Answer: in the parkerian hexad, THIS
refers to how useful the data is to you.
ex; for an attacker, encrypted data would be of very little use as it's
unreadable, unencrypted data would be useful because it's readable.
m; is not necessarily binary and can have varying degrees of
usefulness, depending on the data and format.
◉ types of attacks. Answer: THIS has four categories: interception,
interruption, modification, and fabrication. each category can affect
one or more principles of the CIA triad.
◉ interception (types of attacks). Answer: an attack allowing
unauthorized users access to data, applications, or environments
and are primarily attacks against confidentiality.
ex; unauthorized file viewing or copying, eavesdropping on phone
conversations, or reading someone else's email.
SECURITY OA PA 2 FINAL SCRIPT 2026
QUESTIONS WITH ANSWERS GRADED A+
◉ family educational rights and privacy act (FERPA). Answer:
defines how institutions must handle student records to protect
their privacy and how people can view or share them.
◉ international organization for standardization (ISO). Answer: a
body first created in 1926 to set standards between nations.
the 27000/27k series of THIS covers information security; 27000,
27001, 27002. these documents lay out best practices for managing
risk, controls, privacy, technical issues, and a wide array of other
specifics.
◉ national institute of standards and technology (NIST). Answer:
provides guidelines for many topics in computing and technology,
including risk management.
m; two commonly referenced publications on risk management are
SP 800-37 and SP 800-53.
,SP 800-37 lays out the risk management framework in six steps:
categorize, select, implement, assess, authorize, and monitor.
◉ confidentiality (CIA triad). Answer: refers to our ability to protect
data from those who are not authorized to view it.
m; can be compromised in a number of ways; losing laptop with
data, someone looking over your shoulder while entering password,
email attachments sent to wrong people, attackers could penetrate
your system.
◉ integrity (CIA triad). Answer: the ability to prevent people from
changing your data in an unauthorized or undesirable manner.
m; must have the means to prevent unauthorized changes to data
and the ability to reverse unauthorized changes.
is particularly important when it concerns data that provides the
foundation for other decisions; an attacker could alter data from
medical tests which can harm the patient.
◉ availability (CIA triad). Answer: the ability to access our data
when we need it.
,m; THIS can be be lost due to power outages, operating system or
application problems, network attacks, or compromising of a
system.
when the issues are caused by an attacker it is called a denial-of-
service (DoS) attack.
◉ integrity (parkerian hexad). Answer: THIS is the same as from the
CIA triad, however this version doesn't account for authorized, but
incorrect, modification of data; the data must be whole and
completely unchanged.
◉ possession/control (parkerian hexad). Answer: in the parkerian
hexad, THIS refers to the physical disposition of the media on which
the data is stored; enabling you to discuss the loss of data in the
physical sense.
ex; an encrypted hard-drive is stolen, it is considered a loss of THIS
because you no longer physically have the hard-drive.
◉ authenticity (parkerian hexad). Answer: in the parkerian hexad,
THIS allows you to say whether you've attributed the data in
question to the proper owner or creator.
, ex; if something is altered to appear to have come from someone
other than the proper owner or creator, then it violates THIS.
◉ utility (parkerian hexad). Answer: in the parkerian hexad, THIS
refers to how useful the data is to you.
ex; for an attacker, encrypted data would be of very little use as it's
unreadable, unencrypted data would be useful because it's readable.
m; is not necessarily binary and can have varying degrees of
usefulness, depending on the data and format.
◉ types of attacks. Answer: THIS has four categories: interception,
interruption, modification, and fabrication. each category can affect
one or more principles of the CIA triad.
◉ interception (types of attacks). Answer: an attack allowing
unauthorized users access to data, applications, or environments
and are primarily attacks against confidentiality.
ex; unauthorized file viewing or copying, eavesdropping on phone
conversations, or reading someone else's email.