WGU D486 GOVERNANCE, RISK, AND
COMPLIANCE 70DF FINAL TEST 2026
QUESTIONS WITH CORRECT ANSWERS
GRADED A+
◍ rootkit.
Answer: A set of programs that enables its user to gain administrator-level
access to a computer without the end user's consent or knowledge.
◍ What role do boards play in GRC governance structures?.
Answer: Establish strategic direction and ensure efficiency of GRC
procedures
◍ independent contractor.
Answer: An individual who provides services to another individual or
organization according to terms defined in a written contract or within a
verbal agreement.
◍ strategic lawsuit against public participation (SLAPP).
Answer: A lawsuit filed by corporations, government officials, and others
against citizens and community groups who oppose them on matters of
concern. The lawsuit is typically without merit and is used to intimidate
critics out of fear of the cost and effort associated with a major legal battle.
◍ utility patent.
Answer: A type of patent "issued for the invention of a new and useful
process, machine, manufacture, or composition of matter, or a new and
useful improvement thereof, it generally permits its owner to exclude others
from making, using, or selling the invention for a period of up to 20 years
from the date of patent application filing, subject to the payment of
, maintenance fees."
◍ What is the focus of incident response plans?.
Answer: Effective management and response to security incidents or
breaches
◍ What is an Acceptable Use Policy (AUP)?.
Answer: A policy that sets standards for how technology resources should
be used in an organization
◍ What is the role of standards in GRC?.
Answer: To ensure uniformity and reliability in compliance and risk
management efforts
◍ What does GRC stand for?.
Answer: Governance, Risk, and Compliance
◍ What is the function of committees in GRC?.
Answer: To implement specialized GRC activities linked to particular
domains
◍ How does GRC help organizations?.
Answer: By managing operational risks, complying with regulations, and
maintaining governance structures
◍ common Ethical issues for IT users.
Answer: Software PiracyInappropriate use of computing
resourcesInappropriate Sharing of information
◍ noncompete agreement.
Answer: Terms of an employment contract that prohibit an employee from
working for any competitors for a specified period of time, often one to two
years.
◍ What do policies specify in GRC?.
Answer: What is permissible and what is not within organizational activity
◍ What are typical password rules in GRC standards?.
Answer: At least eight characters with a mix of capital and small letters,
, digits, and special characters
◍ Capability Maturity Model Integration (CMMI) models.
Answer: Collection of best practices that help organizations improve their
processes.
◍ What encryption standards are recommended for in-transit data?.
Answer: Secure Sockets Layer/Transport Layer Security (SSL/TLS)
◍ Supply Chain Sustainability.
Answer: A component of corporate social responsibility (CSR) that focuses
on developing and maintaining a supply chain that meets the needs of the
present without compromising the ability of future generations to meet their
needs.
◍ What are the main components of a GRC framework?.
Answer: Guidelines, policies, and standards
◍ remote monitoring.
Answer: Also called home monitoring, it is the regular, ongoing, accurate
measurement of an individual's vital signs (temperature, blood pressure,
heart rate, and breathing rate) and other health measures (e.g., glucose levels
for a diabetic) and the transmission of this data to a healthcare provider.
◍ Agreement on Trade-Related Aspects of Intellectual Property Rights
(TRIPS).
Answer: An agreement of the World Trade Organization that requires
member governments to ensure that intellectual property rights can be
enforced under their laws and that penalties for infringement are tough
enough to deter further violations.
◍ What do governmental organizations provide in GRC?.
Answer: Rules that govern GRC activities, protecting public interest and
promoting market justice
◍ What do information security policies outline?.
Answer: Ways to protect against breaches and unauthorized access to
, sensitive data
◍ What do change management procedures guide?.
Answer: The implementation of changes within an organization
◍ What is the purpose of guidelines in GRC?.
Answer: To provide recommended best practices for compliance and risk
management
◍ trade secret Information.
Answer: Generally unknown to the public, that a company has taken strong
measures to keep confidential.
◍ copyright infringement.
Answer: A violation of the rights secured by the owner of a copyright;
occurs when someone copies a substantial and material part of another's
copyrighted work without permission.
◍ What are comprehensive playbooks in GRC?.
Answer: Step-by-step instructions on how to handle various situations
◍ IT user.
Answer: A person who uses a hardware or software product; the term
distinguishes end users from the IT workers who develop, install, service,
and support the product. IT users need the product to deliver organizational
benefits or to increase their productivity.
◍ What do standards in GRC outline?.
Answer: Operational and technological prerequisites required for rule
adherence
◍ fair information practices.
Answer: A term for a set of guidelines that govern the collection and use of
personal data.
◍ What encryption standard is recommended for stored data?.
Answer: Advanced Encryption Standard (AES)
◍ pen register.
COMPLIANCE 70DF FINAL TEST 2026
QUESTIONS WITH CORRECT ANSWERS
GRADED A+
◍ rootkit.
Answer: A set of programs that enables its user to gain administrator-level
access to a computer without the end user's consent or knowledge.
◍ What role do boards play in GRC governance structures?.
Answer: Establish strategic direction and ensure efficiency of GRC
procedures
◍ independent contractor.
Answer: An individual who provides services to another individual or
organization according to terms defined in a written contract or within a
verbal agreement.
◍ strategic lawsuit against public participation (SLAPP).
Answer: A lawsuit filed by corporations, government officials, and others
against citizens and community groups who oppose them on matters of
concern. The lawsuit is typically without merit and is used to intimidate
critics out of fear of the cost and effort associated with a major legal battle.
◍ utility patent.
Answer: A type of patent "issued for the invention of a new and useful
process, machine, manufacture, or composition of matter, or a new and
useful improvement thereof, it generally permits its owner to exclude others
from making, using, or selling the invention for a period of up to 20 years
from the date of patent application filing, subject to the payment of
, maintenance fees."
◍ What is the focus of incident response plans?.
Answer: Effective management and response to security incidents or
breaches
◍ What is an Acceptable Use Policy (AUP)?.
Answer: A policy that sets standards for how technology resources should
be used in an organization
◍ What is the role of standards in GRC?.
Answer: To ensure uniformity and reliability in compliance and risk
management efforts
◍ What does GRC stand for?.
Answer: Governance, Risk, and Compliance
◍ What is the function of committees in GRC?.
Answer: To implement specialized GRC activities linked to particular
domains
◍ How does GRC help organizations?.
Answer: By managing operational risks, complying with regulations, and
maintaining governance structures
◍ common Ethical issues for IT users.
Answer: Software PiracyInappropriate use of computing
resourcesInappropriate Sharing of information
◍ noncompete agreement.
Answer: Terms of an employment contract that prohibit an employee from
working for any competitors for a specified period of time, often one to two
years.
◍ What do policies specify in GRC?.
Answer: What is permissible and what is not within organizational activity
◍ What are typical password rules in GRC standards?.
Answer: At least eight characters with a mix of capital and small letters,
, digits, and special characters
◍ Capability Maturity Model Integration (CMMI) models.
Answer: Collection of best practices that help organizations improve their
processes.
◍ What encryption standards are recommended for in-transit data?.
Answer: Secure Sockets Layer/Transport Layer Security (SSL/TLS)
◍ Supply Chain Sustainability.
Answer: A component of corporate social responsibility (CSR) that focuses
on developing and maintaining a supply chain that meets the needs of the
present without compromising the ability of future generations to meet their
needs.
◍ What are the main components of a GRC framework?.
Answer: Guidelines, policies, and standards
◍ remote monitoring.
Answer: Also called home monitoring, it is the regular, ongoing, accurate
measurement of an individual's vital signs (temperature, blood pressure,
heart rate, and breathing rate) and other health measures (e.g., glucose levels
for a diabetic) and the transmission of this data to a healthcare provider.
◍ Agreement on Trade-Related Aspects of Intellectual Property Rights
(TRIPS).
Answer: An agreement of the World Trade Organization that requires
member governments to ensure that intellectual property rights can be
enforced under their laws and that penalties for infringement are tough
enough to deter further violations.
◍ What do governmental organizations provide in GRC?.
Answer: Rules that govern GRC activities, protecting public interest and
promoting market justice
◍ What do information security policies outline?.
Answer: Ways to protect against breaches and unauthorized access to
, sensitive data
◍ What do change management procedures guide?.
Answer: The implementation of changes within an organization
◍ What is the purpose of guidelines in GRC?.
Answer: To provide recommended best practices for compliance and risk
management
◍ trade secret Information.
Answer: Generally unknown to the public, that a company has taken strong
measures to keep confidential.
◍ copyright infringement.
Answer: A violation of the rights secured by the owner of a copyright;
occurs when someone copies a substantial and material part of another's
copyrighted work without permission.
◍ What are comprehensive playbooks in GRC?.
Answer: Step-by-step instructions on how to handle various situations
◍ IT user.
Answer: A person who uses a hardware or software product; the term
distinguishes end users from the IT workers who develop, install, service,
and support the product. IT users need the product to deliver organizational
benefits or to increase their productivity.
◍ What do standards in GRC outline?.
Answer: Operational and technological prerequisites required for rule
adherence
◍ fair information practices.
Answer: A term for a set of guidelines that govern the collection and use of
personal data.
◍ What encryption standard is recommended for stored data?.
Answer: Advanced Encryption Standard (AES)
◍ pen register.