WGU C836 Fundamentals of
Information Security Exam 2026
CIA Triad, Threats, Security Controls
Complete Study Guide
75+ Verified Exam Questions · Rated A+ · Guaranteed Results
V CIA Triad (Confidentiality, V Security Controls (Technical,
Integrity, Availability) Administrative, Physical)
V Security Threats & V Risk Management & Compliance
Vulnerabilities (Malware, V Security Policies &
Social Engineering) Procedures
Instant PDF Download · 100% Verified Answers · Score 90%+
, BEST SELLER · IT/SECURITY
WGU C836 Fundamentals of
Information Security Exam 2026
A+
CIA Triad, Threats, Security Controls Rated
2026/2027 -- Q&A with Verified Answers
Every section. Every topic. 100% correct answers guaranteed.
Used by 5,000+ information security students to pass on their first attempt.
CIA Triad Security Threats Vulnerabilities Security Controls Risk Management
Compliance Security Policies
Used by 5,000+ students · 100% Verified Answers · 2026/2027 Latest Update
Instant PDF Download
,ION 1 | CIA Triad (Confidentiality, Integrity, Availability) | Q1-Q18 | WGU C836 Fundamentals of Information Security Exam 2026 CIA Triad, Threats, Security Controls 2026
Q1 Question 1 of 75
A 29-year-old security analyst at a healthcare organization discovers that patient records have been
accessed by an unauthorized employee who used a colleague's login credentials. The primary CIA
triad principle violated in this incident is:
A. Confidentiality because sensitive patient information was viewed by an unauthorized
individual
B. Availability because the system remained operational during the unauthorized access event
C. Integrity because the patient records may have been altered during the unauthorized access
D. Non-repudiation because the legitimate user can deny having performed the unauthorized access
Correct Answer: A
Rationale:
Confidentiality ensures that information is accessible only to those authorized to access it. When an
unauthorized person views patient records using stolen credentials, the confidentiality of that data is
breached. Integrity relates to data modification, availability relates to system uptime, and non-repudiation is
a separate principle ensuring actions cannot be denied.
Q2 Question 2 of 75
A financial institution implements a hash function on all transaction records before storing them in the
database. When an auditor reviews the records six months later, she can verify that no transactions
have been altered. This approach primarily protects the CIA principle of:
A. Confidentiality because the hash function encrypts the transaction records to prevent unauthorized
viewing
B. Integrity because the hash function detects any changes made to the transaction records
after they were stored
C. Availability because the hash function ensures that transaction records remain accessible to
authorized users
D. Authentication because the hash function verifies the identity of the user who created each
transaction
Correct Answer: B
Rationale:
A hash function creates a fixed-size digest of data that changes if even one bit of the original data is
modified, making it an integrity verification mechanism. Hashing does not encrypt data for confidentiality,
does not ensure system availability, and does not authenticate users.
WGU C836 Fundamentals of Information Security Exam 2026 CIA Triad, Threats, Security Controls -- 2026/2027 | Passing Score: 80% | Page 3 of 41
, Q3 Question 3 of 75
A 34-year-old network administrator at an e-commerce company is configuring a load balancer and
redundant web servers to ensure that the company's online store remains accessible even during
peak traffic events and hardware failures. This design primarily supports the CIA principle of:
A. Confidentiality because the load balancer encrypts traffic between clients and web servers
B. Integrity because the redundant servers verify that data has not been tampered with
C. Availability because the redundant architecture ensures continuous access to the online
store despite failures
D. Non-repudiation because the load balancer provides proof of all transactions processed
Correct Answer: C
Rationale:
Redundant servers and load balancing are availability controls that ensure systems remain accessible
during failures or high demand. Encryption supports confidentiality, data verification supports integrity, and
non-repudiation involves proof of origin for transactions.
Q4 Question 4 of 75
A defense contractor stores classified documents on an air-gapped system that is physically isolated
from any network connection. Only personnel with top-secret clearance who pass biometric
authentication can access the room. This approach primarily enforces:
A. Availability by ensuring that classified documents are always accessible to cleared personnel on
demand
B. Authentication by verifying the biometric identity of all personnel who enter the facility
C. Integrity by preventing any modifications to classified documents through network isolation
D. Confidentiality by restricting access to classified information through physical isolation and
authentication controls
Correct Answer: D
Rationale:
An air-gapped system with biometric access controls is a confidentiality measure designed to prevent
unauthorized access to sensitive information. While physical isolation may incidentally protect integrity, the
primary purpose is to keep information confidential. The system is not designed for high availability, and
authentication is a supporting control, not the primary objective.
WGU C836 Fundamentals of Information Security Exam 2026 CIA Triad, Threats, Security Controls -- 2026/2027 | Passing Score: 80% | Page 4 of 41