Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 76 pages
Exam (elaborations)

WGU Course C836 Practice Exam - Fundamentals of Information Security | A Review of 200 Real Comprehensive -Questions with Solutions Each Supported by Rationale

Document preview thumbnail
Preview 4 out of 76 pages

WGU C836 Practice Exam: 200 Real Questions & Answers with Rationales to Pass the Fundamentals of Information Security This document is a complete practice exam for the WGU Course C836 – Fundamentals of Information Security. Featuring 200 realistic questions and detailed answers, it serves as an essential tool for final exam preparation. Designed to simulate the real test environment, these questions are organized by topic to help you track your progress and focus on areas needing improvement. From essential security terminology to advanced attack frameworks like Metasploit and common vulnerabilities like SQL injection, this guide covers it all. The included rationales provide crucial context, linking each answer back to the core security principles required to pass the exam and build a solid foundation in cybersecurity. WGU Course C836 Practice Exam - Fundamentals of Information Security | A Review of 200 Real Comprehensive -Questions with Solutions Each Supported by Rationale ________________________________________ INTRODUCTION This comprehensive practice examination is designed to prepare students for the WGU Course C836 - Fundamentals of Information Security assessment. The questions cover key security concepts including: • Vulnerability Assessment Tools (Nessus, network scanning, and penetration testing) • Attack Frameworks (Exploit frameworks, attack methodologies) • Software Vulnerabilities (Buffer overflows, race conditions, injection attacks) • Web Application Security (XSS, XSRF, SQL injection, clickjacking) • Secure Coding Practices (CERT guidelines, input validation, authentication) • System Security Fundamentals (Access control, authentication, cryptography basics) This exam contains 200 multiple-choice questions with detailed rationales for each answer. Questions are organized by topic area and difficulty level to simulate the actual certification exam experience. Use this practice test to identify knowledge gaps and reinforce your understanding of information security fundamentals. ________________________________________ TABLE OF CONTENTS Section Topic Area Questions 1 Security Fundamentals & Terminology 1-30 2 Vulnerability Assessment & Penetration Testing 31-55 3 Application Security & Secure Coding 56-85 4 Web Application Attacks 86-115 5 Software Vulnerabilities 116-145 6 Security Management & Risk 146-175 7 Cryptography & Access Control 176-200 ________________________________________ MULTICHOICE SECTION 1: SECURITY FUNDAMENTALS & TERMINOLOGY Questions 1-30 ________________________________________ 1. Which of the following best describes the primary goal of information security? A) To prevent all security breaches B) To balance protection with usability and cost C) To eliminate all vulnerabilities D) To focus only on technical controls Answer: B Rationale: Information security aims to balance protection (confidentiality, integrity, availability) with operational requirements, usability, and cost constraints. Complete prevention of all breaches is impossible, and security must serve business needs. ________________________________________ 2. What is the fundamental difference between a vulnerability and a threat? A) Vulnerabilities are intentional, threats are accidental B) A vulnerability is a weakness, while a threat is a potential danger that could exploit it C) Threats are always technical, vulnerabilities are always human D) There is no significant difference Answer: B Rationale: A vulnerability is a weakness or gap in security protection, while a threat is a potential danger that could exploit that vulnerability. The combination of threat, vulnerability, and asset creates risk. ________________________________________ 3. Which of the following is NOT considered a fundamental security objective? A) Confidentiality B) Integrity C) Availability D) Authenticity Answer: D Rationale: The three fundamental security objectives (CIA triad) are Confidentiality, Integrity, and Availability. Authenticity is important but is typically considered a subset or related concept rather than a primary objective. ________________________________________ 4. What term describes the process of verifying a user's identity? A) Authorization B) Authentication C) Accounting D) Auditing Answer: B Rationale: Authentication is the process of verifying that a user's claimed identity is genuine. Authorization determines what the authenticated user can access, while accounting tracks user activities. ________________________________________ 5. Which of the following represents the strongest authentication factor? A) Something you know (password) B) Something you have (smart card) C) Something you are (biometric) D) Multi-factor authentication Answer: D Rationale: Multi-factor authentication (MFA) combines two or more authentication factors, providing significantly stronger security than any single factor alone. Even biometrics, which are generally strong, can be compromised or spoofed. ________________________________________ 6. In information security, what is "defense in depth"? A) Having multiple layers of security controls B) Placing all security at the perimeter C) Using only one type of control D) Focusing on physical security only Answer: A Rationale: Defense in depth is a security strategy that uses multiple layers of defense throughout an information system. If one layer fails, subsequent layers continue to provide protection. ________________________________________ 7. What is the primary purpose of risk assessment? A) To eliminate all risks B) To identify, analyze, and evaluate risks to determine appropriate controls C) To prove that security is unnecessary D) To focus only on technical vulnerabilities Answer: B Rationale: Risk assessment identifies assets, threats, and vulnerabilities, then analyzes the potential impact and likelihood to determine the appropriate security controls and risk treatment strategies. ________________________________________ 8. Which of the following is an example of a physical security control? A) Firewall B) Encryption C) Biometric door locks D) Intrusion detection system Answer: C Rationale: Biometric door locks are physical security controls that restrict physical access to facilities or areas. Firewalls, encryption, and IDS are technical/logical controls. ________________________________________ 9. What is the difference between a security policy and a security procedure? A) There is no difference B) Policies are high-level directives; procedures are step-by-step instructions C) Policies are optional; procedures are mandatory D) Policies are for managers; procedures are for technical staff Answer: B Rationale: Security policies are high-level management directives that establish security requirements. Procedures are detailed, step-by-step instructions on how to implement the policies. ________________________________________ 10. Which of the following best describes "residual risk"? A) The risk that cannot be identified B) The risk that remains after controls have been implemented C) The risk that is always accepted D) The risk that only affects physical assets Answer: B Rationale: Residual risk is the risk that remains after security controls have been applied. Organizations typically accept residual risk when the cost of additional controls exceeds the potential loss. ________________________________________ 11. What is the primary purpose of security awareness training? A) To make all employees security experts B) To ensure users understand their security responsibilities C) To eliminate all security incidents D) To replace technical security controls Answer: B Rationale: Security awareness training educates users about security risks, policies, and their role in protecting organizational assets. It cannot replace technical controls but complements them by creating a security-conscious workforce. ________________________________________ 12. Which of the following is an example of a deterrent control? A) Security guard B) Encryption C) Warning banner D) Firewall Answer: C Rationale: Warning banners serve as deterrent controls by discouraging unauthorized behavior through visible warnings of consequences. Security guards

Content preview

WGU Course C836 Practice Exam -
Fundamentals of Information Security | A
Review of 200 Real Comprehensive -
Questions with Solutions Each Supported by
Rationale

INTRODUCTION
This comprehensive practice examination is designed to prepare students for the
WGU Course C836 - Fundamentals of Information Security assessment. The
questions cover key security concepts including:
• Vulnerability Assessment Tools (Nessus, network scanning, and
penetration testing)
• Attack Frameworks (Exploit frameworks, attack methodologies)
• Software Vulnerabilities (Buffer overflows, race conditions, injection
attacks)
• Web Application Security (XSS, XSRF, SQL injection, clickjacking)
• Secure Coding Practices (CERT guidelines, input validation,
authentication)
• System Security Fundamentals (Access control, authentication,
cryptography basics)
This exam contains 200 multiple-choice questions with detailed rationales for each
answer. Questions are organized by topic area and difficulty level to simulate the
actual certification exam experience. Use this practice test to identify knowledge
gaps and reinforce your understanding of information security fundamentals.

,\
TABLE OF CONTENTS

Section Topic Area Questions

1 Security Fundamentals & Terminology 1-30

2 Vulnerability Assessment & Penetration Testing 31-55

3 Application Security & Secure Coding 56-85

4 Web Application Attacks 86-115

5 Software Vulnerabilities 116-145

6 Security Management & Risk 146-175

7 Cryptography & Access Control 176-200




MULTICHOICE
SECTION 1: SECURITY FUNDAMENTALS & TERMINOLOGY
Questions 1-30


1. Which of the following best describes the primary goal of information
security?
A) To prevent all security breaches
B) To balance protection with usability and cost

,C) To eliminate all vulnerabilities
D) To focus only on technical controls
Answer: B
Rationale: Information security aims to balance protection (confidentiality,
integrity, availability) with operational requirements, usability, and cost
constraints. Complete prevention of all breaches is impossible, and security must
serve business needs.


2. What is the fundamental difference between a vulnerability and a threat?
A) Vulnerabilities are intentional, threats are accidental
B) A vulnerability is a weakness, while a threat is a potential danger that could
exploit it
C) Threats are always technical, vulnerabilities are always human
D) There is no significant difference
Answer: B
Rationale: A vulnerability is a weakness or gap in security protection, while a
threat is a potential danger that could exploit that vulnerability. The combination
of threat, vulnerability, and asset creates risk.


3. Which of the following is NOT considered a fundamental security
objective?
A) Confidentiality
B) Integrity
C) Availability
D) Authenticity
Answer: D
Rationale: The three fundamental security objectives (CIA triad) are
Confidentiality, Integrity, and Availability. Authenticity is important but is typically
considered a subset or related concept rather than a primary objective.

, 4. What term describes the process of verifying a user's identity?
A) Authorization
B) Authentication
C) Accounting
D) Auditing
Answer: B
Rationale: Authentication is the process of verifying that a user's claimed identity
is genuine. Authorization determines what the authenticated user can access, while
accounting tracks user activities.


5. Which of the following represents the strongest authentication factor?
A) Something you know (password)
B) Something you have (smart card)
C) Something you are (biometric)
D) Multi-factor authentication
Answer: D
Rationale: Multi-factor authentication (MFA) combines two or more authentication
factors, providing significantly stronger security than any single factor alone. Even
biometrics, which are generally strong, can be compromised or spoofed.


6. In information security, what is "defense in depth"?
A) Having multiple layers of security controls
B) Placing all security at the perimeter
C) Using only one type of control
D) Focusing on physical security only
Answer: A
Rationale: Defense in depth is a security strategy that uses multiple layers of
defense throughout an information system. If one layer fails, subsequent layers
continue to provide protection.

Document information

Uploaded on
July 1, 2026
Number of pages
76
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$18.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TutorGeoff
3.9
(14)
Sold
57
Followers
2
Items
633
Last sold
3 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions