Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 394 pages
Exam (elaborations)

WGU C845 (Information Systems Security) Task 3: Risk and Mitigation

Document preview thumbnail
Preview 4 out of 394 pages

This document is a study aid for the WGU course C845, Information Systems Security, focusing on Task 3. It contains practice questions that cover evaluating data security risks, implementing mitigation strategies, and understanding business continuity and disaster recovery planning. The content is geared toward IT security management, covering topics like access control, risk analysis, and incident response.

Content preview

WGU C845 VUN1 TASK 3: EVALUATING DATA
SECURITY RISKS AND MITIGATION
STRATEGIES| UPDATE WITH COMPLETE
SOLUTIONS LATEST UPDATE


Which of the following is not considered an example of a non-discretionary access

control system?

A MAC

B ACL

C ABAC

D RBAC - ANSWER-B

How should countermeasures be implemented as part of the recovery phase of incident

response?

A During next year's security review

B Based on the lowest cost among available options

C As defined by the current security policy

D As determined by the violation that occurred - ANSWER-D

Remote control malware was found on a client device, and an unknown attacker was manipulating the
network from afar. The attack resulted in the network switches reverting to flooding mode, thereby
enabling the attacker to eavesdrop on a significant portion of network communications. After
reviewing IDS and traffic logs, you determine that this was accomplished by an attack utility which
generated a constant Ethernet frames with random source MAC addresses. What can be done to
prevent this attack from occurring in the future?

A Restrict access to DHCP.

B Use a static HOSTS file.

,C Use MAC limiting on the switch ports.D Implement an ARP monitor. - ANSWER-C How is
quantitative risk analysis performed?

A Through the Delphi technique

B With scenario-based assessments

C Using calculations

D Via employee interviews - ANSWER-C

What special component on a motherboard can be used to securely store the

encryption key for whole drive encryption?

A CMOS

B RAM

C TPM

D CPU - ANSWER-C

When is it appropriate to contact law enforcement when an organization experiences a

security breach?

A If a violation is more severe than just breaking company policy rules

B If a breach of security occurs

C If a tolerable or accepted risk is realized

D If an insider uses another employee's credentials - ANSWER-A

What is the name of a cryptographic attack based on a database of pre-computed hash

values and the original plaintext values?

A Brute force attack

B Rainbow table attack

C Frequency analysis

D Chosen plaintext attack - ANSWER-B

What is the purpose of a Security Information and Event Management (SIEM) product?

A To provide real-time logging and analysis of security events

,B To define the requirements of security procedures

C To provide event planning guidance for holding industry conferences

D To improve employee security training - ANSWER-A

How does salting passwords reduce the likelihood that a password cracking attack will

be successful?

A It prevents automated attacks.

B It forces the attacker to focus on one account at a time.

C It triggers an account lockout after a fixed number of false attempts.

D It increases the work load required to become successful. - ANSWER-D



Which of the following clearance levels or classification labels is not generally used in a

government- or military-based MAC scheme?

A Unclassified

B Confidential

C Top Secret

D Proprietary - ANSWER-D

You are starting a new website. You want to quickly allow users to begin using your site

without having the hassle of creating a new user account. You set up a one-way trust

federated access link from your website to the three major social networks. Why should

you use a one-way trust in this configuration rather than a two-way trust in this

scenario?

A A one-way trust allows your website to trust the user accounts of the social networks

without requiring the social networks to trust your website.

B Two-way trusts are only valid in private networks and cannot be used across the

Internet.

C A one-way trust allows your website to access the file storage of the social networks.

, D A two-way trust would grant the social network administrators full access to your

backend database. - ANSWER-A

Why should the risks of an organization be reported as defined by enterprise risk

management (ERM)?

A It is a means to predict loss, select countermeasures, and reduce downtime.

B It is a government regulation.

C It helps with internal transparency, risk assessment, risk response, and risk

monitoring.

D It assists with strategic planning, compliance, and training. - ANSWER-C



Which of the following is a symmetric algorithm?

A Diffie-Hellman

B RSA

C AES

D HMAC - ANSWER-C

How can a user be given the power to set privileges on an object for other users when

within a DAC operating system?

A Remove special permissions for the user on the object.

B Grant the user full control over the object.

C Give the user the modify privilege on the object.

D Issue an administrative job label to the user. - ANSWER-B

Your company adopts a new end-user security awareness program. This training includes malware
introduction, social media issues, password guidelines, data exposure, and lost devices. How often
should end users receive this training?

A once a year and upon termination

B upon new hire and once a year thereafter

Document information

Uploaded on
August 4, 2026
Number of pages
394
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$27.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Highgradeshub
4.0
(2)
Sold
16
Followers
0
Items
5372
Last sold
1 week ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions