WGU D430 FUNDAMENTAL OF INFORMATION SECURITY PRE-ASSESSMENT &
OA EXAM – QUESTIONS AND ANSWERS | EXAM TESTBANK WITH VERIFIED
AND WELL DETAILED ANSWERS | PLUS RATIONALES | DOWNLOAD AND PASS |
LATEST EXAM UPDATE 2026/2027
Core Domains
Information Security Governance and Risk Management
Access Control and Identity Management
Network and Communications Security
Security Operations and Incident Response
Cryptography and PKI
Application and Data Security
Physical and Environmental Security
Legal, Regulatory, and Compliance Frameworks
Business Continuity and Disaster Recovery Planning
Security Architecture and Design
Introduction
This comprehensive assessment is designed to evaluate a candidate's mastery of the
fundamental principles and practices of information security. It rigorously tests
knowledge across the core domains, blending foundational theory with applied
professional knowledge. The exam includes a mix of multiple-choice questions and
scenario-based items to assess critical thinking, decision-making, and the ability to
apply security concepts in real-world situations. Candidates must demonstrate their
understanding of risk management, access controls, network security, and incident
response, among other key areas. The emphasis is on practical application, ethical
considerations, and the ability to navigate complex security challenges, preparing
,candidates for both the Pre-Assessment and the Objective Assessment. This test
bank serves as a definitive study resource for achieving success.
SECTION ONE: QUESTIONS 1 – 50
1. Which of the following best describes the primary purpose of the 'CIA Triad'
in information security?
A. To define a set of policies for user access control.
B. To ensure the confidentiality, integrity, and availability of information.
C. To establish a framework for auditing security controls.
D. To provide a method for encrypting data at rest and in transit.
🟢 Correct Answer: B. To ensure the confidentiality, integrity, and availability of
information.
🔴 Explanation: The CIA Triad is the foundational model for information security,
representing the three core principles: Confidentiality, Integrity, and Availability.
All security controls are designed to support one or more of these principles.
2. What is the primary objective of a risk assessment in an information security
program?
A. To eliminate all identified risks to the organization.
B. To ensure 100% compliance with all regulatory requirements.
C. To identify, quantify, and prioritize risks to inform decision-making.
D. To install the latest security software and hardware.
,🟢 Correct Answer: C. To identify, quantify, and prioritize risks to inform decision-
making.
🔴 Explanation: A risk assessment is a systematic process to understand the risks
an organization faces. It helps in making informed decisions about how to treat
those risks (e.g., mitigate, accept, transfer, avoid), not to eliminate all risks, which
is impossible.
3. A security analyst discovers that a user has been granted administrative
privileges on a system that they no longer require for their job duties. This is a
violation of which security principle?
A. Separation of Duties
B. Least Privilege
C. Defense in Depth
D. Need to Know
🟢 Correct Answer: B. Least Privilege
🔴 Explanation: The principle of least privilege dictates that users should be
granted only the minimum level of access and permissions necessary to perform
their job functions. Granting unnecessary administrative rights violates this
principle.
4. An organization is developing a new web application and wants to ensure
that a security vulnerability in one component does not compromise the entire
system. Which architectural principle is being applied?
A. Separation of Duties
B. Defense in Depth
, C. Fail Safe
D. Weakest Link
🟢 Correct Answer: B. Defense in Depth
🔴 Explanation: Defense in Depth is the strategy of using multiple, overlapping
layers of security controls. This ensures that if one layer is breached, other layers
will continue to provide protection, preventing a single point of failure.
5. Which type of attack involves an attacker tricking a user into revealing
sensitive information by masquerading as a trustworthy entity in an electronic
communication?
A. Phishing
B. Man-in-the-Middle
C. Denial of Service
D. SQL Injection
🟢 Correct Answer: A. Phishing
🔴 Explanation: Phishing is a social engineering attack where the attacker sends
fraudulent communications, often emails, that appear to come from a legitimate
source to steal sensitive data like login credentials or credit card numbers.
6. What is the primary goal of a Business Continuity Plan (BCP)?
A. To detect and respond to a security incident.
B. To restore business operations to a normal state after a disaster.
C. To ensure critical business functions can continue during and after a disaster.
D. To eliminate all potential risks to the business.
OA EXAM – QUESTIONS AND ANSWERS | EXAM TESTBANK WITH VERIFIED
AND WELL DETAILED ANSWERS | PLUS RATIONALES | DOWNLOAD AND PASS |
LATEST EXAM UPDATE 2026/2027
Core Domains
Information Security Governance and Risk Management
Access Control and Identity Management
Network and Communications Security
Security Operations and Incident Response
Cryptography and PKI
Application and Data Security
Physical and Environmental Security
Legal, Regulatory, and Compliance Frameworks
Business Continuity and Disaster Recovery Planning
Security Architecture and Design
Introduction
This comprehensive assessment is designed to evaluate a candidate's mastery of the
fundamental principles and practices of information security. It rigorously tests
knowledge across the core domains, blending foundational theory with applied
professional knowledge. The exam includes a mix of multiple-choice questions and
scenario-based items to assess critical thinking, decision-making, and the ability to
apply security concepts in real-world situations. Candidates must demonstrate their
understanding of risk management, access controls, network security, and incident
response, among other key areas. The emphasis is on practical application, ethical
considerations, and the ability to navigate complex security challenges, preparing
,candidates for both the Pre-Assessment and the Objective Assessment. This test
bank serves as a definitive study resource for achieving success.
SECTION ONE: QUESTIONS 1 – 50
1. Which of the following best describes the primary purpose of the 'CIA Triad'
in information security?
A. To define a set of policies for user access control.
B. To ensure the confidentiality, integrity, and availability of information.
C. To establish a framework for auditing security controls.
D. To provide a method for encrypting data at rest and in transit.
🟢 Correct Answer: B. To ensure the confidentiality, integrity, and availability of
information.
🔴 Explanation: The CIA Triad is the foundational model for information security,
representing the three core principles: Confidentiality, Integrity, and Availability.
All security controls are designed to support one or more of these principles.
2. What is the primary objective of a risk assessment in an information security
program?
A. To eliminate all identified risks to the organization.
B. To ensure 100% compliance with all regulatory requirements.
C. To identify, quantify, and prioritize risks to inform decision-making.
D. To install the latest security software and hardware.
,🟢 Correct Answer: C. To identify, quantify, and prioritize risks to inform decision-
making.
🔴 Explanation: A risk assessment is a systematic process to understand the risks
an organization faces. It helps in making informed decisions about how to treat
those risks (e.g., mitigate, accept, transfer, avoid), not to eliminate all risks, which
is impossible.
3. A security analyst discovers that a user has been granted administrative
privileges on a system that they no longer require for their job duties. This is a
violation of which security principle?
A. Separation of Duties
B. Least Privilege
C. Defense in Depth
D. Need to Know
🟢 Correct Answer: B. Least Privilege
🔴 Explanation: The principle of least privilege dictates that users should be
granted only the minimum level of access and permissions necessary to perform
their job functions. Granting unnecessary administrative rights violates this
principle.
4. An organization is developing a new web application and wants to ensure
that a security vulnerability in one component does not compromise the entire
system. Which architectural principle is being applied?
A. Separation of Duties
B. Defense in Depth
, C. Fail Safe
D. Weakest Link
🟢 Correct Answer: B. Defense in Depth
🔴 Explanation: Defense in Depth is the strategy of using multiple, overlapping
layers of security controls. This ensures that if one layer is breached, other layers
will continue to provide protection, preventing a single point of failure.
5. Which type of attack involves an attacker tricking a user into revealing
sensitive information by masquerading as a trustworthy entity in an electronic
communication?
A. Phishing
B. Man-in-the-Middle
C. Denial of Service
D. SQL Injection
🟢 Correct Answer: A. Phishing
🔴 Explanation: Phishing is a social engineering attack where the attacker sends
fraudulent communications, often emails, that appear to come from a legitimate
source to steal sensitive data like login credentials or credit card numbers.
6. What is the primary goal of a Business Continuity Plan (BCP)?
A. To detect and respond to a security incident.
B. To restore business operations to a normal state after a disaster.
C. To ensure critical business functions can continue during and after a disaster.
D. To eliminate all potential risks to the business.