ASSESSMENT | OA V1 AND V2 | ACTUAL QUESTIONS AND ANSWERS | 2026
UPDATE | 100% CORRECT] ACTUAL QUESTIONS AND CORRECT ANSWERS
(LATEST 2026 UPDATE) | COMPLETE Q&A WITH VERIFIED ANSWERS AND
DETAILED RATIONALS | OBJECTIVE ASSESSMENT PREP | A+ GRADED
Core Domains
Information Security Fundamentals and the CIA Triad
Risk Management and Security Governance
Access Control and Identity Management
Cryptography and Public Key Infrastructure
Network Security and Firewalls
Security Operations and Incident Response
Business Continuity and Disaster Recovery
Legal, Ethical, and Compliance Issues
Physical and Environmental Security
Software Development Security
Introduction
This objective assessment evaluates the student’s mastery of foundational
information security principles as taught in WGU’s D827/D430 course.
The 70 multiple-choice questions cover the core domains of security
governance, risk management, access control, cryptography, network
defense, incident response, business continuity, and legal compliance.
Each question is designed to test both conceptual understanding and
practical application, preparing students for the certification-aligned
exam and for real-world security roles. Detailed RATIONALE s reinforce
learning and promote critical thinking. Success on this assessment
confirms readiness to protect organizational assets and to uphold the
confidentiality, integrity, and availability of information systems.
SECTION ONE: QUESTIONS 1–70
, 1. A security analyst discovers that an unauthorized user was able to view
confidential payroll data. Which principle of the CIA triad has been
violated?
A. Integrity
B. Availability
C. Confidentiality
D. Non-repudiation
C. Confidentiality
RATIONALE : Confidentiality ensures that information is accessible only to
those authorized. Unauthorized viewing of payroll data breaches confidentiality.
Integrity (A) involves data accuracy; availability (B) ensures systems are
accessible; non-repudiation (D) prevents denial of actions.
2. Which of the following is an example of a detective control?
A. A firewall blocking incoming traffic
B. An intrusion detection system (IDS) generating alerts
C. A security guard checking badges at a gate
D. Data encryption at rest
B. An intrusion detection system (IDS) generating alerts
RATIONALE : Detective controls identify and alert on security events after
they occur. An IDS detects malicious activity and notifies administrators. A firewall
(A) is a preventive control; a security guard (C) is a deterrent/preventive;
encryption (D) is a preventive control.
3. A company wants to ensure that a user cannot deny having sent a specific
email. Which security service is required?
A. Authentication
B. Integrity
C. Non-repudiation
D. Authorization
C. Non-repudiation
, RATIONALE : Non-repudiation provides proof of the origin and integrity of
data, preventing the sender from denying they sent it. Digital signatures are
commonly used. Authentication (A) verifies identity; integrity (B) ensures data
hasn't been altered; authorization (D) grants permissions.
4. Which access control model assigns permissions based on the sensitivity of
the information and the clearance of the subject?
A. Discretionary Access Control (DAC)
B. Mandatory Access Control (MAC)
C. Role-Based Access Control (RBAC)
D. Rule-Based Access Control
B. Mandatory Access Control (MAC)
RATIONALE : MAC uses labels (e.g., Top Secret, Confidential) and clearances;
the system enforces access based on these labels, not the owner’s discretion. DAC
(A) gives owners control; RBAC (C) assigns permissions by job role; rule-based (D)
uses dynamic rules.
5. A risk management strategy where an organization decides to purchase
insurance to cover potential losses from a data breach is known as:
A. Risk avoidance
B. Risk mitigation
C. Risk transfer
D. Risk acceptance
C. Risk transfer
RATIONALE : Transferring risk shifts the financial impact to a third party, such
as an insurer. Avoidance (A) eliminates the risk entirely; mitigation (B) reduces the
risk; acceptance (D) acknowledges and tolerates the risk.
6. Which of the following is a symmetric encryption algorithm?
A. RSA
B. Diffie-Hellman
C. AES
D. ECC