Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 59 pages
Exam (elaborations)

WGU D486 DFN1 Task 1 Governance Risk & Compliance FMC Remediation Actual 2026/2027 – Complete Questions with Detailed Rationales | 100% Verified Solutions – Pass Guaranteed – A+ Graded INSTANT DOWNOLD

Document preview thumbnail
Preview 4 out of 59 pages

WGU D486 DFN1 Task 1 Governance Risk & Compliance FMC Remediation Actual 2026/2027 – Complete Questions with Detailed Rationales | 100% Verified Solutions – Pass Guaranteed – A+ Graded INSTANT DOWNOLD

Content preview

WGU D486 DFN1 Task 1 Governance Risk
& Compliance FMC Remediation Actual
2026/2027 – Complete Questions with
Detailed Rationales | 100% Verified
Solutions – Pass Guaranteed – A+ Graded
INSTANT DOWNOLD

Question 1: What is the primary purpose of IT governance?

 Answer: To ensure that IT investments and activities align with
organizational goals, deliver business value, manage risks, and comply with
legal and regulatory requirements.
 Rationale: IT governance provides the overarching framework and
leadership structure to align IT strategy with business strategy. This involves
not only managing risk but also ensuring technology investments create
value and the organization meets its legal and regulatory obligations.

Question 2: Which framework is primarily used for IT governance?

 Answer: B) COBIT.
 Rationale: COBIT (Control Objectives for Information and Related
Technologies) is a widely accepted framework that separates governance
from management. It provides comprehensive guidance for governing and
managing enterprise IT, helping organizations generate maximum added
value from their IT investments while mitigating risk.

Question 3: What is the definition of risk in the context of information
security?

, Answer: Risk is the potential that a given threat will exploit vulnerabilities
of an asset or group of assets and thereby cause harm to the organization.
It is measured in terms of likelihood and impact.
 Rationale: Risk is not just a threat or a vulnerability, but the intersection of
the two. For a risk to exist, there must be a threat agent capable of
exploiting a vulnerability, and the resulting impact must be of concern to
the organization.

Question 4: Which risk treatment option involves eliminating the
activity causing the risk?

 Answer: B) Avoid.
 Rationale: Risk avoidance is the strategy of not performing an activity that
carries potential risk. For example, if a new market introduces unacceptable
regulatory risk, the organization may choose to avoid that market entirely
rather than accept or mitigate the risk.

Question 5: Which framework focuses on information security
management systems (ISMS)?

 Answer: B) ISO/IEC 27001.
 Rationale: ISO/IEC 27001 is a globally recognized standard that specifies
the requirements for establishing, implementing, maintaining, and
continually improving an information security management system (ISMS).
It provides a systematic approach to managing sensitive company
information so that it remains secure.

Question 6: What does the acronym CIA stand for in cybersecurity?

 Answer: Confidentiality, Integrity, Availability.
 Rationale: The CIA triad is a foundational security model that guides
security policies. Confidentiality ensures data is accessible only to

, authorized users; Integrity ensures data is accurate and unaltered; and
Availability ensures data and systems are accessible when needed.

Question 7: Which role is ultimately responsible for corporate
governance?

 Answer: C) Board of Directors.
 Rationale: The Board of Directors holds the ultimate responsibility for
corporate governance, including overseeing the organization's strategic
direction, risk management framework, and compliance with laws and
regulations. The board delegates the implementation of these tasks to
management.

Question 8: What is residual risk?

 Answer: Residual risk is the risk that remains after security controls have
been implemented.
 Rationale: It's impossible to eliminate all risks. Residual risk is the level of
risk that management is willing to accept after all feasible and cost-effective
security measures have been applied. It's the risk that the organization
must monitor and manage going forward.

Question 9: Which of the following is considered an administrative
security control?

 Answer: C) Security Awareness Training.
 Rationale: Administrative controls are management-driven policies,
procedures, and practices. Security awareness training is an administrative
control because it aims to educate employees about security policies and
their responsibilities, thereby influencing behavior to reduce risk. This is
distinct from technical controls like firewalls or encryption.

Question 10: Why are periodic security audits important?

,  Answer: Security audits verify compliance, evaluate the effectiveness of
controls, identify weaknesses, and support continuous improvement of
governance and risk management practices.
 Rationale: Audits provide an independent assessment of the security
posture. They are critical for identifying gaps that could be exploited,
ensuring compliance with policies and regulations, and providing evidence
to stakeholders that risks are being managed appropriately.

Question 11: What is a Business Impact Analysis (BIA)?

 Answer: A BIA identifies critical business functions, estimates the impact of
disruptions, and determines recovery priorities.
 Rationale: The BIA is a key component of business continuity planning. It
helps organizations understand the potential financial and operational
consequences of a disruption, allowing them to prioritize which functions
and systems need to be restored first in the event of an incident.

Question 12: Why is segregation of duties important?

 Answer: It reduces fraud and errors by ensuring that no single individual
controls all phases of a critical process.
 Rationale: Segregation of duties is a fundamental internal control. By
dividing responsibilities among multiple individuals, it creates a system of
checks and balances that prevents a single person from having excessive
power or from committing and concealing errors or fraud.

Question 13: Which regulation protects personal health information in
the United States?

 Answer: C) HIPAA.
 Rationale: The Health Insurance Portability and Accountability Act (HIPAA)
establishes national standards for the protection of individuals' medical
records and other personal health information (PHI). It applies to covered

Document information

Uploaded on
August 15, 2026
Number of pages
59
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$20.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
3
Followers
0
Items
334
Last sold
4 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions