WGU D440 Cybersecurity Foundations Mock Exam 2026 UPDAT… 2026 Update • Verified Answers
✓ VERIFIED • 2026 UPDATE • 100% ACCURATE
WGU D440 Cybersecurity Foundations Mock Exam
2026 UPDATE
Actual Exam Questions & Verified Answers
with Detailed Rationales
Document Type: Exam (Elaborations)
Academic Year:
Total Questions: 50 Multiple Choice
Includes: Correct Answers + Full Rationales
Status: Verified & Updated for 2026
Exam (Elaborations) • Actual Questions & Rationales Page 1
,WGU D440 Cybersecurity Foundations Mock Exam 2026 UPDAT… 2026 Update • Verified Answers
Questions & Verified Answers
1. Which component of the CIA triad is compromised when an attacker performs a successful
DoS attack against a web server?
A. Confidentiality
B. Availability
C. Integrity
D. Accountability
Answer: B
Rationale: Availability ensures that systems and data are accessible to authorized users when needed. A
Denial of Service (DoS) attack specifically targets the uptime and accessibility of a resource. Applying this
knowledge in clinical settings supports safe, evidence-based practice and improves patient outcomes.
2. An organization implements encryption to ensure that sensitive data cannot be read by
unauthorized individuals. Which principle of the CIA triad is being addressed?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Answer: A
Rationale: Confidentiality is the principle of ensuring that data is only accessible to those who have the
authorization to view it. Encryption is a primary tool for achieving this. Applying this knowledge in clinical
settings supports safe, evidence-based practice and improves patient outcomes.
3. Which of the following describes ‘Integrity’ in the context of the CIA triad?
A. Ensuring data is available for use
B. Ensuring data has not been modified by unauthorized parties
C. Protecting data from unauthorized disclosure
D. Providing proof of the origin of data
Answer: B
Rationale: Integrity focuses on the accuracy and consistency of data, ensuring it is not altered by unauthorized
users or processes. Exam questions often test the ability to distinguish this concept from closely related
distractors, making a clear rationale essential for mastery. Applying this knowledge in clinical settings supports
safe, evidence-based practice and improves patient outcomes.
Exam (Elaborations) • Actual Questions & Rationales Page 2
, WGU D440 Cybersecurity Foundations Mock Exam 2026 UPDAT… 2026 Update • Verified Answers
4. What is the primary purpose of the ‘Identify’ function in the NIST Cybersecurity Framework?
A. To develop the organizational understanding to manage cybersecurity risk
B. To implement safeguards to ensure delivery of services
C. To develop activities to identify the occurrence of a security event
D. To restore capabilities or services that were impaired
Answer: A
Rationale: The Identify function focuses on understanding the business context, resources, and risks to enable
the organization to prioritize its efforts. Applying this knowledge in clinical settings supports safe,
evidence-based practice and improves patient outcomes. This is an important clinical concept because
selecting the correct answer (A) requires understanding both the pathophysiology and the practical nursing
implications.
5. Which threat actor is typically characterized as a highly skilled, state-sponsored group that
conducts long-term, targeted operations?
A. Script Kiddie
B. Hacktivist
C. Advanced Persistent Threat (APT)
D. Insider Threat
Answer: C
Rationale: APTs are sophisticated, well-funded groups (often state-sponsored) that maintain a long-term
presence on a network to exfiltrate data. Recognizing this principle allows the nurse to prioritize care, anticipate
complications, and provide accurate patient education. Exam questions often test the ability to distinguish this
concept from closely related distractors, making a clear rationale essential for mastery.
6. A company decides to purchase an insurance policy to cover potential financial losses from
a data breach. Which risk management strategy is being used?
A. Risk Acceptance
B. Risk Avoidance
C. Risk Mitigation
D. Risk Transference
Answer: D
Rationale: Risk Transference involves shifting the financial consequences of a risk to a third party, such as an
insurance company. This is an important clinical concept because selecting the correct answer (D) requires
understanding both the pathophysiology and the practical nursing implications. Recognizing this principle
allows the nurse to prioritize care, anticipate complications, and provide accurate patient education.
Exam (Elaborations) • Actual Questions & Rationales Page 3
✓ VERIFIED • 2026 UPDATE • 100% ACCURATE
WGU D440 Cybersecurity Foundations Mock Exam
2026 UPDATE
Actual Exam Questions & Verified Answers
with Detailed Rationales
Document Type: Exam (Elaborations)
Academic Year:
Total Questions: 50 Multiple Choice
Includes: Correct Answers + Full Rationales
Status: Verified & Updated for 2026
Exam (Elaborations) • Actual Questions & Rationales Page 1
,WGU D440 Cybersecurity Foundations Mock Exam 2026 UPDAT… 2026 Update • Verified Answers
Questions & Verified Answers
1. Which component of the CIA triad is compromised when an attacker performs a successful
DoS attack against a web server?
A. Confidentiality
B. Availability
C. Integrity
D. Accountability
Answer: B
Rationale: Availability ensures that systems and data are accessible to authorized users when needed. A
Denial of Service (DoS) attack specifically targets the uptime and accessibility of a resource. Applying this
knowledge in clinical settings supports safe, evidence-based practice and improves patient outcomes.
2. An organization implements encryption to ensure that sensitive data cannot be read by
unauthorized individuals. Which principle of the CIA triad is being addressed?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Answer: A
Rationale: Confidentiality is the principle of ensuring that data is only accessible to those who have the
authorization to view it. Encryption is a primary tool for achieving this. Applying this knowledge in clinical
settings supports safe, evidence-based practice and improves patient outcomes.
3. Which of the following describes ‘Integrity’ in the context of the CIA triad?
A. Ensuring data is available for use
B. Ensuring data has not been modified by unauthorized parties
C. Protecting data from unauthorized disclosure
D. Providing proof of the origin of data
Answer: B
Rationale: Integrity focuses on the accuracy and consistency of data, ensuring it is not altered by unauthorized
users or processes. Exam questions often test the ability to distinguish this concept from closely related
distractors, making a clear rationale essential for mastery. Applying this knowledge in clinical settings supports
safe, evidence-based practice and improves patient outcomes.
Exam (Elaborations) • Actual Questions & Rationales Page 2
, WGU D440 Cybersecurity Foundations Mock Exam 2026 UPDAT… 2026 Update • Verified Answers
4. What is the primary purpose of the ‘Identify’ function in the NIST Cybersecurity Framework?
A. To develop the organizational understanding to manage cybersecurity risk
B. To implement safeguards to ensure delivery of services
C. To develop activities to identify the occurrence of a security event
D. To restore capabilities or services that were impaired
Answer: A
Rationale: The Identify function focuses on understanding the business context, resources, and risks to enable
the organization to prioritize its efforts. Applying this knowledge in clinical settings supports safe,
evidence-based practice and improves patient outcomes. This is an important clinical concept because
selecting the correct answer (A) requires understanding both the pathophysiology and the practical nursing
implications.
5. Which threat actor is typically characterized as a highly skilled, state-sponsored group that
conducts long-term, targeted operations?
A. Script Kiddie
B. Hacktivist
C. Advanced Persistent Threat (APT)
D. Insider Threat
Answer: C
Rationale: APTs are sophisticated, well-funded groups (often state-sponsored) that maintain a long-term
presence on a network to exfiltrate data. Recognizing this principle allows the nurse to prioritize care, anticipate
complications, and provide accurate patient education. Exam questions often test the ability to distinguish this
concept from closely related distractors, making a clear rationale essential for mastery.
6. A company decides to purchase an insurance policy to cover potential financial losses from
a data breach. Which risk management strategy is being used?
A. Risk Acceptance
B. Risk Avoidance
C. Risk Mitigation
D. Risk Transference
Answer: D
Rationale: Risk Transference involves shifting the financial consequences of a risk to a third party, such as an
insurance company. This is an important clinical concept because selecting the correct answer (D) requires
understanding both the pathophysiology and the practical nursing implications. Recognizing this principle
allows the nurse to prioritize care, anticipate complications, and provide accurate patient education.
Exam (Elaborations) • Actual Questions & Rationales Page 3