WESTERN GOVERNORS UNIVERSITY
D322 D430 - FUNDAMENTALS OF
INFORMATION SECURITY
QUESTIONS AND CORRECT ANSWERS
(VERIFIED ANSWERS) PLUS
RATIONALES 2026 Q&A | INSTANT
DOWNLOAD PDF
Core Domains
• Foundational Security Principles and Concepts
• Risk Management and Governance
• Cryptography and Public Key Infrastructure (PKI)
• Network Security and Architecture
• Access Control and Identity Management
• Security Operations and Incident Response
• Business Continuity and Disaster Recovery Planning
• Legal, Regulatory, and Compliance Frameworks
• Physical Security and Environmental Controls
• Ethics and Professional Security Standards
Introduction
This comprehensive assessment is designed to rigorously evaluate a
candidate's mastery of the core concepts and practical applications central
to the Fundamentals of Information Security. The examination measures
foundational theory, applied professional knowledge, and the ability to
,navigate complex regulatory and ethical landscapes. Through a
combination of direct multiple-choice questions and scenario-based
inquiries, candidates will demonstrate their capacity for critical thinking
and decision-making in real-world security contexts. Success on this exam
reflects a robust understanding of how to identify, analyze, and mitigate
information security risks while ensuring organizational resilience and
compliance.
SECTION ONE: QUESTIONS 1 – 100
1. Which of the following is the PRIMARY goal of the "CIA" triad in
information security?
A. To provide a framework for legal compliance and auditing.
B. To ensure data is readily available to all users at all times.
C. To ensure the confidentiality, integrity, and availability of information
assets.
D. To define the roles and responsibilities of security personnel.
C. To ensure the confidentiality, integrity, and availability of
information assets.
RATIONALE: The CIA triad (Confidentiality, Integrity, Availability) is
the cornerstone model for information security policy. Confidentiality
ensures that data is accessible only to authorized users; Integrity
ensures that data is accurate and has not been tampered with; and
Availability ensures that systems and data are accessible when needed.
The other options describe elements that support the CIA triad but are
not its primary, overarching goal.
2. An organization is developing a new mobile application that will
process sensitive customer data. Which of the following security
principles dictates that the application should be designed with
security controls integrated from the very beginning of the
development lifecycle?
,A. Security through obscurity
B. Separation of duties
C. Defense in depth
D. Security by design
D. Security by design
RATIONALE: Security by design is the principle that security should
be an integral part of the system's architecture and development
process from the outset. This is a proactive approach to mitigating
vulnerabilities before they are introduced. Security through obscurity
(A) is a weak and disfavored principle. Separation of duties (B) is an
administrative control for preventing fraud. Defense in depth (C) is a
strategy of using multiple layers of security, which is related but not the
specific principle of building security into the design phase.
3. A security administrator is tasked with mitigating the risk of a
data breach resulting from a lost or stolen company laptop. Which
of the following controls would be MOST effective in protecting the
data on the hard drive?
A. Implementing a strong password policy for user logins.
B. Installing a biometric fingerprint reader on the laptop.
C. Encrypting the entire hard drive using full-disk encryption.
D. Enabling a firewall on the laptop to block unauthorized inbound
connections.
C. Encrypting the entire hard drive using full-disk encryption.
RATIONALE: Full-disk encryption (FDE) ensures that data is
unreadable without the proper decryption key, even if the physical
drive is removed and accessed via another system. While strong
passwords and biometrics (A & B) protect against unauthorized login on
the original system, they do not protect the raw data if the drive is
accessed externally. A firewall (D) protects the system from network-
based attacks, not physical data theft.
, 4. Which of the following attack vectors exploits a user's trust in a
legitimate-looking email or website to steal sensitive credentials?
A. Phishing
B. Man-in-the-middle
C. Malware
D. Denial of Service (DoS)
A. Phishing
RATIONALE: Phishing is a social engineering attack that uses
deceptive emails or websites to trick users into revealing sensitive
information like usernames, passwords, or credit card details. A man-in-
the-middle attack (B) involves intercepting communication between two
parties. Malware (C) is malicious software. A Denial of Service (DoS)
attack (D) aims to make a system or network unavailable to its users.
5. In the context of risk management, what is the term for a strategy
that involves accepting the potential loss and taking no action to
mitigate the risk?
A. Risk avoidance
B. Risk mitigation
C. Risk transfer
D. Risk acceptance
D. Risk acceptance
RATIONALE: Risk acceptance is a deliberate decision to
acknowledge a risk and its potential impact without implementing
specific controls. This is often done when the cost of mitigation exceeds
the potential loss or when the risk falls within the organization's risk
tolerance. Risk avoidance (A) is the decision to eliminate the activity
causing the risk. Risk mitigation (B) involves implementing controls to
reduce the risk. Risk transfer (C) involves shifting the financial burden of
a risk to another party (e.g., insurance).
D322 D430 - FUNDAMENTALS OF
INFORMATION SECURITY
QUESTIONS AND CORRECT ANSWERS
(VERIFIED ANSWERS) PLUS
RATIONALES 2026 Q&A | INSTANT
DOWNLOAD PDF
Core Domains
• Foundational Security Principles and Concepts
• Risk Management and Governance
• Cryptography and Public Key Infrastructure (PKI)
• Network Security and Architecture
• Access Control and Identity Management
• Security Operations and Incident Response
• Business Continuity and Disaster Recovery Planning
• Legal, Regulatory, and Compliance Frameworks
• Physical Security and Environmental Controls
• Ethics and Professional Security Standards
Introduction
This comprehensive assessment is designed to rigorously evaluate a
candidate's mastery of the core concepts and practical applications central
to the Fundamentals of Information Security. The examination measures
foundational theory, applied professional knowledge, and the ability to
,navigate complex regulatory and ethical landscapes. Through a
combination of direct multiple-choice questions and scenario-based
inquiries, candidates will demonstrate their capacity for critical thinking
and decision-making in real-world security contexts. Success on this exam
reflects a robust understanding of how to identify, analyze, and mitigate
information security risks while ensuring organizational resilience and
compliance.
SECTION ONE: QUESTIONS 1 – 100
1. Which of the following is the PRIMARY goal of the "CIA" triad in
information security?
A. To provide a framework for legal compliance and auditing.
B. To ensure data is readily available to all users at all times.
C. To ensure the confidentiality, integrity, and availability of information
assets.
D. To define the roles and responsibilities of security personnel.
C. To ensure the confidentiality, integrity, and availability of
information assets.
RATIONALE: The CIA triad (Confidentiality, Integrity, Availability) is
the cornerstone model for information security policy. Confidentiality
ensures that data is accessible only to authorized users; Integrity
ensures that data is accurate and has not been tampered with; and
Availability ensures that systems and data are accessible when needed.
The other options describe elements that support the CIA triad but are
not its primary, overarching goal.
2. An organization is developing a new mobile application that will
process sensitive customer data. Which of the following security
principles dictates that the application should be designed with
security controls integrated from the very beginning of the
development lifecycle?
,A. Security through obscurity
B. Separation of duties
C. Defense in depth
D. Security by design
D. Security by design
RATIONALE: Security by design is the principle that security should
be an integral part of the system's architecture and development
process from the outset. This is a proactive approach to mitigating
vulnerabilities before they are introduced. Security through obscurity
(A) is a weak and disfavored principle. Separation of duties (B) is an
administrative control for preventing fraud. Defense in depth (C) is a
strategy of using multiple layers of security, which is related but not the
specific principle of building security into the design phase.
3. A security administrator is tasked with mitigating the risk of a
data breach resulting from a lost or stolen company laptop. Which
of the following controls would be MOST effective in protecting the
data on the hard drive?
A. Implementing a strong password policy for user logins.
B. Installing a biometric fingerprint reader on the laptop.
C. Encrypting the entire hard drive using full-disk encryption.
D. Enabling a firewall on the laptop to block unauthorized inbound
connections.
C. Encrypting the entire hard drive using full-disk encryption.
RATIONALE: Full-disk encryption (FDE) ensures that data is
unreadable without the proper decryption key, even if the physical
drive is removed and accessed via another system. While strong
passwords and biometrics (A & B) protect against unauthorized login on
the original system, they do not protect the raw data if the drive is
accessed externally. A firewall (D) protects the system from network-
based attacks, not physical data theft.
, 4. Which of the following attack vectors exploits a user's trust in a
legitimate-looking email or website to steal sensitive credentials?
A. Phishing
B. Man-in-the-middle
C. Malware
D. Denial of Service (DoS)
A. Phishing
RATIONALE: Phishing is a social engineering attack that uses
deceptive emails or websites to trick users into revealing sensitive
information like usernames, passwords, or credit card details. A man-in-
the-middle attack (B) involves intercepting communication between two
parties. Malware (C) is malicious software. A Denial of Service (DoS)
attack (D) aims to make a system or network unavailable to its users.
5. In the context of risk management, what is the term for a strategy
that involves accepting the potential loss and taking no action to
mitigate the risk?
A. Risk avoidance
B. Risk mitigation
C. Risk transfer
D. Risk acceptance
D. Risk acceptance
RATIONALE: Risk acceptance is a deliberate decision to
acknowledge a risk and its potential impact without implementing
specific controls. This is often done when the cost of mitigation exceeds
the potential loss or when the risk falls within the organization's risk
tolerance. Risk avoidance (A) is the decision to eliminate the activity
causing the risk. Risk mitigation (B) involves implementing controls to
reduce the risk. Risk transfer (C) involves shifting the financial burden of
a risk to another party (e.g., insurance).