• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 58 pages
Exam (elaborations)

WGU D830 YCN1 TASK 2: SECURITY ANALYSIS OF AN ORGANIZATION'S SYSTEMS QUESTIONS AND ANSWERS ALREADY GRADED A+| 100% VERIFIED SOLUTIONS

Document preview thumbnail
Preview 4 out of 58 pages

WGU D830 YCN1 TASK 2: SECURITY ANALYSIS OF AN ORGANIZATION'S SYSTEMS QUESTIONS AND ANSWERS ALREADY GRADED A+| 100% VERIFIED SOLUTIONS

Content preview

WGU D830 YCN1 TASK 2: SECURITY ANALYSIS OF AN ORGANIZATION'S SYSTEMS QUESTIONS AND
ANSWERS ALREADY GRADED A+| 100% VERIFIED SOLUTIONS

Core Domains

Risk Management Frameworks and Methodologies (NIST, ISO, COBIT)
Security Controls and Countermeasures (Technical, Administrative, Physical)
Network Security Architecture and Perimeter Defense
Access Control Models and Identity Management
Vulnerability Assessment and Penetration Testing
Incident Response, Disaster Recovery, and Business Continuity
Security Governance, Policy, and Compliance (HIPAA, GDPR, PCI DSS)
Cryptography and Data Protection
Security Operations Center (SOC) and Threat Intelligence
Ethical, Legal, and Professional Standards in Cybersecurity

Introduction

This comprehensive examination is designed to assess the knowledge and analytical skills required for the WGU
D830 YCN1 Task 2: Security Analysis of an Organization's Systems. It evaluates competency in identifying security
vulnerabilities, analyzing risk, and recommending appropriate controls to protect organizational assets. The
assessment consists of multiple-choice questions and scenario-based items that require critical thinking,
application of security frameworks (NIST, ISO), and decision-making in real-world security contexts. Emphasis is
placed on the integration of technical, administrative, and physical controls, compliance with regulatory standards,

,and the development of incident response and business continuity strategies. This examination prepares
candidates to perform comprehensive security analyses and contribute to the protection of modern organizational
information systems.

SECTION ONE: QUESTIONS 1-100

1. An organization is implementing a defense-in-depth strategy. Which of the following best describes this
security approach?

A. A single, comprehensive security solution that protects all assets
B. Multiple layers of security controls placed throughout an information system
C. A perimeter-based security model that focuses on external threats
D. A security approach that relies solely on encryption technologies

🟢 Correct answer: B
🔴 RATIONALE: Defense-in-depth is a layered security strategy that uses multiple, overlapping controls to
protect information assets. If one layer fails, additional layers provide continued protection, reducing the overall
risk to the organization.




2. During a security risk assessment, a consultant identifies that employees frequently leave their
workstations unlocked when away from their desks. This is an example of which type of vulnerability?

A. Technical vulnerability
B. Physical vulnerability

,C. Administrative vulnerability
D. Operational vulnerability

🟢 Correct answer: C
🔴 RATIONALE: Unlocked workstations represent an administrative vulnerability because it relates to policy,
procedure, and human behavior. While it has technical implications, the root cause is a failure in administrative
controls and security awareness training.




3. An organization's security policy requires that all sensitive data be encrypted both at rest and in transit.
Which standard is the organization most likely complying with?

A. ISO 27001
B. HIPAA Security Rule
C. NIST SP 800-53
D. All of the above

🟢 Correct answer: D
🔴 RATIONALE: Encryption of sensitive data is a common requirement in multiple security frameworks and
regulations, including ISO 27001, HIPAA, and NIST SP 800-53. The specific requirement may vary, but all
emphasize the protection of sensitive data through encryption.

, 4. A security analyst is conducting a vulnerability scan on the organization's network. The scan identifies
several systems with missing security patches. Which step should the analyst take first?

A. Immediately apply all missing patches
B. Evaluate the risk associated with each vulnerability
C. Report the findings to the Chief Information Officer
D. Disconnect the affected systems from the network

🟢 Correct answer: B
🔴 RATIONALE: Before taking action, the analyst should evaluate the risk associated with each identified
vulnerability. Not all missing patches pose the same level of risk; prioritization is necessary to address the most
critical vulnerabilities first based on the organization's risk appetite.




5. A database administrator discovers that a former employee's account is still active and has been used to
access sensitive customer information. Which security control should have prevented this situation?

A. Encryption
B. Firewall rules
C. Access control and account management
D. Intrusion detection system

🟢 Correct answer: C

Document information

Uploaded on
August 26, 2026
Number of pages
58
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$30.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
63
Followers
4
Items
5365
Last sold
8 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions