WGU C182 TESTED QUESTIONS AND
SOLUTIONS FINAL PAPER
◉ Host Name
Answer: Identifies the organization that is responsible for the
information on the page or provides the server space where the
information is stored
◉ TLD(Top Level Domain) Name
Answer: Always ends with a period and a three or two letter
extension which signifies the type of organization or country
associated with the page
◉ Resource/Filename ID
Answer: Indicates the name of the file you are accessing, or the
location of the document on the server
◉ CIA
Answer: Confidentiality, Integrity, Availability
◉ Confidentiality
Answer: Requires that data bet kept secure so that they are not
accidentally provided or obtained by unauthorized users
,◉ Integrity
Answer: Requires that data is correct
◉ Availability
Answer: Requires that information is available when needed
◉ Data Integrity Efforts
Answer: 1st - Must include a component that ensures the accuracy
of the collected data
2nd - Must be entered into the system accurately
3rd - Data modification must be tracked
◉ Strategic Risk Analysis
Answer: 1. Identify the organization's information assets
2. Identify vulnerabilities of each asset
3. Determine threats
4. Prioritizing risks
5. Develop and enact policies that will reduce threats
◉ Information Security Classifications
Answer: Public - available through public sources; includes names
and addresses
, Sensitive - not considered a threat to a person's privacy if others
learn of it; include email addresses
Private - information that could be a threat if disclosed to others;
includes social security and credit card numbers
Confidential - information that an organization will keep secret;
includes patentable information and business plans
◉ Defense in Depth
Answer: Protecting every layer that surrounds data
◉ Phishing
Answer: Emails to people to redirect them to a website to perform
some operation but the website is a fake and just takes the
information
◉ SQL Injection
Answer: An attacker issues a SQL command to a web server as
part of the URL or as input to a form on a company's website; web
server might pass the command onto the database which then
allows potentially anything to be done to the database
◉ Buffer Overflow
SOLUTIONS FINAL PAPER
◉ Host Name
Answer: Identifies the organization that is responsible for the
information on the page or provides the server space where the
information is stored
◉ TLD(Top Level Domain) Name
Answer: Always ends with a period and a three or two letter
extension which signifies the type of organization or country
associated with the page
◉ Resource/Filename ID
Answer: Indicates the name of the file you are accessing, or the
location of the document on the server
◉ CIA
Answer: Confidentiality, Integrity, Availability
◉ Confidentiality
Answer: Requires that data bet kept secure so that they are not
accidentally provided or obtained by unauthorized users
,◉ Integrity
Answer: Requires that data is correct
◉ Availability
Answer: Requires that information is available when needed
◉ Data Integrity Efforts
Answer: 1st - Must include a component that ensures the accuracy
of the collected data
2nd - Must be entered into the system accurately
3rd - Data modification must be tracked
◉ Strategic Risk Analysis
Answer: 1. Identify the organization's information assets
2. Identify vulnerabilities of each asset
3. Determine threats
4. Prioritizing risks
5. Develop and enact policies that will reduce threats
◉ Information Security Classifications
Answer: Public - available through public sources; includes names
and addresses
, Sensitive - not considered a threat to a person's privacy if others
learn of it; include email addresses
Private - information that could be a threat if disclosed to others;
includes social security and credit card numbers
Confidential - information that an organization will keep secret;
includes patentable information and business plans
◉ Defense in Depth
Answer: Protecting every layer that surrounds data
◉ Phishing
Answer: Emails to people to redirect them to a website to perform
some operation but the website is a fake and just takes the
information
◉ SQL Injection
Answer: An attacker issues a SQL command to a web server as
part of the URL or as input to a form on a company's website; web
server might pass the command onto the database which then
allows potentially anything to be done to the database
◉ Buffer Overflow