WGU D414 CYBER OPERATIONS FUNDAMENTALS
OA VERSION 2: QUESTIONS AND CORRECT
ANSWERS (VERIFIED ANSWERS) PLUS RATIONALES
2026 Q&A | INSTANT DOWNLOAD PDF
Core Domains:
Security Concepts (CIA triad, risk, vulnerabilities, access control models, CVSS)
Security Monitoring (Network security, IDS/IPS, SIEM, SOAR, data visibility, 5-tuple)
Host-Based Analysis (Windows/Linux forensics, malware analysis, endpoint security, EDR)
Network Intrusion Analysis (Attack types, protocol anomalies, IDS/IPS)
Incident Response and Security Policies (NIST SP 800-61, IR roles, playbooks)
Endpoint and Cloud Security (Agent vs. agentless, container and cloud security)
Threat Intelligence and Hunting (Attack frameworks like MITRE ATT&CK, IoC vs. IoA)
Cybersecurity Tools (Wireshark, tcpdump, NetFlow, Snort, YARA, Sysinternals)
This comprehensive Objective Assessment guide is designed to prepare students for the WGU
D414 Cyber Operations Fundamentals exam. The examination evaluates the knowledge and
skills related to security concepts, security monitoring, host-based analysis, network intrusion
analysis, and security policies and procedures, as defined in the Cisco CCNA Cybersecurity
(200-201 CCNACBR v1.2) exam blueprint . Questions are structured to assess both theoretical
understanding and practical application in a Security Operations Center (SOC) environment.
Each item includes a verified correct answer accompanied by a detailed rationale to reinforce
learning and support exam preparation for the 2026 updated curriculum .
SECTION ONE: QUESTIONS 1 – 150
Question 1
In the CIA triad, what does the principle of "Integrity" ensure?
A. Data is available when needed
B. Data is accurate and trustworthy and has not been altered by unauthorized entities
C. Data is confidential and only accessible by authorized users
D. Data is backed up regularly to prevent loss
B. Data is accurate and trustworthy and has not been altered by unauthorized entities
RATIONALE: The CIA triad consists of Confidentiality, Integrity, and Availability.
Integrity ensures that data is accurate, trustworthy, and has not been altered or tampered with by
,unauthorized entities. It is often ensured through hashing and digital signatures. Confidentiality
ensures data is accessible only to authorized users, and Availability ensures data is accessible
when needed.
Question 2
A SOC analyst is investigating a potential breach and needs to isolate a compromised host from a
large dataset of logs. Which approach is most effective for this task?
A. Analyzing the packet payloads to identify malware signatures
B. Interpreting the 5-tuple (source IP, destination IP, source port, destination port, protocol) to
track a session
C. Using the hostname and username from the logs
D. Analyzing the time stamps of all log entries
B. Interpreting the 5-tuple (source IP, destination IP, source port, destination port, protocol)
to track a session
RATIONALE: The 5-tuple approach is a method of isolating a compromised host in a
grouped set of logs by identifying the unique combination of source IP, destination IP, source
port, destination port, and protocol that defines a specific session. This helps in pinpointing the
exact traffic flow associated with a suspicious host .
Question 3
What is the primary difference between a Vulnerability and an Exploit?
A. A vulnerability is a weakness in a system, while an exploit is the code or technique used to
take advantage of that weakness
B. A vulnerability is a type of malware, while an exploit is a security patch
C. A vulnerability is a type of attack, while an exploit is the target of the attack
D. Both terms are synonymous and refer to any potential threat
A. A vulnerability is a weakness in a system, while an exploit is the code or technique used
to take advantage of that weakness
RATIONALE: In security concepts, a vulnerability is a flaw or weakness in a system,
application, or network that could be exploited. An exploit is a specific piece of code, technique,
or method that takes advantage of a vulnerability to cause unintended consequences or gain
unauthorized access . Understanding this distinction is fundamental to risk assessment and
security operations.
Question 4
,A security analyst observes a sequence of failed login attempts followed by a successful login
from a new geographic location. What is the best initial action?
A. Immediately block the source IP address
B. Escalate to the incident response team as a potential account compromise
C. Ignore the alert as false positive
D. Reset the user's password immediately
B. Escalate to the incident response team as a potential account compromise
RATIONALE: This pattern indicates a potential "brute force" attack followed by a
successful login from an unusual location, suggesting an account compromise. While blocking
the IP might be part of the response, escalation to the incident response team is the best initial
action to trigger a formal investigation, validate the activity, and determine the appropriate
containment and remediation steps.
Question 5
Which of the following is the best definition of "Rule-based detection" as used in security
monitoring?
A. Using artificial intelligence and machine learning to identify unusual behavior
B. Comparing network traffic against a known baseline of normal behavior to detect anomalies
C. Using a set of predefined conditions or signatures to match known threats
D. Implementing honeypots to capture attacker methodologies
C. Using a set of predefined conditions or signatures to match known threats
RATIONALE: Rule-based detection, which is often signature-based, compares network
traffic, log entries, or other data against a set of predefined rules or patterns to identify known
threats (e.g., an IDS rule for a specific exploit). In contrast, behavioral or statistical detection
establishes a baseline and identifies deviations from that baseline, which can help detect zero-day
or novel threats .
Question 6
In incident response, what is the primary goal of the "Containment" phase?
A. To eliminate the root cause of the incident
B. To identify the attack vectors used by the threat actor
C. To limit the damage of an incident and prevent it from spreading
D. To return affected systems to their normal state
C. To limit the damage of an incident and prevent it from spreading
, RATIONALE: According to the NIST SP 800-61 framework, containment is a critical step
after detection and analysis. Its primary goal is to limit the scope and impact of the incident to
prevent further damage while preserving evidence for later analysis . Eradication removes the
root cause, and recovery restores systems to normal operation.
Question 7
A system administrator finds a suspicious process running on a Windows server. Which
Sysinternals tool is most appropriate for analyzing the process's parent-child relationship and its
loaded DLLs?
A. Process Monitor (ProcMon)
B. Process Explorer
C. Autoruns
D. TCPView
B. Process Explorer
RATIONALE: Process Explorer is a powerful Sysinternals tool that provides detailed
information about running processes on a Windows system. It can be used to view the process
tree (parent-child relationships), identify which DLLs are loaded by a process, and inspect other
properties like handles and open files . This makes it ideal for analyzing suspicious processes.
ProcMon monitors real-time file system and registry activity, Autoruns analyzes startup entries,
and TCPView shows active network connections.
Question 8
Which of the following access control models restricts access based on a user's role within an
organization?
A. Discretionary Access Control (DAC)
B. Mandatory Access Control (MAC)
C. Role-Based Access Control (RBAC)
D. Rule-Based Access Control
C. Role-Based Access Control (RBAC)
RATIONALE: RBAC (Role-Based Access Control) is a non-discretionary access control
model where access to resources is determined by the roles (e.g., Manager, Administrator,
Employee) a user has within an organization . This is a common and efficient model for
managing access in large organizations. DAC allows the owner to set permissions, MAC is a
system-enforced model based on security labels, and Rule-Based Access Control uses a set of
rules to define access.
OA VERSION 2: QUESTIONS AND CORRECT
ANSWERS (VERIFIED ANSWERS) PLUS RATIONALES
2026 Q&A | INSTANT DOWNLOAD PDF
Core Domains:
Security Concepts (CIA triad, risk, vulnerabilities, access control models, CVSS)
Security Monitoring (Network security, IDS/IPS, SIEM, SOAR, data visibility, 5-tuple)
Host-Based Analysis (Windows/Linux forensics, malware analysis, endpoint security, EDR)
Network Intrusion Analysis (Attack types, protocol anomalies, IDS/IPS)
Incident Response and Security Policies (NIST SP 800-61, IR roles, playbooks)
Endpoint and Cloud Security (Agent vs. agentless, container and cloud security)
Threat Intelligence and Hunting (Attack frameworks like MITRE ATT&CK, IoC vs. IoA)
Cybersecurity Tools (Wireshark, tcpdump, NetFlow, Snort, YARA, Sysinternals)
This comprehensive Objective Assessment guide is designed to prepare students for the WGU
D414 Cyber Operations Fundamentals exam. The examination evaluates the knowledge and
skills related to security concepts, security monitoring, host-based analysis, network intrusion
analysis, and security policies and procedures, as defined in the Cisco CCNA Cybersecurity
(200-201 CCNACBR v1.2) exam blueprint . Questions are structured to assess both theoretical
understanding and practical application in a Security Operations Center (SOC) environment.
Each item includes a verified correct answer accompanied by a detailed rationale to reinforce
learning and support exam preparation for the 2026 updated curriculum .
SECTION ONE: QUESTIONS 1 – 150
Question 1
In the CIA triad, what does the principle of "Integrity" ensure?
A. Data is available when needed
B. Data is accurate and trustworthy and has not been altered by unauthorized entities
C. Data is confidential and only accessible by authorized users
D. Data is backed up regularly to prevent loss
B. Data is accurate and trustworthy and has not been altered by unauthorized entities
RATIONALE: The CIA triad consists of Confidentiality, Integrity, and Availability.
Integrity ensures that data is accurate, trustworthy, and has not been altered or tampered with by
,unauthorized entities. It is often ensured through hashing and digital signatures. Confidentiality
ensures data is accessible only to authorized users, and Availability ensures data is accessible
when needed.
Question 2
A SOC analyst is investigating a potential breach and needs to isolate a compromised host from a
large dataset of logs. Which approach is most effective for this task?
A. Analyzing the packet payloads to identify malware signatures
B. Interpreting the 5-tuple (source IP, destination IP, source port, destination port, protocol) to
track a session
C. Using the hostname and username from the logs
D. Analyzing the time stamps of all log entries
B. Interpreting the 5-tuple (source IP, destination IP, source port, destination port, protocol)
to track a session
RATIONALE: The 5-tuple approach is a method of isolating a compromised host in a
grouped set of logs by identifying the unique combination of source IP, destination IP, source
port, destination port, and protocol that defines a specific session. This helps in pinpointing the
exact traffic flow associated with a suspicious host .
Question 3
What is the primary difference between a Vulnerability and an Exploit?
A. A vulnerability is a weakness in a system, while an exploit is the code or technique used to
take advantage of that weakness
B. A vulnerability is a type of malware, while an exploit is a security patch
C. A vulnerability is a type of attack, while an exploit is the target of the attack
D. Both terms are synonymous and refer to any potential threat
A. A vulnerability is a weakness in a system, while an exploit is the code or technique used
to take advantage of that weakness
RATIONALE: In security concepts, a vulnerability is a flaw or weakness in a system,
application, or network that could be exploited. An exploit is a specific piece of code, technique,
or method that takes advantage of a vulnerability to cause unintended consequences or gain
unauthorized access . Understanding this distinction is fundamental to risk assessment and
security operations.
Question 4
,A security analyst observes a sequence of failed login attempts followed by a successful login
from a new geographic location. What is the best initial action?
A. Immediately block the source IP address
B. Escalate to the incident response team as a potential account compromise
C. Ignore the alert as false positive
D. Reset the user's password immediately
B. Escalate to the incident response team as a potential account compromise
RATIONALE: This pattern indicates a potential "brute force" attack followed by a
successful login from an unusual location, suggesting an account compromise. While blocking
the IP might be part of the response, escalation to the incident response team is the best initial
action to trigger a formal investigation, validate the activity, and determine the appropriate
containment and remediation steps.
Question 5
Which of the following is the best definition of "Rule-based detection" as used in security
monitoring?
A. Using artificial intelligence and machine learning to identify unusual behavior
B. Comparing network traffic against a known baseline of normal behavior to detect anomalies
C. Using a set of predefined conditions or signatures to match known threats
D. Implementing honeypots to capture attacker methodologies
C. Using a set of predefined conditions or signatures to match known threats
RATIONALE: Rule-based detection, which is often signature-based, compares network
traffic, log entries, or other data against a set of predefined rules or patterns to identify known
threats (e.g., an IDS rule for a specific exploit). In contrast, behavioral or statistical detection
establishes a baseline and identifies deviations from that baseline, which can help detect zero-day
or novel threats .
Question 6
In incident response, what is the primary goal of the "Containment" phase?
A. To eliminate the root cause of the incident
B. To identify the attack vectors used by the threat actor
C. To limit the damage of an incident and prevent it from spreading
D. To return affected systems to their normal state
C. To limit the damage of an incident and prevent it from spreading
, RATIONALE: According to the NIST SP 800-61 framework, containment is a critical step
after detection and analysis. Its primary goal is to limit the scope and impact of the incident to
prevent further damage while preserving evidence for later analysis . Eradication removes the
root cause, and recovery restores systems to normal operation.
Question 7
A system administrator finds a suspicious process running on a Windows server. Which
Sysinternals tool is most appropriate for analyzing the process's parent-child relationship and its
loaded DLLs?
A. Process Monitor (ProcMon)
B. Process Explorer
C. Autoruns
D. TCPView
B. Process Explorer
RATIONALE: Process Explorer is a powerful Sysinternals tool that provides detailed
information about running processes on a Windows system. It can be used to view the process
tree (parent-child relationships), identify which DLLs are loaded by a process, and inspect other
properties like handles and open files . This makes it ideal for analyzing suspicious processes.
ProcMon monitors real-time file system and registry activity, Autoruns analyzes startup entries,
and TCPView shows active network connections.
Question 8
Which of the following access control models restricts access based on a user's role within an
organization?
A. Discretionary Access Control (DAC)
B. Mandatory Access Control (MAC)
C. Role-Based Access Control (RBAC)
D. Rule-Based Access Control
C. Role-Based Access Control (RBAC)
RATIONALE: RBAC (Role-Based Access Control) is a non-discretionary access control
model where access to resources is determined by the roles (e.g., Manager, Administrator,
Employee) a user has within an organization . This is a common and efficient model for
managing access in large organizations. DAC allows the owner to set permissions, MAC is a
system-enforced model based on security labels, and Rule-Based Access Control uses a set of
rules to define access.