WGU D414 Cyber Operations
Fundamentals Full Exam WITH
VERIFIED ANSWERS And rationale
updated 2026
Domain 1: Security Concepts (Questions 1–20)
Question 1: A payroll database is altered by an unauthorized user, but the service
remains online and no evidence shows the data was disclosed. Which CIA objective is
primarily affected?
A) Confidentiality
B) Integrity
C) Availability
D) Non-repudiation
Rationale: Integrity protects the accuracy and trustworthiness of information against
unauthorized modification. Availability is not the primary issue because the database
remained accessible, and confidentiality concerns unauthorized disclosure. -1
Question 2: A DDoS campaign prevents customers from reaching an online service
for two hours. Which element of the CIA triad is most directly affected?
A) Confidentiality
B) Integrity
C) Availability
D) Authentication
Rationale: Denial-of-service activity primarily affects availability because legitimate
users cannot access the service. The attack does not necessarily involve data
disclosure (confidentiality) or modification (integrity). -1
Question 3: An organization implements a policy where an employee’s access rights
are limited to only the information and resources necessary for their specific job
functions. This is known as:
A) Implicit Deny
B) Least Privilege
,C) Separation of Duties
D) Job Rotation
Rationale: The principle of least privilege minimizes the attack surface by ensuring
users have the minimum level of access required to perform their duties. -4
Question 4: A security officer receives a report that an attacker intercepted and
possibly altered communication between two parties who believed they were directly
communicating with each other. What type of attack is this?
A) Denial of Service
B) Man-in-the-Middle (MITM)
C) Phishing
D) Replay Attack
Rationale: In a MITM attack, the attacker secretly relays and possibly alters the
communication between two parties who believe they are directly communicating
with each other. -4
Question 5: Which authentication factor category does a smart card represent?
A) Something you know
B) Something you have
C) Something you are
D) Something you do
Rationale: Authentication factors fall into three categories: something you know
(password, PIN), something you have (smart card, token, phone), and something you
are (biometrics). A smart card is a physical possession-based factor. -14
Question 6: What does hashing provide for data communication?
A) Data non-repudiation
B) Origin authentication
C) Data encryption
D) Data integrity
Rationale: Hashing provides data integrity by producing a fixed-length digest that
changes if the data is modified. It does not encrypt data or provide non-repudiation
on its own. -11
Question 7: An organization purchases cyber liability insurance. Which risk treatment
strategy is being used?
, A) Risk acceptance
B) Risk transference
C) Risk mitigation
D) Risk avoidance
Rationale: Insurance shifts the financial impact of a risk to another party, but the risk
itself remains. This is risk transference. -6
Question 8: A corporation hires a group of experienced cyber criminals to create a
prolonged and in-depth presence on the network of a competitor to steal or
sabotage sensitive data. Which type of attack does this scenario describe?
A) DDoS
B) Ransomware
C) Man-in-the-middle
D) APT
Rationale: An Advanced Persistent Threat (APT) involves a prolonged, stealthy
presence on a network to steal or sabotage data, often by well-funded and skilled
actors. -11
Question 9: An organization decides to cease using an outdated software system
that cannot be secured. This is an example of:
A) Risk acceptance
B) Risk transference
C) Risk mitigation
D) Risk avoidance
Rationale: Risk avoidance eliminates the risk by discontinuing the activity that
creates it. Ceasing use of the vulnerable system avoids the risk entirely. -6
Question 10: What is the primary purpose of Multi-Factor Authentication (MFA)?
A) To eliminate the need for passwords
B) To require multiple forms of verification from different categories
C) To encrypt all user data
D) To prevent all types of cyber attacks
Rationale: MFA requires authentication factors from at least two of three categories:
something you know, something you have, and something you are. This significantly
reduces the risk of unauthorized access even if one factor is compromised. -14
Question 11: A company experiences a data breach where customer credit card
numbers are stolen. Which element of the CIA triad has been primarily violated?
Fundamentals Full Exam WITH
VERIFIED ANSWERS And rationale
updated 2026
Domain 1: Security Concepts (Questions 1–20)
Question 1: A payroll database is altered by an unauthorized user, but the service
remains online and no evidence shows the data was disclosed. Which CIA objective is
primarily affected?
A) Confidentiality
B) Integrity
C) Availability
D) Non-repudiation
Rationale: Integrity protects the accuracy and trustworthiness of information against
unauthorized modification. Availability is not the primary issue because the database
remained accessible, and confidentiality concerns unauthorized disclosure. -1
Question 2: A DDoS campaign prevents customers from reaching an online service
for two hours. Which element of the CIA triad is most directly affected?
A) Confidentiality
B) Integrity
C) Availability
D) Authentication
Rationale: Denial-of-service activity primarily affects availability because legitimate
users cannot access the service. The attack does not necessarily involve data
disclosure (confidentiality) or modification (integrity). -1
Question 3: An organization implements a policy where an employee’s access rights
are limited to only the information and resources necessary for their specific job
functions. This is known as:
A) Implicit Deny
B) Least Privilege
,C) Separation of Duties
D) Job Rotation
Rationale: The principle of least privilege minimizes the attack surface by ensuring
users have the minimum level of access required to perform their duties. -4
Question 4: A security officer receives a report that an attacker intercepted and
possibly altered communication between two parties who believed they were directly
communicating with each other. What type of attack is this?
A) Denial of Service
B) Man-in-the-Middle (MITM)
C) Phishing
D) Replay Attack
Rationale: In a MITM attack, the attacker secretly relays and possibly alters the
communication between two parties who believe they are directly communicating
with each other. -4
Question 5: Which authentication factor category does a smart card represent?
A) Something you know
B) Something you have
C) Something you are
D) Something you do
Rationale: Authentication factors fall into three categories: something you know
(password, PIN), something you have (smart card, token, phone), and something you
are (biometrics). A smart card is a physical possession-based factor. -14
Question 6: What does hashing provide for data communication?
A) Data non-repudiation
B) Origin authentication
C) Data encryption
D) Data integrity
Rationale: Hashing provides data integrity by producing a fixed-length digest that
changes if the data is modified. It does not encrypt data or provide non-repudiation
on its own. -11
Question 7: An organization purchases cyber liability insurance. Which risk treatment
strategy is being used?
, A) Risk acceptance
B) Risk transference
C) Risk mitigation
D) Risk avoidance
Rationale: Insurance shifts the financial impact of a risk to another party, but the risk
itself remains. This is risk transference. -6
Question 8: A corporation hires a group of experienced cyber criminals to create a
prolonged and in-depth presence on the network of a competitor to steal or
sabotage sensitive data. Which type of attack does this scenario describe?
A) DDoS
B) Ransomware
C) Man-in-the-middle
D) APT
Rationale: An Advanced Persistent Threat (APT) involves a prolonged, stealthy
presence on a network to steal or sabotage data, often by well-funded and skilled
actors. -11
Question 9: An organization decides to cease using an outdated software system
that cannot be secured. This is an example of:
A) Risk acceptance
B) Risk transference
C) Risk mitigation
D) Risk avoidance
Rationale: Risk avoidance eliminates the risk by discontinuing the activity that
creates it. Ceasing use of the vulnerable system avoids the risk entirely. -6
Question 10: What is the primary purpose of Multi-Factor Authentication (MFA)?
A) To eliminate the need for passwords
B) To require multiple forms of verification from different categories
C) To encrypt all user data
D) To prevent all types of cyber attacks
Rationale: MFA requires authentication factors from at least two of three categories:
something you know, something you have, and something you are. This significantly
reduces the risk of unauthorized access even if one factor is compromised. -14
Question 11: A company experiences a data breach where customer credit card
numbers are stolen. Which element of the CIA triad has been primarily violated?