• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 30 pages
Exam (elaborations)

WGU D522 (WEN1) TASK 1 ACTUAL EXAM 2026/2027 | Incident Response & DNS Remediation | Python, GitLab, Device Inventory, Email & Helpdesk API | Pass Guaranteed - A+ Graded

Document preview thumbnail
Preview 3 out of 30 pages

Pass WGU D522 (WEN1) Task 1 on your first attempt with this complete 2026/2027 updated performance assessment guide. This A+ Graded resource covers all Task 1 requirements including incident response procedures, DNS remediation steps, Python scripting, GitLab repository setup, device inventory management, email configuration, and helpdesk API integration. The guide includes a complete evidence walkthrough, showing you exactly what to document, how to capture screenshots, and how to organize your submission for full marks. Each step is aligned with the latest WGU D522 (WEN1) rubric requirements for 2026/2027. Perfect for IT and cybersecurity students seeking a guaranteed pass on their performance assessment. With our Pass Guarantee, you can confidently complete your WGU D522 Task 1. Download your complete performance assessment guide instantly!

Content preview

WGU D522 (WEN1) TASK 1 - PERFORMANCE ASSESSMENT PREP Incident Response & DNS Remediation




WGU D522 (WEN1) Task 1 Performance
Assessment
Incident Response & DNS Remediation
Python • GitLab • Device Inventory • Email • Helpdesk API • Evidence

EXAM INSTRUCTIONS: This comprehensive 100-question examination covers all eight competency
domains of the WGU D522 (WEN1) Task 1 Performance Assessment. Questions are designed to test recall
of NIST SP 800-61 IR fundamentals, DNS architecture and attacks, Python scripting for security
automation, GitLab workflows, device inventory management, email analysis, Helpdesk API integration, and
evidence handling. Each question has ONE correct answer (A, B, C, or D). After each question, the correct
answer and a detailed rationale citing NIST principles, DNS concepts, Python logic, GitLab workflows, API
practices, and chain of custody standards are provided. Total exam length: 100 questions across 8
sections. Recommended completion time: 2.5 hours.



SECTION 1: Incident Response Fundamentals
NIST SP 800-61 IR Lifecycle, team roles, communication protocols, and incident classification.

Q1: Per NIST SP 800-61 Rev. 2, the incident response lifecycle consists of four phases. Which
sequence correctly represents the order of these phases?
A. Detection & Analysis → Preparation → Containment, Eradication & Recovery → Post-Incident Activity
B. Preparation → Detection & Analysis → Containment, Eradication & Recovery → Post-Incident Activity
[CORRECT]
C. Preparation → Containment → Detection → Recovery
D. Detection → Containment → Eradication → Recovery
Correct Answer: B
Rationale: NIST SP 800-61 Rev. 2 defines the four-phase IR lifecycle: (1) Preparation; (2) Detection & Analysis;
(3) Containment, Eradication & Recovery; (4) Post-Incident Activity. Option A reverses Preparation and
Detection - Preparation must come first because it establishes the IR capability. Options C and D omit
Post-Incident Activity (lessons learned) and split Containment/Eradication/Recovery improperly. WGU D522
Task 1 expects students to map incident handling steps to these four NIST phases.


Q2: During a confirmed ransomware outbreak affecting three file servers, the Incident Commander
assigns one team member to maintain a written timeline of every action taken, decision made, and
communication sent. What role is this team member performing?
A. Communications Lead
B. Scribe [CORRECT]
C. Forensic Analyst
D. Escalation Coordinator
Correct Answer: B
Rationale: The Scribe is responsible for documenting the incident timeline - actions, decisions, commands
executed, and timestamps. This contemporaneous record is critical for post-incident review, root cause analysis,
and chain of custody. The Communications Lead handles stakeholder notifications; the Forensic Analyst handles
evidence; the Escalation Coordinator routes issues upward. WGU D522 Task 1 rubric explicitly requires



WGU D522 Performance Assessment Preparation Page 1

,WGU D522 (WEN1) TASK 1 - PERFORMANCE ASSESSMENT PREP Incident Response & DNS Remediation




documented timeline entries for each remediation action.


Q3: An analyst detects unusual DNS traffic but is unsure whether the activity constitutes a true
incident. According to NIST SP 800-61, which IR lifecycle phase is currently active?
A. Preparation
B. Detection & Analysis [CORRECT]
C. Containment
D. Post-Incident Activity
Correct Answer: B
Rationale: Detection & Analysis includes the initial identification, triage, and validation of a potential incident
before formal containment is authorized. The analyst is still confirming whether the activity is malicious.
Preparation ends when the signal is observed; Containment begins only after the incident is confirmed and
isolation is authorized; Post-Incident Activity occurs after recovery. D522 Task 1 requires students to clearly
identify when this phase begins and ends.


Q4: Which of the following actions is a PREPARATION-phase activity under NIST SP 800-61?
A. Isolating an infected host from the network.
B. Building an IR contact list, training the IR team, and pre-staging toolkits. [CORRECT]
C. Writing the lessons-learned report.
D. Eradicating malware from the affected server.
Correct Answer: B
Rationale: Preparation activities include building contact lists, training team members, developing policies,
establishing communication methods, and pre-staging forensic toolkits. Option A is Containment; Option C is
Post-Incident Activity; Option D is Eradication. WGU D522 Task 1 rubric requires students to demonstrate
preparation through documented runbooks, asset inventory, and pre-staged Python tooling.


Q5: A responder wants to stop the spread of ransomware by disconnecting an infected
workstation from the network while leaving it powered on. This action is best classified as:
A. Eradication
B. Recovery
C. Short-term Containment [CORRECT]
D. Post-Incident Activity
Correct Answer: C
Rationale: Short-term containment is an immediate action to stop the bleeding - disconnecting the host, isolating
VLANs, or blocking an IP at the firewall - while preserving volatile evidence. Eradication removes the threat
(malware, accounts). Recovery restores service from clean backups and validates the system. Disconnecting
(rather than powering off) preserves RAM, which is critical for forensic analysis. D522 Task 1 requires
distinguishing short-term from long-term containment.


Q6: Which of the following BEST describes the difference between Containment and Eradication?
A. Containment removes malware; Eradication isolates the host.
B. Containment limits the incident's scope; Eradication removes the root cause and artifacts from the
environment. [CORRECT]
C. Containment restores systems from backup; Eradication disconnects them.



WGU D522 Performance Assessment Preparation Page 2

, WGU D522 (WEN1) TASK 1 - PERFORMANCE ASSESSMENT PREP Incident Response & DNS Remediation




D. There is no difference; both are interchangeable phases.
Correct Answer: B
Rationale: Containment limits the incident's scope and prevents further damage (e.g., network isolation).
Eradication removes the malware, malicious accounts, and persistence mechanisms after evidence is collected.
Option A reverses the definitions; Option C confuses Containment with Recovery; Option D is incorrect - the
distinction is fundamental and is a commonly confused concept pair called out in WGU D522 Task 1.


Q7: During Recovery phase, an analyst restores a DNS server from a known-good backup. Which
validation step MUST be performed before returning the server to production?
A. Notify the local news media.
B. Verify the restored system is free of malicious records, monitoring confirms expected behavior, and the
system is hardened against the original vector. [CORRECT]
C. Immediately reconnect it without testing to minimize downtime.
D. Wipe the server again before reconnecting.
Correct Answer: B
Rationale: Recovery requires validation: confirm the system is clean, patched/hardened, monitored for
re-infection, and behaves correctly before returning to production. Option A is unnecessary disclosure; Option C
skips critical validation and risks re-infection; Option D is wasteful and destroys the restored state. WGU D522
Task 1 explicitly requires DNS remediation validation - corrected records, propagation verification, and ongoing
monitoring.


Q8: In the Post-Incident Activity phase, which artifact provides the MOST value for improving
future response?
A. The original alert email.
B. The lessons-learned report with timeline analysis, root cause, and actionable recommendations.
[CORRECT]
C. The hardware inventory spreadsheet.
D. The helpdesk ticket closing notification.
Correct Answer: B
Rationale: The lessons-learned report captures the timeline, root cause analysis, what worked and what failed,
and actionable recommendations for improving detection, response, and prevention. This is the core deliverable
of Post-Incident Activity per NIST SP 800-61. The alert email and helpdesk ticket are operational artifacts. WGU
D522 Task 1 requires a written lessons-learned-style summary that ties DNS remediation back to prevention.


Q9: An Incident Commander is deciding whether to escalate a low-severity phishing ticket. Which
factor MOST strongly supports escalation to a major incident?
A. The phishing email was sent to 500+ employees and credentials were entered on a fake site.
[CORRECT]
B. The phishing email contained a minor spelling error.
C. The email came from a marketing vendor.
D. The helpdesk received two unrelated complaints the same day.
Correct Answer: A
Rationale: Mass distribution (500+ recipients) plus confirmed credential compromise transforms a low-severity
phishing ticket into a major incident requiring IR team activation, credential revocation, and active remediation.
Spelling errors, vendor origin, or unrelated complaints do not, by themselves, indicate scope expansion. WGU



WGU D522 Performance Assessment Preparation Page 3

Document information

Uploaded on
September 18, 2026
Number of pages
30
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$20.50

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NURSEEXAMITY
3.4
(108)
Sold
577
Followers
275
Items
6778
Last sold
2 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions