WGU D430 Fundamentals of
Information Security Questions &
Answers 2026/2027 Updated Exam
Edition with Rationales
Comprehensive Examination Question Bank • Concept Mapping
TOTAL QUESTIONS EXAM TOPICS RATIONALES
95 Questions 11 Modules 100% Verified
DOCUMENT OVERVIEW
This document contains 95 verified questions with correct answers and detailed rationales focused on
information security principles and practices. It covers critical areas such as confidentiality, integrity,
availability, and various security standards, making it suitable for exam preparation, course review, and
professional certification in the field of information security.
EXAM BLUEPRINT & TOPIC DISTRIBUTION
Systematic breakdown of subject domains and exam coverage.
Topic Module Scope & Core Focus Questions Share (%)
CIA Triad: Confidentiality, This topic covers the foundational principles of information
Integrity, and Availability security regarding the protection of data. 9 Qs 9.5%
This topic discusses various types of attacks that threaten
Attacks and Threats information security, including their definitions and impacts. 9 Qs 9.5%
This topic explores the risk management process, including
Risk Management Processes identification of assets and threats. 9 Qs 9.5%
This topic explains the principles and applications of
Cryptography Fundamentals cryptography in securing information. 9 Qs 9.5%
Authentication and Access This topic covers various methods and practices for
Control authenticating users and controlling access to information. 9 Qs 9.5%
Confidential • Student Study Edition • Practice & Review Guide Page 1 of 32
,STUDENT STUDY & MASTERY EDITION PRACTICE & REVIEW GUIDE
This topic addresses various regulatory and compliance
Compliance Standards standards relevant to information security. 9 Qs 9.5%
Incident Response and This topic details the steps and procedures involved in
Management effectively responding to security incidents. 9 Qs 9.5%
This topic discusses methods for protecting data at rest, in
Data Protection Techniques motion, and during use. 8 Qs 8.4%
This topic reviews the processes and strategies for
Operational Security maintaining security in operational environments. 8 Qs 8.4%
This topic covers aspects of privacy laws and guidelines that
Information Privacy protect personal information. 8 Qs 8.4%
This topic includes tools and techniques for monitoring and
Digital Forensics and Monitoring analyzing security incidents. 8 Qs 8.4%
Total Exam Coverage 11 Integrated Topic Modules 95 Qs 100.0%
Confidential • Student Study Edition • Practice & Review Guide Page 2 of 32
,STUDENT STUDY & MASTERY EDITION PRACTICE & REVIEW GUIDE
TOPIC 1: CIA TRIAD: CONFIDENTIALITY, INTEGRITY, AND AVAILABILITY
9 Questions • 9.5% of Exam • This topic covers the foundational principles of information security regarding the protection of data.
QUESTION 1
Define the confidentiality in theCIA triad.
Answer: Our ability to protect data from those who are not authorized to view it.
Rationale: Confidentiality, a core tenet of theCIA triad (Confidentiality, Integrity, Availability), ensures that information is
accessible only to authorized individuals, thereby preventing unauthorized
disclosure. This principle directly addresses the protection of sensitive data from access by unauthorized entities.
QUESTION 2
Examples of confidentiality
Answer: A patron using an ATM card wants to keep their PIN number confidential.
An ATM owner wants to keep bank account numbers confidential.
Rationale: Confidentiality refers to protecting sensitive personal information from unauthorized disclosure, as demonstrated
by patrons safeguarding PINs and financial institutions protecting account numbers.
This principle is fundamental to privacy and security in information management.
QUESTION 3
How can confidentiality be broken?
Answer: Losing a laptop
An attacker gets access to info
A person can look over your shoulder.
Rationale: Confidentiality is breached when protected health information is exposed through unauthorized access, such as
a lost device, a cyberattack, or visual observation by an unauthorized individual.
This highlights the principle of safeguarding patient data from any potential disclosure.
Confidential • Student Study Edition • Practice & Review Guide Page 3 of 32
, STUDENT STUDY & MASTERY EDITION PRACTICE & REVIEW GUIDE
QUESTION 4
Define integrity in theCIA triad.
Answer: The ability to prevent people from changing your data and the ability to reverse unwanted changes.
Rationale: Integrity ensures data is accurate and unaltered, meaning it can be protected from unauthorized modification
and restored if changes occur. This principle underpins data trustworthiness and reliability.
QUESTION 5
How do you control integrity?
Answer: Permissions restrict what users can do (read, write, etc.)
Rationale: Integrity is maintained by enforcing access controls and permissions, which dictate user capabilities such as
reading or writing data, thereby preventing unauthorized modifications. This principle is rooted in the concept of least
privilege, ensuring data remains unaltered by unintended or malicious actions.
QUESTION 6
Examples of integrity
Answer: Data used by a doctor to make medical decisions needs to be correct or the patient can die.
Rationale: Integrity in data means it is accurate, complete, and trustworthy, which is paramount for clinical decision-making
to prevent adverse patient outcomes. This highlights the critical need for data integrity in healthcare where errors can have
life-threatening consequences.
QUESTION 7
How can availability be broken?
Answer: Loss of power, application problems. If caused by an attacker, this is a Denial of Service attack.
Rationale: Availability is compromised by disruptions like power outages or application malfunctions, and when an attacker
intentionally causes these disruptions, it constitutes a Denial of Service (DoS)
attack. This highlights that availability depends on uninterrupted access and functionality, which can be deliberately
undermined.
Confidential • Student Study Edition • Practice & Review Guide Page 4 of 32