WGU D430 Fundamentals of
Information Security Questions &
Answers 2026/2027 Latest Verified
Exam Edition with Rationales
Comprehensive Examination Question Bank • Concept Mapping
TOTAL QUESTIONS EXAM TOPICS RATIONALES
239 Questions 12 Modules 100% Verified
DOCUMENT OVERVIEW
This document contains 239 verified questions with correct answers and detailed rationales focused on
information security principles. It serves as a comprehensive resource for understanding key concepts in
security, access controls, data protection, and intrusion detection systems. Students can utilize this material
for study, review, and certification preparation in the field of information security.
EXAM BLUEPRINT & TOPIC DISTRIBUTION
Systematic breakdown of subject domains and exam coverage.
Topic Module Scope & Core Focus
Information Security Fundamentals Explores the foundational principles and practices of protecting information and systems.
Access Control Mechanisms Examines various models and methods for managing user access to resources.
Data Protection Techniques Covers strategies for safeguarding sensitive information from unauthorized access.
Focuses on the technologies and methodologies used to detect unauthorized access
Intrusion Detection Systems attempts.
Details the steps involved in identifying, assessing, and mitigating risks in information
Risk Management Process security.
Incident Response Strategies Discusses the protocols and procedures for responding to security incidents effectively.
Compliance and Legal Considerations Reviews the regulations and standards that govern information security practices.
Confidential • Student Study Edition • Practice & Review Guide Page 1 of 82
,STUDENT STUDY & MASTERY EDITION PRACTICE & REVIEW GUIDE
Vulnerability Assessment Covers the processes for identifying and analyzing vulnerabilities in systems.
Examines different types of threats and attacks that organizations face in the digital
Cybersecurity Threats and Attacks landscape.
Authentication and Authorization Explores mechanisms for verifying user identities and granting access rights.
Encryption and Cryptography Discusses methods for securing data through encryption and cryptographic techniques.
Business Continuity Planning Focuses on strategies to ensure operations can continue during and after a security incident.
Total Exam Coverage 12 Integrated Topic Modules • 239 Examination Questions
Confidential • Student Study Edition • Practice & Review Guide Page 2 of 82
,STUDENT STUDY & MASTERY EDITION PRACTICE & REVIEW GUIDE
QUESTION 1
Information security
Answer: "Protecting information and information systems from unauthorized access, use, disclosure,
disruption, modification, or destruction." - US law protection of digital assets.
Rationale: Information security encompasses safeguarding data and systems from unauthorized actions, ensuring
confidentiality, integrity, and availability. This principle underlies the protection of all digital assets.
QUESTION 2
Secure
Answer: It's difficult to define when you're truly secure. when you can spot insecurities, you can take steps
to mitigate these issues. although you'll never get to a truly secure state, you can take steps in the right
direction. m; as you increase the level of security, you decrease the level of productivity. the cost of security
should never outstrip the value of what it's protecting.
Rationale: True security is an unattainable ideal, as continuous vigilance and mitigation of insecurities are necessary to
progress toward a more secure state. The cost-benefit analysis of security measures is critical, balancing protection value
against potential productivity loss.
QUESTION 3
Data at rest and in motion (and in use)
Answer: Data at rest is stored data not in the process of being moved; usually protected with encryption at
the level of the file or the entire storage device. data in motion is data that is in the process of being moved;
usually protected with encryption, but in this case the encryption protects the network protocol or the path of
the data. data in use is the data that is actively being accessed at the moment. protection includes
permissions and authentication of users. could be conflated with data in motion.
Rationale: Data at rest is stored and typically secured by encrypting files or devices, while data in motion is actively
transmitted and secured via network protocol encryption. Data in use refers to data actively accessed, with protection relying
on user permissions and authentication.
Confidential • Student Study Edition • Practice & Review Guide Page 3 of 82
, STUDENT STUDY & MASTERY EDITION PRACTICE & REVIEW GUIDE
QUESTION 4
Defense by layer
Answer: The layers of your defense-in-depth strategy will vary depending on situation and environment.
logical (nonphysical) layers: external network, network perimeter, internal network, host, application, and
data layers as areas to place your defenses. m; defenses for layers can appear in more than one area.
penetration testing, for example, can and should be used in all layers.
Rationale: A defense-in-depth strategy employs multiple, diverse layers of security controls, acknowledging that the specific
implementation of these logical and physical layers varies based on the unique context of the environment being protected.
The principle is that if one layer fails, others are in place to mitigate the threat, requiring a comprehensive and adaptable
approach to security.
QUESTION 5
Confidentiality (CIA triad)
Answer: Refers to our ability to protect data from those who are not authorized to view it. m; can be
compromised in a number of ways; losing laptop with data, someone looking over your shoulder while
entering password, email attachments sent to wrong people, attackers could penetrate your system.
Rationale: Confidentiality safeguards sensitive information from unauthorized disclosure, which can be breached through
physical loss, shoulder surfing, misdirected communications, or system
penetration. This principle is a cornerstone of theCIA triad, emphasizing the protection of data integrity and privacy.
QUESTION 6
Integrity (CIA triad)
Answer: The ability to prevent people from changing your data in an unauthorized or undesirable manner. m;
must have the means to prevent unauthorized changes to data and the ability to reverse unauthorized
changes. is particularly important when it concerns data that provides the foundation for other decisions; an
attacker could alter data from medical tests which can harm the patient.
Rationale: Data integrity ensures that information is accurate and trustworthy by preventing unauthorized modifications and
allowing for the reversal of such changes, which is vital for maintaining the reliability of foundational data used in critical
decision-making processes. This principle guards against malicious alterations that could have severe consequences, such
as impacting patient care based on falsified medical test results.
Confidential • Student Study Edition • Practice & Review Guide Page 4 of 82