WGU D430 FUNDAMENTALS OF
INFORMATION SECURITY
OBJECTIVE ASSESSMENT 2026
150 Questions with Answers and Detailed Rationales
100 PERCENT GUARANTEED PASS
INSTANT DOWNLOAD ANSWERS INCLUDED
IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
WGU D430 FUNDAMENTALS OF INFORMATION SECURITY OBJECTIVE ASSESSMENT 2026. It contains 150
carefully selected questions that reflect the most current exam content and testing strategies. Each question is
accompanied by a correct answer and a detailed rationale that explains the underlying pathophysiology,
pharmacology, or clinical reasoning.
Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas
Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions
Review Summary 150 Questions
Foundations - Application - WGU D430 Fundamentals OF Information Security Objective Assessment 2026
Information Security / Cybersecurity Fundamentals Undergraduate YEAR 3/4 Upper-division
All answers with rationales
,Table of Contents
Content Area Questions Key Topics
Security Fundamentals AND 1-25 Security, Control, Access, Organization, Property
THE CIA Triad
RISK Management AND 26-50 Control, Security, Access, Ensure, Network
Threat Assessment
Access Control AND 51-75 Security, Control, Impact, Access, Response
Authentication
Cryptography AND 76-100 Access, Security, Control, Users, Organization
Encryption
Network Security AND 101-125 Security, Control, Organization, Attacker, Ensure
Perimeter Defense
Security Policies Standards 126-150 Control, Access, Threat, Company, Directly
AND Compliance
TOTAL 150 All questions include answers and detailed rationales
,Section A - Security Fundamentals AND THE CIA Triad
Q1.
A hospital's electronic health record (EHR) system must remain accessible to clinicians at
all times, but patient data must also be protected from unauthorized modification. Which
security property is most directly compromised if an attacker alters a patient's medication
dosage in the database?
A. Confidentiality B. Integrity
C. Availability D. Non-repudiation
Correct: B - Integrity
Rationale:Integrity ensures data is not altered or destroyed in an unauthorized manner.
Unauthorized modification of a medication dosage directly violates integrity. Confidentiality
concerns unauthorized disclosure, availability concerns timely access, and non-repudiation
concerns proof of origin.
Why the other answers are wrong:
A. Confidentiality is breached when data is disclosed to unauthorized parties, not when it is
altered.
C. Availability is compromised when systems or data are inaccessible, not when data is
modified.
D. Non-repudiation ensures a party cannot deny sending a message; it is not directly violated
by data alteration.
Reference: Whitman, M.E. & Mattord, H.J. (2022). Principles of Information Security, 7th Ed., Ch. 1.
Q2.
A security analyst is calculating the annualized loss expectancy (ALE) for a specific risk.
The asset value is $500,000, the exposure factor is 20%, and the annualized rate of
occurrence is 0.1. What is the ALE?
A. $10,000 B. $50,000
C. $100,000 D. $500,000
Correct: A - $10,000
Rationale:SLE = AV × EF = $500,000 × 0.20 = $100,000. ALE = SLE × ARO = $100,000 ×
0.1 = $10,000. The other options result from misapplication of the formulas.
Why the other answers are wrong:
B. $50,000 equals AV × ARO, ignoring the exposure factor.
C. $100,000 is the SLE, not the ALE.
D. $500,000 is the asset value, not the annualized loss.
Page 3
, Section A - Security Fundamentals AND THE CIA Triad
Reference: Gibson, D. (2023). Managing Risk in Information Systems, 3rd Ed., Ch. 4.
Q3.
Which access control model enforces access based on a user's role within the
organization and is most appropriate for a large enterprise with high employee turnover?
A. Mandatory Access Control (MAC) B. Discretionary Access Control (DAC)
C. Role-Based Access Control (RBAC) D. Rule-Based Access Control
Correct: C - Role-Based Access Control (RBAC)
Rationale:RBAC assigns permissions to roles rather than individuals, simplifying
administration and reducing errors during employee changes. MAC uses labels and
clearances, DAC lets owners set permissions, and rule-based uses global rules often for
network devices.
Why the other answers are wrong:
A. MAC is based on security labels and clearances, not organizational roles, and is inflexible
for high turnover.
B. DAC allows data owners to assign permissions, which can become inconsistent and hard to
manage at scale.
D. Rule-based access control applies global rules (e.g., firewall ACLs) and is not primarily
role-centric.
Reference: Stallings, W. & Brown, L. (2023). Computer Security: Principles and Practice, 5th Ed., Ch. 4.
Q4.
A company wants to ensure that a digitally signed contract cannot be repudiated by the
sender. Which cryptographic property does a digital signature primarily provide?
A. Confidentiality B. Integrity and non-repudiation
C. Availability D. Anonymity
Correct: B - Integrity and non-repudiation
Rationale:Digital signatures provide integrity (via hash) and non-repudiation (via sender's
private key). They do not inherently provide confidentiality, availability, or anonymity.
Why the other answers are wrong:
A. Confidentiality requires encryption, not just signing.
C. Availability is about uptime and access, not signatures.
D. Anonymity is the opposite of non-repudiation.
Reference: Paar, C. & Pelzl, J. (2023). Understanding Cryptography, 2nd Ed., Ch. 10.
Page 4
INFORMATION SECURITY
OBJECTIVE ASSESSMENT 2026
150 Questions with Answers and Detailed Rationales
100 PERCENT GUARANTEED PASS
INSTANT DOWNLOAD ANSWERS INCLUDED
IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
WGU D430 FUNDAMENTALS OF INFORMATION SECURITY OBJECTIVE ASSESSMENT 2026. It contains 150
carefully selected questions that reflect the most current exam content and testing strategies. Each question is
accompanied by a correct answer and a detailed rationale that explains the underlying pathophysiology,
pharmacology, or clinical reasoning.
Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas
Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions
Review Summary 150 Questions
Foundations - Application - WGU D430 Fundamentals OF Information Security Objective Assessment 2026
Information Security / Cybersecurity Fundamentals Undergraduate YEAR 3/4 Upper-division
All answers with rationales
,Table of Contents
Content Area Questions Key Topics
Security Fundamentals AND 1-25 Security, Control, Access, Organization, Property
THE CIA Triad
RISK Management AND 26-50 Control, Security, Access, Ensure, Network
Threat Assessment
Access Control AND 51-75 Security, Control, Impact, Access, Response
Authentication
Cryptography AND 76-100 Access, Security, Control, Users, Organization
Encryption
Network Security AND 101-125 Security, Control, Organization, Attacker, Ensure
Perimeter Defense
Security Policies Standards 126-150 Control, Access, Threat, Company, Directly
AND Compliance
TOTAL 150 All questions include answers and detailed rationales
,Section A - Security Fundamentals AND THE CIA Triad
Q1.
A hospital's electronic health record (EHR) system must remain accessible to clinicians at
all times, but patient data must also be protected from unauthorized modification. Which
security property is most directly compromised if an attacker alters a patient's medication
dosage in the database?
A. Confidentiality B. Integrity
C. Availability D. Non-repudiation
Correct: B - Integrity
Rationale:Integrity ensures data is not altered or destroyed in an unauthorized manner.
Unauthorized modification of a medication dosage directly violates integrity. Confidentiality
concerns unauthorized disclosure, availability concerns timely access, and non-repudiation
concerns proof of origin.
Why the other answers are wrong:
A. Confidentiality is breached when data is disclosed to unauthorized parties, not when it is
altered.
C. Availability is compromised when systems or data are inaccessible, not when data is
modified.
D. Non-repudiation ensures a party cannot deny sending a message; it is not directly violated
by data alteration.
Reference: Whitman, M.E. & Mattord, H.J. (2022). Principles of Information Security, 7th Ed., Ch. 1.
Q2.
A security analyst is calculating the annualized loss expectancy (ALE) for a specific risk.
The asset value is $500,000, the exposure factor is 20%, and the annualized rate of
occurrence is 0.1. What is the ALE?
A. $10,000 B. $50,000
C. $100,000 D. $500,000
Correct: A - $10,000
Rationale:SLE = AV × EF = $500,000 × 0.20 = $100,000. ALE = SLE × ARO = $100,000 ×
0.1 = $10,000. The other options result from misapplication of the formulas.
Why the other answers are wrong:
B. $50,000 equals AV × ARO, ignoring the exposure factor.
C. $100,000 is the SLE, not the ALE.
D. $500,000 is the asset value, not the annualized loss.
Page 3
, Section A - Security Fundamentals AND THE CIA Triad
Reference: Gibson, D. (2023). Managing Risk in Information Systems, 3rd Ed., Ch. 4.
Q3.
Which access control model enforces access based on a user's role within the
organization and is most appropriate for a large enterprise with high employee turnover?
A. Mandatory Access Control (MAC) B. Discretionary Access Control (DAC)
C. Role-Based Access Control (RBAC) D. Rule-Based Access Control
Correct: C - Role-Based Access Control (RBAC)
Rationale:RBAC assigns permissions to roles rather than individuals, simplifying
administration and reducing errors during employee changes. MAC uses labels and
clearances, DAC lets owners set permissions, and rule-based uses global rules often for
network devices.
Why the other answers are wrong:
A. MAC is based on security labels and clearances, not organizational roles, and is inflexible
for high turnover.
B. DAC allows data owners to assign permissions, which can become inconsistent and hard to
manage at scale.
D. Rule-based access control applies global rules (e.g., firewall ACLs) and is not primarily
role-centric.
Reference: Stallings, W. & Brown, L. (2023). Computer Security: Principles and Practice, 5th Ed., Ch. 4.
Q4.
A company wants to ensure that a digitally signed contract cannot be repudiated by the
sender. Which cryptographic property does a digital signature primarily provide?
A. Confidentiality B. Integrity and non-repudiation
C. Availability D. Anonymity
Correct: B - Integrity and non-repudiation
Rationale:Digital signatures provide integrity (via hash) and non-repudiation (via sender's
private key). They do not inherently provide confidentiality, availability, or anonymity.
Why the other answers are wrong:
A. Confidentiality requires encryption, not just signing.
C. Availability is about uptime and access, not signatures.
D. Anonymity is the opposite of non-repudiation.
Reference: Paar, C. & Pelzl, J. (2023). Understanding Cryptography, 2nd Ed., Ch. 10.
Page 4