• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 114 pages
Exam (elaborations)

Wgu D430 Information Security Exam Simulation Questions And Correct Answers Plus Rationales| Instant Download

Document preview thumbnail
Preview 4 out of 114 pages

This study document gives you a full set of practice questions for the WGU D430 Information Security exam, each with the correct answer and a clear rationale. Topics include risk management, zero-trust architecture, incident response, access control, SIEM, GDPR, defense in depth, and common web vulnerabilities. Use it to test your knowledge and get ready for exam day.

Content preview

, Question 1
An organization uses a risk matrix with likelihood and impact scales from 1 to
5. A vulnerability has a likelihood of 4 and an impact of 5. The organization's
risk appetite is low, and the asset value is $2 million. If the annualized rate of
occurrence (ARO) is 0.3, what is the annualized loss expectancy (ALE), and
what risk response is most appropriate?
A. ALE = $300,000; risk avoidance
B. ALE = $600,000; risk mitigation
C. ALE = $300,000; risk mitigation
D. ALE = $600,000; risk avoidance
Correct Answer: B - ALE = $600,000; risk mitigation


RATIONALE
ALE = SLE × ARO. SLE = asset value × exposure factor. Assuming
exposure factor = 1 (full loss), SLE = $2,000,000. ALE = $2,000,000
× 0.3 = $600,000. Given low risk appetite and high ALE, mitigation
(reducing likelihood/impact) is most appropriate. Avoidance would
mean discontinuing the activity, which may not be feasible.

Question 2
Which of the following best describes the security property that ensures a
digital signature provides non-repudiation?
A. The signature is encrypted with the sender's private key, which only
the sender possesses.
B. The signature is encrypted with the recipient's public key, ensuring
only the recipient can verify.
C. The signature uses a symmetric key shared between sender and
receiver.
D. The signature is hashed with a salt and stored in a public ledger.
Correct Answer: A - The signature is encrypted with the sender's
private key, which only the sender possesses.


Page 2

, RATIONALE
Non-repudiation in digital signatures relies on asymmetric
cryptography: the sender signs with their private key, and anyone can
verify with the sender's public key. This proves the sender's identity
and prevents denial. Symmetric keys or recipient's public key do not
provide non-repudiation.

Question 3
A company implements a zero-trust architecture. Which of the following is the
most critical principle to enforce?
A. All internal network traffic is trusted by default.
B. Access decisions are based on continuous verification of user and
device posture.
C. VPNs are used to grant broad access to the internal network.
D. Perimeter firewalls are the primary control for preventing
unauthorized access.
Correct Answer: B - Access decisions are based on continuous
verification of user and device posture.


RATIONALE
Zero-trust eliminates implicit trust based on network location. It
requires continuous authentication and authorization of every access
request, considering user identity, device health, and context.
Traditional perimeter models (VPNs, firewalls) assume internal trust,
which contradicts zero-trust.

Question 4
In an incident response process, which phase involves determining the scope of
an incident and identifying affected systems?
A. Preparation
B. Detection and Analysis
C. Containment, Eradication, and Recovery


Page 3

, D. Post-Incident Activity


Correct Answer: B - Detection and Analysis


RATIONALE
The Detection and Analysis phase of NIST SP 800-61 involves
identifying and validating incidents, assessing scope, and determining
impact. Containment follows after analysis. Preparation is proactive,
and Post-Incident is after recovery.

Question 5
Which of the following is a key difference between RBAC and ABAC?
A. RBAC uses attributes like time and location, while ABAC uses roles.
B. ABAC grants access based on user roles, while RBAC uses resource
attributes.
C. RBAC assigns permissions based on roles, while ABAC evaluates
attributes of user, resource, and environment.
D. ABAC is only used for external users, while RBAC is for internal
users.
Correct Answer: C - RBAC assigns permissions based on roles,
while ABAC evaluates attributes of user, resource, and
environment.


RATIONALE
RBAC (Role-Based Access Control) grants access based on the user's
role within the organization. ABAC (Attribute-Based Access Control)
uses a combination of attributes (user, resource, action, environment)
to make dynamic access decisions. This allows finer-grained,
context-aware control.




Page 4

Document information

Uploaded on
October 1, 2026
Number of pages
114
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$30.00

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CaseHero
3.8
(4)
Sold
20
Followers
0
Items
6237
Last sold
6 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions