WGU D430 FUNDAMENTALS OF INFORMATION SECURITY EXAM
OBJECTIVE ASSESSMENT NEWEST 2026 TEST BANK ACTUAL EXAM 300
QUESTIONS AND CORRECT DETAILED ANSWERS (VERIFIED
ANSWERS) |ALREADY GRADED A+
1.A company wants to update its access control policy.
The company wants to prevent hourly employees from logging in to company
computers after business hours.
Which type of access control policy should be implemented?
A. Discretionary
B. Attribute-based
C. Physical
D. Mandatory
Rationale: Attribute-Based Access Control (ABAC) can use attributes such as
the user's role and the time of access to determine whether access should be
permitted. Because the company needs to restrict employee logins based on
business hours, an environmental attribute such as time can be incorporated
into the access-control decision.
2.A new software development company has determined that one of its
proprietary algorithms is at a high risk for unauthorized disclosure. The
company's security up to this point has been fairly lax.
Which procedure should the company implement to protect this asset?
A. Relocate the algorithm to encrypted storage.
B. Store the algorithm on highly available servers.
C. Create multiple off-site backups of the algorithm.
D. Transfer the algorithm onto servers in the demilitarized zone.
Rationale: Encrypting the proprietary algorithm protects its confidentiality by
making the information unreadable to unauthorized individuals who may gain
,access to the storage medium. Since the primary risk identified is unauthorized
disclosure, encryption directly addresses that risk.
3.An accounting firm stores financial data for many customers. The company
policy requires that employees only access data for customers they are assigned
to. The company implements a written policy indicating an employee can be
fired for violating this requirement.
Which type of control has the company implemented?
A. Deterrent
B. Preventive
C. Detective
D. Active
Rationale: A deterrent control discourages individuals from performing
unauthorized or prohibited actions by establishing consequences for violating
security policies. Stating that an employee can be fired for accessing
unauthorized customer data is intended to discourage employees from
violating the access requirement.
4.How can an operating system be hardened in accordance to the principle of
least privilege?
A. Remove unneeded services.
B. Restrict account permissions.
C. Implement account auditing.
D. Remove unnecessary software.
Rationale: The principle of least privilege requires users and accounts to
receive only the permissions necessary to perform their required tasks.
,Restricting account permissions minimizes unnecessary access and reduces the
potential impact of a compromised account.
5.A company implements an Internet-facing web server for its sales force to
review product information. The sales force can also update its profiles and
profile photos, but not the product information. There is no other information on
this server.Which content access permissions should be granted to the sales
force based on the principle of least privilege?
A. Read and limited write access
B. Limited read access only
C. Limited write access only
D. Read and write access
Rationale: The sales force needs read access to product information and
limited write access to its own profiles and profile photos. Granting only these
necessary permissions follows the principle of least privilege while preventing
users from modifying product information.
6.A corporation has discovered that some confidential personnel information
has been used inappropriately.
How can the principle of least privilege be applied to limit access to
confidential personnel records?
A. Only allow access to department heads and executives.
B. Only allow access to those who work in the human resources department.
C. Only allow access to those with elevated security permissions.
D. Only allow access to those who need access to perform their job.
Rationale: Least privilege means granting access based on job-related
necessity, rather than position, seniority, or department alone. Limiting
, confidential personnel records to individuals who require them to perform their
duties minimizes unnecessary exposure and reduces the risk of inappropriate
access.
7.A user runs an application that has been infected with malware that is less
than 24 hours old. The malware then infects the operating system.
Which safeguard should be implemented to prevent this type of attack?
A. Install the latest security updates.
B. Modify the default user accounts.
C. Uninstall unnecessary software.
D. Limit user account privileges.
Rationale: Limiting user account privileges applies the principle of least
privilege, reducing the ability of newly introduced malware to make significant
changes to the operating system.
________________________________________________________________
8.A company was the victim of a security breach resulting in stolen user
credentials. An attacker used a stolen username and password to log in to an
employee email account.
Which security practice could have reduced the post-breach impact of this
event?
A. Multi-factor authentication
B. Mutual authentication
C. Network segmentation
D. Operating system hardening
Rationale: Multi-factor authentication requires an additional authentication
factor beyond the username and password. Therefore, stolen credentials alone
OBJECTIVE ASSESSMENT NEWEST 2026 TEST BANK ACTUAL EXAM 300
QUESTIONS AND CORRECT DETAILED ANSWERS (VERIFIED
ANSWERS) |ALREADY GRADED A+
1.A company wants to update its access control policy.
The company wants to prevent hourly employees from logging in to company
computers after business hours.
Which type of access control policy should be implemented?
A. Discretionary
B. Attribute-based
C. Physical
D. Mandatory
Rationale: Attribute-Based Access Control (ABAC) can use attributes such as
the user's role and the time of access to determine whether access should be
permitted. Because the company needs to restrict employee logins based on
business hours, an environmental attribute such as time can be incorporated
into the access-control decision.
2.A new software development company has determined that one of its
proprietary algorithms is at a high risk for unauthorized disclosure. The
company's security up to this point has been fairly lax.
Which procedure should the company implement to protect this asset?
A. Relocate the algorithm to encrypted storage.
B. Store the algorithm on highly available servers.
C. Create multiple off-site backups of the algorithm.
D. Transfer the algorithm onto servers in the demilitarized zone.
Rationale: Encrypting the proprietary algorithm protects its confidentiality by
making the information unreadable to unauthorized individuals who may gain
,access to the storage medium. Since the primary risk identified is unauthorized
disclosure, encryption directly addresses that risk.
3.An accounting firm stores financial data for many customers. The company
policy requires that employees only access data for customers they are assigned
to. The company implements a written policy indicating an employee can be
fired for violating this requirement.
Which type of control has the company implemented?
A. Deterrent
B. Preventive
C. Detective
D. Active
Rationale: A deterrent control discourages individuals from performing
unauthorized or prohibited actions by establishing consequences for violating
security policies. Stating that an employee can be fired for accessing
unauthorized customer data is intended to discourage employees from
violating the access requirement.
4.How can an operating system be hardened in accordance to the principle of
least privilege?
A. Remove unneeded services.
B. Restrict account permissions.
C. Implement account auditing.
D. Remove unnecessary software.
Rationale: The principle of least privilege requires users and accounts to
receive only the permissions necessary to perform their required tasks.
,Restricting account permissions minimizes unnecessary access and reduces the
potential impact of a compromised account.
5.A company implements an Internet-facing web server for its sales force to
review product information. The sales force can also update its profiles and
profile photos, but not the product information. There is no other information on
this server.Which content access permissions should be granted to the sales
force based on the principle of least privilege?
A. Read and limited write access
B. Limited read access only
C. Limited write access only
D. Read and write access
Rationale: The sales force needs read access to product information and
limited write access to its own profiles and profile photos. Granting only these
necessary permissions follows the principle of least privilege while preventing
users from modifying product information.
6.A corporation has discovered that some confidential personnel information
has been used inappropriately.
How can the principle of least privilege be applied to limit access to
confidential personnel records?
A. Only allow access to department heads and executives.
B. Only allow access to those who work in the human resources department.
C. Only allow access to those with elevated security permissions.
D. Only allow access to those who need access to perform their job.
Rationale: Least privilege means granting access based on job-related
necessity, rather than position, seniority, or department alone. Limiting
, confidential personnel records to individuals who require them to perform their
duties minimizes unnecessary exposure and reduces the risk of inappropriate
access.
7.A user runs an application that has been infected with malware that is less
than 24 hours old. The malware then infects the operating system.
Which safeguard should be implemented to prevent this type of attack?
A. Install the latest security updates.
B. Modify the default user accounts.
C. Uninstall unnecessary software.
D. Limit user account privileges.
Rationale: Limiting user account privileges applies the principle of least
privilege, reducing the ability of newly introduced malware to make significant
changes to the operating system.
________________________________________________________________
8.A company was the victim of a security breach resulting in stolen user
credentials. An attacker used a stolen username and password to log in to an
employee email account.
Which security practice could have reduced the post-breach impact of this
event?
A. Multi-factor authentication
B. Mutual authentication
C. Network segmentation
D. Operating system hardening
Rationale: Multi-factor authentication requires an additional authentication
factor beyond the username and password. Therefore, stolen credentials alone