WGU D315 Network and Security Foundation
2024/2025 Objective Assessment Verified Questions
and Answers 100% Graded A+
In which physical LAN topology are nodes connected to each other with a backbone
cable that loops around and ends at the same point it started?
a. Ring
b. Bus
c. Star
d. Tree - Ring
Which OSI layer ensures error-free packets?
a. Application
b. Transport
c. Session
d. Presentation - Transport
Which topology uses a switch or hub to connect to all devices in the same network?
a. Mesh
b. Ring
c. Star
d. Bus - Star
Which cloud service provides hardware, operating systems, and web servers but not
end-user applications?
a. IaaS
b. PaaS
c. SaaS
d. RaaS - PaaS
Which cloud model provides an exclusive cloud computing service environment that is
shared between two or more organizations?
a. Public
b. Private
c. Community
d. Hybrid - Community
,Which type of software is used to provide virtualization?
a. Database
b. Hypervisor
c. Antivirus
d. Spreadsheet - Hypervisor
A user that does not want to be identified while communicating on a network uses an
application to alter the computer's identity. Which type of exploit is being perpetrated?
a. Denial-of-service
b. ARP poisoning
c. Smurf attack
d. Spoofing - Spoofing
An attacker attempts to misdirect traffic on a network back to the attacker by corrupting
the network computer's cache of IP address to MAC address mappings that are cached.
Which exploit is the attacker perpetrating?
a. Port scanning
b. Wiretapping
c. Denial-of-service
d. ARP poisoning - ARP poisoning
Which exploit actually breaches the physical medium or uses devices to monitor signals
from outside the physical medium itself?
a. Spoofing
b. Wiretapping
c. Sniffing
d. Port scanning - Wiretapping
Which type of attack can overwhelm a web server by inserting more data into a web
form than the system was configured to hold?
a. Buffer overflow
b. ARP poisoning
c. Session hijacking
d. Cross-site scripting - Buffer overflow
Which type of attack sends an email claiming to be from a reputable business in order
to entice the recipient to provide sensitive information?
a. Denial-of-service
b. Phishing
c. Password attacks
,d. Man-in-the-middle - Phishing
A user on a network is planning to launch an exploit against a coworker in a neighboring
department. The user needs to identify the IP address of a coworker in the desired
department. Which tool or utility will allow the user to watch network traffic in real time to
identify a target?
a. Port scan
b. Antivirus software
c. Sniffer
d. Port redirection - Sniffer
Which group of attackers is typically used for penetration testing?
a. Red Team
b. Blue Team
c. White Team
d. Gray Team - Red Team
Which type of attack exploits an unpatched software vulnerability?
a. Zero-day
b. Brue-force
c. Diffie-Hellman
d. Man-in-the-middle - Zero-day
A company has the policy that all new user passwords are P@ssw0rd but does not
require new users to change their password. An employee randomly tries a coworker's
account with the new user password to see if they can log in as the coworker. Which
type of vulnerability does this create?
a. BYOD
b. Weak password
c. Default password
d. Misconfigured firewall rules - Default password
An employee that does not want to miss emails from important clients sets up her
cellular smartphone to allow her to check email. Unfortunately, she does not install
antivirus software on the cellular phone. What type of vulnerability is represented?
a. Industry threat
b. Misconfigured firewall rules
c. Weak passwords
d. BYOD/Mobile - BYOD/Mobile
What is the definition of vulnerability, in computer security?
, a. It is a weakness which can be exploited by a threat, such as an attacker, to perform
unauthorized actions within a computer system.
b. It is a possible danger that might exploit a weakness to breach security and therefore
cause possible harm.
c. It is an action taken by a threat that exploits a weakness that attempts to either block
authorized access to an asset or to gain unauthorized access to an asset.
d. It is the potential of a threat to exploit a weakness via an attack. - It is a weakness
which can be exploited by a threat, such as an attacker, to perform unauthorized actions
within a computer system.
What is required to establish a secure connection to a remote network over an insecure
link?
a. Virtual Private Network (VPN) service
b. Linux
c. Command Line Interface
d. TOR Network - Virtual Private Network (VPN) service
An organization is concerned about brute force attacks.
How should the organization counter this risk?
a. Install a mantrap and biometric scanner at the entrance of its data center.
b. Implement a system hardening policy that ensures operating system updates and
software patches are installed regularly.
c. Institute a log-in policy that locks users out of an account after three failed password
attempts.
d. Initiate role-based access to its systems to reduce the possibility of escalated
privileges. - c. Institute a log-in policy that locks users out of an account after three
failed password attempts.
An organization suffers a social engineering attack that results in a cybercriminal
gaining access to its networks and to its customers' private information.
How can the organization mitigate this risk in the future?
a. Update user antivirus software to the latest version
b. Implement a stronger password policy
c. Provide regular cybersecurity training for employees
d. Install a sophisticated intrusion detection system - c. Provide regular cybersecurity
training for employees
Which OSI layer is related to the function of the IP protocol suite?
a. Transport
b. Network
2024/2025 Objective Assessment Verified Questions
and Answers 100% Graded A+
In which physical LAN topology are nodes connected to each other with a backbone
cable that loops around and ends at the same point it started?
a. Ring
b. Bus
c. Star
d. Tree - Ring
Which OSI layer ensures error-free packets?
a. Application
b. Transport
c. Session
d. Presentation - Transport
Which topology uses a switch or hub to connect to all devices in the same network?
a. Mesh
b. Ring
c. Star
d. Bus - Star
Which cloud service provides hardware, operating systems, and web servers but not
end-user applications?
a. IaaS
b. PaaS
c. SaaS
d. RaaS - PaaS
Which cloud model provides an exclusive cloud computing service environment that is
shared between two or more organizations?
a. Public
b. Private
c. Community
d. Hybrid - Community
,Which type of software is used to provide virtualization?
a. Database
b. Hypervisor
c. Antivirus
d. Spreadsheet - Hypervisor
A user that does not want to be identified while communicating on a network uses an
application to alter the computer's identity. Which type of exploit is being perpetrated?
a. Denial-of-service
b. ARP poisoning
c. Smurf attack
d. Spoofing - Spoofing
An attacker attempts to misdirect traffic on a network back to the attacker by corrupting
the network computer's cache of IP address to MAC address mappings that are cached.
Which exploit is the attacker perpetrating?
a. Port scanning
b. Wiretapping
c. Denial-of-service
d. ARP poisoning - ARP poisoning
Which exploit actually breaches the physical medium or uses devices to monitor signals
from outside the physical medium itself?
a. Spoofing
b. Wiretapping
c. Sniffing
d. Port scanning - Wiretapping
Which type of attack can overwhelm a web server by inserting more data into a web
form than the system was configured to hold?
a. Buffer overflow
b. ARP poisoning
c. Session hijacking
d. Cross-site scripting - Buffer overflow
Which type of attack sends an email claiming to be from a reputable business in order
to entice the recipient to provide sensitive information?
a. Denial-of-service
b. Phishing
c. Password attacks
,d. Man-in-the-middle - Phishing
A user on a network is planning to launch an exploit against a coworker in a neighboring
department. The user needs to identify the IP address of a coworker in the desired
department. Which tool or utility will allow the user to watch network traffic in real time to
identify a target?
a. Port scan
b. Antivirus software
c. Sniffer
d. Port redirection - Sniffer
Which group of attackers is typically used for penetration testing?
a. Red Team
b. Blue Team
c. White Team
d. Gray Team - Red Team
Which type of attack exploits an unpatched software vulnerability?
a. Zero-day
b. Brue-force
c. Diffie-Hellman
d. Man-in-the-middle - Zero-day
A company has the policy that all new user passwords are P@ssw0rd but does not
require new users to change their password. An employee randomly tries a coworker's
account with the new user password to see if they can log in as the coworker. Which
type of vulnerability does this create?
a. BYOD
b. Weak password
c. Default password
d. Misconfigured firewall rules - Default password
An employee that does not want to miss emails from important clients sets up her
cellular smartphone to allow her to check email. Unfortunately, she does not install
antivirus software on the cellular phone. What type of vulnerability is represented?
a. Industry threat
b. Misconfigured firewall rules
c. Weak passwords
d. BYOD/Mobile - BYOD/Mobile
What is the definition of vulnerability, in computer security?
, a. It is a weakness which can be exploited by a threat, such as an attacker, to perform
unauthorized actions within a computer system.
b. It is a possible danger that might exploit a weakness to breach security and therefore
cause possible harm.
c. It is an action taken by a threat that exploits a weakness that attempts to either block
authorized access to an asset or to gain unauthorized access to an asset.
d. It is the potential of a threat to exploit a weakness via an attack. - It is a weakness
which can be exploited by a threat, such as an attacker, to perform unauthorized actions
within a computer system.
What is required to establish a secure connection to a remote network over an insecure
link?
a. Virtual Private Network (VPN) service
b. Linux
c. Command Line Interface
d. TOR Network - Virtual Private Network (VPN) service
An organization is concerned about brute force attacks.
How should the organization counter this risk?
a. Install a mantrap and biometric scanner at the entrance of its data center.
b. Implement a system hardening policy that ensures operating system updates and
software patches are installed regularly.
c. Institute a log-in policy that locks users out of an account after three failed password
attempts.
d. Initiate role-based access to its systems to reduce the possibility of escalated
privileges. - c. Institute a log-in policy that locks users out of an account after three
failed password attempts.
An organization suffers a social engineering attack that results in a cybercriminal
gaining access to its networks and to its customers' private information.
How can the organization mitigate this risk in the future?
a. Update user antivirus software to the latest version
b. Implement a stronger password policy
c. Provide regular cybersecurity training for employees
d. Install a sophisticated intrusion detection system - c. Provide regular cybersecurity
training for employees
Which OSI layer is related to the function of the IP protocol suite?
a. Transport
b. Network