Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 20 pages
Exam (elaborations)

WGU C795 CYBERSECURITY MANAGEMENT I – STRATEGIC EXAM QUESTIONS AND FULLY CORRECT ANSWERS

Document preview thumbnail
Preview 3 out of 20 pages

WGU C795 CYBERSECURITY MANAGEMENT I – STRATEGIC EXAM QUESTIONS AND FULLY CORRECT ANSWERS.....

Content preview

WGU C795 CYBERSECURITY MANAGEMENT I –
STRATEGIC EXAM QUESTIONS AND FULLY
CORRECT ANSWERS




300 QUESTIONS & ANSWERS


1. What is cybersecurity governance? The framework of policies, procedures,
and controls that guide an organization's cybersecurity strategy and ensure
alignment with business objectives.
2. What are the three primary components of the CIA triad?
Confidentiality, Integrity, and Availability.
3. Define confidentiality in cybersecurity context. Ensuring that information
is accessible only to those authorized to have access.
4. What does integrity mean in cybersecurity? Maintaining the accuracy and
completeness of data and preventing unauthorized modification.
5. What is availability in cybersecurity terms? Ensuring that information and
resources are accessible to authorized users when needed.
6. What is the primary purpose of a cybersecurity framework? To provide a
structured approach to managing cybersecurity risks and establishing security
controls.
7. Name three widely recognized cybersecurity frameworks. NIST
Cybersecurity Framework, ISO 27001, and COBIT.
8. What are the five core functions of the NIST Cybersecurity Framework?
Identify, Protect, Detect, Respond, and Recover.
9. What is a cybersecurity policy? A formal document that outlines an
organization's approach to managing and protecting information assets.
10. What is the difference between a policy and a procedure? A policy
defines what should be done, while a procedure defines how it should be done.

,11. What is risk appetite in cybersecurity? The level of risk an organization is
willing to accept in pursuit of its objectives.
12. Define risk tolerance. The specific level of risk that an organization can
accept without compromising its operations or objectives.
13. What is a security control? A safeguard or countermeasure designed to
protect the confidentiality, integrity, and availability of information.
14. Name the three types of security controls. Administrative (management),
technical (logical), and physical controls.
15. What is defense in depth? A layered security approach that uses multiple
security controls to protect information assets.
16. What is the principle of least privilege? Granting users only the minimum
access rights necessary to perform their job functions.
17. What is separation of duties? Dividing critical tasks among multiple
people to prevent fraud and errors.
18. Define due diligence in cybersecurity. The reasonable care and
investigation required to protect an organization's assets and comply with
regulations.
19. What is due care? The ongoing effort to maintain security and protect
assets through proper implementation of controls.
20. What is a security baseline? A minimum set of security controls that must
be implemented to protect information systems.
21. What is configuration management? The process of maintaining systems
in a known, secure state through documented procedures.
22. Define security awareness training. Educational programs designed to
help employees understand security policies and recognize threats.
23. What is the purpose of background checks in cybersecurity? To verify
the trustworthiness and reliability of individuals with access to sensitive
information.
24. What is an acceptable use policy (AUP)? A policy that defines appropriate
and inappropriate uses of an organization's IT resources.
25. What is clean desk policy? A policy requiring employees to secure
sensitive information when not in use and maintain clear workspaces.

, 26. Define privileged access management (PAM). The management and
monitoring of accounts with elevated access rights to critical systems and data.
27. What is identity and access management (IAM)? A framework for
managing digital identities and controlling access to resources.
28. What is single sign-on (SSO)? A method that allows users to access
multiple applications with one set of credentials.
29. Define multi-factor authentication (MFA). A security process requiring
users to provide two or more verification factors to gain access.
30. What is role-based access control (RBAC)? An access control method
where permissions are assigned based on user roles within an organization.
31. What is mandatory access control (MAC)? A security model where
access is controlled by the system based on security labels and clearances.
32. Define discretionary access control (DAC). A security model where
resource owners can grant or deny access to other users.
33. What is attribute-based access control (ABAC)? An access control model
that uses attributes of users, resources, and environment to make access
decisions.
34. What is a security incident? Any event that threatens the confidentiality,
integrity, or availability of information assets.
35. Define a security event. Any observable occurrence in a system or network
that may indicate a security issue.
36. What is the purpose of logging and monitoring? To detect, investigate,
and respond to security incidents and maintain audit trails.
37. What is log retention? The practice of storing log files for a specified
period to support investigations and compliance.
38. Define security metrics. Quantifiable measures used to assess the
effectiveness of security controls and programs.
39. What are key performance indicators (KPIs) in cybersecurity? Metrics
that measure the success of cybersecurity objectives and initiatives.
40. What is a security dashboard? A visual representation of security metrics
and status information for management reporting.
41. Define security posture. The overall security strength and resilience of an
organization's IT infrastructure.

Document information

Uploaded on
June 11, 2025
Number of pages
20
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$18.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
luzlinkuz
3.8
(325)
Sold
1583
Followers
852
Items
31845
Last sold
4 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions