1
Test Bank for WGU D430 Fundamentals of
Information Security 2025 – 100% Verified
Questions and Detailed Correct Answers |
Objective Assessment | Graded A+
1. A company wants to restrict hourly employees from accessing systems after business
hours. Which access control model is most suitable?
A. Mandatory Access Control (MAC)
B. Discretionary Access Control (DAC)
C. Role-Based Access Control (RBAC)
D. Attribute-Based Access Control (ABAC)
Rationale: ABAC uses attributes (e.g., time of day, user role) to enforce access policies,
aligning with the need to restrict access based on business hours. MAC is too rigid, DAC
is owner-controlled, and RBAC is role-focused without dynamic attributes. [WGU D430
Objective: Access Control Models]
2. Which principle of the CIA triad is most affected by a ransomware attack that encrypts
critical files?
A. Availability
B. Confidentiality
C. Integrity
D. Accountability
Rationale: Ransomware prevents access to data, primarily impacting availability.
Confidentiality may be secondary if data is exfiltrated, but the core issue is access denial.
[WGU D430 Objective: CIA Triad]
3. What is the primary purpose of implementing a honeypot in a network?
A. Block unauthorized access
B. Detect and analyze malicious activity
C. Encrypt sensitive data
D. Authenticate users
Rationale: A honeypot is a decoy system designed to attract attackers, allowing security
teams to monitor and analyze their behavior. [WGU D430 Objective: Intrusion
Detection]
4. A new software company stores proprietary algorithms on a server. Which method best
protects against unauthorized disclosure?
A. Store on highly available servers
B. Transfer to a demilitarized zone (DMZ)
C. Use encrypted storage
D. Create off-site backups
Rationale: Encryption ensures data confidentiality, protecting against unauthorized
access even if the server is compromised. DMZ and backups address other concerns.
[WGU D430 Objective: Data Protection]
, 2
5. Which type of control is a policy that threatens termination for accessing unauthorized
customer data?
A. Deterrent
B. Preventive
C. Detective
D. Corrective
Rationale: A deterrent control discourages violations through consequences, like
termination. Preventive controls block actions, and detective controls identify violations.
[WGU D430 Objective: Security Controls]
6. How can an operating system be hardened using the principle of least privilege?
A. Enable all services
B. Grant admin rights to all users
C. Restrict account permissions
D. Install unnecessary software
Rationale: Least privilege limits access to only what is needed, reducing risk by
restricting account permissions. [WGU D430 Objective: System Hardening]
7. A web server allows sales staff to read product data and update profiles. What
permissions align with least privilege?
A. Read and limited write access
B. Full read and write access
C. Write-only access
D. Read-only access
Rationale: Sales staff need read access for product data and limited write access for
profiles, adhering to least privilege. [WGU D430 Objective: Access Control]
8. How should confidential personnel records be protected using least privilege?
A. Allow access to executives only
B. Grant access only to those with job-related needs
C. Permit access to all HR staff
D. Require elevated security permissions
Rationale: Least privilege restricts access to only those whose roles require it,
minimizing exposure. [WGU D430 Objective: Access Control]
9. What safeguard prevents malware infection from a recently released application?
A. Install all updates
B. Uninstall unused software
C. Modify default accounts
D. Limit user account privileges
Rationale: Limiting privileges prevents malware from executing with elevated
permissions, reducing impact. [WGU D430 Objective: Malware Mitigation]
10. Which practice reduces the impact of stolen credentials in a breach?
A. Multi-factor authentication (MFA)
B. Network segmentation
C. OS hardening
D. Mutual authentication
Rationale: MFA requires additional verification, mitigating risks from stolen credentials.
[WGU D430 Objective: Authentication]
, 3
11. What is the primary goal of the risk management process?
A. Eliminate all vulnerabilities
B. Reduce risk to acceptable levels
C. Implement all possible controls
D. Identify all threats
Rationale: Risk management balances risk reduction with cost and feasibility, aiming for
acceptable levels. [WGU D430 Objective: Risk Management]
12. Which attack type most commonly affects the integrity principle of the CIA triad?
A. Interception
B. Modification
C. Denial-of-service
D. Fabrication
Rationale: Modification attacks alter data, directly impacting integrity. [WGU D430
Objective: CIA Triad]
13. What tool is best used to identify open ports on a network device?
A. Packet sniffer
B. Port scanner
C. Firewall
D. Intrusion prevention system
Rationale: Port scanners detect open ports, identifying potential entry points. [WGU
D430 Objective: Network Security Tools]
14. Which cryptographic method uses a single key for encryption and decryption?
A. Symmetric encryption
B. Asymmetric encryption
C. Hashing
D. Digital signatures
Rationale: Symmetric encryption uses one shared key, unlike symmetric or hashing
methods. [WGU D430 Objective: Cryptography]
15. What is the role of a digital signature in information security?
A. Encrypt data
B. Verify sender identity and data integrity
C. Provide availability
D. Ensure confidentiality
Rationale: Digital signatures authenticate the sender and confirm data has not been
altered. [WGU D430 Objective: Cryptography]
16. Which access control model allows the resource owner to set permissions?
A. Mandatory Access Control (MAC)
B. Discretionary Access Control (DAC)
C. Role-Based Access Control (RBAC)
D. Attribute-Based Access Control (ABAC)
Rationale: DAC gives owners control over access permissions, unlike other models.
[WGU D430 Objective: Access Control Models]
17. What is the first step in the incident response process?
A. Containment
B. Eradication
C. Preparation
, 4
D. Recovery
Rationale: Preparation involves planning and training to handle incidents effectively.
[WGU D430 Objective: Incident Response]
18. Which control type detects unauthorized access after it occurs?
A. Preventive
B. Detective
C. Deterrent
D. Corrective
Rationale: Detective controls, like logs, identify incidents after they happen. [WGU
D430 Objective: Security Controls]
19. What is the primary purpose of a network intrusion detection system (NIDS)?
A. Block malicious traffic
B. Monitor and alert on suspicious activity
C. Encrypt network data
D. Authenticate users
Rationale: NIDS monitors traffic for malicious patterns and alerts administrators. [WGU
D430 Objective: Intrusion Detection]
20. Which risk management strategy involves accepting a risk without mitigation?
A. Avoidance
B. Acceptance
C. Mitigation
D. Transference
Rationale: Acceptance acknowledges a risk but takes no action, often for low-impact
risks. [WGU D430 Objective: Risk Management]
21. What is the purpose of vulnerability assessments?
A. Identify weaknesses in systems
B. Encrypt sensitive data
C. Authenticate users
D. Monitor network traffic
Rationale: Vulnerability assessments scan for weaknesses that could be exploited.
[WGU D430 Objective: Vulnerability Management]
22. Which law requires companies to maintain accurate financial records?
A. HIPAA
B. Sarbanes-Oxley Act (SOX)
C. GDPR
D. PCI DSS
Rationale: SOX mandates financial transparency and accountability for public
companies. [WGU D430 Objective: Regulatory Compliance]
23. What is the primary function of a firewall in a network?
A. Detect intrusions
B. Filter network traffic
C. Encrypt data
D. Authenticate users
Rationale: Firewalls control traffic based on rules, allowing or blocking packets. [WGU
D430 Objective: Network Security]
Test Bank for WGU D430 Fundamentals of
Information Security 2025 – 100% Verified
Questions and Detailed Correct Answers |
Objective Assessment | Graded A+
1. A company wants to restrict hourly employees from accessing systems after business
hours. Which access control model is most suitable?
A. Mandatory Access Control (MAC)
B. Discretionary Access Control (DAC)
C. Role-Based Access Control (RBAC)
D. Attribute-Based Access Control (ABAC)
Rationale: ABAC uses attributes (e.g., time of day, user role) to enforce access policies,
aligning with the need to restrict access based on business hours. MAC is too rigid, DAC
is owner-controlled, and RBAC is role-focused without dynamic attributes. [WGU D430
Objective: Access Control Models]
2. Which principle of the CIA triad is most affected by a ransomware attack that encrypts
critical files?
A. Availability
B. Confidentiality
C. Integrity
D. Accountability
Rationale: Ransomware prevents access to data, primarily impacting availability.
Confidentiality may be secondary if data is exfiltrated, but the core issue is access denial.
[WGU D430 Objective: CIA Triad]
3. What is the primary purpose of implementing a honeypot in a network?
A. Block unauthorized access
B. Detect and analyze malicious activity
C. Encrypt sensitive data
D. Authenticate users
Rationale: A honeypot is a decoy system designed to attract attackers, allowing security
teams to monitor and analyze their behavior. [WGU D430 Objective: Intrusion
Detection]
4. A new software company stores proprietary algorithms on a server. Which method best
protects against unauthorized disclosure?
A. Store on highly available servers
B. Transfer to a demilitarized zone (DMZ)
C. Use encrypted storage
D. Create off-site backups
Rationale: Encryption ensures data confidentiality, protecting against unauthorized
access even if the server is compromised. DMZ and backups address other concerns.
[WGU D430 Objective: Data Protection]
, 2
5. Which type of control is a policy that threatens termination for accessing unauthorized
customer data?
A. Deterrent
B. Preventive
C. Detective
D. Corrective
Rationale: A deterrent control discourages violations through consequences, like
termination. Preventive controls block actions, and detective controls identify violations.
[WGU D430 Objective: Security Controls]
6. How can an operating system be hardened using the principle of least privilege?
A. Enable all services
B. Grant admin rights to all users
C. Restrict account permissions
D. Install unnecessary software
Rationale: Least privilege limits access to only what is needed, reducing risk by
restricting account permissions. [WGU D430 Objective: System Hardening]
7. A web server allows sales staff to read product data and update profiles. What
permissions align with least privilege?
A. Read and limited write access
B. Full read and write access
C. Write-only access
D. Read-only access
Rationale: Sales staff need read access for product data and limited write access for
profiles, adhering to least privilege. [WGU D430 Objective: Access Control]
8. How should confidential personnel records be protected using least privilege?
A. Allow access to executives only
B. Grant access only to those with job-related needs
C. Permit access to all HR staff
D. Require elevated security permissions
Rationale: Least privilege restricts access to only those whose roles require it,
minimizing exposure. [WGU D430 Objective: Access Control]
9. What safeguard prevents malware infection from a recently released application?
A. Install all updates
B. Uninstall unused software
C. Modify default accounts
D. Limit user account privileges
Rationale: Limiting privileges prevents malware from executing with elevated
permissions, reducing impact. [WGU D430 Objective: Malware Mitigation]
10. Which practice reduces the impact of stolen credentials in a breach?
A. Multi-factor authentication (MFA)
B. Network segmentation
C. OS hardening
D. Mutual authentication
Rationale: MFA requires additional verification, mitigating risks from stolen credentials.
[WGU D430 Objective: Authentication]
, 3
11. What is the primary goal of the risk management process?
A. Eliminate all vulnerabilities
B. Reduce risk to acceptable levels
C. Implement all possible controls
D. Identify all threats
Rationale: Risk management balances risk reduction with cost and feasibility, aiming for
acceptable levels. [WGU D430 Objective: Risk Management]
12. Which attack type most commonly affects the integrity principle of the CIA triad?
A. Interception
B. Modification
C. Denial-of-service
D. Fabrication
Rationale: Modification attacks alter data, directly impacting integrity. [WGU D430
Objective: CIA Triad]
13. What tool is best used to identify open ports on a network device?
A. Packet sniffer
B. Port scanner
C. Firewall
D. Intrusion prevention system
Rationale: Port scanners detect open ports, identifying potential entry points. [WGU
D430 Objective: Network Security Tools]
14. Which cryptographic method uses a single key for encryption and decryption?
A. Symmetric encryption
B. Asymmetric encryption
C. Hashing
D. Digital signatures
Rationale: Symmetric encryption uses one shared key, unlike symmetric or hashing
methods. [WGU D430 Objective: Cryptography]
15. What is the role of a digital signature in information security?
A. Encrypt data
B. Verify sender identity and data integrity
C. Provide availability
D. Ensure confidentiality
Rationale: Digital signatures authenticate the sender and confirm data has not been
altered. [WGU D430 Objective: Cryptography]
16. Which access control model allows the resource owner to set permissions?
A. Mandatory Access Control (MAC)
B. Discretionary Access Control (DAC)
C. Role-Based Access Control (RBAC)
D. Attribute-Based Access Control (ABAC)
Rationale: DAC gives owners control over access permissions, unlike other models.
[WGU D430 Objective: Access Control Models]
17. What is the first step in the incident response process?
A. Containment
B. Eradication
C. Preparation
, 4
D. Recovery
Rationale: Preparation involves planning and training to handle incidents effectively.
[WGU D430 Objective: Incident Response]
18. Which control type detects unauthorized access after it occurs?
A. Preventive
B. Detective
C. Deterrent
D. Corrective
Rationale: Detective controls, like logs, identify incidents after they happen. [WGU
D430 Objective: Security Controls]
19. What is the primary purpose of a network intrusion detection system (NIDS)?
A. Block malicious traffic
B. Monitor and alert on suspicious activity
C. Encrypt network data
D. Authenticate users
Rationale: NIDS monitors traffic for malicious patterns and alerts administrators. [WGU
D430 Objective: Intrusion Detection]
20. Which risk management strategy involves accepting a risk without mitigation?
A. Avoidance
B. Acceptance
C. Mitigation
D. Transference
Rationale: Acceptance acknowledges a risk but takes no action, often for low-impact
risks. [WGU D430 Objective: Risk Management]
21. What is the purpose of vulnerability assessments?
A. Identify weaknesses in systems
B. Encrypt sensitive data
C. Authenticate users
D. Monitor network traffic
Rationale: Vulnerability assessments scan for weaknesses that could be exploited.
[WGU D430 Objective: Vulnerability Management]
22. Which law requires companies to maintain accurate financial records?
A. HIPAA
B. Sarbanes-Oxley Act (SOX)
C. GDPR
D. PCI DSS
Rationale: SOX mandates financial transparency and accountability for public
companies. [WGU D430 Objective: Regulatory Compliance]
23. What is the primary function of a firewall in a network?
A. Detect intrusions
B. Filter network traffic
C. Encrypt data
D. Authenticate users
Rationale: Firewalls control traffic based on rules, allowing or blocking packets. [WGU
D430 Objective: Network Security]