• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 32 pages
Exam (elaborations)

Test Bank for WGU D430 Fundamentals of Information Security 2025 – 100% Verified Questions and Detailed Correct Answers | Objective Assessment | Graded A+

Document preview thumbnail
Preview 4 out of 32 pages

Test Bank for WGU D430 Fundamentals of Information Security 2025 – 100% Verified Questions and Detailed Correct Answers | Objective Assessment | Graded A+

Content preview

1



Test Bank for WGU D430 Fundamentals of
Information Security 2025 – 100% Verified
Questions and Detailed Correct Answers |
Objective Assessment | Graded A+

1. A company wants to restrict hourly employees from accessing systems after business
hours. Which access control model is most suitable?
A. Mandatory Access Control (MAC)
B. Discretionary Access Control (DAC)
C. Role-Based Access Control (RBAC)
D. Attribute-Based Access Control (ABAC)
Rationale: ABAC uses attributes (e.g., time of day, user role) to enforce access policies,
aligning with the need to restrict access based on business hours. MAC is too rigid, DAC
is owner-controlled, and RBAC is role-focused without dynamic attributes. [WGU D430
Objective: Access Control Models]
2. Which principle of the CIA triad is most affected by a ransomware attack that encrypts
critical files?
A. Availability
B. Confidentiality
C. Integrity
D. Accountability
Rationale: Ransomware prevents access to data, primarily impacting availability.
Confidentiality may be secondary if data is exfiltrated, but the core issue is access denial.
[WGU D430 Objective: CIA Triad]
3. What is the primary purpose of implementing a honeypot in a network?
A. Block unauthorized access
B. Detect and analyze malicious activity
C. Encrypt sensitive data
D. Authenticate users
Rationale: A honeypot is a decoy system designed to attract attackers, allowing security
teams to monitor and analyze their behavior. [WGU D430 Objective: Intrusion
Detection]
4. A new software company stores proprietary algorithms on a server. Which method best
protects against unauthorized disclosure?
A. Store on highly available servers
B. Transfer to a demilitarized zone (DMZ)
C. Use encrypted storage
D. Create off-site backups
Rationale: Encryption ensures data confidentiality, protecting against unauthorized
access even if the server is compromised. DMZ and backups address other concerns.
[WGU D430 Objective: Data Protection]

, 2


5. Which type of control is a policy that threatens termination for accessing unauthorized
customer data?
A. Deterrent
B. Preventive
C. Detective
D. Corrective
Rationale: A deterrent control discourages violations through consequences, like
termination. Preventive controls block actions, and detective controls identify violations.
[WGU D430 Objective: Security Controls]
6. How can an operating system be hardened using the principle of least privilege?
A. Enable all services
B. Grant admin rights to all users
C. Restrict account permissions
D. Install unnecessary software
Rationale: Least privilege limits access to only what is needed, reducing risk by
restricting account permissions. [WGU D430 Objective: System Hardening]
7. A web server allows sales staff to read product data and update profiles. What
permissions align with least privilege?
A. Read and limited write access
B. Full read and write access
C. Write-only access
D. Read-only access
Rationale: Sales staff need read access for product data and limited write access for
profiles, adhering to least privilege. [WGU D430 Objective: Access Control]
8. How should confidential personnel records be protected using least privilege?
A. Allow access to executives only
B. Grant access only to those with job-related needs
C. Permit access to all HR staff
D. Require elevated security permissions
Rationale: Least privilege restricts access to only those whose roles require it,
minimizing exposure. [WGU D430 Objective: Access Control]
9. What safeguard prevents malware infection from a recently released application?
A. Install all updates
B. Uninstall unused software
C. Modify default accounts
D. Limit user account privileges
Rationale: Limiting privileges prevents malware from executing with elevated
permissions, reducing impact. [WGU D430 Objective: Malware Mitigation]
10. Which practice reduces the impact of stolen credentials in a breach?
A. Multi-factor authentication (MFA)
B. Network segmentation
C. OS hardening
D. Mutual authentication
Rationale: MFA requires additional verification, mitigating risks from stolen credentials.
[WGU D430 Objective: Authentication]

, 3


11. What is the primary goal of the risk management process?
A. Eliminate all vulnerabilities
B. Reduce risk to acceptable levels
C. Implement all possible controls
D. Identify all threats
Rationale: Risk management balances risk reduction with cost and feasibility, aiming for
acceptable levels. [WGU D430 Objective: Risk Management]
12. Which attack type most commonly affects the integrity principle of the CIA triad?
A. Interception
B. Modification
C. Denial-of-service
D. Fabrication
Rationale: Modification attacks alter data, directly impacting integrity. [WGU D430
Objective: CIA Triad]
13. What tool is best used to identify open ports on a network device?
A. Packet sniffer
B. Port scanner
C. Firewall
D. Intrusion prevention system
Rationale: Port scanners detect open ports, identifying potential entry points. [WGU
D430 Objective: Network Security Tools]
14. Which cryptographic method uses a single key for encryption and decryption?
A. Symmetric encryption
B. Asymmetric encryption
C. Hashing
D. Digital signatures
Rationale: Symmetric encryption uses one shared key, unlike symmetric or hashing
methods. [WGU D430 Objective: Cryptography]
15. What is the role of a digital signature in information security?
A. Encrypt data
B. Verify sender identity and data integrity
C. Provide availability
D. Ensure confidentiality
Rationale: Digital signatures authenticate the sender and confirm data has not been
altered. [WGU D430 Objective: Cryptography]
16. Which access control model allows the resource owner to set permissions?
A. Mandatory Access Control (MAC)
B. Discretionary Access Control (DAC)
C. Role-Based Access Control (RBAC)
D. Attribute-Based Access Control (ABAC)
Rationale: DAC gives owners control over access permissions, unlike other models.
[WGU D430 Objective: Access Control Models]
17. What is the first step in the incident response process?
A. Containment
B. Eradication
C. Preparation

, 4


D. Recovery
Rationale: Preparation involves planning and training to handle incidents effectively.
[WGU D430 Objective: Incident Response]
18. Which control type detects unauthorized access after it occurs?
A. Preventive
B. Detective
C. Deterrent
D. Corrective
Rationale: Detective controls, like logs, identify incidents after they happen. [WGU
D430 Objective: Security Controls]
19. What is the primary purpose of a network intrusion detection system (NIDS)?
A. Block malicious traffic
B. Monitor and alert on suspicious activity
C. Encrypt network data
D. Authenticate users
Rationale: NIDS monitors traffic for malicious patterns and alerts administrators. [WGU
D430 Objective: Intrusion Detection]
20. Which risk management strategy involves accepting a risk without mitigation?
A. Avoidance
B. Acceptance
C. Mitigation
D. Transference
Rationale: Acceptance acknowledges a risk but takes no action, often for low-impact
risks. [WGU D430 Objective: Risk Management]
21. What is the purpose of vulnerability assessments?
A. Identify weaknesses in systems
B. Encrypt sensitive data
C. Authenticate users
D. Monitor network traffic
Rationale: Vulnerability assessments scan for weaknesses that could be exploited.
[WGU D430 Objective: Vulnerability Management]
22. Which law requires companies to maintain accurate financial records?
A. HIPAA
B. Sarbanes-Oxley Act (SOX)
C. GDPR
D. PCI DSS
Rationale: SOX mandates financial transparency and accountability for public
companies. [WGU D430 Objective: Regulatory Compliance]
23. What is the primary function of a firewall in a network?
A. Detect intrusions
B. Filter network traffic
C. Encrypt data
D. Authenticate users
Rationale: Firewalls control traffic based on rules, allowing or blocking packets. [WGU
D430 Objective: Network Security]

Document information

Uploaded on
June 23, 2025
Number of pages
32
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$16.79

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAACTUALEXAMS
3.5
(174)
Sold
1332
Followers
209
Items
10153
Last sold
4 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions