1
WGU C724 Information
Systems Management Final
Exam (2025/2026)
Cybersecurity (15 Questions)
1. What is the primary purpose of a firewall in a network security system?
A. To encrypt data transmissions
B. To filter incoming and outgoing network traffic
C. To store user credentials securely
D. To monitor employee internet usage
Correct Answer: B. To filter incoming and outgoing network traffic
Explanation: A firewall acts as a barrier between a trusted internal network and
untrusted external networks, filtering traffic based on predefined rules to prevent
unauthorized access and cyber threats.
2. Which type of cyberattack involves overwhelming a system with excessive traffic?
A. Phishing
B. Malware
C. Denial-of-Service (DoS)
D. Man-in-the-Middle (MitM)
Correct Answer: C. Denial-of-Service (DoS)
Explanation: A DoS attack floods a system with traffic to disrupt its availability,
preventing legitimate users from accessing services.
3. What is a key component of an effective cybersecurity policy?
A. Allowing unrestricted software downloads
B. Regular employee training on security practices
C. Disabling multi-factor authentication
D. Storing passwords in plain text
Correct Answer: B. Regular employee training on security practices
Explanation: Employee training ensures awareness of security threats, such as phishing,
and promotes adherence to best practices, reducing human error as a vulnerability.
4. Which encryption method uses the same key for both encryption and decryption?
A. Asymmetric encryption
B. Symmetric encryption
C. Hashing
D. Digital signatures
Correct Answer: B. Symmetric encryption
Explanation: Symmetric encryption uses a single key for both encryption and
decryption, offering efficiency but requiring secure key management.
, 2
5. What is the purpose of a vulnerability assessment in cybersecurity?
A. To install software updates
B. To identify and prioritize security weaknesses
C. To encrypt sensitive data
D. To monitor network traffic
Correct Answer: B. To identify and prioritize security weaknesses
Explanation: A vulnerability assessment scans systems to detect weaknesses, such as
outdated software, allowing organizations to prioritize remediation efforts.
6. Which of the following is a common social engineering tactic?
A. SQL injection
B. Phishing emails
C. Brute force attacks
D. Packet sniffing
Correct Answer: B. Phishing emails
Explanation: Phishing emails trick users into revealing sensitive information or clicking
malicious links, exploiting human psychology rather than technical vulnerabilities.
7. What does a Chief Information Security Officer (CISO) primarily oversee?
A. Software development
B. Cybersecurity strategy and policies
C. Hardware maintenance
D. Customer relationship management
Correct Answer: B. Cybersecurity strategy and policies
Explanation: The CISO is responsible for developing and implementing an
organization’s cybersecurity strategy to protect data and systems.
8. Which protocol ensures secure data transmission over the internet?
A. HTTP
B. FTP
C. HTTPS
D. SMTP
Correct Answer: C. HTTPS
Explanation: HTTPS uses SSL/TLS encryption to secure data transmitted between a
user’s browser and a website, ensuring confidentiality and integrity.
9. What is the first step in responding to a data breach?
A. Notify the public immediately
B. Contain the breach to limit damage
C. Ignore minor incidents
D. Restore all systems
Correct Answer: B. Contain the breach to limit damage
Explanation: Containment, such as isolating affected systems, is critical to prevent
further data loss or system compromise during a breach.
10. Which cybersecurity framework provides guidelines for protecting critical
infrastructure?
A. ISO 9001
B. NIST Cybersecurity Framework
C. COBIT
D. ITIL
WGU C724 Information
Systems Management Final
Exam (2025/2026)
Cybersecurity (15 Questions)
1. What is the primary purpose of a firewall in a network security system?
A. To encrypt data transmissions
B. To filter incoming and outgoing network traffic
C. To store user credentials securely
D. To monitor employee internet usage
Correct Answer: B. To filter incoming and outgoing network traffic
Explanation: A firewall acts as a barrier between a trusted internal network and
untrusted external networks, filtering traffic based on predefined rules to prevent
unauthorized access and cyber threats.
2. Which type of cyberattack involves overwhelming a system with excessive traffic?
A. Phishing
B. Malware
C. Denial-of-Service (DoS)
D. Man-in-the-Middle (MitM)
Correct Answer: C. Denial-of-Service (DoS)
Explanation: A DoS attack floods a system with traffic to disrupt its availability,
preventing legitimate users from accessing services.
3. What is a key component of an effective cybersecurity policy?
A. Allowing unrestricted software downloads
B. Regular employee training on security practices
C. Disabling multi-factor authentication
D. Storing passwords in plain text
Correct Answer: B. Regular employee training on security practices
Explanation: Employee training ensures awareness of security threats, such as phishing,
and promotes adherence to best practices, reducing human error as a vulnerability.
4. Which encryption method uses the same key for both encryption and decryption?
A. Asymmetric encryption
B. Symmetric encryption
C. Hashing
D. Digital signatures
Correct Answer: B. Symmetric encryption
Explanation: Symmetric encryption uses a single key for both encryption and
decryption, offering efficiency but requiring secure key management.
, 2
5. What is the purpose of a vulnerability assessment in cybersecurity?
A. To install software updates
B. To identify and prioritize security weaknesses
C. To encrypt sensitive data
D. To monitor network traffic
Correct Answer: B. To identify and prioritize security weaknesses
Explanation: A vulnerability assessment scans systems to detect weaknesses, such as
outdated software, allowing organizations to prioritize remediation efforts.
6. Which of the following is a common social engineering tactic?
A. SQL injection
B. Phishing emails
C. Brute force attacks
D. Packet sniffing
Correct Answer: B. Phishing emails
Explanation: Phishing emails trick users into revealing sensitive information or clicking
malicious links, exploiting human psychology rather than technical vulnerabilities.
7. What does a Chief Information Security Officer (CISO) primarily oversee?
A. Software development
B. Cybersecurity strategy and policies
C. Hardware maintenance
D. Customer relationship management
Correct Answer: B. Cybersecurity strategy and policies
Explanation: The CISO is responsible for developing and implementing an
organization’s cybersecurity strategy to protect data and systems.
8. Which protocol ensures secure data transmission over the internet?
A. HTTP
B. FTP
C. HTTPS
D. SMTP
Correct Answer: C. HTTPS
Explanation: HTTPS uses SSL/TLS encryption to secure data transmitted between a
user’s browser and a website, ensuring confidentiality and integrity.
9. What is the first step in responding to a data breach?
A. Notify the public immediately
B. Contain the breach to limit damage
C. Ignore minor incidents
D. Restore all systems
Correct Answer: B. Contain the breach to limit damage
Explanation: Containment, such as isolating affected systems, is critical to prevent
further data loss or system compromise during a breach.
10. Which cybersecurity framework provides guidelines for protecting critical
infrastructure?
A. ISO 9001
B. NIST Cybersecurity Framework
C. COBIT
D. ITIL