WGU MSCSIA C706 CHAPTERS 1 -4
EXAM 2025/2026 QUESTIONS AND
ANSWERS 100% PASS
Confidentiality - ANS means that the private and sensitive data handled by the application
cannot be read by anyone who is not explicitly authorized to view it.
Intregrity - ANS means that the data processed by an application is not modified by any
unauthorized channels or any unauthorized persons.
Availability - ANS the system's ability to remain operational even in the face of failure or
attack.
Cleartext or Plaintext - ANS information that is not encrypted.
Ciphertext - ANS information that is encrypted.
Encryption - ANS in secret key cryptography, a single key is used to run an algorithm to
transform plaintext to ciphertext.
Confusion - ANS states that the key should have a complex relationship to the ciphertext
(i.e., each bit of the key affects as many bits of the ciphertext as possible) to prevent an
attacker from discovering part of the key from the ciphertext.
pg. 1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
, Diffusion - ANS states that the ciphertext should have a complex, nonlinear relationship to
the plaintext (each bit of the plaintext affecting as many bits of the ciphertext as possible) such
that it cannot be exploited by an attacker.
Prevention - ANS the assertion that an attack absolutely cannot happen to or through your
system.
Avoidance - ANS is a best attempt at making sure that attacks do not affect your system.
Scope creep - ANS a software system taking on more and more functionality as it is
developed.
Waterfall mode SDLC - ANS 1. requirements analysis 2. design 3. construction 4. test 5.
installation 6. operation 7. maintenance 8. retirement.
COTS - ANS Commercial Off The Shelf
FOSS - ANS Free Open Source Software
Verification - ANS determination of whether the product is being built correctly; this is the
part that should be done before the product is viewed by customers.
Validation - ANS testing of whether the correct product is being built; this is the testing that
should be conducted by the end users of a system.
Apply defense in depth - ANS make sure there are no holes in your application.
Minimize the attack surface - ANS make sure the only openings in your system are the ones
you want.
pg. 2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
EXAM 2025/2026 QUESTIONS AND
ANSWERS 100% PASS
Confidentiality - ANS means that the private and sensitive data handled by the application
cannot be read by anyone who is not explicitly authorized to view it.
Intregrity - ANS means that the data processed by an application is not modified by any
unauthorized channels or any unauthorized persons.
Availability - ANS the system's ability to remain operational even in the face of failure or
attack.
Cleartext or Plaintext - ANS information that is not encrypted.
Ciphertext - ANS information that is encrypted.
Encryption - ANS in secret key cryptography, a single key is used to run an algorithm to
transform plaintext to ciphertext.
Confusion - ANS states that the key should have a complex relationship to the ciphertext
(i.e., each bit of the key affects as many bits of the ciphertext as possible) to prevent an
attacker from discovering part of the key from the ciphertext.
pg. 1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
, Diffusion - ANS states that the ciphertext should have a complex, nonlinear relationship to
the plaintext (each bit of the plaintext affecting as many bits of the ciphertext as possible) such
that it cannot be exploited by an attacker.
Prevention - ANS the assertion that an attack absolutely cannot happen to or through your
system.
Avoidance - ANS is a best attempt at making sure that attacks do not affect your system.
Scope creep - ANS a software system taking on more and more functionality as it is
developed.
Waterfall mode SDLC - ANS 1. requirements analysis 2. design 3. construction 4. test 5.
installation 6. operation 7. maintenance 8. retirement.
COTS - ANS Commercial Off The Shelf
FOSS - ANS Free Open Source Software
Verification - ANS determination of whether the product is being built correctly; this is the
part that should be done before the product is viewed by customers.
Validation - ANS testing of whether the correct product is being built; this is the testing that
should be conducted by the end users of a system.
Apply defense in depth - ANS make sure there are no holes in your application.
Minimize the attack surface - ANS make sure the only openings in your system are the ones
you want.
pg. 2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED