100% de satisfacción garantizada Inmediatamente disponible después del pago Tanto en línea como en PDF No estas atado a nada 4,6 TrustPilot
logo-home
Examen

WGU D430 Fundamentals of Information Security OA Actual Exam 2026 | Questions with Verified Answers | 100% Correct | Pass Guaranteed

Puntuación
-
Vendido
-
Páginas
12
Grado
A+
Subido en
06-01-2026
Escrito en
2025/2026

WGU D430 Fundamentals of Information Security OA Actual Exam 2026 | Questions with Verified Answers | 100% Correct | Pass Guaranteed

Institución
WGU D430
Grado
WGU D430









Ups! No podemos cargar tu documento ahora. Inténtalo de nuevo o contacta con soporte.

Escuela, estudio y materia

Institución
WGU D430
Grado
WGU D430

Información del documento

Subido en
6 de enero de 2026
Número de páginas
12
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas

Temas

Vista previa del contenido

WGU D430 Fundamentals of Information Security OA
Actual Exam 2026 | Questions with Verified Answers |
100% Correct | Pass Guaranteed

SECTION 1: Security Concepts & Governance
Q1: Which primary goal of the CIA triad is violated when a database record is modified by an
unauthorized user?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Correct Answer: B
Rationale: Integrity ensures that data remains accurate and unaltered without authorization;
unauthorized modification directly violates this principle. Confidentiality (A) is concerned with
disclosure, not alteration. Availability (C) relates to timely access. Non-repudiation (D) prevents
denial of an action but does not address data alteration.
Q2: A company must decide whether to accept, transfer, mitigate, or avoid a risk with an
annualized loss expectancy (ALE) of $45,000 and mitigation cost of $60,000. Which risk
response is MOST aligned with NIST SP 800-30 guidance?
A. Accept the risk
B. Transfer the risk
C. Avoid the risk
D. Mitigate the risk
Correct Answer: A
Rationale: When mitigation cost exceeds the ALE, accepting the risk is usually justified unless
regulatory or reputational factors dictate otherwise. Transfer (B) via insurance still costs
premiums near or above ALE. Avoid (C) would eliminate the asset/process, which is extreme.
Mitigate (D) is uneconomical here.
Q3: Which governance document is MOST appropriate for high-level statements such as “All
customer PII must be encrypted at rest”?
A. Policy
B. Standard
C. Procedure
D. Guideline
Correct Answer: A
Rationale: Policies are executive-level documents that set mandatory requirements. Standards
(B) define specific technologies or parameters, procedures (C) give step-by-step instructions,
and guidelines (D) are non-mandatory recommendations.

, Q4: The ISO 27001 certification process requires which phase to be completed BEFORE
conducting the Stage 2 audit?
A. Risk assessment
B. Statement of Applicability
C. Management review
D. Stage 1 audit (readiness review)
Correct Answer: D
Rationale: ISO 27001 mandates a Stage 1 readiness review to verify that the ISMS is
sufficiently implemented before the Stage 2 certification audit. Risk assessment (A), SoA (B),
and management review (C) are all required but occur earlier within the ISMS build, not the
certification sequence.
Q5: Which document provides a mapping between NIST SP 800-53 controls and PCI DSS
requirements?
A. NIST SP 800-37 Rev. 2
B. NIST Cybersecurity Framework
C. NIST SP 800-53A
D. NIST Interagency Report (NISTIR) 8097
Correct Answer: B
Rationale: The CSF includes Informative References that map 800-53 controls to sector-specific
standards such as PCI DSS. 800-37 (A) is Risk Management Framework; 800-53A (C) is
assessment guidance; NISTIR 8097 (D) addresses mobile threat catalog, not mappings.
Q6: A startup stores health records in AWS. Which regulation MOST directly requires a
documented Business Associate Agreement (BAA) with AWS?
A. HIPAA
B. HITECH
C. GDPR
D. SOX
Correct Answer: A
Rationale: HIPAA mandates BAAs when a covered entity shares PHI with a cloud provider.
HITECH (B) strengthens HIPAA but does not create new agreement types. GDPR (C) requires
data-processing agreements, not BAAs. SOX (D) focuses on financial reporting.
Q7: In quantitative risk analysis, which variable is multiplied by Exposure Factor to derive Single
Loss Expectancy (SLE)?
A. Annualized Rate of Occurrence (ARO)
B. Asset Value (AV)
C. Safeguard cost
D. Residual risk
Correct Answer: B
Rationale: SLE = AV × EF. ARO (A) is used later to compute ALE. Safeguard cost (C) and
residual risk (D) are not components of SLE.
Q8: Which of the following BEST exemplifies the concept of “due care” from a legal
perspective?
A. Installing the latest firewall after a breach
B. Performing annual penetration tests aligned with industry norms
$15.99
Accede al documento completo:

100% de satisfacción garantizada
Inmediatamente disponible después del pago
Tanto en línea como en PDF
No estas atado a nada

Conoce al vendedor
Seller avatar
TommyRicks

Conoce al vendedor

Seller avatar
TommyRicks Chamberlain College Of Nursing
Seguir Necesitas iniciar sesión para seguir a otros usuarios o asignaturas
Vendido
Nuevo en Stuvia
Miembro desde
1 mes
Número de seguidores
0
Documentos
480
Última venta
-
TommyRicks

One stop shop for all all study materials, Study guides,Exams and all assignments and homeworks.

0.0

0 reseñas

5
0
4
0
3
0
2
0
1
0

Recientemente visto por ti

Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes