Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 56 páginas
Examen

WGU C836 Fundamentals of Information Security Final Exam 2025–2026 | WGU C836 OA Real Exam-Style Q&A | Latest Updated Study Guide with Verified Correct Answers

Document preview thumbnail
Vista previa 4 fuera de 56 páginas

Prepare confidently for the WGU C836 Objective Assessment (OA) with this fully updated 2025–2026 study guide featuring realistic, exam-style multiple-choice questions with verified correct answers and clear rationales. This guide is designed to mirror the structure, difficulty level, and competency focus of the WGU C836 Fundamentals of Information Security final exam. Key topics covered include: • CIA triad (Confidentiality, Integrity, Availability) • Principle of Least Privilege • Access control models • Authentication vs. authorization • Risk management and mitigation strategies • Malware types (virus, worm, ransomware, Trojan) • Phishing and social engineering attacks • Denial of Service (DoS) and Distributed DoS attacks • Encryption basics and cryptography fundamentals • Network security controls and firewalls • Security policies and governance • Incident response fundamentals Each question includes a concise rationale to reinforce understanding and strengthen critical thinking — not just memorization. Ideal for WGU students preparing for C836 OA who want structured review, high-yield content, and realistic practice before scheduling their exam. Instant digital download. Organized. Focused. Exam-ready.

Vista previa del contenido

WGU C836 FUndamentals oF InFormatIon seCUrIty
FInal exam QUestIons and ansWers 2025–2026 |
WGU C836 oa real exam-style Q&a | latest
Updated stUdy GUIde WIth VerIFIed CorreCt
ansWers

Sample Exam Questions



1. Which of the following is a primary goal of information security?
• A) Increase software functionality
• B) Triple data storage capacity

• C) Maintain data confidentiality

• D) Enhance system usability

Correct Option: C) Maintain data confidentiality

Rationale: The primary goals of information security generally focus on ensuring
confidentiality, integrity, and availability of data. Confidentiality involves protecting information
from unauthorized access.



2. What is the principle of least privilege?

• A) Users should have all privileges for usability

• B) Users are granted only the minimum level of access necessary
• C) Access is revoked after completion of tasks

• D) Privileges are determined by IT professionals only

Correct Option: B) Users are granted only the minimum level of access necessary

Rationale: The principle of least privilege is a security practice that restricts user access rights to
the bare minimum permissions they need to perform their job functions.



3. Which type of attack involves overwhelming a system with traffic to render it unusable?
• A) Phishing

• B) Denial of Service (DoS)

,WGU C836 FUndamentals oF InFormatIon seCUrIty
FInal exam QUestIons and ansWers 2025–2026 |
WGU C836 oa real exam-style Q&a | latest
Updated stUdy GUIde WIth VerIFIed CorreCt
ansWers

• C) Man-in-the-Middle

• D) SQL Injection

Correct Option: B) Denial of Service (DoS)
Rationale: A Denial of Service attack aims to make a machine or network resource unavailable
by overwhelming it with a flood of illegitimate requests.


4. What is the purpose of encryption in data security?

• A) To protect data confidentiality during transmission

• B) To improve data integrity

• C) To enhance data accessibility

• D) To expedite data processing speed

Correct Option: A) To protect data confidentiality during transmission

Rationale: Encryption serves to protect the confidentiality of data by transforming it into a
format that is unreadable without the corresponding decryption key.


5. Which standard focuses on managing and protecting sensitive data?

• A) HIPAA

• B) PCI DSS

• C) NIST SP 800-53

• D) ISO 27001

Correct Option: B) PCI DSS

Rationale: The Payment Card Industry Data Security Standard (PCI DSS) is a set of security
standards designed to ensure that companies that accept, process, store, or transmit credit card
information maintain a secure environment.

,WGU C836 FUndamentals oF InFormatIon seCUrIty
FInal exam QUestIons and ansWers 2025–2026 |
WGU C836 oa real exam-style Q&a | latest
Updated stUdy GUIde WIth VerIFIed CorreCt
ansWers

6. Which of the following is a common method for preventing unauthorized access to a
network?

• A) Firewalls

• B) Intrusion Detection Systems (IDS)

• C) Access Control Lists (ACLs)
• D) Network Protocols

Correct Option: C) Access Control Lists (ACLs)

Rationale: ACLs help define who can access certain resources in a network, enforcing security
by allowing only authorized users or systems.



7. What does HTTPS stand for?

• A) Hypertext Transfer Protocol Standard

• B) Hypertext Transfer Protocol Secure

• C) Hypertext Transfer Privacy Standard

• D) Hypertext Transfer Protocol Secure Layer
Correct Option: B) Hypertext Transfer Protocol Secure

Rationale: HTTPS is the secure version of HTTP, which encrypts the data exchanged to protect
against interception.


8. A company experiences a data breach. Which of the following is the first action they
should take?

• A) Inform customers

• B) Contain the breach
• C) Identify the attack vector

, WGU C836 FUndamentals oF InFormatIon seCUrIty
FInal exam QUestIons and ansWers 2025–2026 |
WGU C836 oa real exam-style Q&a | latest
Updated stUdy GUIde WIth VerIFIed CorreCt
ansWers

• D) Restore data from backup

Correct Option: B) Contain the breach

Rationale: Containment should be the first step to prevent further data loss or damage.


9. What is a strong password policy likely to include?

• A) At least 5 characters

• B) A mix of letters, numbers, and symbols

• C) Easy-to-remember words

• D) Use of personal information

Correct Option: B) A mix of letters, numbers, and symbols
Rationale: A strong password combines various character types to enhance security, making it
much harder to guess or crack.


10. Which of the following is considered a social engineering attack?
• A) DDoS

• B) Pretexting

• C) SQL Injection

• D) Trojan Horse

Correct Option: B) Pretexting

Rationale: Pretexting involves creating a fabricated scenario to obtain information from a target,
often used in social engineering attacks.


11. What does MFA stand for in cybersecurity?

Información del documento

Subido en
25 de febrero de 2026
Número de páginas
56
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$13.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Vendido
308
Seguidores
37
Artículos
7743
Última venta
6 días hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes