WGU C795 CYBERSECURITY
MANAGEMENT II - TACTICAL
COMPREHENSIVE STUDY GUIDE 2026 FULL
QUESTIONS AND SOLUTIONS GRADED A+
◍ Security Support Personnel.
Answer: Staff who assist security operations and support system
functionality.
◍ is something of value worth protecting..
Answer: A asset
◍ Access controls.
Answer: What control mechanism defines authentication and authorization
protocols for users?
◍ Security Technician.
Answer: A professional who installs and maintains security hardware and
software.
◍ Cybersecurity is a component of information security, Cybersecurity deals
with the protection of digital assets, Cybersecurity should align with
enterprise information security objectives.
Answer: All of the following statements are true:
◍ Incident.
Answer: NIST defines a(n) __________ as a "violation or imminent threat
of violation of computer security policies, acceptable use policies, or
standard security practices."
◍ -providing strategic direction- ensuring that objectives are achieved-
verifying that organizational resources are being used appropriately -
, ascertaining whether risk is being managed . properly.
Answer: Governance has several goals, including:
◍ Risk Severity.
Answer: A combination of likelihood and impact used to determine risk
level.
◍ Guidelines.
Answer: __________ provide general guidance and recommendations on
what to do in particular circumstances.
◍ Containment.
Answer: Which element of an incident response plan involves obtaining and
preserving evidence?
◍ Reasons Security Policies Fail.
Answer: Lack of training, weak ownership, poor communication,
inconsistent enforcement, or outdated policies.
◍ includes many components such as directory services, authentication and
authorization services, and user management capabilities such as
provisioning and deprovisioning..
Answer: Identity Management
◍ Project Management Process - Closing.
Answer: The final phase where the project is completed and documented.
◍ Project Management Process - Execution.
Answer: The phase where project tasks are performed according to the plan.
◍ Risk Transference.
Answer: Shifting risk to another party through insurance, outsourcing, or
contracts.
◍ asset value, criticality, reliability of each control and degree of exposure..
Answer: The number and types of layers needed for defense in depth are a
function of:
◍ - an intruder must penetrate three separate devices- private network
, addresses are not disclosed to the internet- internal systems do not have
direct access to the Internet.
Answer: The key benefits of the DMZ system are:
◍ is a class of malware that hides the existence of other malware by modifying
the underlying operating system..
Answer: Rootkit
◍ Cost Benefit Analysis (CBA).
Answer: A method used to compare the cost of security controls with the
expected reduction in losses.
◍ Examples of Security Awareness Methods.
Answer: Email reminders, posters, login banners, short training modules,
and security campaigns.
◍ Loss of functionality and operational effectiveness, Loss of productive time,
Interference with enterprise's objectives.
Answer: Potential consequences resulting from lack of availability include
◍ communicate required and prohibited activities and behaviors..
Answer: Policies
◍ Risk.
Answer: The potential for loss or damage when a threat exploits a
vulnerability affecting an asset.
◍ are used to interpret policies in specific situations..
Answer: Standards
◍ SecSDLC Physical Design Phase.
Answer: The phase where specific technologies and solutions are selected to
implement the logical design.
◍ Detect and block traffic from infected internal end points, Eliminate threats
such as email spam, viruses and worms, Control user traffic bound toward
the Internet, Monitor and detect network ports for rogue activity..
Answer: The Internet perimeter should
MANAGEMENT II - TACTICAL
COMPREHENSIVE STUDY GUIDE 2026 FULL
QUESTIONS AND SOLUTIONS GRADED A+
◍ Security Support Personnel.
Answer: Staff who assist security operations and support system
functionality.
◍ is something of value worth protecting..
Answer: A asset
◍ Access controls.
Answer: What control mechanism defines authentication and authorization
protocols for users?
◍ Security Technician.
Answer: A professional who installs and maintains security hardware and
software.
◍ Cybersecurity is a component of information security, Cybersecurity deals
with the protection of digital assets, Cybersecurity should align with
enterprise information security objectives.
Answer: All of the following statements are true:
◍ Incident.
Answer: NIST defines a(n) __________ as a "violation or imminent threat
of violation of computer security policies, acceptable use policies, or
standard security practices."
◍ -providing strategic direction- ensuring that objectives are achieved-
verifying that organizational resources are being used appropriately -
, ascertaining whether risk is being managed . properly.
Answer: Governance has several goals, including:
◍ Risk Severity.
Answer: A combination of likelihood and impact used to determine risk
level.
◍ Guidelines.
Answer: __________ provide general guidance and recommendations on
what to do in particular circumstances.
◍ Containment.
Answer: Which element of an incident response plan involves obtaining and
preserving evidence?
◍ Reasons Security Policies Fail.
Answer: Lack of training, weak ownership, poor communication,
inconsistent enforcement, or outdated policies.
◍ includes many components such as directory services, authentication and
authorization services, and user management capabilities such as
provisioning and deprovisioning..
Answer: Identity Management
◍ Project Management Process - Closing.
Answer: The final phase where the project is completed and documented.
◍ Project Management Process - Execution.
Answer: The phase where project tasks are performed according to the plan.
◍ Risk Transference.
Answer: Shifting risk to another party through insurance, outsourcing, or
contracts.
◍ asset value, criticality, reliability of each control and degree of exposure..
Answer: The number and types of layers needed for defense in depth are a
function of:
◍ - an intruder must penetrate three separate devices- private network
, addresses are not disclosed to the internet- internal systems do not have
direct access to the Internet.
Answer: The key benefits of the DMZ system are:
◍ is a class of malware that hides the existence of other malware by modifying
the underlying operating system..
Answer: Rootkit
◍ Cost Benefit Analysis (CBA).
Answer: A method used to compare the cost of security controls with the
expected reduction in losses.
◍ Examples of Security Awareness Methods.
Answer: Email reminders, posters, login banners, short training modules,
and security campaigns.
◍ Loss of functionality and operational effectiveness, Loss of productive time,
Interference with enterprise's objectives.
Answer: Potential consequences resulting from lack of availability include
◍ communicate required and prohibited activities and behaviors..
Answer: Policies
◍ Risk.
Answer: The potential for loss or damage when a threat exploits a
vulnerability affecting an asset.
◍ are used to interpret policies in specific situations..
Answer: Standards
◍ SecSDLC Physical Design Phase.
Answer: The phase where specific technologies and solutions are selected to
implement the logical design.
◍ Detect and block traffic from infected internal end points, Eliminate threats
such as email spam, viruses and worms, Control user traffic bound toward
the Internet, Monitor and detect network ports for rogue activity..
Answer: The Internet perimeter should