WGU Lesson 13 Review Activities EXAM
QUESTIONS AND VERIFED CRRECT
ANSWERS GRADED A+ LATEST 2026-
2027 100% GUARANTEED PASS
What type of assessment is most likely to measure security policies and controls against a
standard framework? - CORRECT ANSWER-This can be referred to as posture assessment or risk
assessment.
True or false? An automated vulnerability scanner can be used to detect zero-days. - CORRECT
ANSWER-False - An automated scanner is configured with a list of known vulnerabilities to scan
for. By definition, zero-day vulnerabilities are unknown to the vendor or to security
practitioners. A zero-day is detected either through detailed manual research or because an
exploit is discovered.
What type of assessment tool is configured with details of CVEs? - CORRECT ANSWER-Common
Vulnerabilities and Exposures (CVE) is a dictionary of vulnerabilities in published operating
systems and applications software. An automated vulnerability scanner is configured with
scripts to scan a host for known vulnerabilities.
515web IT staff discovered an entry when reviewing their audit logs showing that a junior
employee from the sales department had logged into the network at 3:00 a.m. Further review
of the audit logs show that he had changed his timecard on the HR server. Which security factor
was breached, and did the attack exploit a software vulnerability or a configuration
vulnerability? - CORRECT ANSWER-The attack compromised the integrity of data stored in the
network. It exploiteda configuration weakness. The employee should not have had permission
toalter the timecard.
, What type of security audit performs active testing of security controls? - CORRECT ANSWER-A
penetration test (pen test).
What element is missing from the following list, and what is its purpose?
Identification
Authentication
Accounting - CORRECT ANSWER-Authorization - assigning privileges over the network object to
the subject.
What is the purpose of SSO? - CORRECT ANSWER-Single Sign-on allows users to authenticate
once to gain access to different resources. This reduces the number of logins a user has to
remember.
True or false? A subject's private key is embedded in the digital certificate that represents its
digital identity? - CORRECT ANSWER-False-the private key must be kept secure and not revealed
to any other party. The public part of the key pair is embedded in the certificate.
What is a RADIUS client, and how should it be configured? - CORRECT ANSWER-False-the
private key must be kept secure and not revealed to any other party. The public part of the key
pair is embedded in the certificate.
Where would EAPoL be configured? - CORRECT ANSWER-On a switch interface/port. A switch
that supports 802.1X port-based access control can enable a port but allow only the transfer of
Extensible Authentication Protocol over LAN (EAPoL) traffic. This allows the client device and/or
user to be authenticated before full network access is granted.
What makes Access Control - CORRECT ANSWER-Allowing- lets us give a particular party access
to a given source
Denying- opposite of gaining access
Limiting- allowing some access to our resource, only up to a certain point
QUESTIONS AND VERIFED CRRECT
ANSWERS GRADED A+ LATEST 2026-
2027 100% GUARANTEED PASS
What type of assessment is most likely to measure security policies and controls against a
standard framework? - CORRECT ANSWER-This can be referred to as posture assessment or risk
assessment.
True or false? An automated vulnerability scanner can be used to detect zero-days. - CORRECT
ANSWER-False - An automated scanner is configured with a list of known vulnerabilities to scan
for. By definition, zero-day vulnerabilities are unknown to the vendor or to security
practitioners. A zero-day is detected either through detailed manual research or because an
exploit is discovered.
What type of assessment tool is configured with details of CVEs? - CORRECT ANSWER-Common
Vulnerabilities and Exposures (CVE) is a dictionary of vulnerabilities in published operating
systems and applications software. An automated vulnerability scanner is configured with
scripts to scan a host for known vulnerabilities.
515web IT staff discovered an entry when reviewing their audit logs showing that a junior
employee from the sales department had logged into the network at 3:00 a.m. Further review
of the audit logs show that he had changed his timecard on the HR server. Which security factor
was breached, and did the attack exploit a software vulnerability or a configuration
vulnerability? - CORRECT ANSWER-The attack compromised the integrity of data stored in the
network. It exploiteda configuration weakness. The employee should not have had permission
toalter the timecard.
, What type of security audit performs active testing of security controls? - CORRECT ANSWER-A
penetration test (pen test).
What element is missing from the following list, and what is its purpose?
Identification
Authentication
Accounting - CORRECT ANSWER-Authorization - assigning privileges over the network object to
the subject.
What is the purpose of SSO? - CORRECT ANSWER-Single Sign-on allows users to authenticate
once to gain access to different resources. This reduces the number of logins a user has to
remember.
True or false? A subject's private key is embedded in the digital certificate that represents its
digital identity? - CORRECT ANSWER-False-the private key must be kept secure and not revealed
to any other party. The public part of the key pair is embedded in the certificate.
What is a RADIUS client, and how should it be configured? - CORRECT ANSWER-False-the
private key must be kept secure and not revealed to any other party. The public part of the key
pair is embedded in the certificate.
Where would EAPoL be configured? - CORRECT ANSWER-On a switch interface/port. A switch
that supports 802.1X port-based access control can enable a port but allow only the transfer of
Extensible Authentication Protocol over LAN (EAPoL) traffic. This allows the client device and/or
user to be authenticated before full network access is granted.
What makes Access Control - CORRECT ANSWER-Allowing- lets us give a particular party access
to a given source
Denying- opposite of gaining access
Limiting- allowing some access to our resource, only up to a certain point