WGU D330 Introduction to
Cryptography Objective Assessment
(OA) Final Exam 2026/2027:
Advanced Study Manual for
Cryptographic Algorithms,
Authentication, and Network
Security
Question 1:
Which attack type most commonly impacts the CIA triad principles of integrity and
availability?
A. Interception
B. Modification
C. Fabrication
D. Interruption
Correct Answer: B. Modification
Rationale: Modification attacks involve altering data, system configurations, or
communication content, directly violating integrity. They may also affect availability
if altered systems become unusable or unstable. Interception primarily affects
confidentiality, while interruption affects availability. Fabrication introduces false
data but does not necessarily disrupt system availability or integrity as directly as
modification does.
Question 2:
Which principle of the CIA triad is most affected by an interception attack?
A. Integrity
B. Availability
C. Confidentiality
D. Authentication
Correct Answer: C. Confidentiality
,2026/2027
Rationale: Interception attacks involve unauthorized access to data during
transmission or storage, such as eavesdropping or packet sniffing. This directly
compromises confidentiality because sensitive information is exposed to unauthorized
parties. Integrity and availability are not primarily impacted because the data is not
altered or disrupted.
Question 3:
In information security, something that has the potential to cause harm to assets is
known as a:
A. Risk
B. Vulnerability
C. Impact
D. Threat
Correct Answer: D. Threat
Rationale: A threat is any potential cause of harm to an asset, such as malware,
hackers, or natural disasters. A vulnerability is a weakness, risk is the likelihood of
harm occurring, and impact refers to the consequences if the threat is realized.
Question 4:
Controls that protect systems, networks, and environments that process, transmit, and
store data are called:
A. Physical controls
B. Administrative controls
C. Logical controls
D. Operational controls
Correct Answer: C. Logical controls
Rationale: Logical controls (also known as technical controls) include firewalls,
encryption, authentication systems, and access controls that protect digital
environments. Physical controls protect facilities, and administrative controls involve
policies and procedures.
Question 5:
What is the first step in the risk management process?
A. Identify threats
B. Assess risks
C. Identify assets
D. Mitigate risks
, 2026/2027
Correct Answer: C. Identify assets
Rationale: The first step in risk management is identifying what needs protection
(assets). Without knowing assets, it is impossible to evaluate threats, vulnerabilities,
or risks properly.
Question 6:
Information security is best defined as:
A. Protecting only confidential data
B. Preventing system downtime
C. Protecting information systems from unauthorized access or modification
D. Encrypting all stored data
Correct Answer: C. Protecting information systems from unauthorized access or
modification
Rationale: Information security includes confidentiality, integrity, and availability
protections against unauthorized access, use, disclosure, disruption, modification, or
destruction.
Question 7:
A weakness that can be exploited by a threat is called a:
A. Risk
B. Vulnerability
C. Threat
D. Exposure
Correct Answer: B. Vulnerability
Rationale: A vulnerability is a weakness in a system, design, or process that can be
exploited by a threat to cause harm.
Question 8:
The likelihood that a harmful event will occur is called:
A. Threat
B. Risk
C. Impact
D. Exposure
Correct Answer: B. Risk