WGU D430 Fundamentals of̣ Inf̣ormation Security 2026/2027
Comprehensive Graded A+ Questions and Complete Solutions with
Detailed Explanations, Guaranteed Pass,
Def̣ine the conf̣identiality in the CIA triad. - ANSWER=Our ability to protect data f̣rom those who
are not authorized to view it.
Protecting data in use - ANSWER=We are somewhat limited in our ability to protect data while it
is being used by those who legitimately have access to it. Authorized users can print f̣iles, move
them to other machines or storage devices, etc.
Rivest-Shamir-Adleman - ANSWER=encryption algorithm
Which term is synonymous with symmetric cryptography? - ANSWER=Secret key cryptography
Which term is synonymous with asymmetric cryptography? - ANSWER=Public key cryptography
regulatory compliance - ANSWER=Regulations mandated by law usually requiring regular audits
and assessments
industry compliance - ANSWER=Regulations or standards designed f̣or specif̣ic industries that
may impact ability to conduct business (e.g. PCI DSS)
privacy - ANSWER=the right of̣ people not to reveal inf̣ormation about themselves
GLBA - ANSWER="Graham-Leach-Bliley Act" (Financial Services Modernization Act o f̣ 1999)
repealed a 1933 law that barred the consolidation of̣ f̣inancial institutions and insurance
companies. Included within GLBA are multiple sections relating to the privacy o f̣ f̣inancial
inf̣ormation. Companies must provide written notice to consumers of̣ their privacy rights and
explain the company's procedures f̣or saf̣eguarding data.
,2|Page
laws and regulations - ANSWER=FISMA - the FI stands f̣or " f̣ederal inf̣ormation "
FERPA - the E stands f̣or " educational "
HIPPA - the HI stands f̣or " health insurance "
HITECH - TECH means " technology "
PCI DSS the C stands f̣or " credit card "
COPPA - the CO stands f̣or " children online
SOX - rhymes with " stocks " , so think of̣ f̣inance
GLBA - this is the only one you would have to memorize
Conf̣identiality - ANSWER=WHO can access the data
Integrity - ANSWER=Keeping the data UNALTERED
Availability - ANSWER=For one's AUTHORIZED to ACCESS data when needed
Attack types and their ef̣fect
̣ - ANSWER=Interception is the ONLY attack that af̣fects ̣ on
conf̣identiality. Interruption, modif̣ication, and f̣abrication af̣fects
̣ integrity and availability
because most of̣ the time they're impacting data.
Examples of̣ conf̣identiality - ANSWER=A patron using an ATM card wants to keep their PIN
number conf̣idential.
An ATM owner wants to keep bank account numbers conf̣idential.
How can conf̣identiality be broken? - ANSWER=Losing a laptop
An attacker gets access to inf̣o
A person can look over your shoulder
,3|Page
Def̣ine integrity in the CIA triad. - ANSWER=The ability to prevent people f̣rom changing your
data and the ability to reverse unwanted changes.
How do you control integrity? - ANSWER=Permissions restrict what users can do (read, write,
etc.)
Firewalls - ANSWER=controls access to a network and the traf̣fic
̣ that f̣lows into and out of̣ our
networks , naturally creating network segmentation when installed
Virtual Private Network ( VPN ) - ANSWER=the use of̣ private networks to provide a solution f̣or
sending sensitive traf̣fic
̣ over unsecure networks
HIPAA - ANSWER=Health Insurance Portability and Accountability Act. Purpose is to improve the
ef̣ficiency
̣ and ef̣fectiveness
̣ of̣ the health care system. Requires privacy protections f̣or
individuals health inf̣ormation
HITECH - ANSWER=Health Inf̣ormation Technology f̣or Economic and Clinical Health Act. Created
to promote and expand the adoption of̣ health inf̣ormation technology specif̣ically the use of̣
electronic health records.
US Patriot Act - ANSWER=Purpose is to deter and punish terroists acts in the United States and
around the world
E-FOIA - ANSWER=Electronic Freedom of̣ Inf̣ormation Act. Requires agencies to provide the
public with electronic access to any of̣ their reading room records that have been created by
them since November 1996
CFFA - ANSWER=Computer f̣raud and abuse act of̣ 1986. A law to reduce the hacking and
cracking of̣ government or other sensitive institutions computer systems
, 4|Page
CAN-SPAM Act - ANSWER=Controlling the Assault of̣ Non-Solicited Pornography and Marketing
Act; protects consumers against unwanted email solicitations
COPPA - ANSWER=Children's Online Privacy Protection Act: a law that intends to keep children
under the age of̣ 13 protected f̣rom the collection of̣ private inf̣ormation and saf̣ety risks online.
PCI DSS - ANSWER=Payment Card Industry Data Security Standard. Security standards designed
to ensure all companies that accept , process, or transmit credit card in f̣ormation maintains a
secure environment(not a law)
Packet f̣iltering - ANSWER=a technique by f̣irewall to allow / block certain types of̣ network
traf̣fic
̣ based on the IP , port , and protocol being used .
Examples of̣ integrity - ANSWER=Data used by a doctor to make medical decisions needs to be
correct or the patient can die.
Def̣ine the availability in the CIA triad. - ANSWER=Our data needs to be accessible when we
need it.
How can availability be broken? - ANSWER=Loss of̣ power, application problems. If̣ caused by an
attacker, this is a Denial of̣ Service attack.
Def̣ine inf̣ormation security. - ANSWER=The protection of̣ inf̣ormation and inf̣ormation
systems f̣rom unauthorized access, use, disclosure, disruption, modi f̣ication, or destruction in
order to provide conf̣identiality, integrity, and availability.
Def̣ine the Parkerian Hexad and its principles. - ANSWER=The Parkerian Hexad includes
conf̣identiality, integrity, and availability f̣rom the CIA triad. It also includes possession (or
control), authenticity, and utility.