WGU C836 Fundamentals of
Information Security – Western
Governors University (WGU) –
2026/2027 Academic Year –
Comprehensive Objective Assessment
(OA) Review | with complete solutions.
SECTION 1: CORE SECURITY PRINCIPLES
(Questions 1-10)
1. What does the CIA triad in information security stand for?
A) Control, Identity, Authorization
B) Confidentiality, Integrity, Availability
C) Compliance, Inspection, Audit
D) Cryptography, Internet, Access
Answer: B) Confidentiality, Integrity, Availability
Rationale: The CIA triad is the foundation of security principles .
Confidentiality ensures data is accessible only to authorized users, Integrity
ensures data is accurate and unaltered, and Availability ensures systems are
accessible when needed.
Source: WGU C836 Fundamental of Information Security Exam Q&A
,2. Which principle of the CIA triad is being applied when a company
institutes a policy that "All office computer monitors must face
toward employees and must face away from doorways"?
A) Availability
B) Confidentiality
C) Utility
D) Integrity
Answer: B) Confidentiality
Rationale: This policy addresses confidentiality by preventing unauthorized
viewing of sensitive information . Controlling screen visibility is a physical
control to protect data from unauthorized disclosure. This is a classic
example of applying confidentiality principles in the workplace.
Source: WGU C836 200+ Questions Exam Bank, Brian MacFarlane OA
3. At a small company, an employee makes an unauthorized data
alteration. Which component of the CIA triad has been
compromised?
A) Confidentiality
B) Authenticity
C) Integrity
D) Availability
Answer: C) Integrity
,Rationale: Integrity ensures that data is accurate and unaltered . When an
employee makes an unauthorized data alteration, the integrity of the data
has been compromised because the data is no longer accurate or
trustworthy .
Source: WGU C836 Fundamentals of Information Security 200+ Questions,
Docsity
4. A malicious hacker was successful in a denial of service (DoS)
attack against an institution's mail server. Fortunately, no data was
lost or altered while the server was offline. Which type of attack is
this?
A) Modification
B) Fabrication
C) Interception
D) Interruption
Answer: D) Interruption
Rationale: An interruption attack makes a system or resource unavailable .
Since the server was taken offline and made unavailable, this is an
interruption attack. This specifically targets the availability component of the
CIA triad.
Source: WGU Course C836 Fundamentals of Information Security – OA |
200+ Questions, Brian MacFarlane
5. A company has had several successful denial of service (DoS)
attacks on its email server. Which security principle is being
attacked?
A) Possession
B) Integrity
, C) Confidentiality
D) Availability
Answer: D) Availability
Rationale: A Denial of Service (DoS) attack aims to make a machine or
network resource unavailable by overwhelming it with illegitimate requests .
This directly attacks the availability principle of the CIA triad by preventing
legitimate users from accessing the resource .
Source: WGU C836 Exam Prep, Brian MacFarlane OA
6. Which principle of the Parkerian hexad is being addressed when
an auditor asks how a company's most critical data is used to
ensure proper defense mechanisms are in place?
A) Possession
B) Integrity
C) Authenticity
D) Utility
Answer: D) Utility
Rationale: The Parkerian Hexad includes Utility, which refers to how useful
the data is to an organization . Understanding how critical data is used helps
determine what defense mechanisms are needed to protect it effectively.
Utility is distinct from the CIA triad and focuses on the usefulness and value
of data.
Source: WGU C836 Fundamentals of Information Security – OA | 200+
Questions
Information Security – Western
Governors University (WGU) –
2026/2027 Academic Year –
Comprehensive Objective Assessment
(OA) Review | with complete solutions.
SECTION 1: CORE SECURITY PRINCIPLES
(Questions 1-10)
1. What does the CIA triad in information security stand for?
A) Control, Identity, Authorization
B) Confidentiality, Integrity, Availability
C) Compliance, Inspection, Audit
D) Cryptography, Internet, Access
Answer: B) Confidentiality, Integrity, Availability
Rationale: The CIA triad is the foundation of security principles .
Confidentiality ensures data is accessible only to authorized users, Integrity
ensures data is accurate and unaltered, and Availability ensures systems are
accessible when needed.
Source: WGU C836 Fundamental of Information Security Exam Q&A
,2. Which principle of the CIA triad is being applied when a company
institutes a policy that "All office computer monitors must face
toward employees and must face away from doorways"?
A) Availability
B) Confidentiality
C) Utility
D) Integrity
Answer: B) Confidentiality
Rationale: This policy addresses confidentiality by preventing unauthorized
viewing of sensitive information . Controlling screen visibility is a physical
control to protect data from unauthorized disclosure. This is a classic
example of applying confidentiality principles in the workplace.
Source: WGU C836 200+ Questions Exam Bank, Brian MacFarlane OA
3. At a small company, an employee makes an unauthorized data
alteration. Which component of the CIA triad has been
compromised?
A) Confidentiality
B) Authenticity
C) Integrity
D) Availability
Answer: C) Integrity
,Rationale: Integrity ensures that data is accurate and unaltered . When an
employee makes an unauthorized data alteration, the integrity of the data
has been compromised because the data is no longer accurate or
trustworthy .
Source: WGU C836 Fundamentals of Information Security 200+ Questions,
Docsity
4. A malicious hacker was successful in a denial of service (DoS)
attack against an institution's mail server. Fortunately, no data was
lost or altered while the server was offline. Which type of attack is
this?
A) Modification
B) Fabrication
C) Interception
D) Interruption
Answer: D) Interruption
Rationale: An interruption attack makes a system or resource unavailable .
Since the server was taken offline and made unavailable, this is an
interruption attack. This specifically targets the availability component of the
CIA triad.
Source: WGU Course C836 Fundamentals of Information Security – OA |
200+ Questions, Brian MacFarlane
5. A company has had several successful denial of service (DoS)
attacks on its email server. Which security principle is being
attacked?
A) Possession
B) Integrity
, C) Confidentiality
D) Availability
Answer: D) Availability
Rationale: A Denial of Service (DoS) attack aims to make a machine or
network resource unavailable by overwhelming it with illegitimate requests .
This directly attacks the availability principle of the CIA triad by preventing
legitimate users from accessing the resource .
Source: WGU C836 Exam Prep, Brian MacFarlane OA
6. Which principle of the Parkerian hexad is being addressed when
an auditor asks how a company's most critical data is used to
ensure proper defense mechanisms are in place?
A) Possession
B) Integrity
C) Authenticity
D) Utility
Answer: D) Utility
Rationale: The Parkerian Hexad includes Utility, which refers to how useful
the data is to an organization . Understanding how critical data is used helps
determine what defense mechanisms are needed to protect it effectively.
Utility is distinct from the CIA triad and focuses on the usefulness and value
of data.
Source: WGU C836 Fundamentals of Information Security – OA | 200+
Questions