SECURITY POLICIES & REMEDIATION PLAN | 2026
UPDATE WITH COMPLETE SOLUTIONS.
190 Questions with Answers and Detailed Rationales
100 PERCENT GUARANTEED PASS
INSTANT DOWNLOAD ANSWERS INCLUDED
IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
WGU D828 TASK 2 | TELEMEDICA GOVERNANCE, SECURITY POLICIES & REMEDIATION PLAN | 2026
UPDATE WITH COMPLETE SOLUTIONS.. It contains 190 carefully selected questions that reflect the most
current exam content and testing strategies. Each question is accompanied by a correct answer and a detailed
rationale that explains the underlying pathophysiology, pharmacology, or clinical reasoning.
Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas
Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions
Review Summary 190 Questions
Foundations - Application - WGU D828 TASK 2 Telemedica Governance Security Policies & Remediation
PLAN 2026 Update WITH Complete Solutions Healthcare Governance Cybersecurity AND Compliance
Graduate
All answers with rationales
,Table of Contents
Content Area Questions Key Topics
Governance AND 1-32 Telemedica, Security, Access, Hipaa, Control
Compliance Frameworks
Security Policies AND 33-64 Security, Telemedica, Access, Control, Critical
Standards
RISK Management AND 65-96 Security, Telemedica S, Hipaa, Critical, Response
Remediation Planning
DATA Privacy AND Protection 97-128 Telemedica, Hipaa, Breach, Security, Incident
Incident Response AND 129-160 Telemedica, Security, Hipaa, Business, Breach
Business Continuity
Access Control AND Identity 161-190 Telemedica S, Security, Hipaa, Governance, Critical
Management
TOTAL 190 All questions include answers and detailed rationales
,Section A - Governance AND Compliance Frameworks
Q1.
TeleMedica is adopting a zero-trust architecture. Which combination of controls BEST
aligns with NIST SP 800-207 while preserving healthcare workflow efficiency?
A. Network segmentation with implicit trust B. Continuous verification of every access
for internal IP ranges, MFA for remote request, least-privilege micro-segmentation,
access only, and endpoint detection on all and dynamic policy enforcement based on
devices. user, device, and data sensitivity.
C. Perimeter firewall strengthening, D. Single sign-on with adaptive risk-based
VPN-only access for all users, and periodic MFA, but allowing legacy systems to bypass
access reviews every 90 days. verification due to interoperability
constraints.
Correct: B - Continuous verification of every access request, least-privilege
micro-segmentation, and dynamic policy enforcement based on user, device, and data
sensitivity.
Rationale:Zero trust requires continuous verification of every request, least-privilege
micro-segmentation, and dynamic policy enforcement-not implicit trust or periodic reviews.
Option B fully embodies NIST SP 800-207 principles. Option A retains implicit trust; C is
traditional perimeter security; D violates zero trust by allowing bypasses.
Q2.
During a HIPAA risk assessment, TeleMedica identifies that its business associate
agreement (BAA) with a cloud provider lacks a clause on breach notification timing. Under
the HIPAA Omnibus Rule, what is the contractual obligation that MUST be included?
A. The BAA must require the business B. The BAA must require the business
associate to notify the covered entity of a associate to notify the covered entity of a
breach no later than 60 days after discovery. breach no later than 30 days after discovery,
with a 10-day extension for forensic
investigation.
C. The BAA must require the business D. The BAA must require the business
associate to notify the covered entity of a associate to notify the covered entity of a
breach within 24 hours of discovery, to meet breach within 30 days of discovery, but only
the HHS 'wall of shame' posting deadlines. if the breach affects more than 500
individuals.
Correct: A - The BAA must require the business associate to notify the covered entity of a
breach no later than 60 days after discovery.
Page 3
, Section A - Governance AND Compliance Frameworks
Rationale: HIPAA requires business associates to notify the covered entity of a breach without
unreasonable delay and no later than 60 days after discovery. Covered entities then have up
to 60 days to notify individuals (with 30 days for large breaches). Option A is correct; the other
options misstate the timeline or conditions.
Q3.
TeleMedica's remediation plan includes revisiting its disaster recovery (DR) strategy. The
current RTO is 4 hours and RPO is 30 minutes. After a recent ransomware attack, the
board demands a 2-hour RTO and 15-minute RPO. Which DR strategy adjustment is MOST
cost-effective while meeting the new targets?
A. Maintain the existing off-site backups but B. Implement synchronous replication to a
switch from weekly to daily full backups and warm standby site with automated failover
rely on manual restoration. and regular testing of the failover process.
C. Use asynchronous replication to a cold D. Adopt a pilot light approach where critical
site with a recovery plan that requires systems are pre-provisioned but data
manual system reconfiguration and data replication is hourly, accepting an RPO of 60
restoration from tape. minutes.
Correct: B - Implement synchronous replication to a warm standby site with automated
failover and regular testing of the failover process.
Rationale:To achieve RTO of 2 hours and RPO of 15 minutes, automated failover with
synchronous replication is needed. Option B meets both targets. Option A has too high RTO;
C has too high RTO and RPO; D has RPO of 60 minutes, violating the 15-minute RPO.
Q4.
TeleMedica's security team is developing a phishing simulation program. Which metric set
would provide the MOST meaningful evaluation of the program's effectiveness in reducing
human risk?
A. Click rate on simulated phishing emails, B. Percentage of employees who complete
number of employees who report phishing, annual security training, number of
and time-to-report for each simulation. simulated emails sent, and number of repeat
offenders.
C. Total number of phishing emails detected D. Number of employees who fail the
by the email gateway, number of malware simulation, number of tickets submitted to
infections prevented, and cost of the the helpdesk, and average time to
simulation platform. remediate a reported incident.
Correct: A - Click rate on simulated phishing emails, number of employees who report
phishing, and time-to-report for each simulation.
Page 4