Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

WGU D430 Fundamentals of Information Security Objective Assessment 2026 Complete exam questions with verified detailed answers

Beoordeling
-
Verkocht
-
Pagina's
62
Cijfer
A+
Geüpload op
02-01-2026
Geschreven in
2025/2026

This document includes the newest 2026 objective assessment content for WGU D430 Fundamentals of Information Security, featuring complete exam-style questions with correct, detailed, and verified answers. It covers core information security principles such as CIA triad, risk management, access control, cryptography, network security, compliance, and incident response, and reflects an assessment already graded with an A+.

Meer zien Lees minder
Instelling
WGU D430 FUNDAMENTALS OF INFORMATION SECURITY
Vak
WGU D430 FUNDAMENTALS OF INFORMATION SECURITY

Voorbeeld van de inhoud

1



WGU D430 Fundamentals of Information Security
Objective Assessment 2026 Complete exam questions
with verified detailed answers
Q1: CIA Triad, Governance, Risk, & Compliance (GRC)
A hospital’s electronic health-record system is being audited after several patient files were
altered without authorization. Which core security principle has been MOST directly violated?

A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation

Answer: B

Rationale: Integrity ensures that data has not been modified or tampered with in an
unauthorized manner (ISO 27001 A.8.1, NIST SP 800-53 SI-7). Because the files were changed
without permission, the hospital cannot trust the accuracy of the data—an integrity failure.
Confidentiality (A) relates to disclosure, Availability (C) to timely access, and Non-repudiation
(D) to undeniable proof of action; none were the primary issue here.



Q2: CIA Triad, Governance, Risk, & Compliance (GRC)
A U.S. state agency that processes driver’s-license data must comply with which federal law that
REQUIRES an annual privacy assessment and mandates safeguards for personally identifiable
information (PII)?

A. FISMA
B. HIPAA
C. GLBA
D. SOX

Answer: A

Rationale: The Federal Information Security Modernization Act (FISMA) requires federal
agencies and their contractors to conduct annual privacy-impact assessments and implement
NIST SP 800-53 controls to protect PII (44 U.S.C. § 3554). HIPAA (B) covers health data, GLBA (C)
financial institutions, and SOX (D) public-company financial reporting—none apply universally to
state DMV data.

, 2




Q3: Security Frameworks & Controls
Which NIST Cybersecurity Framework (CSF) category BEST describes the activity of creating and
maintaining a hardware inventory that records every router, switch, and firewall in an
enterprise?

A. ID.AM-1
B. PR.AC-3
C. DE.AE-2
D. RS.CO-1

Answer: A

Rationale: ID.AM-1 (Identify → Asset Management → “Physical devices and systems within the
organization are inventoried”) mandates maintaining a current list of hardware assets. PR.AC-3
(B) covers remote access, DE.AE-2 (C) anomaly analysis, and RS.CO-1 (D) response planning—
none directly address asset inventory.



Q4: Asset Security & Data Protection
A company tags all laptops with encrypted asset IDs and stores them in a bar-code database.
Which ISO 27001 control objective is PRIMARILY supported?

A. A.5 – Information security policies
B. A.8.1 – Inventory of assets
C. A.12.3 – Information backup
D. A.16.1 – Incident management

Answer: B

Rationale: ISO 27001 Annex A.8.1 requires an inventory of assets to maintain accountability and
traceability. Tagging laptops supports this objective by ensuring every physical asset is recorded
and tracked.



Q5: Network & Infrastructure Security
A network engineer wants to stop an attacker who has stolen valid VPN credentials from
accessing the corporate LAN at 02:00 a.m. from an unknown IP geolocation. Which control type
should be implemented?

, 3


A. Preventive
B. Detective
C. Corrective
D. Deterrent

Answer: A

Rationale: Geo-blocking and time-based access rules on the VPN gateway are preventive
controls (NIST SP 800-53 AC-2, AC-3) that stop the session before it enters the network.
Detective (B) would log it; corrective (C) would undo damage afterward; deterrent (D)
discourages but does not block.



Q6: Identity & Access Management (IAM)
Which authentication factor category is demonstrated when a user signs in by looking into an
infrared camera that maps retinal blood-vessel patterns?

A. Something you know
B. Something you have
C. Something you are
D. Something you do

Answer: C

Rationale: Biometric retina scanning is “something you are,” an inherence factor (NIST SP 800-
63B 4.2). It relies on a unique physiological characteristic rather than knowledge, possession, or
behavior.



Q7: Security Operations & Incident Response
During which NIST incident-response life-cycle phase is a lessons-learned report MOST
commonly drafted?

A. Preparation
B. Detection & Analysis
C. Containment, Eradication & Recovery
D. Post-Incident Activity

Answer: D

, 4


Rationale: NIST SP 800-61r2 labels “Post-Incident Activity” as the phase where teams
summarize what happened, document evidence, and produce a lessons-learned report to
improve future response.



Q8: CIA Triad, Governance, Risk, & Compliance (GRC)
A publicly traded retailer must file an annual report that includes an attestation on the
effectiveness of internal controls over financial reporting. Which SOX section mandates this
requirement?

A. Section 404
B. Section 302
C. Section 201
D. Section 802

Answer: A

Rationale: SOX §404 requires management and external auditors to report on the adequacy of
internal controls over financial reporting. Section 302 (B) covers quarterly certifications, while
201 & 802 address auditor independence and record retention.



Q9: Security Frameworks & Controls
An organization maps each CIS Critical Security Control to corresponding NIST SP 800-53
controls and documents the linkage. Which CIS control phase does this activity exemplify?

A. Inventory and Control of Hardware Assets
B. Continuous Vulnerability Management
C. Control Systems Design and Mapping
D. Governance and Risk Management

Answer: C

Rationale: CIS v8 “Implementation Group” guidance includes mapping CIS controls to other
frameworks (e.g., NIST) under the umbrella of control design and alignment, ensuring layered
coverage.



Q10: Asset Security & Data Protection
Data custodians are PRIMARILY responsible for which task within an information-governance
model?

Geschreven voor

Instelling
WGU D430 FUNDAMENTALS OF INFORMATION SECURITY
Vak
WGU D430 FUNDAMENTALS OF INFORMATION SECURITY

Documentinformatie

Geüpload op
2 januari 2026
Aantal pagina's
62
Geschreven in
2025/2026
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$16.19
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
ExamAceStuvia Rasmussen College
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
30
Lid sinds
8 maanden
Aantal volgers
0
Documenten
813
Laatst verkocht
6 dagen geleden
Top Grades By ExamAceStuvia

Ace Your Certification — The Smart Way! Welcome to ExamAceStuvia – the ultimate battle-tested exam prep platform built by passers, for future passers. Get thousands of real exam questions straight from people who just crushed the same test you’re facing. No fluff. No outdated dumps. Just authentic, up-to-date practice that feels exactly like the real thing. Why thousands choose Examice every day: 400+ published exams across 100+ top providers (AWS, Microsoft, Cisco, ,NCLEX , WGU , CompTIA, and many more) Whether you're preparing for nursing licensure (NCLEX, ATI, HESI, ANCC, AANP), healthcare certifications (ACLS, BLS, PALS, PMHNP, AGNP), standardized tests (TEAS, HESI, PAX, NLN), or university-specific exams (WGU, Portage Learning, Georgia Tech, and more), our documents are 100% correct, up-to-date for 2025/2026, and reviewed for accuracy.. Community-powered accuracy → open discussions, source-backed references, democratic voting & follow-up Q&A to lock in the real correct answers Realistic exam that builds confidence and exposes weak spots fast Most affordable premium prep in the industry – quality without breaking the bank Regular updates so you’re always studying what actually appears today Whether you're chasing that dream job, promotion, or career switch — ExamAce turns “I hope I pass” into “I’ve got this.” Join the community that’s already helped thousands certify. Try ExamAceStuvia today → pass tomorrow.

Lees meer Lees minder
4.5

4 beoordelingen

5
3
4
0
3
1
2
0
1
0

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen