Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

WGU C836 Fundamentals of Information Security OA Final Exam 2026: 300 Practice Questions with Answers & Rationales

Beoordeling
-
Verkocht
-
Pagina's
116
Cijfer
A+
Geüpload op
28-04-2026
Geschreven in
2025/2026

Prepare for the WGU C836 Fundamentals of Information Security Objective Assessment (OA) Final Exam with this comprehensive 300-question practice set, complete with correct answers and detailed rationales. Aligned with WGU course objectives, this resource covers every major domain: Foundational Security Concepts – CIA Triad (Confidentiality, Integrity, Availability), Parkerian Hexad (added Possession/Control, Authenticity, Utility), threats vs. vulnerabilities vs. risks (relationships, formulas), risk management process (identify assets → identify threats → assess vulnerabilities → assess risks → mitigate risks), defense in depth, control types (physical, logical/technical, administrative), risk treatment strategies (acceptance, mitigation, transference, avoidance), risk assessment (quantitative SLE/ALE/ARO, qualitative High/Medium/Low), Business Impact Analysis (BIA), Recovery Time Objective (RTO), Recovery Point Objective (RPO), Maximum Tolerable Downtime (MTD), Work Recovery Time (WRT) Security Attacks & Threats – Attack types (interception, interruption, modification, fabrication), DoS/DDoS, SQL injection, XSS, CSRF, clickjacking, buffer overflow, man-in-the-middle (MITM), replay attacks, session hijacking, ARP spoofing, DNS spoofing/p poisoning, phishing, spear phishing, whaling, pretexting, tailgating, baiting, watering hole, malvertising, side-channel attacks (timing, power analysis), birthday attacks, rainbow tables, pass-the-hash, credential stuffing, password spraying, brute force vs. dictionary vs. hybrid attacks, logic bombs, rootkits, ransomware, worms vs. viruses vs. Trojan horses, APTs, zero-day vulnerabilities, rogue AP, evil twin, skimming, sniffing/packet capture Risk Management – Quantitative vs. qualitative risk assessment, SLE (Asset Value × Exposure Factor), ALE (SLE × ARO), risk register, inherent vs. residual risk, risk appetite, compensating controls, defense in depth, disaster recovery (cold/hot/warm sites), business continuity planning (BCP), incident response phases (Preparation, Detection & Analysis, Containment & Eradication & Recovery, Post-incident Activity), chain of custody, e-discovery, legal hold, forensic imaging Access Control & Identity Management – Authentication factors (something you know/have/are/do/somewhere you are), 2FA/MFA, AAA (Authentication, Authorization, Accounting), access control models (DAC, MAC, RBAC, ABAC), principle of least privilege, separation of duties, job rotation, mandatory vacation, access recertification, single sign-on (SSO), federation (SAML, OAuth, OpenID Connect), biometrics (FAR, FRR, CER), password policies (NIST SP 800-63b recommendations), CAPTCHA, session lock/timeout, ACLs, capabilities Cryptography – Symmetric vs. asymmetric encryption, AES, RSA, ECC, 3DES, RC4, ChaCha20, block vs. stream ciphers, hash functions (SHA-256, MD5, collision/preimage attacks), salting passwords, digital signatures (integrity + non-repudiation), PKI (public/private keys, certificates, CAs, root/intermediate CAs, CRL, OCSP), TLS/SSL (handshake, POODLE/BEAST, Perfect Forward Secrecy), Diffie-Hellman key exchange, IPsec, VPN, SSH, WEP (insecure) vs. WPA2 (AES-CCMP) vs. WPA3 (SAE, GCMP), KRACK attack, nonces, hardware security (HSM, TPM, Secure Boot) Network & Host Security – Firewalls (packet filtering, stateful inspection, NGFW, proxy), DMZ, VLANs, network segmentation, IDS vs. IPS (signature-based vs. anomaly-based), honeypots, vulnerability scanners vs. penetration testing (Metasploit), WAF, OS hardening (disable unnecessary services, patch management, remove default accounts), configuration management, configuration drift, change management, NAC, split tunneling, DLP, full disk encryption (FDE), RAID (fault tolerance), 3-2-1 backup rule Compliance & Standards – HIPAA, GLBA, PCI DSS, SOX, ISO/IEC 27001/27002, NIST SP 800-53, OWASP Top 10, CWE Incident Response & Forensics – Incident response phases, forensic imaging (write blockers, chain of custody), legal hold, e-discovery Ideal for WGU C836 students preparing for the OA final exam, information security fundamentals, and cybersecurity foundations courses.

Meer zien Lees minder
Instelling
WGU C836
Vak
WGU C836

Voorbeeld van de inhoud

WGU C836 Fundamentals of Information
Security OA Final Exam NEWEST 2026
– 300 Questions with Answers &
Rationales

Section 1: Foundational Security Concepts (Questions 1–60)
1. A company's website has suffered several denial of service (DoS) attacks
and wishes to thwart future attacks. Which security principle is the company
addressing?
A) Authenticity
B) Confidentiality
C) Possession
D) Availability

✅ Correct Answer: D
Rationale: Availability refers to the ability to access data or systems when
needed. A Denial of Service (DoS) attack is designed to overwhelm resources
so that legitimate users cannot access them, directly violating the principle
of availability .


2. At a small company, an employee makes an unauthorized data alteration.
Which component of the CIA triad has been compromised?
A) Confidentiality
B) Authenticity
C) Integrity
D) Availability

✅ Correct Answer: C
Rationale: Integrity ensures that data is not altered or deleted in an

,unauthorized or undesirable manner. Unauthorized alteration is a direct
violation of data integrity .


3. Which aspect of the CIA triad is violated by an unauthorized database
rollback or undo?
A) Availability
B) Identification
C) Integrity
D) Confidentiality

✅ Correct Answer: C
Rationale: Reverting a database to a previous state without authorization
alters the current data set. This manipulation affects the trustworthiness and
accuracy of the data, thus compromising Integrity .


4. An organization has a requirement that all database servers and file
servers be configured to maintain operations in the presence of a failure.
Which principle of the CIA triad is this requirement implementing?
A) Utility
B) Integrity
C) Availability
D) Confidentiality

✅ Correct Answer: C
Rationale: Availability means ensuring systems and data are accessible when
authorized users need them. Designing for failure tolerance ensures the
system remains operational, directly supporting availability .

,5. An attacker performs a buffer overflow attack on an organization's web
server. The web server locks up and must be restarted. Which part of the CIA
triad is under attack?
A) Confidentiality
B) Integrity
C) Control
D) Availability

✅ Correct Answer: D
Rationale: The buffer overflow caused the server to crash (lock up). Because
the service is down and users cannot access the website, Availability is
compromised .


6. A bank wants to ensure user interactions with the online banking website
are confidential. Which security solution should be implemented?
A) SSH/FTP
B) AES
C) SSL/TLS
D) VPN

✅ Correct Answer: C
Rationale: SSL/TLS (Secure Sockets Layer/Transport Layer Security) encrypts
the traffic between the user's browser and the web server, ensuring
confidentiality of the session .


7. An organization discovers that an attacker has been cutting fiber optic
cables in a remote data center to disrupt operations. Which principle of the
CIA triad is the attacker primarily targeting?
A) Authorization
B) Availability

, C) Identification
D) Confidentiality

✅ Correct Answer: B
Rationale: Cutting physical cables disrupts the connection to the data. If the
data cannot be accessed because the network is physically broken, the
Availability principle is violated .


8. The Fabrication attack type most commonly affects which principle(s) of
the CIA triad?
A) Availability
B) Integrity
C) Confidentiality
D) Integrity and Availability

✅ Correct Answer: D
Rationale: Fabrication attacks involve generating spurious data, processes, or
communications. They primarily affect integrity (creating false data) but
could also be considered an availability attack if the fabricated data
overwhelms resources .


9. Which of the following is NOT one of the three components of the CIA
triad?
A) Confidentiality
B) Integrity
C) Possession
D) Availability

✅ Correct Answer: C
Rationale: The CIA triad consists of Confidentiality, Integrity, and
Availability. Possession is an additional principle included in Donn Parker's
expanded model (the Parkerian Hexad).

Geschreven voor

Instelling
WGU C836
Vak
WGU C836

Documentinformatie

Geüpload op
28 april 2026
Aantal pagina's
116
Geschreven in
2025/2026
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$28.49
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
PremiumExamBank Chamberlain College Of Nursng
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
332
Lid sinds
2 jaar
Aantal volgers
65
Documenten
5492
Laatst verkocht
14 uur geleden
TEST BANKS AND ALL KINDS OF EXAMS SOLUTIONS

TESTBANKS, SOLUTION MANUALS & ALL EXAMS SHOP!!!! TOP 5_star RATED page offering the very best of study materials that guarantee Success in your studies. Latest, Top rated & Verified; Testbanks, Solution manuals & Exam Materials. You get value for your money, Satisfaction and best customer service!!! Buy without Doubt..

4.8

1043 beoordelingen

5
929
4
74
3
25
2
10
1
5

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen