, WGUjD430j FUNDAMENTALSj OFj INFORMATIONjSE
CURITYjFINALjEXAMjANDj PRACTICEj EXAMj2024/A
CTUALjEXAMSj WITHj 500j QUESTIONSjAND
CORRECTj DETAILEDjANSWERS/A+j GRADEjWG
UjD430jFINALjEXAM
Accessj Controlj Listj –
CORRECTjANSWER:j infoj aboutj whatj kindj ofj accessj certainpartiesj arejallowed
jtojhavejtojajgivenjsystem
Readj,j writej,jexecute
Accessj Controlj Modelsj –
CORRECTjANSWER:j Discretionaryj (j DACj )Mandatoryj (j MACj )jRulej
-jbased
Rolej -jbasedj(jRBACj)
Attributej-j basedj(jABACj)
Accountabilityj –
CORRECTjANSWER:
Refersj toj makingj surej thatjaj personj isresponsiblej forj theirj actionsj .
-Itj providesj usjwithjthej meansj toj tracej activitiesj inj ourj environmentj backj toj their
source
-
Dependsj onjidentificationj ,j authenticationj ,j andj accessj controlj beingj presentj sojthat
j wecanjknowj whoj aj givenj transactionj isj associatedj withj ,j andj what
permissionsj werej usedj toj allowj themj tojcarryj itj outj .
2/85
,Acessj Controlj –
CORRECTjANSWER:j Allowingj -
j letsj usj givej aj particularj partyj accesstoj aj givenjsource
Denyingj -j oppositej ofj gainingj access
Limitingj-jallowingj somejaccessj tojourjresourcej ,j onlyj upjtoj aj certainjpoint
Revokingj -j takesj accessj awayj fromj formerj user
AESj–
CORRECTjANSWER:jusesjthreejdifferentjciphersj:jonejwithjaj128j-
jbitjkeyj,jonej withjaj192j-jbitjkeyj,jandjonejwithjaj256j-
jbitjkeyj,jalljhavingjajblockjlengthjofj128jbits
Asymmetricj cryptographyj –
CORRECTjANSWER:j aj publicj keyj andj aj privatej keyj .jThepublicj keyjisj usedj tojenc
ryptj dataj sentj fromj thej senderj toj thej receiverj andj isj sharedj withj everyonej .jPrivatej
keysj arejusedj toj decryptj datajthatjarrivesj atj thejreceivingj endj andj arejveryj carefull
yjguardedjbyjthejreceivej (jakajthejpublicj keyjcryptographyj)
Asymmetricj KeyjAlgorithmsj –
CORRECTjANSWER:
Securej Socketsj Layerj (j RSAj)Ellipticj Curvej Cryptographyj (j ECCj )jPr
ettyjGoodjPrivacyj(jPGPj)
TransportjLayerjSecurityj(j
TLSj)
AttackjTypesj–
3/85
, CORRECTjANSWER:j InterceptionInterruptionjModification
Fabrication
Attackjtypesj andj theirj effectj –
CORRECTjANSWER:jInterceptionjisjthejONLYjattackj thatjaffectsjonjconfidentia
lity.j Interruption,j modification,j andjfabricationj affectsj integrityandjavailabilityjbec
ausejmostjofjthejtimejthey'rejimpactingjdata.
Attributej-j basedj (jABACj )
-
j CORRECTjANSWER:j basedj onj attributesj ,j suchj asj ofj apersonj ,j resourcej ,j orjanje
nvironment
Auditingj –
CORRECTjANSWER:j thej examinationj andj reviewj ofj anj organization'sjrecordsjt
oj ensurejaccountabilityj throughjtechnicaljmeansj.
Authenticationj –
CORRECTjANSWER:j verifyingj thatj aj personj isj whoj theyj claimj toj be
Authorizationj –
CORRECTjANSWER:j whatj thej userj canjaccessj ,jmodifyj,j andj delete
Availabilityj –
CORRECTjANSWER:j Forj one'sjAUTHORIZEDj tojACCESSj dataj whenneeded
4/85