Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

WGU D483 Comp Tia Sys Study Questions And Answers

Rating
-
Sold
-
Pages
5
Grade
A+
Uploaded on
22-12-2025
Written in
2025/2026

WGU D483 Comp Tia Sys Study Questions And Answers An organization recently had an attack that resulted in system data loss. The system administrator must now restore the system with a data backup. What functional security control was the system administrator able to implement? A.Preventative B.Responsive C.Corrective D.Compensating The system administrator used a corrective control after the attack. A good example of a corrective control is a backup system that can restore data that an attacker damages during an intrusion. Preventative controls act to eliminate or reduce the likelihood that an attack can succeed. A preventative control operates before an attack can take place. Responsive controls serve to direct corrective actions enacted after the organization confirms the incident. They often document these actions in a playbook. The compensating control is a substitute for a principal control, as recommended by a security standard, and affords the same (or better) level of protection but uses a different methodology or technology. A security engineer installs a next-generation firewall on the perimeter of a network. This installation is an example of what type of security control class? A.Managerial B.Operational C.Detective D.Technical Firewalls, antivirus software, and operating system (OS) access control models are examples of technical controls. The engineer would implement technical control as a system (hardware, software, or firmware). The managerial control gives oversight of the information system. Examples could include risk identification or a tool allowing the evaluation and selection of other security controls. People primarily implement operational control rather than systems. For example, security guards and training programs are operational controls rather than technical controls. The detective control is a functional control that is not a security control class An engineer is considering appropriate risk responses using threat modeling. They are trying to understand which threat actors are in scope for their organization. How does threat modeling identify the principal risks and tactics, techniques, and procedures (TTPs) for which their system may be susceptible? (Select the three best options.) A.By evaluating the system from an attacker's point of view B.By evaluating a system from a neutral perspective C.Through using tools such as diagrams D.By analyzing the system from the defender's perspective Evaluating systems from a neutral perspective is not a method used in threat modeling. A mission-critical system is offline at an organization due to a zero-day attack. The associated software vendor plans to release a patch to remediate the vulnerability. Which of the following are important patch management considerations for this scenario? (Select the three best options.) A.A patch test environment B.Immediate push delivery of critical security patches C.A specific team responsible for reviewing vendor-supplied newsletters and security patch bulletins D.A routine schedule for the rollout of noncritical patches D. While creating a routine schedule for the rollout of noncritical patches has merit, it does not illustrate important patch management considerations in this example. A security analyst would address noncritical patches at a later time. A security analyst is reviewing an announcement from the Cybersecurity and Infrastructure Security Agency. Which source of defensive open-source intelligence (OSINT) does the agency represent? A.CERT B.Internal sources C.Government bulletins D.CSIRT The government is responsible for protecting the country's constituents and the national infrastructure and publishing various information and advice regarding observed threats. For example, the Department of Homeland Security and the Cybersecurity and Infrastructure Agency publishes several types of cybersecurity guidance, including basic informational content and binding operational directives that federal agencies must implement. A computer emergency response team (CERT) aims to mitigate cybercrime and minimize damage by responding to incidents quickly.

Show more Read less
Institution
WGU D483 CompTia SysA+
Course
WGU D483 CompTia SysA+

Content preview

WGU D483 Comp Tia Sys Study
Questions And Answers

An organization recently had an attack that resulted in system data loss. The
system administrator must now restore the system with a data backup. What
functional security control was the system administrator able to implement?
A.Preventative
B.Responsive
C.Corrective
D.Compensating

The system administrator used a corrective control after the attack. A good example of
a corrective control is a backup system that can restore data that an attacker damages
during an intrusion.

Preventative controls act to eliminate or reduce the likelihood that an attack can
succeed. A preventative control operates before an attack can take place.

Responsive controls serve to direct corrective actions enacted after the organization
confirms the incident. They often document these actions in a playbook.

The compensating control is a substitute for a principal control, as recommended by a
security standard, and affords the same (or better) level of protection but uses a
different methodology or technology.
A security engineer installs a next-generation firewall on the perimeter of a
network. This installation is an example of what type of security control class?
A.Managerial
B.Operational
C.Detective
D.Technical


Firewalls, antivirus software, and operating system (OS) access control models are
examples of technical controls. The engineer would implement technical control as a
system (hardware, software, or firmware).

The managerial control gives oversight of the information system. Examples could
include risk identification or a tool allowing the evaluation and selection of other security
controls.

People primarily implement operational control rather than systems. For example,
security guards and training programs are operational controls rather than technical

, controls.

The detective control is a functional control that is not a security control class

An engineer is considering appropriate risk responses using threat modeling.
They are trying to understand which threat actors are in scope for their
organization. How does threat modeling identify the principal risks and tactics,
techniques, and procedures (TTPs) for which their system may be susceptible?
(Select the three best options.)
A.By evaluating the system from an attacker's point of view
B.By evaluating a system from a neutral perspective
C.Through using tools such as diagrams
D.By analyzing the system from the defender's perspective

Evaluating systems from a neutral perspective is not a method used in threat modeling.
A mission-critical system is offline at an organization due to a zero-day attack.
The associated software vendor plans to release a patch to remediate the
vulnerability. Which of the following are important patch management
considerations for this scenario? (Select the three best options.)
A.A patch test environment
B.Immediate push delivery of critical security patches
C.A specific team responsible for reviewing vendor-supplied newsletters and
security patch bulletins
D.A routine schedule for the rollout of noncritical patches

D. While creating a routine schedule for the rollout of noncritical patches has merit, it
does not illustrate important patch management considerations in this example. A
security analyst would address noncritical patches at a later time.
A security analyst is reviewing an announcement from the Cybersecurity and
Infrastructure Security Agency. Which source of defensive open-source
intelligence (OSINT) does the agency represent?
A.CERT
B.Internal sources
C.Government bulletins
D.CSIRT

The government is responsible for protecting the country's constituents and the national
infrastructure and publishing various information and advice regarding observed threats.
For example, the Department of Homeland Security and the Cybersecurity and
Infrastructure Agency publishes several types of cybersecurity guidance, including basic
informational content and binding operational directives that federal agencies must
implement.

A computer emergency response team (CERT) aims to mitigate cybercrime and
minimize damage by responding to incidents quickly.

Written for

Institution
WGU D483 CompTia SysA+
Course
WGU D483 CompTia SysA+

Document information

Uploaded on
December 22, 2025
Number of pages
5
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$11.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Brainariam Harvard University
Follow You need to be logged in order to follow users or courses
Sold
148
Member since
1 year
Number of followers
7
Documents
8375
Last sold
3 days ago

Our store offers a wide selection of materials on various subjects and difficulty levels, created by experienced teachers. We specialize on NURSING,WGU,ACLS USMLE,TNCC,PMHNP,ATI and other major courses, Updated Exam, Study Guides and Test banks. If you don't find any document you are looking for in this store contact us and we will fetch it for you in minutes, we love impressing our clients with our quality work and we are very punctual on deadlines. Please go through the sets description appropriately before any purchase and leave a review after purchasing so as to make sure our customers are 100% satisfied. I WISH YOU SUCCESS IN YOUR EDUCATION JOURNEY

Read more Read less
3.3

25 reviews

5
8
4
2
3
8
2
3
1
4

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions