Page 1 of 396
1
WGU C725 INFORMATION SECURITY AND ASSURANCE
EXAM COMPLETE 500 QUESTIONS AND CORRECT
DETAILED ANSWERS LATEST UPDATE THIS YEAR - JUST
RELEASED
Which business role must ensure that all operations fit within the business goals?
A data owner B business/mission owner C system owner D data custodian Answer B is correct.
The person in the business/mission owner role must ensure that all operations fit within the business or mission goals.System and data owners are responsible for ensuring that proper controls are in place to maintain the integrity, confidentiality, and availability of the information.
The system owner is responsible for maintaining and protecting one or more data processing systems. The role of a system owner includes the integration of required security features into the applications and the purchase decision of the applications. The system owner also ensures that the remote access control, password management, and operating system configuration 1 / 4
Page 2 of 396
2 provide the necessary security.
The data owner is typically part of management. The data owner controls the process of defining IT service levels, provides information during the review of controls, and is responsible for authorizing the enforcement of security controls to protect the information assets of the organization. For example, a business unit manager has the primary responsibility of protecting the information assets by exercising due diligence and due care practices.
The data custodian is directly responsible for maintaining and protecting the data. This role is typically delegated to the IT department staff and includes implementing the organization security through the implementation and maintenance of security controls. The data custodian
role also includes the following tasks:
Maintaining records of activity Verifying the accuracy and reliability of the data Backing up and restoring data on a regular basis What process does a system use to officially permit access to a file or a program?
A Authorization B Validation C Authentication D Identification 2 / 4
Page 3 of 396
3 Answer A is correct.
A system can use an authorization process to officially permit access to a file or a program. This process is used for granting permission and specifying access rights to resources.
Answer B is incorrect. Validation confirms the data values being entered by a user are valid or not.
Answer C is incorrect. Authentication is an act of establishing or confirming something (or someone) as authentic, such as, the claims made by or about the subject are true.
Answer D is incorrect. Identification is the process by which a subject professes an identity and accountability is initiated.All but which of the following items requires awareness for all individuals affected?
A The backup mechanism used to retain email messages B Restricting personal email C Recording phone conversations D Gathering information about surfing habits Answer A is correct.
- / 4
Page 4 of 396
4 Users should be aware that email messages are retained, but the backup mechanism used to perform this operation does not need to be disclosed to them.Which of the following security factors does not come under CIA triad?A Confidentiality B Authentication C Integrity D Availability Answer B is correct.
Authentication does not come under CIA triad. CIA triad is the process defined by the CIA to confirm whether the security is properly implemented. Authentication is a process of verifying the identity of a person, network host, or system process. The authentication process compares the provided credentials with the credentials stored in the database of an authentication server.
Answers C, D, and A are incorrect. Confidentiality, integrity, and availability are the security factors that come under CIA triad.
- / 4