Page 1 of 89
1
WGU C836 FUNDAMENTALS OF INFORMATION SECURITY OA
EXAM LATEST 2024-2025 VERSION A, B AND STUDY GUIDE
COMPLETE 350 QUESTIONS AND CORRECT DETAILED
ANSWERS
WGU C836 FUNDAMENTALS OF INFORMATION SECURITY OA EXAM A
An organization employs a VPN to safeguard it's information. Which security principle is protected by VPN?
Data in motion Data in storage Data at rest Data in use Data in motion A malicious attacker was successful in a denial of service (DoS) attack against an institution's mail server. Fortunately, no data was lost or altered while the server was offline. Which type of attack was this?
Interruption Interception Modification Fabrication Interruption A company has had several successful denial of service (DoS) attacks on its email server.Which security principle is being attacked?
- / 4
Page 2 of 89
2 Availability Confidentiality Integrity Possession Availability A new start-up company has started working on a social networking website. The company has moved all its source code to a cloud provider and wants to protect this source code from unauthorized access. Which cyber defense concept should the start-up company use to maintain the confidentiality of its source code?
File Encryption Alarm systems Antivirus Software Account permissions File Encryption A company has an annual audit of installed software and data storage systems. During the audit, the auditor asks how the company's most critical data is used. This determination helps the auditor ensure that the proper defense mechanisms are in place to protect critical data.Which principle of the Parkerian hexad is the auditor addressing?
Utility Possession Authenticity Integrity Utility 2 / 4
Page 3 of 89
3 Which cybersecurity term is defined as the potential for an attack on a resource?
Threat Vulnerability Risk Impact Threat Which security type deliberately exposes a system's vulnerabilities or resources to an attacker?
Intrusion Detection Intrusion Prevention Firewalls Honeypots Honeypots Which tool can be used to map devices on a network, along with their operating system types and versions?
Port Scanner Stateful Firewall Packet Filter Packet Sniffer Port Scanner Which web attack is a server-side attack?
SQL Injection 3 / 4
Page 4 of 89
4 Cross-site scripting Cross-site request forgery Clickjacking SQL Injection Which web attack is possible due to a lack of input validation?
SQL injection Cross-site request forgery Clickjacking Extraneous files SQL injection Which file action implements the principle of confidentiality from the CIA triad?
Compression Hash Backup Encryption Encryption Which cyber defense concept suggests limiting permissions to only what is necessary to perform a particular task?
Defense in depth Authorization Authentication Principle of least privilege
- / 4