Fundamentals of Information Security - D430
Review this completed exam record, including subject, platform, academic level, completion details, and preview question.
72 previously done information-security practice questions with answer choices and explanations. WGU exam questions.
Exam Record Details
Questions 1-10: Core Infrastructure & Access Controls
Question 1
Question: A security procedure document outlines requirements for encryption of data in
transit, maintaining access lists for viewing confidential information, and performing
regular backups. Which layer of the defense-in-depth model does this document target?
Answer choices
- Application Layer
- Network Layer
- Physical Layer
- Data Layer
Explanation
The requirements focus entirely on safeguarding the data itself (via
confidentiality and availability controls) rather than network perimeters or physical locks.
Question 2
Question: A facility policy states that only IT employees are permitted entry into the
server room, and security guards must verify employee identification cards before
allowing access. Which types of access control and verification are being utilized?
Answer choices
- Discretionary access control and nonrepudiation
- Mandatory access control and auditing
- Role-based access control and authentication
- Attribute-based access control and authorization
Explanation
Restricting entry by department is role-based access control (RBAC), and
verifying physical identification credentials serves as authentication.
Question 3
Question: An organization installs warning signs, computer-controlled door locks, and
burglary alarm systems around its primary data center. Which category of security control
do these items represent?
Answer choices
- Administrative security
- Technical security
- Physical security
- Operations security
Explanation
These measures involve tangible mechanisms designed to protect physical
facilities and hardware assets from unauthorized entry.
Question 4
Question: A federal agency is looking to adopt a new cloud-based computing solution
and needs to verify that the cloud provider meets standardized federal security
assessment and continuous monitoring guidelines. Which standard covers this
requirement?
Answer choices
- GLBA
- SOX
- FISMA
- FedRAMP
Explanation
FedRAMP specifically standardizes security authorization and assessment
criteria for cloud products and services utilized by US federal agencies.
Question 5
Question: A company upgrades its network access controls by requiring employees to
use a physical smart card and enter a matching 4-digit PIN to log into their workstations.
Which security function is directly improved by this change?
Answer choices
- Authorization
- Authentication
- Least privilege
- Non-repudiation
Explanation
Smart cards and PINs serve as multi-factor authentication (MFA), validating
that the user is exactly who they claim to be.
Question 6
Question: Which security mechanism serves as an example of a preventive control?
Answer choices
- Warning signs
- Burglary alarm systems
- Intrusion detection systems (IDS)
- Mechanical locks
Explanation
Mechanical locks are a preventive control because they actively block an
adversary from entering a restricted space.
Question 7
Question: An organization implements software-based cryptographic algorithms to
scramble files and protect information confidentiality. Which control type does this
represent?
Answer choices
- Administrative
- Physical
- Technical
- Deterrent
Explanation
Technical controls (or logical controls) use hardware, software, or firmware
mechanisms to protect systems and data.
Question 8
Question: Which type of passive attack targets data confidentiality by capturing data
streams while in transit without altering the content, making it highly difficult to detect?
Answer choices
- Interruption
- Interception
- Modification
- Fabrication
Explanation
Interception involves unauthorized reading or wiretapping of data streams,
which directly undermines data privacy/confidentiality.
Question 9
Question: Which tool is specifically used on websites to prevent automated software
scripts and bots from submitting forms or spamming web pages?
Answer choices
- Firewall
- Vulnerability scanner
- Captchas
- Intrusion Detection System (IDS)
Explanation
CAPTCHAs test whether an online user is a real human being or an
automated script.
Question 10
Question: Which device acts as an intermediary between an internal network user and
the internet, allowing administrators to filter web traffic against an access control list
(ACL)?
Answer choices
- Proxy server
- Intrusion detection system
- Digital signature
- Honeypot
Explanation
A proxy server acts as a gateway that checks outgoing requests and blocks
unauthorized websites using an ACL.
Questions 11–20: Network Defense & Deceptive Attacks
Question 11
Question: Which mechanism provides non-repudiation by cryptographically binding a
sender's unique private key to an outgoing email message?
Answer choices
- Symmetric encryption
- Digital signatures
- Password salting
- Substitution ciphers
Explanation
Digital signatures mathematically prove authorship, preventing the sender
from falsely denying they sent the message.
Question 12
Question: Which type of server can be implemented at a network boundary to inspect
and filter out incoming malicious content, such as spam emails, before it reaches user
inboxes?
Answer choices
- FTP server
- DNS server
- Proxy server
- Web server
Explanation
Mail or content proxy servers filter incoming network applications to stop
unwanted spam and malicious payloads.
Question 13
Question: Multiple system administrators are currently logging into servers using a
shared root account, making it impossible to audit individual actions. Which remediation
strategy best resolves this accountability vulnerability?
Answer choices
- Review the audit logs daily
- Implement password management tools
- Update all system patches
- Create unique accounts
Explanation
Assigning unique credentials to every single person ensures clear individual
accountability in audit logs.
Question 14
Question: An employee receives an email that appears to be from their department
manager demanding immediate delivery of internal accounting documents. The employee
later discovers the email was spoofed. Which attack type does this describe?
Answer choices
- Social engineering
- Personal equipment vulnerability
- Network usage policy violation
- Password policy failure
Explanation
Social engineering manipulates human behavior and exploits trust/urgency
to trick targets into handing over secrets.
Question 15
Question: A security analyst wants to scan the local wireless spectrum to identify
unauthorized or rogue access points operating inside the office building. Which tool
should they use?
Answer choices
- Shodan
- Censys
- Maltego
- Kismet
Explanation
Kismet is an open-source wireless network detector, packet sniffer, and rogue access point identification tool.
Question 16
Question: A security team needs to audit system and user behaviors that took place over
the last several months. Which practice provides the historical records needed for this
review?
Answer choices
- Real-time monitoring
- Logging
- Data backup
- Record review
Explanation
Logging continually records system and network events into data storage
files to build an audit trail for historical reviews.
Question 17
Question: Which security control combines hash functions to verify data integrity
alongside public-key cryptography to verify sender authenticity?
Answer choices
- Symmetric encryption
- Asymmetric encryption
- Digital signatures
- Security tokens
Explanation
Digital signatures use asymmetric cryptography to cryptographically hash
and sign files, verifying both data integrity and origin authenticity.
Question 18
Question: An attacker exploits a system misconfiguration to gain control of a database
engine's high-level root or service account. Which term defines this security event?
Answer choices
- Protocol issue
- Arbitrary code execution
- Unauthenticated access
- Privilege escalation
Explanation
Privilege escalation happens when a lower-privileged user exploits flaws to
gain higher-level operational rights.
Question 19
Question: A proxy server stands between a private company network and the public
internet, inspecting all inbound requests to block unauthorized outside traffic. In this role,
what type of tool is the proxy acting as?
Answer choices
- Public key infrastructure (PKI)
- Antivirus software
- Firewall
- Penetration testing tool
Explanation
When an application proxy inspects, filters, and blocks network traffic based
on security criteria, it is serving as a firewall.
Question 20
Question: An enterprise runs periodic, simulated phishing campaigns to evaluate how
well employees spot suspicious emails. Which threat vector is this security exercise
designed to combat?
Answer choices
- Application vulnerabilities
- Social engineering
- Detective controls failure
- Preventive controls failure
Explanation
Phishing is a human-centric social engineering threat, making awareness
simulations the ideal method for testing user behaviors.
Questions 21-30: Access Control Policies & MFA
Question 21
Question: A file sharing system denies access to guests, grants read-only access to
standard users, and provides full modify permissions to administrators based on their job
requirements. Which security principle is being demonstrated?
Answer choices
- Input validation
- Auditing
- Least privilege
- Encryption
Explanation
The principle of least privilege ensures users are given only the bare
minimum rights necessary to perform their roles.
Question 22
Question: Which type of security solution acts as the primary perimeter defense tool to
control the entry and exit of traffic based on organizational security rules?
Answer choices
- VPN
- Antivirus
- Firewall
- Intrusion Detection System (IDS)
Explanation
Firewalls are gatekeepers that explicitly monitor and filter data traffic trying
to enter or leave a network segment.
Question 23
Question: An IT department wants to block employees from accessing personal external
webmail providers (such as Gmail or Yahoo) via work browsers. Which solution should
they configure?
Answer choices
- Media access control list
- SQL Server
- Proxy server
- File system access control list
Explanation
Web proxies can inspect outbound HTTP/HTTPS requests to block specific
categories of websites, like personal webmail.
Question 24
Question: A company wants to guarantee that customer and employee records stored on
an internal file server remain unreadable even if an intruder compromises the physical
server. Which solution should they deploy?
Answer choices
- Data backups
- Data encryption
- File audits
- File hashes
Explanation
Encryption translates plaintext data into unreadable ciphertext, protecting
confidentiality even if files are stolen.
Question 25
Question: A secure system grants user access only if they provide a correct
alphanumeric password and connect from an approved, specific corporate network IP
address. Which multi-factor authentication categories are used?
Answer choices
- Something you have and something you are
- Something you know and something you have
- Something you know and where you are
- Something you are and where you are
Explanation
Passwords fall under "something you know," while an IP address check
validates network location ("where you are").
Question 26
Question: An employee accesses a secure area by swiping a physical smart card and
entering a 4-digit code on an adjacent keypad. Which multi-factor authentication factors
are being combined?
Answer choices
- Something you have and something you are
- Something you know and something you have
- Something you know and where you are
- Something you are and where you are
Explanation
The physical smart card is "something you have," and the memorized
numeric PIN is "something you know."
Question 27
Question: A security analyst gathers target company information by reading public
employee profiles on LinkedIn, searching company websites, and examining public
records. Which intelligence category is this?
Answer choices
- OSINT
- SIGINT
- GEOINT
- HUMINT
Explanation
Open Source Intelligence (OSINT) is the collection and analysis of data
gathered from legally available public platforms.
Question 28
Question: An offline laptop user completes word processing and email drafting tasks
daily while logged in under a local administrator account. What asset is at the greatest
risk of compromise due to this practice?
Answer choices
- Internal email server
- Network firewall
- Operating system
- Corporate file server
Explanation
Since the laptop is offline, corporate network servers are safe, but running
local software as an admin risks exposing the local operating system to high-privilege
malware execution.
Question 29
Question: A network engineer deploys an intentionally unpatched, vulnerable server
containing fake data to distract hackers and monitor their attack methods. What is this
decoy system called?
Answer choices
- Firewall
- Scanner
- Sniffer
- Honeypot
Explanation
Honeypots are fake target systems set up to safely lure, trap, and study
hackers without endangering live company production systems.
Question 30
Question: Which authentication type requires both the client machine and the receiving
host server to validate each other's security certificates before opening a connection?
Answer choices
- Mutual
- Certificate-based
- Biometric
- Multifactor
Explanation
Mutual authentication (two-way authentication) forces both ends of a
communication channel to verify their identity to one another.
Questions 31- 40: Vulnerabilities & The CIA Triad
Question 31
Question: A software engineer discovers a coding loophole in an application's input form
that could allow external users to bypass safety controls. How is this weakness classified?
Answer choices
- Threat
- Vulnerability
- Risk
- Impact
Explanation
A vulnerability is any software, hardware, or structural weakness that could
be exploited by an adversary.
Question 32
Question: Which security feature randomizes the layout coordinates of key data
components within system memory to protect programs against buffer overflow exploits?
Answer choices
- Network segmentation
- Intrusion prevention system (IPS)
- Address space layout randomization
- Redundant array of independent disks (RAID)
Explanation
Address Space Layout Randomization (ASLR) continuously shifts memory
architectures so attackers cannot predict attack address zones.
Question 33
Question: A user unknowingly downloads a decorative screensaver that contains a
background script designed to autonomously copy and spread itself to other systems over
the local network. What type of attack is this?
Answer choices
- Injection
- Tailgating
- Pretexting
- Malware
Explanation
Worms and malicious payloads bundled inside legitimate-looking software
fall under the category of malware (malicious software).
Question 34
Question: A company secures its environment by using firewalls at the edge, network
segmentation inside, host anti-malware software, and encrypted databases. What
overarching security strategy does this represent?
Answer choices
- Access control
- Defense in depth
- Data utility
- Multifactor authentication
Explanation
Defense in depth uses independent, layered security barriers so that if one
control breaks, others are behind it to stop the threat.
Question 35
Question: Which cryptographic mechanism ensures nonrepudiation, making it impossible
for a document sender to deny that they created and transmitted a specific file?
Answer choices
- Symmetric ciphers
- Digital signature
- Hash functions
- Security token
Explanation
Digital signatures bind a file to the author's private key, mathematically
proving origin and ensuring nonrepudiation.
Question 36
Question: Which statement accurately describes a modification attack?
Answer choices
- An attack that creates or inserts false data into a system.
- An attack that makes system data or services unavailable.
- An attack that allows unauthorized users to view sensitive data.
- An attack that alters existing data on a system.
Explanation
Modification attacks target data integrity by tampering with, changing, or
overwriting valid files or settings.
Question 37
Question: Which form of keyless cryptography processes arbitrary data inputs to
generate a unique, fixed-size mathematical value used solely to verify data integrity?
Answer choices
- Symmetric cryptography
- Asymmetric cryptography
- Hash functions
- Digital certificates
Explanation
Hash functions do not use keys; they use deterministic algorithms to create
hashes that reveal if files have been tampered with.
Question 38
Question: An IT team minimizes a new server's vulnerability footprint by deleting default
user accounts, removing optional software tools, and disabling unneeded communication
ports. What is this process called?
Answer choices
- Principle of least privilege
- Operating system hardening
- Logging and auditing
- Antimalware protection
Explanation
Hardening removes unnecessary applications, protocols, and entry features
to shrink an operating system's overall attack surface.
Question 39
Question: When an organization guarantees that data received over a network exactly
matches the data originally transmitted by the sender, which pillar of the CIA triad is
maintained?
Answer choices
- Confidentiality
- Integrity
- Availability
- Identity
Explanation
Integrity deals with keeping data accurate, complete, and fully protected
from unauthorized modifications during transmission or storage.
Question 40
Question: Which core cybersecurity concept within the CIA triad focuses specifically on
ensuring that sensitive data is restricted from unauthorized viewing or disclosure?
Answer choices
- Confidentiality
- Integrity
- Availability
- Authentication
Explanation
Confidentiality protects secrets and privacy, preventing unauthorized
entities from reading or viewing secure information assets.
Questions 41-50: CIA Triad Scenarios & Attacks
Question 41
Question: An organization wants to preserve the confidentiality of a sensitive project file
stored on a shared network drive. Which action should they take?
Answer choices
- Encrypt the file
- Sign the file digitally
- Save multiple copies of the file
Explanation
Encryption scrambles data so that unauthorized entities cannot view or
understand it, satisfying confidentiality.
Question 42
Question: Which component of the CIA triad is directly compromised when an
unauthorized hacker breaks through access list rules to view private corporate data?
Answer choices
- Confidentiality
- Availability
- Integrity
Explanation
Unauthorized reading or disclosure of internal data breaches the
confidentiality pillar of security.
Question 43
Question: Which scenario represents a clear compromise of data integrity?
Answer choices
- A distributed denial-of-service (DDoS) attack makes an internal web application
- A malicious user accesses a system and makes unauthorized changes to a
- An unauthorized individual views a coworker's screen to steal sensitive credentials.
Explanation
Making unauthorized changes to database entries directly corrupts the
accuracy and validity of information, violating integrity.
Question 44
Question: Which statement describes the primary function of data integrity within the CIA
triad?
Answer choices
- Allows authorized users to access data whenever and wherever it is needed.
- Ensures proper attribution regarding who owns or created system data.
- Prevents data from being changed in an unauthorized manner.
- Protects data from those who are not authorized to view it.
Explanation
Integrity is the security principle that prevents information from being
tampered with, altered, or deleted by unauthorized sources.
Question 45
Question: A security rule ensures that document files cannot be modified or deleted by
anyone who lacks explicit write permissions. Which leg of the CIA triad does this
preserve?
Answer choices
- Confidentiality
- Integrity
- Availability
Explanation
Protecting information against unauthorized modifications or deletions
maintains its integrity.
Question 46
Question: An e-commerce company deploys redundant web servers across multiple
geographic regions to ensure their online storefront remains online and resilient to single
hardware failures. Which security leg does this support?
Answer choices
- Confidentiality
- Integrity
- Availability
Explanation
Redundancy keeps systems up and running continuously, ensuring
availability for users.
Question 47
Question: A system engineer configures a RAID array so that if a single hard drive
suffers a mechanical failure, the system stays online and accessible without losing data.
Which principle is being prioritized?
Answer choices
- Confidentiality
- Availability
- Authenticity
Explanation
RAID disk mirroring ensures continuous operational availability, preventing
system downtime due to individual drive failures.
Question 48
Question: An attacker executes an exploit that reroutes legitimate user traffic away from
a critical network service, preventing employees from connecting to it. Which security
pillar is targeted?
Answer choices
- Confidentiality
- Integrity
- Availability
- Authorization
Explanation
Disrupting or blocking legitimate access to systems, tools, or data
constitutes an attack against availability.
Question 49
Question: A business owner receives a phone call from an individual pretending to be a
bank agent who tricks them into revealing their Social Security Number and date of birth.
Which security principle was the target of this attack?
Answer choices
- Confidentiality
- Availability
- Possession
- Authenticity
Explanation
Vishing attacks that seek to harvest private personal data look to violate
data privacy and confidentiality.
Question 50
Question: A phishing email tricks an employee into inputting their account username and
password onto a fraudulent webpage. Which core security pillar is directly targeted by this
credential-harvesting scheme?
Answer choices
- Confidentiality
- Integrity
- Availability
- Identification
Explanation
Harvesting login credentials aims to grant unauthorized users entry into
private systems, jeopardizing confidentiality.
Questions 51–62: Data States, Physical Risks & The Parkerian
Hexad
Question 51
Question: A rogue user connects a packet sniffer to an unencrypted public Wi-Fi network
to intercept and read sensitive corporate communications sent by a nearby remote
worker. Which CIA triad principle is violated?
Answer choices
- Confidentiality
- Integrity
- Availability
- Authorization
Explanation
Intercepting cleartext network traffic allows unauthorized entities to view
private information, breaching confidentiality.
Question 52
Question: A corporate policy mandates the use of BitLocker full-disk encryption to
safeguard all files stored locally on company laptop drives. Which data state does this
control protect?
Answer choices
- Data in use
- Data in motion
- Data at rest
Explanation
Data at rest refers to static information stored on physical storage drives,
disks, or media.
Question 53
Question: Which security concept relies on a mathematically linked public key and
private key pair to handle secure transmissions or authenticate entities?
Answer choices
- Symmetric cryptography
- Asymmetric cryptography
- Digital signatures
- Hash functions
Explanation
Asymmetric cryptography (or public-key cryptography) is built upon the dual
public/private key system.
Question 54
Question: A financial firm installs polarized privacy screens over employee computer
monitors to prevent shoulder surfing from passersby. Which state of data is being
secured?
Answer choices
- Data at rest
- Data in motion
- Data in use
- Data in storage
Explanation
Data in use describes information actively loaded into memory, processed
by the CPU, or displayed on a screen.
Question 55
Question: High server room temperatures combined with improper relative humidity
levels cause a primary network switch to overheat and reboot unexpectedly. How is this
threat event classified?
Answer choices
- Administrative
- Physical
- Residual
Explanation
Physical environmental threats involve tangible conditions (such as climate,
fire, or water) that degrade hardware infrastructure assets.
Question 56
Question: A data center built beneath a large lake in an area prone to earthquakes faces
risks from seismic tremors, flooding, and shifting seasonal temperatures. Which set of
threats matches these scenarios?
Answer choices
- Movement, water, extreme temperatures
- Structural, liquid, external weather
- Geological, environmental, atmospheric
Explanation
Earthquakes represent movement, lakes represent water hazards, and
climate shifts represent temperature extremes.
Question 57
Question: An organization mounts magnetic platter hard drives (HDDs) inside locked
harnesses within police cruisers. Drivers find that the drives fail frequently when vehicles
traverse rugged off-road terrains. Which threat caused this failure?
Answer choices
- Unauthorized access
- Weather factors
- Rough roads
Explanation
The physical shocks and heavy vibrations of rough roads cause the
mechanical parts and read/write heads inside traditional HDDs to crash.
Question 58
Question: Which security tool is used to monitor, baseline, and immediately alert
administrators if unauthorized modifications are made to operating system files or registry
keys?
Answer choices
- SOAR
- SIEM
- IPS
- FIM
Explanation
File Integrity Monitoring (FIM) constantly validates core operating system
files and registry keys against a secure baseline to check for unauthorized alterations.
Question 59
Question: A network architect isolates public-facing web servers into a separate DMZ
network zone, keeping them completely distinct from internal servers holding credit card
data. What is this security practice called?
Answer choices
- Security awareness training
- Input validation
- Network segmentation
Explanation
Network segmentation splits networks into distinct subnets to prevent
lateral movement if one zone gets compromised.
Question 60
Question: A remote executive works from a hotel room and wants to keep their internet
traffic confidential from network sniffers operating on the hotel's shared Wi-Fi. What
solution should they use?
Answer choices
- Use a VPN connection
- Multifactor authentication
- Digital signatures
- Wired connections
Explanation
Virtual Private Networks (VPNs) create an encrypted communication tunnel
over untrusted networks to protect data in motion.
Question 61
Question: An enterprise hosts its core application source code on an air-gapped system
inside a vault protected by biometric biometric locks and security guards. Which attribute
of the Parkerian Hexad does this security posture emphasize?
Answer choices
- Integrity
- Authenticity
- Possession
- Utility
Explanation
Possession (or control) in the Parkerian Hexad relates to keeping strict
physical custody and ownership over the hardware hosting an asset.
Question 62
Question: A risk compliance officer expresses concern that transferring company records
to an external cloud database means the data will be physically controlled by a third party.
Which element of the Parkerian Hexad is missing from the CIA triad that describes this
concern?
Answer choices
- Confidentiality
- Integrity
- Possession
- Utility
Explanation
Possession explicitly defines the physical custody or control over
information assets, an element not isolated within the traditional CIA triad.
Questions 63-72: Additional Practice Questions
Question 63
Question: Which two legs of the CIA triad can be affected by a fabrication attack?
Answer choices
- Availability and integrity
- Integrity and confidentiality
- Authenticity and confidentiality
- Confidentiality and availability
Explanation
Fabricating fake data directly compromises data accuracy (integrity) and
can overload system processing resources (availability).
Question 64
Question: Which category of attack that violates integrity is represented by using a man-
in-the-middle attack to alter a web application's content with a malicious script?
Answer choices
- Modification
- Interruption
- Interception
- Fabrication
Explanation
When an attacker intercepts a traffic stream and alters its content before it
reaches the destination, it is a modification attack.
Question 65
Question: A company's internal network traffic is intercepted but not altered by an
attacker using a proxy. Which principle of the CIA triad is violated by this attack?
Answer choices
- Integrity
- Availability
- Confidentiality
- Authenticity
Explanation
Intercepting and viewing traffic without changing it leaves integrity intact but
breaches data privacy (confidentiality).
Question 66
Question: A mobile app requires users to create accounts to personalize their experience
and save preferences. Users are required to be older than 13 years old to create an
account. Which privacy guideline promotes best practices regarding the collection of
personal information for users of the mobile app?
Answer choices
- Allow users to choose whether to share personal information.
- Require users to obtain parental consent prior to account creation.
- Allow users to opt out after using the application for a week.
- Require users to provide detailed information during account creation.
Explanation
Privacy frameworks prioritize user choice and consent, granting individuals
autonomy over what personal data they share.
Question 67
Question: A retail website intends to collect email addresses to send promotional offers
and newsletters to its customers. Which privacy guideline should be prioritized by the
retail website before collecting the email addresses to promote best practices?
Answer choices
- Allow users to specify the number of offers and newsletters to be received
- Ensure email addresses are only collected from verified customers
- Require additional personal information to accompany the email address
- Provide information about how the email addresses will be used
Explanation
Under the principle of Transparency/Notice, organizations must explain the
purpose of data collection before collecting it.
Question 68
Question: A retail company in Minnesota that processes credit card transactions is
undergoing an audit. The auditors discover the company has not had a penetration test in
three years. The company must pay a fine and is not allowed to process credit card
transactions until it passes a penetration test. Which type of compliance guideline did the
company violate?
Answer choices
- State regulatory
- Federal regulatory
- Mandatory industry
- Optional industry
Explanation
Credit card handling rules are set by the PCI DSS framework, which is a
mandatory, contractually enforced industry standard rather than a government law.
Question 69
Question: Which law identifies compliance requirements for banks and financial
institutions?
Answer choices
- FERPA
- GLBA
- PCI DSS
- HIPAA
Explanation
The Gramm-Leach-Bliley Act (GLBA) is a federal US law mandating strict
data protection and privacy rules specifically for financial entities and banks.
Question 70
Question: A company has point of sale credit card systems in retail locations which are
not routinely checked for malware. Which regulation is the company violating?
Answer choices
- PCI DSS
- HIPAA
- GLBA
- SOX
Explanation
Point-of-Sale (POS) devices and credit card transaction data fall directly
under the regulatory domain of PCI DSS compliance.
Question 71
Question: Which regulation ensures all US federal agencies implement security controls
to enumerate risks and grant organizations the authority to operate (ATO)?
Answer choices
- GDPR
- HIPAA
- FISMA
- NIST
Explanation
The Federal Information Security Modernization Act (FISMA) requires
federal agencies to assess risk and secure an official Authority to Operate (ATO).
Question 72
Question: Which pair of regulations protect the confidentiality and integrity of financial
information?
Answer choices
- FISMA and SOX
- FISMA and HIPAA
- SOX and GLBA
- HIPAA and GLBA
Explanation
Sarbanes-Oxley (SOX) handles accounting integrity for public markets, and
GLBA governs consumer data security at financial institutions.
PDF Preview
Generate, preview, and download this exam record.