← Back to Past Exams Database
Verified Exam Record Score: 92%+

Fundamentals of Information Security - D430

Review this completed exam record, including subject, platform, academic level, completion details, and preview question.

Cybersecurity ProctorU - Guardian Browser University
Subject
Cybersecurity
Platform
ProctorU - Guardian Browser
Academic Level
University
Date Completed
22 Sep 2026
Preview Question

72 previously done information-security practice questions with answer choices and explanations. WGU exam questions. 

Exam Record Details

Questions 1-10: Core Infrastructure & Access Controls

Question 1

Question: A security procedure document outlines requirements for encryption of data in

transit, maintaining access lists for viewing confidential information, and performing

regular backups. Which layer of the defense-in-depth model does this document target?

Answer choices

  • Application Layer
  • Network Layer
  • Physical Layer
  • Data Layer

Explanation

The requirements focus entirely on safeguarding the data itself (via

confidentiality and availability controls) rather than network perimeters or physical locks.

Question 2

Question: A facility policy states that only IT employees are permitted entry into the

server room, and security guards must verify employee identification cards before

allowing access. Which types of access control and verification are being utilized?

Answer choices

  • Discretionary access control and nonrepudiation
  • Mandatory access control and auditing
  • Role-based access control and authentication
  • Attribute-based access control and authorization

Explanation

Restricting entry by department is role-based access control (RBAC), and

verifying physical identification credentials serves as authentication.

Question 3

Question: An organization installs warning signs, computer-controlled door locks, and

burglary alarm systems around its primary data center. Which category of security control

do these items represent?

Answer choices

  • Administrative security
  • Technical security
  • Physical security
  • Operations security

Explanation

These measures involve tangible mechanisms designed to protect physical

facilities and hardware assets from unauthorized entry.

Question 4

Question: A federal agency is looking to adopt a new cloud-based computing solution

and needs to verify that the cloud provider meets standardized federal security

assessment and continuous monitoring guidelines. Which standard covers this

requirement?

Answer choices

  • GLBA
  • SOX
  • FISMA
  • FedRAMP

Explanation

FedRAMP specifically standardizes security authorization and assessment

criteria for cloud products and services utilized by US federal agencies.

Question 5

Question: A company upgrades its network access controls by requiring employees to

use a physical smart card and enter a matching 4-digit PIN to log into their workstations.

Which security function is directly improved by this change?

Answer choices

  • Authorization
  • Authentication
  • Least privilege
  • Non-repudiation

Explanation

Smart cards and PINs serve as multi-factor authentication (MFA), validating

that the user is exactly who they claim to be.

Question 6

Question: Which security mechanism serves as an example of a preventive control?

Answer choices

  • Warning signs
  • Burglary alarm systems
  • Intrusion detection systems (IDS)
  • Mechanical locks

Explanation

Mechanical locks are a preventive control because they actively block an

adversary from entering a restricted space.

Question 7

Question: An organization implements software-based cryptographic algorithms to

scramble files and protect information confidentiality. Which control type does this

represent?

Answer choices

  • Administrative
  • Physical
  • Technical
  • Deterrent

Explanation

Technical controls (or logical controls) use hardware, software, or firmware

mechanisms to protect systems and data.

Question 8

Question: Which type of passive attack targets data confidentiality by capturing data

streams while in transit without altering the content, making it highly difficult to detect?

Answer choices

  • Interruption
  • Interception
  • Modification
  • Fabrication

Explanation

Interception involves unauthorized reading or wiretapping of data streams,

which directly undermines data privacy/confidentiality.

Question 9

Question: Which tool is specifically used on websites to prevent automated software

scripts and bots from submitting forms or spamming web pages?

Answer choices

  • Firewall
  • Vulnerability scanner
  • Captchas
  • Intrusion Detection System (IDS)

Explanation

CAPTCHAs test whether an online user is a real human being or an

automated script.

Question 10

Question: Which device acts as an intermediary between an internal network user and

the internet, allowing administrators to filter web traffic against an access control list

(ACL)?

Answer choices

  • Proxy server
  • Intrusion detection system
  • Digital signature
  • Honeypot

Explanation

A proxy server acts as a gateway that checks outgoing requests and blocks

unauthorized websites using an ACL.

Questions 11–20: Network Defense & Deceptive Attacks

Question 11

Question: Which mechanism provides non-repudiation by cryptographically binding a

sender's unique private key to an outgoing email message?

Answer choices

  • Symmetric encryption
  • Digital signatures
  • Password salting
  • Substitution ciphers

Explanation

Digital signatures mathematically prove authorship, preventing the sender

from falsely denying they sent the message.

Question 12

Question: Which type of server can be implemented at a network boundary to inspect

and filter out incoming malicious content, such as spam emails, before it reaches user

inboxes?

Answer choices

  • FTP server
  • DNS server
  • Proxy server
  • Web server

Explanation

Mail or content proxy servers filter incoming network applications to stop

unwanted spam and malicious payloads.

Question 13

Question: Multiple system administrators are currently logging into servers using a

shared root account, making it impossible to audit individual actions. Which remediation

strategy best resolves this accountability vulnerability?

Answer choices

  • Review the audit logs daily
  • Implement password management tools
  • Update all system patches
  • Create unique accounts

Explanation

Assigning unique credentials to every single person ensures clear individual

accountability in audit logs.

Question 14

Question: An employee receives an email that appears to be from their department

manager demanding immediate delivery of internal accounting documents. The employee

later discovers the email was spoofed. Which attack type does this describe?

Answer choices

  • Social engineering
  • Personal equipment vulnerability
  • Network usage policy violation
  • Password policy failure

Explanation

Social engineering manipulates human behavior and exploits trust/urgency

to trick targets into handing over secrets.

Question 15

Question: A security analyst wants to scan the local wireless spectrum to identify

unauthorized or rogue access points operating inside the office building. Which tool

should they use?

Answer choices

  • Shodan
  • Censys
  • Maltego
  • Kismet

Explanation

Kismet is an open-source wireless network detector, packet sniffer, and rogue access point identification tool.

Question 16

Question: A security team needs to audit system and user behaviors that took place over

the last several months. Which practice provides the historical records needed for this

review?

Answer choices

  • Real-time monitoring
  • Logging
  • Data backup
  • Record review

Explanation

Logging continually records system and network events into data storage

files to build an audit trail for historical reviews.

Question 17

Question: Which security control combines hash functions to verify data integrity

alongside public-key cryptography to verify sender authenticity?

Answer choices

  • Symmetric encryption
  • Asymmetric encryption
  • Digital signatures
  • Security tokens

Explanation

Digital signatures use asymmetric cryptography to cryptographically hash

and sign files, verifying both data integrity and origin authenticity.

Question 18

Question: An attacker exploits a system misconfiguration to gain control of a database

engine's high-level root or service account. Which term defines this security event?

Answer choices

  • Protocol issue
  • Arbitrary code execution
  • Unauthenticated access
  • Privilege escalation

Explanation

Privilege escalation happens when a lower-privileged user exploits flaws to

gain higher-level operational rights.

Question 19

Question: A proxy server stands between a private company network and the public

internet, inspecting all inbound requests to block unauthorized outside traffic. In this role,

what type of tool is the proxy acting as?

Answer choices

  • Public key infrastructure (PKI)
  • Antivirus software
  • Firewall
  • Penetration testing tool

Explanation

When an application proxy inspects, filters, and blocks network traffic based

on security criteria, it is serving as a firewall.

Question 20

Question: An enterprise runs periodic, simulated phishing campaigns to evaluate how

well employees spot suspicious emails. Which threat vector is this security exercise

designed to combat?

Answer choices

  • Application vulnerabilities
  • Social engineering
  • Detective controls failure
  • Preventive controls failure

Explanation

Phishing is a human-centric social engineering threat, making awareness

simulations the ideal method for testing user behaviors.

Questions 21-30: Access Control Policies & MFA

Question 21

Question: A file sharing system denies access to guests, grants read-only access to

standard users, and provides full modify permissions to administrators based on their job

requirements. Which security principle is being demonstrated?

Answer choices

  • Input validation
  • Auditing
  • Least privilege
  • Encryption

Explanation

The principle of least privilege ensures users are given only the bare

minimum rights necessary to perform their roles.

Question 22

Question: Which type of security solution acts as the primary perimeter defense tool to

control the entry and exit of traffic based on organizational security rules?

Answer choices

  • VPN
  • Antivirus
  • Firewall
  • Intrusion Detection System (IDS)

Explanation

Firewalls are gatekeepers that explicitly monitor and filter data traffic trying

to enter or leave a network segment.

Question 23

Question: An IT department wants to block employees from accessing personal external

webmail providers (such as Gmail or Yahoo) via work browsers. Which solution should

they configure?

Answer choices

  • Media access control list
  • SQL Server
  • Proxy server
  • File system access control list

Explanation

Web proxies can inspect outbound HTTP/HTTPS requests to block specific

categories of websites, like personal webmail.

Question 24

Question: A company wants to guarantee that customer and employee records stored on

an internal file server remain unreadable even if an intruder compromises the physical

server. Which solution should they deploy?

Answer choices

  • Data backups
  • Data encryption
  • File audits
  • File hashes

Explanation

Encryption translates plaintext data into unreadable ciphertext, protecting

confidentiality even if files are stolen.

Question 25

Question: A secure system grants user access only if they provide a correct

alphanumeric password and connect from an approved, specific corporate network IP

address. Which multi-factor authentication categories are used?

Answer choices

  • Something you have and something you are
  • Something you know and something you have
  • Something you know and where you are
  • Something you are and where you are

Explanation

Passwords fall under "something you know," while an IP address check

validates network location ("where you are").

Question 26

Question: An employee accesses a secure area by swiping a physical smart card and

entering a 4-digit code on an adjacent keypad. Which multi-factor authentication factors

are being combined?

Answer choices

  • Something you have and something you are
  • Something you know and something you have
  • Something you know and where you are
  • Something you are and where you are

Explanation

The physical smart card is "something you have," and the memorized

numeric PIN is "something you know."

Question 27

Question: A security analyst gathers target company information by reading public

employee profiles on LinkedIn, searching company websites, and examining public

records. Which intelligence category is this?

Answer choices

  • OSINT
  • SIGINT
  • GEOINT
  • HUMINT

Explanation

Open Source Intelligence (OSINT) is the collection and analysis of data

gathered from legally available public platforms.

Question 28

Question: An offline laptop user completes word processing and email drafting tasks

daily while logged in under a local administrator account. What asset is at the greatest

risk of compromise due to this practice?

Answer choices

  • Internal email server
  • Network firewall
  • Operating system
  • Corporate file server

Explanation

Since the laptop is offline, corporate network servers are safe, but running

local software as an admin risks exposing the local operating system to high-privilege

malware execution.

Question 29

Question: A network engineer deploys an intentionally unpatched, vulnerable server

containing fake data to distract hackers and monitor their attack methods. What is this

decoy system called?

Answer choices

  • Firewall
  • Scanner
  • Sniffer
  • Honeypot

Explanation

Honeypots are fake target systems set up to safely lure, trap, and study

hackers without endangering live company production systems.

Question 30

Question: Which authentication type requires both the client machine and the receiving

host server to validate each other's security certificates before opening a connection?

Answer choices

  • Mutual
  • Certificate-based
  • Biometric
  • Multifactor

Explanation

Mutual authentication (two-way authentication) forces both ends of a

communication channel to verify their identity to one another.

Questions 31- 40: Vulnerabilities & The CIA Triad

Question 31

Question: A software engineer discovers a coding loophole in an application's input form

that could allow external users to bypass safety controls. How is this weakness classified?

Answer choices

  • Threat
  • Vulnerability
  • Risk
  • Impact

Explanation

A vulnerability is any software, hardware, or structural weakness that could

be exploited by an adversary.

Question 32

Question: Which security feature randomizes the layout coordinates of key data

components within system memory to protect programs against buffer overflow exploits?

Answer choices

  • Network segmentation
  • Intrusion prevention system (IPS)
  • Address space layout randomization
  • Redundant array of independent disks (RAID)

Explanation

Address Space Layout Randomization (ASLR) continuously shifts memory

architectures so attackers cannot predict attack address zones.

Question 33

Question: A user unknowingly downloads a decorative screensaver that contains a

background script designed to autonomously copy and spread itself to other systems over

the local network. What type of attack is this?

Answer choices

  • Injection
  • Tailgating
  • Pretexting
  • Malware

Explanation

Worms and malicious payloads bundled inside legitimate-looking software

fall under the category of malware (malicious software).

Question 34

Question: A company secures its environment by using firewalls at the edge, network

segmentation inside, host anti-malware software, and encrypted databases. What

overarching security strategy does this represent?

Answer choices

  • Access control
  • Defense in depth
  • Data utility
  • Multifactor authentication

Explanation

Defense in depth uses independent, layered security barriers so that if one

control breaks, others are behind it to stop the threat.

Question 35

Question: Which cryptographic mechanism ensures nonrepudiation, making it impossible

for a document sender to deny that they created and transmitted a specific file?

Answer choices

  • Symmetric ciphers
  • Digital signature
  • Hash functions
  • Security token

Explanation

Digital signatures bind a file to the author's private key, mathematically

proving origin and ensuring nonrepudiation.

Question 36

Question: Which statement accurately describes a modification attack?

Answer choices

  • An attack that creates or inserts false data into a system.
  • An attack that makes system data or services unavailable.
  • An attack that allows unauthorized users to view sensitive data.
  • An attack that alters existing data on a system.

Explanation

Modification attacks target data integrity by tampering with, changing, or

overwriting valid files or settings.

Question 37

Question: Which form of keyless cryptography processes arbitrary data inputs to

generate a unique, fixed-size mathematical value used solely to verify data integrity?

Answer choices

  • Symmetric cryptography
  • Asymmetric cryptography
  • Hash functions
  • Digital certificates

Explanation

Hash functions do not use keys; they use deterministic algorithms to create

hashes that reveal if files have been tampered with.

Question 38

Question: An IT team minimizes a new server's vulnerability footprint by deleting default

user accounts, removing optional software tools, and disabling unneeded communication

ports. What is this process called?

Answer choices

  • Principle of least privilege
  • Operating system hardening
  • Logging and auditing
  • Antimalware protection

Explanation

Hardening removes unnecessary applications, protocols, and entry features

to shrink an operating system's overall attack surface.

Question 39

Question: When an organization guarantees that data received over a network exactly

matches the data originally transmitted by the sender, which pillar of the CIA triad is

maintained?

Answer choices

  • Confidentiality
  • Integrity
  • Availability
  • Identity

Explanation

Integrity deals with keeping data accurate, complete, and fully protected

from unauthorized modifications during transmission or storage.

Question 40

Question: Which core cybersecurity concept within the CIA triad focuses specifically on

ensuring that sensitive data is restricted from unauthorized viewing or disclosure?

Answer choices

  • Confidentiality
  • Integrity
  • Availability
  • Authentication

Explanation

Confidentiality protects secrets and privacy, preventing unauthorized

entities from reading or viewing secure information assets.

Questions 41-50: CIA Triad Scenarios & Attacks

Question 41

Question: An organization wants to preserve the confidentiality of a sensitive project file

stored on a shared network drive. Which action should they take?

Answer choices

  • Encrypt the file
  • Sign the file digitally
  • Save multiple copies of the file

Explanation

Encryption scrambles data so that unauthorized entities cannot view or

understand it, satisfying confidentiality.

Question 42

Question: Which component of the CIA triad is directly compromised when an

unauthorized hacker breaks through access list rules to view private corporate data?

Answer choices

  • Confidentiality
  • Availability
  • Integrity

Explanation

Unauthorized reading or disclosure of internal data breaches the

confidentiality pillar of security.

Question 43

Question: Which scenario represents a clear compromise of data integrity?

Answer choices

  • A distributed denial-of-service (DDoS) attack makes an internal web application
  • A malicious user accesses a system and makes unauthorized changes to a
  • An unauthorized individual views a coworker's screen to steal sensitive credentials.

Explanation

Making unauthorized changes to database entries directly corrupts the

accuracy and validity of information, violating integrity.

Question 44

Question: Which statement describes the primary function of data integrity within the CIA

triad?

Answer choices

  • Allows authorized users to access data whenever and wherever it is needed.
  • Ensures proper attribution regarding who owns or created system data.
  • Prevents data from being changed in an unauthorized manner.
  • Protects data from those who are not authorized to view it.

Explanation

Integrity is the security principle that prevents information from being

tampered with, altered, or deleted by unauthorized sources.

Question 45

Question: A security rule ensures that document files cannot be modified or deleted by

anyone who lacks explicit write permissions. Which leg of the CIA triad does this

preserve?

Answer choices

  • Confidentiality
  • Integrity
  • Availability

Explanation

Protecting information against unauthorized modifications or deletions

maintains its integrity.

Question 46

Question: An e-commerce company deploys redundant web servers across multiple

geographic regions to ensure their online storefront remains online and resilient to single

hardware failures. Which security leg does this support?

Answer choices

  • Confidentiality
  • Integrity
  • Availability

Explanation

Redundancy keeps systems up and running continuously, ensuring

availability for users.

Question 47

Question: A system engineer configures a RAID array so that if a single hard drive

suffers a mechanical failure, the system stays online and accessible without losing data.

Which principle is being prioritized?

Answer choices

  • Confidentiality
  • Availability
  • Authenticity

Explanation

RAID disk mirroring ensures continuous operational availability, preventing

system downtime due to individual drive failures.

Question 48

Question: An attacker executes an exploit that reroutes legitimate user traffic away from

a critical network service, preventing employees from connecting to it. Which security

pillar is targeted?

Answer choices

  • Confidentiality
  • Integrity
  • Availability
  • Authorization

Explanation

Disrupting or blocking legitimate access to systems, tools, or data

constitutes an attack against availability.

Question 49

Question: A business owner receives a phone call from an individual pretending to be a

bank agent who tricks them into revealing their Social Security Number and date of birth.

Which security principle was the target of this attack?

Answer choices

  • Confidentiality
  • Availability
  • Possession
  • Authenticity

Explanation

Vishing attacks that seek to harvest private personal data look to violate

data privacy and confidentiality.

Question 50

Question: A phishing email tricks an employee into inputting their account username and

password onto a fraudulent webpage. Which core security pillar is directly targeted by this

credential-harvesting scheme?

Answer choices

  • Confidentiality
  • Integrity
  • Availability
  • Identification

Explanation

Harvesting login credentials aims to grant unauthorized users entry into

private systems, jeopardizing confidentiality.

Questions 51–62: Data States, Physical Risks & The Parkerian

Hexad

Question 51

Question: A rogue user connects a packet sniffer to an unencrypted public Wi-Fi network

to intercept and read sensitive corporate communications sent by a nearby remote

worker. Which CIA triad principle is violated?

Answer choices

  • Confidentiality
  • Integrity
  • Availability
  • Authorization

Explanation

Intercepting cleartext network traffic allows unauthorized entities to view

private information, breaching confidentiality.

Question 52

Question: A corporate policy mandates the use of BitLocker full-disk encryption to

safeguard all files stored locally on company laptop drives. Which data state does this

control protect?

Answer choices

  • Data in use
  • Data in motion
  • Data at rest

Explanation

Data at rest refers to static information stored on physical storage drives,

disks, or media.

Question 53

Question: Which security concept relies on a mathematically linked public key and

private key pair to handle secure transmissions or authenticate entities?

Answer choices

  • Symmetric cryptography
  • Asymmetric cryptography
  • Digital signatures
  • Hash functions

Explanation

Asymmetric cryptography (or public-key cryptography) is built upon the dual

public/private key system.

Question 54

Question: A financial firm installs polarized privacy screens over employee computer

monitors to prevent shoulder surfing from passersby. Which state of data is being

secured?

Answer choices

  • Data at rest
  • Data in motion
  • Data in use
  • Data in storage

Explanation

Data in use describes information actively loaded into memory, processed

by the CPU, or displayed on a screen.

Question 55

Question: High server room temperatures combined with improper relative humidity

levels cause a primary network switch to overheat and reboot unexpectedly. How is this

threat event classified?

Answer choices

  • Administrative
  • Physical
  • Residual

Explanation

Physical environmental threats involve tangible conditions (such as climate,

fire, or water) that degrade hardware infrastructure assets.

Question 56

Question: A data center built beneath a large lake in an area prone to earthquakes faces

risks from seismic tremors, flooding, and shifting seasonal temperatures. Which set of

threats matches these scenarios?

Answer choices

  • Movement, water, extreme temperatures
  • Structural, liquid, external weather
  • Geological, environmental, atmospheric

Explanation

Earthquakes represent movement, lakes represent water hazards, and

climate shifts represent temperature extremes.

Question 57

Question: An organization mounts magnetic platter hard drives (HDDs) inside locked

harnesses within police cruisers. Drivers find that the drives fail frequently when vehicles

traverse rugged off-road terrains. Which threat caused this failure?

Answer choices

  • Unauthorized access
  • Weather factors
  • Rough roads

Explanation

The physical shocks and heavy vibrations of rough roads cause the

mechanical parts and read/write heads inside traditional HDDs to crash.

Question 58

Question: Which security tool is used to monitor, baseline, and immediately alert

administrators if unauthorized modifications are made to operating system files or registry

keys?

Answer choices

  • SOAR
  • SIEM
  • IPS
  • FIM

Explanation

File Integrity Monitoring (FIM) constantly validates core operating system

files and registry keys against a secure baseline to check for unauthorized alterations.

Question 59

Question: A network architect isolates public-facing web servers into a separate DMZ

network zone, keeping them completely distinct from internal servers holding credit card

data. What is this security practice called?

Answer choices

  • Security awareness training
  • Input validation
  • Network segmentation

Explanation

Network segmentation splits networks into distinct subnets to prevent

lateral movement if one zone gets compromised.

Question 60

Question: A remote executive works from a hotel room and wants to keep their internet

traffic confidential from network sniffers operating on the hotel's shared Wi-Fi. What

solution should they use?

Answer choices

  • Use a VPN connection
  • Multifactor authentication
  • Digital signatures
  • Wired connections

Explanation

Virtual Private Networks (VPNs) create an encrypted communication tunnel

over untrusted networks to protect data in motion.

Question 61

Question: An enterprise hosts its core application source code on an air-gapped system

inside a vault protected by biometric biometric locks and security guards. Which attribute

of the Parkerian Hexad does this security posture emphasize?

Answer choices

  • Integrity
  • Authenticity
  • Possession
  • Utility

Explanation

Possession (or control) in the Parkerian Hexad relates to keeping strict

physical custody and ownership over the hardware hosting an asset.

Question 62

Question: A risk compliance officer expresses concern that transferring company records

to an external cloud database means the data will be physically controlled by a third party.

Which element of the Parkerian Hexad is missing from the CIA triad that describes this

concern?

Answer choices

  • Confidentiality
  • Integrity
  • Possession
  • Utility

Explanation

Possession explicitly defines the physical custody or control over

information assets, an element not isolated within the traditional CIA triad.

Questions 63-72: Additional Practice Questions

Question 63

Question: Which two legs of the CIA triad can be affected by a fabrication attack?

Answer choices

  • Availability and integrity
  • Integrity and confidentiality
  • Authenticity and confidentiality
  • Confidentiality and availability

Explanation

Fabricating fake data directly compromises data accuracy (integrity) and

can overload system processing resources (availability).

Question 64

Question: Which category of attack that violates integrity is represented by using a man-

in-the-middle attack to alter a web application's content with a malicious script?

Answer choices

  • Modification
  • Interruption
  • Interception
  • Fabrication

Explanation

When an attacker intercepts a traffic stream and alters its content before it

reaches the destination, it is a modification attack.

Question 65

Question: A company's internal network traffic is intercepted but not altered by an

attacker using a proxy. Which principle of the CIA triad is violated by this attack?

Answer choices

  • Integrity
  • Availability
  • Confidentiality
  • Authenticity

Explanation

Intercepting and viewing traffic without changing it leaves integrity intact but

breaches data privacy (confidentiality).

Question 66

Question: A mobile app requires users to create accounts to personalize their experience

and save preferences. Users are required to be older than 13 years old to create an

account. Which privacy guideline promotes best practices regarding the collection of

personal information for users of the mobile app?

Answer choices

  • Allow users to choose whether to share personal information.
  • Require users to obtain parental consent prior to account creation.
  • Allow users to opt out after using the application for a week.
  • Require users to provide detailed information during account creation.

Explanation

Privacy frameworks prioritize user choice and consent, granting individuals

autonomy over what personal data they share.

Question 67

Question: A retail website intends to collect email addresses to send promotional offers

and newsletters to its customers. Which privacy guideline should be prioritized by the

retail website before collecting the email addresses to promote best practices?

Answer choices

  • Allow users to specify the number of offers and newsletters to be received
  • Ensure email addresses are only collected from verified customers
  • Require additional personal information to accompany the email address
  • Provide information about how the email addresses will be used

Explanation

Under the principle of Transparency/Notice, organizations must explain the

purpose of data collection before collecting it.

Question 68

Question: A retail company in Minnesota that processes credit card transactions is

undergoing an audit. The auditors discover the company has not had a penetration test in

three years. The company must pay a fine and is not allowed to process credit card

transactions until it passes a penetration test. Which type of compliance guideline did the

company violate?

Answer choices

  • State regulatory
  • Federal regulatory
  • Mandatory industry
  • Optional industry

Explanation

Credit card handling rules are set by the PCI DSS framework, which is a

mandatory, contractually enforced industry standard rather than a government law.

Question 69

Question: Which law identifies compliance requirements for banks and financial

institutions?

Answer choices

  • FERPA
  • GLBA
  • PCI DSS
  • HIPAA

Explanation

The Gramm-Leach-Bliley Act (GLBA) is a federal US law mandating strict

data protection and privacy rules specifically for financial entities and banks.

Question 70

Question: A company has point of sale credit card systems in retail locations which are

not routinely checked for malware. Which regulation is the company violating?

Answer choices

  • PCI DSS
  • HIPAA
  • GLBA
  • SOX

Explanation

Point-of-Sale (POS) devices and credit card transaction data fall directly

under the regulatory domain of PCI DSS compliance.

Question 71

Question: Which regulation ensures all US federal agencies implement security controls

to enumerate risks and grant organizations the authority to operate (ATO)?

Answer choices

  • GDPR
  • HIPAA
  • FISMA
  • NIST

Explanation

The Federal Information Security Modernization Act (FISMA) requires

federal agencies to assess risk and secure an official Authority to Operate (ATO).

Question 72

Question: Which pair of regulations protect the confidentiality and integrity of financial

information?

Answer choices

  • FISMA and SOX
  • FISMA and HIPAA
  • SOX and GLBA
  • HIPAA and GLBA

Explanation

Sarbanes-Oxley (SOX) handles accounting integrity for public markets, and

GLBA governs consumer data security at financial institutions.

 

PDF Preview

Generate, preview, and download this exam record.

Waiting Download PDF
Size
—
Pages
—
Created
—
Page — / —
100%
Generating PDF…
Expert Help Available

Ace Your Online Exams

Connect with trusted academic professionals for reliable test support and secure results. Order now to get started.