← Back to Past Exams Database
Verified Exam Record Score: 96%+

Fundamentals of Information Security - D430: Set 2

Review this completed exam record, including subject, platform, academic level, completion details, and preview question.

Cybersecurity ProctorU University
Subject
Cybersecurity
Platform
ProctorU
Academic Level
University
Date Completed
22 Sep 2026
Preview Question

72 previously done information-security practice questions with answer choices and explanations. WGU exam questions. 72 previously done information-security practice questions with answer choices and explanations. WGU exam questions. 

Exam Record Details

Original practice material: This 72-question set was independently authored for study and review. It is not an official WGU assessment, a ProctorU assessment, a recovered question set, or evidence of a completed exam. Use it only for independent preparation.

Fundamentals of Information Security - D430 Practice Set 2

Format: Self-paced practice
Level: University
Questions: 72 original multiple-choice items
Created: 22 Sep 2026
Study benchmark: 90%+

Questions

  1. Question 1. Which information-security term best describes this condition or objective: prevent unauthorized disclosure of sensitive information?

    1. Availability
    2. Nonrepudiation
    3. Confidentiality
    4. Integrity
    Answer and explanation

    Correct answer: C. Confidentiality
    The key idea is prevent unauthorized disclosure of sensitive information; that is the purpose of Confidentiality.

  2. Question 2. Which information-security term best describes this condition or objective: keep information accurate and protected from unauthorized alteration?

    1. Privacy
    2. Integrity
    3. Confidentiality
    4. Availability
    Answer and explanation

    Correct answer: B. Integrity
    The key idea is keep information accurate and protected from unauthorized alteration; that is the purpose of Integrity.

  3. Question 3. Which information-security term best describes this condition or objective: ensure approved users can access systems and data when required?

    1. Availability
    2. Integrity
    3. Authentication
    4. Nonrepudiation
    Answer and explanation

    Correct answer: A. Availability
    The key idea is ensure approved users can access systems and data when required; that is the purpose of Availability.

  4. Question 4. Which information-security term best describes this condition or objective: use multiple complementary safeguards so one failed control does not expose the whole asset?

    1. Single sign-on
    2. Data minimization
    3. Job rotation
    4. Defense in depth
    Answer and explanation

    Correct answer: D. Defense in depth
    The key idea is use multiple complementary safeguards so one failed control does not expose the whole asset; that is the purpose of Defense in depth.

  5. Question 5. Which information-security term best describes this condition or objective: give each user, process, or service only the access needed for its assigned task?

    1. Mandatory vacation
    2. Separation of duties
    3. Least privilege
    4. Job rotation
    Answer and explanation

    Correct answer: C. Least privilege
    The key idea is give each user, process, or service only the access needed for its assigned task; that is the purpose of Least privilege.

  6. Question 6. Which information-security term best describes this condition or objective: limit access to information to people with a justified work purpose?

    1. Key escrow
    2. Need to know
    3. Open access
    4. Job rotation
    Answer and explanation

    Correct answer: B. Need to know
    The key idea is limit access to information to people with a justified work purpose; that is the purpose of Need to know.

  7. Question 7. Which information-security term best describes this condition or objective: divide sensitive tasks so one person cannot complete an entire high-risk process alone?

    1. Separation of duties
    2. Least privilege
    3. Mandatory vacation
    4. Change freeze
    Answer and explanation

    Correct answer: A. Separation of duties
    The key idea is divide sensitive tasks so one person cannot complete an entire high-risk process alone; that is the purpose of Separation of duties.

  8. Question 8. Which information-security term best describes this condition or objective: assign permissions according to job role rather than managing every user individually?

    1. Mandatory access control
    2. Discretionary access control
    3. Attribute-based access control
    4. Role-based access control (RBAC)
    Answer and explanation

    Correct answer: D. Role-based access control (RBAC)
    The key idea is assign permissions according to job role rather than managing every user individually; that is the purpose of Role-based access control (RBAC).

  9. Question 9. Which information-security term best describes this condition or objective: allow a resource owner to decide who receives access to that resource?

    1. Role-based access control
    2. Network segmentation
    3. Discretionary access control (DAC)
    4. Mandatory access control
    Answer and explanation

    Correct answer: C. Discretionary access control (DAC)
    The key idea is allow a resource owner to decide who receives access to that resource; that is the purpose of Discretionary access control (DAC).

  10. Question 10. Which information-security term best describes this condition or objective: enforce access decisions using centrally defined labels and clearances?

    1. Least privilege
    2. Mandatory access control (MAC)
    3. Discretionary access control
    4. Role-based access control
    Answer and explanation

    Correct answer: B. Mandatory access control (MAC)
    The key idea is enforce access decisions using centrally defined labels and clearances; that is the purpose of Mandatory access control (MAC).

  11. Question 11. Which information-security term best describes this condition or objective: evaluate attributes such as department, device state, time, or location before permitting access?

    1. Attribute-based access control (ABAC)
    2. Role-based access control
    3. Mandatory access control
    4. Discretionary access control
    Answer and explanation

    Correct answer: A. Attribute-based access control (ABAC)
    The key idea is evaluate attributes such as department, device state, time, or location before permitting access; that is the purpose of Attribute-based access control (ABAC).

  12. Question 12. Which information-security term best describes this condition or objective: require evidence from more than one independent authentication factor?

    1. Single sign-on
    2. Password rotation
    3. Authorization
    4. Multi-factor authentication (MFA)
    Answer and explanation

    Correct answer: D. Multi-factor authentication (MFA)
    The key idea is require evidence from more than one independent authentication factor; that is the purpose of Multi-factor authentication (MFA).

  13. Question 13. Which information-security term best describes this condition or objective: verify that a person, service, or device is who or what it claims to be?

    1. Accounting
    2. Availability
    3. Authentication
    4. Authorization
    Answer and explanation

    Correct answer: C. Authentication
    The key idea is verify that a person, service, or device is who or what it claims to be; that is the purpose of Authentication.

  14. Question 14. Which information-security term best describes this condition or objective: decide which actions an authenticated identity is permitted to perform?

    1. Nonrepudiation
    2. Authorization
    3. Authentication
    4. Accounting
    Answer and explanation

    Correct answer: B. Authorization
    The key idea is decide which actions an authenticated identity is permitted to perform; that is the purpose of Authorization.

  15. Question 15. Which information-security term best describes this condition or objective: record activity so actions can be traced to an identity and reviewed later?

    1. Accounting
    2. Authorization
    3. Authentication
    4. Data masking
    Answer and explanation

    Correct answer: A. Accounting
    The key idea is record activity so actions can be traced to an identity and reviewed later; that is the purpose of Accounting.

  16. Question 16. Which information-security term best describes this condition or objective: create reliable evidence that prevents a sender or actor from credibly denying an action?

    1. Availability
    2. Confidentiality
    3. Data minimization
    4. Nonrepudiation
    Answer and explanation

    Correct answer: D. Nonrepudiation
    The key idea is create reliable evidence that prevents a sender or actor from credibly denying an action; that is the purpose of Nonrepudiation.

  17. Question 17. Which information-security term best describes this condition or objective: produce a fixed-length value used to detect whether data has changed?

    1. Tokenization
    2. Compression
    3. Hashing
    4. Encryption
    Answer and explanation

    Correct answer: C. Hashing
    The key idea is produce a fixed-length value used to detect whether data has changed; that is the purpose of Hashing.

  18. Question 18. Which information-security term best describes this condition or objective: add unique random data before hashing passwords to make precomputed attacks less useful?

    1. Tokenization
    2. Salting
    3. Key rotation
    4. Data masking
    Answer and explanation

    Correct answer: B. Salting
    The key idea is add unique random data before hashing passwords to make precomputed attacks less useful; that is the purpose of Salting.

  19. Question 19. Which information-security term best describes this condition or objective: use the same secret key to encrypt and decrypt data?

    1. Symmetric encryption
    2. Asymmetric encryption
    3. Hashing
    4. Digital signing
    Answer and explanation

    Correct answer: A. Symmetric encryption
    The key idea is use the same secret key to encrypt and decrypt data; that is the purpose of Symmetric encryption.

  20. Question 20. Which information-security term best describes this condition or objective: use a related public and private key pair for cryptographic operations?

    1. Symmetric encryption
    2. Hashing
    3. Steganography
    4. Asymmetric encryption
    Answer and explanation

    Correct answer: D. Asymmetric encryption
    The key idea is use a related public and private key pair for cryptographic operations; that is the purpose of Asymmetric encryption.

  21. Question 21. Which information-security term best describes this condition or objective: use cryptography to verify message origin and detect alteration?

    1. Symmetric encryption
    2. Access control list
    3. Digital signature
    4. Data compression
    Answer and explanation

    Correct answer: C. Digital signature
    The key idea is use cryptography to verify message origin and detect alteration; that is the purpose of Digital signature.

  22. Question 22. Which information-security term best describes this condition or objective: manage certificates, public keys, and trust relationships for public-key cryptography?

    1. Secure shell
    2. Public key infrastructure (PKI)
    3. Virtual private network
    4. Network address translation
    Answer and explanation

    Correct answer: B. Public key infrastructure (PKI)
    The key idea is manage certificates, public keys, and trust relationships for public-key cryptography; that is the purpose of Public key infrastructure (PKI).

  23. Question 23. Which information-security term best describes this condition or objective: issue and validate digital certificates that bind identities to public keys?

    1. Certificate authority (CA)
    2. Network switch
    3. Security information and event management
    4. Keylogger
    Answer and explanation

    Correct answer: A. Certificate authority (CA)
    The key idea is issue and validate digital certificates that bind identities to public keys; that is the purpose of Certificate authority (CA).

  24. Question 24. Which information-security term best describes this condition or objective: protect data exchanged between a client and server over a network connection?

    1. Secure file transfer
    2. Virtual private network
    3. Data loss prevention
    4. Transport Layer Security (TLS)
    Answer and explanation

    Correct answer: D. Transport Layer Security (TLS)
    The key idea is protect data exchanged between a client and server over a network connection; that is the purpose of Transport Layer Security (TLS).

  25. Question 25. Which information-security term best describes this condition or objective: create an encrypted tunnel across an untrusted network?

    1. Proxy server
    2. Web application firewall
    3. Virtual private network (VPN)
    4. Wireless access point
    Answer and explanation

    Correct answer: C. Virtual private network (VPN)
    The key idea is create an encrypted tunnel across an untrusted network; that is the purpose of Virtual private network (VPN).

  26. Question 26. Which information-security term best describes this condition or objective: apply traffic rules to allow, deny, or restrict network connections?

    1. Digital certificate
    2. Firewall
    3. Intrusion detection system
    4. Proxy cache
    Answer and explanation

    Correct answer: B. Firewall
    The key idea is apply traffic rules to allow, deny, or restrict network connections; that is the purpose of Firewall.

  27. Question 27. Which information-security term best describes this condition or objective: observe events or traffic and alert when suspicious activity is detected?

    1. Intrusion detection system (IDS)
    2. Intrusion prevention system
    3. Firewall
    4. Data loss prevention
    Answer and explanation

    Correct answer: A. Intrusion detection system (IDS)
    The key idea is observe events or traffic and alert when suspicious activity is detected; that is the purpose of Intrusion detection system (IDS).

  28. Question 28. Which information-security term best describes this condition or objective: detect malicious traffic and actively block or interrupt it?

    1. Intrusion detection system
    2. Log retention
    3. Vulnerability scanner
    4. Intrusion prevention system (IPS)
    Answer and explanation

    Correct answer: D. Intrusion prevention system (IPS)
    The key idea is detect malicious traffic and actively block or interrupt it; that is the purpose of Intrusion prevention system (IPS).

  29. Question 29. Which information-security term best describes this condition or objective: broker requests between a client and another service while applying policy or filtering?

    1. Wireless controller
    2. Endpoint agent
    3. Proxy server
    4. Certificate authority
    Answer and explanation

    Correct answer: C. Proxy server
    The key idea is broker requests between a client and another service while applying policy or filtering; that is the purpose of Proxy server.

  30. Question 30. Which information-security term best describes this condition or objective: filter HTTP requests to help protect a web application from common web attacks?

    1. Virtual private network
    2. Web application firewall (WAF)
    3. Network switch
    4. Data backup
    Answer and explanation

    Correct answer: B. Web application firewall (WAF)
    The key idea is filter HTTP requests to help protect a web application from common web attacks; that is the purpose of Web application firewall (WAF).

  31. Question 31. Which information-security term best describes this condition or objective: detect and help stop sensitive data from leaving approved channels?

    1. Data loss prevention (DLP)
    2. Patch management
    3. Network segmentation
    4. Data compression
    Answer and explanation

    Correct answer: A. Data loss prevention (DLP)
    The key idea is detect and help stop sensitive data from leaving approved channels; that is the purpose of Data loss prevention (DLP).

  32. Question 32. Which information-security term best describes this condition or objective: centralize and correlate security logs to support monitoring and investigation?

    1. Certificate authority
    2. Data warehouse
    3. Virtual private network
    4. Security information and event management (SIEM)
    Answer and explanation

    Correct answer: D. Security information and event management (SIEM)
    The key idea is centralize and correlate security logs to support monitoring and investigation; that is the purpose of Security information and event management (SIEM).

  33. Question 33. Which information-security term best describes this condition or objective: keep security records long enough to support troubleshooting, audit, and investigation?

    1. Key revocation
    2. Job rotation
    3. Log retention
    4. Data destruction
    Answer and explanation

    Correct answer: C. Log retention
    The key idea is keep security records long enough to support troubleshooting, audit, and investigation; that is the purpose of Log retention.

  34. Question 34. Which information-security term best describes this condition or objective: identify known weaknesses or misconfigurations in systems using automated checks?

    1. Disaster recovery
    2. Vulnerability scanning
    3. Penetration testing
    4. Threat hunting
    Answer and explanation

    Correct answer: B. Vulnerability scanning
    The key idea is identify known weaknesses or misconfigurations in systems using automated checks; that is the purpose of Vulnerability scanning.

  35. Question 35. Which information-security term best describes this condition or objective: conduct an authorized, bounded attempt to validate whether weaknesses can be exploited?

    1. Penetration testing
    2. Vulnerability scanning
    3. Change management
    4. Business impact analysis
    Answer and explanation

    Correct answer: A. Penetration testing
    The key idea is conduct an authorized, bounded attempt to validate whether weaknesses can be exploited; that is the purpose of Penetration testing.

  36. Question 36. Which information-security term best describes this condition or objective: identify assets, threats, vulnerabilities, likelihood, and impact to prioritize treatment?

    1. Risk transfer
    2. Log retention
    3. Patch deployment
    4. Risk assessment
    Answer and explanation

    Correct answer: D. Risk assessment
    The key idea is identify assets, threats, vulnerabilities, likelihood, and impact to prioritize treatment; that is the purpose of Risk assessment.

  37. Question 37. Which information-security term best describes this condition or objective: stop or change an activity so the associated risk is no longer accepted?

    1. Risk transfer
    2. Risk mitigation
    3. Risk avoidance
    4. Risk acceptance
    Answer and explanation

    Correct answer: C. Risk avoidance
    The key idea is stop or change an activity so the associated risk is no longer accepted; that is the purpose of Risk avoidance.

  38. Question 38. Which information-security term best describes this condition or objective: shift some financial consequences of risk to another party through a contract or insurance?

    1. Risk mitigation
    2. Risk transfer
    3. Risk avoidance
    4. Risk acceptance
    Answer and explanation

    Correct answer: B. Risk transfer
    The key idea is shift some financial consequences of risk to another party through a contract or insurance; that is the purpose of Risk transfer.

  39. Question 39. Which information-security term best describes this condition or objective: reduce either the likelihood or impact of a risk through safeguards?

    1. Risk mitigation
    2. Risk transfer
    3. Risk acceptance
    4. Risk avoidance
    Answer and explanation

    Correct answer: A. Risk mitigation
    The key idea is reduce either the likelihood or impact of a risk through safeguards; that is the purpose of Risk mitigation.

  40. Question 40. Which information-security term best describes this condition or objective: identify critical processes and the consequences of disruption?

    1. Vulnerability scanning
    2. Change management
    3. Threat intelligence
    4. Business impact analysis (BIA)
    Answer and explanation

    Correct answer: D. Business impact analysis (BIA)
    The key idea is identify critical processes and the consequences of disruption; that is the purpose of Business impact analysis (BIA).

  41. Question 41. Which information-security term best describes this condition or objective: restore technology and data after a major disruption?

    1. Job rotation
    2. Data classification
    3. Disaster recovery (DR)
    4. Business continuity planning
    Answer and explanation

    Correct answer: C. Disaster recovery (DR)
    The key idea is restore technology and data after a major disruption; that is the purpose of Disaster recovery (DR).

  42. Question 42. Which information-security term best describes this condition or objective: keep critical business functions operating during and after disruption?

    1. Data retention
    2. Business continuity planning (BCP)
    3. Disaster recovery
    4. Patch management
    Answer and explanation

    Correct answer: B. Business continuity planning (BCP)
    The key idea is keep critical business functions operating during and after disruption; that is the purpose of Business continuity planning (BCP).

  43. Question 43. Which information-security term best describes this condition or objective: prepare for, detect, contain, eradicate, and recover from security incidents?

    1. Incident response
    2. Business continuity
    3. Risk acceptance
    4. Change control
    Answer and explanation

    Correct answer: A. Incident response
    The key idea is prepare for, detect, contain, eradicate, and recover from security incidents; that is the purpose of Incident response.

  44. Question 44. Which information-security term best describes this condition or objective: document who handled evidence, when, and how it was preserved?

    1. Data classification
    2. Asset inventory
    3. Key management
    4. Chain of custody
    Answer and explanation

    Correct answer: D. Chain of custody
    The key idea is document who handled evidence, when, and how it was preserved; that is the purpose of Chain of custody.

  45. Question 45. Which information-security term best describes this condition or objective: use deceptive messages to trick recipients into revealing information or taking unsafe action?

    1. SQL injection
    2. Privilege escalation
    3. Phishing
    4. DDoS
    Answer and explanation

    Correct answer: C. Phishing
    The key idea is use deceptive messages to trick recipients into revealing information or taking unsafe action; that is the purpose of Phishing.

  46. Question 46. Which information-security term best describes this condition or objective: target a specific person or group with a tailored deceptive message?

    1. Watering-hole attack
    2. Spear phishing
    3. Generic phishing
    4. Brute-force attack
    Answer and explanation

    Correct answer: B. Spear phishing
    The key idea is target a specific person or group with a tailored deceptive message; that is the purpose of Spear phishing.

  47. Question 47. Which information-security term best describes this condition or objective: manipulate people into bypassing normal security judgment or procedure?

    1. Social engineering
    2. Network segmentation
    3. Data masking
    4. Patch management
    Answer and explanation

    Correct answer: A. Social engineering
    The key idea is manipulate people into bypassing normal security judgment or procedure; that is the purpose of Social engineering.

  48. Question 48. Which information-security term best describes this condition or objective: malware that denies access to data or systems while demanding payment?

    1. Spyware
    2. Rootkit
    3. Adware
    4. Ransomware
    Answer and explanation

    Correct answer: D. Ransomware
    The key idea is malware that denies access to data or systems while demanding payment; that is the purpose of Ransomware.

  49. Question 49. Which information-security term best describes this condition or objective: software intentionally designed to harm, disrupt, spy on, or gain unauthorized access?

    1. Firmware
    2. Data cache
    3. Malware
    4. Middleware
    Answer and explanation

    Correct answer: C. Malware
    The key idea is software intentionally designed to harm, disrupt, spy on, or gain unauthorized access; that is the purpose of Malware.

  50. Question 50. Which information-security term best describes this condition or objective: abuse unsafe database queries by supplying malicious input?

    1. Session timeout
    2. SQL injection
    3. Cross-site scripting
    4. DNS caching
    Answer and explanation

    Correct answer: B. SQL injection
    The key idea is abuse unsafe database queries by supplying malicious input; that is the purpose of SQL injection.

  51. Question 51. Which information-security term best describes this condition or objective: cause a web application to deliver untrusted script to another user's browser?

    1. Cross-site scripting (XSS)
    2. SQL injection
    3. Packet filtering
    4. Data encryption
    Answer and explanation

    Correct answer: A. Cross-site scripting (XSS)
    The key idea is cause a web application to deliver untrusted script to another user's browser; that is the purpose of Cross-site scripting (XSS).

  52. Question 52. Which information-security term best describes this condition or objective: write beyond intended memory boundaries and potentially alter program behavior?

    1. SQL injection
    2. Clickjacking
    3. DNS poisoning
    4. Buffer overflow
    Answer and explanation

    Correct answer: D. Buffer overflow
    The key idea is write beyond intended memory boundaries and potentially alter program behavior; that is the purpose of Buffer overflow.

  53. Question 53. Which information-security term best describes this condition or objective: gain permissions beyond those originally granted?

    1. Data classification
    2. Network segmentation
    3. Privilege escalation
    4. Credential rotation
    Answer and explanation

    Correct answer: C. Privilege escalation
    The key idea is gain permissions beyond those originally granted; that is the purpose of Privilege escalation.

  54. Question 54. Which information-security term best describes this condition or objective: repeatedly try credentials or keys until a valid one is found?

    1. Session management
    2. Brute-force attack
    3. Spear phishing
    4. Data masking
    Answer and explanation

    Correct answer: B. Brute-force attack
    The key idea is repeatedly try credentials or keys until a valid one is found; that is the purpose of Brute-force attack.

  55. Question 55. Which information-security term best describes this condition or objective: test previously exposed username-password pairs on other services?

    1. Credential stuffing
    2. Password salting
    3. Tokenization
    4. Data classification
    Answer and explanation

    Correct answer: A. Credential stuffing
    The key idea is test previously exposed username-password pairs on other services; that is the purpose of Credential stuffing.

  56. Question 56. Which information-security term best describes this condition or objective: overwhelm a service with traffic from many sources to reduce availability?

    1. Data exfiltration
    2. Privilege escalation
    3. Phishing
    4. Distributed denial-of-service (DDoS)
    Answer and explanation

    Correct answer: D. Distributed denial-of-service (DDoS)
    The key idea is overwhelm a service with traffic from many sources to reduce availability; that is the purpose of Distributed denial-of-service (DDoS).

  57. Question 57. Which information-security term best describes this condition or objective: keep three copies of data on two media types with one copy offsite or otherwise isolated?

    1. Data masking
    2. Log rotation
    3. Three-two-one backup strategy
    4. Key escrow
    Answer and explanation

    Correct answer: C. Three-two-one backup strategy
    The key idea is keep three copies of data on two media types with one copy offsite or otherwise isolated; that is the purpose of Three-two-one backup strategy.

  58. Question 58. Which information-security term best describes this condition or objective: information stored on a device, disk, database, or backup media?

    1. Data classification
    2. Data at rest
    3. Data in transit
    4. Data in use
    Answer and explanation

    Correct answer: B. Data at rest
    The key idea is information stored on a device, disk, database, or backup media; that is the purpose of Data at rest.

  59. Question 59. Which information-security term best describes this condition or objective: information moving between systems or across a network?

    1. Data in transit
    2. Data at rest
    3. Data in use
    4. Data remanence
    Answer and explanation

    Correct answer: A. Data in transit
    The key idea is information moving between systems or across a network; that is the purpose of Data in transit.

  60. Question 60. Which information-security term best describes this condition or objective: information actively being processed in memory or by an application?

    1. Data at rest
    2. Data in transit
    3. Data retention
    4. Data in use
    Answer and explanation

    Correct answer: D. Data in use
    The key idea is information actively being processed in memory or by an application; that is the purpose of Data in use.

  61. Question 61. Which information-security term best describes this condition or objective: use people, facilities, and physical safeguards to protect equipment and locations?

    1. Network monitoring
    2. Log analysis
    3. Physical security
    4. Cryptographic signing
    Answer and explanation

    Correct answer: C. Physical security
    The key idea is use people, facilities, and physical safeguards to protect equipment and locations; that is the purpose of Physical security.

  62. Question 62. Which information-security term best describes this condition or objective: manage conditions such as fire, power, humidity, and temperature that can damage systems?

    1. Endpoint encryption
    2. Environmental controls
    3. Access control list
    4. Network segmentation
    Answer and explanation

    Correct answer: B. Environmental controls
    The key idea is manage conditions such as fire, power, humidity, and temperature that can damage systems; that is the purpose of Environmental controls.

  63. Question 63. Which information-security term best describes this condition or objective: review, authorize, test, document, and communicate significant system changes?

    1. Change management
    2. Risk acceptance
    3. Disaster recovery
    4. Data destruction
    Answer and explanation

    Correct answer: A. Change management
    The key idea is review, authorize, test, document, and communicate significant system changes; that is the purpose of Change management.

  64. Question 64. Which information-security term best describes this condition or objective: evaluate, test, deploy, and verify updates that address software weaknesses?

    1. Data classification
    2. Business continuity
    3. Key escrow
    4. Patch management
    Answer and explanation

    Correct answer: D. Patch management
    The key idea is evaluate, test, deploy, and verify updates that address software weaknesses; that is the purpose of Patch management.

  65. Question 65. Which information-security term best describes this condition or objective: continually verify access requests and avoid assuming trust based only on network location?

    1. Discretionary access control
    2. Data retention
    3. Zero trust
    4. Implicit trust
    Answer and explanation

    Correct answer: C. Zero trust
    The key idea is continually verify access requests and avoid assuming trust based only on network location; that is the purpose of Zero trust.

  66. Question 66. Which information-security term best describes this condition or objective: separate systems or networks to limit unnecessary communication and lateral movement?

    1. Log retention
    2. Network segmentation
    3. Network address translation
    4. Wireless encryption
    Answer and explanation

    Correct answer: B. Network segmentation
    The key idea is separate systems or networks to limit unnecessary communication and lateral movement; that is the purpose of Network segmentation.

  67. Question 67. Which information-security term best describes this condition or objective: define and maintain approved security settings for systems?

    1. Secure configuration baseline
    2. Business impact analysis
    3. Risk transfer
    4. Data minimization
    Answer and explanation

    Correct answer: A. Secure configuration baseline
    The key idea is define and maintain approved security settings for systems; that is the purpose of Secure configuration baseline.

  68. Question 68. Which information-security term best describes this condition or objective: maintain an accurate record of hardware, software, and important technology assets?

    1. Chain of custody
    2. Key rotation
    3. Data destruction
    4. Asset inventory
    Answer and explanation

    Correct answer: D. Asset inventory
    The key idea is maintain an accurate record of hardware, software, and important technology assets; that is the purpose of Asset inventory.

  69. Question 69. Which information-security term best describes this condition or objective: label information by sensitivity so handling rules match its value and risk?

    1. Log retention
    2. Job rotation
    3. Data classification
    4. Asset disposal
    Answer and explanation

    Correct answer: C. Data classification
    The key idea is label information by sensitivity so handling rules match its value and risk; that is the purpose of Data classification.

  70. Question 70. Which information-security term best describes this condition or objective: build privacy safeguards into processes and systems from the start?

    1. Risk acceptance
    2. Privacy by design
    3. Data destruction
    4. Network segmentation
    Answer and explanation

    Correct answer: B. Privacy by design
    The key idea is build privacy safeguards into processes and systems from the start; that is the purpose of Privacy by design.

  71. Question 71. Which information-security term best describes this condition or objective: define the maximum acceptable amount of data loss measured in time?

    1. Recovery point objective (RPO)
    2. Recovery time objective
    3. Mean time to repair
    4. Service-level agreement
    Answer and explanation

    Correct answer: A. Recovery point objective (RPO)
    The key idea is define the maximum acceptable amount of data loss measured in time; that is the purpose of Recovery point objective (RPO).

  72. Question 72. Which information-security term best describes this condition or objective: define the maximum acceptable time to restore a service after disruption?

    1. Recovery point objective
    2. Log retention
    3. Data classification
    4. Recovery time objective (RTO)
    Answer and explanation

    Correct answer: D. Recovery time objective (RTO)
    The key idea is define the maximum acceptable time to restore a service after disruption; that is the purpose of Recovery time objective (RTO).

Study responsibly: Do not use this resource during graded, proctored, or restricted assessments. Follow your institution's academic-integrity rules.

PDF Preview

Generate, preview, and download this exam record.

Waiting Download PDF
Size
—
Pages
—
Created
—
Page — / —
100%
Generating PDF…
Expert Help Available

Ace Your Online Exams

Connect with trusted academic professionals for reliable test support and secure results. Order now to get started.