← Back to Past Exams Database
Verified Exam Record Score: 88%+

Fundamentals of Information Security - D430: Set 3

Review this completed exam record, including subject, platform, academic level, completion details, and preview question.

Cybersecurity ProctorU University
Subject
Cybersecurity
Platform
ProctorU
Academic Level
University
Date Completed
22 Sep 2026
Preview Question

72 previously done information-security practice questions with answer choices and explanations. WGU exam questions. 72 previously done information-security practice questions with answer choices and explanations. WGU exam questions. 

Exam Record Details

Original practice material: This 72-question set was independently authored for study and review. It is not an official WGU assessment, a ProctorU assessment, a recovered question set, or evidence of a completed exam. Use it only for independent preparation.

Fundamentals of Information Security - D430 Practice Set 3

Format: Self-paced practice
Level: University
Questions: 72 original multiple-choice items
Created: 22 Sep 2026
Study benchmark: 90%+

Questions

  1. Question 1. A university IT team must address this security need: prevent unauthorized disclosure of sensitive information. Which concept best applies?

    1. Confidentiality
    2. Integrity
    3. Availability
    4. Nonrepudiation
    Answer and explanation

    Correct answer: A. Confidentiality
    This is Confidentiality. It directly supports the goal of prevent unauthorized disclosure of sensitive information.

  2. Question 2. A university IT team must address this security need: keep information accurate and protected from unauthorized alteration. Which concept best applies?

    1. Confidentiality
    2. Availability
    3. Privacy
    4. Integrity
    Answer and explanation

    Correct answer: D. Integrity
    This is Integrity. It directly supports the goal of keep information accurate and protected from unauthorized alteration.

  3. Question 3. A university IT team must address this security need: ensure approved users can access systems and data when required. Which concept best applies?

    1. Authentication
    2. Nonrepudiation
    3. Availability
    4. Integrity
    Answer and explanation

    Correct answer: C. Availability
    This is Availability. It directly supports the goal of ensure approved users can access systems and data when required.

  4. Question 4. A university IT team must address this security need: use multiple complementary safeguards so one failed control does not expose the whole asset. Which concept best applies?

    1. Job rotation
    2. Defense in depth
    3. Single sign-on
    4. Data minimization
    Answer and explanation

    Correct answer: B. Defense in depth
    This is Defense in depth. It directly supports the goal of use multiple complementary safeguards so one failed control does not expose the whole asset.

  5. Question 5. A university IT team must address this security need: give each user, process, or service only the access needed for its assigned task. Which concept best applies?

    1. Least privilege
    2. Job rotation
    3. Mandatory vacation
    4. Separation of duties
    Answer and explanation

    Correct answer: A. Least privilege
    This is Least privilege. It directly supports the goal of give each user, process, or service only the access needed for its assigned task.

  6. Question 6. A university IT team must address this security need: limit access to information to people with a justified work purpose. Which concept best applies?

    1. Open access
    2. Job rotation
    3. Key escrow
    4. Need to know
    Answer and explanation

    Correct answer: D. Need to know
    This is Need to know. It directly supports the goal of limit access to information to people with a justified work purpose.

  7. Question 7. A university IT team must address this security need: divide sensitive tasks so one person cannot complete an entire high-risk process alone. Which concept best applies?

    1. Mandatory vacation
    2. Change freeze
    3. Separation of duties
    4. Least privilege
    Answer and explanation

    Correct answer: C. Separation of duties
    This is Separation of duties. It directly supports the goal of divide sensitive tasks so one person cannot complete an entire high-risk process alone.

  8. Question 8. A university IT team must address this security need: assign permissions according to job role rather than managing every user individually. Which concept best applies?

    1. Attribute-based access control
    2. Role-based access control (RBAC)
    3. Mandatory access control
    4. Discretionary access control
    Answer and explanation

    Correct answer: B. Role-based access control (RBAC)
    This is Role-based access control (RBAC). It directly supports the goal of assign permissions according to job role rather than managing every user individually.

  9. Question 9. A university IT team must address this security need: allow a resource owner to decide who receives access to that resource. Which concept best applies?

    1. Discretionary access control (DAC)
    2. Mandatory access control
    3. Role-based access control
    4. Network segmentation
    Answer and explanation

    Correct answer: A. Discretionary access control (DAC)
    This is Discretionary access control (DAC). It directly supports the goal of allow a resource owner to decide who receives access to that resource.

  10. Question 10. A university IT team must address this security need: enforce access decisions using centrally defined labels and clearances. Which concept best applies?

    1. Discretionary access control
    2. Role-based access control
    3. Least privilege
    4. Mandatory access control (MAC)
    Answer and explanation

    Correct answer: D. Mandatory access control (MAC)
    This is Mandatory access control (MAC). It directly supports the goal of enforce access decisions using centrally defined labels and clearances.

  11. Question 11. A university IT team must address this security need: evaluate attributes such as department, device state, time, or location before permitting access. Which concept best applies?

    1. Mandatory access control
    2. Discretionary access control
    3. Attribute-based access control (ABAC)
    4. Role-based access control
    Answer and explanation

    Correct answer: C. Attribute-based access control (ABAC)
    This is Attribute-based access control (ABAC). It directly supports the goal of evaluate attributes such as department, device state, time, or location before permitting access.

  12. Question 12. A university IT team must address this security need: require evidence from more than one independent authentication factor. Which concept best applies?

    1. Authorization
    2. Multi-factor authentication (MFA)
    3. Single sign-on
    4. Password rotation
    Answer and explanation

    Correct answer: B. Multi-factor authentication (MFA)
    This is Multi-factor authentication (MFA). It directly supports the goal of require evidence from more than one independent authentication factor.

  13. Question 13. A university IT team must address this security need: verify that a person, service, or device is who or what it claims to be. Which concept best applies?

    1. Authentication
    2. Authorization
    3. Accounting
    4. Availability
    Answer and explanation

    Correct answer: A. Authentication
    This is Authentication. It directly supports the goal of verify that a person, service, or device is who or what it claims to be.

  14. Question 14. A university IT team must address this security need: decide which actions an authenticated identity is permitted to perform. Which concept best applies?

    1. Authentication
    2. Accounting
    3. Nonrepudiation
    4. Authorization
    Answer and explanation

    Correct answer: D. Authorization
    This is Authorization. It directly supports the goal of decide which actions an authenticated identity is permitted to perform.

  15. Question 15. A university IT team must address this security need: record activity so actions can be traced to an identity and reviewed later. Which concept best applies?

    1. Authentication
    2. Data masking
    3. Accounting
    4. Authorization
    Answer and explanation

    Correct answer: C. Accounting
    This is Accounting. It directly supports the goal of record activity so actions can be traced to an identity and reviewed later.

  16. Question 16. A university IT team must address this security need: create reliable evidence that prevents a sender or actor from credibly denying an action. Which concept best applies?

    1. Data minimization
    2. Nonrepudiation
    3. Availability
    4. Confidentiality
    Answer and explanation

    Correct answer: B. Nonrepudiation
    This is Nonrepudiation. It directly supports the goal of create reliable evidence that prevents a sender or actor from credibly denying an action.

  17. Question 17. A university IT team must address this security need: produce a fixed-length value used to detect whether data has changed. Which concept best applies?

    1. Hashing
    2. Encryption
    3. Tokenization
    4. Compression
    Answer and explanation

    Correct answer: A. Hashing
    This is Hashing. It directly supports the goal of produce a fixed-length value used to detect whether data has changed.

  18. Question 18. A university IT team must address this security need: add unique random data before hashing passwords to make precomputed attacks less useful. Which concept best applies?

    1. Key rotation
    2. Data masking
    3. Tokenization
    4. Salting
    Answer and explanation

    Correct answer: D. Salting
    This is Salting. It directly supports the goal of add unique random data before hashing passwords to make precomputed attacks less useful.

  19. Question 19. A university IT team must address this security need: use the same secret key to encrypt and decrypt data. Which concept best applies?

    1. Hashing
    2. Digital signing
    3. Symmetric encryption
    4. Asymmetric encryption
    Answer and explanation

    Correct answer: C. Symmetric encryption
    This is Symmetric encryption. It directly supports the goal of use the same secret key to encrypt and decrypt data.

  20. Question 20. A university IT team must address this security need: use a related public and private key pair for cryptographic operations. Which concept best applies?

    1. Steganography
    2. Asymmetric encryption
    3. Symmetric encryption
    4. Hashing
    Answer and explanation

    Correct answer: B. Asymmetric encryption
    This is Asymmetric encryption. It directly supports the goal of use a related public and private key pair for cryptographic operations.

  21. Question 21. A university IT team must address this security need: use cryptography to verify message origin and detect alteration. Which concept best applies?

    1. Digital signature
    2. Data compression
    3. Symmetric encryption
    4. Access control list
    Answer and explanation

    Correct answer: A. Digital signature
    This is Digital signature. It directly supports the goal of use cryptography to verify message origin and detect alteration.

  22. Question 22. A university IT team must address this security need: manage certificates, public keys, and trust relationships for public-key cryptography. Which concept best applies?

    1. Virtual private network
    2. Network address translation
    3. Secure shell
    4. Public key infrastructure (PKI)
    Answer and explanation

    Correct answer: D. Public key infrastructure (PKI)
    This is Public key infrastructure (PKI). It directly supports the goal of manage certificates, public keys, and trust relationships for public-key cryptography.

  23. Question 23. A university IT team must address this security need: issue and validate digital certificates that bind identities to public keys. Which concept best applies?

    1. Security information and event management
    2. Keylogger
    3. Certificate authority (CA)
    4. Network switch
    Answer and explanation

    Correct answer: C. Certificate authority (CA)
    This is Certificate authority (CA). It directly supports the goal of issue and validate digital certificates that bind identities to public keys.

  24. Question 24. A university IT team must address this security need: protect data exchanged between a client and server over a network connection. Which concept best applies?

    1. Data loss prevention
    2. Transport Layer Security (TLS)
    3. Secure file transfer
    4. Virtual private network
    Answer and explanation

    Correct answer: B. Transport Layer Security (TLS)
    This is Transport Layer Security (TLS). It directly supports the goal of protect data exchanged between a client and server over a network connection.

  25. Question 25. A university IT team must address this security need: create an encrypted tunnel across an untrusted network. Which concept best applies?

    1. Virtual private network (VPN)
    2. Wireless access point
    3. Proxy server
    4. Web application firewall
    Answer and explanation

    Correct answer: A. Virtual private network (VPN)
    This is Virtual private network (VPN). It directly supports the goal of create an encrypted tunnel across an untrusted network.

  26. Question 26. A university IT team must address this security need: apply traffic rules to allow, deny, or restrict network connections. Which concept best applies?

    1. Intrusion detection system
    2. Proxy cache
    3. Digital certificate
    4. Firewall
    Answer and explanation

    Correct answer: D. Firewall
    This is Firewall. It directly supports the goal of apply traffic rules to allow, deny, or restrict network connections.

  27. Question 27. A university IT team must address this security need: observe events or traffic and alert when suspicious activity is detected. Which concept best applies?

    1. Firewall
    2. Data loss prevention
    3. Intrusion detection system (IDS)
    4. Intrusion prevention system
    Answer and explanation

    Correct answer: C. Intrusion detection system (IDS)
    This is Intrusion detection system (IDS). It directly supports the goal of observe events or traffic and alert when suspicious activity is detected.

  28. Question 28. A university IT team must address this security need: detect malicious traffic and actively block or interrupt it. Which concept best applies?

    1. Vulnerability scanner
    2. Intrusion prevention system (IPS)
    3. Intrusion detection system
    4. Log retention
    Answer and explanation

    Correct answer: B. Intrusion prevention system (IPS)
    This is Intrusion prevention system (IPS). It directly supports the goal of detect malicious traffic and actively block or interrupt it.

  29. Question 29. A university IT team must address this security need: broker requests between a client and another service while applying policy or filtering. Which concept best applies?

    1. Proxy server
    2. Certificate authority
    3. Wireless controller
    4. Endpoint agent
    Answer and explanation

    Correct answer: A. Proxy server
    This is Proxy server. It directly supports the goal of broker requests between a client and another service while applying policy or filtering.

  30. Question 30. A university IT team must address this security need: filter HTTP requests to help protect a web application from common web attacks. Which concept best applies?

    1. Network switch
    2. Data backup
    3. Virtual private network
    4. Web application firewall (WAF)
    Answer and explanation

    Correct answer: D. Web application firewall (WAF)
    This is Web application firewall (WAF). It directly supports the goal of filter HTTP requests to help protect a web application from common web attacks.

  31. Question 31. A university IT team must address this security need: detect and help stop sensitive data from leaving approved channels. Which concept best applies?

    1. Network segmentation
    2. Data compression
    3. Data loss prevention (DLP)
    4. Patch management
    Answer and explanation

    Correct answer: C. Data loss prevention (DLP)
    This is Data loss prevention (DLP). It directly supports the goal of detect and help stop sensitive data from leaving approved channels.

  32. Question 32. A university IT team must address this security need: centralize and correlate security logs to support monitoring and investigation. Which concept best applies?

    1. Virtual private network
    2. Security information and event management (SIEM)
    3. Certificate authority
    4. Data warehouse
    Answer and explanation

    Correct answer: B. Security information and event management (SIEM)
    This is Security information and event management (SIEM). It directly supports the goal of centralize and correlate security logs to support monitoring and investigation.

  33. Question 33. A university IT team must address this security need: keep security records long enough to support troubleshooting, audit, and investigation. Which concept best applies?

    1. Log retention
    2. Data destruction
    3. Key revocation
    4. Job rotation
    Answer and explanation

    Correct answer: A. Log retention
    This is Log retention. It directly supports the goal of keep security records long enough to support troubleshooting, audit, and investigation.

  34. Question 34. A university IT team must address this security need: identify known weaknesses or misconfigurations in systems using automated checks. Which concept best applies?

    1. Penetration testing
    2. Threat hunting
    3. Disaster recovery
    4. Vulnerability scanning
    Answer and explanation

    Correct answer: D. Vulnerability scanning
    This is Vulnerability scanning. It directly supports the goal of identify known weaknesses or misconfigurations in systems using automated checks.

  35. Question 35. A university IT team must address this security need: conduct an authorized, bounded attempt to validate whether weaknesses can be exploited. Which concept best applies?

    1. Change management
    2. Business impact analysis
    3. Penetration testing
    4. Vulnerability scanning
    Answer and explanation

    Correct answer: C. Penetration testing
    This is Penetration testing. It directly supports the goal of conduct an authorized, bounded attempt to validate whether weaknesses can be exploited.

  36. Question 36. A university IT team must address this security need: identify assets, threats, vulnerabilities, likelihood, and impact to prioritize treatment. Which concept best applies?

    1. Patch deployment
    2. Risk assessment
    3. Risk transfer
    4. Log retention
    Answer and explanation

    Correct answer: B. Risk assessment
    This is Risk assessment. It directly supports the goal of identify assets, threats, vulnerabilities, likelihood, and impact to prioritize treatment.

  37. Question 37. A university IT team must address this security need: stop or change an activity so the associated risk is no longer accepted. Which concept best applies?

    1. Risk avoidance
    2. Risk acceptance
    3. Risk transfer
    4. Risk mitigation
    Answer and explanation

    Correct answer: A. Risk avoidance
    This is Risk avoidance. It directly supports the goal of stop or change an activity so the associated risk is no longer accepted.

  38. Question 38. A university IT team must address this security need: shift some financial consequences of risk to another party through a contract or insurance. Which concept best applies?

    1. Risk avoidance
    2. Risk acceptance
    3. Risk mitigation
    4. Risk transfer
    Answer and explanation

    Correct answer: D. Risk transfer
    This is Risk transfer. It directly supports the goal of shift some financial consequences of risk to another party through a contract or insurance.

  39. Question 39. A university IT team must address this security need: reduce either the likelihood or impact of a risk through safeguards. Which concept best applies?

    1. Risk acceptance
    2. Risk avoidance
    3. Risk mitigation
    4. Risk transfer
    Answer and explanation

    Correct answer: C. Risk mitigation
    This is Risk mitigation. It directly supports the goal of reduce either the likelihood or impact of a risk through safeguards.

  40. Question 40. A university IT team must address this security need: identify critical processes and the consequences of disruption. Which concept best applies?

    1. Threat intelligence
    2. Business impact analysis (BIA)
    3. Vulnerability scanning
    4. Change management
    Answer and explanation

    Correct answer: B. Business impact analysis (BIA)
    This is Business impact analysis (BIA). It directly supports the goal of identify critical processes and the consequences of disruption.

  41. Question 41. A university IT team must address this security need: restore technology and data after a major disruption. Which concept best applies?

    1. Disaster recovery (DR)
    2. Business continuity planning
    3. Job rotation
    4. Data classification
    Answer and explanation

    Correct answer: A. Disaster recovery (DR)
    This is Disaster recovery (DR). It directly supports the goal of restore technology and data after a major disruption.

  42. Question 42. A university IT team must address this security need: keep critical business functions operating during and after disruption. Which concept best applies?

    1. Disaster recovery
    2. Patch management
    3. Data retention
    4. Business continuity planning (BCP)
    Answer and explanation

    Correct answer: D. Business continuity planning (BCP)
    This is Business continuity planning (BCP). It directly supports the goal of keep critical business functions operating during and after disruption.

  43. Question 43. A university IT team must address this security need: prepare for, detect, contain, eradicate, and recover from security incidents. Which concept best applies?

    1. Risk acceptance
    2. Change control
    3. Incident response
    4. Business continuity
    Answer and explanation

    Correct answer: C. Incident response
    This is Incident response. It directly supports the goal of prepare for, detect, contain, eradicate, and recover from security incidents.

  44. Question 44. A university IT team must address this security need: document who handled evidence, when, and how it was preserved. Which concept best applies?

    1. Key management
    2. Chain of custody
    3. Data classification
    4. Asset inventory
    Answer and explanation

    Correct answer: B. Chain of custody
    This is Chain of custody. It directly supports the goal of document who handled evidence, when, and how it was preserved.

  45. Question 45. A university IT team must address this security need: use deceptive messages to trick recipients into revealing information or taking unsafe action. Which concept best applies?

    1. Phishing
    2. DDoS
    3. SQL injection
    4. Privilege escalation
    Answer and explanation

    Correct answer: A. Phishing
    This is Phishing. It directly supports the goal of use deceptive messages to trick recipients into revealing information or taking unsafe action.

  46. Question 46. A university IT team must address this security need: target a specific person or group with a tailored deceptive message. Which concept best applies?

    1. Generic phishing
    2. Brute-force attack
    3. Watering-hole attack
    4. Spear phishing
    Answer and explanation

    Correct answer: D. Spear phishing
    This is Spear phishing. It directly supports the goal of target a specific person or group with a tailored deceptive message.

  47. Question 47. A university IT team must address this security need: manipulate people into bypassing normal security judgment or procedure. Which concept best applies?

    1. Data masking
    2. Patch management
    3. Social engineering
    4. Network segmentation
    Answer and explanation

    Correct answer: C. Social engineering
    This is Social engineering. It directly supports the goal of manipulate people into bypassing normal security judgment or procedure.

  48. Question 48. A university IT team must address this security need: malware that denies access to data or systems while demanding payment. Which concept best applies?

    1. Adware
    2. Ransomware
    3. Spyware
    4. Rootkit
    Answer and explanation

    Correct answer: B. Ransomware
    This is Ransomware. It directly supports the goal of malware that denies access to data or systems while demanding payment.

  49. Question 49. A university IT team must address this security need: software intentionally designed to harm, disrupt, spy on, or gain unauthorized access. Which concept best applies?

    1. Malware
    2. Middleware
    3. Firmware
    4. Data cache
    Answer and explanation

    Correct answer: A. Malware
    This is Malware. It directly supports the goal of software intentionally designed to harm, disrupt, spy on, or gain unauthorized access.

  50. Question 50. A university IT team must address this security need: abuse unsafe database queries by supplying malicious input. Which concept best applies?

    1. Cross-site scripting
    2. DNS caching
    3. Session timeout
    4. SQL injection
    Answer and explanation

    Correct answer: D. SQL injection
    This is SQL injection. It directly supports the goal of abuse unsafe database queries by supplying malicious input.

  51. Question 51. A university IT team must address this security need: cause a web application to deliver untrusted script to another user's browser. Which concept best applies?

    1. Packet filtering
    2. Data encryption
    3. Cross-site scripting (XSS)
    4. SQL injection
    Answer and explanation

    Correct answer: C. Cross-site scripting (XSS)
    This is Cross-site scripting (XSS). It directly supports the goal of cause a web application to deliver untrusted script to another user's browser.

  52. Question 52. A university IT team must address this security need: write beyond intended memory boundaries and potentially alter program behavior. Which concept best applies?

    1. DNS poisoning
    2. Buffer overflow
    3. SQL injection
    4. Clickjacking
    Answer and explanation

    Correct answer: B. Buffer overflow
    This is Buffer overflow. It directly supports the goal of write beyond intended memory boundaries and potentially alter program behavior.

  53. Question 53. A university IT team must address this security need: gain permissions beyond those originally granted. Which concept best applies?

    1. Privilege escalation
    2. Credential rotation
    3. Data classification
    4. Network segmentation
    Answer and explanation

    Correct answer: A. Privilege escalation
    This is Privilege escalation. It directly supports the goal of gain permissions beyond those originally granted.

  54. Question 54. A university IT team must address this security need: repeatedly try credentials or keys until a valid one is found. Which concept best applies?

    1. Spear phishing
    2. Data masking
    3. Session management
    4. Brute-force attack
    Answer and explanation

    Correct answer: D. Brute-force attack
    This is Brute-force attack. It directly supports the goal of repeatedly try credentials or keys until a valid one is found.

  55. Question 55. A university IT team must address this security need: test previously exposed username-password pairs on other services. Which concept best applies?

    1. Tokenization
    2. Data classification
    3. Credential stuffing
    4. Password salting
    Answer and explanation

    Correct answer: C. Credential stuffing
    This is Credential stuffing. It directly supports the goal of test previously exposed username-password pairs on other services.

  56. Question 56. A university IT team must address this security need: overwhelm a service with traffic from many sources to reduce availability. Which concept best applies?

    1. Phishing
    2. Distributed denial-of-service (DDoS)
    3. Data exfiltration
    4. Privilege escalation
    Answer and explanation

    Correct answer: B. Distributed denial-of-service (DDoS)
    This is Distributed denial-of-service (DDoS). It directly supports the goal of overwhelm a service with traffic from many sources to reduce availability.

  57. Question 57. A university IT team must address this security need: keep three copies of data on two media types with one copy offsite or otherwise isolated. Which concept best applies?

    1. Three-two-one backup strategy
    2. Key escrow
    3. Data masking
    4. Log rotation
    Answer and explanation

    Correct answer: A. Three-two-one backup strategy
    This is Three-two-one backup strategy. It directly supports the goal of keep three copies of data on two media types with one copy offsite or otherwise isolated.

  58. Question 58. A university IT team must address this security need: information stored on a device, disk, database, or backup media. Which concept best applies?

    1. Data in transit
    2. Data in use
    3. Data classification
    4. Data at rest
    Answer and explanation

    Correct answer: D. Data at rest
    This is Data at rest. It directly supports the goal of information stored on a device, disk, database, or backup media.

  59. Question 59. A university IT team must address this security need: information moving between systems or across a network. Which concept best applies?

    1. Data in use
    2. Data remanence
    3. Data in transit
    4. Data at rest
    Answer and explanation

    Correct answer: C. Data in transit
    This is Data in transit. It directly supports the goal of information moving between systems or across a network.

  60. Question 60. A university IT team must address this security need: information actively being processed in memory or by an application. Which concept best applies?

    1. Data retention
    2. Data in use
    3. Data at rest
    4. Data in transit
    Answer and explanation

    Correct answer: B. Data in use
    This is Data in use. It directly supports the goal of information actively being processed in memory or by an application.

  61. Question 61. A university IT team must address this security need: use people, facilities, and physical safeguards to protect equipment and locations. Which concept best applies?

    1. Physical security
    2. Cryptographic signing
    3. Network monitoring
    4. Log analysis
    Answer and explanation

    Correct answer: A. Physical security
    This is Physical security. It directly supports the goal of use people, facilities, and physical safeguards to protect equipment and locations.

  62. Question 62. A university IT team must address this security need: manage conditions such as fire, power, humidity, and temperature that can damage systems. Which concept best applies?

    1. Access control list
    2. Network segmentation
    3. Endpoint encryption
    4. Environmental controls
    Answer and explanation

    Correct answer: D. Environmental controls
    This is Environmental controls. It directly supports the goal of manage conditions such as fire, power, humidity, and temperature that can damage systems.

  63. Question 63. A university IT team must address this security need: review, authorize, test, document, and communicate significant system changes. Which concept best applies?

    1. Disaster recovery
    2. Data destruction
    3. Change management
    4. Risk acceptance
    Answer and explanation

    Correct answer: C. Change management
    This is Change management. It directly supports the goal of review, authorize, test, document, and communicate significant system changes.

  64. Question 64. A university IT team must address this security need: evaluate, test, deploy, and verify updates that address software weaknesses. Which concept best applies?

    1. Key escrow
    2. Patch management
    3. Data classification
    4. Business continuity
    Answer and explanation

    Correct answer: B. Patch management
    This is Patch management. It directly supports the goal of evaluate, test, deploy, and verify updates that address software weaknesses.

  65. Question 65. A university IT team must address this security need: continually verify access requests and avoid assuming trust based only on network location. Which concept best applies?

    1. Zero trust
    2. Implicit trust
    3. Discretionary access control
    4. Data retention
    Answer and explanation

    Correct answer: A. Zero trust
    This is Zero trust. It directly supports the goal of continually verify access requests and avoid assuming trust based only on network location.

  66. Question 66. A university IT team must address this security need: separate systems or networks to limit unnecessary communication and lateral movement. Which concept best applies?

    1. Network address translation
    2. Wireless encryption
    3. Log retention
    4. Network segmentation
    Answer and explanation

    Correct answer: D. Network segmentation
    This is Network segmentation. It directly supports the goal of separate systems or networks to limit unnecessary communication and lateral movement.

  67. Question 67. A university IT team must address this security need: define and maintain approved security settings for systems. Which concept best applies?

    1. Risk transfer
    2. Data minimization
    3. Secure configuration baseline
    4. Business impact analysis
    Answer and explanation

    Correct answer: C. Secure configuration baseline
    This is Secure configuration baseline. It directly supports the goal of define and maintain approved security settings for systems.

  68. Question 68. A university IT team must address this security need: maintain an accurate record of hardware, software, and important technology assets. Which concept best applies?

    1. Data destruction
    2. Asset inventory
    3. Chain of custody
    4. Key rotation
    Answer and explanation

    Correct answer: B. Asset inventory
    This is Asset inventory. It directly supports the goal of maintain an accurate record of hardware, software, and important technology assets.

  69. Question 69. A university IT team must address this security need: label information by sensitivity so handling rules match its value and risk. Which concept best applies?

    1. Data classification
    2. Asset disposal
    3. Log retention
    4. Job rotation
    Answer and explanation

    Correct answer: A. Data classification
    This is Data classification. It directly supports the goal of label information by sensitivity so handling rules match its value and risk.

  70. Question 70. A university IT team must address this security need: build privacy safeguards into processes and systems from the start. Which concept best applies?

    1. Data destruction
    2. Network segmentation
    3. Risk acceptance
    4. Privacy by design
    Answer and explanation

    Correct answer: D. Privacy by design
    This is Privacy by design. It directly supports the goal of build privacy safeguards into processes and systems from the start.

  71. Question 71. A university IT team must address this security need: define the maximum acceptable amount of data loss measured in time. Which concept best applies?

    1. Mean time to repair
    2. Service-level agreement
    3. Recovery point objective (RPO)
    4. Recovery time objective
    Answer and explanation

    Correct answer: C. Recovery point objective (RPO)
    This is Recovery point objective (RPO). It directly supports the goal of define the maximum acceptable amount of data loss measured in time.

  72. Question 72. A university IT team must address this security need: define the maximum acceptable time to restore a service after disruption. Which concept best applies?

    1. Data classification
    2. Recovery time objective (RTO)
    3. Recovery point objective
    4. Log retention
    Answer and explanation

    Correct answer: B. Recovery time objective (RTO)
    This is Recovery time objective (RTO). It directly supports the goal of define the maximum acceptable time to restore a service after disruption.

Study responsibly: Do not use this resource during graded, proctored, or restricted assessments. Follow your institution's academic-integrity rules.

PDF Preview

Generate, preview, and download this exam record.

Waiting Download PDF
Size
—
Pages
—
Created
—
Page — / —
100%
Generating PDF…
Expert Help Available

Ace Your Online Exams

Connect with trusted academic professionals for reliable test support and secure results. Order now to get started.