Fundamentals of Information Security - D430: Set 1
Review this completed exam record, including subject, platform, academic level, completion details, and preview question.
72 previously done information-security practice questions with answer choices and explanations. WGU exam questions. 72 previously done information-security practice questions with answer choices and explanations. WGU exam questions.
Exam Record Details
Original practice material: This 72-question set was independently authored for study and review. It is not an official WGU assessment, a ProctorU assessment, a recovered question set, or evidence of a completed exam. Use it only for independent preparation.
Fundamentals of Information Security - D430 Practice Set 1
Format: Self-paced practice
Level: University
Questions: 72 original multiple-choice items
Created: 22 Sep 2026
Study benchmark: 90%+
Questions
Question 1. Which security concept is most closely associated with this objective: prevent unauthorized disclosure of sensitive information?
- Confidentiality
- Integrity
- Availability
- Nonrepudiation
Answer and explanation
Correct answer: A. Confidentiality
Confidentiality is correct because it is used to prevent unauthorized disclosure of sensitive information.Question 2. Which security concept is most closely associated with this objective: keep information accurate and protected from unauthorized alteration?
- Confidentiality
- Availability
- Privacy
- Integrity
Answer and explanation
Correct answer: D. Integrity
Integrity is correct because it is used to keep information accurate and protected from unauthorized alteration.Question 3. Which security concept is most closely associated with this objective: ensure approved users can access systems and data when required?
- Authentication
- Nonrepudiation
- Availability
- Integrity
Answer and explanation
Correct answer: C. Availability
Availability is correct because it is used to ensure approved users can access systems and data when required.Question 4. Which security concept is most closely associated with this objective: use multiple complementary safeguards so one failed control does not expose the whole asset?
- Job rotation
- Defense in depth
- Single sign-on
- Data minimization
Answer and explanation
Correct answer: B. Defense in depth
Defense in depth is correct because it is used to use multiple complementary safeguards so one failed control does not expose the whole asset.Question 5. Which security concept is most closely associated with this objective: give each user, process, or service only the access needed for its assigned task?
- Least privilege
- Job rotation
- Mandatory vacation
- Separation of duties
Answer and explanation
Correct answer: A. Least privilege
Least privilege is correct because it is used to give each user, process, or service only the access needed for its assigned task.Question 6. Which security concept is most closely associated with this objective: limit access to information to people with a justified work purpose?
- Open access
- Job rotation
- Key escrow
- Need to know
Answer and explanation
Correct answer: D. Need to know
Need to know is correct because it is used to limit access to information to people with a justified work purpose.Question 7. Which security concept is most closely associated with this objective: divide sensitive tasks so one person cannot complete an entire high-risk process alone?
- Mandatory vacation
- Change freeze
- Separation of duties
- Least privilege
Answer and explanation
Correct answer: C. Separation of duties
Separation of duties is correct because it is used to divide sensitive tasks so one person cannot complete an entire high-risk process alone.Question 8. Which security concept is most closely associated with this objective: assign permissions according to job role rather than managing every user individually?
- Attribute-based access control
- Role-based access control (RBAC)
- Mandatory access control
- Discretionary access control
Answer and explanation
Correct answer: B. Role-based access control (RBAC)
Role-based access control (RBAC) is correct because it is used to assign permissions according to job role rather than managing every user individually.Question 9. Which security concept is most closely associated with this objective: allow a resource owner to decide who receives access to that resource?
- Discretionary access control (DAC)
- Mandatory access control
- Role-based access control
- Network segmentation
Answer and explanation
Correct answer: A. Discretionary access control (DAC)
Discretionary access control (DAC) is correct because it is used to allow a resource owner to decide who receives access to that resource.Question 10. Which security concept is most closely associated with this objective: enforce access decisions using centrally defined labels and clearances?
- Discretionary access control
- Role-based access control
- Least privilege
- Mandatory access control (MAC)
Answer and explanation
Correct answer: D. Mandatory access control (MAC)
Mandatory access control (MAC) is correct because it is used to enforce access decisions using centrally defined labels and clearances.Question 11. Which security concept is most closely associated with this objective: evaluate attributes such as department, device state, time, or location before permitting access?
- Mandatory access control
- Discretionary access control
- Attribute-based access control (ABAC)
- Role-based access control
Answer and explanation
Correct answer: C. Attribute-based access control (ABAC)
Attribute-based access control (ABAC) is correct because it is used to evaluate attributes such as department, device state, time, or location before permitting access.Question 12. Which security concept is most closely associated with this objective: require evidence from more than one independent authentication factor?
- Authorization
- Multi-factor authentication (MFA)
- Single sign-on
- Password rotation
Answer and explanation
Correct answer: B. Multi-factor authentication (MFA)
Multi-factor authentication (MFA) is correct because it is used to require evidence from more than one independent authentication factor.Question 13. Which security concept is most closely associated with this objective: verify that a person, service, or device is who or what it claims to be?
- Authentication
- Authorization
- Accounting
- Availability
Answer and explanation
Correct answer: A. Authentication
Authentication is correct because it is used to verify that a person, service, or device is who or what it claims to be.Question 14. Which security concept is most closely associated with this objective: decide which actions an authenticated identity is permitted to perform?
- Authentication
- Accounting
- Nonrepudiation
- Authorization
Answer and explanation
Correct answer: D. Authorization
Authorization is correct because it is used to decide which actions an authenticated identity is permitted to perform.Question 15. Which security concept is most closely associated with this objective: record activity so actions can be traced to an identity and reviewed later?
- Authentication
- Data masking
- Accounting
- Authorization
Answer and explanation
Correct answer: C. Accounting
Accounting is correct because it is used to record activity so actions can be traced to an identity and reviewed later.Question 16. Which security concept is most closely associated with this objective: create reliable evidence that prevents a sender or actor from credibly denying an action?
- Data minimization
- Nonrepudiation
- Availability
- Confidentiality
Answer and explanation
Correct answer: B. Nonrepudiation
Nonrepudiation is correct because it is used to create reliable evidence that prevents a sender or actor from credibly denying an action.Question 17. Which security concept is most closely associated with this objective: produce a fixed-length value used to detect whether data has changed?
- Hashing
- Encryption
- Tokenization
- Compression
Answer and explanation
Correct answer: A. Hashing
Hashing is correct because it is used to produce a fixed-length value used to detect whether data has changed.Question 18. Which security concept is most closely associated with this objective: add unique random data before hashing passwords to make precomputed attacks less useful?
- Key rotation
- Data masking
- Tokenization
- Salting
Answer and explanation
Correct answer: D. Salting
Salting is correct because it is used to add unique random data before hashing passwords to make precomputed attacks less useful.Question 19. Which security concept is most closely associated with this objective: use the same secret key to encrypt and decrypt data?
- Hashing
- Digital signing
- Symmetric encryption
- Asymmetric encryption
Answer and explanation
Correct answer: C. Symmetric encryption
Symmetric encryption is correct because it is used to use the same secret key to encrypt and decrypt data.Question 20. Which security concept is most closely associated with this objective: use a related public and private key pair for cryptographic operations?
- Steganography
- Asymmetric encryption
- Symmetric encryption
- Hashing
Answer and explanation
Correct answer: B. Asymmetric encryption
Asymmetric encryption is correct because it is used to use a related public and private key pair for cryptographic operations.Question 21. Which security concept is most closely associated with this objective: use cryptography to verify message origin and detect alteration?
- Digital signature
- Data compression
- Symmetric encryption
- Access control list
Answer and explanation
Correct answer: A. Digital signature
Digital signature is correct because it is used to use cryptography to verify message origin and detect alteration.Question 22. Which security concept is most closely associated with this objective: manage certificates, public keys, and trust relationships for public-key cryptography?
- Virtual private network
- Network address translation
- Secure shell
- Public key infrastructure (PKI)
Answer and explanation
Correct answer: D. Public key infrastructure (PKI)
Public key infrastructure (PKI) is correct because it is used to manage certificates, public keys, and trust relationships for public-key cryptography.Question 23. Which security concept is most closely associated with this objective: issue and validate digital certificates that bind identities to public keys?
- Security information and event management
- Keylogger
- Certificate authority (CA)
- Network switch
Answer and explanation
Correct answer: C. Certificate authority (CA)
Certificate authority (CA) is correct because it is used to issue and validate digital certificates that bind identities to public keys.Question 24. Which security concept is most closely associated with this objective: protect data exchanged between a client and server over a network connection?
- Data loss prevention
- Transport Layer Security (TLS)
- Secure file transfer
- Virtual private network
Answer and explanation
Correct answer: B. Transport Layer Security (TLS)
Transport Layer Security (TLS) is correct because it is used to protect data exchanged between a client and server over a network connection.Question 25. Which security concept is most closely associated with this objective: create an encrypted tunnel across an untrusted network?
- Virtual private network (VPN)
- Wireless access point
- Proxy server
- Web application firewall
Answer and explanation
Correct answer: A. Virtual private network (VPN)
Virtual private network (VPN) is correct because it is used to create an encrypted tunnel across an untrusted network.Question 26. Which security concept is most closely associated with this objective: apply traffic rules to allow, deny, or restrict network connections?
- Intrusion detection system
- Proxy cache
- Digital certificate
- Firewall
Answer and explanation
Correct answer: D. Firewall
Firewall is correct because it is used to apply traffic rules to allow, deny, or restrict network connections.Question 27. Which security concept is most closely associated with this objective: observe events or traffic and alert when suspicious activity is detected?
- Firewall
- Data loss prevention
- Intrusion detection system (IDS)
- Intrusion prevention system
Answer and explanation
Correct answer: C. Intrusion detection system (IDS)
Intrusion detection system (IDS) is correct because it is used to observe events or traffic and alert when suspicious activity is detected.Question 28. Which security concept is most closely associated with this objective: detect malicious traffic and actively block or interrupt it?
- Vulnerability scanner
- Intrusion prevention system (IPS)
- Intrusion detection system
- Log retention
Answer and explanation
Correct answer: B. Intrusion prevention system (IPS)
Intrusion prevention system (IPS) is correct because it is used to detect malicious traffic and actively block or interrupt it.Question 29. Which security concept is most closely associated with this objective: broker requests between a client and another service while applying policy or filtering?
- Proxy server
- Certificate authority
- Wireless controller
- Endpoint agent
Answer and explanation
Correct answer: A. Proxy server
Proxy server is correct because it is used to broker requests between a client and another service while applying policy or filtering.Question 30. Which security concept is most closely associated with this objective: filter HTTP requests to help protect a web application from common web attacks?
- Network switch
- Data backup
- Virtual private network
- Web application firewall (WAF)
Answer and explanation
Correct answer: D. Web application firewall (WAF)
Web application firewall (WAF) is correct because it is used to filter HTTP requests to help protect a web application from common web attacks.Question 31. Which security concept is most closely associated with this objective: detect and help stop sensitive data from leaving approved channels?
- Network segmentation
- Data compression
- Data loss prevention (DLP)
- Patch management
Answer and explanation
Correct answer: C. Data loss prevention (DLP)
Data loss prevention (DLP) is correct because it is used to detect and help stop sensitive data from leaving approved channels.Question 32. Which security concept is most closely associated with this objective: centralize and correlate security logs to support monitoring and investigation?
- Virtual private network
- Security information and event management (SIEM)
- Certificate authority
- Data warehouse
Answer and explanation
Correct answer: B. Security information and event management (SIEM)
Security information and event management (SIEM) is correct because it is used to centralize and correlate security logs to support monitoring and investigation.Question 33. Which security concept is most closely associated with this objective: keep security records long enough to support troubleshooting, audit, and investigation?
- Log retention
- Data destruction
- Key revocation
- Job rotation
Answer and explanation
Correct answer: A. Log retention
Log retention is correct because it is used to keep security records long enough to support troubleshooting, audit, and investigation.Question 34. Which security concept is most closely associated with this objective: identify known weaknesses or misconfigurations in systems using automated checks?
- Penetration testing
- Threat hunting
- Disaster recovery
- Vulnerability scanning
Answer and explanation
Correct answer: D. Vulnerability scanning
Vulnerability scanning is correct because it is used to identify known weaknesses or misconfigurations in systems using automated checks.Question 35. Which security concept is most closely associated with this objective: conduct an authorized, bounded attempt to validate whether weaknesses can be exploited?
- Change management
- Business impact analysis
- Penetration testing
- Vulnerability scanning
Answer and explanation
Correct answer: C. Penetration testing
Penetration testing is correct because it is used to conduct an authorized, bounded attempt to validate whether weaknesses can be exploited.Question 36. Which security concept is most closely associated with this objective: identify assets, threats, vulnerabilities, likelihood, and impact to prioritize treatment?
- Patch deployment
- Risk assessment
- Risk transfer
- Log retention
Answer and explanation
Correct answer: B. Risk assessment
Risk assessment is correct because it is used to identify assets, threats, vulnerabilities, likelihood, and impact to prioritize treatment.Question 37. Which security concept is most closely associated with this objective: stop or change an activity so the associated risk is no longer accepted?
- Risk avoidance
- Risk acceptance
- Risk transfer
- Risk mitigation
Answer and explanation
Correct answer: A. Risk avoidance
Risk avoidance is correct because it is used to stop or change an activity so the associated risk is no longer accepted.Question 38. Which security concept is most closely associated with this objective: shift some financial consequences of risk to another party through a contract or insurance?
- Risk avoidance
- Risk acceptance
- Risk mitigation
- Risk transfer
Answer and explanation
Correct answer: D. Risk transfer
Risk transfer is correct because it is used to shift some financial consequences of risk to another party through a contract or insurance.Question 39. Which security concept is most closely associated with this objective: reduce either the likelihood or impact of a risk through safeguards?
- Risk acceptance
- Risk avoidance
- Risk mitigation
- Risk transfer
Answer and explanation
Correct answer: C. Risk mitigation
Risk mitigation is correct because it is used to reduce either the likelihood or impact of a risk through safeguards.Question 40. Which security concept is most closely associated with this objective: identify critical processes and the consequences of disruption?
- Threat intelligence
- Business impact analysis (BIA)
- Vulnerability scanning
- Change management
Answer and explanation
Correct answer: B. Business impact analysis (BIA)
Business impact analysis (BIA) is correct because it is used to identify critical processes and the consequences of disruption.Question 41. Which security concept is most closely associated with this objective: restore technology and data after a major disruption?
- Disaster recovery (DR)
- Business continuity planning
- Job rotation
- Data classification
Answer and explanation
Correct answer: A. Disaster recovery (DR)
Disaster recovery (DR) is correct because it is used to restore technology and data after a major disruption.Question 42. Which security concept is most closely associated with this objective: keep critical business functions operating during and after disruption?
- Disaster recovery
- Patch management
- Data retention
- Business continuity planning (BCP)
Answer and explanation
Correct answer: D. Business continuity planning (BCP)
Business continuity planning (BCP) is correct because it is used to keep critical business functions operating during and after disruption.Question 43. Which security concept is most closely associated with this objective: prepare for, detect, contain, eradicate, and recover from security incidents?
- Risk acceptance
- Change control
- Incident response
- Business continuity
Answer and explanation
Correct answer: C. Incident response
Incident response is correct because it is used to prepare for, detect, contain, eradicate, and recover from security incidents.Question 44. Which security concept is most closely associated with this objective: document who handled evidence, when, and how it was preserved?
- Key management
- Chain of custody
- Data classification
- Asset inventory
Answer and explanation
Correct answer: B. Chain of custody
Chain of custody is correct because it is used to document who handled evidence, when, and how it was preserved.Question 45. Which security concept is most closely associated with this objective: use deceptive messages to trick recipients into revealing information or taking unsafe action?
- Phishing
- DDoS
- SQL injection
- Privilege escalation
Answer and explanation
Correct answer: A. Phishing
Phishing is correct because it is used to use deceptive messages to trick recipients into revealing information or taking unsafe action.Question 46. Which security concept is most closely associated with this objective: target a specific person or group with a tailored deceptive message?
- Generic phishing
- Brute-force attack
- Watering-hole attack
- Spear phishing
Answer and explanation
Correct answer: D. Spear phishing
Spear phishing is correct because it is used to target a specific person or group with a tailored deceptive message.Question 47. Which security concept is most closely associated with this objective: manipulate people into bypassing normal security judgment or procedure?
- Data masking
- Patch management
- Social engineering
- Network segmentation
Answer and explanation
Correct answer: C. Social engineering
Social engineering is correct because it is used to manipulate people into bypassing normal security judgment or procedure.Question 48. Which security concept is most closely associated with this objective: malware that denies access to data or systems while demanding payment?
- Adware
- Ransomware
- Spyware
- Rootkit
Answer and explanation
Correct answer: B. Ransomware
Ransomware is correct because it is used to malware that denies access to data or systems while demanding payment.Question 49. Which security concept is most closely associated with this objective: software intentionally designed to harm, disrupt, spy on, or gain unauthorized access?
- Malware
- Middleware
- Firmware
- Data cache
Answer and explanation
Correct answer: A. Malware
Malware is correct because it is used to software intentionally designed to harm, disrupt, spy on, or gain unauthorized access.Question 50. Which security concept is most closely associated with this objective: abuse unsafe database queries by supplying malicious input?
- Cross-site scripting
- DNS caching
- Session timeout
- SQL injection
Answer and explanation
Correct answer: D. SQL injection
SQL injection is correct because it is used to abuse unsafe database queries by supplying malicious input.Question 51. Which security concept is most closely associated with this objective: cause a web application to deliver untrusted script to another user's browser?
- Packet filtering
- Data encryption
- Cross-site scripting (XSS)
- SQL injection
Answer and explanation
Correct answer: C. Cross-site scripting (XSS)
Cross-site scripting (XSS) is correct because it is used to cause a web application to deliver untrusted script to another user's browser.Question 52. Which security concept is most closely associated with this objective: write beyond intended memory boundaries and potentially alter program behavior?
- DNS poisoning
- Buffer overflow
- SQL injection
- Clickjacking
Answer and explanation
Correct answer: B. Buffer overflow
Buffer overflow is correct because it is used to write beyond intended memory boundaries and potentially alter program behavior.Question 53. Which security concept is most closely associated with this objective: gain permissions beyond those originally granted?
- Privilege escalation
- Credential rotation
- Data classification
- Network segmentation
Answer and explanation
Correct answer: A. Privilege escalation
Privilege escalation is correct because it is used to gain permissions beyond those originally granted.Question 54. Which security concept is most closely associated with this objective: repeatedly try credentials or keys until a valid one is found?
- Spear phishing
- Data masking
- Session management
- Brute-force attack
Answer and explanation
Correct answer: D. Brute-force attack
Brute-force attack is correct because it is used to repeatedly try credentials or keys until a valid one is found.Question 55. Which security concept is most closely associated with this objective: test previously exposed username-password pairs on other services?
- Tokenization
- Data classification
- Credential stuffing
- Password salting
Answer and explanation
Correct answer: C. Credential stuffing
Credential stuffing is correct because it is used to test previously exposed username-password pairs on other services.Question 56. Which security concept is most closely associated with this objective: overwhelm a service with traffic from many sources to reduce availability?
- Phishing
- Distributed denial-of-service (DDoS)
- Data exfiltration
- Privilege escalation
Answer and explanation
Correct answer: B. Distributed denial-of-service (DDoS)
Distributed denial-of-service (DDoS) is correct because it is used to overwhelm a service with traffic from many sources to reduce availability.Question 57. Which security concept is most closely associated with this objective: keep three copies of data on two media types with one copy offsite or otherwise isolated?
- Three-two-one backup strategy
- Key escrow
- Data masking
- Log rotation
Answer and explanation
Correct answer: A. Three-two-one backup strategy
Three-two-one backup strategy is correct because it is used to keep three copies of data on two media types with one copy offsite or otherwise isolated.Question 58. Which security concept is most closely associated with this objective: information stored on a device, disk, database, or backup media?
- Data in transit
- Data in use
- Data classification
- Data at rest
Answer and explanation
Correct answer: D. Data at rest
Data at rest is correct because it is used to information stored on a device, disk, database, or backup media.Question 59. Which security concept is most closely associated with this objective: information moving between systems or across a network?
- Data in use
- Data remanence
- Data in transit
- Data at rest
Answer and explanation
Correct answer: C. Data in transit
Data in transit is correct because it is used to information moving between systems or across a network.Question 60. Which security concept is most closely associated with this objective: information actively being processed in memory or by an application?
- Data retention
- Data in use
- Data at rest
- Data in transit
Answer and explanation
Correct answer: B. Data in use
Data in use is correct because it is used to information actively being processed in memory or by an application.Question 61. Which security concept is most closely associated with this objective: use people, facilities, and physical safeguards to protect equipment and locations?
- Physical security
- Cryptographic signing
- Network monitoring
- Log analysis
Answer and explanation
Correct answer: A. Physical security
Physical security is correct because it is used to use people, facilities, and physical safeguards to protect equipment and locations.Question 62. Which security concept is most closely associated with this objective: manage conditions such as fire, power, humidity, and temperature that can damage systems?
- Access control list
- Network segmentation
- Endpoint encryption
- Environmental controls
Answer and explanation
Correct answer: D. Environmental controls
Environmental controls is correct because it is used to manage conditions such as fire, power, humidity, and temperature that can damage systems.Question 63. Which security concept is most closely associated with this objective: review, authorize, test, document, and communicate significant system changes?
- Disaster recovery
- Data destruction
- Change management
- Risk acceptance
Answer and explanation
Correct answer: C. Change management
Change management is correct because it is used to review, authorize, test, document, and communicate significant system changes.Question 64. Which security concept is most closely associated with this objective: evaluate, test, deploy, and verify updates that address software weaknesses?
- Key escrow
- Patch management
- Data classification
- Business continuity
Answer and explanation
Correct answer: B. Patch management
Patch management is correct because it is used to evaluate, test, deploy, and verify updates that address software weaknesses.Question 65. Which security concept is most closely associated with this objective: continually verify access requests and avoid assuming trust based only on network location?
- Zero trust
- Implicit trust
- Discretionary access control
- Data retention
Answer and explanation
Correct answer: A. Zero trust
Zero trust is correct because it is used to continually verify access requests and avoid assuming trust based only on network location.Question 66. Which security concept is most closely associated with this objective: separate systems or networks to limit unnecessary communication and lateral movement?
- Network address translation
- Wireless encryption
- Log retention
- Network segmentation
Answer and explanation
Correct answer: D. Network segmentation
Network segmentation is correct because it is used to separate systems or networks to limit unnecessary communication and lateral movement.Question 67. Which security concept is most closely associated with this objective: define and maintain approved security settings for systems?
- Risk transfer
- Data minimization
- Secure configuration baseline
- Business impact analysis
Answer and explanation
Correct answer: C. Secure configuration baseline
Secure configuration baseline is correct because it is used to define and maintain approved security settings for systems.Question 68. Which security concept is most closely associated with this objective: maintain an accurate record of hardware, software, and important technology assets?
- Data destruction
- Asset inventory
- Chain of custody
- Key rotation
Answer and explanation
Correct answer: B. Asset inventory
Asset inventory is correct because it is used to maintain an accurate record of hardware, software, and important technology assets.Question 69. Which security concept is most closely associated with this objective: label information by sensitivity so handling rules match its value and risk?
- Data classification
- Asset disposal
- Log retention
- Job rotation
Answer and explanation
Correct answer: A. Data classification
Data classification is correct because it is used to label information by sensitivity so handling rules match its value and risk.Question 70. Which security concept is most closely associated with this objective: build privacy safeguards into processes and systems from the start?
- Data destruction
- Network segmentation
- Risk acceptance
- Privacy by design
Answer and explanation
Correct answer: D. Privacy by design
Privacy by design is correct because it is used to build privacy safeguards into processes and systems from the start.Question 71. Which security concept is most closely associated with this objective: define the maximum acceptable amount of data loss measured in time?
- Mean time to repair
- Service-level agreement
- Recovery point objective (RPO)
- Recovery time objective
Answer and explanation
Correct answer: C. Recovery point objective (RPO)
Recovery point objective (RPO) is correct because it is used to define the maximum acceptable amount of data loss measured in time.Question 72. Which security concept is most closely associated with this objective: define the maximum acceptable time to restore a service after disruption?
- Data classification
- Recovery time objective (RTO)
- Recovery point objective
- Log retention
Answer and explanation
Correct answer: B. Recovery time objective (RTO)
Recovery time objective (RTO) is correct because it is used to define the maximum acceptable time to restore a service after disruption.
Study responsibly: Do not use this resource during graded, proctored, or restricted assessments. Follow your institution's academic-integrity rules.
PDF Preview
Generate, preview, and download this exam record.