Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free WGU Network Engineering and Security Foundation Network-and-Security-Foundation Exam Questions

Page: 1 / 7 Total 62 questions

Want more questions? Get Premium Access.

Question 1

Access to a company's information system requires a user to be within a valid geographic location and to enter a valid username and password.

Which concept does this scenario demonstrate?

Correct Answer: B. Multifactor authentication
Explanation:

Multifactor authentication (MFA) requires users to verify their identity using multiple factors, such as something they know (password), something they have (a token or phone), or somewhere they are (geolocation-based access control). Requiring both location verification and password authentication demonstrates MFA.

Certificate verification checks digital certificates for security but does not use multiple authentication factors.

User-based accounting logs user activities but does not verify identity.

Single sign-on (SSO) allows access to multiple systems with one login but is not necessarily MFA.


Question 2

An organization has experienced injection attacks in the past and wants to take actions to mitigate this type of attack.

What should this organization do?

Correct Answer: C. Use server-side validation
Explanation:

Server-side validation helps prevent SQL injection, command injection, and other input-based attacks by ensuring that user input is properly sanitized before being processed by the system. Parameterized queries and input validation should also be implemented to further reduce risk.

Detecting code vulnerabilities is helpful but not a direct mitigation technique.

Decreasing wireless range does not affect injection attacks.

Using WPA2 secures wireless networks but does not prevent injection attacks.


Question 3

When setting up a network, a technician needs a router that creates an access point.

Which router should be used?

Correct Answer: A. Wireless router
Explanation:

A wireless router is designed to create an access point that allows wireless devices to connect to a network. It combines the functions of a traditional router with a wireless access point, enabling communication between wired and wireless devices. These routers use Wi-Fi standards (e.g., 802.11ac, 802.11ax) to transmit data wirelessly.

Broadband routers primarily provide internet connectivity but do not necessarily include Wi-Fi functionality unless specified.

Core routers handle large-scale data routing in the backbone of networks but are not designed for access point creation.

Inter-provider border routers function at an ISP level for routing traffic between different networks, not for providing user access.


Question 4

An organization does not have controls in place to limit employee access to sensitive customer data.

What is a component of the CIA triad that is violated?

Correct Answer: A. Confidentiality
Explanation:

Confidentiality ensures that only authorized users have access to sensitive information. Without proper access controls, employees may be able to view or modify sensitive data without proper authorization, leading to a confidentiality breach.

Integrity involves protecting data from unauthorized modifications.

Availability ensures that systems remain operational.

Interpretation is not part of the CIA triad.


Question 5

A company wants to implement virtual machines with a focus on security and efficiency.

Which type of hypervisor fits the need described in the scenario?

Correct Answer: C. Type 1
Explanation:

A Type 1 hypervisor (bare-metal hypervisor) runs directly on the hardware, providing better security and efficiency compared to Type 2 hypervisors. It reduces attack surfaces and optimizes resource utilization. Examples include VMware ESXi and Microsoft Hyper-V.

Type 2 hypervisors rely on a host OS, making them less secure and efficient.

Open-source and proprietary describe licensing models, not hypervisor types.


Question 6

An attacker sends emails claiming that an online account has been locked. The email provides a fake link with the goal of tricking users into providing login credentials.

Which malicious attack strategy is represented in the scenario?

Correct Answer: A. Phishing
Explanation:

Phishing is a cyberattack where attackers impersonate legitimate entities (e.g., banks, companies) and send fraudulent emails or messages designed to trick recipients into revealing sensitive information, such as usernames, passwords, or financial details. The fake link in the email directs victims to a malicious site that captures their credentials.

IP address spoofing disguises a system's identity but does not involve email deception.

Session hijacking takes over an active session but does not involve email scams.

Man-in-the-middle attack intercepts communication rather than tricking users via emails.


Question 7

A company wants to implement a cloud service to obtain access to virtual machines. The company wants to be able to choose the operating systems and configure each of the machines.

What is the type of cloud service model that fits the needs of this company?

Correct Answer: B. Infrastructure as a Service (IaaS)
Explanation:

Infrastructure as a Service (IaaS) provides virtualized computing resources over the cloud, including virtual machines where users can install and configure their own operating systems and applications. It offers flexibility and scalability without requiring hardware investment. Examples include AWS EC2 and Microsoft Azure Virtual Machines.

FaaS executes small code functions without infrastructure management.

PaaS provides a managed platform but not full OS control.

SaaS offers ready-to-use applications without infrastructure control.


Question 8

An organization is updating its information security policies in order to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA).

What should this organization expect to be required under this legislation?

Correct Answer: A. Securely dispose of personally identifiable information
Explanation:

PIPEDA requires businesses in Canada to protect personal information through security measures and proper disposal practices. This includes secure deletion of personal data when no longer needed to prevent unauthorized access.

Compensating individuals for data sales is not a legal requirement.

Notifying individuals of each data access is unnecessary unless required by a breach.

Disclosing security software is not mandated by PIPEDA.


Question 9

In order to reduce the risk of insider attacks, a company assigns role-based permissions to its users.

Which network security concept does this scenario address?

Correct Answer: D. Authorization
Explanation:

Authorization is the process of granting specific access rights and permissions based on user roles. By implementing Role-Based Access Control (RBAC), organizations ensure that users only have access to resources necessary for their job functions, reducing the risk of insider threats.

Authentication verifies identity but does not control access.

Accounting logs activities but does not restrict access.

Availability ensures system uptime but is unrelated to permissions.


Question 10

An attacker uses login data from a data breach to attempt to access another web service.

Which malicious attack strategy is represented in the scenario?

Correct Answer: B. Credential stuffing
Explanation:

Credential stuffing is a cyberattack where attackers use stolen username-password combinations from one breach to try logging into other services, exploiting users who reuse passwords. Automated tools test multiple credentials against multiple sites, leading to unauthorized access.

Brute-force attack systematically tries all possible passwords but does not use breached data.

Session hijacking intercepts active user sessions but does not use stolen credentials.

Social engineering manipulates users into revealing credentials, rather than using breached data.