C845 Information Systems Security is recorded under banner number ITAS 3050 and is worth 4 competency units. It is a practitioner-level course covering authentication, security testing, intrusion detection and prevention, incident response and recovery, attacks and countermeasures, and cryptography. C845 is a legacy course in the cybersecurity plan, and its material now appears split across D332 and D340 in newer plans, so check which codes your Degree Plan lists.
Six domains that later became two courses
The breadth of C845 is its defining feature. It carries in one 4 competency unit course material that newer plans distribute across a testing course and a defense course, plus cryptography that now has its own home. That means the study load is unusually wide relative to the unit count, and a plan that treats each domain in turn is worth building before you start rather than discovering the breadth in week three.
Authentication is the anchor domain. Something you know, something you have and something you are are three factor categories, and combining categories is what makes authentication multi-factor; two passwords are not two factors. Beyond factors, the course touches how authentication is federated, how sessions are maintained after login, and why a stolen session can bypass strong authentication entirely.
Testing, detection and response then form a cycle. Testing finds weaknesses before an attacker does. Detection notices when something is happening anyway. Response limits the damage and restores service. Countermeasures close the specific gap that was used. Studying these as a cycle rather than as four lists makes the applied questions much easier, because scenarios usually enter the cycle at one point and ask what happens next.
Cryptography appears here in service of the rest: which property a mechanism provides, where it applies, and what key handling it demands. At practitioner level the expectation is correct application rather than mathematical analysis, and precision about what a mechanism does is worth more than familiarity with algorithm names.
The record shows Competent or Not Competent, without letter grades, and WGU keeps no ordinary grade point average, with 4 competency units describing its share of a flat-priced six month term. Any hands-on element happens inside the authorised environment your course provides.
Turning a wide rubric into a section plan
If your version of C845 uses a performance assessment, the aspects usually span several of the domains rather than sitting inside one. WGU requires a score of 2 in each aspect for a task to pass and judges each aspect alone, so on a wide rubric the danger is uneven coverage rather than difficulty.
Budget with breadth in mind. Take a rubric with eight scored aspects and a target near 2,400 words. Reserve 150 words for the environment and the security question being asked, and 110 for the close, leaving 2,140 across eight aspects, or roughly 267 each. Weight by demand: three aspects requiring a recommendation with justification take 360 each, which is 1,080; the five remaining aspects, covering mechanisms, detection, response steps or cryptographic application, take 212 each, which is 1,060. Together that is 2,140.
Write the domain headings before you write any content, then fill the thinnest one first. In a wide course the natural drift is to spend disproportionate effort on the domain you already know, and the aspect you are least comfortable with is the one most likely to fall below the line.
Where an aspect asks for a countermeasure, tie it explicitly to an attack described earlier in your own document. Internal cross-references make a wide submission read as one analysis rather than as six short essays stapled together.
Shape for a practitioner security analysis
C845 deliverables usually analyse a system and recommend protection across several domains. These proportions fit that document.
| Section | Content | Share |
|---|---|---|
| System and exposure | The environment, its users, its data, and how each is reached from outside. | 12 percent |
| Authentication and access | Factors in use, session handling, and where privilege is broader than it needs to be. | 16 percent |
| Testing approach | How weaknesses would be found here, within an authorised scope, and what testing would not reveal. | 14 percent |
| Detection and prevention | What is monitored, what would generate an alert, and what would pass unnoticed. | 17 percent |
| Response and recovery | The steps taken when an alert is real, with authorisation and restoration verification. | 16 percent |
| Cryptographic measures | Where encryption, hashing or signing applies, and the key handling each requires. | 15 percent |
| Close | Priority order and the residual exposure you are accepting. | 10 percent |
Sourcing across six security domains
Breadth means several source families in one document, and keeping them straight is part of the work. Control and process guidance belongs to published frameworks and national agency documentation. Attack technique descriptions belong to recognised public knowledge bases with dates attached. Cryptographic parameter recommendations belong to standards bodies, in their current revision. Product behaviour belongs to vendor documentation.
Because the domains connect, be careful not to let a source from one carry a claim in another. Guidance about authentication practice does not support a claim about detection coverage, even though both appear in the same document and both concern security. Each claim needs a source that actually addresses it.
State limits alongside capabilities. Multi-factor authentication does not protect a session already established. Monitoring does not see what is not logged. Testing does not prove the absence of weaknesses. These sentences cost nothing and they are exactly what distinguishes practitioner-level writing from a summary of best practice.
Where the scenario supplies detail, use it. Number of users, presence of remote access, whether data is regulated and who administers what are all facts that change the right answer, and a document that never refers to them is answering a generic question rather than the one asked.
Follow the citation style named in your task and place each reference beside the claim it supports. Where you compare options, a small table with the option, what it addresses and what it costs keeps a wide document readable and gives the justification aspects an obvious place to be scored.
What passes and what returns
Competent submissions cover every domain at comparable depth, connect them to each other, apply mechanisms to the described environment, and state limits and residual exposure honestly. They read as one analysis with a priority order at the end.
Returns in a wide course usually come from imbalance. One domain is thorough and another is a paragraph. Countermeasures appear with no attack behind them. Cryptography is named without saying which property it provides. Or the document is technically correct throughout and never prioritises, leaving the reader with eight equal recommendations.
The submissions that stand out in a wide course are the ones that show the domains interacting. Detection depends on what authentication logs record. Response depends on whether testing already established what normal looks like. Cryptographic choices determine what monitoring can see inside a session. Writing two or three sentences that link domains explicitly turns a broad document into an argument, and it demonstrates exactly the practitioner understanding the course title claims.
A quick balance check: count the words under each domain heading. If one is triple another, you have found your weakest aspect before the evaluator did, and the fix is usually an hour of study rather than an hour of writing.
WGU attaches no grade penalty to a revised and resubmitted performance assessment, so send it in the moment each aspect is genuinely addressed, and let the evaluator find the last gap faster than you would. If your section also carries an objective assessment, WGU objective assessments are proctored and our position does not move: preparation only, with domain drills, practice questions and a candid read on your preassessment result. We never sit an exam, are absent for the whole of it, and we would refuse portal credentials if they were offered.
Six domains, one deadline?
Send the C845 rubric and scenario. We balance the domains, connect them into one analysis, and set word targets per aspect.
Eight mistakes that cost time in C845
- Underestimating the breadth. Six domains in four competency units is wide. Plan each domain separately before starting.
- Two passwords called multi-factor. Factors have categories. Two items from the same category is not multi-factor.
- Ignoring session handling. Strong authentication protects login. A stolen session bypasses it entirely.
- Countermeasures with no attack. Tie every control back to something you described earlier in the document.
- Cryptography without a property. Say whether you are providing confidentiality, integrity, authentication or non-repudiation.
- Uneven domains. Count the words per section. The thin one is where the return comes from.
- No priority order. Eight equal recommendations are not a recommendation.
- Testing outside the authorised environment. Any hands-on work stays inside the scope your course provides, without exception.
- Studying only the familiar domain. Effort follows comfort unless you plan against it, and the unfamiliar domain is where the score is decided.
Three questions students ask about C845
Is C845 still on current Degree Plans?
Can I use study material for D332 and D340 instead?
How practical is the course?
Where C845 sits in WGU's programs
The July 2026 catalog places this code in 1 current WGU program. Open a program page for the complete standard path and term positions. The live Degree Plan remains authoritative after transfer credit, substitutions, and mentor planning.
The assessments, one by one
The public catalog does not publish this course's PA/OA identity or task count. WGU Tutors publishes at most one PA manual per course and only from a WGU-controlled public rubric. Until that source exists, PA help begins from the student's real Course of Study and OA support remains preparation only.