D329

D329 Network and Security - Applications help

The short answer

D329 Network and Security - Applications is recorded under banner number ITEC 2112 and is worth 4 competency units. It is the applications half of the network security pair, aligned to the CompTIA Security+ body of knowledge: threats, attacks and vulnerabilities, designing security solutions for enterprise infrastructures, and implementing them across hardware. Note that it shares its banner number with D315, the foundations course of the same pair, so always confirm the course code on your Degree Plan rather than relying on the banner alone.

D329 grading scale at WGU, how the work is graded, from WGU Tutors
How WGU grades D329, visualized by WGU Tutors.

Threats are only useful when attached to controls

The volume of threat terminology in this course tempts students into flashcard study, and flashcards produce a familiar failure: you can define a technique and still cannot say what stops it. Every threat in the syllabus exists in a pair with the controls that reduce it. Credential attacks pair with multi-factor authentication, lockout policy and monitoring for impossible travel. Traffic interception pairs with encryption in transit and certificate validation. Studying in pairs halves the memory load and produces answers that can survive an applied question.

Enterprise design is the second half and it is where the course earns its Applications title. Designing security for an infrastructure means placing controls where the traffic and the trust boundaries actually are: segmenting so a compromise in one zone does not become a compromise everywhere, authenticating at the point of access rather than at the perimeter only, and logging where you would need evidence later. A design answer that lists good controls without saying where they sit has not answered the question.

Implementation across hardware brings the practical constraints. Controls have to run on real devices with real capacity, and a design that assumes every switch supports every feature is a design that will not survive procurement. Scenarios in this course often include an equipment detail for exactly that reason.

The layered idea worth carrying through everything: no single control is expected to hold. Defence in depth means an attacker has to defeat several independent measures, and an answer that shows two or three layers with different failure modes is stronger than one that names a single excellent control.

Competent or Not Competent is the whole scale. There are no letter grades and no ordinary grade point average, and 4 competency units describes how much of a flat-priced six month term this course occupies. Security material rewards concentrated study, so a focused run at this course usually costs less time overall than months of intermittent contact.

Building a security design plan from scored aspects

If your version of D329 is assessed by a performance assessment, the aspects usually mix threat analysis with design and implementation. WGU requires a score of 2 in each aspect for a task to pass and scores each aspect separately, so a thorough threat catalogue does nothing for an unaddressed implementation aspect.

Convert to a budget first. Suppose the rubric shows eight scored aspects and the deliverable targets about 2,300 words. Reserve 150 words for the infrastructure description and 110 for the close, leaving 2,040 across eight aspects, or 255 each. Weight it: three aspects that ask you to design or justify controls need 340 each because each requires a threat, a placement and a residual risk; the five remaining aspects, which identify, describe or apply, take 204. Three at 340 plus five at 204 is 2,040 exactly.

Draft the threat analysis before the design section even if the rubric lists them the other way round. A design written first tends to be a list of controls the student already knew, with threats reverse-engineered to justify them, and evaluators recognise that shape. Threats first produces a design that answers something, and it usually shortens the document because controls with no matching threat get dropped instead of defended.

Use a fixed internal pattern for every control you recommend: the threat it addresses, where it sits in the infrastructure, what it costs in performance or administration, and what it still leaves exposed. That last element, residual risk, is the single most reliable way to lift a security answer, and students omit it more often than any other component.

Shape for an enterprise security design

D329 deliverables usually assess an infrastructure and design protection for it. These proportions fit that document.

SectionContentShare
Infrastructure baselineThe environment as it stands: segments, devices, access paths, and what data lives where.12 percent
Threat analysisCredible threats for this environment, each tied to an asset and an access path rather than listed generically.19 percent
Design decisionsControls chosen, placed on the topology, with the threat each one addresses.22 percent
Implementation detailHow each control is configured on the actual hardware, including capability constraints.17 percent
Layering and residual riskWhich layers back each other up and what remains exposed after all controls are in place.14 percent
Monitoring and responseWhat is logged, who watches it, and what a detection would trigger.11 percent
ClosePriority order for implementation with the reason the first item goes first.5 percent

Sourcing security claims responsibly

Security has strong public sources and a great deal of vendor noise around them. Control definitions and design guidance belong to published frameworks and to national cyber agency guidance. Vulnerability and technique descriptions belong to the recognised public catalogues and to agency advisories, which are dated and versioned for good reason. Product capability belongs to vendor documentation, kept subordinate to the control discussion so the design does not read as a shopping list.

Currency matters more here than in most subjects. Attack techniques and recommended mitigations change, and a source three or four years old may recommend something now considered inadequate. Give the date of anything you cite and prefer the current version of a framework or advisory over a summary that quotes an older edition.

Be precise about what a control does. Encryption in transit does not protect a compromised endpoint. Multi-factor authentication does not stop a session token being stolen after login. Precision of this kind is what an evaluator uses to distinguish a student who understands controls from one who has memorised their names, and stating a limitation costs a sentence.

Follow the citation style named in your task and cite at the point of claim. Where you place a control on a diagram, refer to it by the same name in the text, and keep one naming convention for zones and devices across every section so the design can be followed without translation.

Competent security work versus a return

Competent submissions connect everything. Threats are specific to the described environment, controls are placed rather than listed, implementation acknowledges the hardware, and residual risk is stated plainly. The document reads like a design review rather than a glossary.

Returns share four signatures. The threat section is a generic catalogue that would fit any organization. Controls are named without placement, so the design cannot be evaluated. The submission claims that a control eliminates a risk, which no control does. Or the implementation section ignores a capability constraint the scenario explicitly stated.

A useful final check: for each control in your design, write one sentence describing how an attacker would still succeed. If you cannot write that sentence, you have not understood the control well enough yet. If you can, that sentence usually belongs in the document.

Performance assessment work at WGU can be revised and resubmitted with no grade penalty, so submit once every aspect has a genuine answer. If your section also carries an objective assessment, WGU objective assessments are proctored and our boundary is absolute. We prepare only: threat and control pairing drills, practice questions, and a straight read on whether your preassessment result says go or wait. We never sit an exam, stay out of the room entirely, and portal credentials are never requested or handled.

Controls listed but not placed?

Send the D329 rubric and your infrastructure scenario. We pair threats with controls, place them, and return a plan with word targets.

Seven mistakes that cost time in D329

  • Studying threats alone. Learn every threat with its controls attached. Applied questions ask for the pair, not the definition.
  • Generic threat catalogues. A threat list that would fit any organization tells the evaluator you did not read the scenario.
  • Controls with no placement. Where a control sits determines what it protects. Put it on the topology.
  • Claiming elimination. Controls reduce risk. Saying a measure eliminates a threat is the fastest way to look inexperienced.
  • Ignoring hardware limits. If the scenario names the equipment, its capabilities are part of the problem being set.
  • Skipping residual risk. The strongest paragraph in most security submissions is the one that says what is still exposed.
  • Confusing the codes. D329 shares banner ITEC 2112 with D315, which is the foundations course. Check the course code on your Degree Plan.
  • Designing without an implementation order. Everything cannot be first. Rank the controls and give a reason for the one at the top.

Three questions students ask about D329

Why do D315 and D329 share the same banner number?
The catalog records banner ITEC 2112 against both the foundations and the applications course in this pair. That makes the banner number ambiguous on its own, so use the course code from your Degree Plan, D315 or D329, when you register, search for material or ask your program mentor about sequencing.
Does this course prepare me for a security certification?
The material aligns to a widely recognised security certification body of knowledge, so study here transfers if you later choose to pursue it. Whether a certification is required for your program is a Degree Plan question rather than a course question, and your program mentor is the right person to confirm it.
How much networking do I need before starting?
Enough to read a topology, understand addressing and know how traffic flows between segments. The security design work assumes you can place a control in a network rather than only name it, so students who have finished the foundations networking material find this course substantially smoother.

Where D329 sits in WGU's programs

The July 2026 catalog places this code in 6 current WGU programs. Open a program page for the complete standard path and term positions. The live Degree Plan remains authoritative after transfer credit, substitutions, and mentor planning.

The assessments, one by one

The public catalog does not publish this course's PA/OA identity or task count. WGU Tutors publishes at most one PA manual per course and only from a WGU-controlled public rubric. Until that source exists, PA help begins from the student's real Course of Study and OA support remains preparation only.

Keep going

Online now