D329 Network and Security - Applications is recorded under banner number ITEC 2112 and is worth 4 competency units. It is the applications half of the network security pair, aligned to the CompTIA Security+ body of knowledge: threats, attacks and vulnerabilities, designing security solutions for enterprise infrastructures, and implementing them across hardware. Note that it shares its banner number with D315, the foundations course of the same pair, so always confirm the course code on your Degree Plan rather than relying on the banner alone.
Threats are only useful when attached to controls
The volume of threat terminology in this course tempts students into flashcard study, and flashcards produce a familiar failure: you can define a technique and still cannot say what stops it. Every threat in the syllabus exists in a pair with the controls that reduce it. Credential attacks pair with multi-factor authentication, lockout policy and monitoring for impossible travel. Traffic interception pairs with encryption in transit and certificate validation. Studying in pairs halves the memory load and produces answers that can survive an applied question.
Enterprise design is the second half and it is where the course earns its Applications title. Designing security for an infrastructure means placing controls where the traffic and the trust boundaries actually are: segmenting so a compromise in one zone does not become a compromise everywhere, authenticating at the point of access rather than at the perimeter only, and logging where you would need evidence later. A design answer that lists good controls without saying where they sit has not answered the question.
Implementation across hardware brings the practical constraints. Controls have to run on real devices with real capacity, and a design that assumes every switch supports every feature is a design that will not survive procurement. Scenarios in this course often include an equipment detail for exactly that reason.
The layered idea worth carrying through everything: no single control is expected to hold. Defence in depth means an attacker has to defeat several independent measures, and an answer that shows two or three layers with different failure modes is stronger than one that names a single excellent control.
Competent or Not Competent is the whole scale. There are no letter grades and no ordinary grade point average, and 4 competency units describes how much of a flat-priced six month term this course occupies. Security material rewards concentrated study, so a focused run at this course usually costs less time overall than months of intermittent contact.
Building a security design plan from scored aspects
If your version of D329 is assessed by a performance assessment, the aspects usually mix threat analysis with design and implementation. WGU requires a score of 2 in each aspect for a task to pass and scores each aspect separately, so a thorough threat catalogue does nothing for an unaddressed implementation aspect.
Convert to a budget first. Suppose the rubric shows eight scored aspects and the deliverable targets about 2,300 words. Reserve 150 words for the infrastructure description and 110 for the close, leaving 2,040 across eight aspects, or 255 each. Weight it: three aspects that ask you to design or justify controls need 340 each because each requires a threat, a placement and a residual risk; the five remaining aspects, which identify, describe or apply, take 204. Three at 340 plus five at 204 is 2,040 exactly.
Draft the threat analysis before the design section even if the rubric lists them the other way round. A design written first tends to be a list of controls the student already knew, with threats reverse-engineered to justify them, and evaluators recognise that shape. Threats first produces a design that answers something, and it usually shortens the document because controls with no matching threat get dropped instead of defended.
Use a fixed internal pattern for every control you recommend: the threat it addresses, where it sits in the infrastructure, what it costs in performance or administration, and what it still leaves exposed. That last element, residual risk, is the single most reliable way to lift a security answer, and students omit it more often than any other component.
Shape for an enterprise security design
D329 deliverables usually assess an infrastructure and design protection for it. These proportions fit that document.
| Section | Content | Share |
|---|---|---|
| Infrastructure baseline | The environment as it stands: segments, devices, access paths, and what data lives where. | 12 percent |
| Threat analysis | Credible threats for this environment, each tied to an asset and an access path rather than listed generically. | 19 percent |
| Design decisions | Controls chosen, placed on the topology, with the threat each one addresses. | 22 percent |
| Implementation detail | How each control is configured on the actual hardware, including capability constraints. | 17 percent |
| Layering and residual risk | Which layers back each other up and what remains exposed after all controls are in place. | 14 percent |
| Monitoring and response | What is logged, who watches it, and what a detection would trigger. | 11 percent |
| Close | Priority order for implementation with the reason the first item goes first. | 5 percent |
Sourcing security claims responsibly
Security has strong public sources and a great deal of vendor noise around them. Control definitions and design guidance belong to published frameworks and to national cyber agency guidance. Vulnerability and technique descriptions belong to the recognised public catalogues and to agency advisories, which are dated and versioned for good reason. Product capability belongs to vendor documentation, kept subordinate to the control discussion so the design does not read as a shopping list.
Currency matters more here than in most subjects. Attack techniques and recommended mitigations change, and a source three or four years old may recommend something now considered inadequate. Give the date of anything you cite and prefer the current version of a framework or advisory over a summary that quotes an older edition.
Be precise about what a control does. Encryption in transit does not protect a compromised endpoint. Multi-factor authentication does not stop a session token being stolen after login. Precision of this kind is what an evaluator uses to distinguish a student who understands controls from one who has memorised their names, and stating a limitation costs a sentence.
Follow the citation style named in your task and cite at the point of claim. Where you place a control on a diagram, refer to it by the same name in the text, and keep one naming convention for zones and devices across every section so the design can be followed without translation.
Competent security work versus a return
Competent submissions connect everything. Threats are specific to the described environment, controls are placed rather than listed, implementation acknowledges the hardware, and residual risk is stated plainly. The document reads like a design review rather than a glossary.
Returns share four signatures. The threat section is a generic catalogue that would fit any organization. Controls are named without placement, so the design cannot be evaluated. The submission claims that a control eliminates a risk, which no control does. Or the implementation section ignores a capability constraint the scenario explicitly stated.
A useful final check: for each control in your design, write one sentence describing how an attacker would still succeed. If you cannot write that sentence, you have not understood the control well enough yet. If you can, that sentence usually belongs in the document.
Performance assessment work at WGU can be revised and resubmitted with no grade penalty, so submit once every aspect has a genuine answer. If your section also carries an objective assessment, WGU objective assessments are proctored and our boundary is absolute. We prepare only: threat and control pairing drills, practice questions, and a straight read on whether your preassessment result says go or wait. We never sit an exam, stay out of the room entirely, and portal credentials are never requested or handled.
Controls listed but not placed?
Send the D329 rubric and your infrastructure scenario. We pair threats with controls, place them, and return a plan with word targets.
Seven mistakes that cost time in D329
- Studying threats alone. Learn every threat with its controls attached. Applied questions ask for the pair, not the definition.
- Generic threat catalogues. A threat list that would fit any organization tells the evaluator you did not read the scenario.
- Controls with no placement. Where a control sits determines what it protects. Put it on the topology.
- Claiming elimination. Controls reduce risk. Saying a measure eliminates a threat is the fastest way to look inexperienced.
- Ignoring hardware limits. If the scenario names the equipment, its capabilities are part of the problem being set.
- Skipping residual risk. The strongest paragraph in most security submissions is the one that says what is still exposed.
- Confusing the codes. D329 shares banner ITEC 2112 with D315, which is the foundations course. Check the course code on your Degree Plan.
- Designing without an implementation order. Everything cannot be first. Rank the controls and give a reason for the one at the top.
Three questions students ask about D329
Why do D315 and D329 share the same banner number?
Does this course prepare me for a security certification?
How much networking do I need before starting?
Where D329 sits in WGU's programs
The July 2026 catalog places this code in 6 current WGU programs. Open a program page for the complete standard path and term positions. The live Degree Plan remains authoritative after transfer credit, substitutions, and mentor planning.
The assessments, one by one
The public catalog does not publish this course's PA/OA identity or task count. WGU Tutors publishes at most one PA manual per course and only from a WGU-controlled public rubric. Until that source exists, PA help begins from the student's real Course of Study and OA support remains preparation only.