D340

D340 Cyber Defense and Countermeasures help

The short answer

D340 Cyber Defense and Countermeasures is listed under banner number ITAS 3021 and is worth 4 competency units. It covers handling and responding to computer security incidents, with the principles and techniques used to detect and respond to current and emerging threats. D340 and ITAS 3021 are one requirement, and the course text is near-identical to the graduate D483. The habit it builds is deciding under pressure with incomplete information, then being able to justify the decision afterwards.

D340 grading scale at WGU, how the work is graded, from WGU Tutors
How WGU grades D340, visualized by WGU Tutors.

Response is a sequence of decisions, each with a cost

Incident response looks like a technical activity and is mostly a decision activity. Do you isolate the affected host immediately, losing the volatile evidence that would tell you what happened, or do you observe longer and accept that the attacker may extend their access? Do you reset credentials now, alerting an intruder who might otherwise be watched, or later? Every choice buys something and pays for it, and the course wants you able to name what you bought.

The lifecycle gives that decision-making a structure. Preparation is everything you do before an incident so that response is possible at all: logging, contacts, playbooks, backups you have tested. Detection and analysis is where you decide what is happening. Containment, eradication and recovery is where you act. Post-incident activity is where the organization learns. Aspects in this course frequently map onto that structure, and answers that respect it read as informed.

Preparation is the phase students underweight and it is the cheapest place to earn credit. If the scenario organization does not log the thing you would need to investigate, that is a preparation finding, and saying so is more useful than pretending the evidence exists. Real response work is constrained by decisions made months earlier, and recognising that constraint is analysis rather than an excuse.

Communication runs through everything. Who is told, when, at what level of detail, and who is authorised to speak to outside parties are questions with legal and regulatory dimensions. A response plan that handles the technical work perfectly and does not say who notifies whom is incomplete in a way the aspects will notice.

Your result reads Competent or Not Competent, because letter grades and an ordinary grade point average do not exist here, and 4 competency units is how the course's weight is expressed in a six month flat-rate term.

Turning aspects into a response document

If your version of D340 is assessed by a performance assessment, the aspects usually follow the incident lifecycle plus the countermeasure recommendations that come out of it. WGU requires a score of 2 in each aspect for a task to pass and judges each one alone, so strong containment reasoning will not carry an unaddressed post-incident or communication aspect.

Budget before drafting. Take a rubric with eight scored aspects and a target near 2,400 words. Reserve 160 words for the environment and the reported incident, and 120 for the close, leaving 2,120 across eight aspects, or 265 each. Weight by demand: three aspects requiring decisions with justification need 360 each, which is 1,080; the five remaining aspects, covering detection, evidence, communication, recovery and lessons, take 208 each, which is 1,040. Together that is 2,120.

Inside every decision paragraph, state the option chosen, the option rejected, and the cost of the choice. Response writing that presents one path with no alternatives reads as narration; response writing that shows a decision being made reads as competence, and it is what a post-incident review would actually contain.

Reserve budget for timing. Incidents are sequences, and a document that gives times for detection, decision, containment and recovery lets an evaluator see the shape of the response rather than only its content.

Shape for an incident response deliverable

D340 deliverables usually handle an incident and recommend countermeasures. These proportions fit that document.

SectionContentShare
Environment and readinessThe estate, what is logged and retained, and what preparation exists before the incident starts.13 percent
Detection and scopingHow the incident was noticed, what was affected, and what remained unknown at each point.16 percent
Containment decisionOptions, the choice made, what evidence or access it cost, and the authorisation for it.18 percent
Eradication and recoveryRemoval of the cause, restoration path, and the verification that service and integrity returned.17 percent
CommunicationInternal notification, escalation, and any external or regulatory obligation with its trigger.13 percent
CountermeasuresControls recommended to prevent recurrence, each tied to the specific failure it addresses.16 percent
CloseLessons captured as concrete changes with owners, not as general observations.7 percent

Sourcing response and countermeasure claims

Incident handling has published guidance from national agencies and standards bodies, and that guidance is the right authority for lifecycle structure, evidence handling and notification practice. Cite it precisely, because response guidance is prescriptive in places and a paraphrase can change what is being recommended.

Threat and technique claims belong to recognised knowledge bases of attacker behaviour and to dated agency advisories. Currency is important: a countermeasure that was adequate three years ago may now be routinely bypassed, and citing an old source without noting its age invites the evaluator to check.

Where regulation is involved, cite the regulation. Notification obligations vary by jurisdiction and by data type, and the strongest submissions state which obligation applies, what triggers it and what the timeframe is, rather than saying that authorities should be informed. If the scenario does not give you enough to determine jurisdiction, say what you would need to know; that is a better answer than an invented certainty.

Distinguish what was known at the time from what is known now. Response documents are written after the fact and it is easy to describe early decisions using information that only arrived later, which makes the responder look either prescient or negligent depending on the sentence. Saying explicitly what was known at each decision point, and what was still unknown, is how a real post-incident review reads and it protects your reasoning from hindsight.

Keep to the citation style the task requires and attach every source to the sentence that depends on it. Where you present a decision, a short table of option, consequence and choice is worth more than three paragraphs, and it makes your reasoning checkable at a glance.

Competent response work and returned work

Competent submissions show decisions rather than events. Options are named, costs are acknowledged, timing is visible, communication obligations are handled specifically, and countermeasures address the actual failure rather than being a general list of good practice.

Returns cluster in four shapes. The document narrates what happened with no decision points visible. Containment is described with no mention of what it cost in evidence or availability. Communication is reduced to informing management. Or the countermeasure section recommends controls that would not have prevented this incident, which is the clearest sign that the analysis and the recommendations were written separately.

The check that catches the last one: for every countermeasure you propose, write the sentence "if this had been in place, the incident would have been stopped or detected at this point". If you cannot write that sentence, the control may still be worth having but it does not belong in this section.

A returned performance assessment costs nothing in grade terms to rework, so submit as soon as every aspect has a real answer, since an early submission leaves room for a revision cycle. If your section also carries an objective assessment, WGU objective assessments are proctored and our boundary is fixed: preparation only, with lifecycle drills, scenario practice and a candid read on your preassessment result. We will not take your exam, stay out of the room entirely, and your portal login is never something we touch.

Incident written as a story?

Send the D340 rubric and scenario. We convert it into visible decisions with costs, a timeline, and word targets for every aspect.

Eight mistakes that cost time in D340

  • Narrating instead of deciding. Name the options, the choice and the cost. That is what a response document is for.
  • Ignoring the evidence cost of containment. Pulling a machine off the network destroys volatile evidence. Say that you knew.
  • Skipping preparation. If the logging you need does not exist, that is a finding, not an obstacle to work around silently.
  • Communication reduced to management. Regulatory and external notification have triggers and timeframes. Name them.
  • Generic countermeasures. Every control should map to the specific failure that let this incident happen.
  • No timeline. Incidents are sequences. Times for detection, decision and containment show the shape of the response.
  • Undated threat sources. Technique and mitigation advice ages quickly in this field.
  • Lessons with no owner. A lesson that is not assigned to someone as a change is an observation, not an outcome.

Three questions students ask about D340

How is D340 different from the graduate D483?
The course text is near-identical, with D340 sitting in the bachelor's plan under banner ITAS 3021 and D483 in the graduate plan under ITAS 5222. They are separate catalog entries and separate requirements, so your Degree Plan determines which one applies rather than the similarity of the descriptions.
Do I need forensics knowledge for this course?
You need to understand that evidence exists and that some response actions destroy it, which is a decision-level awareness rather than a forensic skill. The detailed acquisition and analysis techniques belong to the dedicated digital forensics course, and that course pairs well with this one.
Should I write about a real breach?
Follow your rubric, which normally supplies a scenario. Where public incidents are used as supporting material, treat published accounts as illustrations with a date rather than as authoritative fact, since early reporting on breaches is frequently corrected later.

Where D340 sits in WGU's programs

The July 2026 catalog places this code in 1 current WGU program. Open a program page for the complete standard path and term positions. The live Degree Plan remains authoritative after transfer credit, substitutions, and mentor planning.

The assessments, one by one

The public catalog does not publish this course's PA/OA identity or task count. WGU Tutors publishes at most one PA manual per course and only from a WGU-controlled public rubric. Until that source exists, PA help begins from the student's real Course of Study and OA support remains preparation only.

Keep going

Online now