WGU C836: Fundamentals of Information Security
C836 is WGU's entry point to security: the CIA triad, threats and vulnerabilities, access control, cryptography basics, and security across operations, networks, and applications. It's required across the IT and cybersecurity degrees and ends in an OA.
Fennie is independent and not affiliated with Western Governors University. This is an unofficial study guide.
Build my C836 study planWhat makes it hard
The book (Andress's Foundations of Information Security) is short, but the OA expects precise definitions — students lose points confusing closely related terms like authentication vs. authorization or the access control models. Most pass in 2–3 weeks; the trap is assuming general IT knowledge substitutes for the course's specific framing.
What you'll cover
- • CIA triad and security principles
- • Identification, authentication, authorization
- • Access control models
- • Cryptography basics
- • Network and operating system security
- • Application security and auditing
The C836 study guide
How to study for WGU C836, step by step.
- 1
Take the pre-assessment before opening the book
General IT knowledge doesn't substitute for this course's specific framing, and the PA proves it. Use the score report to target your reading.
- 2
Read Andress with a definitions notebook
The book is short, so read your weak chapters carefully and write down every precise definition — the OA punishes fuzzy paraphrases.
- 3
Drill the paired terms until they separate
Authentication vs. authorization, the access control models, symmetric vs. asymmetric crypto — these near-twins are where most points are lost. Flashcard them daily.
- 4
Test yourself with scenarios
For each access control model, practice naming which one a described situation uses. The OA frames several questions this way.
- 5
Pass the PA cleanly, then schedule
The pre-assessment maps closely to the OA here. A comfortable pass is your green light to book within the week.
- 6
Turn the plan over to Fennie
Upload the C836 chapter list to Fennie and Daily Plans spaces the definition-heavy review to your OA date, with flashcards for the paired terms generated automatically. Free to start.
Start my C836 plan free
How Fennie helps with C836
Fennie's Daily Plans pace the C836 chapters so the definition-heavy material gets spaced review instead of a single cram. Auto-generate flashcards for the paired terms students mix up, and chat through scenarios until you can tell the access control models apart cold.
FAQ
Is WGU C836 hard?
It's on the easier side of the cybersecurity courses, but the OA punishes fuzzy definitions. Students who can precisely distinguish similar terms (authentication vs. authorization, the access control models) pass comfortably.
How long does C836 take?
Most students report 2–3 weeks. The assigned book is short, so steady daily reading plus flashcard review covers it.
What should I focus on for the C836 OA?
The CIA triad, access control models, cryptography vocabulary, and the differences between similar security terms. The pre-assessment maps closely to the OA, so use it as your readiness gate.
Pass C836 with a plan, not a cram
Upload your C836 materials and Fennie generates a Daily Plan paced to your deadline — plus chat, flashcards, and quizzes built from the actual course content.
Get started freeMore WGU courses
C840 — Digital Forensics in Cybersecurity
C840 covers the digital forensics process — evidence handling, chain of custody, forensic tools, and the legal context around investigations. It's part of WGU's cybersecurity program and is assessed with an OA plus applied lab exposure in the course.
C841 — Legal Issues in Information Security
C841 covers cybersecurity law and ethics — CFAA, ECPA, regulatory compliance, and ethical frameworks — assessed through a performance assessment built around the well-known TechFite case study. You analyze the case and write papers applying laws and ethics to what happened.
C844 — Emerging Technologies in Cybersecurity
C844 is a hands-on performance assessment course: you run network scans with Nmap and packet analysis with Wireshark, then write up findings and recommendations as if reporting to an organization. It sits in the cybersecurity program's applied tier.
D329 — Network and Security - Applications
D329 is WGU's CompTIA Security+ course — the SY0-701 certification exam serves as the course assessment. It covers threats and vulnerabilities, security architecture, identity and access management, cryptography, and incident response at Security+ depth.