WGU D488 EXAM | CYBERSECURITY
ARCHITECTURE AND ENGINEERING
EXAM | QUESTIONS AND ANSWERS
RATED A+ | LATEST 2025/2026 GUIDE
VPC
-Correct Answer- Traffic mirroring is a feature available on cloud platform's
designed to all traffic to be forwarded and inspected.
Wireless Intrusion Detection System (WIDS)
-Correct Answer- A type of NIDS that scans the radio frequency spectrum
for possible threats to the wireless network, primarily rogue access points.
Network Intrusion Prevention System (NIPS)
-Correct Answer- A technology that monitors network traffic to immediately
react to block a malicious attack. It is place inline with traffic and
susceptible to false positive in not configured properly and will block
legitimate traffic
Wireless Intrusion Prevention System (WIPS)
,-Correct Answer- Used to detect and restrict network access to
unauthorized wireless devices, also capable of searching for and locating
rogue access points.
File Integrity Monitoring (FIM)
-Correct Answer- Used to validate the integrity of operating system and
application software files using a verification method between the current
file state and a known good baseline
Simple Network Management Protocol (SNMP)
-Correct Answer- A protocol used to monitor and manage network devices,
such as routers, switches, and servers.
NetFlow
-Correct Answer- A network protocol system created by Cisco that collects
active IP network traffic as it flows in or out of an interface, including its
point of origin, destination, volume and paths on the network
Data Loss Prevention (DLP)
-Correct Answer- A system that can identify critical data, monitor how it is
being accessed, and protect it from unauthorized users.
,Antivirus
-Correct Answer- software that is specifically designed to detect viruses
and protect a computer and files from harm. Now part of and endpoint
detection and response strategy.
Network Segmentation
-Correct Answer- The act of dividing a network into multiple smaller
networks, each acting as its own small network (subnet) This is called
subnetting. The basic principle behind this is that an individual network
segment failure does not impact the larger enterprise network.
Virtual LANs (Virtual Local Area Networks)
-Correct Answer- Segmenting a network logically from endpoints in one
network from the endpoints in another network.
Screened Subnet
-Correct Answer- also known as DMZ; commonly uses two firewalls; one
between public network and DMZ; other resides between the DMZ and the
private network
Staging Environment
, -Correct Answer- A "production like" environment to test installation,
configuration and migration scripts.
Performance testing, load testing, processes required by other teams,
boundary partners, etc.
Guest environment
-Correct Answer- Describe the hosts and networks available to visitors,
such as the public or vendors and should be completely isolated.
Access Control Lists
-Correct Answer-
- acts like firewall for subnet
- across multiple subnets
- overrules security groups
- rules evaluated from lowest to greatest
- default traffic permissions denies inbound and outbound
peer-to-peer
-Correct Answer- A network model where all computers on the network are
equal and data may be shared from computer to computer.
air gap
ARCHITECTURE AND ENGINEERING
EXAM | QUESTIONS AND ANSWERS
RATED A+ | LATEST 2025/2026 GUIDE
VPC
-Correct Answer- Traffic mirroring is a feature available on cloud platform's
designed to all traffic to be forwarded and inspected.
Wireless Intrusion Detection System (WIDS)
-Correct Answer- A type of NIDS that scans the radio frequency spectrum
for possible threats to the wireless network, primarily rogue access points.
Network Intrusion Prevention System (NIPS)
-Correct Answer- A technology that monitors network traffic to immediately
react to block a malicious attack. It is place inline with traffic and
susceptible to false positive in not configured properly and will block
legitimate traffic
Wireless Intrusion Prevention System (WIPS)
,-Correct Answer- Used to detect and restrict network access to
unauthorized wireless devices, also capable of searching for and locating
rogue access points.
File Integrity Monitoring (FIM)
-Correct Answer- Used to validate the integrity of operating system and
application software files using a verification method between the current
file state and a known good baseline
Simple Network Management Protocol (SNMP)
-Correct Answer- A protocol used to monitor and manage network devices,
such as routers, switches, and servers.
NetFlow
-Correct Answer- A network protocol system created by Cisco that collects
active IP network traffic as it flows in or out of an interface, including its
point of origin, destination, volume and paths on the network
Data Loss Prevention (DLP)
-Correct Answer- A system that can identify critical data, monitor how it is
being accessed, and protect it from unauthorized users.
,Antivirus
-Correct Answer- software that is specifically designed to detect viruses
and protect a computer and files from harm. Now part of and endpoint
detection and response strategy.
Network Segmentation
-Correct Answer- The act of dividing a network into multiple smaller
networks, each acting as its own small network (subnet) This is called
subnetting. The basic principle behind this is that an individual network
segment failure does not impact the larger enterprise network.
Virtual LANs (Virtual Local Area Networks)
-Correct Answer- Segmenting a network logically from endpoints in one
network from the endpoints in another network.
Screened Subnet
-Correct Answer- also known as DMZ; commonly uses two firewalls; one
between public network and DMZ; other resides between the DMZ and the
private network
Staging Environment
, -Correct Answer- A "production like" environment to test installation,
configuration and migration scripts.
Performance testing, load testing, processes required by other teams,
boundary partners, etc.
Guest environment
-Correct Answer- Describe the hosts and networks available to visitors,
such as the public or vendors and should be completely isolated.
Access Control Lists
-Correct Answer-
- acts like firewall for subnet
- across multiple subnets
- overrules security groups
- rules evaluated from lowest to greatest
- default traffic permissions denies inbound and outbound
peer-to-peer
-Correct Answer- A network model where all computers on the network are
equal and data may be shared from computer to computer.
air gap