,WGU D488 Cybersecurity Architecture & Engineering Final Exam Test
Bank Actual 2026/2027 – Complete Exam-Style Questions | 100%
Verified – Pass Guaranteed – A+ Graded
1. Which principle ensures users are granted only the minimal access rights
needed to perform their job functions?
A. Defense in Depth
B. Separation of Duties
C. Least Privilege
D. Zero Trust
Answer: C. Least Privilege - This principle limits access rights to the absolute
minimum necessary, reducing the attack surface and potential damage from
compromised accounts.
2. A government agency is planning a hybrid cloud deployment. Strict controls
must be in place that can label classified data. The solution must ensure that
access rights will be granted based on the user's government security
classification. Which access control model should be used?
A. Role-Based Access Control (RBAC)
B. Mandatory Access Control (MAC)
C. Attribute-Based Access Control (ABAC)
Answer: B. Mandatory Access Control (MAC) - MAC is standard for classified
environments. Access is based on system-enforced security labels (e.g., Top
Secret, Confidential), and users cannot change these controls.
3. A security team notices traffic coming from a country where the organization
does not have any business operations. Which of the following could this be an
indicator of?
A. High call volume
B. Odd network traffic
C. Geographic anomalies
D. Unauthorized changes
Answer: C. Geographic anomalies - Traffic from unexpected geographic locations
is a geographic anomaly that may indicate a security threat.
, 4. A cybersecurity analyst at a software company conducted a vulnerability
assessment and discovered multiple vulnerabilities on the company's webpage.
The CISO decided not to fix the discrepancies due to the vulnerabilities being
outside of the organization's resources. Which risk mitigation strategy is
demonstrated?
A. Accept
B. Mitigate
C. Avoid
D. Transfer
Answer: A. Accept - Risk acceptance acknowledges a risk but takes no action,
often because the cost of mitigation is not justified.
5. Which solution will notify the security team automatically in the event of
future malware variants invading the network?
A. Security information and event management (SIEM) alerts
B. Data loss prevention (DLP) alerts
C. Antivirus alerts
D. Syslog alerts
Answer: C. Antivirus alerts - Antivirus solutions are specifically designed to detect
and alert on malware infections.
6. What is the primary purpose of a Security Information and Event
Management (SIEM) system?
A. Block malware
B. Aggregate and analyze logs
C. Encrypt traffic
D. Manage user credentials
Answer: B. Aggregate and analyze logs - A SIEM collects, normalizes, correlates,
and analyzes security event data from multiple sources, providing centralized
monitoring and alerting.
7. A security architect is designing a strategy to help continue operating in the
face of a cyber-attack. Which of the following will help accomplish this
objective?
A. Heterogeneity
B. Clustering
Bank Actual 2026/2027 – Complete Exam-Style Questions | 100%
Verified – Pass Guaranteed – A+ Graded
1. Which principle ensures users are granted only the minimal access rights
needed to perform their job functions?
A. Defense in Depth
B. Separation of Duties
C. Least Privilege
D. Zero Trust
Answer: C. Least Privilege - This principle limits access rights to the absolute
minimum necessary, reducing the attack surface and potential damage from
compromised accounts.
2. A government agency is planning a hybrid cloud deployment. Strict controls
must be in place that can label classified data. The solution must ensure that
access rights will be granted based on the user's government security
classification. Which access control model should be used?
A. Role-Based Access Control (RBAC)
B. Mandatory Access Control (MAC)
C. Attribute-Based Access Control (ABAC)
Answer: B. Mandatory Access Control (MAC) - MAC is standard for classified
environments. Access is based on system-enforced security labels (e.g., Top
Secret, Confidential), and users cannot change these controls.
3. A security team notices traffic coming from a country where the organization
does not have any business operations. Which of the following could this be an
indicator of?
A. High call volume
B. Odd network traffic
C. Geographic anomalies
D. Unauthorized changes
Answer: C. Geographic anomalies - Traffic from unexpected geographic locations
is a geographic anomaly that may indicate a security threat.
, 4. A cybersecurity analyst at a software company conducted a vulnerability
assessment and discovered multiple vulnerabilities on the company's webpage.
The CISO decided not to fix the discrepancies due to the vulnerabilities being
outside of the organization's resources. Which risk mitigation strategy is
demonstrated?
A. Accept
B. Mitigate
C. Avoid
D. Transfer
Answer: A. Accept - Risk acceptance acknowledges a risk but takes no action,
often because the cost of mitigation is not justified.
5. Which solution will notify the security team automatically in the event of
future malware variants invading the network?
A. Security information and event management (SIEM) alerts
B. Data loss prevention (DLP) alerts
C. Antivirus alerts
D. Syslog alerts
Answer: C. Antivirus alerts - Antivirus solutions are specifically designed to detect
and alert on malware infections.
6. What is the primary purpose of a Security Information and Event
Management (SIEM) system?
A. Block malware
B. Aggregate and analyze logs
C. Encrypt traffic
D. Manage user credentials
Answer: B. Aggregate and analyze logs - A SIEM collects, normalizes, correlates,
and analyzes security event data from multiple sources, providing centralized
monitoring and alerting.
7. A security architect is designing a strategy to help continue operating in the
face of a cyber-attack. Which of the following will help accomplish this
objective?
A. Heterogeneity
B. Clustering