WGU D488 FINAL EXAM TEST BANK 2026/2027
Cybersecurity WITH MULTIPLE CHOICES ,CORRECT
ANSWERS WELL VERIFIED AND IN DEPTH RATIONALES.
SECTION 1: SECURITY ARCHITECTURE FUNDAMENTALS (Questions 1-25)
Question 1
Which of the following best describes the primary purpose of a security architecture
framework?
A) To provide a checklist of security controls
B) To establish a structured approach to designing, implementing, and managing
security controls
C) To replace all existing security measures
D) To focus exclusively on network security
CORRECT ANSWER: B
Rationale: Security architecture frameworks provide structured methodologies for
designing and implementing security controls across an organization. They offer
systematic approaches rather than simple checklists (A), don't replace existing
measures (C), and encompass far more than just network security (D).
Question 2
In the context of security architecture, what is meant by "defense in depth"?
A) Using a single, powerful security solution
B) Implementing multiple layers of security controls
C) Focusing only on perimeter security
,D) Relying solely on encryption
CORRECT ANSWER: B
Rationale: Defense in depth is a strategy that employs multiple layers of security controls
throughout an information system. If one layer fails, others continue to provide
protection. Option A describes a single point of failure approach, C ignores internal
controls, and D focuses only on one control type.
Question 3
Which security principle requires that users should only have the minimum levels of
access necessary to perform their job functions?
A) Separation of duties
B) Need-to-know
C) Least privilege
D) Defense in depth
CORRECT ANSWER: C
Rationale: The principle of least privilege mandates that users, processes, and systems
be granted only the minimum necessary permissions. Separation of duties (A) divides
responsibilities, need-to-know (B) is similar but specifically about information access,
and defense in depth (D) is about layered security.
Question 4
What is the primary purpose of a Security Operations Center (SOC)?
A) To develop new security software
B) To continuously monitor and respond to security incidents
C) To manage physical security only
,D) To conduct penetration testing
CORRECT ANSWER: B
Rationale: A SOC is a centralized unit that deals with security issues on an organizational
and technical level, including continuous monitoring, detection, analysis, and response
to cybersecurity incidents. Development (A), physical security only (C), and penetration
testing (D) are not primary SOC functions.
Question 5
Which framework provides a common language for describing security incidents and
exchanging information?
A) ISO 27001
B) NIST SP 800-53
C) STIX/TAXII
D) COBIT
CORRECT ANSWER: C
Rationale: STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated
eXchange of Intelligence Information) provide standardized languages and protocols
for sharing threat intelligence. ISO 27001 (A) is an information security management
standard, NIST SP 800-53 (B) is a security controls catalog, and COBIT (D) is an IT
governance framework.
Question 6
What is the primary difference between a vulnerability and an exploit?
A) A vulnerability is a weakness, while an exploit is the code that takes advantage of it
B) They are the same thing
, C) An exploit is a weakness, while a vulnerability is the code that takes advantage of it
D) Both refer to malware only
CORRECT ANSWER: A
Rationale: A vulnerability is a flaw or weakness in a system that could be exploited,
while an exploit is the actual code or technique used to take advantage of that
vulnerability. They are distinct concepts (B is incorrect), and they are not limited to
malware (D).
Question 7
Which security control type is designed to deter, prevent, or stop an attack?
A) Detective control
B) Preventive control
C) Corrective control
D) Compensating control
CORRECT ANSWER: B
Rationale: Preventive controls are designed to stop security incidents before they
occur. Detective controls (A) identify incidents after they happen, corrective controls
(C) restore systems after incidents, and compensating controls (D) provide alternative
protection when primary controls aren't feasible.
Question 8
What is the purpose of a security baseline?
A) To define the absolute minimum security configuration for a system
B) To outline the maximum security configuration
C) To replace all existing security policies
Cybersecurity WITH MULTIPLE CHOICES ,CORRECT
ANSWERS WELL VERIFIED AND IN DEPTH RATIONALES.
SECTION 1: SECURITY ARCHITECTURE FUNDAMENTALS (Questions 1-25)
Question 1
Which of the following best describes the primary purpose of a security architecture
framework?
A) To provide a checklist of security controls
B) To establish a structured approach to designing, implementing, and managing
security controls
C) To replace all existing security measures
D) To focus exclusively on network security
CORRECT ANSWER: B
Rationale: Security architecture frameworks provide structured methodologies for
designing and implementing security controls across an organization. They offer
systematic approaches rather than simple checklists (A), don't replace existing
measures (C), and encompass far more than just network security (D).
Question 2
In the context of security architecture, what is meant by "defense in depth"?
A) Using a single, powerful security solution
B) Implementing multiple layers of security controls
C) Focusing only on perimeter security
,D) Relying solely on encryption
CORRECT ANSWER: B
Rationale: Defense in depth is a strategy that employs multiple layers of security controls
throughout an information system. If one layer fails, others continue to provide
protection. Option A describes a single point of failure approach, C ignores internal
controls, and D focuses only on one control type.
Question 3
Which security principle requires that users should only have the minimum levels of
access necessary to perform their job functions?
A) Separation of duties
B) Need-to-know
C) Least privilege
D) Defense in depth
CORRECT ANSWER: C
Rationale: The principle of least privilege mandates that users, processes, and systems
be granted only the minimum necessary permissions. Separation of duties (A) divides
responsibilities, need-to-know (B) is similar but specifically about information access,
and defense in depth (D) is about layered security.
Question 4
What is the primary purpose of a Security Operations Center (SOC)?
A) To develop new security software
B) To continuously monitor and respond to security incidents
C) To manage physical security only
,D) To conduct penetration testing
CORRECT ANSWER: B
Rationale: A SOC is a centralized unit that deals with security issues on an organizational
and technical level, including continuous monitoring, detection, analysis, and response
to cybersecurity incidents. Development (A), physical security only (C), and penetration
testing (D) are not primary SOC functions.
Question 5
Which framework provides a common language for describing security incidents and
exchanging information?
A) ISO 27001
B) NIST SP 800-53
C) STIX/TAXII
D) COBIT
CORRECT ANSWER: C
Rationale: STIX (Structured Threat Information eXpression) and TAXII (Trusted Automated
eXchange of Intelligence Information) provide standardized languages and protocols
for sharing threat intelligence. ISO 27001 (A) is an information security management
standard, NIST SP 800-53 (B) is a security controls catalog, and COBIT (D) is an IT
governance framework.
Question 6
What is the primary difference between a vulnerability and an exploit?
A) A vulnerability is a weakness, while an exploit is the code that takes advantage of it
B) They are the same thing
, C) An exploit is a weakness, while a vulnerability is the code that takes advantage of it
D) Both refer to malware only
CORRECT ANSWER: A
Rationale: A vulnerability is a flaw or weakness in a system that could be exploited,
while an exploit is the actual code or technique used to take advantage of that
vulnerability. They are distinct concepts (B is incorrect), and they are not limited to
malware (D).
Question 7
Which security control type is designed to deter, prevent, or stop an attack?
A) Detective control
B) Preventive control
C) Corrective control
D) Compensating control
CORRECT ANSWER: B
Rationale: Preventive controls are designed to stop security incidents before they
occur. Detective controls (A) identify incidents after they happen, corrective controls
(C) restore systems after incidents, and compensating controls (D) provide alternative
protection when primary controls aren't feasible.
Question 8
What is the purpose of a security baseline?
A) To define the absolute minimum security configuration for a system
B) To outline the maximum security configuration
C) To replace all existing security policies