ACCOUNTABILITY | 2026 UPDATE
WITH COMPLETE SOLUTIONS.
PRENIUM EXAM
150 Questions with Answers and Detailed Rationales
100 PERCENT GUARANTEED PASS
INSTANT DOWNLOAD ANSWERS INCLUDED
IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
WGU D259 YCM2 TASK 3 - ACCOUNTABILITY | 2026 UPDATE WITH COMPLETE SOLUTIONS.. It contains
150 carefully selected questions that reflect the most current exam content and testing strategies. Each question
is accompanied by a correct answer and a detailed rationale that explains the underlying pathophysiology,
pharmacology, or clinical reasoning.
Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas
Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions
Review Summary 150 Questions
Foundations - Application - WGU D259 YCM2 TASK 3 Accountability 2026 Update WITH Complete
Solutions Cybersecurity AND Information Assurance Graduate
All answers with rationales
,Table of Contents
Content Area Questions Key Topics
Accountability AND 1-25 Accountability, Framework, Context, Security, Mechanism
Responsibility IN Nursing
Legal AND Ethical Issues IN 26-50 Accountability, Context, Framework, Public, Approach
Nursing
Quality Improvement AND 51-75 Accountability, Organization, Context, Governance, Effectively
Patient Safety
Evidence-based AND 76-100 Accountability, Framework, Security, Cloud, Organization S
Research
Leadership AND 101-125 Accountability, Rehabilitation, Cybersecurity, Context, Model
Management IN Nursing
Healthcare Policy AND 126-150 Accountability, Principle, Controller, Security, Ensure
Advocacy
TOTAL 150 All questions include answers and detailed rationales
,Section A - Accountability AND Responsibility IN Nursing
Q1.
In a zero-trust architecture, which mechanism most directly enforces accountability for
user actions across a dynamic network perimeter?
A. Continuous authentication and session B. Network segmentation based on static IP
monitoring addresses
C. Annual penetration testing and D. Centralized logging without real-time
vulnerability scanning analysis
Correct: A - Continuous authentication and session monitoring
Rationale:Continuous authentication and session monitoring provide real-time verification of
user identity and behavior, enabling accountability for actions in a zero-trust environment.
Network segmentation (B) is a design principle but does not directly track user actions.
Penetration testing (C) is periodic and not a continuous control. Centralized logging (D)
without real-time analysis does not enforce accountability proactively.
Q2.
A financial institution is adopting COBIT 2019 to enhance governance. Which component
is crucial for aligning IT objectives with enterprise goals and ensuring stakeholder
accountability?
A. The capability maturity model for B. The balanced scorecard for IT
processes performance
C. The goals cascade from stakeholder D. The IT balanced business scorecard
needs to IT goals
Correct: C - The goals cascade from stakeholder needs to IT goals
Rationale:The goals cascade in COBIT 2019 translates stakeholder needs into enterprise
goals, IT goals, and enabling processes, ensuring alignment and accountability. Capability
maturity (A) assesses process capability but not alignment. Balanced scorecards (B, D) are
performance measurement tools, not alignment mechanisms.
Q3.
When evaluating a cloud service provider's accountability under the shared responsibility
model, which of the following is the customer's primary responsibility?
A. Physical security of data center facilities B. Patch management of the hypervisor
C. Classification and protection of data D. Management of the cloud infrastructure's
assets network components
Page 3
, Section A - Accountability AND Responsibility IN Nursing
Correct: C - Classification and protection of data assets
Rationale:Under the shared responsibility model, the customer is accountable for data
classification, access management, and protecting data within the cloud. Physical security
(A), hypervisor patching (B), and network infrastructure management (D) are typically the
provider's responsibilities.
Q4.
In the NIST Risk Management Framework (RMF), which step formally assigns
responsibility for system security and establishes accountability?
A. Step 1: Categorize Information System B. Step 2: Select Security Controls
C. Step 3: Implement Security Controls D. Step 6: Monitor Security Controls
Correct: A - Step 1: Categorize Information System
Rationale:Step 1 (Categorize) identifies the system's impact level and triggers the
authorization process, which includes assigning responsibility to the Authorizing Official.
While monitoring (D) ensures ongoing accountability, initial assignment occurs during
categorization. Selecting (B) and implementing (C) controls follow after responsibilities are
established.
Q5.
A security analyst discovers that a contractor's access credentials were used to exfiltrate
sensitive data. The organization's accountability policy requires least privilege. Which
control failure most likely enabled this incident?
A. Lack of mandatory annual security B. Inadequate user access reviews and
awareness training timely revocation
C. Absence of a data loss prevention (DLP) D. Weak encryption standards for data at
system rest
Correct: B - Inadequate user access reviews and timely revocation
Rationale:Inadequate access reviews and revocation allow excessive privileges to persist,
violating least privilege and enabling misuse. Training (A) is important but not the direct
control failure. DLP (C) might detect but not prevent the exfiltration if access is legitimate.
Encryption (D) does not address access control.
Q6.
Under the GDPR, which principle requires that personal data be processed in a manner
that ensures appropriate security, including protection against unauthorized or unlawful
processing?
Page 4