New WGU D488 Objective Assessment 2026
Test Bank 2
Cybersecurity Architecture and Engineering
Real Exam Questions with Correct Answers and Rationales
Aligned with 2026 WGU D488 Curriculum and Industry Cybersecurity Standards
Total Questions Sections Cognitive Levels Aligned Standards
80 8 Recall / Application / Analysis CISSP, CCSP, CISM, Security+
-1-
,WGU D488 Cybersecurity Architecture and Engineering Exam 2026 Page 2
Table of Contents
Section 1: Enterprise Security Architecture and Frameworks (Q1-Q14) 3
Section 2: Network Security Architecture (Q15-Q26) 6
Section 3: Identity and Access Management (Q27-Q36) 9
Section 4: Cloud Security Architecture and Virtualization (Q37-Q46) 11
Section 5: Application Security and DevSecOps (Q47-Q54) 14
Section 6: Data Security and Cryptography (Q55-Q62) 16
Section 7: Security Operations, Monitoring, and Incident Response (Q63-Q72) 18
Section 8: Risk Management, Business Continuity, and Compliance (Q73-Q80) 21
-2-
, WGU D488 Cybersecurity Architecture and Engineering Exam 2026 Page 3
Section 1: Enterprise Security Architecture and Frameworks (Q1-Q14)
Q1: A financial services company is redesigning its security program and needs a framework that integrates
governance, risk management, and compliance into a single lexicon. The CISO wants a framework aligned with
enterprise IT goals rather than purely security-focused objectives. Which framework best fits this requirement?
A. NIST Cybersecurity Framework v2.0
B. ISO/IEC 27001:2022
C. COBIT 2019 [CORRECT]
D. SABSA
Correct Answer: C
Rationale: COBIT 2019 is a governance and management framework designed to bridge business goals with IT objectives, making it
ideal for integrating governance, risk, and compliance across the enterprise. Unlike NIST CSF which is primarily security-focused,
COBIT provides a holistic approach to IT governance. ISO 27001 is an information security management standard focused on
establishing ISMS controls. SABSA is an enterprise security architecture framework, not a governance framework.
Q2: Under NIST CSF v2.0, which function was added as a core function that was not present in v1.1, reflecting the
increasing emphasis on governance over security programs?
A. Identify
B. Govern [CORRECT]
C. Recover
D. Protect
Correct Answer: B
Rationale: NIST CSF v2.0 introduced the Govern function as a foundational pillar, elevating governance to the same level as the
original five functions. The Govern function establishes and monitors organizational context, risk management strategy,
expectations, and policy. The Identify, Protect, Detect, Respond, and Recover functions all existed in v1.1 and remain in v2.0.
Q3: An organization implementing ISO/IEC 27001:2022 must demonstrate continual improvement of its ISMS.
Which clause in the 2022 revision places the strongest emphasis on leadership accountability for the security
management system?
A. Clause 4 - Context of the organization
B. Clause 5 - Leadership [CORRECT]
C. Clause 7 - Support
D. Clause 9 - Performance evaluation
Correct Answer: B
Rationale: Clause 5 of ISO/IEC 27001:2022 requires top management to demonstrate leadership and commitment by establishing
an information security policy, ensuring objectives are set, and integrating the ISMS into organizational processes. This clause was
strengthened in the 2022 revision to explicitly hold leadership accountable. Clause 4 addresses context, Clause 7 covers support
resources, and Clause 9 deals with monitoring and measurement.
Q4: A security architect is using the SABSA framework to develop a security architecture. At which lifecycle stage
would the architect define the business attributes, ownership, and risk appetite associated with business assets?
A. Conceptual Architecture layer [CORRECT]
B. Logical Architecture layer
C. Physical Architecture layer
D. Component Architecture layer
Correct Answer: A
Rationale: The SABSA Conceptual Architecture layer maps business requirements to security services, defining business attributes,
ownership, and risk appetite. This layer answers the question of what the business needs from a security perspective. The Logical
layer defines security services and mechanisms, the Physical layer maps logical designs to technology, and the Component layer
specifies vendor products and configurations.
Q5: An enterprise wants to eliminate the concept of a trusted internal network. The CISO mandates that every
access request must be continuously validated regardless of network location. Which principle from NIST SP
-3-