1|Page
WGU D488 FINAL EXAM TEST BANK (LATEST UPDATE
) CYBERSECURITY ARCHITECTURE AND
ENGINEERING | QUESTIONS AND ANSWERS | GRADE A |
100% CORRECT (VERIFIED SOLUTIONS)
1. An enterprise is redesigning its security architecture and wants
security controls to be integrated across business processes,
applications, networks, data, and infrastructure rather than
implemented as isolated technologies. Which approach BEST supports
this objective?
A. Enterprise security architecture
B. Point-to-point security
C. Perimeter-only security
D. Application-only security
Answer: A
2. A security architect is evaluating an organization's ability to identify,
protect, detect, respond to, and recover from cybersecurity threats.
Which framework is MOST appropriate for organizing these
cybersecurity capabilities?
A. NIST Cybersecurity Framework
,2|Page
B. OSI model
C. TCP/IP model
D. RAID framework
Answer: A
3. An organization assumes that no user, device, application, or network
connection should automatically be trusted merely because it is located
inside the corporate network. Which architectural approach is being
applied?
A. Zero Trust
B. Perimeter trust
C. Implicit trust
D. Flat-network architecture
Answer: A
4. Which principle is MOST central to a Zero Trust architecture?
A. Trust internal network traffic by default
B. Verify explicitly and continuously evaluate access based on context
C. Give authenticated users unrestricted access
,3|Page
D. Treat physical location as sufficient proof of trust
Answer: B
5. A security architect limits an administrator's permissions to only the
systems and functions required to perform assigned duties. Which
principle is being applied?
A. Least privilege
B. Open access
C. Maximum availability
D. Implicit trust
Answer: A
6. An organization requires two different employees to approve a highly
sensitive financial transaction before it can be completed. Which
principle is BEST demonstrated?
A. Separation of duties
B. Single sign-on
C. Data masking
D. Network address translation
, 4|Page
Answer: A
7. A company wants multiple security mechanisms to protect a critical
application so that failure of one control does not expose the entire
system. Which strategy is MOST appropriate?
A. Defense in depth
B. Single-layer security
C. Security through obscurity
D. Centralized trust
Answer: A
8. A public-facing web application is separated from internal database
systems by placing it within a controlled network segment. What
architecture is being used?
A. Demilitarized zone
B. Flat network
C. Peer-to-peer network
D. Storage area network
WGU D488 FINAL EXAM TEST BANK (LATEST UPDATE
) CYBERSECURITY ARCHITECTURE AND
ENGINEERING | QUESTIONS AND ANSWERS | GRADE A |
100% CORRECT (VERIFIED SOLUTIONS)
1. An enterprise is redesigning its security architecture and wants
security controls to be integrated across business processes,
applications, networks, data, and infrastructure rather than
implemented as isolated technologies. Which approach BEST supports
this objective?
A. Enterprise security architecture
B. Point-to-point security
C. Perimeter-only security
D. Application-only security
Answer: A
2. A security architect is evaluating an organization's ability to identify,
protect, detect, respond to, and recover from cybersecurity threats.
Which framework is MOST appropriate for organizing these
cybersecurity capabilities?
A. NIST Cybersecurity Framework
,2|Page
B. OSI model
C. TCP/IP model
D. RAID framework
Answer: A
3. An organization assumes that no user, device, application, or network
connection should automatically be trusted merely because it is located
inside the corporate network. Which architectural approach is being
applied?
A. Zero Trust
B. Perimeter trust
C. Implicit trust
D. Flat-network architecture
Answer: A
4. Which principle is MOST central to a Zero Trust architecture?
A. Trust internal network traffic by default
B. Verify explicitly and continuously evaluate access based on context
C. Give authenticated users unrestricted access
,3|Page
D. Treat physical location as sufficient proof of trust
Answer: B
5. A security architect limits an administrator's permissions to only the
systems and functions required to perform assigned duties. Which
principle is being applied?
A. Least privilege
B. Open access
C. Maximum availability
D. Implicit trust
Answer: A
6. An organization requires two different employees to approve a highly
sensitive financial transaction before it can be completed. Which
principle is BEST demonstrated?
A. Separation of duties
B. Single sign-on
C. Data masking
D. Network address translation
, 4|Page
Answer: A
7. A company wants multiple security mechanisms to protect a critical
application so that failure of one control does not expose the entire
system. Which strategy is MOST appropriate?
A. Defense in depth
B. Single-layer security
C. Security through obscurity
D. Centralized trust
Answer: A
8. A public-facing web application is separated from internal database
systems by placing it within a controlled network segment. What
architecture is being used?
A. Demilitarized zone
B. Flat network
C. Peer-to-peer network
D. Storage area network