2026/2027 WGU D488 Cybersecurity Architecture and Engineering Oa | Wgu D488
Objective Assessment 2026/2027 Test Bank With Actual Exam Questions And Correct
Answers | D488 OA Prep Test Bank
2026/2027 Official Exam
A+ 5 100%
QUESTIONS EXAM DOMAINS RATIONALES
VERIFIED COVERED INCLUDED
CATEGORIES
■ Section 1: Risk Management, Governance & Compliance (Q1–14)
■ Section 2: Secure Network & Infrastructure Architecture (Q15–28)
■ Section 3: Cloud, Virtualization & Enterprise Data Security (Q29–42)
■ Section 4: Threat Analysis, Vulnerability Management & Incident Response (Q43–56)
■ Section 5: Secure Application Integration, Architecture Patterns & Resilience (Q57–70)
STUVIAACTUALEXAM
Original practice content aligned to publicly described WGU D488 competencies and related cybersecurity architecture domains. Not an official WGU product.
, SECTION 1: RISK MANAGEMENT, GOVERNANCE & COMPLIANCE
Q1. A security architect is preparing a risk assessment for a new customer-facing portal. Leadership wants quantitative risk
figures. The architect calculates annualized loss expectancy (ALE) for a data-breach scenario. ALE is obtained by:
A. Adding the asset value to the exposure factor.
B. Dividing residual risk by inherent risk.
C. Subtracting the cost of controls from the asset value only.
D. Multiplying single-loss expectancy (SLE) by the annual rate of occurrence (ARO).
Correct Answer: D
Rationale: ALE = SLE × ARO. SLE itself is asset value × exposure factor. This quantitative method supports prioritization of controls.
Q2. An organization must decide whether to accept, mitigate, transfer, or avoid a residual risk after controls are applied. The
decision that leaves the risk unchanged and documents management’s willingness to live with it is:
A. Risk avoidance by shutting down the system.
B. Risk mitigation by adding more technical controls.
C. Risk acceptance.
D. Risk transfer through insurance only.
Correct Answer: C
Rationale: Acceptance is the formal decision to retain residual risk when further treatment is not cost-effective or practical.
Q3. A vendor risk assessment reveals that a critical SaaS provider has weak contractual security clauses and no right-to-audit
language. The most appropriate next architectural action is to:
A. Negotiate stronger contractual security requirements and continuous-assurance mechanisms before expanding reliance on the
vendor.
B. Ignore the findings because the vendor is already in production.
C. Rely solely on the vendor’s marketing brochure for assurance.
D. Immediately terminate all business with every SaaS provider.
Correct Answer: A
Rationale: Vendor risk is managed through contractual controls, SLAs, and assurance rights; weak language must be remediated.
Q4. Key risk indicators (KRIs) differ from key performance indicators (KPIs) in that KRIs primarily:
A. Replace the need for any risk assessment.
B. Are identical to KPIs in every governance framework.
C. Provide early warning of increasing risk exposure so that management can intervene before thresholds are breached.
D. Measure only operational efficiency of the help desk.
Correct Answer: C
Rationale: KRIs are forward-looking risk metrics; KPIs track performance against objectives.
Q5. A multinational firm must comply with both GDPR and CCPA for customer data. The architect’s recommended approach for
data-handling controls is to:
A. Store all data unencrypted to simplify audits.
B. Apply only the least-restrictive local law to all data.
C. Ignore one regulation because dual compliance is impossible.
D. Map overlapping and unique requirements and implement the more stringent control set where requirements conflict.
Correct Answer: D
Rationale: When multiple privacy regimes apply, organizations typically adopt the strictest applicable controls for the data in scope.
STUVIAACTUALEXAM | Page 2 of 14