WGU D488 Cybersecurity Architecture and
Engineering Final Comprehensive Examination
2026/2027 | Verified Questions
Western Governors University | D488 Cybersecurity Architecture and Engineering | University-Level
Cybersecurity Students
100 Verified Questions | 4 Core Domains | Academic Year 2026/2027
Prepared by
Western Governors University | D488 Cybersecurity Architecture and Engineering
Final Comprehensive Examination Actual Exam | Academic Year 2026/2027
WGU D488 Cybersecurity Architecture and Engineering Final Comprehensive Examination 2026/2027 | Verified Questions
,INTRODUCTION
This comprehensive examination contains 100 verified questions designed to reinforce the official
Western Governors University D488 Cybersecurity Architecture and Engineering course objectives for the
Final Comprehensive Examination. The questions are organized across four core domains: Security
Architecture and Engineering; Enterprise Security Operations; Governance, Risk, and Compliance (GRC);
and Cryptography and Advanced Authentication. Content is original and aligned to the 2026/2027
academic year, emphasizing architectural and operational reasoning and foundational cybersecurity
knowledge required for actual exam readiness and professional proficiency.
ACTUAL QUESTIONS
Domain 1: Security Architecture and Engineering
Question 1. Which security principle requires that a user or process is granted only the
privileges necessary to perform its authorized tasks?
A. Least privilege
B. Defense in depth
C. Separation of duties
D. Security through obscurity
Correct Answer: A
Rationale: The principle of least privilege limits access rights to the minimum necessary for users or
processes to complete their assigned functions.
Question 2. What is the primary purpose of a demilitarized zone (DMZ) in network
architecture?
A. To store all internal databases
B. To replace the need for firewalls
C. To host publicly accessible services while isolating them from the internal network
D. To provide unrestricted access between networks
Correct Answer: C
Rationale: A DMZ provides a controlled buffer zone for external-facing services, limiting exposure of the
internal network.
Question 3. Which architectural model separates the presentation, application logic, and
data layers?
A. Monolithic architecture exclusively
B. Single-layer design
C. Peer-to-peer only
D. N-tier or multi-tier architecture
Correct Answer: D
Rationale: Multi-tier architecture isolates presentation, business logic, and data storage to improve
security, scalability, and maintainability.
Question 4. What is the primary goal of defense in depth?
A. Relying on a single strong control
B. Implementing multiple layers of security controls so that failure of one does not compromise the
entire system
C. Eliminating all monitoring
D. Using only perimeter defenses
Correct Answer: B
WGU D488 Cybersecurity Architecture and Engineering Final Comprehensive Examination 2026/2027 | Verified Questions
, Rationale: Defense in depth uses overlapping controls across people, process, and technology to reduce
the likelihood of a successful attack.
Question 5. Which design principle states that the absence of a security decision should
result in a secure state?
A. Fail-open
B. Security through obscurity
C. Fail-secure or fail-safe
D. Complete mediation exclusively
Correct Answer: C
Rationale: Fail-secure design ensures that when a system fails, it defaults to a state that denies access
rather than allowing it.
Question 6. What is the primary function of a security information and event management
(SIEM) system in an architecture?
A. Replacing all firewalls
B. Providing end-user authentication exclusively
C. Storing only backup data
D. Aggregating, correlating, and analyzing security logs and events from multiple sources
Correct Answer: D
Rationale: SIEM platforms centralize log collection and apply correlation rules to detect and alert on
security incidents.
Question 7. Which network segmentation approach isolates systems with similar security
requirements?
A. Security zones or enclaves
B. Flat network design
C. Unrestricted inter-VLAN routing
D. Single broadcast domain only
Correct Answer: A
Rationale: Security zoning groups assets by sensitivity and function, applying consistent controls at
zone boundaries.
Question 8. What is the primary purpose of a jump host or bastion host?
A. To store sensitive data permanently
B. To provide a hardened, controlled entry point for administrative access to internal systems
C. To replace all user workstations
D. To host public web applications exclusively
Correct Answer: B
Rationale: Bastion or jump hosts are hardened systems used as the sole administrative gateway into
protected networks.
Question 9. Which principle requires that every access to every object be checked for
authorization?
A. Complete mediation
B. Least privilege only
C. Economy of mechanism
D. Open design
Correct Answer: A
Rationale: Complete mediation ensures that every access request is verified against the current
authorization policy.
WGU D488 Cybersecurity Architecture and Engineering Final Comprehensive Examination 2026/2027 | Verified Questions