1
WGU D489 CYBERSECURITY MANAGEMENT WESTERN
GOVERNORS UNIVERSITY ACADEMIC YEAR 2026-2027
FULL PACKAGE QUESTIONS ANSWERS AND RATIONALES
INSTANT DOWNLOAD PDF..!!
The WGU D489 Cybersecurity Management Objective Assessment is a rigorous, competency-based
evaluation designed for students pursuing careers in cybersecurity leadership and management. This
course focuses on the strategic and managerial aspects of cybersecurity, emphasizing governance,
risk management, compliance, and the development of comprehensive security programs that align
with organizational objectives. The assessment is critical because it validates a candidate's ability to
think like a security leader—not just a technician—by applying frameworks such as NIST, ISO/IEC
27001, and the NICE Cybersecurity Workforce Framework to real-world scenarios. The exam format
consists of scenario-based multiple-choice questions covering six core competencies: cybersecurity
governance and strategy, risk management, security policy development, legal and regulatory
compliance, incident response and business continuity, and security program management. This
question bank has been meticulously crafted to simulate the advanced, application-level difficulty of
the actual assessment. By working through these 200 scenario-driven questions, you will develop the
critical reasoning and strategic decision-making skills needed to pass on your first attempt.
CORE DOMAINS TESTED
1. Cybersecurity Governance and Strategy – Governance frameworks, board-level oversight,
risk appetite, strategic alignment, security culture, and the distinction between governance
and management.
2. Risk Management – Risk assessment methodologies (qualitative and quantitative), risk
treatment strategies, business impact analysis (BIA), gap analysis, and risk register
management.
3. Security Policy, Standards, Procedures, and Guidelines – Hierarchical policy development,
security awareness training, acceptable use policies, and the NICE Cybersecurity Workforce
Framework for role definition.
4. Legal, Regulatory, and Compliance Landscape – GDPR, HIPAA, PCI DSS, SOX, state breach
notification laws, data classification, privacy requirements, and third-party vendor
compliance.
5. Incident Response, Business Continuity, and Disaster Recovery – Incident response lifecycle,
business continuity planning (BCP), disaster recovery (DR), tabletop exercises, and post-
incident review.
,2
6. Security Program Management and Operations – Security metrics and KPIs, Zero Trust
architecture, defense in depth, SIEM, vulnerability management, and third-party risk
management.
,3
QUESTIONS 1-200
Q1: A newly appointed Chief Information Security Officer (CISO) is
developing a strategic cybersecurity plan. The organization's board of
directors has expressed concern that previous security initiatives
were not aligned with business goals. Which framework should the
CISO use as the foundation for aligning cybersecurity strategy with
business objectives?
A) The OSI model
B) The NIST Cybersecurity Framework (CSF)
C) The TCP/IP protocol suite
D) A vendor-specific security product roadmap
Rationale: The correct answer is B because the NIST CSF provides a
common language for understanding and managing cybersecurity
risk, organized around five core functions (Identify, Protect, Detect,
Respond, Recover) that align with business objectives. Option A is
incorrect because the OSI model is a technical networking reference,
not a strategic management framework. Option C is incorrect
because TCP/IP is a technical protocol suite, not a governance
framework. Option D is incorrect because vendor roadmaps are
product-specific and do not provide a business-aligned strategic
foundation.
Q2: A Board of Directors is reviewing the organization's cybersecurity
posture. The board's primary responsibility in cybersecurity is:
A) Configuring firewall rules
B) Approving the risk appetite and providing strategic oversight
C) Conducting daily vulnerability scans
D) Managing the security operations center (SOC)
Rationale: The correct answer is B because the board's role is
, 4
fiduciary oversight—setting the risk appetite and ensuring
management implements appropriate controls. Option A is incorrect
because firewall configuration is a technical, management-level task.
Option C is incorrect because vulnerability scanning is an operational
activity. Option D is incorrect because SOC management is an
operational responsibility delegated to management.
Q3: An organization has experienced a data breach involving
customer personally identifiable information (PII). The legal team is
determining which regulatory requirements apply. The organization
operates primarily in California. Which regulation is most relevant?
A) HIPAA
B) CCPA (California Consumer Privacy Act)
C) SOX
D) FISMA
Rationale: The correct answer is B because CCPA governs the privacy
rights of California residents and imposes requirements on businesses
handling their personal information. Option A is incorrect because
HIPAA applies to protected health information. Option C is incorrect
because SOX applies to financial reporting and corporate governance.
Option D is incorrect because FISMA applies to federal information
systems.
Q4: A security manager is conducting a risk assessment. The team
has identified a vulnerability that could result in a $500,000 loss with
a 10% probability of occurrence in any given year. What is the
Annualized Loss Expectancy (ALE)?
A) $5,000
B) *$50,000**
C) $500,000
D) $5,000,000
*Rationale: The correct answer is B because ALE = Single Loss
WGU D489 CYBERSECURITY MANAGEMENT WESTERN
GOVERNORS UNIVERSITY ACADEMIC YEAR 2026-2027
FULL PACKAGE QUESTIONS ANSWERS AND RATIONALES
INSTANT DOWNLOAD PDF..!!
The WGU D489 Cybersecurity Management Objective Assessment is a rigorous, competency-based
evaluation designed for students pursuing careers in cybersecurity leadership and management. This
course focuses on the strategic and managerial aspects of cybersecurity, emphasizing governance,
risk management, compliance, and the development of comprehensive security programs that align
with organizational objectives. The assessment is critical because it validates a candidate's ability to
think like a security leader—not just a technician—by applying frameworks such as NIST, ISO/IEC
27001, and the NICE Cybersecurity Workforce Framework to real-world scenarios. The exam format
consists of scenario-based multiple-choice questions covering six core competencies: cybersecurity
governance and strategy, risk management, security policy development, legal and regulatory
compliance, incident response and business continuity, and security program management. This
question bank has been meticulously crafted to simulate the advanced, application-level difficulty of
the actual assessment. By working through these 200 scenario-driven questions, you will develop the
critical reasoning and strategic decision-making skills needed to pass on your first attempt.
CORE DOMAINS TESTED
1. Cybersecurity Governance and Strategy – Governance frameworks, board-level oversight,
risk appetite, strategic alignment, security culture, and the distinction between governance
and management.
2. Risk Management – Risk assessment methodologies (qualitative and quantitative), risk
treatment strategies, business impact analysis (BIA), gap analysis, and risk register
management.
3. Security Policy, Standards, Procedures, and Guidelines – Hierarchical policy development,
security awareness training, acceptable use policies, and the NICE Cybersecurity Workforce
Framework for role definition.
4. Legal, Regulatory, and Compliance Landscape – GDPR, HIPAA, PCI DSS, SOX, state breach
notification laws, data classification, privacy requirements, and third-party vendor
compliance.
5. Incident Response, Business Continuity, and Disaster Recovery – Incident response lifecycle,
business continuity planning (BCP), disaster recovery (DR), tabletop exercises, and post-
incident review.
,2
6. Security Program Management and Operations – Security metrics and KPIs, Zero Trust
architecture, defense in depth, SIEM, vulnerability management, and third-party risk
management.
,3
QUESTIONS 1-200
Q1: A newly appointed Chief Information Security Officer (CISO) is
developing a strategic cybersecurity plan. The organization's board of
directors has expressed concern that previous security initiatives
were not aligned with business goals. Which framework should the
CISO use as the foundation for aligning cybersecurity strategy with
business objectives?
A) The OSI model
B) The NIST Cybersecurity Framework (CSF)
C) The TCP/IP protocol suite
D) A vendor-specific security product roadmap
Rationale: The correct answer is B because the NIST CSF provides a
common language for understanding and managing cybersecurity
risk, organized around five core functions (Identify, Protect, Detect,
Respond, Recover) that align with business objectives. Option A is
incorrect because the OSI model is a technical networking reference,
not a strategic management framework. Option C is incorrect
because TCP/IP is a technical protocol suite, not a governance
framework. Option D is incorrect because vendor roadmaps are
product-specific and do not provide a business-aligned strategic
foundation.
Q2: A Board of Directors is reviewing the organization's cybersecurity
posture. The board's primary responsibility in cybersecurity is:
A) Configuring firewall rules
B) Approving the risk appetite and providing strategic oversight
C) Conducting daily vulnerability scans
D) Managing the security operations center (SOC)
Rationale: The correct answer is B because the board's role is
, 4
fiduciary oversight—setting the risk appetite and ensuring
management implements appropriate controls. Option A is incorrect
because firewall configuration is a technical, management-level task.
Option C is incorrect because vulnerability scanning is an operational
activity. Option D is incorrect because SOC management is an
operational responsibility delegated to management.
Q3: An organization has experienced a data breach involving
customer personally identifiable information (PII). The legal team is
determining which regulatory requirements apply. The organization
operates primarily in California. Which regulation is most relevant?
A) HIPAA
B) CCPA (California Consumer Privacy Act)
C) SOX
D) FISMA
Rationale: The correct answer is B because CCPA governs the privacy
rights of California residents and imposes requirements on businesses
handling their personal information. Option A is incorrect because
HIPAA applies to protected health information. Option C is incorrect
because SOX applies to financial reporting and corporate governance.
Option D is incorrect because FISMA applies to federal information
systems.
Q4: A security manager is conducting a risk assessment. The team
has identified a vulnerability that could result in a $500,000 loss with
a 10% probability of occurrence in any given year. What is the
Annualized Loss Expectancy (ALE)?
A) $5,000
B) *$50,000**
C) $500,000
D) $5,000,000
*Rationale: The correct answer is B because ALE = Single Loss