WGU D486 – DFN1 TASK 1 COMPREHENSIVE GRC PRACTICE
QUESTIONS WITH RADICAL RATIONALES
IT Governance, Risk & Compliance Management / Cybersecurity Frameworks
Exam coverage:
I. Section 1 (Q1-25): IT Governance fundamentals – GRC
disciplines, COBIT, ISO 27001, NIST 800-53, CIA triad,
segregation of duties.
II. Section 2 (Q26-50): Regulatory compliance – FISMA, HIPAA
(Privacy/Security Rules, Minimum Necessary), SOX Sections
302/404, PCI DSS, CISA, Red Flag Rules.
III. Section 3 (Q51-70): Risk management – risk treatment (avoid,
accept, transfer, mitigate), inherent vs. residual risk,
qualitative/quantitative assessment, BIA.
IV. Section 4 (Q71-90): Fielder Medical Center case study – six
gaps (antivirus, EPP, MFA, PCI DSS, government access, PII),
outdated SSP, remediation.
V. Section 5 (Q91-100): ServiceNow GRC architecture –
Authority Documents, Citations, Control Objectives, Entities,
UCF integration.
QUESTION 1
What is the primary purpose of IT governance?
, Page 2 of 55
A) To ensure IT investments and activities align with
organizational goals, deliver business value, manage risks, and
comply with legal and regulatory requirements
B) To maximize the organization's IT budget through cost-cutting
measures
C) To implement the latest cybersecurity technologies without
considering business impact
D) To outsource all IT decision-making to external consultants
CORRECT: A) To ensure IT investments and activities align
with organizational goals, deliver business value, manage
risks, and comply with legal and regulatory requirements ✔️
RATIONALE: IT governance ensures that IT investments and
activities align with organizational goals, deliver business value,
manage risks, and comply with legal and regulatory
requirements. This is the foundational principle of GRC,
establishing that IT must serve the broader business strategy
rather than operating independently .
QUESTION 2
Which framework is primarily used for IT governance?
A) ISO 9001
B) COBIT
C) Scrum
D) Six Sigma
CORRECT: B) COBIT ✔️
RATIONALE: COBIT (Control Objectives for Information and
Related Technologies) provides comprehensive guidance for
, Page 3 of 55
governing and managing enterprise IT. It is the most widely
recognized framework specifically designed for IT governance,
whereas ISO 9001 addresses quality management, Scrum is for
Agile project management, and Six Sigma focuses on process
improvement .
QUESTION 3
What is risk management?
A) A one-time project that eliminates all organizational risks
B) The continuous process of identifying, assessing, prioritizing,
treating, monitoring, and communicating risks that may impact
organizational objectives
C) A compliance requirement that applies only to financial
institutions
D) A function that is solely the responsibility of the IT
department
CORRECT: B) The continuous process of identifying,
assessing, prioritizing, treating, monitoring, and
communicating risks that may impact organizational
objectives ✔️
RATIONALE: Risk management is the continuous process of
identifying, assessing, prioritizing, treating, monitoring, and
communicating risks that may impact organizational objectives.
This is an ongoing cycle, not a one-time activity, and applies
across the entire organization .
QUESTION 4
As a discipline of GRC, what does Governance mean?
, Page 4 of 55
A) The process of determining where the organization is most
vulnerable or has the greatest exposure
B) The policies and oversight needed to ensure consistent
sustainability of goals
C) Implementing and managing the governance structure set
forth by executive leadership
D) An internal or external consultancy process aiming to prove
the effectiveness of controls
CORRECT: B) The policies and oversight needed to ensure
consistent sustainability of goals ✔️
RATIONALE: Governance refers to the policies and oversight
needed to ensure consistent sustainability of goals. This
involves establishing the framework within which the
organization operates, ensuring alignment between strategic
objectives and day-to-day operations .
QUESTION 5
As a discipline of GRC, what does Risk Management mean?
A) The policies and oversight needed to ensure consistent
sustainability of goals
B) Implementing and managing the governance structure set
forth by executive leadership
C) The process of determining where the organization is most
vulnerable or has the greatest exposure
D) An internal or external consultancy process aiming to prove
the effectiveness of controls
CORRECT: C) The process of determining where the