• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 50 pages
Exam (elaborations)

WGU D490 CAPSTONE ACTUAL EXAM 2026/2027 | AI-Driven Cybersecurity | AIaaS, GRC & Ethical Design | Complete Solution | Pass Guaranteed - A+ Graded

Document preview thumbnail
Preview 4 out of 50 pages

Complete your WGU D490 Capstone with this comprehensive 2026/2027 solution guide for AI-Driven Cybersecurity. This A+ Graded resource contains the complete solution covering AIaaS integration, Governance Risk and Compliance (GRC), and ethical design principles. Key areas include AI security frameworks, risk assessment, regulatory compliance, ethical AI implementation, and capstone project documentation. Each section provides clear guidance to reinforce understanding and application. With our Pass Guarantee, you can complete your capstone confidently and pass on your first attempt. Download your complete WGU D490 Capstone solution instantly!

Content preview

WGU D490 Capstone: AI-Driven Cybersecurity | 2026/2027 Update with Complete Solution Integrating AIaaS, GRC, and Ethical Design




WGU D490 Capstone: AI-Driven Cybersecurity
Integrating AIaaS, GRC, and Ethical Design
2026/2027 Update with Complete Solution | 150 Verified Questions


Aligned with the 2026-2027 Western Governors University (WGU) D490 Cybersecurity Capstone competencies and
current AI cybersecurity standards including NIST AI RMF 1.0, NIST CSF 2.0, ISO 42001, EU AI Act, and emerging AI
governance regulations. Comprehensive coverage of AI-as-a-Service (AIaaS) architecture, GRC framework integration,
ethical/responsible AI design, AI-driven threat detection, Zero Trust with AI, AI risk management, and capstone
professional practice.


Cognitive Distribution: 25% Recall · 50% Application · 25% Analysis | Question Design: 75% Scenario-Based · 25% Direct
Recall

WGU D490 Capstone Integration: This 150-question comprehensive exam integrates all WGU D490 capstone competencies
across 8 sections. Section 1 covers AI fundamentals and cybersecurity integration (supervised/unsupervised/reinforcement
learning, neural networks, AI in security operations). Section 2 covers AIaaS architecture and deployment (cloud AI
platforms—AWS, Azure, Google Cloud, IBM; vendor selection criteria; integration models). Section 3 covers GRC frameworks
(NIST CSF 2.0, NIST AI RMF, ISO 27001, ISO 42001, SOC 2, GDPR, CCPA, HIPAA, PCI DSS, EU AI Act, COBIT, FAIR,
OCTAVE). Section 4 covers ethical design and responsible AI (bias, fairness, transparency, explainability, privacy-preserving
AI, human oversight, accountability). Section 5 covers AI-driven threat detection and response (anomaly detection, SOAR,
UEBA, automated incident response). Section 6 covers Zero Trust with AI (Zero Trust principles, AI-enhanced IAM,
microsegmentation, continuous monitoring). Section 7 covers AI risk management and compliance (risk assessment, model
governance, drift detection, audit readiness). Section 8 covers capstone integration and professional practice (project design,
documentation, stakeholder communication, ethical decision-making). Distractors target common capstone pitfalls including
confusing governance frameworks, misapplying ethical principles, incorrect AIaaS vendor selection, and misunderstanding bias
mitigation. Commonly confused concept pairs addressed: AI Governance vs. Data Governance, Explainability vs.
Interpretability, Fairness vs. Bias, SOAR vs. SIEM.


Section Overview
# Section Topic Coverage Q Range

1 AI Fundamentals and Cybersecurity Integration AI/ML Concepts, AI in Security Operations, & Threat Detection Q1-Q24

2 AI-as-a-Service (AIaaS) Architecture and Deployment
Cloud AI Services, Vendor Selection, & Integration Models Q25-Q45

3 Governance, Risk, and Compliance (GRC) Frameworks
NIST, ISO 27001, SOC 2, GDPR, & AI Governance Q46-Q70

4 Ethical Design and Responsible AI AI Ethics, Bias, Fairness, Transparency, & Accountability Q71-Q92

5 AI-Driven Threat Detection and Response Anomaly Detection, SOAR, UEBA, & Incident Response AutomationQ93-Q112

6 Security Architecture and Zero Trust with AI Zero Trust Principles, AI-Enhanced IAM, & Network Security Q113-Q130

7 Risk Management and Compliance for AI Systems AI Risk Assessment, Model Governance, & Audit Readiness Q131-Q142

8 Capstone Integration and Professional Practice Project Design, Documentation, & Stakeholder Communication Q143-Q150




Western Governors University - Cybersecurity Capstone Preparation Page 1

,WGU D490 Capstone: AI-Driven Cybersecurity | 2026/2027 Update with Complete Solution Integrating AIaaS, GRC, and Ethical Design




Section 1: AI Fundamentals and Cybersecurity Integration
AI/ML Concepts, AI in Security Operations, & Threat Detection

Q1: A security team wants to build an AI model that classifies network packets as malicious or benign using a
labeled dataset of 1 million historical packets. Which type of machine learning is MOST appropriate?
A. Unsupervised learning
B. Supervised learning [CORRECT]
C. Reinforcement learning
D. Self-supervised learning
Correct Answer: B
Rationale:
Supervised learning requires labeled data (each packet is already tagged as malicious/benign)—the model learns the mapping
between input features and known outputs, making it ideal for classification tasks like malicious packet detection. Unsupervised
learning would cluster unlabeled data (useful for anomaly detection but not classification with known labels). Reinforcement
learning optimizes sequential decisions through rewards, and self-supervised learning creates labels from data structure (used in
NLP/vision pre-training). The labeled dataset here is the key discriminator.


Q2: A security analyst wants to detect unusual user behavior without prior labeling of normal versus
abnormal activity. Which AI approach is MOST appropriate?
A. Supervised classification using decision trees
B. Unsupervised clustering (e.g., k-means, isolation forest) for anomaly detection [CORRECT]
C. Reinforcement learning for policy optimization
D. Linear regression for prediction
Correct Answer: B
Rationale:
Unsupervised learning techniques (clustering like k-means, isolation forests, autoencoders) detect anomalies without labeled
data by identifying patterns that deviate from the established norm—perfect for UEBA and zero-day detection where attack
patterns are unknown. Supervised classification requires known attack labels, reinforcement learning optimizes sequential
actions, and linear regression predicts continuous values rather than classifying anomalies. The absence of labeled anomaly
data is the key discriminator.


Q3: An AI model trained to detect phishing emails achieves 99% accuracy on training data but only 62% on
new emails. Which problem is the model exhibiting?
A. Underfitting
B. Overfitting [CORRECT]
C. High bias
D. Vanishing gradient
Correct Answer: B
Rationale:
Overfitting occurs when a model learns training data too well—including noise—resulting in high training accuracy but poor
generalization to new data (low testing accuracy). Underfitting shows poor performance on both training and testing data (high
bias). Vanishing gradient is a training optimization issue in deep networks. Solutions include regularization (L1/L2), dropout,
cross-validation, more training data, or simpler models. This gap between training (99%) and testing (62%) is the classic
overfitting signature.




Western Governors University - Cybersecurity Capstone Preparation Page 2

,WGU D490 Capstone: AI-Driven Cybersecurity | 2026/2027 Update with Complete Solution Integrating AIaaS, GRC, and Ethical Design




Q4: Which AI technique is BEST suited for natural language processing tasks such as analyzing suspicious
email content for phishing indicators?
A. Convolutional Neural Networks (CNNs)
B. Recurrent Neural Networks (RNNs) or Transformer models [CORRECT]
C. k-Nearest Neighbors (k-NN)
D. Decision Trees
Correct Answer: B
Rationale:
RNNs and Transformer-based models (BERT, GPT) are designed for sequential data like text—they capture contextual
relationships between words essential for understanding phishing language patterns. CNNs are best for image processing
(spatial data), k-NN is a simple instance-based classifier, and decision trees handle tabular data. Transformers have largely
superseded RNNs in NLP due to attention mechanisms enabling parallel processing and better long-range context.


Q5: A security operations center (SOC) deploys an AI model that flags 95% of normal traffic as malicious,
overwhelming analysts. Which metric should be optimized to reduce these false positives?
A. Recall
B. Precision [CORRECT]
C. Accuracy
D. F1 score
Correct Answer: B
Rationale:
Precision = true positives / (true positives + false positives). Optimizing precision minimizes false positives (alarm fatigue).
Recall (sensitivity) = true positives / (true positives + false negatives)—optimizing recall minimizes false negatives (missed
attacks). Accuracy can be misleading with imbalanced data. F1 balances precision and recall. The scenario describes alarm
fatigue from false positives, so precision is the priority. However, in real SOCs, F1 or PR curves often guide threshold tuning to
balance both.


Q6: A company wants to use AI to predict which employees are most likely to click on phishing links based on
past behavior. Which ethical concern is MOST significant?
A. Model interpretability for ML engineers
B. Privacy, potential discrimination, and employee surveillance concerns [CORRECT]
C. Cloud infrastructure cost
D. Vendor lock-in
Correct Answer: B
Rationale:
Predictive employee profiling raises serious privacy (GDPR/CCPA), discrimination (algorithmic bias against protected groups),
and workplace surveillance concerns. Employees may be unfairly targeted based on factors correlated with protected
characteristics. Ethical AI design requires consent, transparency, fairness audits, and human oversight. While interpretability,
cost, and vendor lock-in are considerations, they are secondary to the fundamental ethical and legal issues of profiling humans
based on behavioral predictions.


Q7: Which type of AI learning uses reward signals to train an agent to make sequential decisions in an
environment?
A. Supervised learning
B. Unsupervised learning



Western Governors University - Cybersecurity Capstone Preparation Page 3

, WGU D490 Capstone: AI-Driven Cybersecurity | 2026/2027 Update with Complete Solution Integrating AIaaS, GRC, and Ethical Design




C. Reinforcement learning [CORRECT]
D. Transfer learning
Correct Answer: C
Rationale:
Reinforcement learning (RL) trains an agent through trial-and-error interactions with an environment, receiving rewards or
penalties for actions—used in autonomous systems, game playing (AlphaGo), and increasingly in adaptive security (e.g.,
dynamic defense strategies). Supervised learning uses labeled data, unsupervised learning finds patterns in unlabeled data, and
transfer learning applies knowledge from one task to another. RL's defining feature is the reward signal driving sequential
decision-making.


Q8: A cybersecurity firm wants to detect malware without relying on known signatures. Which AI technique
is MOST appropriate?
A. Signature-based matching using regex
B. Behavioral analysis using unsupervised anomaly detection [CORRECT]
C. Hash-based exact matching
D. Static YARA rules
Correct Answer: B
Rationale:
Behavioral analysis using unsupervised anomaly detection identifies malware based on actions (network behavior, system calls,
file operations) rather than known signatures—essential for zero-day and polymorphic malware. Signature matching, hash
matching, and YARA rules all require known indicators of compromise (IOCs), making them ineffective against novel threats.
AI-driven behavioral analysis can flag previously unseen malicious patterns based on deviations from learned baselines.


Q9: A neural network with multiple hidden layers used for image-based malware analysis is an example of:
A. Shallow learning
B. Deep learning [CORRECT]
C. Reinforcement learning
D. Transfer learning
Correct Answer: B
Rationale:
Deep learning refers to neural networks with multiple hidden layers (typically >3) that can learn hierarchical
representations—used in image classification (CNNs for malware byte visualization), NLP, and speech recognition. 'Shallow
learning' refers to models with few layers (e.g., logistic regression). Reinforcement and transfer learning are paradigms, not
architectural depth categories. Deep learning excels at complex pattern recognition but requires significant data and compute
resources.


Q10: A security team trains an AI model on data from 2019-2022 but deploys it in 2026 without retraining.
Which risk is MOST likely?
A. Data poisoning
B. Model drift (concept drift) due to evolving attack patterns [CORRECT]
C. Adversarial evasion
D. Membership inference attack
Correct Answer: B
Rationale:




Western Governors University - Cybersecurity Capstone Preparation Page 4

Document information

Uploaded on
October 5, 2026
Number of pages
50
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$20.50

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NURSEEXAMITY
3.4
(110)
Sold
602
Followers
276
Items
6933
Last sold
9 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions