• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 45 pages
Exam (elaborations)

WGU D490 CAPSTONE TASK 2 ACTUAL EXAM 2026/2027 | CI/CD Pipeline Security for AWS Cloud-Native Applications | Complete Solutions | Pass Guaranteed - A+ Graded

Document preview thumbnail
Preview 4 out of 45 pages

Complete WGU D490 MSCIA Capstone Task 2 with this comprehensive 2026/2027 solution guide for CI/CD Pipeline Security in AWS. This A+ Graded resource covers the complete Security Architecture Review (SAR) with verified solutions and detailed rationales. Key areas include vulnerability scans, audit results, compliance logging, NIST CSF alignment, and stakeholder analysis. Each section provides step-by-step implementation guidance for securing cloud-native deployments using tools like OWASP Dependency-Check, Trivy, SAST, DAST, and AWS CodePipeline security controls. With our Pass Guarantee, you can complete your capstone confidently and pass on your first attempt. Download your complete WGU D490 Task 2 CI/CD Pipeline Security solution instantly!

Content preview

WGU D490 MSCIA
Graduate Capstone Task 2
CI/CD Pipeline Security for Cloud-Native Applications in AWS




140 Questions with Complete Solutions
DevSecOps, AWS Security, IaC, Containers, Supply Chain, & Incident Response

2026/2027 Update with Complete Solution




Western Governors University
Master of Science, Cybersecurity and Information Assurance (MSCIA)
D490 Capstone Task 2 — Cloud-Native Application Security
8 Sections · AWS DevSecOps & Cloud Security



TOTAL QUESTIONS 140

SECTIONS 8

FORMAT Multiple Choice (A-D) with Complete Solutions

COGNITIVE LEVELS 25% Recall / 50% Application / 25% Analysis

STYLE 75% Scenario-Based / 25% Direct Recall

CONTENT 2026/2027 Updated AWS Security, SLSA, DevSecOps



This comprehensive test bank covers the WGU D490 MSCIA Capstone Task 2 competencies for CI/CD pipeline security
in AWS cloud-native applications. Content includes DevSecOps principles, AWS security foundations (IAM, VPC,
Well-Architected Framework), pipeline security controls (SAST, secret scanning, artifact signing), Infrastructure as Code
security (Terraform, CloudFormation, Policy as Code), container and serverless security (ECS/EKS, Lambda), supply
chain security (SBOM, SLSA, Sigstore), monitoring and incident response (GuardDuty, Security Hub), and capstone
documentation. Each question includes detailed rationales with AWS service capabilities, security control principles,



WGU D490 MSCIA Capstone Task 2 - CI/CD Pipeline Security in AWS Page 1
140 Questions | 2026/2027 Update | Complete Solutions

, pipeline stage requirements, and integration best practices.




WGU D490 MSCIA Capstone Task 2 - CI/CD Pipeline Security in AWS Page 2
140 Questions | 2026/2027 Update | Complete Solutions

, Table of Contents

Section 1: CI/CD Fundamentals and DevSecOps Principles
Pipeline Stages, Continuous Integration/Delivery/Deployment, & Shift-Left Security
Q1-Q22
Section 2: AWS Cloud-Native Architecture and Security Foundations
Shared Responsibility Model, IAM, VPC, & Well-Architected Framework
Q23-Q45
Section 3: CI/CD Pipeline Security Controls
Source Code Security, Build Security, Artifact Security, & Deployment Security
Q46-Q70
Section 4: Infrastructure as Code (IaC) Security
Terraform, CloudFormation, Policy as Code, & Drift Detection
Q71-Q90
Section 5: Container and Serverless Security
Docker, ECS/EKS, Lambda, Container Scanning, & Runtime Protection
Q91-Q110
Section 6: Supply Chain Security and Software Composition Analysis
SBOM, Dependency Scanning, & Third-Party Risk
Q111-Q125
Section 7: Monitoring, Detection, and Incident Response in CI/CD
CloudWatch, GuardDuty, Security Hub, & Automated Remediation
Q126-Q135
Section 8: Capstone Documentation and Professional Practice
Architecture Diagrams, Risk Assessment, & Stakeholder Communication
Q136-Q140


Note: All 140 questions are sequentially numbered Q1 through Q140 with detailed rationales including CI/CD
security reasoning, AWS service capabilities, security control principles, pipeline stage requirements, and
integration best practices aligned with the 2026/2027 WGU D490 MSCIA Capstone Task 2 requirements.




WGU D490 MSCIA Capstone Task 2 - CI/CD Pipeline Security in AWS Page 3
140 Questions | 2026/2027 Update | Complete Solutions

, Section 1: CI/CD Fundamentals and DevSecOps Principles
Pipeline Stages, Continuous Integration/Delivery/Deployment, & Shift-Left Security
Q1-Q22



Q1: A DevSecOps team designs a pipeline where every change that passes automated tests is
automatically released to production with no human approval. Which deployment model does this
describe?
A. Continuous Integration
B. Continuous Delivery
C. Continuous Deployment [CORRECT]
D. Continuous Inspection
Correct Answer: C
Rationale: Continuous Deployment automatically releases every change that passes automated tests to
production without a manual approval gate. Continuous Delivery also automates the pipeline but stops at
a manual approval gate before production. Continuous Integration focuses on frequent merging and
automated builds, not deployment, and Continuous Inspection is not a recognized deployment model.

Q2: A security engineer wants to reduce the cost of fixing vulnerabilities by detecting them earlier in
the development lifecycle. Which practice directly supports this goal?
A. Shift-right testing in production
B. Shift-left security in the SDLC [CORRECT]
C. Runtime patching after deployment
D. Annual penetration testing only
Correct Answer: B
Rationale: Shift-left security integrates controls earlier in the SDLC where vulnerabilities are cheaper
and easier to fix before code is built or deployed. Shift-right testing emphasizes production observability
and runtime protection, which occurs too late to reduce remediation cost. Runtime patching and annual
penetration testing are reactive controls that do not catch issues during development.

Q3: A team must detect SQL injection flaws in source code before it is compiled. Which testing
approach should be applied?
A. Dynamic Application Security Testing (DAST)
B. Runtime Application Self-Protection (RASP)
C. Static Application Security Testing (SAST) [CORRECT]
D. Interactive Application Security Testing (IAST)
Correct Answer: C
Rationale: SAST analyzes source code without executing it, making it ideal for finding injection flaws
before compilation. DAST tests a running application from the outside and cannot inspect source code
directly. IAST combines static and dynamic techniques but requires instrumented runtime execution, and
RASP blocks attacks in production rather than scanning code.




WGU D490 MSCIA Capstone Task 2 - CI/CD Pipeline Security in AWS Page 4
140 Questions | 2026/2027 Update | Complete Solutions

Document information

Uploaded on
October 6, 2026
Number of pages
45
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$22.50

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NURSEEXAMITY
3.4
(110)
Sold
602
Followers
276
Items
6933
Last sold
9 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions