WGU MSCSIA D490 DDN2 CAPSTONE TASK 2 | 2026 UPDATE
| WITH COMPLETE SOLUTIONS
Question 1
A cybersecurity analyst working for a healthcare organization has
been assigned to evaluate the security posture of a newly
deployed electronic health record system and discovers that
several administrative accounts are using weak passwords,
excessive permissions, and shared login credentials, creating a
significant risk that unauthorized users could gain access to
sensitive patient information and violate confidentiality
requirements. What security principle should the analyst prioritize
when recommending improvements?
A. Least privilege access control
B. Increasing network bandwidth
C. Removing all authentication requirements
D. Allowing unrestricted administrator access
✅ Correct Answer: A
Solution:
The principle of least privilege ensures that users receive only the
minimum permissions necessary to perform their responsibilities.
This reduces the risk of unauthorized access and limits damage if
an account is compromised.
Question 2
A financial organization experiences a cybersecurity incident
where attackers gain access to an employee account through
stolen credentials and begin accessing confidential customer
records. The security team wants to implement additional controls
to reduce the possibility that stolen passwords alone can be used
to access critical systems. Which security control would provide
the greatest improvement?
A. Multi-factor authentication
B. Disabling system monitoring
,C. Removing password expiration policies
D. Increasing the number of employees with administrative access
✅ Correct Answer: A
Solution:
Multi-factor authentication requires additional verification beyond a
password, such as a security token or biometric factor, making
unauthorized access more difficult.
Question 3
A cybersecurity project manager is developing a risk management
plan for an organization that recently migrated business
applications to a cloud environment. The manager identifies
potential threats including unauthorized access, data exposure,
service outages, and compliance failures. Which activity should be
performed first to create an effective risk management strategy?
A. Conduct a risk assessment to identify threats, vulnerabilities,
and potential impacts.
B. Purchase security software immediately without analysis.
C. Disable all cloud services.
D. Ignore risks that have not caused previous incidents.
✅ Correct Answer: A
Solution:
A risk assessment provides visibility into threats, vulnerabilities,
likelihood, and impact, allowing organizations to select appropriate
security controls.
Question 4
A security engineer discovers that employees frequently receive
phishing emails containing malicious links designed to steal login
, information. The organization wants to reduce successful phishing
attacks through improved employee awareness. Which solution is
most appropriate?
A. Security awareness training combined with phishing simulations
B. Allow employees to click any links without restrictions
C. Remove all email communication
D. Disable cybersecurity monitoring tools
✅ Correct Answer: A
Solution:
Security awareness training helps employees recognize social
engineering attempts, while simulations measure improvement and
identify additional training needs.
Question 5
A company experiences a ransomware attack that encrypts
important business files and prevents employees from accessing
critical systems. The cybersecurity team wants to improve
recovery capability after future incidents. Which control would
provide the strongest improvement?
A. Maintain tested offline backups and an incident response
recovery plan.
B. Delete all security logs.
C. Allow employees to share passwords.
D. Remove antivirus protections.
✅ Correct Answer: A
Solution:
Reliable backups and recovery procedures reduce downtime and
help organizations restore operations after ransomware attacks.
| WITH COMPLETE SOLUTIONS
Question 1
A cybersecurity analyst working for a healthcare organization has
been assigned to evaluate the security posture of a newly
deployed electronic health record system and discovers that
several administrative accounts are using weak passwords,
excessive permissions, and shared login credentials, creating a
significant risk that unauthorized users could gain access to
sensitive patient information and violate confidentiality
requirements. What security principle should the analyst prioritize
when recommending improvements?
A. Least privilege access control
B. Increasing network bandwidth
C. Removing all authentication requirements
D. Allowing unrestricted administrator access
✅ Correct Answer: A
Solution:
The principle of least privilege ensures that users receive only the
minimum permissions necessary to perform their responsibilities.
This reduces the risk of unauthorized access and limits damage if
an account is compromised.
Question 2
A financial organization experiences a cybersecurity incident
where attackers gain access to an employee account through
stolen credentials and begin accessing confidential customer
records. The security team wants to implement additional controls
to reduce the possibility that stolen passwords alone can be used
to access critical systems. Which security control would provide
the greatest improvement?
A. Multi-factor authentication
B. Disabling system monitoring
,C. Removing password expiration policies
D. Increasing the number of employees with administrative access
✅ Correct Answer: A
Solution:
Multi-factor authentication requires additional verification beyond a
password, such as a security token or biometric factor, making
unauthorized access more difficult.
Question 3
A cybersecurity project manager is developing a risk management
plan for an organization that recently migrated business
applications to a cloud environment. The manager identifies
potential threats including unauthorized access, data exposure,
service outages, and compliance failures. Which activity should be
performed first to create an effective risk management strategy?
A. Conduct a risk assessment to identify threats, vulnerabilities,
and potential impacts.
B. Purchase security software immediately without analysis.
C. Disable all cloud services.
D. Ignore risks that have not caused previous incidents.
✅ Correct Answer: A
Solution:
A risk assessment provides visibility into threats, vulnerabilities,
likelihood, and impact, allowing organizations to select appropriate
security controls.
Question 4
A security engineer discovers that employees frequently receive
phishing emails containing malicious links designed to steal login
, information. The organization wants to reduce successful phishing
attacks through improved employee awareness. Which solution is
most appropriate?
A. Security awareness training combined with phishing simulations
B. Allow employees to click any links without restrictions
C. Remove all email communication
D. Disable cybersecurity monitoring tools
✅ Correct Answer: A
Solution:
Security awareness training helps employees recognize social
engineering attempts, while simulations measure improvement and
identify additional training needs.
Question 5
A company experiences a ransomware attack that encrypts
important business files and prevents employees from accessing
critical systems. The cybersecurity team wants to improve
recovery capability after future incidents. Which control would
provide the strongest improvement?
A. Maintain tested offline backups and an incident response
recovery plan.
B. Delete all security logs.
C. Allow employees to share passwords.
D. Remove antivirus protections.
✅ Correct Answer: A
Solution:
Reliable backups and recovery procedures reduce downtime and
help organizations restore operations after ransomware attacks.