WGU MSCSIA D490 CAPSTONE DDN2 TASK 3:
TECHNOLOGY -SUPPORTED SECURITY SOLUTION |
2026 UPDATE | WITH COMPLETE SOLUTIONS
Question 1
A regional healthcare organization has experienced
several successful phishing attacks that resulted in
compromised employee credentials and unauthorized
access to electronic health records. As part of a capstone
project, you have been asked to recommend a
technology-supported security solution that significantly
reduces the likelihood of credential theft while minimizing
disruption to clinical workflows. Which technology should
be prioritized?
A. Multi-factor authentication (MFA)
B. Disable password requirements
C. Allow employees to share accounts
D. Remove login monitoring
✅ Correct Answer: A
Complete Solution
Multi-factor authentication adds an additional verification
factor beyond passwords, making stolen credentials much
less useful to attackers while maintaining usability.
Question 2
A manufacturing company wants to improve its ability to
detect cyberattacks affecting servers, workstations,
firewalls, and cloud applications. The organization
currently reviews logs manually, resulting in delayed
,detection of security incidents. Which technology-
supported solution would best address this problem?
A. Security Information and Event Management (SIEM)
B. Remove all event logs
C. Store logs without analysis
D. Disable security monitoring
✅ Correct Answer: A
Complete Solution
A SIEM centralizes security logs, correlates events,
generates alerts, and supports faster incident detection
and response.
Question 3
A financial institution is implementing a new endpoint
protection strategy because traditional antivirus software
has failed to detect several advanced malware infections.
Which technology provides continuous monitoring,
behavioral analysis, and rapid containment of
compromised devices?
A. Endpoint Detection and Response (EDR)
B. Disk defragmentation software
C. Basic file compression
D. Printer management software
✅ Correct Answer: A
Complete Solution
, EDR continuously monitors endpoints, detects suspicious
behavior, and enables rapid investigation and containment
of threats.
Question 4
A cybersecurity consultant recommends implementing a
Zero Trust architecture during a capstone project. Which
statement best describes the primary principle of Zero
Trust?
A. Every user, device, and connection must be
continuously verified before access is granted.
B. Internal users should always be trusted automatically.
C. Authentication is only required once when an employee
is hired.
D. Network perimeter defenses eliminate the need for
additional controls.
✅ Correct Answer: A
Complete Solution
Zero Trust assumes no implicit trust and requires
continuous verification of users, devices, and access
requests.
Question 5
A company plans to implement a Data Loss Prevention
(DLP) solution after discovering employees have
accidentally emailed confidential customer information
outside the organization. What is the primary purpose of
DLP technology?
TECHNOLOGY -SUPPORTED SECURITY SOLUTION |
2026 UPDATE | WITH COMPLETE SOLUTIONS
Question 1
A regional healthcare organization has experienced
several successful phishing attacks that resulted in
compromised employee credentials and unauthorized
access to electronic health records. As part of a capstone
project, you have been asked to recommend a
technology-supported security solution that significantly
reduces the likelihood of credential theft while minimizing
disruption to clinical workflows. Which technology should
be prioritized?
A. Multi-factor authentication (MFA)
B. Disable password requirements
C. Allow employees to share accounts
D. Remove login monitoring
✅ Correct Answer: A
Complete Solution
Multi-factor authentication adds an additional verification
factor beyond passwords, making stolen credentials much
less useful to attackers while maintaining usability.
Question 2
A manufacturing company wants to improve its ability to
detect cyberattacks affecting servers, workstations,
firewalls, and cloud applications. The organization
currently reviews logs manually, resulting in delayed
,detection of security incidents. Which technology-
supported solution would best address this problem?
A. Security Information and Event Management (SIEM)
B. Remove all event logs
C. Store logs without analysis
D. Disable security monitoring
✅ Correct Answer: A
Complete Solution
A SIEM centralizes security logs, correlates events,
generates alerts, and supports faster incident detection
and response.
Question 3
A financial institution is implementing a new endpoint
protection strategy because traditional antivirus software
has failed to detect several advanced malware infections.
Which technology provides continuous monitoring,
behavioral analysis, and rapid containment of
compromised devices?
A. Endpoint Detection and Response (EDR)
B. Disk defragmentation software
C. Basic file compression
D. Printer management software
✅ Correct Answer: A
Complete Solution
, EDR continuously monitors endpoints, detects suspicious
behavior, and enables rapid investigation and containment
of threats.
Question 4
A cybersecurity consultant recommends implementing a
Zero Trust architecture during a capstone project. Which
statement best describes the primary principle of Zero
Trust?
A. Every user, device, and connection must be
continuously verified before access is granted.
B. Internal users should always be trusted automatically.
C. Authentication is only required once when an employee
is hired.
D. Network perimeter defenses eliminate the need for
additional controls.
✅ Correct Answer: A
Complete Solution
Zero Trust assumes no implicit trust and requires
continuous verification of users, devices, and access
requests.
Question 5
A company plans to implement a Data Loss Prevention
(DLP) solution after discovering employees have
accidentally emailed confidential customer information
outside the organization. What is the primary purpose of
DLP technology?