100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

WGU D488 Actual Exam Questions and Answers with Rationales 2026/2027 | Cybersecurity Architecture & Engineering Final | OA Test Bank | Pass Guarantee

Rating
-
Sold
-
Pages
28
Grade
A+
Uploaded on
31-12-2025
Written in
2025/2026

PASS WGU D488 CYBERSECURITY ARCHITECTURE & ENGINEERING ON YOUR FIRST ATTEMPT WITH ACTUAL EXAM QUESTIONS FOR 2026/2027! This comprehensive test bank delivers real questions from the Objective Assessment (OA), complete with verified answers and detailed technical rationales. Your definitive preparation for mastering security architecture, engineering principles, and enterprise defense strategies in WGU's cybersecurity program. This collection features actual exam questions from WGU's D488 Cybersecurity Architecture and Engineering course, updated for the 2026/2027 academic year. Each question includes the verified answer and a comprehensive rationale that explains security architecture frameworks, engineering controls, defense-in-depth strategies, and enterprise security solutions. This resource ensures you're prepared for both exam success and practical application in cybersecurity roles. WHAT THIS D488 CYBERSECURITY TEST BANK INCLUDES: ACTUAL WGU D488 OA EXAM QUESTIONS for Cybersecurity Architecture & Engineering (2026/2027) VERIFIED ANSWERS & DETAILED TECHNICAL RATIONALES explaining security architecture and engineering concepts COMPREHENSIVE SECURITY COVERAGE: Security Architecture Frameworks, Engineering Controls, Enterprise Defense, Cryptography, and Cloud Security OA-ALIGNED CONTENT - Matches WGU's Objective Assessment format and expectations ENTERPRISE SECURITY FOCUS - Large-scale security architecture and engineering solutions FRAMEWORKS & STANDARDS - NIST, ISO, SABSA, TOGAF, and other industry frameworks COMPETENCY-BASED READY - Efficient preparation for WGU's demonstrate-mastery model Stop struggling with complex security architecture. Get the actual exam questions that give you the definitive advantage in WGU's D488. Purchase now and accelerate your cybersecurity degree completion with confidence!

Show more Read less
Institution
WGU D488
Course
WGU D488










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
WGU D488
Course
WGU D488

Document information

Uploaded on
December 31, 2025
Number of pages
28
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

1



WGU D488 Actual Exam Questions and
Answers with Rationales 2026/2027 |
Cybersecurity Architecture &
Engineering Final | OA Test Bank | Pass
Guarantee

Q001: A multinational enterprise is mapping its cybersecurity architecture to
business objectives. Which SABSA layer is MOST appropriate for defining
security-driven business goals?
Options:
A. Physical
B. Component
C. Contextual - CORRECT
D. Logical
ANSWER: C
Q002: During the TOGAF ADM Phase C, the security architect discovers that
customer PII is stored in an unencrypted RDBMS. Which ADM phase should
address this risk?
Options:
A. Phase A: Architecture Vision
B. Phase B: Business Architecture
C. Phase C: Information Systems Architecture - CORRECT
D. Phase E: Opportunities and Solutions

, 2


ANSWER: C
Q003: A green-field cloud-native application will be deployed in AWS. The CISO
mandates defense-in-depth and zero-trust principles. Which combination BEST
embodies these tenets?
Options:
A. Single VPC, one subnet, security-group rules open to 0.0.0.0/0
B. IAM roles, VPC segmentation, ALB with WAF, GuardDuty, KMS-encrypted S3
- CORRECT
D. Shared SSH keys, public S3 buckets, open NACLs
ANSWER: B
Q004: An architect is selecting a public-key algorithm for long-term data
confidentiality (> 20 years). Which NIST-approved algorithm offers quantum-
resistant security?
Options:
A. RSA-4096
B. ECDH P-384
C. Kyber (ML-KEM) - CORRECT
D. DSA-2048
ANSWER: C
Q005: The enterprise PKI’s CRL endpoint is experiencing availability issues.
Which alternative revocation mechanism provides higher resilience and real-time
status?
Options:
A. Manual certificate whitelisting
B. OCSP stapling - CORRECT
C. Longer certificate lifespans

, 3


D. Static CRL caching only
ANSWER: B
Q006: A DevOps pipeline requires secrets (API keys, DB credentials). Which
toolset BEST enforces least-privilege, auditability, and automatic rotation?
Options:
A. Hard-coded in GitHub
B. Kubernetes ConfigMaps
C. HashiCorp Vault - CORRECT
D. Shared Google Doc
ANSWER: C
Q007: A microservice uses mTLS for east-west traffic. The security engineer wants
to offload TLS processing and enforce consistent policies. Which architectural
pattern is MOST suitable?
Options:
A. Service mesh (e.g., Istio) - CORRECT
B. Direct service-to-service TLS
C. SSH tunnels
D. GRE tunnels
ANSWER: A
Q008: An organization must encrypt data at rest on EBS volumes AND allow
granular key revocation per project. Which AWS encryption approach BEST meets
these requirements?
Options:
A. AWS-managed keys (AWS KMS default)
B. Customer-managed keys in AWS KMS with key policies - CORRECT
C. Transparent disk encryption outside AWS

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIASTUDYGUIDE University Of California - Los Angeles (UCLA)
View profile
Follow You need to be logged in order to follow users or courses
Sold
592
Member since
2 year
Number of followers
200
Documents
4136
Last sold
1 day ago
STUVIASTUDYGUIDES

Join Thousands of successful students who use our study materials to boost their grades. With carefully crafted notes and well-researched guides, you're just a click away from mastering your courses. Study hard, study smart, and get the grades you deserve!

3.6

76 reviews

5
34
4
11
3
10
2
7
1
14

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions