• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 72 pages
Exam (elaborations)

WGU D488 Cybersecurity Architecture and Engineering Final Exam 2026/2027 Actual Exam - Complete Questions with Detailed Rationales | 100% Verified Graded A+ Pass Guaranteed - A+ Graded

Document preview thumbnail
Preview 4 out of 72 pages

WGU D488 Cybersecurity Architecture and Engineering Final Exam 2026/2027 Actual Exam - Complete Questions with Detailed Rationales | 100% Verified Graded A+ Pass Guaranteed - A+ Graded

Content preview

1


WGU D488 Cybersecurity Architecture and Engineering
Final Exam 2026/2027 Actual Exam - Complete
Questions with Detailed Rationales | 100% Verified
Graded A+ Pass Guaranteed - A+ Graded


Part 1: Core Security Concepts & Risk Management (1–25)

1. A security analyst is conducting a risk assessment for a healthcare organization. Which of the
following correctly describes the relationship between vulnerability, threat, and risk?

• A) A threat is a weakness in the system, a vulnerability is a potential danger, and risk is the
probability of exploitation.

• B) A vulnerability is a weakness, a threat is a potential danger, and risk is the likelihood of a
threat exploiting a vulnerability.

• C) A threat is a weakness, a vulnerability is a potential danger, and risk is the impact of an attack.

• D) Vulnerability and threat are the same; risk is the impact.

Correct Answer✅ B
Detailed Rationale: A vulnerability is a flaw or weakness in a system (e.g., unpatched software).
A threat is any potential danger that could exploit a vulnerability (e.g., a hacker). Risk is the likelihood
that a specific threat will exploit a specific vulnerability and the resulting impact.

2. A company is evaluating the cost of a security breach. Which risk management metric calculates the
maximum amount of data loss an organization can tolerate over a specific time period?

• A) Recovery Time Objective (RTO)

• B) Recovery Point Objective (RPO)

• C) Service Level Agreement (SLA)

• D) Mean Time to Repair (MTTR)

Correct Answer✅ B
Detailed Rationale: RPO defines the maximum tolerable period in which data might be lost from an IT
service due to a major incident. For example, an RPO of 4 hours means the organization can lose no
more than 4 hours of data. RTO is the target time to restore services after an interruption.

3. An organization has decided to purchase cyber insurance to transfer the financial risk of a potential
data breach. This is an example of which risk treatment strategy?

,2


• A) Risk avoidance

• B) Risk mitigation

• C) Risk transference

• D) Risk acceptance

Correct Answer✅ C
Detailed Rationale: Risk transference shifts the financial burden of a risk to a third party, typically
through insurance policies or outsourcing. Risk mitigation reduces the likelihood or impact. Risk
avoidance eliminates the activity that creates the risk. Risk acceptance means acknowledging the risk
and taking no action.

4. A security architect is designing a new authentication system. Which of the following is considered a
"something you have" factor in multi-factor authentication (MFA)?

• A) Password

• B) Fingerprint

• C) Hardware token

• D) PIN

Correct Answer✅ C
Detailed Rationale: Multi-factor authentication relies on three categories: something you
know (password, PIN), something you have (smart card, hardware token, phone), and something you
are (biometrics like fingerprint or retina scan).

5. An organization has discovered that an employee's credentials were stolen and used to access
sensitive data. The employee's account was protected by a password only. Which security control would
have been most effective in preventing this breach?

• A) Data Loss Prevention (DLP)

• B) Multi-Factor Authentication (MFA)

• C) Intrusion Detection System (IDS)

• D) Firewall

Correct Answer✅ B
Detailed Rationale: MFA adds a layer of protection beyond just a password. Even if credentials are
stolen, the attacker would also need the second factor (e.g., a one-time code from a mobile app or
hardware token), making unauthorized access much more difficult.

6. What is the primary difference between a vulnerability scan and a penetration test?

• A) A vulnerability scan is automated, while a penetration test is always manual.

,3


• B) A vulnerability scan identifies potential weaknesses, while a penetration test exploits them to
prove real-world impact.

• C) A vulnerability scan is performed annually, while a penetration test is performed monthly.

• D) A vulnerability scan requires no credentials, while a penetration test always requires
credentials.

Correct Answer✅ B
Detailed Rationale: A vulnerability scan is an automated process that identifies potential security
weaknesses without attempting to exploit them. A penetration test (ethical hacking) involves actively
attempting to exploit vulnerabilities to determine if unauthorized access is possible and to measure the
real-world impact.

7. Which security principle ensures that a user can only access the minimum data necessary to perform
their job functions?

• A) Separation of duties

• B) Least privilege

• C) Defense in depth

• D) Fail secure

Correct Answer✅ B
Detailed Rationale: The principle of least privilege restricts user permissions to only those required for
their specific role. This minimizes the potential damage from compromised accounts or insider threats.

8. A security engineer is implementing a new firewall rule to allow web traffic only from a specific
trusted network. This is an example of which access control model?

• A) Role-Based Access Control (RBAC)

• B) Mandatory Access Control (MAC)

• C) Discretionary Access Control (DAC)

• D) Rule-Based Access Control

Correct Answer✅ D
Detailed Rationale: Rule-Based Access Control uses a set of pre-defined rules (e.g., firewall rules, ACLs)
to grant or deny access based on conditions such as source IP, time of day, or protocol.

9. During a disaster recovery drill, it is determined that the backup data stored offsite is six months old.
Which metric has been violated?

• A) Recovery Time Objective (RTO)

• B) Mean Time to Recover (MTTR)

• C) Recovery Point Objective (RPO)

, 4


• D) Service Level Objective (SLO)

Correct Answer✅ C
Detailed Rationale: RPO defines how much data loss is acceptable (measured in time). An RPO of 24
hours would require backups at least daily; six-month-old backups violate that objective. RTO defines
how quickly services must be restored.

10. Which of the following is a primary goal of a security architecture framework (e.g., SABSA, TOGAF)?

• A) To provide a checklist for software development

• B) To align security strategy with business objectives and provide a structured approach to
security design

• C) To replace all existing security controls

• D) To define specific firewall rules

Correct Answer✅ B
Detailed Rationale: Security architecture frameworks like SABSA (Sherwood Applied Business Security
Architecture) and TOGAF (The Open Group Architecture Framework) provide structured methodologies
to ensure security is designed in alignment with business goals, not as an afterthought.

11. A company's risk assessment has identified that a legacy server running Windows Server 2008
contains customer credit card data. Which of the following is the best immediate mitigation strategy?

• A) Purchase cyber insurance to transfer the risk

• B) Isolate the server from the network and plan for migration

• C) Increase the frequency of vulnerability scans

• D) Ignore the risk because the server still works

Correct Answer✅ B
Detailed Rationale: A legacy operating system no longer receives security patches, creating a critical
vulnerability. The best immediate action is to isolate it (e.g., via network segmentation or firewalls) to
prevent attackers from reaching it, while simultaneously planning for migration to a supported OS.

12. Which risk management framework is widely used by U.S. federal agencies to manage cybersecurity
risk?

• A) COBIT

• B) ISO 27001

• C) NIST Risk Management Framework (RMF)

• D) PCI DSS

Correct Answer✅ C
Detailed Rationale: The NIST RMF (National Institute of Standards and Technology Risk Management

Document information

Uploaded on
April 5, 2026
Number of pages
72
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$23.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NursingTotur2
3.4
(90)
Sold
631
Followers
41
Items
6478
Last sold
17 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions