1
WGU D488 Cybersecurity Architecture and
Engineering — Final Objective Assessment
2026/2027
Section 1: Identity and Access Management (IAM) & Authentication
1. A company wants to allow employees to access multiple internal applications with a single set of
credentials. Which technology should they implement?
• A) Multi-factor Authentication (MFA)
• B) Single Sign-On (SSO)
• C) Password Policy
• D) Role-Based Access Control (RBAC)
• Answer: B) Single Sign-On (SSO)
• Rationale: SSO allows users to use one authentication credential to access multiple accounts or
applications.
2. What authentication protocol is commonly used in Windows domain environments and uses OS-
generated keys?
• A) RADIUS
• B) TACACS+
• C) Kerberos
• D) LDAP
• Answer: C) Kerberos
• Rationale: Kerberos is an authentication protocol used in Windows domain environments that
uses OS-generated keys, making it more secure than manually entered keys.
3. An organization wants users of their site to provide a password, memorable word, and PIN. What
should be implemented?
• A) Multi-factor Authentication (MFA)
• B) Two-factor Authentication (2FA)
• C) Single Sign-On (SSO)
,2
• D) Single-factor Authentication
• Answer: A) Multi-factor Authentication (MFA)
• Rationale: MFA enhances security by requiring multiple forms of authentication, reducing the
risk of unauthorized access.
4. What is the primary purpose of Privileged Access Management (PAM)?
• A) Managing all user passwords in the organization
• B) Monitoring and controlling access to critical systems by users with elevated access
• C) Enforcing password complexity rules for all users
• D) Providing single sign-on capabilities across applications
• Answer: B) Monitoring and controlling access to critical systems by users with elevated
access
• Rationale: PAM is a security practice that monitors and controls access to critical systems and
data by users with elevated access, such as admin accounts.
5. What is the key difference between RADIUS and Diameter?
• A) RADIUS is TCP-based; Diameter is UDP-based
• B) RADIUS is UDP-based; Diameter is TCP-based with a failover mechanism
• C) RADIUS encrypts all data; Diameter encrypts only passwords
• D) There is no difference; they are the same protocol
• Answer: B) RADIUS is UDP-based; Diameter is TCP-based with a failover mechanism
• Rationale: Diameter improves upon RADIUS by addressing weaknesses such as the lack of a
failover mechanism, which is possible because Diameter is TCP-based.
6. What is a password audit primarily used for?
• A) Enforcing password complexity rules
• B) Detecting weak passwords that match common dictionary words
• C) Preventing brute force attacks in real-time
• D) Managing password expiration dates
• Answer: B) Detecting weak passwords that match common dictionary words
• Rationale: Password auditing allows existing passwords to be compared against known weak
passwords to help determine the security of a credential.
7. A security analyst needs to ensure that a directory service runs securely over the network. What
should they implement?
,3
• A) LDAP
• B) Kerberos
• C) RADIUS
• D) LDAPS
• Answer: D) LDAPS
• Rationale: Secure LDAP (LDAPS) is a method of implementing LDAP using SSL/TLS encryption
protocols to prevent eavesdropping and man-in-the-middle attacks.
8. Which authentication protocol is Cisco-developed and encrypts all data in its packets?
• A) RADIUS
• B) Diameter
• C) TACACS+
• D) Kerberos
• Answer: C) TACACS+
• *Rationale: TACACS+ is a Cisco-developed authentication protocol that is a reliable, connection-
oriented protocol using port 49 and encrypts all data in its packets.*
9. What type of security should a business use on its layer 2 switch to isolate the finance network
from other departmental networks?
• A) Virtual Private Network (VPN)
• B) Internet Protocol Security (IPSec)
• C) Virtual Local Area Network (VLAN)
• D) Remotely Triggered Black Hole (RTBH)
• Answer: C) Virtual Local Area Network (VLAN)
• Rationale: VLANs allow companies to logically segment network traffic, ensuring devices on
different VLANs cannot communicate unless otherwise specified in a layer 3 device like a router.
10. A company wants to ensure only work applications can be installed on company laptops for
remote employees. What should be implemented?
• A) Containerization
• B) Token-based access
• C) Patch repository
• D) Whitelisting
, 4
• Answer: D) Whitelisting
• Rationale: Application whitelisting is a security technique that only allows pre-approved software
to execute on a system, preventing users from installing unauthorized applications.
Section 2: Network Security, Firewalls & Intrusion Detection
11. A company wants to implement intrusion detection, spam filtering, content filtering, and antivirus
controls using the least amount of infrastructure. Which solution should they deploy?
• A) Anti-spam gateway
• B) Proxy server
• C) Unified Threat Management (UTM) appliance
• D) Web Application Firewall (WAF)
• Answer: C) Unified Threat Management (UTM) appliance
• Rationale: A UTM appliance combines multiple security features into a single device, minimizing
infrastructure while meeting all requirements.
12. A security team has a database of signatures and wants their IDS to validate against them. Which
detection technique should be used?
• A) Anomaly-based detection
• B) Deep packet inspection
• C) Signature-based detection
• D) Behavior-based detection
• Answer: C) Signature-based detection
• Rationale: Signature-based detection uses a database of known threat signatures to identify and
alert on inbound threats.
13. A network technician needs to block several known bad actor IP addresses. What type of rule
should they create?
• A) Signature rules
• B) Firewall rules
• C) Behavior rules
• D) Data Loss Prevention (DLP) rules
• Answer: B) Firewall rules
WGU D488 Cybersecurity Architecture and
Engineering — Final Objective Assessment
2026/2027
Section 1: Identity and Access Management (IAM) & Authentication
1. A company wants to allow employees to access multiple internal applications with a single set of
credentials. Which technology should they implement?
• A) Multi-factor Authentication (MFA)
• B) Single Sign-On (SSO)
• C) Password Policy
• D) Role-Based Access Control (RBAC)
• Answer: B) Single Sign-On (SSO)
• Rationale: SSO allows users to use one authentication credential to access multiple accounts or
applications.
2. What authentication protocol is commonly used in Windows domain environments and uses OS-
generated keys?
• A) RADIUS
• B) TACACS+
• C) Kerberos
• D) LDAP
• Answer: C) Kerberos
• Rationale: Kerberos is an authentication protocol used in Windows domain environments that
uses OS-generated keys, making it more secure than manually entered keys.
3. An organization wants users of their site to provide a password, memorable word, and PIN. What
should be implemented?
• A) Multi-factor Authentication (MFA)
• B) Two-factor Authentication (2FA)
• C) Single Sign-On (SSO)
,2
• D) Single-factor Authentication
• Answer: A) Multi-factor Authentication (MFA)
• Rationale: MFA enhances security by requiring multiple forms of authentication, reducing the
risk of unauthorized access.
4. What is the primary purpose of Privileged Access Management (PAM)?
• A) Managing all user passwords in the organization
• B) Monitoring and controlling access to critical systems by users with elevated access
• C) Enforcing password complexity rules for all users
• D) Providing single sign-on capabilities across applications
• Answer: B) Monitoring and controlling access to critical systems by users with elevated
access
• Rationale: PAM is a security practice that monitors and controls access to critical systems and
data by users with elevated access, such as admin accounts.
5. What is the key difference between RADIUS and Diameter?
• A) RADIUS is TCP-based; Diameter is UDP-based
• B) RADIUS is UDP-based; Diameter is TCP-based with a failover mechanism
• C) RADIUS encrypts all data; Diameter encrypts only passwords
• D) There is no difference; they are the same protocol
• Answer: B) RADIUS is UDP-based; Diameter is TCP-based with a failover mechanism
• Rationale: Diameter improves upon RADIUS by addressing weaknesses such as the lack of a
failover mechanism, which is possible because Diameter is TCP-based.
6. What is a password audit primarily used for?
• A) Enforcing password complexity rules
• B) Detecting weak passwords that match common dictionary words
• C) Preventing brute force attacks in real-time
• D) Managing password expiration dates
• Answer: B) Detecting weak passwords that match common dictionary words
• Rationale: Password auditing allows existing passwords to be compared against known weak
passwords to help determine the security of a credential.
7. A security analyst needs to ensure that a directory service runs securely over the network. What
should they implement?
,3
• A) LDAP
• B) Kerberos
• C) RADIUS
• D) LDAPS
• Answer: D) LDAPS
• Rationale: Secure LDAP (LDAPS) is a method of implementing LDAP using SSL/TLS encryption
protocols to prevent eavesdropping and man-in-the-middle attacks.
8. Which authentication protocol is Cisco-developed and encrypts all data in its packets?
• A) RADIUS
• B) Diameter
• C) TACACS+
• D) Kerberos
• Answer: C) TACACS+
• *Rationale: TACACS+ is a Cisco-developed authentication protocol that is a reliable, connection-
oriented protocol using port 49 and encrypts all data in its packets.*
9. What type of security should a business use on its layer 2 switch to isolate the finance network
from other departmental networks?
• A) Virtual Private Network (VPN)
• B) Internet Protocol Security (IPSec)
• C) Virtual Local Area Network (VLAN)
• D) Remotely Triggered Black Hole (RTBH)
• Answer: C) Virtual Local Area Network (VLAN)
• Rationale: VLANs allow companies to logically segment network traffic, ensuring devices on
different VLANs cannot communicate unless otherwise specified in a layer 3 device like a router.
10. A company wants to ensure only work applications can be installed on company laptops for
remote employees. What should be implemented?
• A) Containerization
• B) Token-based access
• C) Patch repository
• D) Whitelisting
, 4
• Answer: D) Whitelisting
• Rationale: Application whitelisting is a security technique that only allows pre-approved software
to execute on a system, preventing users from installing unauthorized applications.
Section 2: Network Security, Firewalls & Intrusion Detection
11. A company wants to implement intrusion detection, spam filtering, content filtering, and antivirus
controls using the least amount of infrastructure. Which solution should they deploy?
• A) Anti-spam gateway
• B) Proxy server
• C) Unified Threat Management (UTM) appliance
• D) Web Application Firewall (WAF)
• Answer: C) Unified Threat Management (UTM) appliance
• Rationale: A UTM appliance combines multiple security features into a single device, minimizing
infrastructure while meeting all requirements.
12. A security team has a database of signatures and wants their IDS to validate against them. Which
detection technique should be used?
• A) Anomaly-based detection
• B) Deep packet inspection
• C) Signature-based detection
• D) Behavior-based detection
• Answer: C) Signature-based detection
• Rationale: Signature-based detection uses a database of known threat signatures to identify and
alert on inbound threats.
13. A network technician needs to block several known bad actor IP addresses. What type of rule
should they create?
• A) Signature rules
• B) Firewall rules
• C) Behavior rules
• D) Data Loss Prevention (DLP) rules
• Answer: B) Firewall rules