WGU Cybersecurity Architecture and
Engineering
(KFO1 / D488) Certification Exam
Aligned with 2026 Curriculum Standards
Western Governors University | Cybersecurity Architecture and Engineering
Cybersecurity Architecture | Network Engineering | Enterprise Security Design
Exam Composition: 80 multiple-choice questions distributed across four content domains.
Cognitive level distribution: ~30% recall, ~50% application, ~20% analysis. Approximately 75%
of items are scenario-based (enterprise network design, security incident response architecture,
compliance mapping, access control troubleshooting), with 25% direct (definitions, protocol ports,
cryptographic algorithms, framework components). WGU D488/KFO1 alignment with advanced
CompTIA Security+ and CISSP architectural domains, emphasizing Zero Trust Architecture
(ZTA) deployment, micro-segmentation troubleshooting, cryptographic failure analysis, PKI
certificate lifecycle management, and secure protocol selection. Each item includes four options
(A-D), one correct answer, and a concise rationale explaining why the correct option is best and
why distractors are incorrect.
Contents
Section 1: Security Architecture and Design Principles (Q1-Q20)
Section 2: Network and Infrastructure Security (Q21-Q40)
Section 3: Cryptography, PKI, and Identity Access Management (Q41-Q60)
Section 4: Risk Management, Compliance, and Business Continuity (Q61-Q80)
WGU Cybersecurity Architecture and Engineering (KFO1/D488) - Certification Exam 2026 Page 1
, Section 1: Security Architecture and Design Principles
Items 1-20 cover SABSA, TOGAF ADM, Zero Trust Architecture (PEP/PA), Bell-LaPadula and Biba models,
Saltzer-Schroeder principles, TCSEC/TCB, Brewer-Nash, Clark-Wilson, STRIDE/PASTA threat modeling,
defense in depth, fail secure, separation of duties, and the hierarchy of controls.
Q1: Which security architecture framework provides a risk-driven, business-attribute-based
methodology aligned with strategy?
A. TOGAF
B. SABSA (Sherwood Applied Business Security Architecture) [CORRECT]
C. ITIL
D. COBIT
Correct Answer: B
Rationale: SABSA is a risk-driven, business-attribute-based enterprise security architecture framework aligned
with business strategy. TOGAF is general enterprise architecture, ITIL is service management, and COBIT is IT
governance.
Q2: The core principle of Zero Trust Architecture (ZTA) is:
A. Trust all internal traffic by default
B. Never trust, always verify, with explicit per-request authorization [CORRECT]
C. Perimeter-only defense
D. Trust but verify once at login
Correct Answer: B
Rationale: ZTA enforces 'never trust, always verify' with continuous per-request authorization, assuming breach.
Trusting internal traffic and perimeter-only defense are legacy models contrary to ZTA.
Q3: Which ZTA component is responsible for making the real-time access decision based on policy?
A. Policy Administrator (PA) [CORRECT]
B. Policy Enforcement Point (PEP)
C. Trust Algorithm Provider
D. Identity Provider only
Correct Answer: A
Rationale: The PA makes the access decision; the PEP enforces it. The Identity Provider supplies identity claims
but does not make policy decisions on its own.
Q4: In the Bell-LaPadula model, the 'no read up' rule is also called the:
A. *-property (star property)
B. Simple Security Property [CORRECT]
C. Discretionary Security Property
D. Strong Tranquility
Correct Answer: B
Rationale: The Simple Security Property enforces 'no read up' (a subject cannot read objects of higher
classification). The *-property enforces 'no write down'.
WGU Cybersecurity Architecture and Engineering (KFO1/D488) - Certification Exam 2026 Page 2
, Q5: The Biba integrity model's primary rule is:
A. No read up
B. No read down (and no write up) [CORRECT]
C. Trust internal users
D. Default allow
Correct Answer: B
Rationale: Biba enforces 'no read down, no write up' to protect integrity. The other options either belong to
confidentiality models or violate Biba's goals.
Q6: Which principle ensures that no single person can complete a sensitive task alone?
A. Least privilege
B. Separation of Duties (SoD) [CORRECT]
C. Defense in depth
D. Economy of mechanism
Correct Answer: B
Rationale: Separation of Duties splits sensitive tasks across people to prevent fraud. Least privilege limits
permissions, defense in depth layers controls, and economy of mechanism favors simplicity.
Q7: The TOGAF Architecture Development Method (ADM) phase that defines the baseline and
target architecture is:
A. Phase A (Architecture Vision)
B. Phase B (Business Architecture)
C. Phases B, C, D define Business, Information Systems, and Technology architectures [CORRECT]
D. Phase H only
Correct Answer: C
Rationale: Phases B, C, and D define the Business, Information Systems (Applications & Data), and Technology
architectures. Phase A is vision; Phase H is change management.
Q8: Defense in depth is best described as:
A. A single strong firewall
B. Layered, redundant controls across people, process, and technology [CORRECT]
C. Antivirus only
D. Encryption alone
Correct Answer: B
Rationale: Defense in depth uses multiple, layered controls so failure of one does not compromise the system. A
single firewall, antivirus, or encryption alone is not defense in depth.
WGU Cybersecurity Architecture and Engineering (KFO1/D488) - Certification Exam 2026 Page 3
Engineering
(KFO1 / D488) Certification Exam
Aligned with 2026 Curriculum Standards
Western Governors University | Cybersecurity Architecture and Engineering
Cybersecurity Architecture | Network Engineering | Enterprise Security Design
Exam Composition: 80 multiple-choice questions distributed across four content domains.
Cognitive level distribution: ~30% recall, ~50% application, ~20% analysis. Approximately 75%
of items are scenario-based (enterprise network design, security incident response architecture,
compliance mapping, access control troubleshooting), with 25% direct (definitions, protocol ports,
cryptographic algorithms, framework components). WGU D488/KFO1 alignment with advanced
CompTIA Security+ and CISSP architectural domains, emphasizing Zero Trust Architecture
(ZTA) deployment, micro-segmentation troubleshooting, cryptographic failure analysis, PKI
certificate lifecycle management, and secure protocol selection. Each item includes four options
(A-D), one correct answer, and a concise rationale explaining why the correct option is best and
why distractors are incorrect.
Contents
Section 1: Security Architecture and Design Principles (Q1-Q20)
Section 2: Network and Infrastructure Security (Q21-Q40)
Section 3: Cryptography, PKI, and Identity Access Management (Q41-Q60)
Section 4: Risk Management, Compliance, and Business Continuity (Q61-Q80)
WGU Cybersecurity Architecture and Engineering (KFO1/D488) - Certification Exam 2026 Page 1
, Section 1: Security Architecture and Design Principles
Items 1-20 cover SABSA, TOGAF ADM, Zero Trust Architecture (PEP/PA), Bell-LaPadula and Biba models,
Saltzer-Schroeder principles, TCSEC/TCB, Brewer-Nash, Clark-Wilson, STRIDE/PASTA threat modeling,
defense in depth, fail secure, separation of duties, and the hierarchy of controls.
Q1: Which security architecture framework provides a risk-driven, business-attribute-based
methodology aligned with strategy?
A. TOGAF
B. SABSA (Sherwood Applied Business Security Architecture) [CORRECT]
C. ITIL
D. COBIT
Correct Answer: B
Rationale: SABSA is a risk-driven, business-attribute-based enterprise security architecture framework aligned
with business strategy. TOGAF is general enterprise architecture, ITIL is service management, and COBIT is IT
governance.
Q2: The core principle of Zero Trust Architecture (ZTA) is:
A. Trust all internal traffic by default
B. Never trust, always verify, with explicit per-request authorization [CORRECT]
C. Perimeter-only defense
D. Trust but verify once at login
Correct Answer: B
Rationale: ZTA enforces 'never trust, always verify' with continuous per-request authorization, assuming breach.
Trusting internal traffic and perimeter-only defense are legacy models contrary to ZTA.
Q3: Which ZTA component is responsible for making the real-time access decision based on policy?
A. Policy Administrator (PA) [CORRECT]
B. Policy Enforcement Point (PEP)
C. Trust Algorithm Provider
D. Identity Provider only
Correct Answer: A
Rationale: The PA makes the access decision; the PEP enforces it. The Identity Provider supplies identity claims
but does not make policy decisions on its own.
Q4: In the Bell-LaPadula model, the 'no read up' rule is also called the:
A. *-property (star property)
B. Simple Security Property [CORRECT]
C. Discretionary Security Property
D. Strong Tranquility
Correct Answer: B
Rationale: The Simple Security Property enforces 'no read up' (a subject cannot read objects of higher
classification). The *-property enforces 'no write down'.
WGU Cybersecurity Architecture and Engineering (KFO1/D488) - Certification Exam 2026 Page 2
, Q5: The Biba integrity model's primary rule is:
A. No read up
B. No read down (and no write up) [CORRECT]
C. Trust internal users
D. Default allow
Correct Answer: B
Rationale: Biba enforces 'no read down, no write up' to protect integrity. The other options either belong to
confidentiality models or violate Biba's goals.
Q6: Which principle ensures that no single person can complete a sensitive task alone?
A. Least privilege
B. Separation of Duties (SoD) [CORRECT]
C. Defense in depth
D. Economy of mechanism
Correct Answer: B
Rationale: Separation of Duties splits sensitive tasks across people to prevent fraud. Least privilege limits
permissions, defense in depth layers controls, and economy of mechanism favors simplicity.
Q7: The TOGAF Architecture Development Method (ADM) phase that defines the baseline and
target architecture is:
A. Phase A (Architecture Vision)
B. Phase B (Business Architecture)
C. Phases B, C, D define Business, Information Systems, and Technology architectures [CORRECT]
D. Phase H only
Correct Answer: C
Rationale: Phases B, C, and D define the Business, Information Systems (Applications & Data), and Technology
architectures. Phase A is vision; Phase H is change management.
Q8: Defense in depth is best described as:
A. A single strong firewall
B. Layered, redundant controls across people, process, and technology [CORRECT]
C. Antivirus only
D. Encryption alone
Correct Answer: B
Rationale: Defense in depth uses multiple, layered controls so failure of one does not compromise the system. A
single firewall, antivirus, or encryption alone is not defense in depth.
WGU Cybersecurity Architecture and Engineering (KFO1/D488) - Certification Exam 2026 Page 3