WGU D488 CYBERSECURITY ARCHITECTURE
AND ENGINEERING OA 2026 ENTERPRISE
SECURITY DESIGN AND RISK MANAGEMENT
REVIEW PACKAGE
◉ Which type of software testing should be used when there has
been a change within the existing environment?
A - Regression Testing
B - Penetration Testing
C - Requirements Testing
D - Release Testing.
Answer: A - Regression Testing
Regression testing ensures that recent changes within the
environment have not introduced new defects or broken existing
functionality.
◉ Which security technique should be used to detect a weak
password that may match common dictionary words?
A - Password Spraying
B - Password Auditing
C - Password Guessing
,D - Password History
Answer: B - Password Auditing
Password auditing allows for existing passwords to be compared
against known weak passwords to help determine the security of a
credential.
◉ What should an organization implement if it wants users of their
site to provide a password, memorable word, and pin?
A - Multi-factor authentication (MFA)
B - Two-factor authentication (2FA)
C - Two-step verification
D - Single-factor authentication
Answer: A - Multi-factor authentication
MFA enhances security by requiring multiple forms of
authentication, therefore reducing the risk of unauthorized access.
◉ A network technician is asked by their manager to update security
to block several known bad actor IP addresses.
A - Signature rules
B - Firewall rules
C - Behavior rules
,D - Data loss prevention (DLP) rules
Answer: B - Firewall rules
Firewall rules can be set up to deny traffic coming from known
malicious IP addresses.
◉ On a shopping website, there is a 500-millisecond delay when the
authorized payment button is selected for purchases. Attackers have
been running a script to alter the final payment that takes 200
milliseconds. Which vulnerability on the website is being targeted
by the attackers?
A - Buffer Overflow
B - Integer Overflow
C - Broken Authentication
D - Race Condition
Answer: D - Race Condition
A race condition occurs when multiple processes or actions are
executed simultaneously, and the outcome depends on the sequence
or timing of events.
◉ A company wants to provide laptops to its employees so they can
work remotely. What should be implemented to ensure only work
applications can be installed on company laptops?
, A - Containerization
B - Token-based access
C - Patch repository
D - Whitelisting
Answer: D - Whitelisting
Whitelisting ensures that only approved applications can be
installed and executed on company laptops.
◉ What should a business use to provide non-repudiation for emails
between employees?
A - TLS/SSL
B - AES-256
C - S/MIME
D - IPSec
Answer: C - S/MIME (Secure/Multipurpose Internet Mail
Extensions)
S/MIME provides non-repudiation for emails by using digital
signatures.
◉ Which strategy is appropriate for a risk management team to
determine if a business has insufficient security controls?
AND ENGINEERING OA 2026 ENTERPRISE
SECURITY DESIGN AND RISK MANAGEMENT
REVIEW PACKAGE
◉ Which type of software testing should be used when there has
been a change within the existing environment?
A - Regression Testing
B - Penetration Testing
C - Requirements Testing
D - Release Testing.
Answer: A - Regression Testing
Regression testing ensures that recent changes within the
environment have not introduced new defects or broken existing
functionality.
◉ Which security technique should be used to detect a weak
password that may match common dictionary words?
A - Password Spraying
B - Password Auditing
C - Password Guessing
,D - Password History
Answer: B - Password Auditing
Password auditing allows for existing passwords to be compared
against known weak passwords to help determine the security of a
credential.
◉ What should an organization implement if it wants users of their
site to provide a password, memorable word, and pin?
A - Multi-factor authentication (MFA)
B - Two-factor authentication (2FA)
C - Two-step verification
D - Single-factor authentication
Answer: A - Multi-factor authentication
MFA enhances security by requiring multiple forms of
authentication, therefore reducing the risk of unauthorized access.
◉ A network technician is asked by their manager to update security
to block several known bad actor IP addresses.
A - Signature rules
B - Firewall rules
C - Behavior rules
,D - Data loss prevention (DLP) rules
Answer: B - Firewall rules
Firewall rules can be set up to deny traffic coming from known
malicious IP addresses.
◉ On a shopping website, there is a 500-millisecond delay when the
authorized payment button is selected for purchases. Attackers have
been running a script to alter the final payment that takes 200
milliseconds. Which vulnerability on the website is being targeted
by the attackers?
A - Buffer Overflow
B - Integer Overflow
C - Broken Authentication
D - Race Condition
Answer: D - Race Condition
A race condition occurs when multiple processes or actions are
executed simultaneously, and the outcome depends on the sequence
or timing of events.
◉ A company wants to provide laptops to its employees so they can
work remotely. What should be implemented to ensure only work
applications can be installed on company laptops?
, A - Containerization
B - Token-based access
C - Patch repository
D - Whitelisting
Answer: D - Whitelisting
Whitelisting ensures that only approved applications can be
installed and executed on company laptops.
◉ What should a business use to provide non-repudiation for emails
between employees?
A - TLS/SSL
B - AES-256
C - S/MIME
D - IPSec
Answer: C - S/MIME (Secure/Multipurpose Internet Mail
Extensions)
S/MIME provides non-repudiation for emails by using digital
signatures.
◉ Which strategy is appropriate for a risk management team to
determine if a business has insufficient security controls?