A Actual Exam 2026/2027 – Complete Capstone Proposal
Questions with Detailed Rationales | 100% Verified | Pass
Guaranteed – A+ Graded
Q1: A graduate student is selecting a capstone topic and considers proposing
"Improving organizational cybersecurity." The evaluator would most likely respond with:
A. Immediate approval because the topic is broadly relevant
B. A request to narrow the scope because the topic is too vague and lacks specificity
[CORRECT]
C. A suggestion to expand the topic to include all industries globally
D. A pass because cybersecurity is always an acceptable capstone topic
Correct Answer: B
Rationale: WGU D490 Task 1 requires a specific, manageable security problem that can
be addressed with a technology-supported solution. "Improving organizational
cybersecurity" is too broad and lacks definable boundaries, deliverables, and success
criteria. The topic must be narrowed to a concrete problem.
Q2: A student proposes a capstone project based on their real-world experience
implementing a SIEM solution at their current employer. This approach is:
A. Unacceptable because capstone topics must be purely theoretical
B. Acceptable and often encouraged because real experience provides context, data,
and stakeholder identification [CORRECT]
,C. Only acceptable if the student changes all identifying details and fabricates data
D. Rejected because capstone projects cannot involve the student's employer
Correct Answer: B
Rationale: WGU encourages students to select topics based on real-world experience
when possible, as this provides authentic context, identifiable stakeholders, and
measurable outcomes. The project must still meet academic standards, but real
experience strengthens the proposal.
Q3: In Task 1, the student must clearly distinguish between the proposal (Task 1) and
the implementation tasks (Tasks 2 and 3). The primary distinction is that Task 1:
A. Contains the fully implemented solution with all technical configurations
B. Defines the security problem and proposes a technology-supported solution without
yet implementing it [CORRECT]
C. Is a literature review only and does not include a problem statement
D. Includes the final presentation slides and defense script
Correct Answer: B
Rationale: Task 1 is the Capstone Project Proposal that defines the security problem,
establishes scope, identifies stakeholders, and outlines the proposed approach.
Implementation, architecture review, and final defense occur in Tasks 2 and 3. Task 1
must be approved before Task 2 is graded.
Q4: A student is drafting the problem definition for Task 1. Which element is most
critical to include?
, A. A detailed history of all cybersecurity breaches since 1990
B. A specific description of the security problem with organizational context and why it
matters [CORRECT]
C. A list of all possible solutions without selecting one
D. The student's personal opinion about cybersecurity trends
Correct Answer: B
Rationale: The problem definition must describe the security problem in detail with
appropriate organizational context, explain its importance to the organization and
industry, and establish the need for a solution. Vague historical overviews,
undifferentiated solution lists, or unsupported opinions do not meet Task 1 standards.
Q5: When identifying stakeholders for a capstone project, a student should include:
A. Only the student's academic mentor
B. Only external vendors who might sell solutions
C. Both internal stakeholders (IT team, management, end users) and external
stakeholders (regulators, customers, partners) affected by the security problem
[CORRECT]
D. Only hypothetical stakeholders that the student invents
Correct Answer: C
Rationale: Comprehensive stakeholder identification includes internal parties (those
within the organization who are affected by or can influence the project) and external