Comprehensive Question & Answer
Guide for WGU D490 MSCIA Graduate
Capstone Task 1 Section A: AI-Driven
Cybersecurity, Governance, Risk,
Compliance, and Ethical AI
Foundations (2026/2027)
1. What is the primary distinction between Artificial
Intelligence (AI) and Machine Learning (ML) in the context of
cybersecurity?
Correct Answer: B – AI is the broader concept of machines
simulating human intelligence, while ML is a subset focused on
learning from data without explicit programming.
Rationale: AI encompasses a wide range of techniques aimed at
mimicking cognitive functions. ML, a core component of AI,
enables systems to automatically learn and improve from
experience, which is fundamental for developing adaptive
cybersecurity defenses.
,2. In the context of "AIaaS" (AI as a Service), what is the most
significant security governance challenge for an organization?
Correct Answer: C – The shift of security control and data
ownership to a third-party provider, complicating compliance and
risk management.
Rationale: AIaaS introduces a shared responsibility model. The
core governance challenge is maintaining visibility, control, and
compliance (e.g., GDPR, HIPAA) when sensitive data and security
decision-making are partially outsourced.
3. Which of the following best describes an "Adversarial AI"
attack?
Correct Answer: B – The manipulation of an AI model's input
data to cause the model to make a mistake, such as misclassifying
a malicious file as benign.
Rationale: Adversarial AI specifically focuses on exploiting the
vulnerabilities of AI/ML models themselves. This includes
techniques like evasion attacks (perturbing input) or poisoning
attacks (corrupting training data), which are distinct from using AI
as a tool for attacks.
4. What is a "model poisoning" attack in the context of AI
security?
,Correct Answer: B – A technique where an attacker introduces
malicious data into the model's training set to corrupt its
behavior.
Rationale: Model poisoning is a supply chain attack on AI. By
compromising the data used to train the model, an attacker can
cause it to learn incorrect patterns, such as classifying all threats
as benign or opening a hidden backdoor.
5. What is the primary advantage of an AI-powered User and
Entity Behavior Analytics (UEBA) system over traditional rule-
based alerting in a Security Operations Center (SOC)?
Correct Answer: C – It can dynamically learn and identify subtle,
anomalous behaviors indicative of insider threats or compromised
accounts that deviate from established baselines.
Rationale: UEBA systems leverage machine learning to establish
behavioral baselines and detect deviations that may indicate
insider threats, compromised accounts, or other advanced threats
that traditional rule-based systems might miss. They augment,
rather than replace, human analysts.
6. Which of the following is an example of a "safety" risk in
an AI-driven cybersecurity context?
, Correct Answer: B – The AI model's false positive rate causes
analyst burnout, leading to a critical alert being missed.
Rationale: Safety risks in AI pertain to unintended and harmful
outcomes from the system's operation. A high false positive rate
is an operational safety risk that can lead to alert fatigue, causing
human operators to ignore or mishandle real threats, ultimately
increasing organizational risk.
7. What is the primary purpose of an AI "sandbox"
environment in cybersecurity?
Correct Answer: B – To provide an isolated environment for
safely testing and analyzing potentially malicious code or AI
models without risking production systems.
Rationale: A sandbox environment provides isolation for testing
and analysis, allowing security teams to observe the behavior of
suspicious files or AI models without exposing production systems
to potential harm.
8. What distinguishes "explainable AI" (XAI) from traditional
"black box" AI models in cybersecurity?
Correct Answer: B – XAI provides human-understandable
explanations for its decisions and predictions, enabling better
trust, auditability, and compliance.
Guide for WGU D490 MSCIA Graduate
Capstone Task 1 Section A: AI-Driven
Cybersecurity, Governance, Risk,
Compliance, and Ethical AI
Foundations (2026/2027)
1. What is the primary distinction between Artificial
Intelligence (AI) and Machine Learning (ML) in the context of
cybersecurity?
Correct Answer: B – AI is the broader concept of machines
simulating human intelligence, while ML is a subset focused on
learning from data without explicit programming.
Rationale: AI encompasses a wide range of techniques aimed at
mimicking cognitive functions. ML, a core component of AI,
enables systems to automatically learn and improve from
experience, which is fundamental for developing adaptive
cybersecurity defenses.
,2. In the context of "AIaaS" (AI as a Service), what is the most
significant security governance challenge for an organization?
Correct Answer: C – The shift of security control and data
ownership to a third-party provider, complicating compliance and
risk management.
Rationale: AIaaS introduces a shared responsibility model. The
core governance challenge is maintaining visibility, control, and
compliance (e.g., GDPR, HIPAA) when sensitive data and security
decision-making are partially outsourced.
3. Which of the following best describes an "Adversarial AI"
attack?
Correct Answer: B – The manipulation of an AI model's input
data to cause the model to make a mistake, such as misclassifying
a malicious file as benign.
Rationale: Adversarial AI specifically focuses on exploiting the
vulnerabilities of AI/ML models themselves. This includes
techniques like evasion attacks (perturbing input) or poisoning
attacks (corrupting training data), which are distinct from using AI
as a tool for attacks.
4. What is a "model poisoning" attack in the context of AI
security?
,Correct Answer: B – A technique where an attacker introduces
malicious data into the model's training set to corrupt its
behavior.
Rationale: Model poisoning is a supply chain attack on AI. By
compromising the data used to train the model, an attacker can
cause it to learn incorrect patterns, such as classifying all threats
as benign or opening a hidden backdoor.
5. What is the primary advantage of an AI-powered User and
Entity Behavior Analytics (UEBA) system over traditional rule-
based alerting in a Security Operations Center (SOC)?
Correct Answer: C – It can dynamically learn and identify subtle,
anomalous behaviors indicative of insider threats or compromised
accounts that deviate from established baselines.
Rationale: UEBA systems leverage machine learning to establish
behavioral baselines and detect deviations that may indicate
insider threats, compromised accounts, or other advanced threats
that traditional rule-based systems might miss. They augment,
rather than replace, human analysts.
6. Which of the following is an example of a "safety" risk in
an AI-driven cybersecurity context?
, Correct Answer: B – The AI model's false positive rate causes
analyst burnout, leading to a critical alert being missed.
Rationale: Safety risks in AI pertain to unintended and harmful
outcomes from the system's operation. A high false positive rate
is an operational safety risk that can lead to alert fatigue, causing
human operators to ignore or mishandle real threats, ultimately
increasing organizational risk.
7. What is the primary purpose of an AI "sandbox"
environment in cybersecurity?
Correct Answer: B – To provide an isolated environment for
safely testing and analyzing potentially malicious code or AI
models without risking production systems.
Rationale: A sandbox environment provides isolation for testing
and analysis, allowing security teams to observe the behavior of
suspicious files or AI models without exposing production systems
to potential harm.
8. What distinguishes "explainable AI" (XAI) from traditional
"black box" AI models in cybersecurity?
Correct Answer: B – XAI provides human-understandable
explanations for its decisions and predictions, enabling better
trust, auditability, and compliance.