Cybersecurity Architecture
and Engineering
Objective Assessment
Comprehensive Test Bank - 350 Questions
A+ Verified
8 Sections | 350 Questions | With Answer Key
2026-2027 Edition
Sections Covered
1. Security Architecture Principles and Models
2. Security Engineering
3. Secure Network Design
4. Identity and Access Management
5. Security Operations and Incident Response
6. Risk Management and Compliance
7. Cryptography and Data Protection
8. Business Continuity and Disaster Recovery
For Educational Use Only - Western Governors University D488 Preparation
This test bank is designed to help students prepare for the D488 Objective Assessment
,Section 1: Security Architecture Principles
A financial institution is designing a new core banking platform. The CISO requires that no single security control
1 failure exposes customer data. The architecture team must ensure multiple independent security mechanisms
protect each critical asset. Which architecture principle best guides this design approach?
A. A. Least privilege ensures users only access necessary data
B. B. Defense in depth requires layered, independent security controls
C. C. Separation of duties divides tasks among different personnel
D. D. Fail-safe defaults deny access when controls malfunction
A healthcare organization is migrating to a zero-trust architecture. The network architect must redesign the
2 perimeter model so that every access request is verified regardless of source location. Which foundational
zero-trust principle directly supports this requirement?
A. A. Trust but verify for internal network traffic
B. B. Never trust, always verify for every access request
C. C. Implicit trust for authenticated domain users
D. D. Perimeter-based verification for external users only
An enterprise adopting SABSA needs to align security architecture with business objectives. The lead architect
3 maps business attributes to security attributes throughout six layers. Which SABSA layer specifically defines the
security concepts and relationships at the logical level?
A. A. Contextual layer defines the business environment
B. B. Conceptual layer defines security concepts and relationships
C. C. Physical layer defines technology mechanisms
D. D. Component layer defines operational procedures
A manufacturing firm must implement a security architecture that supports business agility while maintaining
4 regulatory compliance. The architect chooses TOGAF ADM to integrate security into enterprise architecture.
During which ADM phase is the security architecture roadmap typically developed?
A. A. Phase A establishes the architecture vision
B. B. Phase E defines opportunities and migration planning
C. C. Phase D develops technology architecture
D. D. Phase F migrates planning with implementation governance
,Section 1: Security Architecture Principles
A defense contractor is implementing the NIST Cybersecurity Framework. The CISO needs to prioritize activities
5 that reduce cybersecurity risk aligned with organizational objectives. Which CSF function focuses on developing
organizational understanding to manage cybersecurity risk?
A. A. Protect function implements safeguards
B. B. Identify function develops organizational understanding
C. C. Detect function enables timely discovery of events
D. D. Respond function supports containment of incidents
A cloud provider is designing a multi-tenant SaaS platform. The security architect must ensure that a tenant's
6 data remains completely isolated from other tenants at every layer. Which architecture pattern best enforces this
strict isolation requirement?
A. A. Shared database with row-level security
B. B. Siloed deployment with dedicated infrastructure per tenant
C. C. Shared compute with container namespaces
D. D. Pooled resources with virtual LAN segmentation
An automotive company is implementing secure-by-design principles for connected vehicle systems. The
7 engineering team must integrate security from the earliest design stages rather than adding it later. Which secure
design principle best describes this approach?
A. A. Economy of mechanism reduces complexity
B. B. Security by design integrates security from inception
C. C. Open design assumes attackers know the design
D. D. Complete mediation validates every access request
A retail chain is implementing a microservices architecture. The security architect must ensure that if one service
8 is compromised, the attacker cannot easily move laterally to other services. Which principle should guide the
segmentation strategy?
A. A. Minimization of attack surface reduces exposed components
B. B. Segmentation and compartmentalization limits lateral movement
C. C. Fail-safe defaults prevent unauthorized access
D. D. Least common mechanism avoids shared resources
, Section 1: Security Architecture Principles
A government agency is implementing a security architecture based on the Zachman Framework. The enterprise
9 architect needs to align security questions across multiple dimensions. Which Zachman dimension addresses
the question 'When does the security control operate?'
A. A. What dimension describes the data
B. B. When dimension describes the timing
C. C. Who dimension describes the people
D. D. How dimension describes the functions
A pharmaceutical company is designing a critical drug manufacturing control system. The safety engineer must
10 ensure that if the security system fails, the manufacturing process defaults to a safe state. Which security design
principle applies here?
A. A. Least privilege restricts user permissions
B. B. Fail-safe defaults ensure safe state on failure
C. C. Separation of duties prevents fraud
D. D. Defense in depth provides layered controls
An energy utility is modernizing its SCADA architecture. The security architect must ensure that the security
11 model does not depend on the secrecy of the architecture or design. Which principle supports this requirement?
A. A. Open design does not rely on secrecy for security
B. B. Security through obscurity hides implementation details
C. C. Least privilege limits access rights
D. D. Psychological acceptability ensures user compliance
A financial services firm is implementing a security architecture using the Sherwood Applied Business Security
12 Architecture (SABSA). The architect needs to derive security requirements from business attributes. Which
SABSA component provides the methodology for this derivation?
A. A. SABSA framework provides a lifecycle model
B. B. SABSA matrix maps business attributes to security attributes
C. C. SABSA service management provides operational support
D. D. SABSA model provides the conceptual layer definitions