WGU D488 FINAL EXAM TEST BANK (2026/2027)
Cybersecurity Architecture & Engineering | 200
Verified Q&A with Rationales | A+ Graded
SECTION 1: NETWORK & APPLICATION SECURITY
1. A security team notices traffic coming from a country where the
organization does not have any business operations. Which of the
following could this be an indicator of?
A) High call volume
B) Odd network traffic
C) Geographic anomalies
D) Unauthorized changes
Correct Answer: C) Geographic anomalies
Rationale: Geographic anomalies refer to unexpected traffic patterns
originating from locations where the organization has no legitimate
presence, often signaling reconnaissance, policy violations, or potential
compromise .
2. A network technician needs to block several known malicious IP
addresses. Which type of rule should be created?
,A) Signature rules
B) Firewall rules
C) Behavior rules
D) Data loss prevention (DLP) rules
Correct Answer: B) Firewall rules
Rationale: Firewalls operate by enforcing rules that control incoming and
outgoing network traffic. Blocking traffic from specific malicious IP addresses
is a direct use of firewall functionality .
3. A security team recently enabled public access to a web application.
Developers report SQL injection attacks. Which solution should be
deployed to block these attacks?
A) Virtual Private Network (VPN)
B) Security Information and Event Management (SIEM)
C) Web Application Firewall (WAF)
D) Secure Shell (SSH)
Correct Answer: C) Web Application Firewall (WAF)
Rationale: A WAF is specifically designed to protect web applications by
filtering and monitoring HTTP traffic, blocking SQL injection attacks and
other web-based threats .
4. External contractors are using personal laptops to access the
corporate network. How can the organization prevent unapproved
devices from connecting?
A) Implementing a DMZ
B) Installing a hardware security module
,C) Implementing port security
D) Deploying a software firewall
Correct Answer: C) Implementing port security
Rationale: Port security restricts which devices can connect to a switch port
based on MAC addresses, effectively preventing unapproved devices from
accessing the network .
5. A publishing company needs intrusion detection, spam filtering,
content filtering, and antivirus with minimal infrastructure. Which
solution is most appropriate?
A) Anti-spam gateway
B) Proxy server
C) Unified Threat Management (UTM) appliance
D) Web Application Firewall (WAF)
Correct Answer: C) Unified Threat Management (UTM) appliance
Rationale: A UTM appliance combines multiple security functions (firewall,
intrusion detection, spam filtering, content filtering, antivirus) into a single
device, requiring minimal infrastructure .
6. The security team wants to deploy an IDS using an existing
signature database. Which detection technique should be used?
A) Intrusion detection
B) Deep packet inspection
C) Signature-based detection
D) Intrusion prevention
, Correct Answer: C) Signature-based detection
Rationale: Signature-based detection relies on a database of known attack
patterns to identify threats, making it the appropriate technique when a
signature database is already available .
7. After a security breach during deployment, the security team needs
a failback option for future application updates. Which should be
implemented?
A) Code scanner
B) Code signing
C) Versioning
D) Security Requirements Traceability Matrix (SRTM)
Correct Answer: C) Versioning
Rationale: Versioning allows the organization to roll back to a previous stable
version if a deployment causes issues, providing a reliable failback option .
8. A software development team needs mobile application builds
trusted by various devices. What should be implemented?
A) Code scanning
B) Regression testing
C) Continuous delivery
D) Code signing
Correct Answer: D) Code signing
Cybersecurity Architecture & Engineering | 200
Verified Q&A with Rationales | A+ Graded
SECTION 1: NETWORK & APPLICATION SECURITY
1. A security team notices traffic coming from a country where the
organization does not have any business operations. Which of the
following could this be an indicator of?
A) High call volume
B) Odd network traffic
C) Geographic anomalies
D) Unauthorized changes
Correct Answer: C) Geographic anomalies
Rationale: Geographic anomalies refer to unexpected traffic patterns
originating from locations where the organization has no legitimate
presence, often signaling reconnaissance, policy violations, or potential
compromise .
2. A network technician needs to block several known malicious IP
addresses. Which type of rule should be created?
,A) Signature rules
B) Firewall rules
C) Behavior rules
D) Data loss prevention (DLP) rules
Correct Answer: B) Firewall rules
Rationale: Firewalls operate by enforcing rules that control incoming and
outgoing network traffic. Blocking traffic from specific malicious IP addresses
is a direct use of firewall functionality .
3. A security team recently enabled public access to a web application.
Developers report SQL injection attacks. Which solution should be
deployed to block these attacks?
A) Virtual Private Network (VPN)
B) Security Information and Event Management (SIEM)
C) Web Application Firewall (WAF)
D) Secure Shell (SSH)
Correct Answer: C) Web Application Firewall (WAF)
Rationale: A WAF is specifically designed to protect web applications by
filtering and monitoring HTTP traffic, blocking SQL injection attacks and
other web-based threats .
4. External contractors are using personal laptops to access the
corporate network. How can the organization prevent unapproved
devices from connecting?
A) Implementing a DMZ
B) Installing a hardware security module
,C) Implementing port security
D) Deploying a software firewall
Correct Answer: C) Implementing port security
Rationale: Port security restricts which devices can connect to a switch port
based on MAC addresses, effectively preventing unapproved devices from
accessing the network .
5. A publishing company needs intrusion detection, spam filtering,
content filtering, and antivirus with minimal infrastructure. Which
solution is most appropriate?
A) Anti-spam gateway
B) Proxy server
C) Unified Threat Management (UTM) appliance
D) Web Application Firewall (WAF)
Correct Answer: C) Unified Threat Management (UTM) appliance
Rationale: A UTM appliance combines multiple security functions (firewall,
intrusion detection, spam filtering, content filtering, antivirus) into a single
device, requiring minimal infrastructure .
6. The security team wants to deploy an IDS using an existing
signature database. Which detection technique should be used?
A) Intrusion detection
B) Deep packet inspection
C) Signature-based detection
D) Intrusion prevention
, Correct Answer: C) Signature-based detection
Rationale: Signature-based detection relies on a database of known attack
patterns to identify threats, making it the appropriate technique when a
signature database is already available .
7. After a security breach during deployment, the security team needs
a failback option for future application updates. Which should be
implemented?
A) Code scanner
B) Code signing
C) Versioning
D) Security Requirements Traceability Matrix (SRTM)
Correct Answer: C) Versioning
Rationale: Versioning allows the organization to roll back to a previous stable
version if a deployment causes issues, providing a reliable failback option .
8. A software development team needs mobile application builds
trusted by various devices. What should be implemented?
A) Code scanning
B) Regression testing
C) Continuous delivery
D) Code signing
Correct Answer: D) Code signing