Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 67 pages
Exam (elaborations)

WGU D488 Cybersecurity Architecture and Engineering Comprehensive Practice Exam 2026–2027 Questions with Answers and Detailed Rationales

Document preview thumbnail
Preview 4 out of 67 pages

Covering secure enterprise architecture, security engineering, cryptography, security models, vulnerability assessment, defense-in-depth, security controls, physical security, risk mitigation, and secure infrastructure design. Designed for focused graduate-level preparation, this resource uses practical cybersecurity scenarios to strengthen architectural analysis, security engineering decisions, and risk-based problem-solving. WGU’s current catalog identifies D488 as a 4-CU Cybersecurity Architecture and Engineering course, while WGU describes the course as developing advanced skills for designing secure enterprise architecture solutions and protecting organizational data and policies.

Content preview

WGU D488 Cybersecurity
Architecture and Engineering
Comprehensive Practice Exam
2026–2027 Questions with
Answers and Detailed
Rationales

Question 1
A financial institution is designing a new enterprise security
architecture. The security architect wants security requirements
to be derived from business objectives, regulatory obligations,
threat conditions, and organizational risk tolerance before
specific technologies are selected.
Which approach BEST supports this objective?
A. Select security products first and map them to business
objectives afterward
B. Develop security requirements from business and risk

,requirements before selecting controls
C. Deploy the same security controls to every system regardless
of data classification
D. Allow each application team to independently define its
security architecture
Answer: B
Rationale: Effective security architecture begins with business
requirements, risk, regulatory obligations, and threat
considerations. Technical controls should implement those
requirements rather than define them. Selecting products first
can create unnecessary complexity, gaps, and vendor-driven
architecture.


Question 2
An organization wants to reduce the likelihood that
compromise of one security control will result in complete
compromise of an enterprise application.
Which principle should the architect emphasize?
A. Single sign-on
B. Defense in depth
C. Centralized logging
D. Data minimization
Answer: B

,Rationale: Defense in depth uses multiple complementary
security mechanisms so that failure or bypass of one control
does not automatically result in total compromise. Controls may
include segmentation, identity enforcement, encryption,
endpoint protection, monitoring, and application-layer
defenses.


Question 3
A security architect is evaluating a proposed architecture and
discovers that a single firewall represents the only security
barrier between the internet and a sensitive internal database.
Which architectural weakness is MOST significant?
A. Excessive encryption
B. Lack of defense in depth
C. Excessive authentication
D. Over-segmentation
Answer: B
Rationale: A single security barrier creates a single point of
defensive failure. A layered architecture should provide multiple
controls between external threats and sensitive assets.


Question 4

, A company wants security controls to remain effective even
when an attacker has successfully compromised an employee
workstation.
Which architecture BEST supports this requirement?
A. Perimeter-only security
B. Zero-trust architecture
C. Flat network architecture
D. Single-factor authentication
Answer: B
Rationale: Zero trust assumes that network location alone does
not establish trust. Access is continuously evaluated using
identity, device posture, context, policy, and other signals.
Compromise of one endpoint therefore does not automatically
provide unrestricted internal access.


Question 5
A security architect is documenting the relationships between
business processes, information assets, applications,
infrastructure, and security controls.
What is the PRIMARY benefit of this documentation?
A. Eliminating the need for vulnerability management
B. Establishing traceability between business requirements and

Document information

Uploaded on
August 12, 2026
Number of pages
67
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$23.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
2
Followers
0
Items
509
Last sold
4 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions