Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 126 pages
Exam (elaborations)

WGU D488 Cybersecurity Architecture & Engineering OA EXAM LATEST 230 QUESTIONS AND 100- Verified ANSWERS JUST RELEASED .

Document preview thumbnail
Preview 4 out of 126 pages

WGU D488 Cybersecurity Architecture & Engineering OA EXAM LATEST 230 QUESTIONS AND 100- Verified ANSWERS JUST RELEASED .

Content preview

WGU D488 Cybersecurity Architecture & Engineering
OA EXAM LATEST 230 QUESTIONS AND 100% Verified
ANSWERS JUST RELEASED

A developer is looking for a solution that will help to detect flaws, bugs, errors, and defects in
applications running in production environments. What is this method called?
A - Continuous integration
B - Continuous delivery
C - Continuous deployment
D - Continuous monitoring - answer>>D - Continuous monitoring


Continuous monitoring mechanisms detect flaws, bugs, errors, and defects. Although often used for
security, developers could use it to look for issues while generating new code.


Continuous integration (CI) is the principle that developers should commit and test updates often,
every day, or sometimes even more frequently.


Continuous delivery is about testing all of the infrastructures that support the application, including
networking, database functionality, client software, and security.


Continuous deployment is the separate process of making changes to the production environment
using configuration management platforms to support the newly updated application.


A security engineer is looking at various methods to use identity proofing. Which of the following are
identity proofing methods? Select 3 answers.
A - Diameter
B - 2FA
C - Out-of-band mechanisms

,D - TOTP - answer>>B, C & D; 2FA, Out of band mechanisms, & TOTP


Two-Factor Authentication (2FA) is an identity proofing method that combines either an ownership-
based smart card or biometric identifier with something a user knows, such as a password or PIN.


Out-of-band mechanisms are another identity proofing method that generates a software token on a
server and sends it to a resource assumed to be safely controlled by the user.


The Time-based One-time Password (TOTP) is a proofing method that is a refinement of the Hashed
Message Authentication Code One-time Password (HOTP).


Diameter improves upon Remote Authentication Dial-in User Service (RADIUS) by strengthening some
of its weaknesses. Diameter is a stronger protocol in many ways but is not as widespread in its
implementation due to the lack of products using it.


A vulnerability manager is onboarding developers to the vulnerability management program and wants
to focus on integrating security from the very beginning. What is the first step of the software
development lifecycle the manager should integrate?
A - Requirements gathering
B - Solution design
C - Test formulation
D - Code testing - answer>>A - Requirements gathering


Planning and requirements gathering is the first step of the software development life cycle (SDLC). It
identifies policy, standard, and regulatory requirements that govern how software operates.


Solution design is the second step incorporating secure coding patterns and best practice guidance
from organizations, such as the Open Web Application Security Project (OWASP).


Formulation of tests and coding is the third step. This step uses Static Code Analysis tools, software
linters, and automated unit tests to identify vulnerabilities while writing code.

,Testing and evaluation of code is the fourth step. It uses Dynamic Code Analysis tools to evaluate
application security and test for the existence of known vulnerabilities.


The vulnerability management lead has been enhancing the security posture year after year and is
looking at security coding standards. What are some sources the management lead could recommend
to the organization? (Select all that apply.)
A - NIST 800-53
B - Carnegie-Mellon Software Engineering Institute
C - OWASP
D - COBIT - answer>>B & C; Carnegie-Mellon Software Engineering Institute & OWASP


A site developer has recently experienced issues with Cross-Site Script Inclusion attacks. Which of the
following response headers could the site developer use to mitigate this attack?
A - COOP
B - COEP
C - CORP
D - XFO - answer>>C - CORP


A developer can set security options in the response header returned by a web server to a client. Such
is the case with Cross-Origin-Resource-Policy (CORP), which protects against speculative execution
(such as Spectre) and Cross-Site Script (XSS) Inclusion attacks.


Cross-Origin-Opener-Policy (COOP) changes the way documents load to prevent cross-origin attacks.
The CORP header would help to prevent XSS Inclusion attacks.


Cross-Origin-Embedder-Policy (COEP) limits documents from loading from origins other than the
source. This would not help against XSS Inclusion attacks.


X-Frame-Options (XFO) defines whether content can be displayed using frames to defend against
clickjacking attacks. This also would not help against XSS Inclusion attacks.

, A security manager is looking for a solution that contains software to monitor and report the day-to-
day operations of an enterprise and the status of various resources and activities. Which of the
following should the security manager consider?
A - CMDB
B - CMS
C - ERP
D - CRM - answer>>C - ERP (Enterprise Resource Planning)


An enterprise resource planning (ERP) solution contains software that monitors the daily operations of
an enterprise. The ERP also reports on the status of various resources and activities.


A configuration management database (CMDB) is a database that contains information on assets and
components within an enterprise's IT environment.


A content management system (CMS) enables non-technical users with the ability to create, manage
and modify content on a website.


A customer relationship management (CRM) system is a platform that enables a company to more
easily work with customers, that includes the data about the customers.


A storage administrator is evaluating various components of the data life cycle to refine processes and
enhance security. What are the first three steps of the data life cycle? (Select all that apply.)
A - Create
B - Store
C - Archive
D - Use - answer>>A, B, & D; Create, Store, and Use


A data center administrator for a small manufacturer has heard a lot of information about 3D printers
and is considering whether one would be useful. What are some of the benefits? Select 3 answers.

Document information

Uploaded on
August 12, 2026
Number of pages
126
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$19.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
dennohz2000
4.0
(83)
Sold
361
Followers
46
Items
7967
Last sold
2 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions