WGU D469 PERFORMANCE ASSESSMENT EXAM – QUESTIONS AND ANSWERS
| VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES | DOWNLOAD
AND PASS | LATEST EXAM UPDATE 2026/2027
Core Domains:
1. Information Technology Governance and Strategy
2. Risk Management and Compliance Frameworks
3. Business Continuity and Disaster Recovery Planning
4. IT Infrastructure and Operations Management
5. Data Security and Privacy Principles
6. Systems Development Life Cycle (SDLC) and Project Management
7. Emerging Technologies and Digital Transformation
8. Vendor Management and Procurement
9. Regulatory and Legal Compliance (GDPR, HIPAA, SOX)
10. Professional Ethics and IT Standards
Introduction
This comprehensive performance assessment is designed to rigorously evaluate
your mastery of the knowledge, skills, and abilities essential for success in the WGU
D469 course. The examination encompasses a wide range of topics from
foundational theoretical concepts to advanced applied practices in the field of
information technology management. You will encounter a diverse array of
multiple-choice questions, including many scenario-based items that assess your
ability to make strategic decisions in realistic professional contexts. This assessment
emphasizes critical thinking, ethical reasoning, and the practical application of
regulatory and compliance frameworks. A balanced distribution of question
difficulty ensures a thorough evaluation of your readiness. Prepare to demonstrate
your capacity to synthesize complex information and apply professional standards
to solve real-world problems.
,════════════════════════════════════
SECTION ONE: QUESTIONS 1–50
════════════════════════════════════
1. Which IT governance framework provides a comprehensive set of controls
and processes designed to help organizations align their IT strategy with
business goals and optimize the value derived from IT investments?
A. ITIL
B. COBIT
C. ISO 27001
D. CMMI
🟢 Correct Answer: B. COBIT
🔴 Explanation: COBIT (Control Objectives for Information and Related
Technologies) is specifically designed to bridge the gap between business goals,
IT strategy, and governance, providing a comprehensive framework for enterprise
IT governance and management.
──────────────────────────────────────
2. A global company is concerned about complying with the General Data
Protection Regulation (GDPR). Which fundamental principle requires that
organizations must obtain explicit, unambiguous consent from individuals
before collecting their personal data?
A. Data Minimization
B. Storage Limitation
C. Accountability
D. Lawfulness, Fairness, and Transparency
🟢 Correct Answer: D. Lawfulness, Fairness, and Transparency
,🔴 Explanation: This principle mandates that data processing must have a legal
basis, be fair to the data subject, and be transparent, requiring clear consent. It is
a foundational requirement under GDPR.
──────────────────────────────────────
3. In the context of a Business Impact Analysis (BIA), what is the primary
objective of identifying the Maximum Tolerable Downtime (MTD) for a critical
business process?
A. To define the cost of implementing a new IT system.
B. To establish the longest period of time a business can survive without that
process.
C. To allocate the budget for a disaster recovery site.
D. To determine the exact number of employees required to restore the process.
🟢 Correct Answer: B. To establish the longest period of time a business can
survive without that process.
🔴 Explanation: The MTD is a key metric in BIA that represents the time a
business can function without a specific process before negative impacts become
unacceptable. It informs the Recovery Time Objective (RTO).
──────────────────────────────────────
4. A project manager is leading an IT system upgrade using a Scrum
framework. During which event does the Scrum Team inspect the Increment,
adapt the Product Backlog, and define a new Sprint Goal based on the work
completed so far?
A. Daily Stand-up
B. Sprint Review
C. Sprint Retrospective
D. Sprint Planning
, 🟢 Correct Answer: B. Sprint Review
🔴 Explanation: The Sprint Review is held at the end of the Sprint to inspect the
Increment and collaborate on what to do next. The Product Backlog is adapted,
and new objectives are discussed for the next Sprint.
──────────────────────────────────────
5. An organization has a strict password policy that requires users to change
their passwords every 90 days. Which type of control does this password policy
represent?
A. Administrative Control
B. Technical Control
C. Physical Control
D. Deterrent Control
🟢 Correct Answer: A. Administrative Control
🔴 Explanation: A password policy is a rule or procedure that governs human
behavior. It is an administrative (or procedural) control, as it defines expectations
and requirements for personnel.
──────────────────────────────────────
6. The concept of 'Defense in Depth' uses multiple layers of security. Which of
the following correctly lists layers of defense from outermost to innermost?
A. Perimeter, Network, Host, Application, Data
B. Data, Application, Host, Network, Perimeter
C. Application, Data, Host, Network, Perimeter
D. Perimeter, Host, Network, Application, Data
🟢 Correct Answer: A. Perimeter, Network, Host, Application, Data
| VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES | DOWNLOAD
AND PASS | LATEST EXAM UPDATE 2026/2027
Core Domains:
1. Information Technology Governance and Strategy
2. Risk Management and Compliance Frameworks
3. Business Continuity and Disaster Recovery Planning
4. IT Infrastructure and Operations Management
5. Data Security and Privacy Principles
6. Systems Development Life Cycle (SDLC) and Project Management
7. Emerging Technologies and Digital Transformation
8. Vendor Management and Procurement
9. Regulatory and Legal Compliance (GDPR, HIPAA, SOX)
10. Professional Ethics and IT Standards
Introduction
This comprehensive performance assessment is designed to rigorously evaluate
your mastery of the knowledge, skills, and abilities essential for success in the WGU
D469 course. The examination encompasses a wide range of topics from
foundational theoretical concepts to advanced applied practices in the field of
information technology management. You will encounter a diverse array of
multiple-choice questions, including many scenario-based items that assess your
ability to make strategic decisions in realistic professional contexts. This assessment
emphasizes critical thinking, ethical reasoning, and the practical application of
regulatory and compliance frameworks. A balanced distribution of question
difficulty ensures a thorough evaluation of your readiness. Prepare to demonstrate
your capacity to synthesize complex information and apply professional standards
to solve real-world problems.
,════════════════════════════════════
SECTION ONE: QUESTIONS 1–50
════════════════════════════════════
1. Which IT governance framework provides a comprehensive set of controls
and processes designed to help organizations align their IT strategy with
business goals and optimize the value derived from IT investments?
A. ITIL
B. COBIT
C. ISO 27001
D. CMMI
🟢 Correct Answer: B. COBIT
🔴 Explanation: COBIT (Control Objectives for Information and Related
Technologies) is specifically designed to bridge the gap between business goals,
IT strategy, and governance, providing a comprehensive framework for enterprise
IT governance and management.
──────────────────────────────────────
2. A global company is concerned about complying with the General Data
Protection Regulation (GDPR). Which fundamental principle requires that
organizations must obtain explicit, unambiguous consent from individuals
before collecting their personal data?
A. Data Minimization
B. Storage Limitation
C. Accountability
D. Lawfulness, Fairness, and Transparency
🟢 Correct Answer: D. Lawfulness, Fairness, and Transparency
,🔴 Explanation: This principle mandates that data processing must have a legal
basis, be fair to the data subject, and be transparent, requiring clear consent. It is
a foundational requirement under GDPR.
──────────────────────────────────────
3. In the context of a Business Impact Analysis (BIA), what is the primary
objective of identifying the Maximum Tolerable Downtime (MTD) for a critical
business process?
A. To define the cost of implementing a new IT system.
B. To establish the longest period of time a business can survive without that
process.
C. To allocate the budget for a disaster recovery site.
D. To determine the exact number of employees required to restore the process.
🟢 Correct Answer: B. To establish the longest period of time a business can
survive without that process.
🔴 Explanation: The MTD is a key metric in BIA that represents the time a
business can function without a specific process before negative impacts become
unacceptable. It informs the Recovery Time Objective (RTO).
──────────────────────────────────────
4. A project manager is leading an IT system upgrade using a Scrum
framework. During which event does the Scrum Team inspect the Increment,
adapt the Product Backlog, and define a new Sprint Goal based on the work
completed so far?
A. Daily Stand-up
B. Sprint Review
C. Sprint Retrospective
D. Sprint Planning
, 🟢 Correct Answer: B. Sprint Review
🔴 Explanation: The Sprint Review is held at the end of the Sprint to inspect the
Increment and collaborate on what to do next. The Product Backlog is adapted,
and new objectives are discussed for the next Sprint.
──────────────────────────────────────
5. An organization has a strict password policy that requires users to change
their passwords every 90 days. Which type of control does this password policy
represent?
A. Administrative Control
B. Technical Control
C. Physical Control
D. Deterrent Control
🟢 Correct Answer: A. Administrative Control
🔴 Explanation: A password policy is a rule or procedure that governs human
behavior. It is an administrative (or procedural) control, as it defines expectations
and requirements for personnel.
──────────────────────────────────────
6. The concept of 'Defense in Depth' uses multiple layers of security. Which of
the following correctly lists layers of defense from outermost to innermost?
A. Perimeter, Network, Host, Application, Data
B. Data, Application, Host, Network, Perimeter
C. Application, Data, Host, Network, Perimeter
D. Perimeter, Host, Network, Application, Data
🟢 Correct Answer: A. Perimeter, Network, Host, Application, Data