Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 28 pages
Exam (elaborations)

WGU D488 OA TEST BANK 1 2026 | Cybersecurity Architecture & Engineering | Actual Exam Questions & Correct Answers | Pass Guaranteed - A+ Graded

Document preview thumbnail
Preview 3 out of 28 pages

Pass the WGU D488 Cybersecurity Architecture and Engineering Objective Assessment with this complete Test Bank 1 featuring actual exam questions and correct answers for 2026. This A+ Graded resource covers all essential cybersecurity domains including security architecture frameworks, network security design, cloud security, identity and access management, cryptography, risk management, incident response, and security operations. Each question is verified and aligned with the latest WGU D488 curriculum. Perfect for WGU students seeking comprehensive OA preparation. With our Pass Guarantee, you can study with confidence. Download your complete WGU D488 OA Test Bank 1 guide instantly!

Content preview

2026 WGU D488 Cybersecurity Architecture
and Engineering Objective Assessment
Test Bank 1 - Practice Exam with Actual Exam Questions and Answers

75 Questions | 9 Sections | Scenario-Based Multiple Choice



Section 1: Security Architecture Principles and Frameworks (Q1-12)

Q1: A financial services firm is modernizing its cybersecurity program and adopts the NIST Cybersecurity Framework.
The CISO needs to present the framework to the board as a continuous lifecycle. Which of the following represents the
correct sequence of the five core functions in the NIST CSF?
A. Protect, Detect, Respond, Recover, Identify
B. Identify, Protect, Detect, Respond, Recover [CORRECT]
C. Identify, Detect, Protect, Respond, Recover
D. Detect, Identify, Protect, Respond, Recover
Correct Answer: B
Rationale: The NIST CSF organizes its five core functions as Identify, Protect, Detect, Respond, and Recover to form a continuous
improvement lifecycle. Identify comes first because an organization must understand its assets, risks, and current posture before it can
protect them. Protect and Detect follow as proactive and reactive measures respectively, while Respond and Recover address incident
handling and restoration. The sequences in options A, C, and D either place identification or detection out of order, breaking the logical
flow from understanding risk through recovery.

Q2: An organization pursuing ISO 27001:2022 certification is mapping its control set to the revised Annex A structure.
The compliance team needs to identify which domain addresses governance-level controls such as policies, roles, and
responsibilities. Which Annex A domain focuses on organizational governance controls?
A. A.5 Organizational Controls [CORRECT]
B. A.6 People Controls
C. A.7 Physical Controls
D. A.8 Technological Controls
Correct Answer: A
Rationale: In ISO 27001:2022, Annex A was restructured from 14 domains into four thematic groups. A.5 Organizational Controls
contains governance-level controls covering information security policies, asset management, and roles and responsibilities. A.6 People
Controls addresses human factors such as screening, terms of employment, and awareness training, not governance structures. A.7
Physical Controls covers physical security perimeters and equipment protection, while A.8 Technological Controls deals with technical
safeguards like cryptography and access control. Only A.5 directly addresses the organizational governance layer the compliance team
requires.

Q3: A multinational bank is implementing COBIT 2019 to align its IT governance with enterprise risk management. The
board wants a specific governance objective that directly addresses cybersecurity risk optimization. Which COBIT 2019
governance objective is most appropriate for ensuring cybersecurity risk is optimized at the board level?
A. EDM01 Ensure Governance Framework Setting and Maintenance
B. EDM03 Ensure Risk Optimization [CORRECT]
C. EDM05 Ensure Stakeholder Needs Are Addressed
D. AP013 Manage Security
Correct Answer: B
Rationale: COBIT 2019 designates EDM03 as the governance objective specifically responsible for ensuring risk optimization, which
encompasses cybersecurity risk at the enterprise level. EDM01 establishes the governance framework itself but does not directly address

,risk optimization. EDM05 focuses on stakeholder value delivery rather than risk management. AP013 is a management process below the
governance layer that handles day-to-day security operations, not board-level risk governance. Therefore, EDM03 is the correct
governance objective the board should adopt for cybersecurity risk oversight.

Q4: An enterprise architecture team is using TOGAF ADM to design a new customer portal. The chief security
architect must ensure that security requirements are captured at the earliest appropriate phase to influence all
downstream design decisions. In which TOGAF ADM phase are security requirements first formally captured?
A. Phase A: Architecture Vision [CORRECT]
B. Phase B: Business Architecture
C. Phase C: Information Systems Architecture
D. Phase D: Technology Architecture
Correct Answer: A
Rationale: In the TOGAF ADM, Phase A Architecture Vision is where security requirements are first captured as part of stakeholder
concerns and architectural constraints. Capturing security requirements at this stage ensures they influence the entire architecture
development effort across all subsequent phases. Phase B focuses on business processes and organizational structure, while Phases C and
D deal with specific architecture domains where requirements are refined rather than initially captured. Waiting until Phase C or D to
introduce security requirements would result in costly retrofits and a design that does not adequately address security from the outset.

Q5: A healthcare organization is migrating from a perimeter-based security model to Zero Trust Architecture. A
security engineer is explaining the fundamental conceptual difference to the IT operations team. Which statement best
describes the core principle that distinguishes Zero Trust from traditional perimeter-based security?
A. Zero Trust eliminates the need for firewalls by using only endpoint protection
B. No implicit trust is granted based solely on network location; every access request is verified
[CORRECT]
C. Zero Trust requires all users to authenticate with multi-factor authentication at the network perimeter
D. Zero Trust architecture assumes that external networks are more trustworthy than internal networks
Correct Answer: B
Rationale: The defining principle of Zero Trust Architecture is that no implicit trust is granted based on network location, meaning every
access request must be authenticated, authorized, and encrypted regardless of whether it originates inside or outside the network
perimeter. Option A is incorrect because Zero Trust does not eliminate firewalls but rather adds additional layers of verification. Option
C misrepresents Zero Trust by tying it to perimeter-only authentication, which contradicts the model. Option D states the opposite of Zero
Trust principles, since the model treats all networks as equally untrusted. This core principle of continuous verification is what
fundamentally differentiates Zero Trust from castle-and-moat perimeter defenses.

Q6: A security architect is using the SABSA framework to develop an enterprise security architecture. She needs to
identify which layer translates business security requirements into specific security services that bridge the gap between
business intent and technical implementation. Which SABSA layer serves this bridging function?
A. Conceptual Layer
B. Physical Layer
C. Logical Layer [CORRECT]
D. Component Layer
Correct Answer: C
Rationale: The SABSA Logical Layer is responsible for defining security services that translate business requirements from the
Conceptual Layer into specifications that guide the Physical and Component layers. It provides the essential bridge between
business-driven security needs and their technical realization. The Conceptual Layer deals with business context, drivers, and stakeholder
requirements at a strategic level without defining services. The Physical Layer maps logical services to specific technology platforms, and
the Component Layer addresses individual product-level selection and configuration. Only the Logical Layer specifically focuses on
security services as the intermediary between business and technology.

, Q7: A security engineer is implementing defense-in-depth for a corporate data center processing payment card data. She
must select one control for each of the five defense-in-depth layers: physical, perimeter, network, host, and
application/data. Which combination correctly maps one control to each layer from outermost to innermost?
A. Mantrap, firewall, IDS, host-based firewall, field-level encryption
B. Badge reader, firewall, patch management, WAF, tokenization [CORRECT]
C. Security guard, DMZ, antivirus, hardening standard, access control list
D. CCTV, router ACL, intrusion prevention system, file integrity monitoring, salting
Correct Answer: B
Rationale: Option B correctly maps defense-in-depth controls across all five layers: a badge reader provides physical access control, a
firewall enforces perimeter network security, patch management addresses network-level vulnerability remediation, a WAF operates at
the host layer to protect web servers, and tokenization secures data at the application/data layer. Option A places IDS at the network layer
instead of perimeter, and host-based firewall is redundant with the perimeter firewall. Option C maps a DMZ as a network-layer control,
but a DMZ is a network zone rather than an active control, and antivirus at the network layer is imprecise. Option D uses router ACL at
the perimeter layer and salting at the data layer, but salting is a specific hashing technique, not a broad data-layer control. Option B is the
most accurate and comprehensive mapping.

Q8: A database administrator is designing access controls for a multi-tier web application backed by a relational
database. The application only needs to retrieve product catalog data for display on a public-facing website. Which
approach best applies the principle of least privilege to this database architecture?
A. Grant the application service account full DBA privileges to avoid connection errors during peak traffic
B. Create a read-only user account but grant SELECT on all schemas to prevent access denied errors
C. Provision an application service account with SELECT privileges limited to only the specific catalog
tables required [CORRECT]
D. Use the database root account for the application since it simplifies connection string configuration
Correct Answer: C
Rationale: Option C correctly applies the principle of least privilege by creating a service account with SELECT access restricted to only
the specific tables the application needs, minimizing the blast radius if the account is compromised. Option A violates least privilege by
granting excessive DBA privileges that could allow an attacker to modify or delete any database object. Option B grants broader access
than necessary across all schemas, which still violates least privilege even though it is read-only. Option D uses the root account, which
represents the maximum privilege level and is the antithesis of least privilege. Restricting access to the minimum required tables is the
correct implementation of this foundational security principle.

Q9: A financial institution processes high-value wire transfers and needs to prevent a single administrator from
committing fraud. The security team designs a control where one administrator configures a new transfer rule while a
second administrator must independently approve it before it becomes active. Which security principle does this control
most directly implement?
A. Defense in depth, because multiple layers of administrators are used
B. Separation of duties, because no single individual can complete a critical transaction alone
[CORRECT]
C. Least privilege, because each administrator has limited access to only their part of the process
D. Job rotation, because administrators switch roles between configuration and approval
Correct Answer: B
Rationale: This control directly implements separation of duties by ensuring that no single administrator has the ability to both configure
and approve a transfer rule, requiring collusion between at least two people to commit fraud. Option A describes defense in depth, which
involves multiple independent layers of controls rather than splitting a single function across individuals. Option C describes least
privilege, which limits the scope of access but does not inherently require dual approval for a single operation. Option D refers to job
rotation, which involves periodically switching personnel between roles to detect fraud over time rather than preventing it through
concurrent authorization. The dual-approval mechanism is the hallmark of separation of duties.

Document information

Uploaded on
August 20, 2026
Number of pages
28
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$30.50

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NURSEEXAMITY
3.4
(97)
Sold
515
Followers
273
Items
6285
Last sold
2 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions