1
WGU D488 OA FINAL EXAM TEST BANK/WGU D488
CYBERSECURITY ARCHITECTURE & ENGINEERING NEWEST
2026/2027 COMPLETE ALL 230 QUESTIONS AND CORRECT
DETAILED ANSWERS |ALREADY GRADED A+||ALREADY
GRADED A+
1.
A multinational organization is redesigning its enterprise security
architecture after discovering that several business units independently
implemented security controls with inconsistent configurations. The
chief information security officer wants an architecture approach that
begins with business requirements and translates those requirements into
security services, mechanisms, and controls while maintaining
traceability between business objectives and technical implementation.
Which architectural approach BEST supports this requirement?
A. SABSA
B. RAID
C. SD-WAN
D. Kerberos
Correct Answer: A. SABSA
2.
A security architect is reviewing a proposed architecture in which an
employee must authenticate before accessing an internal application, but
once authenticated, the employee can freely access every application and
database on the internal network. The architect wants to redesign the
environment according to a security model that assumes no implicit trust
based solely on network location. Which principle should guide the
redesign?
A. Implicit internal trust
B. Zero Trust
,2
C. Network perimeter trust
D. Open authentication
Correct Answer: B. Zero Trust
3.
A company operates a hybrid environment containing on-premises
servers, public-cloud workloads, remote employees, third-party
contractors, and mobile devices. Management wants security controls
that continue to protect resources even when users and devices are
connecting from untrusted networks. Which architecture principle is
MOST appropriate?
A. Trust all internal IP addresses
B. Verify explicitly and enforce least privilege
C. Allow unrestricted internal communication
D. Place all resources behind one perimeter firewall
Correct Answer: B. Verify explicitly and enforce least privilege
4.
A security architect is designing a defense strategy for a financial
organization. The organization already uses firewalls but wants
additional safeguards so that compromise of one security mechanism
does not automatically result in compromise of sensitive systems. Which
principle BEST addresses this requirement?
A. Single sign-on
B. Defense in depth
C. Data normalization
D. Network convergence
Correct Answer: B. Defense in depth
5.
,3
A company determines that an application server should never
communicate directly with the organization's database servers from the
public internet. The security architect places the application servers in a
separate network segment and restricts traffic between segments
according to documented requirements. Which security architecture
technique is being implemented?
A. Network segmentation
B. Password synchronization
C. Data deduplication
D. Load balancing
Correct Answer: A. Network segmentation
6.
A company is conducting a quantitative risk assessment for a critical
database. The database has an asset value of $500,000, the exposure
factor for a particular threat is estimated at 40%, and the threat is
expected to occur twice per year. What is the estimated annual loss
expectancy?
A. $100,000
B. $200,000
C. $400,000
D. $500,000
Correct Answer: C. $400,000
7.
A security manager is comparing two risks. Risk A has a low probability
but could cause catastrophic financial damage, while Risk B has a high
probability but would cause only minor operational disruption. The
organization wants to prioritize resources based on both probability and
potential impact. Which concept is MOST applicable?
, 4
A. Risk rating
B. Hashing
C. Authentication
D. Availability
Correct Answer: A. Risk rating
8.
A company identifies a cybersecurity risk that cannot reasonably be
eliminated and is too expensive to mitigate completely. Management
decides to formally acknowledge the remaining exposure and continue
operating under the existing conditions. Which risk treatment strategy is
being used?
A. Risk avoidance
B. Risk transfer
C. Risk acceptance
D. Risk escalation
Correct Answer: C. Risk acceptance
9.
A healthcare organization determines that a particular security risk can
be reduced by purchasing cybersecurity insurance. The organization
retains some responsibility but shifts a portion of the potential financial
impact to an external party. Which risk treatment strategy is being used?
A. Risk transfer
B. Risk avoidance
C. Risk acceptance
D. Risk elimination
Correct Answer: A. Risk transfer
10.
WGU D488 OA FINAL EXAM TEST BANK/WGU D488
CYBERSECURITY ARCHITECTURE & ENGINEERING NEWEST
2026/2027 COMPLETE ALL 230 QUESTIONS AND CORRECT
DETAILED ANSWERS |ALREADY GRADED A+||ALREADY
GRADED A+
1.
A multinational organization is redesigning its enterprise security
architecture after discovering that several business units independently
implemented security controls with inconsistent configurations. The
chief information security officer wants an architecture approach that
begins with business requirements and translates those requirements into
security services, mechanisms, and controls while maintaining
traceability between business objectives and technical implementation.
Which architectural approach BEST supports this requirement?
A. SABSA
B. RAID
C. SD-WAN
D. Kerberos
Correct Answer: A. SABSA
2.
A security architect is reviewing a proposed architecture in which an
employee must authenticate before accessing an internal application, but
once authenticated, the employee can freely access every application and
database on the internal network. The architect wants to redesign the
environment according to a security model that assumes no implicit trust
based solely on network location. Which principle should guide the
redesign?
A. Implicit internal trust
B. Zero Trust
,2
C. Network perimeter trust
D. Open authentication
Correct Answer: B. Zero Trust
3.
A company operates a hybrid environment containing on-premises
servers, public-cloud workloads, remote employees, third-party
contractors, and mobile devices. Management wants security controls
that continue to protect resources even when users and devices are
connecting from untrusted networks. Which architecture principle is
MOST appropriate?
A. Trust all internal IP addresses
B. Verify explicitly and enforce least privilege
C. Allow unrestricted internal communication
D. Place all resources behind one perimeter firewall
Correct Answer: B. Verify explicitly and enforce least privilege
4.
A security architect is designing a defense strategy for a financial
organization. The organization already uses firewalls but wants
additional safeguards so that compromise of one security mechanism
does not automatically result in compromise of sensitive systems. Which
principle BEST addresses this requirement?
A. Single sign-on
B. Defense in depth
C. Data normalization
D. Network convergence
Correct Answer: B. Defense in depth
5.
,3
A company determines that an application server should never
communicate directly with the organization's database servers from the
public internet. The security architect places the application servers in a
separate network segment and restricts traffic between segments
according to documented requirements. Which security architecture
technique is being implemented?
A. Network segmentation
B. Password synchronization
C. Data deduplication
D. Load balancing
Correct Answer: A. Network segmentation
6.
A company is conducting a quantitative risk assessment for a critical
database. The database has an asset value of $500,000, the exposure
factor for a particular threat is estimated at 40%, and the threat is
expected to occur twice per year. What is the estimated annual loss
expectancy?
A. $100,000
B. $200,000
C. $400,000
D. $500,000
Correct Answer: C. $400,000
7.
A security manager is comparing two risks. Risk A has a low probability
but could cause catastrophic financial damage, while Risk B has a high
probability but would cause only minor operational disruption. The
organization wants to prioritize resources based on both probability and
potential impact. Which concept is MOST applicable?
, 4
A. Risk rating
B. Hashing
C. Authentication
D. Availability
Correct Answer: A. Risk rating
8.
A company identifies a cybersecurity risk that cannot reasonably be
eliminated and is too expensive to mitigate completely. Management
decides to formally acknowledge the remaining exposure and continue
operating under the existing conditions. Which risk treatment strategy is
being used?
A. Risk avoidance
B. Risk transfer
C. Risk acceptance
D. Risk escalation
Correct Answer: C. Risk acceptance
9.
A healthcare organization determines that a particular security risk can
be reduced by purchasing cybersecurity insurance. The organization
retains some responsibility but shifts a portion of the potential financial
impact to an external party. Which risk treatment strategy is being used?
A. Risk transfer
B. Risk avoidance
C. Risk acceptance
D. Risk elimination
Correct Answer: A. Risk transfer
10.