• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 33 pages
Exam (elaborations)

Wgu D488 Final Exam – Exam Questions And Correct Answers (Verified Answers) Plus Rationale | 2027 Q&A | Instant Download Pdf

Document preview thumbnail
Preview 4 out of 33 pages

WGU D488 FINAL EXAM – EXAM QUESTIONS AND CORRECT ANSWERS (VERIFIED ANSWERS) PLUS RATIONALE | 2027 Q&A | INSTANT DOWNLOAD PDF

Content preview

WGU D488 FINAL EXAM – EXAM QUESTIONS AND CORRECT
ANSWERS (VERIFIED ANSWERS) PLUS RATIONALE | 2027 Q&A |
INSTANT DOWNLOAD PDF

1. An enterprise security architect is establishing the foundational principles for
protecting organizational resources. Which principle limits a user or process to
only the permissions required to perform an assigned function?

A. Separation of duties

B. Least privilege

C. Defense in depth

D. Fail-safe defaults

Rationale: Least privilege minimizes unnecessary access and reduces the potential impact of
compromised accounts or processes. Separation of duties distributes responsibilities, while
defense in depth uses multiple security layers.

2. A company wants its security architecture to assume that no user, device, or
application should automatically be trusted simply because it is inside the
corporate network. Which architectural approach best supports this requirement?

A. Perimeter-based security

B. Implicit trust

C. Network address translation

D. Zero Trust

Rationale: Zero Trust continuously evaluates identity, device posture, context, and authorization
rather than granting implicit trust based on network location.

3. An organization deploys multiple independent controls so that the failure of one
security mechanism does not expose the entire environment. Which concept is
being implemented?

A. Defense in depth

B. Single sign-on

C. Data minimization

D. Network convergence

,Rationale: Defense in depth uses multiple complementary security layers, such as access
controls, segmentation, monitoring, and encryption, so one failed control does not become a
single point of compromise.

4. During an architecture review, an engineer identifies that the same administrator
can request, approve, and implement financial-system changes. Which principle
should be applied to reduce this risk?

A. Least functionality

B. Fail-open design

C. Separation of duties

D. Availability

Rationale: Separation of duties prevents one individual from controlling multiple critical stages
of a sensitive process. This reduces opportunities for fraud and unauthorized changes.

5. A security team is designing an enterprise architecture and wants to ensure that
security requirements are considered before systems are deployed rather than
added afterward. Which approach is most appropriate?

A. Reactive security

B. Security by design

C. Compensating control

D. Post-incident hardening

Rationale: Security by design incorporates security requirements, threat considerations, and
controls throughout the system-development and architecture process.

6. A company wants to restrict a server from running software that is not necessary
for its intended function. Which principle most directly supports this objective?

A. Open design

B. Maximum functionality

C. Trust inheritance

D. Least functionality

,Rationale: Least functionality limits systems to the services, applications, and capabilities
necessary for their intended purpose, reducing the attack surface.

7. An architect is evaluating a proposed security control. The control would reduce
risk but would also introduce significant operational costs. Which activity should
occur first when determining whether the control is justified?

A. Risk assessment

B. Password reset

C. Log deletion

D. System decommissioning

Rationale: Risk assessment helps determine the likelihood and impact of threats and
vulnerabilities so management can compare the expected risk reduction with the cost and
operational consequences of a control.

8. A security architect wants to understand how an attacker could move from an
initially compromised workstation to a sensitive database. Which technique is
most useful?

A. Capacity planning

B. Asset tagging

C. Attack-path analysis

D. Data deduplication

Rationale: Attack-path analysis examines potential routes an attacker could use through systems,
identities, privileges, and network relationships to reach a target.

9. A company categorizes information according to sensitivity so that more
restrictive safeguards can be applied to confidential information. What
architectural practice does this support?

A. Load balancing

B. Data classification

C. Network convergence

D. Fault isolation

, Rationale: Data classification assigns sensitivity levels to information and helps determine
appropriate access controls, encryption, retention, and handling requirements.

10. An enterprise identifies its most important business applications and determines
which security controls are required to protect them. Which activity is most
directly being performed?

A. Software refactoring

B. Packet fragmentation

C. Database normalization

D. Asset and risk prioritization

Rationale: Asset and risk prioritization helps organizations focus resources on systems and
information whose compromise would create the greatest business impact.

11. A security architect is reviewing an application that accepts user input and
passes it directly to a database query. Which weakness presents the greatest
immediate concern?

A. SQL injection

B. ARP poisoning

C. DNS tunneling

D. VLAN hopping

Rationale: Unsanitized input incorporated into database queries can allow an attacker to
manipulate SQL statements and access or modify unauthorized data.

12. A web application needs protection against malicious HTTP requests, including
common application-layer attacks. Which control is specifically designed for this
purpose?

A. Network load balancer

B. VPN concentrator

C. Web application firewall

D. Hardware security module

Document information

Uploaded on
September 13, 2026
Number of pages
33
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$17.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TutorCollins21
5.0
(1)
Sold
69
Followers
1
Items
870
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions