WGU D488 CYBERSECURITY
ARCHITECTURE AND ENGINEERING
QUESTIONS AND CORRECT
ANSWERS (VERIFIED ANSWERS)
PLUS RATIONALES 2026/2027 Q&A |
INSTANT DOWNLOAD PDF
Core Domains
Security Architecture Foundations: Principles, Reference Models, and
Frameworks
Threat Modeling, Risk Assessment, and Security Control Engineering
Secure Systems Design, SDLC, and DevSecOps Integration
Cloud, Network, and Zero Trust Architecture Implementation
Governance, Compliance, Cryptography, and Professional Practice
Identity and Access Management
Incident Response and Security Operations
Data Protection and Privacy
Introduction
This comprehensive examination assesses the knowledge and clinical judgment
required for safe cybersecurity architecture and engineering practice. It
evaluates foundational theory, applied professional knowledge, regulatory
compliance, ethical standards, and critical thinking through multiple-choice
and scenario-based questions. The exam emphasizes real-world application,
architectural decision-making, and security engineering principles across
diverse enterprise environments. Candidates must demonstrate competency in
security frameworks, risk management, secure system design, cryptography,
network security, and cloud architecture. This assessment prepares
,cybersecurity professionals for the WGU D488 Objective Assessment while
reinforcing evidence-based security architecture practices.
Section One: Questions 1–100
1. Which security architecture principle states that a system should
default to the most secure configuration, requiring explicit action to
reduce restrictions?
A. Least privilege
B. Defense in depth
C. Fail-safe defaults
D. Separation of duties
C. Fail-safe defaults
RATIONALE: Fail-safe defaults means a system defaults to a secure state,
requiring explicit action to grant access or reduce restrictions. Least privilege
grants minimum necessary access. Defense in depth layers multiple controls.
Separation of duties divides critical functions across roles.
2. An enterprise security architect must align security requirements
with business objectives using TOGAF. Which TOGAF ADM phase is
most relevant for defining security architecture requirements?
A. Preliminary Phase
B. Phase A: Architecture Vision
C. Phase B: Business Architecture
D. Phase C: Information Systems Architecture
D. Phase C: Information Systems Architecture
RATIONALE: Phase C of the TOGAF ADM addresses Information
Systems Architecture, encompassing applications and data security
architecture. Security requirements are formally captured and mapped here.
3. In the SABSA layered model, which layer addresses 'what' questions
and defines business attributes that need protection?
,A. Contextual layer (Why)
B. Conceptual layer (What)
C. Logical layer (How)
D. Physical layer (With what)
B. Conceptual layer (What)
RATIONALE: SABSA's Conceptual layer answers 'What' questions,
defining business assets, attributes, and the security attributes
(confidentiality, integrity, availability, accountability) that need protection.
4. Which component of the NIST Cybersecurity Framework (CSF) 2.0
focuses on organizational understanding and management of
cybersecurity risk to systems, people, assets, data, and capabilities?
A. Identify
B. Protect
C. Govern
D. Detect
C. Govern
RATIONALE: The Govern (GV) function is unique to CSF 2.0, elevating
governance to the same level as the original five functions. It addresses
organizational understanding and management of cybersecurity risk.
5. What is the primary goal of Zero Trust Architecture (ZTA)?
A. Eliminate firewalls
B. Trust internal users by default
C. Verify every access request
D. Centralize authentication only
C. Verify every access request
RATIONALE: Zero Trust assumes no implicit trust, regardless of network
location. Every access request must be authenticated and authorized
explicitly.
, 6. A security architect is selecting an encryption algorithm for data at
rest. Which algorithm is a symmetric block cipher that operates on 128-
bit blocks?
A. RSA
B. AES
C. ECC
D. SHA-256
B. AES
RATIONALE: AES (Advanced Encryption Standard) is a symmetric block
cipher that operates on 128-bit blocks with key sizes of 128, 192, or 256 bits.
7. Which cloud service model provides the least administrative
responsibility for customers?
A. Infrastructure as a Service (IaaS)
B. Platform as a Service (PaaS)
C. Software as a Service (SaaS)
D. Container as a Service (CaaS)
C. Software as a Service (SaaS)
RATIONALE: SaaS provides the least administrative responsibility
because the provider manages the entire stack from infrastructure to
application.
8. A security team needs to block SQL injection attacks against a
publicly accessible web application. Which solution fulfills this
requirement?
A. Virtual private network (VPN)
B. Security information and event management (SIEM)
C. Web application firewall (WAF)
D. Secure Socket Shell (SSH)
C. Web application firewall (WAF)
ARCHITECTURE AND ENGINEERING
QUESTIONS AND CORRECT
ANSWERS (VERIFIED ANSWERS)
PLUS RATIONALES 2026/2027 Q&A |
INSTANT DOWNLOAD PDF
Core Domains
Security Architecture Foundations: Principles, Reference Models, and
Frameworks
Threat Modeling, Risk Assessment, and Security Control Engineering
Secure Systems Design, SDLC, and DevSecOps Integration
Cloud, Network, and Zero Trust Architecture Implementation
Governance, Compliance, Cryptography, and Professional Practice
Identity and Access Management
Incident Response and Security Operations
Data Protection and Privacy
Introduction
This comprehensive examination assesses the knowledge and clinical judgment
required for safe cybersecurity architecture and engineering practice. It
evaluates foundational theory, applied professional knowledge, regulatory
compliance, ethical standards, and critical thinking through multiple-choice
and scenario-based questions. The exam emphasizes real-world application,
architectural decision-making, and security engineering principles across
diverse enterprise environments. Candidates must demonstrate competency in
security frameworks, risk management, secure system design, cryptography,
network security, and cloud architecture. This assessment prepares
,cybersecurity professionals for the WGU D488 Objective Assessment while
reinforcing evidence-based security architecture practices.
Section One: Questions 1–100
1. Which security architecture principle states that a system should
default to the most secure configuration, requiring explicit action to
reduce restrictions?
A. Least privilege
B. Defense in depth
C. Fail-safe defaults
D. Separation of duties
C. Fail-safe defaults
RATIONALE: Fail-safe defaults means a system defaults to a secure state,
requiring explicit action to grant access or reduce restrictions. Least privilege
grants minimum necessary access. Defense in depth layers multiple controls.
Separation of duties divides critical functions across roles.
2. An enterprise security architect must align security requirements
with business objectives using TOGAF. Which TOGAF ADM phase is
most relevant for defining security architecture requirements?
A. Preliminary Phase
B. Phase A: Architecture Vision
C. Phase B: Business Architecture
D. Phase C: Information Systems Architecture
D. Phase C: Information Systems Architecture
RATIONALE: Phase C of the TOGAF ADM addresses Information
Systems Architecture, encompassing applications and data security
architecture. Security requirements are formally captured and mapped here.
3. In the SABSA layered model, which layer addresses 'what' questions
and defines business attributes that need protection?
,A. Contextual layer (Why)
B. Conceptual layer (What)
C. Logical layer (How)
D. Physical layer (With what)
B. Conceptual layer (What)
RATIONALE: SABSA's Conceptual layer answers 'What' questions,
defining business assets, attributes, and the security attributes
(confidentiality, integrity, availability, accountability) that need protection.
4. Which component of the NIST Cybersecurity Framework (CSF) 2.0
focuses on organizational understanding and management of
cybersecurity risk to systems, people, assets, data, and capabilities?
A. Identify
B. Protect
C. Govern
D. Detect
C. Govern
RATIONALE: The Govern (GV) function is unique to CSF 2.0, elevating
governance to the same level as the original five functions. It addresses
organizational understanding and management of cybersecurity risk.
5. What is the primary goal of Zero Trust Architecture (ZTA)?
A. Eliminate firewalls
B. Trust internal users by default
C. Verify every access request
D. Centralize authentication only
C. Verify every access request
RATIONALE: Zero Trust assumes no implicit trust, regardless of network
location. Every access request must be authenticated and authorized
explicitly.
, 6. A security architect is selecting an encryption algorithm for data at
rest. Which algorithm is a symmetric block cipher that operates on 128-
bit blocks?
A. RSA
B. AES
C. ECC
D. SHA-256
B. AES
RATIONALE: AES (Advanced Encryption Standard) is a symmetric block
cipher that operates on 128-bit blocks with key sizes of 128, 192, or 256 bits.
7. Which cloud service model provides the least administrative
responsibility for customers?
A. Infrastructure as a Service (IaaS)
B. Platform as a Service (PaaS)
C. Software as a Service (SaaS)
D. Container as a Service (CaaS)
C. Software as a Service (SaaS)
RATIONALE: SaaS provides the least administrative responsibility
because the provider manages the entire stack from infrastructure to
application.
8. A security team needs to block SQL injection attacks against a
publicly accessible web application. Which solution fulfills this
requirement?
A. Virtual private network (VPN)
B. Security information and event management (SIEM)
C. Web application firewall (WAF)
D. Secure Socket Shell (SSH)
C. Web application firewall (WAF)