WGU D488 Cybersecurity Architecture and
Engineering | Western Governors
University
Section 1: Security Architecture and Design (Questions 1–25)
Question 1
A security architect is designing an enterprise security architecture for a
healthcare organization that must comply with HIPAA. The CISO wants a
framework that starts with business drivers and traces security services down
through layers. Which framework BEST fits this requirement?
A. ITIL
B. SABSA
C. OSI Model
D. Agile Manifesto
Rationale: SABSA (Sherwood Applied Business Security Architecture) is the
enterprise security architecture framework that explicitly traces security services
from business drivers down through layers (business, architecture, systems,
components). ITIL is service-management focused, the OSI model is purely
networking, and Agile is a development methodology—none of them deliver a
capability-to-business mapping as SABSA does .
Question 2
An engineering team integrates an open-source third-party logging library into a
production payment application without security review. Three weeks later, a CVE
is disclosed revealing the library silently exfiltrates environment variables. Which
supply-chain risk BEST describes this scenario?
A. Insider threat from a privileged administrator
B. Insecure third-party component / dependency risk
C. Network perimeter misconfiguration
D. Password policy enforcement failure
, Rationale: Open-source and third-party libraries are a primary supply-chain
vector; unreviewed dependencies can introduce vulnerabilities or malicious
behavior (e.g., the Log4j and event-stream incidents). The scenario describes
dependency risk, not insider activity, perimeter gaps, or password weaknesses .
Question 3
An organization migrates workloads to an IaaS provider. Under the shared
responsibility model, which of the following remains the CUSTOMER's
responsibility?
A. Physical security of the data center
B. Host operating system patching and guest OS hardening
C. Underlying virtualization hypervisor maintenance
D. Physical network cabling and switches
Rationale: In IaaS, the provider secures the physical facility, hardware, and
hypervisor, while the customer is responsible for the guest operating system,
applications, identity, and data. Patching and hardening the OS is therefore a
customer responsibility .
Question 4
A multinational retailer's security operations team discovers that domain
administrators routinely share a single break-glass account. Which IAM control
BEST addresses this risk?
A. Deploy a Privileged Access Management (PAM) solution with credential
vaulting and session recording
B. Implement longer password complexity requirements only
C. Increase the frequency of security awareness training
D. Add an additional firewall rule between users and the directory server
Rationale: PAM solutions with credential vaulting and session recording
directly address the risk of shared privileged accounts by ensuring individual
accountability, just-in-time access, and audit trails. Password complexity alone
,does not prevent sharing, training is not a technical control, and firewall rules do
not address credential sharing .
Question 5
A government agency is planning a hybrid cloud deployment. Strict controls must
be in place that can label classified data. The solution must ensure that access
rights will be granted based on the user's government security classification.
Which access control model should be used?
A. Role-Based Access Control (RBAC)
B. Mandatory Access Control (MAC)
C. Attribute-Based Access Control (ABAC)
D. Discretionary Access Control (DAC)
Rationale: MAC is standard for classified environments. Access is based on
system-enforced security labels (e.g., Top Secret, Confidential), and users cannot
change these controls .
Question 6
Which principle ensures users are granted only the minimal access rights needed
to perform their job functions?
A. Defense in Depth
B. Separation of Duties
C. Least Privilege
D. Zero Trust
Rationale: The principle of least privilege limits access rights to the absolute
minimum necessary, reducing the attack surface and potential damage from
compromised accounts .
Question 7
A cybersecurity analyst at a software company conducted a vulnerability
assessment and discovered multiple vulnerabilities on the company's webpage.
, The CISO decided not to fix the discrepancies due to the vulnerabilities being
outside of the organization's resources. Which risk mitigation strategy is
demonstrated?
A. Accept
B. Mitigate
C. Avoid
D. Transfer
Rationale: Risk acceptance acknowledges a risk but takes no action, often
because the cost of mitigation is not justified .
Question 8
A security team notices traffic coming from a country where the organization
does not have any business operations. Which of the following could this be an
indicator of?
A. High call volume
B. Odd network traffic
C. Geographic anomalies
D. Unauthorized changes
Rationale: Traffic from unexpected geographic locations is a geographic
anomaly that may indicate a security threat .
Question 9
A security architect is designing a strategy to help continue operating in the face
of a cyber-attack. Which of the following will help accomplish this objective?
A. Heterogeneity
B. Clustering
C. Redundancy
D. Virtualization
Engineering | Western Governors
University
Section 1: Security Architecture and Design (Questions 1–25)
Question 1
A security architect is designing an enterprise security architecture for a
healthcare organization that must comply with HIPAA. The CISO wants a
framework that starts with business drivers and traces security services down
through layers. Which framework BEST fits this requirement?
A. ITIL
B. SABSA
C. OSI Model
D. Agile Manifesto
Rationale: SABSA (Sherwood Applied Business Security Architecture) is the
enterprise security architecture framework that explicitly traces security services
from business drivers down through layers (business, architecture, systems,
components). ITIL is service-management focused, the OSI model is purely
networking, and Agile is a development methodology—none of them deliver a
capability-to-business mapping as SABSA does .
Question 2
An engineering team integrates an open-source third-party logging library into a
production payment application without security review. Three weeks later, a CVE
is disclosed revealing the library silently exfiltrates environment variables. Which
supply-chain risk BEST describes this scenario?
A. Insider threat from a privileged administrator
B. Insecure third-party component / dependency risk
C. Network perimeter misconfiguration
D. Password policy enforcement failure
, Rationale: Open-source and third-party libraries are a primary supply-chain
vector; unreviewed dependencies can introduce vulnerabilities or malicious
behavior (e.g., the Log4j and event-stream incidents). The scenario describes
dependency risk, not insider activity, perimeter gaps, or password weaknesses .
Question 3
An organization migrates workloads to an IaaS provider. Under the shared
responsibility model, which of the following remains the CUSTOMER's
responsibility?
A. Physical security of the data center
B. Host operating system patching and guest OS hardening
C. Underlying virtualization hypervisor maintenance
D. Physical network cabling and switches
Rationale: In IaaS, the provider secures the physical facility, hardware, and
hypervisor, while the customer is responsible for the guest operating system,
applications, identity, and data. Patching and hardening the OS is therefore a
customer responsibility .
Question 4
A multinational retailer's security operations team discovers that domain
administrators routinely share a single break-glass account. Which IAM control
BEST addresses this risk?
A. Deploy a Privileged Access Management (PAM) solution with credential
vaulting and session recording
B. Implement longer password complexity requirements only
C. Increase the frequency of security awareness training
D. Add an additional firewall rule between users and the directory server
Rationale: PAM solutions with credential vaulting and session recording
directly address the risk of shared privileged accounts by ensuring individual
accountability, just-in-time access, and audit trails. Password complexity alone
,does not prevent sharing, training is not a technical control, and firewall rules do
not address credential sharing .
Question 5
A government agency is planning a hybrid cloud deployment. Strict controls must
be in place that can label classified data. The solution must ensure that access
rights will be granted based on the user's government security classification.
Which access control model should be used?
A. Role-Based Access Control (RBAC)
B. Mandatory Access Control (MAC)
C. Attribute-Based Access Control (ABAC)
D. Discretionary Access Control (DAC)
Rationale: MAC is standard for classified environments. Access is based on
system-enforced security labels (e.g., Top Secret, Confidential), and users cannot
change these controls .
Question 6
Which principle ensures users are granted only the minimal access rights needed
to perform their job functions?
A. Defense in Depth
B. Separation of Duties
C. Least Privilege
D. Zero Trust
Rationale: The principle of least privilege limits access rights to the absolute
minimum necessary, reducing the attack surface and potential damage from
compromised accounts .
Question 7
A cybersecurity analyst at a software company conducted a vulnerability
assessment and discovered multiple vulnerabilities on the company's webpage.
, The CISO decided not to fix the discrepancies due to the vulnerabilities being
outside of the organization's resources. Which risk mitigation strategy is
demonstrated?
A. Accept
B. Mitigate
C. Avoid
D. Transfer
Rationale: Risk acceptance acknowledges a risk but takes no action, often
because the cost of mitigation is not justified .
Question 8
A security team notices traffic coming from a country where the organization
does not have any business operations. Which of the following could this be an
indicator of?
A. High call volume
B. Odd network traffic
C. Geographic anomalies
D. Unauthorized changes
Rationale: Traffic from unexpected geographic locations is a geographic
anomaly that may indicate a security threat .
Question 9
A security architect is designing a strategy to help continue operating in the face
of a cyber-attack. Which of the following will help accomplish this objective?
A. Heterogeneity
B. Clustering
C. Redundancy
D. Virtualization