• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 34 pages
Exam (elaborations)

WGU D488 Objective Assessment OA Exam Nursing 2026/2027 – Questions and Answers | 100% Verified | Detailed Rationales – Pass Guaranteed – A+ Graded

Document preview thumbnail
Preview 4 out of 34 pages

WGU D488 Objective Assessment OA Exam Nursing 2026/2027 – Questions with Answers | 100% Correct | Nursing Practice, Clinical Reasoning, Patient Safety, Assessment, Ethics, Safety | Graded A+ Verified | Evidence-Based Practice, Care Coordination, Leadership, Informatics, Policy | Detailed Rationales | Verified Correct Answers – Pass Guaranteed – Instant Download

Content preview

CYBERSECURITY ARCHITECTURE · OBJECTIVE ASSESSMENT A+ VERIFIED
New WGU D488 Objective Assessment
2026/2027 Test Bank 2 — Complete
Official Exam Test Bank

150 Questions Full Rationales Verified Answers Test Bank 2




A+ 6 100%
QUESTIONS SECTIONS RATIONALES
Complete coverage Core exam domains Every answer explained


WHAT THIS COVERS

01 Risk Management, Governance & Compliance


02 Secure Network & Infrastructure Architecture


03 Cloud, Virtualization & Enterprise Data Security


04 Threat Analysis, Vulnerability Management & Incident Response


05 Secure Application Integration, Architecture Patterns & Resilience


06 Cryptography & Identity/Access Architecture




ABOUT THIS ASSESSMENT
Build mastery in cybersecurity architecture and engineering — from risk management, governance, and compliance to secure network and
infrastructure architecture, cloud and virtualization security, threat analysis, vulnerability management, incident response, secure
application integration, architecture patterns, resilience, cryptography, and identity and access architecture. This original study bank
targets application and analysis skills for the WGU D488 Objective Assessment, with full rationales for every answer. For review use only;
not an institutional proctored assessment.




PASSING SCORE LEVEL FORMAT
75% Advanced (Cybersecurity Architecture) Application / Analysis


STUVIA ACTUAL EXAM Page 1

,SECTION 1: Risk Management, Governance & Compliance


Q1. A financial services firm is preparing its annual risk assessment for the board. The CISO must prioritize residual risks after
controls are applied. Which approach most effectively supports risk-informed decision making at the executive level?
A. Presenting only inherent risk scores without control context
B. Mapping residual risk to business impact and risk appetite thresholds
C. Listing every technical vulnerability found in the last scan
D. Focusing exclusively on compliance checklist completion rates
Correct Answer: B
Rationale:
Executives need residual risk expressed in business terms against risk appetite. Pure technical lists or inherent-only views do not enable
prioritization or resource allocation decisions.

Q2. An organization adopts a zero-trust architecture initiative. The governance committee asks how policy enforcement points
should be controlled. Which governance mechanism best ensures consistent policy application across hybrid environments?
A. Allowing each business unit to define its own local access policies
B. Relying solely on annual policy document reviews
C. Disabling all network-level controls in favor of endpoint-only controls
D. Centralized policy decision points with distributed enforcement points
Correct Answer: D
Rationale:
Zero-trust requires centralized decisioning for consistency while enforcement can be distributed. Local-only policies create fragmentation;
disabling network controls weakens defense-in-depth.

Q3. A healthcare provider must demonstrate compliance with HIPAA Security Rule requirements for electronic protected health
information. During an audit, the assessor requests evidence of ongoing risk analysis. Which artifact most directly satisfies
this request?
A. A one-time network diagram created three years ago
B. A list of all employees who completed generic security awareness training
C. Documented risk assessments performed at defined intervals with remediation tracking
D. Vendor marketing materials for the electronic health record system
Correct Answer: C
Rationale:
HIPAA requires ongoing risk analysis. Periodic documented assessments with tracked remediation provide the required evidence; static
diagrams or training lists alone are insufficient.

Q4. The enterprise risk committee reviews a proposed control that costs significantly more than the expected annual loss from
the threat it addresses. Which risk treatment decision is most consistent with quantitative risk management principles?
A. Implement the control because any reduction in risk is mandatory
B. Eliminate the business process entirely to avoid the threat
C. Ignore the cost analysis and follow industry peer practices only
D. Accept or transfer the risk when control cost exceeds expected loss reduction
Correct Answer: D
Rationale:
When the cost of a control exceeds the reduction in expected loss, acceptance or transfer is often the rational choice. Blind implementation
ignores economic reality.




STUVIA ACTUAL EXAM · Page 2

,SECTION 1: Risk Management, Governance & Compliance


Q5. A multinational company must align its cybersecurity program with both NIST CSF and ISO 27001. The security architecture
team is mapping controls. Which approach best reduces duplication while satisfying both frameworks?
A. Maintaining two completely separate control catalogs with no cross-reference
B. Using a common control framework that maps to both NIST CSF and ISO 27001 requirements
C. Implementing only NIST CSF and declaring ISO 27001 out of scope
D. Focusing solely on technical controls and ignoring organizational controls
Correct Answer: B
Rationale:
A mapped common-control approach satisfies multiple frameworks efficiently. Separate catalogs increase overhead; ignoring one framework or
entire control categories creates gaps.

Q6. During a tabletop exercise, the incident response team discovers that the current risk register does not include supply-chain
compromise scenarios. Which action most improves the risk management process?
A. Removing all third-party dependencies from the environment
B. Updating the risk register and threat models to include supply-chain scenarios and owners
C. Assuming that existing antivirus software fully covers supply-chain risk
D. Deferring any action until after the next annual audit
Correct Answer: B
Rationale:
Identified gaps must be reflected in the risk register with assigned owners so that treatment can be planned. Ignoring or deferring leaves the
organization exposed.

Q7. A board-level dashboard shows that several high-impact risks have remained open beyond their agreed treatment
deadlines. Which governance response is most appropriate?
A. Reassign the risks to a lower priority category without analysis
B. Transfer all overdue risks to the internal audit team
C. Delete the risks from the register to improve metrics
D. Escalate the overdue risks, review treatment plans, and adjust resources or acceptance decisions
Correct Answer: D
Rationale:
Overdue high-impact risks require escalation and active management. Deleting or artificially lowering priority undermines governance integrity.

Q8. An organization is selecting a GRC platform to support continuous control monitoring. Which capability is most critical for
linking technical findings to compliance obligations?
A. Ability to generate colorful executive presentations only
B. Automated mapping of control failures to specific regulatory and policy requirements
C. Unlimited storage of historical vulnerability scan data without prioritization
D. Integration limited solely to the email system for ticket creation
Correct Answer: B
Rationale:
The value of continuous monitoring lies in translating technical results into compliance impact. Presentation features or raw data storage alone
do not achieve this linkage.

Q9. A new privacy regulation requires data minimization and purpose limitation. The architecture team is reviewing existing data
flows. Which design change most directly supports these principles?
A. Collecting additional demographic fields for future undefined analytics
B. Restricting collection and retention to data elements required for stated business purposes
C. Replicating all production data into unrestricted development environments
D. Disabling encryption so that data can be inspected more easily
Correct Answer: B
Rationale:
Data minimization and purpose limitation require collecting and keeping only what is necessary for defined purposes. Expanding collection or
unrestricted copies work against these principles.




STUVIA ACTUAL EXAM · Page 3

, SECTION 1: Risk Management, Governance & Compliance


Q10. The CISO must report the organization’s cybersecurity posture to external regulators. Which combination of metrics
provides the most balanced view of program effectiveness?
A. Only the number of blocked firewall connections
B. A mix of leading indicators (training completion, patch latency) and lagging indicators (incident rate, dwell time)
C. Solely the annual budget spent on security tools
D. The count of policies published in the last fiscal year
Correct Answer: B
Rationale:
Balanced scorecards combine leading (preventive) and lagging (outcome) indicators. Single technical or budget metrics give an incomplete
picture of effectiveness.

Q11. A cloud migration project introduces new shared-responsibility boundaries. The risk team is updating the control ownership
matrix. Which principle should guide assignment of security responsibilities?
A. Assigning all security responsibility solely to the cloud provider
B. Explicitly documenting provider versus customer responsibilities for each control domain
C. Assuming traditional on-premises ownership models still apply unchanged
D. Leaving ownership undefined until an incident occurs
Correct Answer: B
Rationale:
Shared-responsibility models require clear, documented division of duties. Ambiguity or wholesale transfer of responsibility creates control
gaps.

Q12. An internal audit finds that several business units have implemented shadow IT SaaS applications without security review.
Which governance control most effectively reduces this risk going forward?
A. Banning all SaaS usage organization-wide
B. Relying only on annual employee attestations of compliance
C. Establishing a formal cloud service intake and risk-assessment process with continuous discovery
D. Increasing the frequency of phishing simulations
Correct Answer: C
Rationale:
A structured intake process plus discovery tooling addresses both prevention and detection of unsanctioned services. Total bans are often
impractical and drive further shadow activity.

Q13. The organization must comply with PCI DSS for cardholder data. Architects are designing network segmentation. Which
design choice most directly supports PCI scope reduction?
A. Isolating the cardholder data environment with controlled, monitored entry points
B. Placing all systems, including non-card systems, in a single flat network
C. Encrypting all traffic while leaving the network fully flat and open
D. Outsourcing the entire payment process without any residual contractual controls
Correct Answer: A
Rationale:
Segmentation that isolates the cardholder data environment is a primary method of reducing PCI scope. Flat networks expand scope;
encryption alone does not reduce network scope.




STUVIA ACTUAL EXAM · Page 4

Document information

Uploaded on
September 24, 2026
Number of pages
34
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$16.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAACTUALEXAMS
3.5
(176)
Sold
1339
Followers
209
Items
10203
Last sold
14 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions