CYBERSECURITY ARCHITECTURE · OBJECTIVE ASSESSMENT
WGU D488 Cybersecurity Architecture and Engineering OA — Complete
Official Exam
150 Questions Full Rationales Verified Answers
A+ 6 100%
QUESTIONS SECTIONS RATIONALES
Complete coverage Core exam domains Every answer explained
WHAT THIS COVERS
01 Risk Management, Governance & Compliance
02 Secure Network & Infrastructure Architecture
03 Cloud, Virtualization & Enterprise Data Security
04 Threat Analysis, Vulnerability Management & Incident Response
05 Secure Application Integration, Architecture Patterns & Resilience
06 Cryptography & Identity/Access Architecture
ABOUT THIS ASSESSMENT
Build mastery in cybersecurity architecture and engineering — from risk management, governance, and compliance to secure network and
infrastructure architecture, cloud and virtualization security, threat analysis, vulnerability management, incident response, secure
application integration, architecture patterns, resilience, cryptography, and identity and access architecture. This original study bank
targets application and analysis skills for the WGU D488 Objective Assessment, with full rationales for every answer. For review use only;
not an institutional proctored assessment.
PASSING SCORE LEVEL FORMAT
75% Advanced (Cybersecurity Architecture) Application / Analysis
STUVIA ACTUAL EXAM Page 1
, SECTION 1: Risk Management, Governance & Compliance
Q1. A financial services firm expanding its cloud footprint must demonstrate continuous compliance with PCI DSS and SOC 2. The
CISO asks the architecture team to embed automated evidence collection into the CI/CD pipeline. Which approach best supports
regulatory mapping and real-time audit readiness?
A. Map each pipeline stage to COBIT objectives and generate quarterly static reports
B. Implement continuous control monitoring that tags every change with NIST CSF and ISO 27001 identifiers and stores immutable
evidence in a dedicated repository
C. Rely solely on annual third-party penetration tests and manual spreadsheet tracking
D. Adopt a pure risk-acceptance model without control tagging
Correct Answer: B
Rationale:
Continuous control monitoring with automated tagging produces living evidence auditors can sample at any time. Static quarterly reports and annual
tests leave assessment gaps, while pure risk acceptance without control linkage fails PCI DSS and SOC 2 evidence requirements.
Q2. During a residual-risk workshop, stakeholders disagree on a supply-chain vulnerability in a critical payment library (CVSS 8.7, no
vendor patch for 90 days, processes cardholder data). Which risk-response decision is most consistent with mature enterprise risk
management?
A. Accept the risk because delaying the next release has higher business impact
B. Transfer the risk by purchasing cyber-insurance and continue using the library unchanged
C. Avoid the risk by immediately removing the library and rewriting the payment module
D. Mitigate with a compensating control such as RASP that blocks the known exploit path, plus enhanced monitoring, while planning
long-term replacement
Correct Answer: D
Rationale:
Mature programs prefer mitigation with compensating controls when immediate avoidance would cause severe disruption. Pure acceptance of a
CVSS 8.7 cardholder-data vulnerability is rarely justifiable under PCI DSS. Insurance does not reduce immediate technical exposure.
Q3. A university preparing for its first SOC 2 Type II audit must define the system boundary and trust services criteria. Primary regulated
data consists of student records and research IP. Which combination of trust services criteria is most appropriate?
A. Security and Confidentiality only
B. Security, Availability, and Processing Integrity
C. Security, Confidentiality, and Privacy
D. Availability, Processing Integrity, and Privacy
Correct Answer: C
Rationale:
Student records and research IP primarily require confidentiality and privacy in addition to baseline Security. Availability and Processing Integrity are
secondary for this data classification profile.
Q4. An organization has adopted NIST Cybersecurity Framework 2.0. The architecture team must measure maturity of the Govern
function across six business units with different risk appetites. Which measurement approach yields the most actionable results?
A. Assign a single qualitative maturity score to the entire enterprise based on the lowest-scoring unit
B. Use a capability-maturity model that scores each Govern subcategory independently per business unit and produces a heat-map of
gaps
C. Count the number of documented policies as the maturity metric
D. Rely exclusively on external audit findings from the previous three years
Correct Answer: D
Rationale:
Scoring each Govern subcategory per business unit produces granular, comparable data. A single enterprise score hides variation. Policy count is
incomplete. Historical findings are useful context but not a systematic maturity assessment.
STUVIA ACTUAL EXAM · Page 2
, SECTION 1: Risk Management, Governance & Compliance
Q5. A healthcare provider redesigning identity governance to meet HIPAA and CMMC Level 2 must choose a control that satisfies both
frameworks' access-review mandates. Which control provides the strongest dual coverage?
A. Annual manager attestation with no technical enforcement
B. Quarterly automated access certification requiring manager and data-owner approval, with automatic de-provisioning of non-certified
accounts after a grace period
C. Real-time monitoring of privileged sessions without periodic certification
D. Role-based access matrices reviewed only when a new application is onboarded
Correct Answer: C
Rationale:
Both HIPAA and CMMC emphasize periodic documented access reviews. Automated campaigns with dual approval and automatic de-provisioning
create auditable evidence and reduce orphaned accounts.
Q6. The board requests a quantitative risk analysis for a proposed internet-facing customer portal. The team has ALE, SLE, and ARO
figures for three threat scenarios. Which additional factor must be incorporated before residual risk can be used for capital-budget
decisions?
A. The qualitative risk appetite statement published two years earlier
B. The cost of proposed security controls that will reduce the ALE, enabling cost-benefit comparison
C. The number of employees who completed phishing training last quarter
D. The marketing department's projected user-growth rate
Correct Answer: B
Rationale:
Quantitative risk decisions require comparing control cost against reduction in expected loss. Without control-cost data, residual ALE cannot be
evaluated against appetite in financial terms.
Q7. An enterprise mapping its control environment to CIS Controls v8 Implementation Group 2 finds several Safeguards under Control 4
only partially implemented. Which prioritization method is most consistent with CIS guidance for IG2?
A. Implement every Safeguard simultaneously
B. Prioritize Safeguards that protect assets classified as critical or high-value first, then address lower-value assets
C. Focus exclusively on Safeguards that can be automated and defer manual ones
D. Select Safeguards at random to avoid bias
Correct Answer: D
Rationale:
CIS recommends risk-based prioritization: protect the most critical assets first. Simultaneous full implementation is rarely practical. Automation
preference is secondary.
Q8. A multinational corporation must satisfy GDPR and CCPA for data-subject access requests. The team is designing a centralized
DSAR orchestration platform. Which design decision most effectively reduces legal risk while improving response-time metrics?
A. Store all personal data in a single global database
B. Implement a federated discovery engine that queries regional data stores according to residency rules, applies jurisdiction-specific
redaction, and produces an auditable response package within statutory deadlines
C. Route every DSAR to legal for manual review before any data is released
D. Refuse DSARs that originate from jurisdictions other than the data subject's declared country
Correct Answer: B
Rationale:
A federated engine respects residency constraints, applies correct legal redaction rules, and still meets statutory timelines. A single global database
violates many residency laws.
STUVIA ACTUAL EXAM · Page 3
, SECTION 1: Risk Management, Governance & Compliance
Q9. An internal audit discovers the risk register has not been updated in eighteen months and several high-impact risks lack assigned
owners. Which governance remediation should the CISO recommend first?
A. Immediately purchase additional cyber insurance for all unowned risks
B. Re-establish a risk-ownership matrix, assign accountable executives to every high and critical risk, and institute a quarterly
risk-register review cadence enforced by the risk committee
C. Delete all risks older than one year from the register
D. Outsource the entire risk-management function to a managed security service provider
Correct Answer: B
Rationale:
Clear ownership and a regular review cadence are foundational. Without them residual risk remains invisible to leadership.
Q10. A manufacturing firm adopting zero-trust architecture principles is asked how the existing ISO 27001 Statement of Applicability
should be updated. Which approach preserves certification integrity?
A. Mark every Annex A control as not applicable because zero trust replaces traditional perimeter controls
B. Perform a gap analysis between the current SoA and the zero-trust control set, update applicability and implementation status of
each control, and document residual gaps with compensating measures
C. Replace the entire SoA with a document based solely on NIST SP 800-207
D. Leave the SoA unchanged until the next surveillance audit
Correct Answer: B
Rationale:
ISO 27001 requires the SoA to reflect the actual control environment. A structured gap analysis updates applicability while preserving the
certification trail.
Q11. An energy utility must comply with NERC CIP. The architecture team is evaluating a remote-access solution for substations against
CIP-005 electronic-security-perimeter requirements. Which design element is mandatory?
A. Allow unrestricted outbound internet access from the substation for vendor patching
B. Enforce intermediate system (jump-host) mediation for all interactive remote access into the electronic security perimeter, with
multi-factor authentication and session logging
C. Rely solely on VPN encryption without any intermediate system
D. Permit direct RDP connections from the corporate network into substation HMIs
Correct Answer: B
Rationale:
NERC CIP-005 explicitly requires intermediate systems for interactive remote access, MFA, and logging. Direct connections or unrestricted
outbound access violate the controls.
Q12. A SaaS provider preparing its SOC report is asked to identify complementary user-entity controls (CUECs). Which statement
correctly describes the purpose of CUECs?
A. CUECs are controls the SaaS provider implements on behalf of the customer so the customer has no residual responsibility
B. CUECs are controls the customer is expected to implement in its own environment for overall control objectives to be achieved; the
provider's report discloses them so customers understand shared-responsibility duties
C. CUECs are optional recommendations that appear only in the management letter
D. CUECs replace the need for the customer to perform its own risk assessment
Correct Answer: C
Rationale:
CUECs document the customer's share of control responsibility. They appear in the SOC report so user entities understand what they must do.
STUVIA ACTUAL EXAM · Page 4