• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 40 pages
Exam (elaborations)

WGU D488 Cybersecurity Architecture Engineering OA 2026/2027 – Questions and Answers | 100% Verified | Detailed Rationales – Pass Guaranteed – A+ Graded

Document preview thumbnail
Preview 4 out of 40 pages

WGU D488 Cybersecurity Architecture Engineering OA 2026/2027 – Questions with Answers | 100% Correct | Network Security, Cryptography, Risk Management, Architecture, Frameworks, Ethics | Graded A+ Verified | Identity Management, Cloud Security, Incident Response, Compliance, Auditing | Detailed Rationales | Verified Correct Answers – Pass Guaranteed – Instant Download

Content preview

A+ VERIFIED
CYBERSECURITY ARCHITECTURE · OBJECTIVE ASSESSMENT


WGU D488 Cybersecurity Architecture and Engineering OA — Complete
Official Exam

150 Questions Full Rationales Verified Answers




A+ 6 100%
QUESTIONS SECTIONS RATIONALES
Complete coverage Core exam domains Every answer explained



WHAT THIS COVERS

01 Risk Management, Governance & Compliance


02 Secure Network & Infrastructure Architecture


03 Cloud, Virtualization & Enterprise Data Security


04 Threat Analysis, Vulnerability Management & Incident Response


05 Secure Application Integration, Architecture Patterns & Resilience


06 Cryptography & Identity/Access Architecture




ABOUT THIS ASSESSMENT
Build mastery in cybersecurity architecture and engineering — from risk management, governance, and compliance to secure network and
infrastructure architecture, cloud and virtualization security, threat analysis, vulnerability management, incident response, secure
application integration, architecture patterns, resilience, cryptography, and identity and access architecture. This original study bank
targets application and analysis skills for the WGU D488 Objective Assessment, with full rationales for every answer. For review use only;
not an institutional proctored assessment.




PASSING SCORE LEVEL FORMAT
75% Advanced (Cybersecurity Architecture) Application / Analysis


STUVIA ACTUAL EXAM Page 1

, SECTION 1: Risk Management, Governance & Compliance
Q1. A financial services firm expanding its cloud footprint must demonstrate continuous compliance with PCI DSS and SOC 2. The
CISO asks the architecture team to embed automated evidence collection into the CI/CD pipeline. Which approach best supports
regulatory mapping and real-time audit readiness?

A. Map each pipeline stage to COBIT objectives and generate quarterly static reports
B. Implement continuous control monitoring that tags every change with NIST CSF and ISO 27001 identifiers and stores immutable
evidence in a dedicated repository
C. Rely solely on annual third-party penetration tests and manual spreadsheet tracking
D. Adopt a pure risk-acceptance model without control tagging

Correct Answer: B
Rationale:
Continuous control monitoring with automated tagging produces living evidence auditors can sample at any time. Static quarterly reports and annual
tests leave assessment gaps, while pure risk acceptance without control linkage fails PCI DSS and SOC 2 evidence requirements.


Q2. During a residual-risk workshop, stakeholders disagree on a supply-chain vulnerability in a critical payment library (CVSS 8.7, no
vendor patch for 90 days, processes cardholder data). Which risk-response decision is most consistent with mature enterprise risk
management?

A. Accept the risk because delaying the next release has higher business impact
B. Transfer the risk by purchasing cyber-insurance and continue using the library unchanged
C. Avoid the risk by immediately removing the library and rewriting the payment module
D. Mitigate with a compensating control such as RASP that blocks the known exploit path, plus enhanced monitoring, while planning
long-term replacement

Correct Answer: D
Rationale:
Mature programs prefer mitigation with compensating controls when immediate avoidance would cause severe disruption. Pure acceptance of a
CVSS 8.7 cardholder-data vulnerability is rarely justifiable under PCI DSS. Insurance does not reduce immediate technical exposure.


Q3. A university preparing for its first SOC 2 Type II audit must define the system boundary and trust services criteria. Primary regulated
data consists of student records and research IP. Which combination of trust services criteria is most appropriate?

A. Security and Confidentiality only
B. Security, Availability, and Processing Integrity
C. Security, Confidentiality, and Privacy
D. Availability, Processing Integrity, and Privacy

Correct Answer: C
Rationale:
Student records and research IP primarily require confidentiality and privacy in addition to baseline Security. Availability and Processing Integrity are
secondary for this data classification profile.


Q4. An organization has adopted NIST Cybersecurity Framework 2.0. The architecture team must measure maturity of the Govern
function across six business units with different risk appetites. Which measurement approach yields the most actionable results?

A. Assign a single qualitative maturity score to the entire enterprise based on the lowest-scoring unit
B. Use a capability-maturity model that scores each Govern subcategory independently per business unit and produces a heat-map of
gaps
C. Count the number of documented policies as the maturity metric
D. Rely exclusively on external audit findings from the previous three years

Correct Answer: D
Rationale:
Scoring each Govern subcategory per business unit produces granular, comparable data. A single enterprise score hides variation. Policy count is
incomplete. Historical findings are useful context but not a systematic maturity assessment.




STUVIA ACTUAL EXAM · Page 2

, SECTION 1: Risk Management, Governance & Compliance
Q5. A healthcare provider redesigning identity governance to meet HIPAA and CMMC Level 2 must choose a control that satisfies both
frameworks' access-review mandates. Which control provides the strongest dual coverage?

A. Annual manager attestation with no technical enforcement
B. Quarterly automated access certification requiring manager and data-owner approval, with automatic de-provisioning of non-certified
accounts after a grace period
C. Real-time monitoring of privileged sessions without periodic certification
D. Role-based access matrices reviewed only when a new application is onboarded

Correct Answer: C
Rationale:
Both HIPAA and CMMC emphasize periodic documented access reviews. Automated campaigns with dual approval and automatic de-provisioning
create auditable evidence and reduce orphaned accounts.


Q6. The board requests a quantitative risk analysis for a proposed internet-facing customer portal. The team has ALE, SLE, and ARO
figures for three threat scenarios. Which additional factor must be incorporated before residual risk can be used for capital-budget
decisions?

A. The qualitative risk appetite statement published two years earlier
B. The cost of proposed security controls that will reduce the ALE, enabling cost-benefit comparison
C. The number of employees who completed phishing training last quarter
D. The marketing department's projected user-growth rate

Correct Answer: B
Rationale:
Quantitative risk decisions require comparing control cost against reduction in expected loss. Without control-cost data, residual ALE cannot be
evaluated against appetite in financial terms.


Q7. An enterprise mapping its control environment to CIS Controls v8 Implementation Group 2 finds several Safeguards under Control 4
only partially implemented. Which prioritization method is most consistent with CIS guidance for IG2?

A. Implement every Safeguard simultaneously
B. Prioritize Safeguards that protect assets classified as critical or high-value first, then address lower-value assets
C. Focus exclusively on Safeguards that can be automated and defer manual ones
D. Select Safeguards at random to avoid bias

Correct Answer: D
Rationale:
CIS recommends risk-based prioritization: protect the most critical assets first. Simultaneous full implementation is rarely practical. Automation
preference is secondary.


Q8. A multinational corporation must satisfy GDPR and CCPA for data-subject access requests. The team is designing a centralized
DSAR orchestration platform. Which design decision most effectively reduces legal risk while improving response-time metrics?

A. Store all personal data in a single global database
B. Implement a federated discovery engine that queries regional data stores according to residency rules, applies jurisdiction-specific
redaction, and produces an auditable response package within statutory deadlines
C. Route every DSAR to legal for manual review before any data is released
D. Refuse DSARs that originate from jurisdictions other than the data subject's declared country

Correct Answer: B
Rationale:
A federated engine respects residency constraints, applies correct legal redaction rules, and still meets statutory timelines. A single global database
violates many residency laws.




STUVIA ACTUAL EXAM · Page 3

, SECTION 1: Risk Management, Governance & Compliance
Q9. An internal audit discovers the risk register has not been updated in eighteen months and several high-impact risks lack assigned
owners. Which governance remediation should the CISO recommend first?

A. Immediately purchase additional cyber insurance for all unowned risks
B. Re-establish a risk-ownership matrix, assign accountable executives to every high and critical risk, and institute a quarterly
risk-register review cadence enforced by the risk committee
C. Delete all risks older than one year from the register
D. Outsource the entire risk-management function to a managed security service provider

Correct Answer: B
Rationale:
Clear ownership and a regular review cadence are foundational. Without them residual risk remains invisible to leadership.


Q10. A manufacturing firm adopting zero-trust architecture principles is asked how the existing ISO 27001 Statement of Applicability
should be updated. Which approach preserves certification integrity?

A. Mark every Annex A control as not applicable because zero trust replaces traditional perimeter controls
B. Perform a gap analysis between the current SoA and the zero-trust control set, update applicability and implementation status of
each control, and document residual gaps with compensating measures
C. Replace the entire SoA with a document based solely on NIST SP 800-207
D. Leave the SoA unchanged until the next surveillance audit

Correct Answer: B
Rationale:
ISO 27001 requires the SoA to reflect the actual control environment. A structured gap analysis updates applicability while preserving the
certification trail.


Q11. An energy utility must comply with NERC CIP. The architecture team is evaluating a remote-access solution for substations against
CIP-005 electronic-security-perimeter requirements. Which design element is mandatory?

A. Allow unrestricted outbound internet access from the substation for vendor patching
B. Enforce intermediate system (jump-host) mediation for all interactive remote access into the electronic security perimeter, with
multi-factor authentication and session logging
C. Rely solely on VPN encryption without any intermediate system
D. Permit direct RDP connections from the corporate network into substation HMIs

Correct Answer: B
Rationale:
NERC CIP-005 explicitly requires intermediate systems for interactive remote access, MFA, and logging. Direct connections or unrestricted
outbound access violate the controls.


Q12. A SaaS provider preparing its SOC report is asked to identify complementary user-entity controls (CUECs). Which statement
correctly describes the purpose of CUECs?

A. CUECs are controls the SaaS provider implements on behalf of the customer so the customer has no residual responsibility
B. CUECs are controls the customer is expected to implement in its own environment for overall control objectives to be achieved; the
provider's report discloses them so customers understand shared-responsibility duties
C. CUECs are optional recommendations that appear only in the management letter
D. CUECs replace the need for the customer to perform its own risk assessment

Correct Answer: C
Rationale:
CUECs document the customer's share of control responsibility. They appear in the SOC report so user entities understand what they must do.




STUVIA ACTUAL EXAM · Page 4

Document information

Uploaded on
September 24, 2026
Number of pages
40
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$16.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STUVIAACTUALEXAMS
3.5
(176)
Sold
1339
Followers
209
Items
10203
Last sold
14 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions