Graduate Capstone Task 3
Complete Solutions 2026/2027
120 Questions with Detailed Answers and Rationales
Already Graded A+
Western Governors University (WGU)
Master of Science in Cybersecurity and Information Assurance
Capstone Task 3 - Project Design, Implementation & Defense
COGNITIVE LEVELS: 25% Recall | 50% Application | 25% Analysis
FORMAT: 75% Scenario-based | 25% Direct Recall
TOTAL QUESTIONS: 120 across 8 Content Domains
Section 1: Capstone Task 3 Foundations and Project Scoping (Q1-Q19)
Problem Statement, Objectives, Stakeholders, & Success Criteria
,Q1: A cybersecurity graduate student is developing the problem statement for their WGU
D490 MSCIA Capstone Task 3 project. The sponsoring organization is a mid-size healthcare
provider experiencing an increase in phishing-related credential compromise incidents
despite having mandatory security awareness training. Which problem statement BEST
aligns with the D490 Task 3 rubric requirement for a well-scoped, measurable security
improvement project?
A. 'The organization needs better security awareness training because employees keep clicking
on phishing links.'
B. 'Despite mandatory annual security awareness training, the organization experienced a 45%
increase in credential compromise incidents from phishing attacks over the past 12 months,
indicating a gap between training delivery and behavioral adoption, requiring a multi-layered
technical and process-based solution to reduce successful phishing incidents by 60% within 6
months.' [CORRECT]
C. 'Phishing is a major problem in healthcare and the organization should implement more
controls.'
D. 'The IT department has identified that phishing attacks are increasing and recommends
purchasing a new email security appliance.'
Correct Answer: B
Rationale: The D490 Task 3 rubric requires a problem statement that is specific, measurable, identifies a
clear security gap, and connects to business impact. Option B includes quantified data (45% increase),
identifies the specific gap (training delivery vs. behavioral adoption), proposes a multi-layered solution
(technical + process), and establishes a measurable success criterion (60% reduction in 6 months).
Options A and C are vague and lack measurability. Option D jumps to a solution without properly scoping
the problem. EXAM PEARL: WGU D490 Task 3 problem statements must include: (1) specific security gap
identified, (2) quantified business impact, (3) connection to organizational risk, (4) measurable success
criteria. Vague statements like 'need better training' or 'phishing is bad' fail the rubric. Always tie the
problem to business objectives and risk tolerance.
,Q2: A D490 capstone student is developing SMART objectives for their project. The
sponsoring organization wants to 'improve their overall security posture.' Which objective
BEST meets the SMART criteria (Specific, Measurable, Achievable, Relevant, Time-bound)
per the D490 Task 3 rubric?
A. 'Implement security improvements within the IT department.'
B. 'Reduce the mean time to detect (MTTD) and respond (MTTR) to security incidents from the
current baseline of 72 hours to under 24 hours within 6 months by implementing a SIEM
solution with automated alerting and an incident response runbook.' [CORRECT]
C. 'Achieve 100% compliance with all cybersecurity frameworks within 1 year.'
D. 'Deploy modern security tools to protect against all threats.'
Correct Answer: B
Rationale: Option B is the only choice that satisfies all five SMART criteria: Specific (implement SIEM
with automated alerting and IR runbook), Measurable (reduce MTTD/MTTR from 72 hours to under 24
hours), Achievable (realistic scope with defined technical solution), Relevant (directly addresses incident
response capability), and Time-bound (within 6 months). Option A lacks specificity and measurability.
Option C is unrealistic ('100% compliance,' 'all frameworks'). Option D is vague with no metrics or
timeline. EXAM PEARL: SMART criteria for D490 Task 3 — Specific (what exactly will be done),
Measurable (quantifiable metrics like MTTD, MTTR, incident reduction %), Achievable (realistic with
available resources), Relevant (addresses the identified problem), Time-bound (defined completion date).
Avoid vague goals ('improve security posture') and unrealistic targets ('100% compliance').
Q3: During stakeholder analysis for a D490 capstone project, the student identifies the
following stakeholders: CIO (executive sponsor), IT Director (technical lead), HR Manager
(process owner for onboarding/offboarding), and end users (affected by changes). Which
stakeholder engagement approach is MOST appropriate for the CIO as executive sponsor?
A. Send weekly technical reports detailing vulnerability scan results and patching status
B. Provide monthly executive dashboards with high-level metrics, risk reduction progress, and
business impact aligned to strategic objectives [CORRECT]
C. Invite the CIO to all technical implementation meetings and design reviews
D. Communicate only at project kickoff and final presentation
Correct Answer: B
Rationale: Executive sponsors like the CIO need high-level, strategically aligned communication that
focuses on business outcomes, risk reduction, and ROI — not technical details. Monthly executive
dashboards with KPIs (e.g., risk reduction percentages, incident trends, compliance status) align with the
executive's decision-making needs. Option A (weekly technical reports) is too detailed for an executive
audience. Option C (inviting to all technical meetings) wastes the CIO's time and is inappropriate for their
role. Option D (only kickoff and final) provides insufficient engagement for an executive sponsor who
needs to champion the project. EXAM PEARL: Stakeholder communication in D490 Task 3 must be
tailored to the stakeholder's role: Executive sponsors (CIO/CISO) — high-level dashboards, business
impact, strategic alignment, monthly or quarterly. Technical leads (IT Director, Security Manager) —
detailed technical reports, design documents, weekly. Process owners (HR, Legal) — process workflows,
policy changes, as needed. End users — awareness training, brief communications, change
announcements.
, Q4: A D490 student is developing the project charter for their capstone. Which element is
MOST critical to include to ensure the project scope is properly bounded and prevents
scope creep during implementation?
A. A detailed budget breakdown including all software licensing costs
B. Clearly defined project boundaries including what is IN scope and what is explicitly OUT of
scope, with documented assumptions and constraints [CORRECT]
C. Complete resumes of all project team members
D. Full technical specifications for every security control to be implemented
Correct Answer: B
Rationale: The project charter's most critical scope-management element is clearly defining boundaries
— what is included (in scope) and explicitly excluded (out of scope) — along with assumptions and
constraints. This prevents scope creep, manages stakeholder expectations, and provides a reference point
for change requests. Option A (budget) is important but secondary to scope definition. Option C (team
resumes) is unnecessary for a project charter. Option D (full technical specs) belongs in the design
document, not the charter — the charter defines WHAT the project will achieve, not HOW every control
works. EXAM PEARL: D490 Task 3 project charter must include: (1) Problem statement (the security gap),
(2) Objectives (SMART goals), (3) Scope (in-scope and out-of-scope boundaries), (4) Deliverables (what will
be produced), (5) Assumptions and constraints, (6) Stakeholders and roles, (7) High-level
timeline/milestones, (8) Success criteria. Scope creep is prevented by documenting boundaries and
having a formal change control process.
Q5: A capstone student is working with a financial services organization that must comply
with SOX, GLBA, and PCI DSS regulations. The student's project focuses on implementing a
data loss prevention (DLP) solution. Which success criterion BEST demonstrates alignment
with both business objectives AND regulatory requirements for the D490 Task 3 rubric?
A. 'The DLP solution will be fully deployed within 6 months.'
B. 'The DLP solution will reduce unauthorized data exfiltration events by 75% within 6 months,
as measured by DLP incident reports, while improving the organization's ability to demonstrate
compliance with GLBA Safeguards Rule data protection requirements and SOX internal controls
over financial data, as evidenced by audit findings.' [CORRECT]
C. 'The DLP solution will block all data leaks and prevent all compliance violations.'
D. 'The DLP solution will satisfy the IT department's requirement for better data monitoring.'
Correct Answer: B
Rationale: Option B is the best answer because it is: Specific (reduce unauthorized data exfiltration by
75%), Measurable (DLP incident reports), Achievable (realistic target), Relevant (addresses data
protection), Time-bound (6 months), AND connects to specific regulatory requirements (GLBA Safeguards
Rule, SOX internal controls) with evidence (audit findings). Option A only measures deployment, not
effectiveness. Option C is unrealistic ('all data leaks,' 'all violations'). Option D is too narrowly focused on
IT preferences without business or regulatory alignment. EXAM PEARL: D490 Task 3 success criteria
must: (1) Be SMART (Specific, Measurable, Achievable, Relevant, Time-bound), (2) Connect to business
objectives (risk reduction, operational efficiency), (3) Address regulatory/compliance requirements, (4)
Include evidence/metrics for validation, (5) Align with the identified problem statement. Deployment
milestones alone are insufficient — the project must demonstrate security improvement.