• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 4 fuera de 72 páginas
Examen

WGU D488 Cybersecurity Architecture and Engineering Final Exam 2026/2027 Actual Exam - Complete Questions with Detailed Rationales | 100% Verified Graded A+ Pass Guaranteed - A+ Graded

Document preview thumbnail
Vista previa 4 fuera de 72 páginas

WGU D488 Cybersecurity Architecture and Engineering Final Exam 2026/2027 Actual Exam - Complete Questions with Detailed Rationales | 100% Verified Graded A+ Pass Guaranteed - A+ Graded

Vista previa del contenido

1


WGU D488 Cybersecurity Architecture and Engineering
Final Exam 2026/2027 Actual Exam - Complete
Questions with Detailed Rationales | 100% Verified
Graded A+ Pass Guaranteed - A+ Graded


Part 1: Core Security Concepts & Risk Management (1–25)

1. A security analyst is conducting a risk assessment for a healthcare organization. Which of the
following correctly describes the relationship between vulnerability, threat, and risk?

• A) A threat is a weakness in the system, a vulnerability is a potential danger, and risk is the
probability of exploitation.

• B) A vulnerability is a weakness, a threat is a potential danger, and risk is the likelihood of a
threat exploiting a vulnerability.

• C) A threat is a weakness, a vulnerability is a potential danger, and risk is the impact of an attack.

• D) Vulnerability and threat are the same; risk is the impact.

Correct Answer✅ B
Detailed Rationale: A vulnerability is a flaw or weakness in a system (e.g., unpatched software).
A threat is any potential danger that could exploit a vulnerability (e.g., a hacker). Risk is the likelihood
that a specific threat will exploit a specific vulnerability and the resulting impact.

2. A company is evaluating the cost of a security breach. Which risk management metric calculates the
maximum amount of data loss an organization can tolerate over a specific time period?

• A) Recovery Time Objective (RTO)

• B) Recovery Point Objective (RPO)

• C) Service Level Agreement (SLA)

• D) Mean Time to Repair (MTTR)

Correct Answer✅ B
Detailed Rationale: RPO defines the maximum tolerable period in which data might be lost from an IT
service due to a major incident. For example, an RPO of 4 hours means the organization can lose no
more than 4 hours of data. RTO is the target time to restore services after an interruption.

3. An organization has decided to purchase cyber insurance to transfer the financial risk of a potential
data breach. This is an example of which risk treatment strategy?

,2


• A) Risk avoidance

• B) Risk mitigation

• C) Risk transference

• D) Risk acceptance

Correct Answer✅ C
Detailed Rationale: Risk transference shifts the financial burden of a risk to a third party, typically
through insurance policies or outsourcing. Risk mitigation reduces the likelihood or impact. Risk
avoidance eliminates the activity that creates the risk. Risk acceptance means acknowledging the risk
and taking no action.

4. A security architect is designing a new authentication system. Which of the following is considered a
"something you have" factor in multi-factor authentication (MFA)?

• A) Password

• B) Fingerprint

• C) Hardware token

• D) PIN

Correct Answer✅ C
Detailed Rationale: Multi-factor authentication relies on three categories: something you
know (password, PIN), something you have (smart card, hardware token, phone), and something you
are (biometrics like fingerprint or retina scan).

5. An organization has discovered that an employee's credentials were stolen and used to access
sensitive data. The employee's account was protected by a password only. Which security control would
have been most effective in preventing this breach?

• A) Data Loss Prevention (DLP)

• B) Multi-Factor Authentication (MFA)

• C) Intrusion Detection System (IDS)

• D) Firewall

Correct Answer✅ B
Detailed Rationale: MFA adds a layer of protection beyond just a password. Even if credentials are
stolen, the attacker would also need the second factor (e.g., a one-time code from a mobile app or
hardware token), making unauthorized access much more difficult.

6. What is the primary difference between a vulnerability scan and a penetration test?

• A) A vulnerability scan is automated, while a penetration test is always manual.

,3


• B) A vulnerability scan identifies potential weaknesses, while a penetration test exploits them to
prove real-world impact.

• C) A vulnerability scan is performed annually, while a penetration test is performed monthly.

• D) A vulnerability scan requires no credentials, while a penetration test always requires
credentials.

Correct Answer✅ B
Detailed Rationale: A vulnerability scan is an automated process that identifies potential security
weaknesses without attempting to exploit them. A penetration test (ethical hacking) involves actively
attempting to exploit vulnerabilities to determine if unauthorized access is possible and to measure the
real-world impact.

7. Which security principle ensures that a user can only access the minimum data necessary to perform
their job functions?

• A) Separation of duties

• B) Least privilege

• C) Defense in depth

• D) Fail secure

Correct Answer✅ B
Detailed Rationale: The principle of least privilege restricts user permissions to only those required for
their specific role. This minimizes the potential damage from compromised accounts or insider threats.

8. A security engineer is implementing a new firewall rule to allow web traffic only from a specific
trusted network. This is an example of which access control model?

• A) Role-Based Access Control (RBAC)

• B) Mandatory Access Control (MAC)

• C) Discretionary Access Control (DAC)

• D) Rule-Based Access Control

Correct Answer✅ D
Detailed Rationale: Rule-Based Access Control uses a set of pre-defined rules (e.g., firewall rules, ACLs)
to grant or deny access based on conditions such as source IP, time of day, or protocol.

9. During a disaster recovery drill, it is determined that the backup data stored offsite is six months old.
Which metric has been violated?

• A) Recovery Time Objective (RTO)

• B) Mean Time to Recover (MTTR)

• C) Recovery Point Objective (RPO)

, 4


• D) Service Level Objective (SLO)

Correct Answer✅ C
Detailed Rationale: RPO defines how much data loss is acceptable (measured in time). An RPO of 24
hours would require backups at least daily; six-month-old backups violate that objective. RTO defines
how quickly services must be restored.

10. Which of the following is a primary goal of a security architecture framework (e.g., SABSA, TOGAF)?

• A) To provide a checklist for software development

• B) To align security strategy with business objectives and provide a structured approach to
security design

• C) To replace all existing security controls

• D) To define specific firewall rules

Correct Answer✅ B
Detailed Rationale: Security architecture frameworks like SABSA (Sherwood Applied Business Security
Architecture) and TOGAF (The Open Group Architecture Framework) provide structured methodologies
to ensure security is designed in alignment with business goals, not as an afterthought.

11. A company's risk assessment has identified that a legacy server running Windows Server 2008
contains customer credit card data. Which of the following is the best immediate mitigation strategy?

• A) Purchase cyber insurance to transfer the risk

• B) Isolate the server from the network and plan for migration

• C) Increase the frequency of vulnerability scans

• D) Ignore the risk because the server still works

Correct Answer✅ B
Detailed Rationale: A legacy operating system no longer receives security patches, creating a critical
vulnerability. The best immediate action is to isolate it (e.g., via network segmentation or firewalls) to
prevent attackers from reaching it, while simultaneously planning for migration to a supported OS.

12. Which risk management framework is widely used by U.S. federal agencies to manage cybersecurity
risk?

• A) COBIT

• B) ISO 27001

• C) NIST Risk Management Framework (RMF)

• D) PCI DSS

Correct Answer✅ C
Detailed Rationale: The NIST RMF (National Institute of Standards and Technology Risk Management

Información del documento

Subido en
5 de abril de 2026
Número de páginas
72
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$23.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
NursingTotur2
3.4
(90)
Vendido
631
Seguidores
41
Artículos
6478
Última venta
17 horas hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes