WGU D488 Cybersecurity Architecture and Engineering OA
WGU D488 Cybersecurity Architecture and
Engineering OA Practice Exam Questions
and Answers 2026. Advanced NCLEX-Style
100 MCQs with Rationales
Q1
A company must allow remote employees to securely access internal resources over the Internet.
Management requires confidentiality, integrity, and authentication of all network traffic.
Which solution BEST satisfies these requirements?
A. TLS only
B. SSH
C. IPSec VPN
D. WPA3
Answer: C
Rationale: IPSec provides encryption, integrity, and authentication for IP communications and
is the standard technology for site-to-site and remote-access VPNs.
Q2
An organization experiences repeated SQL injection attacks against a customer-facing
application.
Which security control should be implemented FIRST?
A. IDS
B. SIEM
C. Web Application Firewall
D. Proxy Server
Answer: C
Rationale: A WAF is designed specifically to detect and block application-layer attacks such as
SQL injection.
, WGU D488 Cybersecurity Architecture and Engineering OA
Q3
A security architect wants to minimize the impact of a compromised web server.
Which architecture principle should be implemented?
A. Single sign-on
B. Network segmentation
C. Data deduplication
D. Load balancing
Answer: B
Rationale: Network segmentation limits lateral movement after compromise.
Q4
Which security principle grants users only the permissions required to perform assigned job
functions?
A. Separation of duties
B. Least privilege
C. Defense in depth
D. Need to know
Answer: B
Rationale: Least privilege minimizes attack surface and insider risk.
Q5
A penetration tester discovers that encrypted files can still be decrypted after a storage device is
stolen.
Which control most likely failed?
A. Hashing
B. Key management
C. Tokenization
D. Logging
, WGU D488 Cybersecurity Architecture and Engineering OA
Answer: B
Rationale: Encryption is only as secure as the protection of its cryptographic keys.
Q6
A company wants highly available web servers across multiple regions.
Which cloud design BEST supports this objective?
A. Single Availability Zone
B. Multi-region deployment
C. Local backup server
D. Cold site
Answer: B
Rationale: Multi-region deployments improve resilience and disaster recovery.
Q7
Which cryptographic algorithm is asymmetric?
A. AES
B. ChaCha20
C. RSA
D. 3DES
Answer: C
Rationale: RSA uses public/private key pairs.
Q8
Which hashing algorithm is considered secure for modern password storage when combined with
salting?
A. MD5
B. SHA-1
, WGU D488 Cybersecurity Architecture and Engineering OA
C. bcrypt
D. CRC32
Answer: C
Rationale: bcrypt is intentionally slow and resistant to brute-force attacks.
Q9
A company wants to detect abnormal login behavior using historical patterns.
Which technology is MOST appropriate?
A. Signature IDS
B. Behavior analytics
C. Firewall ACL
D. VLAN
Answer: B
Rationale: Behavioral analytics identifies deviations from normal user activity.
Q10
Which architecture provides multiple independent security layers?
A. Zero Trust
B. Defense in Depth
C. DAC
D. RBAC
Answer: B
Rationale: Multiple overlapping controls reduce the chance of complete compromise.
Q11
Which Zero Trust principle is MOST important?
WGU D488 Cybersecurity Architecture and
Engineering OA Practice Exam Questions
and Answers 2026. Advanced NCLEX-Style
100 MCQs with Rationales
Q1
A company must allow remote employees to securely access internal resources over the Internet.
Management requires confidentiality, integrity, and authentication of all network traffic.
Which solution BEST satisfies these requirements?
A. TLS only
B. SSH
C. IPSec VPN
D. WPA3
Answer: C
Rationale: IPSec provides encryption, integrity, and authentication for IP communications and
is the standard technology for site-to-site and remote-access VPNs.
Q2
An organization experiences repeated SQL injection attacks against a customer-facing
application.
Which security control should be implemented FIRST?
A. IDS
B. SIEM
C. Web Application Firewall
D. Proxy Server
Answer: C
Rationale: A WAF is designed specifically to detect and block application-layer attacks such as
SQL injection.
, WGU D488 Cybersecurity Architecture and Engineering OA
Q3
A security architect wants to minimize the impact of a compromised web server.
Which architecture principle should be implemented?
A. Single sign-on
B. Network segmentation
C. Data deduplication
D. Load balancing
Answer: B
Rationale: Network segmentation limits lateral movement after compromise.
Q4
Which security principle grants users only the permissions required to perform assigned job
functions?
A. Separation of duties
B. Least privilege
C. Defense in depth
D. Need to know
Answer: B
Rationale: Least privilege minimizes attack surface and insider risk.
Q5
A penetration tester discovers that encrypted files can still be decrypted after a storage device is
stolen.
Which control most likely failed?
A. Hashing
B. Key management
C. Tokenization
D. Logging
, WGU D488 Cybersecurity Architecture and Engineering OA
Answer: B
Rationale: Encryption is only as secure as the protection of its cryptographic keys.
Q6
A company wants highly available web servers across multiple regions.
Which cloud design BEST supports this objective?
A. Single Availability Zone
B. Multi-region deployment
C. Local backup server
D. Cold site
Answer: B
Rationale: Multi-region deployments improve resilience and disaster recovery.
Q7
Which cryptographic algorithm is asymmetric?
A. AES
B. ChaCha20
C. RSA
D. 3DES
Answer: C
Rationale: RSA uses public/private key pairs.
Q8
Which hashing algorithm is considered secure for modern password storage when combined with
salting?
A. MD5
B. SHA-1
, WGU D488 Cybersecurity Architecture and Engineering OA
C. bcrypt
D. CRC32
Answer: C
Rationale: bcrypt is intentionally slow and resistant to brute-force attacks.
Q9
A company wants to detect abnormal login behavior using historical patterns.
Which technology is MOST appropriate?
A. Signature IDS
B. Behavior analytics
C. Firewall ACL
D. VLAN
Answer: B
Rationale: Behavioral analytics identifies deviations from normal user activity.
Q10
Which architecture provides multiple independent security layers?
A. Zero Trust
B. Defense in Depth
C. DAC
D. RBAC
Answer: B
Rationale: Multiple overlapping controls reduce the chance of complete compromise.
Q11
Which Zero Trust principle is MOST important?