Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 3 fuera de 28 páginas
Examen

WGU D488 OA TEST BANK 1 2026 | Cybersecurity Architecture & Engineering | Actual Exam Questions & Correct Answers | Pass Guaranteed - A+ Graded

Document preview thumbnail
Vista previa 3 fuera de 28 páginas

Pass the WGU D488 Cybersecurity Architecture and Engineering Objective Assessment with this complete Test Bank 1 featuring actual exam questions and correct answers for 2026. This A+ Graded resource covers all essential cybersecurity domains including security architecture frameworks, network security design, cloud security, identity and access management, cryptography, risk management, incident response, and security operations. Each question is verified and aligned with the latest WGU D488 curriculum. Perfect for WGU students seeking comprehensive OA preparation. With our Pass Guarantee, you can study with confidence. Download your complete WGU D488 OA Test Bank 1 guide instantly!

Vista previa del contenido

2026 WGU D488 Cybersecurity Architecture
and Engineering Objective Assessment
Test Bank 1 - Practice Exam with Actual Exam Questions and Answers

75 Questions | 9 Sections | Scenario-Based Multiple Choice



Section 1: Security Architecture Principles and Frameworks (Q1-12)

Q1: A financial services firm is modernizing its cybersecurity program and adopts the NIST Cybersecurity Framework.
The CISO needs to present the framework to the board as a continuous lifecycle. Which of the following represents the
correct sequence of the five core functions in the NIST CSF?
A. Protect, Detect, Respond, Recover, Identify
B. Identify, Protect, Detect, Respond, Recover [CORRECT]
C. Identify, Detect, Protect, Respond, Recover
D. Detect, Identify, Protect, Respond, Recover
Correct Answer: B
Rationale: The NIST CSF organizes its five core functions as Identify, Protect, Detect, Respond, and Recover to form a continuous
improvement lifecycle. Identify comes first because an organization must understand its assets, risks, and current posture before it can
protect them. Protect and Detect follow as proactive and reactive measures respectively, while Respond and Recover address incident
handling and restoration. The sequences in options A, C, and D either place identification or detection out of order, breaking the logical
flow from understanding risk through recovery.

Q2: An organization pursuing ISO 27001:2022 certification is mapping its control set to the revised Annex A structure.
The compliance team needs to identify which domain addresses governance-level controls such as policies, roles, and
responsibilities. Which Annex A domain focuses on organizational governance controls?
A. A.5 Organizational Controls [CORRECT]
B. A.6 People Controls
C. A.7 Physical Controls
D. A.8 Technological Controls
Correct Answer: A
Rationale: In ISO 27001:2022, Annex A was restructured from 14 domains into four thematic groups. A.5 Organizational Controls
contains governance-level controls covering information security policies, asset management, and roles and responsibilities. A.6 People
Controls addresses human factors such as screening, terms of employment, and awareness training, not governance structures. A.7
Physical Controls covers physical security perimeters and equipment protection, while A.8 Technological Controls deals with technical
safeguards like cryptography and access control. Only A.5 directly addresses the organizational governance layer the compliance team
requires.

Q3: A multinational bank is implementing COBIT 2019 to align its IT governance with enterprise risk management. The
board wants a specific governance objective that directly addresses cybersecurity risk optimization. Which COBIT 2019
governance objective is most appropriate for ensuring cybersecurity risk is optimized at the board level?
A. EDM01 Ensure Governance Framework Setting and Maintenance
B. EDM03 Ensure Risk Optimization [CORRECT]
C. EDM05 Ensure Stakeholder Needs Are Addressed
D. AP013 Manage Security
Correct Answer: B
Rationale: COBIT 2019 designates EDM03 as the governance objective specifically responsible for ensuring risk optimization, which
encompasses cybersecurity risk at the enterprise level. EDM01 establishes the governance framework itself but does not directly address

,risk optimization. EDM05 focuses on stakeholder value delivery rather than risk management. AP013 is a management process below the
governance layer that handles day-to-day security operations, not board-level risk governance. Therefore, EDM03 is the correct
governance objective the board should adopt for cybersecurity risk oversight.

Q4: An enterprise architecture team is using TOGAF ADM to design a new customer portal. The chief security
architect must ensure that security requirements are captured at the earliest appropriate phase to influence all
downstream design decisions. In which TOGAF ADM phase are security requirements first formally captured?
A. Phase A: Architecture Vision [CORRECT]
B. Phase B: Business Architecture
C. Phase C: Information Systems Architecture
D. Phase D: Technology Architecture
Correct Answer: A
Rationale: In the TOGAF ADM, Phase A Architecture Vision is where security requirements are first captured as part of stakeholder
concerns and architectural constraints. Capturing security requirements at this stage ensures they influence the entire architecture
development effort across all subsequent phases. Phase B focuses on business processes and organizational structure, while Phases C and
D deal with specific architecture domains where requirements are refined rather than initially captured. Waiting until Phase C or D to
introduce security requirements would result in costly retrofits and a design that does not adequately address security from the outset.

Q5: A healthcare organization is migrating from a perimeter-based security model to Zero Trust Architecture. A
security engineer is explaining the fundamental conceptual difference to the IT operations team. Which statement best
describes the core principle that distinguishes Zero Trust from traditional perimeter-based security?
A. Zero Trust eliminates the need for firewalls by using only endpoint protection
B. No implicit trust is granted based solely on network location; every access request is verified
[CORRECT]
C. Zero Trust requires all users to authenticate with multi-factor authentication at the network perimeter
D. Zero Trust architecture assumes that external networks are more trustworthy than internal networks
Correct Answer: B
Rationale: The defining principle of Zero Trust Architecture is that no implicit trust is granted based on network location, meaning every
access request must be authenticated, authorized, and encrypted regardless of whether it originates inside or outside the network
perimeter. Option A is incorrect because Zero Trust does not eliminate firewalls but rather adds additional layers of verification. Option
C misrepresents Zero Trust by tying it to perimeter-only authentication, which contradicts the model. Option D states the opposite of Zero
Trust principles, since the model treats all networks as equally untrusted. This core principle of continuous verification is what
fundamentally differentiates Zero Trust from castle-and-moat perimeter defenses.

Q6: A security architect is using the SABSA framework to develop an enterprise security architecture. She needs to
identify which layer translates business security requirements into specific security services that bridge the gap between
business intent and technical implementation. Which SABSA layer serves this bridging function?
A. Conceptual Layer
B. Physical Layer
C. Logical Layer [CORRECT]
D. Component Layer
Correct Answer: C
Rationale: The SABSA Logical Layer is responsible for defining security services that translate business requirements from the
Conceptual Layer into specifications that guide the Physical and Component layers. It provides the essential bridge between
business-driven security needs and their technical realization. The Conceptual Layer deals with business context, drivers, and stakeholder
requirements at a strategic level without defining services. The Physical Layer maps logical services to specific technology platforms, and
the Component Layer addresses individual product-level selection and configuration. Only the Logical Layer specifically focuses on
security services as the intermediary between business and technology.

, Q7: A security engineer is implementing defense-in-depth for a corporate data center processing payment card data. She
must select one control for each of the five defense-in-depth layers: physical, perimeter, network, host, and
application/data. Which combination correctly maps one control to each layer from outermost to innermost?
A. Mantrap, firewall, IDS, host-based firewall, field-level encryption
B. Badge reader, firewall, patch management, WAF, tokenization [CORRECT]
C. Security guard, DMZ, antivirus, hardening standard, access control list
D. CCTV, router ACL, intrusion prevention system, file integrity monitoring, salting
Correct Answer: B
Rationale: Option B correctly maps defense-in-depth controls across all five layers: a badge reader provides physical access control, a
firewall enforces perimeter network security, patch management addresses network-level vulnerability remediation, a WAF operates at
the host layer to protect web servers, and tokenization secures data at the application/data layer. Option A places IDS at the network layer
instead of perimeter, and host-based firewall is redundant with the perimeter firewall. Option C maps a DMZ as a network-layer control,
but a DMZ is a network zone rather than an active control, and antivirus at the network layer is imprecise. Option D uses router ACL at
the perimeter layer and salting at the data layer, but salting is a specific hashing technique, not a broad data-layer control. Option B is the
most accurate and comprehensive mapping.

Q8: A database administrator is designing access controls for a multi-tier web application backed by a relational
database. The application only needs to retrieve product catalog data for display on a public-facing website. Which
approach best applies the principle of least privilege to this database architecture?
A. Grant the application service account full DBA privileges to avoid connection errors during peak traffic
B. Create a read-only user account but grant SELECT on all schemas to prevent access denied errors
C. Provision an application service account with SELECT privileges limited to only the specific catalog
tables required [CORRECT]
D. Use the database root account for the application since it simplifies connection string configuration
Correct Answer: C
Rationale: Option C correctly applies the principle of least privilege by creating a service account with SELECT access restricted to only
the specific tables the application needs, minimizing the blast radius if the account is compromised. Option A violates least privilege by
granting excessive DBA privileges that could allow an attacker to modify or delete any database object. Option B grants broader access
than necessary across all schemas, which still violates least privilege even though it is read-only. Option D uses the root account, which
represents the maximum privilege level and is the antithesis of least privilege. Restricting access to the minimum required tables is the
correct implementation of this foundational security principle.

Q9: A financial institution processes high-value wire transfers and needs to prevent a single administrator from
committing fraud. The security team designs a control where one administrator configures a new transfer rule while a
second administrator must independently approve it before it becomes active. Which security principle does this control
most directly implement?
A. Defense in depth, because multiple layers of administrators are used
B. Separation of duties, because no single individual can complete a critical transaction alone
[CORRECT]
C. Least privilege, because each administrator has limited access to only their part of the process
D. Job rotation, because administrators switch roles between configuration and approval
Correct Answer: B
Rationale: This control directly implements separation of duties by ensuring that no single administrator has the ability to both configure
and approve a transfer rule, requiring collusion between at least two people to commit fraud. Option A describes defense in depth, which
involves multiple independent layers of controls rather than splitting a single function across individuals. Option C describes least
privilege, which limits the scope of access but does not inherently require dual approval for a single operation. Option D refers to job
rotation, which involves periodically switching personnel between roles to detect fraud over time rather than preventing it through
concurrent authorization. The dual-approval mechanism is the hallmark of separation of duties.

Información del documento

Subido en
20 de agosto de 2026
Número de páginas
28
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$30.50

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
NURSEEXAMITY
3.4
(97)
Vendido
515
Seguidores
273
Artículos
6285
Última venta
2 días hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes