• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 4 fuera de 110 páginas
Examen

WGU D489 Task 1 Cybersecurity Management Exam 2025: Complete 200-Question Test Bank with Detailed Rationales – Scenario-Based and Conceptual Questions for a Sure Pass

Document preview thumbnail
Vista previa 4 fuera de 110 páginas

This comprehensive test bank is the ultimate preparation resource for students tackling the WGU D489 Task 1 Cybersecurity Management exam, featuring 200 meticulously crafted questions with detailed rationales that explain the "why" behind every answer, all organized to mirror the exact format, difficulty, and content weighting of the official WGU objective assessment. Covering the complete spectrum of cybersecurity management domains—from core security principles (least privilege, separation of duties, defense in depth, zero trust) and access control models (RBAC, MAC, DAC, ABAC) to risk management frameworks (NIST, ISO, COBIT, COSO) and incident response lifecycle (preparation, identification, containment, eradication, recovery, lessons learned)—this resource systematically builds the deep conceptual understanding and critical thinking skills required to excel on the exam. Dive into critical topics including security governance and policy development, business continuity and disaster recovery planning with RTO and RPO metrics, compliance frameworks (HIPAA, PCI DSS, SOX, GDPR, FISMA), cloud security shared responsibility models, vendor risk management, security awareness training and phishing simulations, technical controls (firewalls, IDS/IPS, SIEM, EDR, DLP, NAC, encryption, MFA), and emerging threats such as APTs, ransomware, social engineering, and insider threats. The guide also thoroughly covers security assessment methodologies including vulnerability scanning, penetration testing, risk assessments (qualitative and quantitative), business impact analysis (BIA), tabletop exercises, and security audits, alongside practical security operations including log management and analysis, incident documentation and tracking, continuous monitoring, and security metrics (MTTD, MTTR). Whether you are preparing for your WGU D489 final exam, seeking a comprehensive review of cybersecurity management principles, or building a foundation for CompTIA Security+, CISSP, or CISM certifications, this test bank eliminates guesswork by providing the most current, accurate, and complete set of exam-style questions and detailed rationales available, ensuring you master the material and achieve the grade you need to advance your cybersecurity management career.

Vista previa del contenido

MEDSTUDY.COM



WGU D489 TASK 1 | CYBERSECURITY
MANAGEMENT | EXAM QUESTIONS AND
CORRECT ANSWERS WITH RATIONALES
GRADED A+ LATEST

1.

A company is implementing a new security policy that requires multi-factor
authentication (MFA) for all remote access. Which of the following best describes
the primary benefit of MFA?
A. It eliminates the need for passwords.
B. It reduces the risk of credential theft and unauthorized access.
C. It simplifies user access management.
D. It removes the need for logging and auditing.
Answer: B
Rationale: MFA requires multiple authentication factors, making it much harder
for attackers to compromise accounts even if passwords are stolen.


2.

A security manager is reviewing access control policies and wants to ensure that
users only have access to what they need to perform their jobs. Which principle is
being applied?
A. Least Privilege
B. Separation of Duties
C. Need to Know
D. Role-Based Access Control
Answer: A
Rationale: Least privilege limits user access to only what is necessary for their
role, reducing risk.

,MEDSTUDY.COM


3.

A company’s SOC has detected unusual outbound traffic from a workstation to an
unknown IP address. The security analyst suspects malware. What should be the
FIRST action?
A. Notify the CEO.
B. Disconnect the workstation from the network.
C. Reboot the workstation.
D. Update antivirus definitions.
Answer: B
Rationale: Disconnecting the system prevents further data exfiltration and limits
spread while preserving evidence.


4.

During a risk assessment, an analyst identifies that the company has a single point
of failure in its data center power supply. This is an example of what type of risk?
A. Strategic Risk
B. Operational Risk
C. Compliance Risk
D. Financial Risk
Answer: B
Rationale: Operational risk includes disruptions in systems or processes that affect
business continuity.


5.

A company is developing its incident response plan. Which of the following is the
most important reason for including a communication plan?
A. To ensure the IT team can work without interruptions.
B. To ensure stakeholders are informed and legal requirements are met.
C. To reduce the cost of incident response.
D. To eliminate the need for documentation.

,MEDSTUDY.COM


Answer: B
Rationale: Communication plans ensure proper notification of stakeholders,
regulatory compliance, and coordinated response.


6.

Which of the following BEST defines “risk appetite”?
A. The amount of risk a company is willing to accept to achieve objectives
B. The total number of risks identified in an assessment
C. The cost of mitigating all identified risks
D. The probability of a threat occurring
Answer: A
Rationale: Risk appetite is the level of risk an organization is willing to accept.


7.

A company wants to protect sensitive data at rest. Which of the following controls
is MOST appropriate?
A. Data encryption
B. Intrusion detection system
C. Network segmentation
D. Vulnerability scanning
Answer: A
Rationale: Encryption protects data at rest by making it unreadable without the
correct keys.

, MEDSTUDY.COM


8.

A security team uses a vulnerability scanner to identify weaknesses in their web
applications. The scanner finds a SQL injection vulnerability. Which phase of the
SDLC is MOST important to address this vulnerability?
A. Requirements
B. Design
C. Development
D. Maintenance
Answer: C
Rationale: SQL injection vulnerabilities are typically introduced during
development and should be addressed through secure coding practices.


9.

A healthcare organization must comply with HIPAA. What is the primary focus of
HIPAA?
A. Protecting financial transactions
B. Protecting patient health information
C. Protecting government data
D. Protecting intellectual property
Answer: B
Rationale: HIPAA protects the confidentiality, integrity, and availability of
protected health information (PHI).

Información del documento

Subido en
2 de septiembre de 2026
Número de páginas
110
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$21.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
PROFDOC
4.3
(69)
Vendido
607
Seguidores
24
Artículos
2377
Última venta
1 día hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes