WGU D489 Cybersecurity Management
Comprehensive Examination 2026/2027 |
Verified Questions
Western Governors University | D489 Cybersecurity Management | University-Level Cybersecurity Students
100 Verified Questions | 4 Core Domains | Academic Year 2026/2027
Prepared by
Western Governors University | D489 Cybersecurity Management
Task 1 Comprehensive Examination Actual Exam | Academic Year 2026/2027
WGU D489 Cybersecurity Management Comprehensive Examination 2026/2027 | Verified Questions
,INTRODUCTION
This comprehensive examination contains exactly 100 verified questions designed to reinforce the official Western
Governors University D489 Cybersecurity Management course objectives for actual exam readiness and strategic
proficiency, aligned to the 2026/2027 academic year. The questions are distributed equally across four core
domains: Domain 1 – Risk Assessment and Management (25 questions); Domain 2 – Security Policies and
Governance (25 questions); Domain 3 – Incident Response and Business Continuity (25 questions); and Domain
4 – Security Controls and Compliance Frameworks (25 questions). The content is original and constructed to
support university-level mastery of risk management, policy frameworks, incident response, and compliance
standards as presented in the D489 curriculum and foundational cybersecurity management resources.
ACTUAL QUESTIONS
Domain 1: Risk Assessment and Management
Question 1. What is the primary purpose of a risk assessment in cybersecurity management?
A. To eliminate all residual risk
B. To identify, analyze, and evaluate risks so that informed decisions can be made about treatment
C. To replace all security controls
D. To guarantee zero incidents
Correct Answer: B
Rationale: Risk assessment provides the structured foundation for prioritizing resources and selecting
appropriate risk responses.
Question 2. Which of the following best describes residual risk?
A. Risk that exists before any controls are applied
B. Risk that remains after controls and treatments have been implemented
C. Risk that is transferred to an insurer
D. Risk that is accepted without analysis
Correct Answer: C
Rationale: Residual risk is the level of risk that persists once selected treatments are in place.
Question 3. What is the primary difference between a threat and a vulnerability?
A. They are identical concepts
B. A threat is a potential cause of an unwanted incident; a vulnerability is a weakness that can be exploited by
a threat
C. A vulnerability is always external
D. A threat is only a software bug
Correct Answer: B
Rationale: Threats act upon vulnerabilities to produce impact; both must be understood for accurate risk
analysis.
Question 4. Which of the following is a correct statement about qualitative risk analysis?
A. It always produces precise monetary values
B. It uses descriptive scales (such as high/medium/low) to rank likelihood and impact when quantitative data
are limited
C. It requires actuarial tables for every asset
D. It replaces the need for any controls
Correct Answer: A
Rationale: Qualitative methods are practical when numerical loss data are incomplete or when relative ranking
is sufficient.
Question 5. What is the primary purpose of a risk register?
A. To list only accepted risks
WGU D489 Cybersecurity Management Comprehensive Examination 2026/2027 | Verified Questions
, B. To document identified risks, their owners, assessments, and treatment status in a living record
C. To replace the incident-response plan
D. To store encryption keys
Correct Answer: D
Rationale: The risk register is the central repository that tracks risk information throughout the risk-
management life cycle.
Question 6. Which of the following is an example of risk transfer?
A. Installing a firewall
B. Purchasing cyber-insurance or outsourcing a function under contract that shifts financial impact
C. Accepting the risk without action
D. Ignoring the risk entirely
Correct Answer: C
Rationale: Transfer shifts the financial or operational consequences of a risk to another party, typically through
insurance or contractual arrangements.
Question 7. What is the primary goal of risk treatment?
A. To increase residual risk
B. To select and implement measures that modify risk to an acceptable level
C. To eliminate the need for monitoring
D. To document risks without action
Correct Answer: D
Rationale: Treatment options include mitigation, transfer, avoidance, and acceptance, chosen according to the
organization’s risk appetite.
Question 8. Which of the following best describes inherent risk?
A. Risk after all controls are applied
B. Risk present in the absence of any controls or treatments
C. Risk that has been transferred
D. Risk that is purely theoretical
Correct Answer: B
Rationale: Inherent risk reflects the raw exposure before the organization applies protective measures.
Question 9. What is the primary purpose of establishing risk appetite?
A. To eliminate all risk-taking
B. To define the amount and type of risk the organization is willing to accept in pursuit of its objectives
C. To set the maximum number of incidents allowed per year without analysis
D. To replace the need for policies
Correct Answer: C
Rationale: Risk appetite guides decision-making by clarifying how much residual risk leadership is prepared to
tolerate.
Question 10. Which of the following is a correct step in the NIST risk-management process?
A. Skip assessment and go directly to acceptance
B. Frame, assess, respond to, and monitor risk in a continuous cycle
C. Perform assessment only once every decade
D. Ignore business context
Correct Answer: B
Rationale: NIST emphasizes a continuous, context-aware cycle of framing, assessment, response, and
monitoring.
Question 11. What is the primary benefit of using a standardized risk-scoring matrix?
WGU D489 Cybersecurity Management Comprehensive Examination 2026/2027 | Verified Questions