WGU D489 Cybersecurity Management |
Western Governors University | Academic
Year 2026/2027
SECTION I: Cybersecurity Governance and Strategy
Question 1
A cybersecurity management plan's PRIMARY purpose is to:
A) Eliminate all cyber threats to the organization
B) Serve as a static compliance document for auditors
C) Align security initiatives with business objectives
D) Provide technical specifications for firewall configurations
Correct Answer: C
Rationale: A cybersecurity management plan is a strategic document that
bridges business goals and security operations, ensuring that resources are
allocated to support the organization's mission. Eliminating all threats (A) is
impossible; the goal is risk management. Static documents (B) fail to adapt to
evolving threats, and technical specifications (D) belong in operational runbooks,
not strategic management plans.
Question 2
Which element is MOST critical for building a cybersecurity-aware organizational
culture?
A) Punitive policies for repeat security offenders
B) Executive leadership endorsement and modeling of secure behaviors
C) Mandatory quarterly security awareness newsletters
D) Outsourcing all security awareness training to a third party
Correct Answer: B
Rationale: Culture starts at the top. When executives visibly champion
security and follow protocols themselves, it signals that security is an
,organizational value, making awareness efforts credible. Punitive measures (A)
alone do not build culture, newsletters (C) without engagement are ineffective,
and outsourcing (D) does not demonstrate organizational commitment.
Question 3
A company's Board of Directors is PRIMARILY responsible for which aspect of
cybersecurity?
A) Configuring intrusion detection systems
B) Approving the risk appetite and providing strategic oversight
C) Conducting daily threat intelligence analysis
D) Managing third-party vendor patching schedules
Correct Answer: B
Rationale: The board governs risk. Their role is fiduciary oversight—setting
the "tone at the top" and accepting the level of residual risk the organization will
bear. Technical configuration (A), daily analysis (C), and vendor management (D)
are management-level operational responsibilities, not board functions.
Question 4
When developing a cybersecurity strategy, a gap analysis is used to:
A) Identify differences between the current security posture and a desired future
state
B) Scan for open ports on the external network perimeter
C) Calculate the annual loss expectancy of a specific asset
D) Document the chain of custody for digital evidence
Correct Answer: A
Rationale: A gap analysis benchmarks the "as-is" state against the "to-be"
state, revealing missing controls, capabilities, or processes that the management
plan must address. Port scanning (B) is a technical vulnerability assessment
activity, ALE calculation (C) is a quantitative risk analysis technique, and chain of
custody (D) is a forensic procedure.
,Question 5
Governance in cybersecurity is BEST defined as:
A) The act of installing security patches on servers
B) A set of responsibilities and practices exercised to provide strategic direction
and ensure objectives are achieved
C) A penetration testing methodology
D) The process of encrypting data at rest
Correct Answer: B
Rationale: Governance is the decision-making framework that ensures
security strategy aligns with business strategy, risks are managed appropriately,
and resources are used responsibly. Patching (A) and encryption (D) are
operational controls, while penetration testing (C) is a technical assessment
technique. Governance operates at the strategic and oversight level.
Question 6
Which of the following BEST describes the relationship between governance and
management in cybersecurity?
A) Governance and management are the same function
B) Governance sets direction and oversight; management implements and
executes
C) Management sets policy; governance enforces it
D) There is no relationship between governance and management
Correct Answer: B
Rationale: Governance provides the framework, oversight, and strategic
direction, while management is responsible for implementing the controls,
policies, and procedures that operationalize governance decisions. They are
complementary but distinct functions (A is incorrect). Option C reverses the
relationship, and D is clearly false.
, Question 7
A security strategy that fails to consider business objectives is MOST likely to
result in:
A) Overinvestment in security controls that do not protect critical assets
B) Complete elimination of all security risks
C) Reduced need for compliance audits
D) Increased employee productivity
Correct Answer: A
Rationale: Security investments must be prioritized based on business
impact. Without alignment to business objectives, resources may be wasted on
controls that do not address the organization's most significant risks. Option B is
impossible; C and D are unrelated outcomes.
Question 8
The PRIMARY difference between a policy and a procedure is that:
A) Policies are technical; procedures are administrative
B) Policies are mandatory statements of intent; procedures are step-by-step
instructions for implementation
C) Policies apply only to executives; procedures apply to all employees
D) Policies are optional; procedures are mandatory
Correct Answer: B
Rationale: Policies are high-level, mandatory statements that articulate
management's intent and direction. Procedures provide the detailed, step-by-step
instructions for implementing policies. Policies are not technical (A), apply to all
personnel (C), and are mandatory, not optional (D).
Question 9
Which governance framework is MOST commonly used for establishing an
Information Security Management System (ISMS)?
Western Governors University | Academic
Year 2026/2027
SECTION I: Cybersecurity Governance and Strategy
Question 1
A cybersecurity management plan's PRIMARY purpose is to:
A) Eliminate all cyber threats to the organization
B) Serve as a static compliance document for auditors
C) Align security initiatives with business objectives
D) Provide technical specifications for firewall configurations
Correct Answer: C
Rationale: A cybersecurity management plan is a strategic document that
bridges business goals and security operations, ensuring that resources are
allocated to support the organization's mission. Eliminating all threats (A) is
impossible; the goal is risk management. Static documents (B) fail to adapt to
evolving threats, and technical specifications (D) belong in operational runbooks,
not strategic management plans.
Question 2
Which element is MOST critical for building a cybersecurity-aware organizational
culture?
A) Punitive policies for repeat security offenders
B) Executive leadership endorsement and modeling of secure behaviors
C) Mandatory quarterly security awareness newsletters
D) Outsourcing all security awareness training to a third party
Correct Answer: B
Rationale: Culture starts at the top. When executives visibly champion
security and follow protocols themselves, it signals that security is an
,organizational value, making awareness efforts credible. Punitive measures (A)
alone do not build culture, newsletters (C) without engagement are ineffective,
and outsourcing (D) does not demonstrate organizational commitment.
Question 3
A company's Board of Directors is PRIMARILY responsible for which aspect of
cybersecurity?
A) Configuring intrusion detection systems
B) Approving the risk appetite and providing strategic oversight
C) Conducting daily threat intelligence analysis
D) Managing third-party vendor patching schedules
Correct Answer: B
Rationale: The board governs risk. Their role is fiduciary oversight—setting
the "tone at the top" and accepting the level of residual risk the organization will
bear. Technical configuration (A), daily analysis (C), and vendor management (D)
are management-level operational responsibilities, not board functions.
Question 4
When developing a cybersecurity strategy, a gap analysis is used to:
A) Identify differences between the current security posture and a desired future
state
B) Scan for open ports on the external network perimeter
C) Calculate the annual loss expectancy of a specific asset
D) Document the chain of custody for digital evidence
Correct Answer: A
Rationale: A gap analysis benchmarks the "as-is" state against the "to-be"
state, revealing missing controls, capabilities, or processes that the management
plan must address. Port scanning (B) is a technical vulnerability assessment
activity, ALE calculation (C) is a quantitative risk analysis technique, and chain of
custody (D) is a forensic procedure.
,Question 5
Governance in cybersecurity is BEST defined as:
A) The act of installing security patches on servers
B) A set of responsibilities and practices exercised to provide strategic direction
and ensure objectives are achieved
C) A penetration testing methodology
D) The process of encrypting data at rest
Correct Answer: B
Rationale: Governance is the decision-making framework that ensures
security strategy aligns with business strategy, risks are managed appropriately,
and resources are used responsibly. Patching (A) and encryption (D) are
operational controls, while penetration testing (C) is a technical assessment
technique. Governance operates at the strategic and oversight level.
Question 6
Which of the following BEST describes the relationship between governance and
management in cybersecurity?
A) Governance and management are the same function
B) Governance sets direction and oversight; management implements and
executes
C) Management sets policy; governance enforces it
D) There is no relationship between governance and management
Correct Answer: B
Rationale: Governance provides the framework, oversight, and strategic
direction, while management is responsible for implementing the controls,
policies, and procedures that operationalize governance decisions. They are
complementary but distinct functions (A is incorrect). Option C reverses the
relationship, and D is clearly false.
, Question 7
A security strategy that fails to consider business objectives is MOST likely to
result in:
A) Overinvestment in security controls that do not protect critical assets
B) Complete elimination of all security risks
C) Reduced need for compliance audits
D) Increased employee productivity
Correct Answer: A
Rationale: Security investments must be prioritized based on business
impact. Without alignment to business objectives, resources may be wasted on
controls that do not address the organization's most significant risks. Option B is
impossible; C and D are unrelated outcomes.
Question 8
The PRIMARY difference between a policy and a procedure is that:
A) Policies are technical; procedures are administrative
B) Policies are mandatory statements of intent; procedures are step-by-step
instructions for implementation
C) Policies apply only to executives; procedures apply to all employees
D) Policies are optional; procedures are mandatory
Correct Answer: B
Rationale: Policies are high-level, mandatory statements that articulate
management's intent and direction. Procedures provide the detailed, step-by-step
instructions for implementing policies. Policies are not technical (A), apply to all
personnel (C), and are mandatory, not optional (D).
Question 9
Which governance framework is MOST commonly used for establishing an
Information Security Management System (ISMS)?