Free WGU Cybersecurity Architecture and Engineering Cybersecurity-Architecture-and-Engineering Exam Questions
Page: 1 / 16Total 232 questions
Want more questions? Get Premium Access.
Question 1
What is one purpose of an End User License Agreement?
Correct Answer:B. Allow customers to legally use the software
Explanation:
AnEnd User License Agreement (EULA)is a legal contract between the software manufacturer and the user.
The primary purpose of a EULA is togrant the user the right to use the software.
It outlines the terms and conditions under which the software can be used.
This can include restrictions on installation, distribution, and modification.
The EULA helps protect the intellectual property rights of the software creator.
'Software Licensing Handbook' by Jeffrey I. Gordon.
'Intellectual Property and Open Source' by Van Lindberg.
Question 2
A healthcare organization is required to comply with the Health Insurance Portability and Accountability Act (HIPAA), which regulates the privacy and security of personal health information. The organization uses simple network management protocol (SNMP) to manage and monitor its network devices.
Which security control will protect the confidentiality of network device information within this organization?
Correct Answer:C. Encryption
Explanation:
The correct answer is C --- Encryption.
WGU Cybersecurity Architecture and Engineering (KFO1 / D488) clearly states that encryption protects the confidentiality of transmitted information. In the case of SNMP (especially older versions like SNMPv1 and SNMPv2), communications are unencrypted, making encryption critical to protecting network management information from unauthorized disclosure.
Access controls (A) restrict who can access systems but do not encrypt data. Network segmentation (B) separates systems but does not encrypt traffic. Security monitoring (D) detects threats but does not protect data confidentiality.
Reference Extract from Study Guide:
'Encryption safeguards sensitive data transmitted over the network, ensuring confidentiality in compliance with privacy regulations such as HIPAA.'
--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Network Security and Data Protection
Question 3
A large technology company has discovered a known vulnerability in its network infrastructure.The infrastructure contains a number of retired assets that are no longer receiving security updates, which could potentially be exploited by attackers to compromise the network. The company has decided to implement hardening techniques and endpoint security controls to mitigate the risk.
Which hardening technique will meet the needs of this company?
Correct Answer:D. Removing all end-of-life devices from the network
Explanation:
End-of-life (EOL) systemspose a significant security risk because they no longer receive patches or security updates. Themost effective and proactive hardening techniquein this case is tocompletely remove those systems from the network.
NIST SP 800-128 (Guide for Security-Focused Configuration Management):
''Systems no longer supported by vendors must be removed, replaced, or isolated as they pose unacceptable risks.''
Other controls are useful for broader protection, but if a system is inherently vulnerable and cannot be patched,removal is the only surefire solution.
WGU Course Alignment:
Domain:System Security Engineering
Topic:Implement system hardening strategies and manage legacy systems
Question 4
Which risk management strategy will ensure the secure configuration and deployment of a new supply chain management system and prevent identity theft?
Correct Answer:D. Implementation of multifactor authentication for all user accounts
Explanation:
The correct answer is D --- Implementation of multifactor authentication for all user accounts.
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488), multifactor authentication (MFA) strengthens identity verification by requiring multiple forms of credentials, significantly reducing the risk of identity theft.
Firewalls (A) and USB port controls (B) improve system security but do not directly prevent identity theft. Vulnerability scanning and patch management (C) address software weaknesses but not user authentication.
Reference Extract from Study Guide:
'Multifactor authentication (MFA) enhances user account security by requiring multiple verification factors, making it significantly harder for attackers to commit identity theft.'
--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Identity and Access Management Best Practices
Question 5
Which motherboard component is used for short-term storage of data?
Correct Answer:D. RAM
Explanation:
Short-term storage of data on a motherboard is managed by Random Access Memory (RAM).
RAM is volatile memory, meaning it temporarily stores data that is actively being used or processed by the CPU.
The other options:
The hard drive is used for long-term storage.
BIOS (Basic Input/Output System) is firmware for hardware initialization.
Read Only Memory (ROM) is used for permanent data storage that doesn't change.
Thus, RAM is the correct answer for short-term data storage.
'Computer Organization and Architecture' by William Stallings, which covers the various types of memory.
'Operating System Concepts' by Abraham Silberschatz, Peter B. Galvin, and Greg Gagne, which explains memory management.
Question 6
In which type of network topology are the networked devices connected to a central device like a hub or switch?
Correct Answer:A. Star
Explanation:
In a star network topology, each network device is connected to a central device like a hub or a switch.
This central device acts as a repeater for data flow.
The other options:
Bus topology uses a single central cable.
Mesh topology involves each device being connected to every other device.
Ring topology connects devices in a circular fashion.
Therefore, the star topology correctly describes a network where devices connect to a central hub or switch.
'Data and Computer Communications' by William Stallings, which explains different network topologies.
'Network+ Guide to Networks' by Jill West, Tamara Dean, and Jean Andrews, which covers network configurations.
Question 7
A professional services organization deployed security edge devices in key locations on its corporate network.
How will these devices improve the organization's security posture?
Correct Answer:A. They act as an initial defense layer for potential threats
Explanation:
Security edge devices(such as NGFWs, IDS/IPS, and secure gateways) are deployed at thenetwork perimeterto inspect and filter traffic, providing aninitial layer of defenseagainst external threats before they reach internal systems.
NIST SP 800-41 Rev. 1:
''Edge security devices enforce security policy at network boundaries and act as a first line of defense by preventing unauthorized or malicious traffic from entering the internal network.''
They are not TPMs or SIEMs, though they maygenerate dataconsumed by SIEMs.
WGU Course Alignment:
Domain:Network Security
Topic:Deploy perimeter defense technologies at network entry points
Question 8
An engineer has noticed increased network traffic originating from an unknown internet protocol (IP) address.
Which action should be taken to analyze the unusual network traffic patterns?
Correct Answer:B. Compare the unknown address to known IP addresses to determine if it is a threat
Explanation:
The correct answer is B --- Compare the unknown address to known IP addresses to determine if it is a threat.
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488), proper threat analysis requires identifying and verifying whether an unknown source is malicious before taking action. Comparing the IP address against known threat databases or intelligence feeds allows the organization to make informed decisions.
Permanently blocking (A) or temporarily blocking (C) without analysis could cause disruption if the IP is legitimate. Rate limiting (D) reduces traffic but does not determine threat status.
Reference Extract from Study Guide:
'Effective incident analysis begins by verifying and classifying the suspicious activity, including checking unknown IP addresses against threat intelligence sources.'
--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Threat Analysis and IncidentHandling
Question 9
A company's website is suddenly redirecting users to a suspicious landing page asking for personal information.
What is the most likely cause of the issue?
Correct Answer:C. Tampering
Explanation:
The correct answer is C --- Tampering.
WGU Cybersecurity Architecture and Engineering (KFO1 / D488) materials explain that tampering refers to unauthorized modifications of systems or data. In this case, the website being altered to redirect users to a malicious landing page indicates that an attacker has tampered with the legitimate website code or its DNS settings.
Exfiltration (A) refers to stealing data. Phishing (B) involves tricking users but not modifying a website. Ransomware (D) encrypts systems for ransom, not cause redirection.
Reference Extract from Study Guide:
'Tampering involves the unauthorized modification of a system or its resources, often to redirect users to malicious destinations or to alter functionality in harmful ways.'
--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Threat Categories and Impacts
Question 10
How can the organizational culture support ethical guidelines?
Correct Answer:B. By outlining the protocols to support security and privacy of data
Explanation:
Organizational culture can support ethical guidelines by establishing clear protocols and policies that promote the security and privacy of data. This includes:
Data protection policies: Guidelines on how data should be handled, stored, and protected.
Ethical behavior: Encouraging employees to adhere to ethical standards and practices.
Training and awareness: Regular training sessions to educate employees on security best practices and ethical behavior.
Incident response: Protocols for responding to data breaches and other security incidents.
A strong organizational culture that prioritizes data security and privacy helps ensure that ethical guidelines are consistently followed.
Reference
Michael E. Whitman and Herbert J. Mattord, 'Principles of Information Security,' Cengage Learning.
Rebecca Herold, 'Managing an Information Security and Privacy Awareness and Training Program,' CRC Press.
Question 11
A large technology company has discovered a known vulnerability in its network infrastructure. The infrastructure contains a number of retired assets that are no longer receiving security updates, which can potentially be exploited by attackers to compromise the network. The company has decided to implement hardening techniques and endpoint security controls to mitigate the risk.
Which hardening technique will meet the needs of this company?
Correct Answer:D. Removing all end-of-life devices from the network
Explanation:
The correct answer is D --- Removing all end-of-life devices from the network.
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488), end-of-life systems pose significant risks because they no longer receive patches or updates. The besthardening technique in this situation is to decommission and remove these devices, eliminating their vulnerabilities altogether.
Access control (A), vulnerability scanning (B), and IDPS (C) are helpful practices but do not eliminate vulnerabilities of unsupported devices.
Reference Extract from Study Guide:
'Removing end-of-life or unsupported assets is essential for maintaining a secure infrastructure, as these devices are highly vulnerable to exploitation.'
--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), System and Device Hardening
Question 12
What is a component of IT infrastructure?
Correct Answer:C. Networks
Explanation:
IT infrastructure encompasses all the physical and virtual resources that support the flow,storage, processing, and analysis of data. Networks, which include the internet, intranets, and extranets, are fundamental components of IT infrastructure as they enable communication and data exchange between different hardware and software components.
Question 13
An IT organization needs to enable secure communication across virtual networks in Microsoft Azure and Amazon Web Services. Which protocol will offer the most reliable and secure method for data transport?
Correct Answer:C. Internet Protocol Security (IPsec)
Explanation:
IPsecis anend-to-end encryption protocol suitethat operates at thenetwork layer, providingauthentication, integrity, and confidentialitybetween virtual networks---even across different cloud environments like Azure and AWS.
NIST SP 800-77 Rev. 1 (Guide to IPsec VPNs):
''IPsec provides network-layer protection through authentication headers (AH) and encapsulating security payloads (ESP), suitable for securing traffic across untrusted environments.''
FTP is insecure, and SSH is more suitable for command-line access or remote sessions---not secure VPC-to-VPC tunnels.
WGU Course Alignment:
Domain:Cryptography
Topic:Use encryption protocols like IPsec for secure data transmission between networks
Question 14
An organization's board of directors is reviewing the risk register and attempting to evaluate whether there is too much risk for the organization.
Which metric should the board review?
Correct Answer:A. Risk appetite
Explanation:
The correct answer is A --- Risk appetite.
As per the WGU Cybersecurity Architecture and Engineering (KFO1 / D488) coursework, risk appetite defines the amount and type of risk an organization is willing to accept in pursuit of its objectives. It is a strategic-level metric used by executive leadership and boards to determine if the current level of risk exceeds what the organization is comfortable handling.
Risk evaluation plans (B) outline how risks are assessed, treatment plans (C) describe mitigation actions, and risk tolerance (D) is more operational, defining acceptable variation from the appetite but not the overall strategic limit.
Reference Extract from Study Guide:
'Risk appetite represents the amount of risk an organization is willing to pursue or retain and is established by senior leadership as part of governance activities.'
Why should an information technology (IT) professional be aware of professional associations?
Correct Answer:A. Professional associations provide up-to-date training.
Explanation:
Professional associations are vital for IT professionals because they:
Provide up-to-date training: Offering courses, certifications, and workshops to keep members current with the latest technologies, practices, and industry standards.
Networking opportunities: Facilitating connections with other professionals in the field, which can lead to job opportunities and collaborations.
Professional development: Offering resources and support for career growth and development.
Industry standards and best practices: Providing guidelines and frameworks to ensure high-quality work and ethical practices.
Staying engaged with professional associations helps IT professionals remain knowledgeable and competent in their field.
Reference
CompTIA, 'Advancing the Global IT Industry.'
ISACA, 'Building a Better Digital World.'
Unlock Full
Cybersecurity-Architecture-and-Engineering Exam Features