Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

Cybersecurity-Architecture-and-Engineering Exam Questions & Answers

WGU Cybersecurity Architecture and Engineering (KFO1/D488)  •  WGU

232 Questions Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample Cybersecurity-Architecture-and-Engineering Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

An organization's engineering team is developing a mobile application that uses near-field communication (NFC) capabilities but wants to ensure that information communicated using this protocol remains confidential.

Correct Answer: D
Explanation:

The correct answer is D --- Encryption to prevent man-in-the-middle and eavesdropping attacks.

WGU Cybersecurity Architecture and Engineering (KFO1 / D488) explains that while NFC is inherently short-range, it is still vulnerable to eavesdropping and man-in-the-middle attacks. Applying encryption ensures that even if communication is intercepted, the data remains protected and confidential.

Kerberos (A) is primarily for authentication within internal networks. Bluetooth restrictions (B) are unrelated to NFC. PDM (C) restricts device usage but does not directly protect NFC communication.

Reference Extract from Study Guide:

'Encrypting near-field communication ensures confidentiality and protects against interception and manipulation through man-in-the-middle and eavesdropping attacks.'

--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Wireless and Mobile Security Concepts

Q2 MultipleChoice

A company is moving its applications to the cloud and is concerned about cyber security threats. The security team has been tasked with providing a comprehensive view of how attackers gainaccess, move through networks, and carry out attacks.

Which framework identifies the seven phases of an attack, from initial infiltration to post-exploitation?

Correct Answer: C
Explanation:

The correct answer is C --- Cyber kill chain.

The Cyber Kill Chain, developed by Lockheed Martin, is a model that breaks down a cyber attack into seven distinct phases: reconnaissance, weaponization, delivery, exploitation, installation, command and control (C2), and actions on objectives. According to the WGU Cybersecurity Architecture and Engineering (KFO1 / D488) study materials, this model helps security teams understand and interrupt an attack at various stages.

While MITRE ATT&CK (B) and its ICS variant (A) provide detailed mappings of techniques used by attackers, they are not structured specifically into seven phases like the Cyber Kill Chain. The Diamond Model (D) is an analysis methodology, not a phase-based model.

Reference Extract from Study Guide:

'The Cyber Kill Chain model divides the sequence of a cyber attack into seven phases, providing a structured method for analyzing and disrupting attacks.'

--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Attack Frameworks and Methodologies

Q3 MultipleChoice

A professional services organization deployed security edge devices in key locations on its corporate network.

How will these devices improve the organization's security posture?

Correct Answer: A
Explanation:

Security edge devices(such as NGFWs, IDS/IPS, and secure gateways) are deployed at thenetwork perimeterto inspect and filter traffic, providing aninitial layer of defenseagainst external threats before they reach internal systems.

NIST SP 800-41 Rev. 1:

''Edge security devices enforce security policy at network boundaries and act as a first line of defense by preventing unauthorized or malicious traffic from entering the internal network.''

They are not TPMs or SIEMs, though they maygenerate dataconsumed by SIEMs.

WGU Course Alignment:

Domain:Network Security

Topic:Deploy perimeter defense technologies at network entry points

Q4 MultipleChoice

A company has recently experienced a data breach in which customer information was stolen. The company is concerned about the potential for future data breaches. A review of the incident revealed that the breach originated from stolen credentials.

Which security measure will meet the needs of this company?

Correct Answer: A
Explanation:

The correct answer is A --- Implementing two-factor authentication.

According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488) content, two-factor authentication (2FA) strengthens authentication processes by requiring users to provide two forms of evidence (e.g., password + SMS code or authentication app) before accessing systems. Even if credentials are stolen, without the second factor, attackers would be unable to log in.

Background checks (B) are important for insider threats but not stolen external credentials. Security awareness training (C) is good practice but does not technically prevent the misuse of stolen credentials. SIEM systems (D) help detect breaches but do not stop unauthorized access at the authentication layer.

Reference Extract from Study Guide:

'Two-factor authentication mitigates the risks associated with credential theft by requiring an additional factor, significantly improving the security posture.'

--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Authentication and Identity Management

Q5 MultipleChoice

An insurance agency is concerned that some employees could be mishandling funds and covering it up. The agency wants to temporarily block these employees from working and ensure that operations continue.

Which strategy should the agency implement?

Correct Answer: B
Explanation:

The correct answer is B --- Mandatory vacation.

According to the WGU Cybersecurity Architecture and Engineering (KFO1 / D488) coursework, mandatory vacation policies require employees to take time off, during which their duties are either paused or performed by others. This break can reveal fraudulent activities, as the original employee cannot cover up their misconduct during their absence.

Separation of duties (A) prevents a single person from controlling critical processes but is not about temporarily removing an employee. Job rotation (C) moves employees between roles regularly but doesn't enforce a break. Least privilege (D) restricts access but does not address uncovering hidden misconduct.

Reference Extract from Study Guide:

'Mandatory vacations help detect fraudulent activities, as employee absence can expose irregularities that would otherwise remain hidden through continuous control over processes.'

--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Administrative Security Controls

Get access to all 232 verified questions with detailed answers.

Unlock All Cybersecurity-Architecture-and-Engineering Questions

Frequently Asked Questions

The Cybersecurity Architecture and Engineering (KFO1/D488) is a capstone course and certification exam offered by Western Governors University that assesses your ability to design, implement, and manage secure IT infrastructure. This exam tests knowledge across network security, cryptography, secure system design, and enterprise security architecture.

The exam covers key cybersecurity domains including network architecture and security, cryptographic systems, secure system design principles, identity and access management, and security governance. You'll also need to understand threat modeling, vulnerability assessment, and how to implement security controls across enterprise environments.

The exam is typically a performance-based assessment that may take several hours to complete, though exact duration can vary. It's designed to comprehensively evaluate your practical cybersecurity architecture and engineering skills rather than just theoretical knowledge.

Most WGU cybersecurity programs require you to complete foundational cybersecurity courses before attempting this capstone exam. It's recommended that you have a solid understanding of networking, systems administration, and basic security principles before attempting this advanced certification.

WGU provides course materials, labs, and study resources specifically designed for this exam as part of your degree program. Additionally, reviewing industry frameworks like NIST, studying for related certifications like Security+, and gaining hands-on experience with security tools and infrastructure design will strengthen your preparation.
Exam Details
  • Exam CodeCybersecurity-Architecture-and-Engineering
  • VendorWGU
  • Total Questions232
  • LanguageEnglish
  • Last UpdatedSep 1, 2026
4.9/5

Pass Cybersecurity-Architecture-and-Engineering First Time

Get all 232 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals