Updated Mar-2026 Exam Engine for Cybersecurity-Architecture-and-Engineering Exam Free Demo & 365 Day Updates [Q39-Q54]

Share

Updated Mar-2026 Exam Engine for Cybersecurity-Architecture-and-Engineering Exam Free Demo & 365 Day Updates

Exam Passing Guarantee Cybersecurity-Architecture-and-Engineering Exam with Accurate Quastions!

NEW QUESTION # 39
A company wants to improve the security of its software development process and reduce the risk of vulnerabilities in its applications. The company is looking for a solution that can isolate its applications and provide a secure environment for development and testing.
Which security technology meets the needs of this company?

  • A. Virtual private network (VPN)
  • B. Data loss prevention (DLP)
  • C. Firewall
  • D. Containerization

Answer: D

Explanation:
The correct answer is D - Containerization.
WGU Cybersecurity Architecture and Engineering (KFO1 / D488) material states that containerization provides isolated environments (containers) where applications can be developed, tested, and deployed securely. This isolation minimizes the risk of vulnerabilities affecting the host system or other applications, improving the overall security of the development process.
DLP (A) prevents data leakage but does not isolate applications. VPNs (B) secure network traffic but do not create isolated development environments. Firewalls (C) control network traffic but do not manage application-level isolation.
Reference Extract from Study Guide:
"Containerization secures application development and deployment by isolating applications in lightweight, standalone environments, reducing risk and improving manageability."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Application Security Concepts


NEW QUESTION # 40
An organization wants to securely transmit sensitive information between two parties. The organization wants to use a cryptographic technique that allows both parties to encrypt and decrypt messages using the same key.
The organization is also concerned about the performance impact of the encryption technique.
Which type of cryptographic algorithm meets the needs of the organization?

  • A. Block cipher
  • B. Hash function
  • C. Asymmetric algorithm
  • D. Symmetric algorithm

Answer: D

Explanation:
The correct answer is C - Symmetric algorithm.
According to the WGU Cybersecurity Architecture and Engineering (KFO1 / D488) study material, symmetric encryption uses the same key for both encryption and decryption, offering high speed and lower computational overhead compared to asymmetric algorithms. This makes symmetric encryption ideal when both security and performance are important factors.
Block cipher (A) is a type of symmetric algorithm but not the broader category being asked. Hash functions (B) are for data integrity, not encryption/decryption. Asymmetric algorithms (D) are more secure for key exchange but have higher computational cost.
Reference Extract from Study Guide:
"Symmetric encryption algorithms use a single shared key for encryption and decryption, offering efficient and high-performance protection for sensitive data transmissions."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Cryptography Fundamentals


NEW QUESTION # 41
Match the legislative purpose with the corresponding legislation.
Answer options may be used more than once or not at all.

Answer:

Explanation:

Explanation:
DMCA (Digital Millennium Copyright Act)
Purpose: The DMCA makes it illegal to violate copyrights by disseminating digitized material.
The DMCA was enacted in 1998 to address the issues of digital rights management and copyright infringement in the digital age. It provides legal protection to copyright holders against unauthorized copying, sharing, and distribution of their digital works. The legislation criminalizes the production and dissemination of technology, devices, or services intended tocircumvent measures that control access to copyrighted works (commonly known as DRM-Digital Rights Management).
DMCA Overview - U.S. Copyright Office
HIPAA (Health Insurance Portability and Accountability Act)
Purpose: Prohibits agencies from distributing an individual's health information without the individual's consent.
HIPAA, enacted in 1996, is designed to protect individuals' medical records and other personal health information. The Privacy Rule under HIPAA sets standards for the protection of health information by health plans, healthcare clearinghouses, and healthcare providers that conduct certain healthcare transactions electronically. It mandates the protection and confidential handling of protected health information (PHI).
References: HIPAA Privacy Rule - U.S. Department of Health & Human Services FERPA (Family Educational Rights and Privacy Act) Purpose: Gives students the right to access their own educational records and prevents schools from distributing student records without permission.
Explanation: FERPA is a federal law enacted in 1974 that protects the privacy of student education records. It grants parents certain rights with respect to their children's education records, which transfer to the student when they reach 18 years of age or attend a school beyond the high school level. FERPA requires that schools must have written permission from the student or parent to release any information from a student's education record.
References: FERPA Regulations - U.S. Department of Education


NEW QUESTION # 42
Which action should an IT department take if an organization decides to expand its business by selling products online?

  • A. Make sure the website can handle e-commerce transactions
  • B. Manage capital to ensure a successful website
  • C. Market the company's products or services
  • D. Ensure that the strategic goals aligned with the organization's mission statement

Answer: A

Explanation:
When an organization decides to expand its business by selling products online, the IT department needs to ensure that the website is equipped to handle e-commerce transactions. This involves:
* Setting up a secure online payment system: Ensuring that payment gateways and encryption methods are in place to protect sensitive customer data.
* Scalability: Making sure the website infrastructure can handle increased traffic and transaction volumes without compromising performance.
* Integration: Ensuring the e-commerce platform is integrated with the organization's existing systems, such as inventory management, order fulfillment, and customer relationship management (CRM) systems.
* Compliance: Adhering to regulatory requirements and industry standards for online transactions, such as PCI DSS compliance for payment processing.
Therefore, making sure the website can handle e-commerce transactions is crucial for a successful online business expansion.
References
* Efraim Turban, Judy Whiteside, David King, and Jon Outland, "Introduction to Electronic Commerce and Social Commerce," Springer.
* Laudon, K.C. and Traver, C.G., "E-commerce 2020-2021: Business, Technology, Society," Pearson.


NEW QUESTION # 43
A government agency is planning a hybrid cloud deployment. Strict controls must be in place that can label classified data. The solution must ensure that access rights will be granted based on the user's government security classification.
Which type of access control should be used?

  • A. Discretionary access control (DAC)
  • B. Mandatory access control (MAC)
  • C. Role-based access control (RBAC)
  • D. Attribute-based access control (ABAC)

Answer: B

Explanation:
The correct answer is A - Mandatory access control (MAC).
Per WGU Cybersecurity Architecture and Engineering (KFO1 / D488) coursework, MAC is a strict access control model where access to resources is based on information labels (such as classified, secret, top secret) and user clearances. Only administrators define and control the policy rules, and users cannot alter access settings, making it ideal for environments where classification labels determine access rights, such as government systems.
ABAC (B) focuses on attributes but is more dynamic rather than based purely on rigid classifications. DAC (C) gives data owners control over access permissions, unsuitable for classified government environments.
RBAC (D) assigns permissions based on roles, but not necessarily aligned with security labels.
Reference Extract from Study Guide:
"Mandatory access control (MAC) enforces access policies based on fixed labels and security classifications, making it the preferred model for high-security environments like government agencies handling classified data."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Access Control Models


NEW QUESTION # 44
A cloud hosting provider is concerned about the potential risks associated with attacks that target the confidentiality and integrity of sensitive data stored on its servers' volatile memory. The provider has decided to implement hardening techniques and endpoint security controls to mitigate the risk.
Which hardening technique will meet the needs of this provider?

  • A. Conducting regular security awareness training for all employees
  • B. Enforcing a strong password complexity policy for all user accounts
  • C. Implementing a next-generation antivirus system to detect and prevent malware attacks
  • D. Implementing secure encrypted enclaves and AMD Secure Memory Encryption

Answer: D

Explanation:
To protect datain use(within memory), the provider must implementhardware-level memory encryptionandtrusted execution environments(secure enclaves), which protect against cold boot attacks, memory scraping, and unauthorized access.
NIST SP 800-207A (Hardware-Enabled Security: Enclaves):
"Trusted execution environments and memory encryption mechanisms help ensure that data remains protected even when systems are compromised at lower levels." This is amodern cloud security best practiceespecially useful forconfidential computingenvironments.
#WGU Course Alignment:
Domain:System Security Engineering / Cryptography
Topic:Protect data in use with hardware-based encryption and enclaves


NEW QUESTION # 45
Which database has multiple tables with interrelated fields?

  • A. Hierarchical
  • B. Interrelated
  • C. Relational
  • D. Flat file

Answer: C

Explanation:
* Arelational databaseis structured to recognize relations among stored items of information.
* Multiple tablesin a relational database can have interrelated fields.
* These relationships are often managed throughforeign keys, which reference the primary keys of other tables.
* This relational model allows for complex queries and data integrity across the database.
* Example:Tables such asCustomers,Orders, andProductsin a sales database, whereOrderstable may reference bothCustomersandProductstables to establish relationships.
References:
* "Database System Concepts" by Silberschatz, Korth, and Sudarshan.
* "SQL and Relational Theory" by C.J. Date.


NEW QUESTION # 46
A company with a hybrid cloud deployment needs to identify all possible threat types that could impact production systems.
Which threat hunting technique should be used to identify potential attacks that have already occurred?

  • A. Log analysis
  • B. Honeypots
  • C. Social engineering
  • D. Penetration testing

Answer: A

Explanation:
The correct answer is B - Log analysis.
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488) curriculum, log analysis is critical for retrospective threat hunting - reviewing system, network, and application logs to identify signs of compromise or unauthorized activities that might have gone unnoticed in real-time. This technique helps uncover attacks that have already occurred in hybrid or cloud environments.
Honeypots (A) are proactive traps to detect future attacks. Social engineering (C) involves manipulating people, not hunting threats. Penetration testing (D) is used to find vulnerabilities, not to review past incidents.
Reference Extract from Study Guide:
"Threat hunting through log analysis involves systematically reviewing collected logs to uncover evidence of past or ongoing compromises, enabling organizations to identify and respond to threats that may have bypassed preventive controls."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Threat Detection and Hunting Concepts Of course!
Here are the verified and properly formatted answers for your next set of questions, strictly following your instructions and the WGU Cybersecurity Architecture and Engineering (KFO1 / D488) official course materials:


NEW QUESTION # 47
Which protocol can be used to provide secure email communication and ensure the confidentiality, integrity, and authenticity of email messages?

  • A. Simple Mail Transfer Protocol (SMTP)
  • B. Internet Protocol Security (IPsec)
  • C. Secure/Multipurpose Internet Mail Extensions (S/MIME)
  • D. Pretty Good Privacy (PGP)

Answer: C

Explanation:
The correct answer is C - Secure/Multipurpose Internet Mail Extensions (S/MIME).
As outlined in WGU Cybersecurity Architecture and Engineering (KFO1 / D488), S/MIME provides encryption, integrity, and authentication for email messages by using public key cryptography and digital signatures.
SMTP (A) is used for sending emails but does not secure them. PGP (B) also secures emails but is not a protocol; it is a program and standard. IPsec (D) secures network communications, not email specifically.
Reference Extract from Study Guide:
"Secure/Multipurpose Internet Mail Extensions (S/MIME) is a protocol used to encrypt and digitally sign email communications, ensuring confidentiality, integrity, and authenticity."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Secure Communication Technologies


NEW QUESTION # 48
Which system conversion method deploys the new system while the old system is still operational in order to compare output?

  • A. Pilot
  • B. Phased
  • C. Direct
  • D. Parallel

Answer: D

Explanation:
Parallel conversion is a system deployment method where the new system is implemented and runs alongside the old system for a period of time. This method allows for:
* Comparison of outputs: Ensuring that the new system produces the same or better results as the old system.
* Risk reduction: If there are issues with the new system, the old system can still be used without interrupting business operations.
* User adaptation: Users can get accustomed to the new system while still having access to the familiar old system.
Parallel conversion is often used to minimize the risk associated with deploying a new system.
References
* Harold Kerzner, "Project Management: A Systems Approach to Planning, Scheduling, and Controlling," Wiley.
* Kathy Schwalbe, "Information Technology Project Management," Cengage Learning.


NEW QUESTION # 49
Which risk management strategy will ensure the secure configuration and deployment of a new online banking system and help prevent credit card fraud?

  • A. Implementation of real-time transaction monitoring
  • B. Configuration of the system to disable all email services on all workstations
  • C. Implementation of a strict firewall policy to restrict access to the system's server
  • D. Use of regular system backups to an off-site location

Answer: A

Explanation:
The correct answer is A - Implementation of real-time transaction monitoring.
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488), real-time transaction monitoring detects and alerts suspicious banking activities immediately, helping prevent credit card fraud and securing the online banking system during deployment and use.
Strict firewall policies (B) help secure access but are not transaction-specific. Disabling email (C) and performing backups (D) are good practices but do not directly address fraud prevention.
Reference Extract from Study Guide:
"Real-time transaction monitoring identifies suspicious activities, providing immediate detection and prevention of fraudulent transactions in online banking systems."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Financial Systems and Fraud Prevention Strategies


NEW QUESTION # 50
A software development company is required to comply with the Payment Card Industry Data Security Standard (PCI DSS), which sets requirements for the protection of cardholder data. The company uses Secure Shell (SSH) to connect to its cloud-based development environment, which contains cardholder data.
Which security control will meet the needs of the company?

  • A. Vulnerability analysis
  • B. Patch management
  • C. Network segmentation
  • D. Strong authentication

Answer: D

Explanation:
The correct answer is C - Strong authentication.
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488) materials, PCI DSS compliance requires strong access controls, including strong authentication mechanisms, especially when accessing environments containing cardholder data. SSH access must be protected with methods such as multi- factor authentication or strong, complex credentials to ensure that only authorized users gain access.
Patch management (A) maintains system security but is not specifically about authentication. Network segmentation (B) limits data exposure but does not directly relate to authentication. Vulnerability analysis (D) identifies weaknesses but does not address the need for strong authentication when connecting to sensitive environments.
Reference Extract from Study Guide:
"Strong authentication mechanisms are crucial to protect access to environments that store, process, or transmit cardholder data, in compliance with PCI DSS standards."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Regulatory Compliance and Access Control


NEW QUESTION # 51
An IT organization has recently implemented a hybrid cloud deployment. The server team is deploying a new set of domain-joined Windows servers on cloud-based virtual machines. Users must be able to use their Active Directory credentials to sign in to applications regardless of whether they are running on Windows servers in the cloud or on-premises.

  • A. Challenge-Handshake Authentication Protocol (CHAP)
  • B. Privileged identity management
  • C. Two-step verification
  • D. Identity federation

Answer: D

Explanation:
Identity federationallows authentication credentials to be used across multiple systems or domains- includingon-premises and cloud platforms-without duplicating user databases.
NIST SP 800-63C (Federated Identity Guidelines):
"Federation enables users to access multiple, disparate services using a single digital identity that can be shared securely across organizational boundaries." This approach is essential in hybrid architectures where cloud VMs and on-prem servers must recognize acentralized identity providerlike Active Directory.
#WGU Course Alignment:
Domain:Access Control and Identity Management
Topic:Implement federated identity in hybrid and multi-cloud environments


NEW QUESTION # 52
A cybersecurity analyst at a manufacturing company is tasked with analyzing the Indicators of Compromise (IOCs) to identify potential threats and vulnerabilities within the organization.While viewing the Security Information and Event Management (SIEM), the analyst notices an unknown IP address logging in to the company's Secure Shell (SSH) server.

  • A. Enumeration
  • B. Weak passwords
  • C. Exfiltration
  • D. Unpatched software

Answer: B

Explanation:
An unknown IP address successfully logging in viaSSHindicates that authentication was achieved - likely due toweak or reused passwords. This is not enumeration or vulnerability exploitation, but acredential-based compromise.
NIST SP 800-118 (Guide to Enterprise Password Management):
"Weak, default, or reused passwords are among the most exploited vulnerabilities in enterprise networks, particularly on remote access services such as SSH." This is one of the most common findings inSIEM alertswhen password policies and access control mechanisms are improperly enforced.
#WGU Course Alignment:
Domain:System Security Engineering
Topic:Implement strong authentication practices and monitor remote access


NEW QUESTION # 53
Which task is the responsibility of a database administrator?

  • A. Installing and configuring databases
  • B. Deciding on database applications for the company
  • C. Compiling code into an executable file
  • D. Troubleshooting network security issues

Answer: A

Explanation:
* ADatabase Administrator (DBA)is responsible for managing the database infrastructure.
* Primary responsibilitiesinclude:
* Installing and configuringnew databases and database servers.
* Ensuring databases run efficiently and are properly maintained.
* Performingbackup and recoveryoperations to prevent data loss.
* Monitoring performanceand tuning databases for optimal performance.
* Implementingsecurity measuresto protect the database against unauthorized access.
References:
* "Database Administration: The Complete Guide to DBA Practices and Procedures" by Craig S. Mullins.
* Oracle and Microsoft SQL Server official documentation.


NEW QUESTION # 54
......

Exam Questions for Cybersecurity-Architecture-and-Engineering Updated Versions With Test Engine: https://www.passtestking.com/WGU/Cybersecurity-Architecture-and-Engineering-practice-exam-dumps.html

Test Engine to Practice Test for Cybersecurity-Architecture-and-Engineering Valid and Updated Dumps: https://drive.google.com/open?id=15vjpRo0DISr315CXlGGi0XzWtxxya7Pu