- 232 Actual Exam Questions
- Compatible with all Devices
- Printable Format
- No Download Limits
- 90 Days Free Updates
Get All WGU Cybersecurity Architecture and Engineering Exam Questions with Validated Answers
| Vendor: | WGU |
|---|---|
| Exam Code: | Cybersecurity-Architecture-and-Engineering |
| Exam Name: | WGU Cybersecurity Architecture and Engineering |
| Exam Questions: | 232 |
| Last Updated: | October 7, 2026 |
| Related Certifications: | WGU Courses and Certifications |
| Exam Tags: | Professional Cybersecurity Architects and Security Engineers |
Looking for a hassle-free way to pass the WGU Cybersecurity Architecture and Engineering exam? DumpsProvider provides the most reliable Dumps Questions and Answers, designed by WGU certified experts to help you succeed in record time. Available in both PDF and Online Practice Test formats, our study materials cover every major exam topic, making it possible for you to pass potentially within just one day!
DumpsProvider is a leading provider of high-quality exam dumps, trusted by professionals worldwide. Our WGU Cybersecurity-Architecture-and-Engineering exam questions give you the knowledge and confidence needed to succeed on the first attempt.
Train with our WGU Cybersecurity-Architecture-and-Engineering exam practice tests, which simulate the actual exam environment. This real-test experience helps you get familiar with the format and timing of the exam, ensuring you're 100% prepared for exam day.
Your success is our commitment! That's why DumpsProvider offers a 100% money-back guarantee. If you don’t pass the WGU Cybersecurity-Architecture-and-Engineering exam, we’ll refund your payment within 24 hours no questions asked.
Don’t waste time with unreliable exam prep resources. Get started with DumpsProvider’s WGU Cybersecurity-Architecture-and-Engineering exam dumps today and achieve your certification effortlessly!
A software development company is required to comply with the Payment Card Industry Data Security Standard (PCI DSS), which sets requirements for the protection of cardholder data. The company uses Secure Shell (SSH) to connect to its cloud-based development environment, which contains cardholder data.
Which security control will meet the needs of the company?
The correct answer is C --- Strong authentication.
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488) materials, PCI DSS compliance requires strong access controls, including strong authentication mechanisms, especially when accessing environments containing cardholder data. SSH access must be protected with methods such as multi-factor authentication or strong, complex credentials to ensure that only authorized users gain access.
Patch management (A) maintains system security but is not specifically about authentication. Network segmentation (B) limits data exposure but does not directly relate to authentication. Vulnerability analysis (D) identifies weaknesses but does not address the need for strong authentication when connecting to sensitive environments.
Reference Extract from Study Guide:
'Strong authentication mechanisms are crucial to protect access to environments that store, process, or transmit cardholder data, in compliance with PCI DSS standards.'
--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Regulatory Compliance and Access Control
=============================================
A government agency is planning a hybrid cloud deployment. Strict controls must be in placethat can label classified data. The solution must ensure that access rights will be granted based on the user's government security classification.
Mandatory Access Control (MAC)is the access control model used in environments that manage classified information such as government or military systems. Under MAC, access is based onsecurity labels(e.g., Top Secret, Confidential), and userscannot changeaccess controls.
NIST SP 800-53 Rev. 5 -- AC-3 (Access Enforcement):
''MAC policies enforce access based on system-enforced labels, without user discretion, and are ideal for high-security environments where strict data control is essential.''
MAC is theonly modelwhere access control decisions arecentrally controlled and enforced by a policy administrator, making it ideal for environments requiringdata labeling and user classification.
WGU Course Alignment:
Domain:Access Control and Identity Management
Topic:Understand and apply MAC for high-security environments
An IT organization has recently implemented a hybrid cloud deployment. The server team is deploying a new set of domain-joined Windows servers on cloud-based virtual machines. Users must be able to use their Active Directory credentials to sign in to applications regardless of whether they are running on Windows servers in the cloud or on-premises.
Which solution should be implemented to meet the requirements?
The correct answer is D --- Identity federation.
WGU Cybersecurity Architecture and Engineering (KFO1 / D488) details that identity federation enables users to authenticate using the same credentials across multiple systems and platforms, including hybrid cloud and on-premises environments. Federation facilitates Single Sign-On (SSO) and seamless authentication.
Two-step verification (A) improves authentication strength but does not federate identities. CHAP (B) is an old protocol for PPP connections. Privileged identity management (C) manages high-privilege accounts, not general user access across domains.
Reference Extract from Study Guide:
'Identity federation allows for seamless authentication across on-premises and cloud environments by trusting external identity providers, supporting Single Sign-On (SSO) and hybrid deployments.'
--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Federation and Identity Management Concepts
A retail company has recently implemented a new point of sale (POS) system that is critical to its business.
Which security control is essential for protecting the availability of the POS system?
Theavailabilityof the POS system depends on itsresilience against known vulnerabilities. Applyingregular security patchesensures that attackers cannot exploit outdated components, which could crash or disrupt the POS system.
NIST SP 800-40 Rev. 3 (Guide to Enterprise Patch Management):
''Prompt application of security patches mitigates vulnerabilities that can be exploited to disrupt system availability or compromise data.''
Backups protect from data loss, butpatching is proactive protectionfor uptime and availability.
WGU Course Alignment:
Domain:Security Operations and Monitoring
Topic:Maintain system availability through proactive patch management
While undergoing a security audit, it is determined that an organization has several backup repositories nested in the cloud without any level of protection. Which action should be taken to protect the backup repositories first?
Theprinciple of least privilegedictates that backups---especially those containing sensitive or mission-critical data---should havestrict access controlsto prevent unauthorized access.
NIST SP 800-209 (Security Guidelines for Storage Infrastructure):
''Access to storage resources must be tightly controlled through identity management and access control policies to prevent compromise or misuse of sensitive data.''
While vulnerability scanning and auditing are goodfollow-upactions,immediate access restrictionis thefirst-line defense.
WGU Course Alignment:
Domain:System Security Engineering
Topic:Secure cloud data storage and apply access control measures
Security & Privacy
Satisfied Customers
Committed Service
Money Back Guranteed