WGU Cybersecurity-Architecture-and-Engineering Exam Overview:
| Certification Vendor: | Western Governors University (WGU) |
| Exam Name: | Cybersecurity Architecture and Engineering |
| Exam Number: | KFO1 / D488 |
| Passing Score: | Competency-based (Pass / Not Yet Competent) |
| Available Languages: | English |
| Exam Format: | Online proctored objective assessment, Multiple-choice (typical WGU OA format) |
| Recommended Training: | WGU Course Materials (Cybersecurity Architecture and Engineering) |
| Exam Registration: | WGU Student Portal (Assessment Scheduling) |
| Sample Questions: | WGU Cybersecurity-Architecture-and-Engineering Sample Questions |
| Exam Way: | Online proctored objective assessment via WGU testing system |
| Pre Condition: | No formal prerequisite exam required; typically taken after foundational cybersecurity coursework within WGU program. |
| Official Syllabus URL: | https://www.wgu.edu/online-it-degrees/cybersecurity-information-assurance-bachelors-program.html |
WGU Cybersecurity-Architecture-and-Engineering Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: Risk and Compliance in Security Architecture | - Security frameworks and standards (NIST, ISO 27001) - Risk assessment methodologies |
| Topic 2: Security Architecture Principles | - Secure system architecture concepts - Security design principles (least privilege, defense in depth) |
| Topic 3: Network Security Architecture | - Network segmentation and zoning - Secure network design and controls (firewalls, IDS/IPS) |
| Topic 4: Identity and Access Management (IAM) | - Access control frameworks (RBAC, ABAC) - Authentication and authorization models |
| Topic 5: Security Engineering and Implementation | - Secure development lifecycle concepts - System hardening and configuration management |
| Topic 6: Cryptography and Data Protection | - Encryption standards and usage scenarios - Key management principles |
WGU Cybersecurity Architecture and Engineering (KFO1/D488) Sample Questions:
1. A government agency is evaluating its business continuity plan to ensure that its operations can continue during a crisis.
What is the term used to describe the critical services that must be maintained during a disruption?
A) Mission essential functions (MEFs)
B) Business continuity planning (BCP)
C) Recovery point objective (RPO)
D) Disaster recovery (DR)
2. A large multinational corporation maintains a complex network of data centers across the world.
Which type of disaster recovery site will ensure business continuity in case of a disaster?
A) A remote location with cloud-based backups
B) A fully equipped hot site with up-to-date hardware and software
C) A secondary location with basic backup hardware and software
D) A mobile data center that can be deployed to the disaster zone
3. A software development company is required to comply with the Payment Card Industry Data Security Standard (PCI DSS), which sets requirements for the protection of cardholder data. The company uses Secure Shell (SSH) to connect to its cloud-based development environment, which contains cardholder data.
Which security control will meet the needs of the company?
A) Patch management
B) Strong authentication
C) Vulnerability analysis
D) Network segmentation
4. What allows a user to query information from an online database with a web application without revealing what they are viewing?
A) Secure function evaluation (SFE)
B) Private function evaluation (PFE)
C) Private information retrieval (PIR)
D) Homomorphic encryption
5. A company has recently failed a security audit. Many of the end users have passwords older than 365 days.
Which password policy type will prevent this issue?
A) Expiration
B) Recovery
C) Complexity
D) Length
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: B | Question # 3 Answer: B | Question # 4 Answer: C | Question # 5 Answer: A |

We're so confident of our products that we provide no hassle product exchange.


By Jeffrey


