Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
A company is preparing to test its disaster recovery plan, which includes procedures for restoringcritical systems in the event of a disruption. The company wants to conduct a test that is as close to a real disaster as possible without actually disrupting business operations.
Which disaster recovery test will meet the needs of the company?
The correct answer is B --- Parallel simulation test.
WGU Cybersecurity Architecture and Engineering (KFO1 / D488) defines a parallel simulation test as simulating a disaster recovery process where systems are restored at an alternate site without actually taking the primary systems offline. It allows organizations to test full restoration capabilities while avoiding disruption of live operations.
Walk-throughs (A) and tabletop exercises (D) are lower-impact simulations. Full interruption tests (C) would stop operations, which the company wants to avoid.
Reference Extract from Study Guide:
'Parallel simulation tests validate the ability to recover and operate critical systems at an alternate site without affecting primary business operations.'
--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Disaster Recovery Testing Types
A financial institution is planning to conduct a business impact analysis (BIA) to evaluate the criticality of its business processes and functions.
Which steps will allow the company to perform a BIA?
The correct answer is C --- Determine business processes and recovery criticality, identify resource requirements, and identify recovery priorities for system resources.
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488), a BIA identifies critical business functions, determines the impact of disruptions, and establishes recovery priorities, including resource needs.
A (monitoring) relates to incident response. B (developing BCP) is after BIA. D (recovery strategies) is part of disaster recovery planning after BIA findings.
Reference Extract from Study Guide:
'Business impact analysis (BIA) involves determining critical business processes, evaluating their recovery requirements, and prioritizing system recovery efforts.'
--- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Business Impact Analysis Procedures
A company has recently completed its disaster recovery plan and is preparing to test it. Thecompany's IT team has identified the need to simulate a disaster scenario to evaluate the effectiveness of the plan. The team has considered options including full interruption tests, walkthroughs, tabletop exercises, and checklists. They want to choose a testing method that will allow them to evaluate the plan in a controlled environment while minimizing the impact on the company's operations.
Which testing method will meet the needs of the company?
Tabletop exercisessimulate emergency scenarios in alow-risk, discussion-based format, allowing teams to walk through recovery procedures and decision-making without disrupting actual business operations.
NIST SP 800-84 (Guide to Test, Training, and Exercise Programs):
''Tabletop exercises are effective tools for validating plans and procedures in a discussion format without impacting normal operations.''
Full interruption tests are disruptive; checklists and walkthroughs offer lower fidelity evaluations.
WGU Course Alignment:
Domain:Business Continuity and Disaster Recovery
Topic:Test disaster plans using low-impact simulation techniques
Which software allows the user to easily access the hardware of a computer?
The operating system (OS) is the primary software that manages all the hardware and other software on a computer. It acts as an intermediary between users and the computer hardware. The OS handles basic tasks such as controlling and allocating memory, prioritizing system requests, controlling input and output devices, facilitating networking, and managing files. Examples include Windows, macOS, and Linux.
How do data support an organization's business goals?
Data support an organization's business goals by providing crucial information that aids in making informed decisions. Analyzing data helps identify trends, measure performance, and uncover insights that drive strategic planning and operational improvements. This informed decision-making process is vital for achieving business goals and staying competitive in the market.
232 questions covering all exam domains, starting from $20
6 domains from the WGU Cybersecurity-Architecture-and-Engineering exam outline, with approximate weightings. Every sample question above is tagged with the domain it comes from
This exam section evaluates the capabilities of Cybersecurity Architects to connect and integrate enterprise software systems securely. It emphasizes secure design patterns, approaches for exchanging data, and maintaining seamless functionality among applications, all while upholding the core principles of security throughout the development and rollout phases.
Sample question from this domain above: Q4
This part assesses Security Engineers, requiring candidates to implement robust protection measures for organizational data. The focus is on utilizing encryption, structured access controls, and systematic data classification to protect sensitive information, ensuring these practices comply with both internal guidelines and broader regulatory expectations.
Sample question from this domain above: Q5
This section tasks Cloud Security Architects with reviewing various cloud infrastructure models and virtualization technologies, examining their security, compliance, and operational efficiency. Participants analyze cloud deployment choices like IaaS, PaaS, and SaaS, understanding the respective responsibility models to securely incorporate these technologies into organizational architecture.
This domain centers on the responsibilities of Security Analysts in recognizing and analyzing threats and weaknesses within enterprise environments. It covers the interpretation of vulnerability scans and threat intelligence, and encourages recommending solutions to minimize potential risks as identified throughout organizational systems.
Incident Response Specialists are measured in this section, as the exam focuses on the coordinated procedures involved in incident management. Topics include planning, identifying, analyzing, containing, eliminating, and recovering from security incidents, along with the structured application of response frameworks and effective communication during critical events.
Cloud Security Engineers are assessed here for their ability to securely deploy and administer cloud solutions. This segment emphasizes activities such as oversight of cloud resources, configuration management, applying security standards, and maintaining compliance with policies governing cloud operations across the enterprise.
Common questions about the exam itself