2025/2026 – Latest Questions & Answers| Questions &
Answers| Grade A+| 100% Correct (Verified Solutions)
WGU D489 – Cybersecurity Management course.
This is written to match WGU OA style: scenario-based, management-focused,
policy/governance heavy, and aligned with NIST, ISO 27001, risk management,
incident response, and executive decision-making.
WGU D489 – Cybersecurity Management
FINAL EXAM PRACTICE (Most Tested • Most Difficult)
Questions 1–50
GOVERNANCE, RISK & COMPLIANCE (GRC)
1.
A CISO wants to align the organization’s cybersecurity strategy with business
objectives. Which document BEST accomplishes this?
A. Incident response plan
B. Security awareness policy
C. Enterprise risk management framework
D. Technical security baseline
Answer-: C
Rationale: ERM frameworks align security risk with organizational goals.
,2.
Which role is ultimately accountable for organizational risk acceptance?
A. Security analyst
B. CISO
C. Risk committee
D. Executive leadership
Answer-: D
3.
Which framework is MOST commonly used for cybersecurity risk management in
U.S. federal and private sectors?
A. ISO 27001
B. COBIT
C. NIST RMF
D. ITIL
Answer-: C
4.
Risk is BEST defined as:
A. Known vulnerabilities
B. Likelihood × impact
C. Threat actors only
D. System weaknesses
Answer-: B
5.
Which activity represents risk acceptance?
A. Purchasing cyber insurance
,B. Implementing compensating controls
C. Formally documenting and approving residual risk
D. Eliminating a system
Answer-: C
6.
A risk register is primarily used to:
A. Track vulnerabilities only
B. Document and prioritize risks
C. Record incident response steps
D. Monitor employee behavior
Answer-: B
7.
Which risk treatment option reduces exposure by sharing risk?
A. Avoidance
B. Mitigation
C. Transfer
D. Acceptance
Answer-: C
8.
Which role should OWN cybersecurity policies?
A. IT department
B. Security operations
C. Executive management
D. Help desk
Answer-: C
, 9.
Which metric BEST demonstrates cybersecurity effectiveness to executives?
A. Number of firewall rules
B. Mean time to detect (MTTD)
C. Antivirus signature count
D. Password length
Answer-: B
10.
Which document defines management intent and direction?
A. Standard
B. Guideline
C. Policy
D. Procedure
Answer-: C
SECURITY POLICIES & PROGRAM MANAGEMENT
11.
Which policy is MOST critical for reducing insider threat risk?
A. Acceptable use policy
B. Data classification policy
C. Least privilege policy
D. Incident response policy
Answer-: C
12.
A cybersecurity program should be reviewed:
A. Only after incidents
B. Annually or after major changes