[2025年10月25日]Cybersecurity-Architecture-and-Engineering認定ガイド問題と解答トレーニング
Cybersecurity-Architecture-and-Engineering認定お試しセット最新Cybersecurity-Architecture-and-EngineeringのPDF問題集
質問 # 43
What is the correct order of project phases?
- A. 1) Initiation2) Planning° 3) Executing4) Monitoring and Controllings) Closing
- B. 1) Executing2) Monitoring and Controlling3) Initiation4) Planning5) Closing
- C. 1)Initiation2)Executing3)Planning4)Monitoring and Controllings) Closing
- D. 1) Planning2) InitiationAMonitoring and Controlling4) Executings) Closing
正解:A
解説:
The correct order of project phases according to the Project Management Institute (PMI) and other standard project management methodologies is:
Initiation: This phase involves defining the project at a high level and getting approval to start.
Planning: In this phase, detailed planning is done to set the project's scope, objectives, and procedures.
Executing: This phase is where the project plan is put into action and the project deliverables are created.
Monitoring and Controlling: This phase involves tracking, reviewing, and regulating the project's progress and performance, ensuring that everything aligns with the project plan.
Closing: This is the final phase, where the project is formally closed, and final deliverables are handed over.
References
Project Management Institute, "A Guide to the Project Management Body of Knowledge (PMBOK Guide)," PMI.
Harold Kerzner, "Project Management: A Systems Approach to Planning, Scheduling, and Controlling," Wiley.
質問 # 44
A security analyst for a financial institution is in the process of planning to upgrade the institution's IT infrastructure to meet current industry standards. There are various potential risks associated with the upgrade, including data breaches, system outages, and cost overruns. The analyst is tasked with managing these risks to ensure a successful upgrade.
What is the first step in the risk management life cycle in this scenario?
- A. Control
- B. Assess
- C. Review
- D. Identify
正解:D
解説:
The correct answer is D - Identify.
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488), the first step in risk management is identifying potential risks. Only once risks are identified can they be assessed, controlled, and reviewed. In this case, identifying potential data breaches, outages, and cost issues is the starting point.
Assess (A) happens after identification. Control (B) involves implementing responses. Review (C) happens later to check effectiveness.
Reference Extract from Study Guide:
"The first phase of risk management is risk identification, where potential threats and vulnerabilities are recognized and documented."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Risk Management Life Cycle
質問 # 45
An application team manages a large farm of web servers on virtual machines in the cloud. The team wants to reduce the server load by caching static content. Adding a second layer of protection is also a requirement.
What should this team recommend in this scenario?
- A. Firewall rule changes
- B. Reverse proxy
- C. Network address translation (NAT)
- D. Intrusion detection system (IDS)
正解:B
解説:
The correct answer is C - Reverse proxy.
As per the WGU Cybersecurity Architecture and Engineering (KFO1 / D488) course content, a reverse proxy server acts on behalf of web servers by caching static content (such as images, scripts, and HTML files), significantly reducing server load. It also provides an additional layer of protection by hiding the backend servers from direct exposure to clients and enabling centralized application of security policies such as SSL termination and Web Application Firewall (WAF) integration.
Firewall rule changes (A) manage access control but do not handle caching or reduce load. An IDS (B) monitors for intrusions but doesn't offload traffic or cache content. NAT (D) translates IP addresses but doesn't cache content or add a protection layer.
Reference Extract from Study Guide:
"A reverse proxy server provides caching capabilities for static content and acts as a protective intermediary between client requests and backend servers, thus reducing server load and enhancing security."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Secure Network Design Concepts
質問 # 46
A large technology company has discovered a known vulnerability in its network infrastructure. The infrastructure contains a number of retired assets that are no longer receiving security updates, which can potentially be exploited by attackers to compromise the network. The company has decided to implement hardening techniques and endpoint security controls to mitigate the risk.
Which hardening technique will meet the needs of this company?
- A. Conducting regular vulnerability scans to identify potential weaknesses
- B. Removing all end-of-life devices from the network
- C. Implementing intrusion detection and prevention systems (IDPS)
- D. Enforcing strict access control policies for all network devices
正解:B
解説:
The correct answer is D - Removing all end-of-life devices from the network.
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488), end-of-life systems pose significant risks because they no longer receive patches or updates. The besthardening technique in this situation is to decommission and remove these devices, eliminating their vulnerabilities altogether.
Access control (A), vulnerability scanning (B), and IDPS (C) are helpful practices but do not eliminate vulnerabilities of unsupported devices.
Reference Extract from Study Guide:
"Removing end-of-life or unsupported assets is essential for maintaining a secure infrastructure, as these devices are highly vulnerable to exploitation."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), System and Device Hardening
質問 # 47
Match the legislative purpose with the corresponding legislation.
Answer options may be used more than once or not at all.
正解:
解説:
* DMCA (Digital Millennium Copyright Act)
* Purpose: The DMCA makes it illegal to violate copyrights by disseminating digitized material.
* Explanation: The DMCA was enacted in 1998 to address the issues of digital rights management and copyright infringement in the digital age. It provides legal protection to copyright holders against unauthorized copying, sharing, and distribution of their digital works. The legislation
* criminalizes the production and dissemination of technology, devices, or services intended to circumvent measures that control access to copyrighted works (commonly known as DRM-Digital Rights Management).
* References: DMCA Overview - U.S. Copyright Office
* HIPAA (Health Insurance Portability and Accountability Act)
* Purpose: Prohibits agencies from distributing an individual's health information without the individual's consent.
* Explanation: HIPAA, enacted in 1996, is designed to protect individuals' medical records and other personal health information. The Privacy Rule under HIPAA sets standards for the protection of health information by health plans, healthcare clearinghouses, and healthcare providers that conduct certain healthcare transactions electronically. It mandates the protection and confidential handling of protected health information (PHI).
* References: HIPAA Privacy Rule - U.S. Department of Health & Human Services
* FERPA (Family Educational Rights and Privacy Act)
* Purpose: Gives students the right to access their own educational records and prevents schools from distributing student records without permission.
* Explanation: FERPA is a federal law enacted in 1974 that protects the privacy of student education records. It grants parents certain rights with respect to their children's education records, which transfer to the student when they reach 18 years of age or attend a school beyond the high school level. FERPA requires that schools must have written permission from the student or parent to release any information from a student's education record.
* References: FERPA Regulations - U.S. Department of Education
質問 # 48
An e-learning company uses Amazon Simple Storage Service (Amazon S3) to store e-books and video files that are served to customers through a custom application. The company has realized that someone has been stealing its intellectual property.
Which threat actor is most likely in this scenario?
- A. Novice hacker
- B. Hacktivist
- C. Competitor
- D. Advanced persistent threat
正解:C
解説:
The correct answer is C - Competitor.
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488), competitors often attempt to steal intellectual property to gain a business advantage. Given the theft of valuable business assets (e-books and videos), the most likely actor is a competitor motivated by financial or market advantage, not ideology or random hacking.
An APT (A) is usually nation-state-sponsored and targets critical infrastructure. A novice hacker (B) might deface or cause damage but is less likely focused on IP theft. Hacktivists (D) are politically motivated, not financially.
Reference Extract from Study Guide:
"Competitors may engage in cyber espionage to steal intellectual property and gain market advantage, representing a significant threat to business assets."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Threat Actor Categories
質問 # 49
Which key exchange algorithm is based on advanced cryptography algorithms and is a more efficient alternative to traditional key exchange algorithms?
- A. Digital Signature Algorithm (DSA)
- B. Rivest-Shamir-Adleman (RSA)
- C. Elliptic Curve Diffie-Hellman (ECDH)
- D. Diffie-Hellman (DH)
正解:C
解説:
The correct answer is B - Elliptic Curve Diffie-Hellman (ECDH).
WGU Cybersecurity Architecture and Engineering (KFO1 / D488) material highlights that ECDH is an enhanced, more efficient form of the traditional Diffie-Hellman key exchange, using elliptic curve cryptography (ECC). It provides similar security with much smaller key sizes, improving performance and efficiency.
DH (A) is the traditional method but is less efficient. RSA (C) is primarily used for encryption and digital signatures. DSA (D) is used for digital signatures, not for key exchange.
Reference Extract from Study Guide:
"Elliptic Curve Diffie-Hellman (ECDH) enhances traditional key exchange by utilizing elliptic curve cryptography, offering higher security with smaller key sizes and improved efficiency."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Cryptographic Key Management
質問 # 50
How are IT and globalization related?
- A. IT allows businesses to reach global HIPAA compliance.
- B. IT allows businesses to create tax havens for global companies.
- C. IT allows businesses to have a global reach.
- D. IT allows businesses to create a global common gateway interface (CGI).
正解:C
解説:
Information Technology (IT) has revolutionized the way businesses operate, enabling them to reach global markets and audiences. IT facilitates communication, data exchange, and operational efficiency across borders, allowing companies to manage global operations and engage with international customers seamlessly.
This global reach is a critical aspect of modern business strategies, driven by advancements in IT infrastructure and services.
質問 # 51
A company may choose to use CDs, DVDs, hard drives, or even cloud storage for data backup.
Which aspect of data backup does this statement describe?
- A. Incremental backups
- B. Image backups
- C. Data mirroring
- D. Backup media
正解:D
解説:
The statement refers to the different types of media that can be used for data backup. Backup media encompasses various storage devices and methods used to store copies of data. Examples include:
* CDs and DVDs: Optical storage media used for smaller-scale backups.
* Hard drives: Mechanical or solid-state drives used for local and external backups.
* Cloud storage: Online services providing remote storage and access to backups.
Choosing the appropriate backup media is crucial for ensuring data availability and recovery in case of data loss.
References
* David M. Kroenke and Randall J. Boyle, "Using MIS," Pearson.
* Curtis Preston, "Backup & Recovery: Inexpensive Backup Solutions for Open Systems," O'Reilly Media.
質問 # 52
What are two differences between a handheld computer and a desktop?
Choose 2 answers.
- A. A desktop has more memory.
- B. A handheld has more internal storage.
- C. A desktop has more internal storage.
- D. A handheld has more memory.
正解:A、C
解説:
Desktops typically have more memory (RAM) and internal storage (hard drives or SSDs) compared to handheld computers. This allows desktops to handle more intensive computing tasks and store larger amounts of data. Handheld devices, on the other hand, prioritize portability and battery life over high storage and memory capacity.
質問 # 53
What does the following SQL statement produce when executed?
SELECT ' FROM Customers
WHERE State = 'Arizona';
- A. All of the records from the Customers table that are located in Arizona
- B. All of the records from the Customers table
- C. All of the records from the Customers database that are located in Arizona
- D. All of the records from the Customers database
正解:A
解説:
* The SQL statementSELECT * FROM Customers WHERE State = 'Arizona';is used to select records from theCustomerstable.
* TheSELECT *clause indicates that all columns from theCustomerstable should be returned.
* TheWHEREclause filters the rows to only include those where theStatecolumn value is'Arizona'.
* The result is a subset of theCustomerstable with all rows that match the condition.
References:
* "SQL For Dummies" by Allen G. Taylor.
* "SQL Pocket Guide" by Jonathan Gennick.
質問 # 54
A government agency is planning a hybrid cloud deployment. Strict controls must be in place that can label classified data. The solution must ensure that access rights will be granted based on the user's government security classification.
Which type of access control should be used?
- A. Mandatory access control (MAC)
- B. Attribute-based access control (ABAC)
- C. Role-based access control (RBAC)
- D. Discretionary access control (DAC)
正解:A
解説:
The correct answer is A - Mandatory access control (MAC).
Per WGU Cybersecurity Architecture and Engineering (KFO1 / D488) coursework, MAC is a strict access control model where access to resources is based on information labels (such as classified, secret, top secret) and user clearances. Only administrators define and control the policy rules, and users cannot alter access settings, making it ideal for environments where classification labels determine access rights, such as government systems.
ABAC (B) focuses on attributes but is more dynamic rather than based purely on rigid classifications. DAC (C) gives data owners control over access permissions, unsuitable for classified government environments.
RBAC (D) assigns permissions based on roles, but not necessarily aligned with security labels.
Reference Extract from Study Guide:
"Mandatory access control (MAC) enforces access policies based on fixed labels and security classifications, making it the preferred model for high-security environments like government agencies handling classified data."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Access Control Models
質問 # 55
A medium-sized grocery chain with locations all across the United States has a new business requirement that all devices must authenticate to access its resources.
What should the grocery chain use for the devices to authenticate?
- A. Public key infrastructure (PKI)
- B. Endpoint passwords
- C. Virtual private network (VPN)
- D. Certificate signing
正解:A
解説:
The correct answer is B - Public key infrastructure (PKI).
According to the WGU Cybersecurity Architecture and Engineering (KFO1 / D488) Study Guide, PKI is the framework that enables the issuance and management of digital certificates used for device authentication. By using certificates, devices can securely authenticate themselves to access corporate resources without relying solely on passwords.
VPNs (A) secure network connections but do not authenticate devices themselves. Certificate signing (C) is a part of PKI but not the complete infrastructure. Endpoint passwords (D) authenticate users, not necessarily the devices.
Reference Extract from Study Guide:
"Public key infrastructure (PKI) enables the issuance of digital certificates used for authenticating users, systems, and devices, ensuring secure access control."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Cryptography and PKI Concepts
質問 # 56
An organization wants to implement a new encryption solution for a real-time video conferencing application.
The organization wants to ensure that the encryption solution provides protection for the video stream without causing significant delays or latency in the conference.
Which type of encryption will meet the needs of the organization?
- A. Asymmetric encryption
- B. Hash functions
- C. Stream ciphers
- D. Block ciphers
正解:C
解説:
The correct answer is C - Stream ciphers.
WGU Cybersecurity Architecture and Engineering (KFO1 / D488) content explains that stream ciphers encrypt data bit-by-bit or byte-by-byte, making them highly efficient and suitable for real-time applications like video conferencing where low latency is critical.
Block ciphers (A) encrypt large chunks of data, causing latency. Asymmetric encryption (B) is too slow for real-time data streams. Hash functions (D) are used for data integrity, not for ongoing data encryption.
Reference Extract from Study Guide:
"Stream ciphers encrypt data continuously and are ideal for real-time applications such as video or audio streaming where low latency is essential."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Encryption Technologies
質問 # 57
A company recently updated its disaster recovery plan (DRP) to ensure business continuity in the event of a disruptive incident.
Which step will ensure the effectiveness of the DRP?
- A. Developing and implementing a testing plan for the DRP
- B. Reviewing and updating the DRP regularly to ensure it remains relevant
- C. Performing a risk assessment of the company's information assets
- D. Training employees on their roles and responsibilities during a disaster
正解:A
解説:
The correct answer is A - Developing and implementing a testing plan for the DRP.
According to WGU Cybersecurity Architecture and Engineering (KFO1 / D488), testing the disaster recovery plan is critical to ensuring that it is functional and effective when an actual disruptive event occurs. Regularly scheduled DRP testing validates that recovery processes work as intended and that personnel are familiar with their responsibilities.
Reviewing (B) and training (D) are important but are supplementary activities. Risk assessment (C) is important for planning but does not test the DRP.
Reference Extract from Study Guide:
"Testing and exercising disaster recovery plans ensure operational readiness and reveal gaps or weaknesses that can be corrected before an actual event occurs."
- WGU Cybersecurity Architecture and Engineering (KFO1 / D488), Disaster Recovery Testing and Validation
質問 # 58
Management has asked its networking team to recommend a solution for direct communication between multiple virtual networks in the cloud. The solution must utilize the least amount of administrative effort.
- A. Remote Desktop Protocol (RDP)
- B. Domain Name System (DNS)
- C. Virtual network peering
- D. Virtual Local Area Network (VLAN)
正解:C
解説:
Virtual Network Peeringallows two or more virtual networks to communicate through private IP addresses, enabling seamless traffic flow across resources in different networks withminimal configuration overhead.
Microsoft Azure Documentation (Network Peering):
"Virtual network peering seamlessly connects Azure virtual networks. The networks appear as one for connectivity purposes, and traffic is routed through Microsoft's backbone infrastructure." Unlike VPNs or complex routing configurations,peeringis simple,requires no downtime, and doesn't need encryption if networks are internal.
#WGU Course Alignment:
Domain:Information Systems and Architecture
Topic:Cloud architecture, network segmentation, and inter-VNET connectivity
質問 # 59
......
ベストWGU Cybersecurity-Architecture-and-Engineering学習ガイドと問題集は2025:https://jp.fast2test.com/Cybersecurity-Architecture-and-Engineering-premium-file.html
トップクラスWGU Cybersecurity-Architecture-and-Engineering試験最先端学習ガイド!練習問題バージョン:https://drive.google.com/open?id=1nkaWXHIV0MyPMwLLQAL27Sg9ppPRhX_r