School of Technology

WGU D490: Cybersecurity Graduate Capstone

A verified study guide to WGU D490: Cybersecurity Graduate Capstone, the 4-CU final course of the MSCSIA. Covers what the performance assessment asks you to produce, how long students report it taking, a week-by-week plan for scoping and writing the project, the mistakes that get submissions returned, and a readiness checklist.

D490School of Technology4 CUsMediumPerformance Assessment
WGU D490 Cybersecurity Graduate Capstone exam guide cover

The Final Course Standing Between You and Your MSCSIA

D490: Cybersecurity Graduate Capstone closes out Western Governors University's Master of Science in Cybersecurity and Information Assurance (MSCSIA), a 34-competency-unit program of ten courses. D490 carries 4 competency units and sits in term four of the standard path — the final term — for a structural reason. The program guidebook is blunt: every other course must be satisfied before you start the capstone. Security Foundations, Secure Network Design, Secure Software Design, Security Operations, Cloud Security, Penetration Testing, Cybersecurity Architecture and Engineering, Governance, Risk, and Compliance, and Cybersecurity Management all come first.

Direct answer: D490 is not an exam — it is a performance assessment built around one substantial cybersecurity project that you plan, justify, and document. You pass by choosing a realistic, narrowly scoped organizational security problem early, then writing to the rubric point by point rather than writing a general paper and hoping it covers everything.

The official course description sets two expectations that explain the grading philosophy. First, your project should show you can stand up a cybersecurity and information assurance program that endures — not a one-off technical fix. Second, it should pull together what you learned across every domain of the degree and point all of it at a single significant, real-world security problem. The evaluator is not checking whether you picked up one new topic in D490. They are checking whether a graduate-level practitioner could hand your document to a decision-maker and have it hold up.

Many students arriving at D490 are working adults who have already spent three terms on technical, certification-aligned coursework — the MSCSIA maps courses to credentials including ISC2 Certified in Cybersecurity, CompTIA CySA+, PenTest+, and ISACA CISM. The capstone feels nothing like that, and the difference is where people stall: no lecture set to consume, no question bank to drill, and no finish line other than the evaluator accepting your work. The ambiguity becomes manageable once you treat the project like a client engagement instead of a school assignment.

What the Capstone Deliverable Is Really Asking For

Because D490 sits on top of the entire degree, the material you draw from is material you already studied. Expect your project to pull from the domains the MSCSIA courses cover:

  • Risk and threat analysis — what the organization actually has to lose, and what realistically threatens it.
  • Secure network architecture — segmentation, device configuration, and design decisions defended against recognized best practice.
  • Security operations and incident response — detection, response, and recovery capability, not prevention alone.
  • Governance, risk, and compliance — mapping recommendations to the standards and regulations that apply to your chosen environment.
  • Security policy and program management — the policies, procedures, and roles that keep the fix alive after you leave.
  • Cloud and software security, where your chosen problem touches them.
  • Implementation realism — timeline, resources, cost justification, and how you will measure whether it worked.

Notice what is missing: novel research. This is an applied capstone, not a thesis. The guidebook's single stated competency is that you integrate and synthesize competencies from across the degree and show you can contribute value in the field — nothing about original contributions to the discipline. Plan to break new ground and you will over-scope and burn weeks.

How Hard Is D490, and How Long Should You Budget?

Difficulty here is logistical more than conceptual. Nothing in the capstone is likely to be harder than what you handled in penetration testing or architecture coursework. It simply eats calendar time in ways technical courses do not, because every submission must be read and returned by an evaluator before you know whether you are finished.

Completion times vary widely and WGU publishes no official figure, so treat any number you see as anecdote rather than benchmark. Students arriving with a well-formed idea and strong writing habits sometimes describe finishing in a couple of weeks; others describe a month or more, usually because a topic had to be reworked or a submission came back. A sensible planning assumption is three to five weeks of steady effort, with your first submission out around week two so returned feedback still leaves room in the term.

Two variables drive that range. The first is topic scope: a tightly bounded problem at a specific organization is far faster to document than "improve security at a large enterprise." The second is your comfort with long-form technical writing — if organizing a long document is not natural for you, add a week and outline before drafting prose.

Building the Capstone: A Working Plan

Week one — lock the topic and get it cleared. Pick a real or realistic organization you understand well, ideally your employer or a plausible composite, and pick one problem you could genuinely fix. Squaring your topic away with your course instructor before you write anything is the highest-value hour you will spend in this course. Bring two or three candidate topics so you have alternatives ready if the first is too broad.

Week one to two — build the evidence base before the prose. Gather the artifacts your argument will rest on: an asset inventory, a risk register, the standards or frameworks you will map against, and the real constraints such as budget or staffing. This is also the moment to re-anchor your vocabulary, so terms like threat, vulnerability, and risk stay precise under evaluator scrutiny.

Week two to three — write to the rubric, not to the topic. Turn every rubric requirement into a heading in your draft, then fill each heading. This is the single most reliable technique in any WGU performance assessment, and it matters most in a document this long, because a strong paper that quietly skips one required element still comes back. Read each requirement literally: if it says "justify," an explanation is not enough — you need reasoning tied to evidence.

Week three — apply active recall to your own document. Close the draft and state out loud what problem you are solving, why your solution is proportionate to the risk, and how you would prove it worked. Anything you cannot say cleanly is a section your evaluator will find vague. This is the capstone equivalent of practice testing, and it surfaces far more problems than rereading.

Week three to four — polish and submit early. Check that every claim is either cited or clearly labeled as your professional judgment, that figures and appendices are referenced in the text, and that the document reads in one voice rather than as stitched fragments. Submit with term time to spare so a revision request is an inconvenience rather than a crisis.

Where D490 Submissions Go Wrong

  • Choosing a topic that is too big. "Redesign enterprise security" cannot be documented, justified, and scheduled at capstone length. Aim for one control domain, one business unit, one measurable outcome.
  • Writing a research paper instead of a project. The capstone wants a plan you could execute, with timeline, resources, and success criteria — not a literature survey.
  • Skipping the durability angle. The official description emphasizes a lasting program. Recommendations with no policy, no named owner, and no maintenance plan read as incomplete.
  • Vague risk language. Calling a threat "high" without describing likelihood, impact, and the assets involved is a fast route to a returned submission.
  • Ignoring the compliance layer. Whatever environment you chose, some standard or regulation applies. Name it and map to it.
  • Treating evaluator feedback as an insult. Revisions are routine. Address each comment explicitly and resubmit quickly rather than rewriting from scratch.
  • Starting late in the term. Evaluator turnaround is outside your control, so a late start is the most common reason a capstone slips into another term — and another tuition payment.

D490 Readiness Checklist

  • Can you state your capstone problem in one sentence a non-technical manager would understand?
  • Can you name the specific organization, environment, and scope boundary your project applies to?
  • Can you tie each proposed control back to a documented risk rather than to preference?
  • Can you identify the standards or regulations your recommendations map to, and explain why they apply?
  • Can you produce a realistic implementation timeline with resources, dependencies, and costs?
  • Can you define how you would measure whether the project succeeded after deployment?
  • Can you point to a heading in your draft for every single rubric requirement?
  • Can you explain how the improvement is sustained — policy, ownership, and review cadence — after the project ends?
  • Have you had your topic reviewed and cleared before investing weeks in the full draft?

Many MSCSIA students arrive from WGU's undergraduate technology degrees, and a few of those courses make useful refreshers while you scope the capstone: D325 Networks for architecture vocabulary, D385 Software Security and Testing if your project touches application security, D370 IT Leadership Foundations for the governance and ownership side, and D333 Ethics in Technology for privacy and compliance framing. The School of Technology hub and the WGU course guide index cover the rest. Always confirm official requirements against the WGU MSCSIA program guidebook.

D490 FAQ

Is D490 an objective assessment or a performance assessment?

D490 is assessed through a performance assessment. There is no proctored multiple-choice exam and no certification exam attached to this course. You submit a capstone project deliverable that an evaluator scores against a rubric, and you may be asked to revise and resubmit.

How many competency units is D490 worth?

The MSCSIA program guidebook lists the Cybersecurity Graduate Capstone at 4 competency units, placed in term four of the standard path within a 34-competency-unit master's program.

Can I take D490 early to get it out of the way?

No. The guidebook states that all other courses must be satisfied before you take D490, because the project is meant to synthesize competencies from across the whole degree. There is no path that front-loads the capstone.

How long does the capstone usually take?

WGU does not publish a figure, and student reports vary a great deal. Some describe finishing in under two weeks with a topic ready to go; others describe three to five weeks or more, with evaluator turnaround being the main variable outside their control. Starting early in the term is the safest strategy either way.

Do I need a real employer to write about?

Not necessarily, but a real or closely modeled environment makes the project far easier to write, because you already know the assets, constraints, and organizational politics. Confirm your approach with your course instructor before you commit to a fictional scenario.

What is the best single piece of preparation advice for D490?

Build your draft's outline directly from the rubric requirements before writing a word of prose. The requirement a student addressed implicitly rather than explicitly is what most often sends a capstone back for revision.

Related Technology guides