WGU C838 EXAM STUDY GUIDE 2026
COMPREHENSIVE QUESTIONS AND
SOLUTIONS
◉ "Which regulation requires a CSP to comply with copyright law for
hosted content?
(A) SOX
(B) SCA
(C) GLBA
(D) DMCA"
Answer: DMCA
Digital Millennium Copyright Act
◉ "Which element is a cloud virtualization risk?
(A) Licensing
(B) Jurisdiction
(C) Guest isolation
(D) Electronic discovery"
Answer: Guest isolation
◉ "Which risk is related to interception of data in transit?
,(A) Virtualization
(B) Traffic blocking
(C) Man-in-the-middle
(D) Software vulnerabilities"
Answer: Man-in-the-middle
◉ "Which method is being used when a company evaluates the
acceptable loss exposure associated with a cloud solution for a given
set of objectives and resources?
(A) Risk appetite
(B) Risk management
(C) Business impact analysis
(D) Business continuity planning"
Answer: Risk appetite
◉ "The security administrator for a global cloud services provider
(CSP) is required to globally standardize the approaches for using
forensics methodologies in the organization.
Which standard should be applied?
(A) Sarbanes-Oxley act (SOX)
(B) Cloud controls matrix (CCM)
(C) International electrotechnical commission (IEC) 27037
(D) International organization for standardization (ISO) 27050-1"
, Answer: International organization for standardization (ISO) 27050-
1
◉ "Which detection and analysis technique is performed to capture
a point-in-time picture of the entire stack at the time of an incident?
(A) Review data access logs
(B) Examine configuration data
(C) Collect metadata during alert
(D) Create a snapshot using API calls"
Answer: Create a snapshot using API calls
◉ "A CSP operating in Australia experiences a security breach that
results in disclosure of personal information that is likely to result in
serious harm. Who is the CSP legally required to notify?
(A) Cloud Security Alliance
(B) Information commissioner
(C) Australian privacy foundation
(D) Asian-Paci?c privacy control board"
Answer: Information commissioner
◉ "A CSP provides services in European Union (EU) countries that
are subject to the network information security (NIS) directive. The
CSP experiences an incident that significantly affects the continuity
of the essential services being provided.
COMPREHENSIVE QUESTIONS AND
SOLUTIONS
◉ "Which regulation requires a CSP to comply with copyright law for
hosted content?
(A) SOX
(B) SCA
(C) GLBA
(D) DMCA"
Answer: DMCA
Digital Millennium Copyright Act
◉ "Which element is a cloud virtualization risk?
(A) Licensing
(B) Jurisdiction
(C) Guest isolation
(D) Electronic discovery"
Answer: Guest isolation
◉ "Which risk is related to interception of data in transit?
,(A) Virtualization
(B) Traffic blocking
(C) Man-in-the-middle
(D) Software vulnerabilities"
Answer: Man-in-the-middle
◉ "Which method is being used when a company evaluates the
acceptable loss exposure associated with a cloud solution for a given
set of objectives and resources?
(A) Risk appetite
(B) Risk management
(C) Business impact analysis
(D) Business continuity planning"
Answer: Risk appetite
◉ "The security administrator for a global cloud services provider
(CSP) is required to globally standardize the approaches for using
forensics methodologies in the organization.
Which standard should be applied?
(A) Sarbanes-Oxley act (SOX)
(B) Cloud controls matrix (CCM)
(C) International electrotechnical commission (IEC) 27037
(D) International organization for standardization (ISO) 27050-1"
, Answer: International organization for standardization (ISO) 27050-
1
◉ "Which detection and analysis technique is performed to capture
a point-in-time picture of the entire stack at the time of an incident?
(A) Review data access logs
(B) Examine configuration data
(C) Collect metadata during alert
(D) Create a snapshot using API calls"
Answer: Create a snapshot using API calls
◉ "A CSP operating in Australia experiences a security breach that
results in disclosure of personal information that is likely to result in
serious harm. Who is the CSP legally required to notify?
(A) Cloud Security Alliance
(B) Information commissioner
(C) Australian privacy foundation
(D) Asian-Paci?c privacy control board"
Answer: Information commissioner
◉ "A CSP provides services in European Union (EU) countries that
are subject to the network information security (NIS) directive. The
CSP experiences an incident that significantly affects the continuity
of the essential services being provided.