WGU D485 DGN2 TASK 1 SWBTL LLC
CLOUD SECURITY IMPLEMENTATION
PLAN 2026 TEST BANK UPDATED
QUESTIONS WITH ANSWERS GRADED A+
⩥ 2: Implements Operations
Which phase of the cloud data lifecycle is most likely to overlap with the
'Create' phase in terms of implementing security controls. Answer: A.
Share
B. Store
C. Use
D. Destroy
Correct. Answer: B. Store
Explanation:
• Store often overlaps with the Create phase because as soon as data is
created, it usually needs to be securely stored. Security controls, such as
encryption, should be implemented at this stage.
• Share and Use happen after data is stored.
• Destroy is the final stage in the lifecycle and typically occurs after data
is no longer needed.
⩥ 3: Conducts Risk Management
,Which risk management approach involves completely eliminating a
risk because it exceeds the organization's risk appetite. Answer: A.
Mitigation
B. Avoidance
C. Transfer
D. Acceptance
Correct Answer: B. Avoidance
Explanation:
• Avoidance involves eliminating the risk entirely, typically when the
potential impact is too great or when controls cannot adequately reduce
the risk to an acceptable level.
• Mitigation involves reducing the risk to an acceptable level.
• Transfer involves shifting the risk to a third party, such as through
insurance.
• Acceptance involves acknowledging the risk and choosing to bear it
without further action.
⩥ 4: Identifies Legal, Compliance, and Ethical Concerns
Which United States law focuses specifically on the privacy of financial
information. Answer: A. Health Insurance Portability and Accountability
Act (HIPAA)
B. Sarbanes-Oxley Act (SOX)
C. Gramm-Leach-Bliley Act (GLBA)
D. Safe Harbor
,Correct Answer: C. Gramm-Leach-Bliley Act (GLBA)
Explanation:
• GLBA is designed to protect consumer financial privacy by setting
regulations for how financial institutions handle private data.
• HIPAA focuses on healthcare information.
• SOX is concerned with corporate financial practices and reporting.
• Safe Harbor was an agreement between the US and EU for data
transfers, not specifically financial privacy.
⩥ 1: Implements Secure Solutions
Which technology is most effective in preventing unauthorized access to
sensitive data by ensuring it is unreadable without proper decryption
keys. Answer: A. Data Masking
B. Tokenization
C. Encryption
D. Obfuscation
Correct Answer: C. Encryption
Explanation: Encryption transforms readable data into an unreadable
format using cryptographic algorithms, making it inaccessible to
unauthorized users. Tokenization and data masking are also methods of
protecting data, but they do not provide the same level of security as
encryption. Obfuscation is the process of making data more difficult to
understand but is not intended to prevent access.
, ⩥ 2: Implements Operations
Which of the following activities is essential during the Secure
Operations phase of the Software Development Lifecycle (SDLC).
Answer: A. Static Analysis
B. Code Review
C. Dynamic Analysis
D. Acceptance Testing
Correct Answer: C. Dynamic Analysis
Explanation: Dynamic Analysis is crucial during the secure operations
phase because it involves testing the software in a runtime environment,
identifying security vulnerabilities that might only become apparent
during execution. Static Analysis and Code Review are performed
earlier in the SDLC, and Acceptance Testing is typically done after
secure operations to verify the system meets the requirements.
⩥ 3: Conducts Risk Management
Which risk management approach involves the transfer of risk to another
party, such as through insurance. Answer: A. Risk Mitigation
B. Risk Avoidance
C. Risk Transference
D. Risk Acceptance
Correct Answer: C. Risk Transference
Explanation: Risk Transference involves shifting the impact of a risk to a
third party, often by using insurance or outsourcing certain activities.
Risk Mitigation involves reducing the risk, Risk Avoidance involves
CLOUD SECURITY IMPLEMENTATION
PLAN 2026 TEST BANK UPDATED
QUESTIONS WITH ANSWERS GRADED A+
⩥ 2: Implements Operations
Which phase of the cloud data lifecycle is most likely to overlap with the
'Create' phase in terms of implementing security controls. Answer: A.
Share
B. Store
C. Use
D. Destroy
Correct. Answer: B. Store
Explanation:
• Store often overlaps with the Create phase because as soon as data is
created, it usually needs to be securely stored. Security controls, such as
encryption, should be implemented at this stage.
• Share and Use happen after data is stored.
• Destroy is the final stage in the lifecycle and typically occurs after data
is no longer needed.
⩥ 3: Conducts Risk Management
,Which risk management approach involves completely eliminating a
risk because it exceeds the organization's risk appetite. Answer: A.
Mitigation
B. Avoidance
C. Transfer
D. Acceptance
Correct Answer: B. Avoidance
Explanation:
• Avoidance involves eliminating the risk entirely, typically when the
potential impact is too great or when controls cannot adequately reduce
the risk to an acceptable level.
• Mitigation involves reducing the risk to an acceptable level.
• Transfer involves shifting the risk to a third party, such as through
insurance.
• Acceptance involves acknowledging the risk and choosing to bear it
without further action.
⩥ 4: Identifies Legal, Compliance, and Ethical Concerns
Which United States law focuses specifically on the privacy of financial
information. Answer: A. Health Insurance Portability and Accountability
Act (HIPAA)
B. Sarbanes-Oxley Act (SOX)
C. Gramm-Leach-Bliley Act (GLBA)
D. Safe Harbor
,Correct Answer: C. Gramm-Leach-Bliley Act (GLBA)
Explanation:
• GLBA is designed to protect consumer financial privacy by setting
regulations for how financial institutions handle private data.
• HIPAA focuses on healthcare information.
• SOX is concerned with corporate financial practices and reporting.
• Safe Harbor was an agreement between the US and EU for data
transfers, not specifically financial privacy.
⩥ 1: Implements Secure Solutions
Which technology is most effective in preventing unauthorized access to
sensitive data by ensuring it is unreadable without proper decryption
keys. Answer: A. Data Masking
B. Tokenization
C. Encryption
D. Obfuscation
Correct Answer: C. Encryption
Explanation: Encryption transforms readable data into an unreadable
format using cryptographic algorithms, making it inaccessible to
unauthorized users. Tokenization and data masking are also methods of
protecting data, but they do not provide the same level of security as
encryption. Obfuscation is the process of making data more difficult to
understand but is not intended to prevent access.
, ⩥ 2: Implements Operations
Which of the following activities is essential during the Secure
Operations phase of the Software Development Lifecycle (SDLC).
Answer: A. Static Analysis
B. Code Review
C. Dynamic Analysis
D. Acceptance Testing
Correct Answer: C. Dynamic Analysis
Explanation: Dynamic Analysis is crucial during the secure operations
phase because it involves testing the software in a runtime environment,
identifying security vulnerabilities that might only become apparent
during execution. Static Analysis and Code Review are performed
earlier in the SDLC, and Acceptance Testing is typically done after
secure operations to verify the system meets the requirements.
⩥ 3: Conducts Risk Management
Which risk management approach involves the transfer of risk to another
party, such as through insurance. Answer: A. Risk Mitigation
B. Risk Avoidance
C. Risk Transference
D. Risk Acceptance
Correct Answer: C. Risk Transference
Explanation: Risk Transference involves shifting the impact of a risk to a
third party, often by using insurance or outsourcing certain activities.
Risk Mitigation involves reducing the risk, Risk Avoidance involves