WGU D486 (DGN2 TASK 1: Cloud Security Implementation
Plan) – 200 Practice Questions & Answers
Question 1: What is the primary reason for SWBTL LLC’s migration to the Microsoft Azure Cloud?
A) To reduce the number of employees in IT
B) To reduce rising data center costs and address cybersecurity concerns
C) To move headquarters to a different region
D) To increase use of physical servers
Answer: B
Rationale: SWBTL is moving to Azure to reduce rising data center costs and address cybersecurity
concerns. (CliffsNotes, 2024)
Question 2: Which key event created the current cloud implementation crisis for SWBTL?
A) A ransomware attack on their data center
B) A sudden budget cut by the CFO
C) The abrupt departure of the consultant managing the cloud migration
D) A change in government security clearance levels
Answer: C
Rationale: The abrupt departure of the consultant managing the migration left the Azure environment in
urgent need of repair. (Docsity, 2024)
Question 3: Which of the following is NOT a key business requirement given by the CIO?
A) FISMA Compliance
B) Use of SaaS applications only
C) Encryption of data at rest and in transit
,D) Role-Based Access Controls
Answer: B
Rationale: Use of SaaS applications is not a specified requirement; the requirements are FISMA, PCI-DSS
compliance, RBAC, encryption, backup plans, and vulnerability scans.
Question 4: Which compliance framework is specifically required for SWBTL's federal government
contracts?
A) SOX (Sarbanes-Oxley)
B) HIPAA
C) Federal Information Security Modernization Act (FISMA)
D) GDPR
Answer: C
Rationale: FISMA is required for federal contracts. (Docsity, 2024)
Question 5: Because SWBTL processes credit cards daily, which security standard is mandatory?
A) SOC 2
B) ISO 27001
C) HIPAA
D) Payment Card Industry Data Security Standard (PCI DSS)
Answer: D
Rationale: SWBTL must adhere to PCI DSS for credit card security. (Docsity, 2024)
,Question 6: What is the purpose of the NIST SP 800-53 assessment for SWBTL?
A) To establish a new logo
B) To mandate stringent security controls and regular assessments
C) To hire new employees
D) To audit financial statements
Answer: B
Rationale: It mandates stringent security controls and regular assessments. (CliffsNotes, 2024)
Question 7: According to business requirements, how should departments be structured in Azure?
A) Share a single resource group
B) Each department must have its own resource group and Azure Key Vault
C) Merge all departments into a single virtual network
D) Use only on-premises resource groups
Answer: B
Rationale: Each department needs its own RG and Key Vault for data isolation. (CliffsNotes, 2024)
Question 8: What is the principle of least privilege?
A) Granting all users full administrative rights
B) Granting users only the permissions necessary to perform their job duties
C) Removing all permissions from users
, D) Rotating passwords weekly
Answer: B
Rationale: Least privilege ensures users have only the permissions necessary for their duties.
Question 9: Which Azure service is responsible for storing and managing encryption keys, secrets, and
certificates?
A) Azure Active Directory
B) Azure Policy
C) Azure Key Vault
D) Azure Monitor
Answer: C
Rationale: Azure Key Vault securely stores keys, secrets, and certs.
Question 10: What is the recommended cloud service model for SWBTL to meet its compliance and
security needs?
A) SaaS (Software as a Service)
B) PaaS (Platform as a Service)
C) Azure Government Infrastructure as a Service (IaaS)
D) On-premises only
Answer: C
Plan) – 200 Practice Questions & Answers
Question 1: What is the primary reason for SWBTL LLC’s migration to the Microsoft Azure Cloud?
A) To reduce the number of employees in IT
B) To reduce rising data center costs and address cybersecurity concerns
C) To move headquarters to a different region
D) To increase use of physical servers
Answer: B
Rationale: SWBTL is moving to Azure to reduce rising data center costs and address cybersecurity
concerns. (CliffsNotes, 2024)
Question 2: Which key event created the current cloud implementation crisis for SWBTL?
A) A ransomware attack on their data center
B) A sudden budget cut by the CFO
C) The abrupt departure of the consultant managing the cloud migration
D) A change in government security clearance levels
Answer: C
Rationale: The abrupt departure of the consultant managing the migration left the Azure environment in
urgent need of repair. (Docsity, 2024)
Question 3: Which of the following is NOT a key business requirement given by the CIO?
A) FISMA Compliance
B) Use of SaaS applications only
C) Encryption of data at rest and in transit
,D) Role-Based Access Controls
Answer: B
Rationale: Use of SaaS applications is not a specified requirement; the requirements are FISMA, PCI-DSS
compliance, RBAC, encryption, backup plans, and vulnerability scans.
Question 4: Which compliance framework is specifically required for SWBTL's federal government
contracts?
A) SOX (Sarbanes-Oxley)
B) HIPAA
C) Federal Information Security Modernization Act (FISMA)
D) GDPR
Answer: C
Rationale: FISMA is required for federal contracts. (Docsity, 2024)
Question 5: Because SWBTL processes credit cards daily, which security standard is mandatory?
A) SOC 2
B) ISO 27001
C) HIPAA
D) Payment Card Industry Data Security Standard (PCI DSS)
Answer: D
Rationale: SWBTL must adhere to PCI DSS for credit card security. (Docsity, 2024)
,Question 6: What is the purpose of the NIST SP 800-53 assessment for SWBTL?
A) To establish a new logo
B) To mandate stringent security controls and regular assessments
C) To hire new employees
D) To audit financial statements
Answer: B
Rationale: It mandates stringent security controls and regular assessments. (CliffsNotes, 2024)
Question 7: According to business requirements, how should departments be structured in Azure?
A) Share a single resource group
B) Each department must have its own resource group and Azure Key Vault
C) Merge all departments into a single virtual network
D) Use only on-premises resource groups
Answer: B
Rationale: Each department needs its own RG and Key Vault for data isolation. (CliffsNotes, 2024)
Question 8: What is the principle of least privilege?
A) Granting all users full administrative rights
B) Granting users only the permissions necessary to perform their job duties
C) Removing all permissions from users
, D) Rotating passwords weekly
Answer: B
Rationale: Least privilege ensures users have only the permissions necessary for their duties.
Question 9: Which Azure service is responsible for storing and managing encryption keys, secrets, and
certificates?
A) Azure Active Directory
B) Azure Policy
C) Azure Key Vault
D) Azure Monitor
Answer: C
Rationale: Azure Key Vault securely stores keys, secrets, and certs.
Question 10: What is the recommended cloud service model for SWBTL to meet its compliance and
security needs?
A) SaaS (Software as a Service)
B) PaaS (Platform as a Service)
C) Azure Government Infrastructure as a Service (IaaS)
D) On-premises only
Answer: C