Page 1 of 349
D320 /WGU D320 - MANAGING CLOUD
SECURITY OA AND PA EXAM BANK | {LATEST
2026/ 2027 UPDATE} COMPLETE ACTUAL AND
AUTHENTIC EXAM | BRAND NEW!
Which one of the following would not normally be found in an
organization's information security policy?
A. Statement of the importance of cybersecurity
B. Requirement to use AES-256 encryption
C. Delegation of authority
D. Designation of responsible executive
B
Which of the following storage types is most closely associated with a
database-type storage implementation?
A) Unstructured
B) Volume
C) Object
,Page 2 of 349
D) Structured
D
Gwen is developing a new security policy for her organization. Which
one of the following statements does not reflect best practices for
policy development?
A. All stakeholders should agree with the proposed policy.
B. The policy should follow normal corporate policy approval
processes.
C. Policies should match the "tone at the top" from senior business
leaders.
D. Cybersecurity managers are typically responsible for
communicating and implementing approved security policies.
A
Which one of the following items is not normally included in a request
for an exception to security policy?
A. Description of a compensating control
B. Description of the risks associated with the exception
,Page 3 of 349
C. Proposed revision to the security policy
D. Business justification for the exception
C
A U.S. federal government agency is negotiating with a cloud service
provider for the use of IaaS services. What program should the vendor
be certified under before entering into this agreement?
A. FIPS 140-2
B. Common Criteria
C. FedRAMP
D. ISO 27001
C
The accounting department in your organization is considering using a
new cloud service provider. As you investigate the provider, you
discover that one of their major investors withdrew their support and
will not be providing future funding. What major concern should you
raise?
A. Vendor lock-in
, Page 4 of 349
B. Vendor suitability
C. Vendor security
D. Vendor viability
D
Which kind of analysis identifies and reports on risks affecting
availability, integrity, and confidentiality (AIC) of key information
assets?
A) Network analysis
B) Predictive analysis
C) Market analysis
D) Gap analysis
D
What type of PII is regulated based on the type of application or per
the conditions of the specific hosting agreement?
A) Specific
B) Contractual
D320 /WGU D320 - MANAGING CLOUD
SECURITY OA AND PA EXAM BANK | {LATEST
2026/ 2027 UPDATE} COMPLETE ACTUAL AND
AUTHENTIC EXAM | BRAND NEW!
Which one of the following would not normally be found in an
organization's information security policy?
A. Statement of the importance of cybersecurity
B. Requirement to use AES-256 encryption
C. Delegation of authority
D. Designation of responsible executive
B
Which of the following storage types is most closely associated with a
database-type storage implementation?
A) Unstructured
B) Volume
C) Object
,Page 2 of 349
D) Structured
D
Gwen is developing a new security policy for her organization. Which
one of the following statements does not reflect best practices for
policy development?
A. All stakeholders should agree with the proposed policy.
B. The policy should follow normal corporate policy approval
processes.
C. Policies should match the "tone at the top" from senior business
leaders.
D. Cybersecurity managers are typically responsible for
communicating and implementing approved security policies.
A
Which one of the following items is not normally included in a request
for an exception to security policy?
A. Description of a compensating control
B. Description of the risks associated with the exception
,Page 3 of 349
C. Proposed revision to the security policy
D. Business justification for the exception
C
A U.S. federal government agency is negotiating with a cloud service
provider for the use of IaaS services. What program should the vendor
be certified under before entering into this agreement?
A. FIPS 140-2
B. Common Criteria
C. FedRAMP
D. ISO 27001
C
The accounting department in your organization is considering using a
new cloud service provider. As you investigate the provider, you
discover that one of their major investors withdrew their support and
will not be providing future funding. What major concern should you
raise?
A. Vendor lock-in
, Page 4 of 349
B. Vendor suitability
C. Vendor security
D. Vendor viability
D
Which kind of analysis identifies and reports on risks affecting
availability, integrity, and confidentiality (AIC) of key information
assets?
A) Network analysis
B) Predictive analysis
C) Market analysis
D) Gap analysis
D
What type of PII is regulated based on the type of application or per
the conditions of the specific hosting agreement?
A) Specific
B) Contractual