Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 33 pages
Exam (elaborations)

WGU D485 DGN2 TASK 1: CLOUD SECURITY IMPLEMENTATION PLAN Comprehensive 80-Question Practice Exam with Verified Answers & Detailed Rationales Updated for 2026 | Complete Solutions | A+ Graded

Document preview thumbnail
Preview 4 out of 33 pages

WGU D485 DGN2 TASK 1: CLOUD SECURITY IMPLEMENTATION PLAN Comprehensive 80-Question Practice Exam with Verified Answers & Detailed Rationales Updated for 2026 | Complete Solutions | A+ Graded

Content preview

WGU D485 DGN2 TASK 1: CLOUD SECURITY
IMPLEMENTATION PLAN Comprehensive 80-Question
Practice Exam with Verified Answers & Detailed Rationales
Updated for 2026 | Complete Solutions | A+ Graded

Question 1
SWBTL LLC is migrating to Microsoft Azure and has identified overly permissive
IAM roles as a high-severity security gap. Which of the following is the BEST
practice for implementing role-based access control (RBAC) in Azure?
A) Assign the Owner role to all users to simplify administration
B) Assign roles with the least privilege necessary and at the narrowest scope
C) Use shared administrative accounts to reduce management overhead
D) Assign Contributor role to all developers for flexibility
Correct Answer: B. Assign roles with the least privilege necessary and at the
narrowest scope
Rationale: The principle of least privilege ensures users receive only the
permissions required to perform their tasks, which reduces risk and improves
auditability. Azure RBAC best practices include assigning roles with the least
amount of privilege and scope, using Azure AD groups rather than direct user
assignments, and reserving Contributor/Owner roles for when absolutely
necessary.


Question 2
Which of the following is the MOST effective way to manage Azure RBAC
assignments at scale?
A) Assign roles directly to individual users
B) Use Azure Active Directory groups for role assignments
C) Create custom roles for each user
D) Use shared accounts for multiple users
Correct Answer: B. Use Azure Active Directory groups for role assignments

,Rationale: Azure AD groups are preferred over direct user assignments for role-
based access control. Group-based assignment simplifies management, improves
auditability, and ensures consistent permission application across users with
similar job functions.


Question 3
SWBTL LLC has identified that MFA is not enforced for administrators as a high-
severity gap. What is the recommended approach to enforce MFA for all
administrative accounts in Azure?
A) Enable MFA manually for each admin account
B) Use Conditional Access policies to require MFA for all admin accounts
C) Require users to change passwords monthly
D) Use security defaults only
Correct Answer: B. Use Conditional Access policies to require MFA for all
admin accounts
Rationale: Conditional Access policies in Microsoft Entra (formerly Azure AD)
dynamically control access to corporate resources based on user identity, location,
device status, and other conditions. Requiring MFA for all admin accounts (Global
admins, Exchange admins, SharePoint admins, etc.) is a critical security control.


Question 4
Which Azure service should be used to enforce MFA for all users, including
external guests accessing SWBTL LLC's cloud resources?
A) Azure Policy
B) Azure Security Center
C) Conditional Access
D) Azure Sentinel
Correct Answer: C. Conditional Access
Rationale: Conditional Access policies can require MFA for all users, including
admins and external identities (guests). Conditional Access provides granular
control over access conditions and is the recommended approach for enforcing
MFA across an organization's Azure environment.

,Question 5
What is the PRIMARY benefit of implementing Conditional Access policies in
"Report-Only" mode before enforcement?
A) It reduces the cost of Azure AD Premium licensing
B) It allows administrators to test policy impact without disrupting users
C) It automatically fixes security gaps
D) It replaces the need for MFA
Correct Answer: B. It allows administrators to test policy impact without
disrupting users
Rationale: Conditional Access policies can be tested in "Report-Only" mode to
see their impact before enforcing them. This allows administrators to validate
policy effectiveness and identify potential disruptions to legitimate workflows
before full implementation.


Question 6
Which of the following is a key component of Azure's identity and access
management framework?
A) Network Security Groups
B) Azure Role-Based Access Control (RBAC)
C) Azure Load Balancer
D) Azure Virtual Network
Correct Answer: B. Azure Role-Based Access Control (RBAC)
Rationale: Azure RBAC is a foundational component of Azure's identity and
access management framework. It manages administrative access to Azure
resources by granting users only the permissions required to perform their tasks.


Question 7
When planning an access control strategy in Azure, which principle should guide
all access assignments?

, A) Grant all users full access for simplicity
B) Grant users the least privilege to get their work done
C) Grant access based on seniority
D) Grant access based on department size
Correct Answer: B. Grant users the least privilege to get their work done
Rationale: The principle of least privilege ensures users receive only the
permissions required to perform their tasks. Avoid assigning broader roles at
broader scopes even if it initially seems more convenient.


Question 8
SWBTL LLC needs to ensure that only authorized personnel can access the Azure
portal. Which of the following should be implemented?
A) Disable all user accounts
B) Enforce MFA and use Conditional Access policies
C) Allow all network traffic
D) Use only shared accounts
Correct Answer: B. Enforce MFA and use Conditional Access policies
Rationale: Requiring MFA for Azure management applies specifically to access
attempts through tools like Azure CLI or the Azure portal. Conditional Access
policies provide the framework for enforcing these requirements dynamically.


Question 9
Which of the following is a best practice for managing Azure AD groups?
A) Create a single group for all users
B) Use groups based on job functions and responsibilities
C) Avoid using groups for role assignments
D) Delete all existing groups
Correct Answer: B. Use groups based on job functions and responsibilities
Rationale: Azure AD groups should be organized based on job functions and
responsibilities to simplify role assignments. This approach ensures that users with

Document information

Uploaded on
July 2, 2026
Number of pages
33
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$34.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
21
Followers
0
Items
2979
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions