WGU D320 - Managing Cloud Security Exam Prep Test Bank
WGU D320 - MANAGING CLOUD SECURITY EXAM PREP TEST BANK
NEWEST 2026/2027 ACTUAL EXAM COMPLETE 700 QUESTIONS AND
CORRECT DETAILED ANSWERS (VERIFIED ANSWERS) |ALREADY
GRADED A+||BRAND NEW VERSION!!
Yasine's organization wants to enable systems to use data controlled by an IRM.
What method is most commonly used to identify systems while allowing them to
have their trust revoked if needed?
A. LEAP authentication
B. Multifactor authentication
C. Certificate-based authentication and authorization
D. TACACS
C
Meena is conducting data discovery with data encoded in JSON. What type of data
is she working with?
A. Structured
B. Semi-structured
C. Super-structured
D. Unstructured
B
Isaac wants to describe common information rights management (IRM) functions
to his team. Which of the following is not a common IRM function?
A. Persistency
B. Crypto-shredding
1|Page
, WGU D320 - Managing Cloud Security Exam Prep Test Bank
C. Automatic expiration
D. Dynamic policy control
B
Which technique is used to obscure data in the cloud?
A) Shuffling
B) Anonymization
C) Disassembling
D) Expunging
B
Naomi is working on a list that will include data obfuscation options for her
organization. Which of the following is not a type of data obfuscation technique?
A. Tokenization
B. Data hiding
C. Anonymization
D. Masking
B
The goals of SIEM solution implementations include all of the following except:
A. Centralization of log streams
B. Trend analysis
C. Dashboarding
D. Performance enhancement
D
Wei's organization uses Lambda functions as part of a serverless application inside
of its Amazon-hosted environment. What storage type should Wei consider the
storage associated with the instances to be?
2|Page
, WGU D320 - Managing Cloud Security Exam Prep Test Bank
A. Long-term
B. Medium term
C. Ephemeral
D. Instantaneous
C
Selah wants to securely store her organization's encryption keys. What solution
should she ask her cloud service provider about?
A. A PKI
B. A DLP
C. A cloud HSM
D. A CRL
C
Jim's organization wants to ensure that it has the right information available in
case of an attack against its web server. Which of the following data elements is
not commonly used and thus shouldn't be expected to be logged?
A. The version of the executable run
B. The service name
C. The source IP address of the traffic
D. The destination IP address of the traffic
A
Susan wants to ensure that files containing credit card numbers are not stored in
her organization's cloud-based file storage. If she deploys a DLP system, what
method should she use to identify files with credit card numbers to have the best
chance of finding them, even if she may encounter some false positives?
A. Manually tag files with credit card numbers at creation.
B. Require users to save files containing credit card numbers with specific file-
naming conventions.
3|Page
, WGU D320 - Managing Cloud Security Exam Prep Test Bank
C. Scan for credit card numbers based on a pattern match or algorithm.
D. Tag files with credit card numbers at destruction.
C
Rhonda is outlining the threats to her cloud storage environment. Which of the
following is not a common threat to cloud storage?
A. Credential theft or compromise
B. Infection with malware or ransomware
C. Privilege reuse
D. Human error
C
Ben wants to implement tokenization for his organization's data. What will he
need to be able to implement it?
A. Authentication factors
B. Databases
C. Encryption keys
D. Personnel
B
Yasmine's organization has identified data masking as a key security control.
Which of the following functions will it provide?
A. Secure remote access
B. Enforcing least privilege
C. Testing data in sandboxed environments
D. Authentication of privileged users
C
Megan wants to improve the controls provided by her organization's data loss
prevention (DLP) tool. What additional tool can be combined with her DLP to most
4|Page
WGU D320 - MANAGING CLOUD SECURITY EXAM PREP TEST BANK
NEWEST 2026/2027 ACTUAL EXAM COMPLETE 700 QUESTIONS AND
CORRECT DETAILED ANSWERS (VERIFIED ANSWERS) |ALREADY
GRADED A+||BRAND NEW VERSION!!
Yasine's organization wants to enable systems to use data controlled by an IRM.
What method is most commonly used to identify systems while allowing them to
have their trust revoked if needed?
A. LEAP authentication
B. Multifactor authentication
C. Certificate-based authentication and authorization
D. TACACS
C
Meena is conducting data discovery with data encoded in JSON. What type of data
is she working with?
A. Structured
B. Semi-structured
C. Super-structured
D. Unstructured
B
Isaac wants to describe common information rights management (IRM) functions
to his team. Which of the following is not a common IRM function?
A. Persistency
B. Crypto-shredding
1|Page
, WGU D320 - Managing Cloud Security Exam Prep Test Bank
C. Automatic expiration
D. Dynamic policy control
B
Which technique is used to obscure data in the cloud?
A) Shuffling
B) Anonymization
C) Disassembling
D) Expunging
B
Naomi is working on a list that will include data obfuscation options for her
organization. Which of the following is not a type of data obfuscation technique?
A. Tokenization
B. Data hiding
C. Anonymization
D. Masking
B
The goals of SIEM solution implementations include all of the following except:
A. Centralization of log streams
B. Trend analysis
C. Dashboarding
D. Performance enhancement
D
Wei's organization uses Lambda functions as part of a serverless application inside
of its Amazon-hosted environment. What storage type should Wei consider the
storage associated with the instances to be?
2|Page
, WGU D320 - Managing Cloud Security Exam Prep Test Bank
A. Long-term
B. Medium term
C. Ephemeral
D. Instantaneous
C
Selah wants to securely store her organization's encryption keys. What solution
should she ask her cloud service provider about?
A. A PKI
B. A DLP
C. A cloud HSM
D. A CRL
C
Jim's organization wants to ensure that it has the right information available in
case of an attack against its web server. Which of the following data elements is
not commonly used and thus shouldn't be expected to be logged?
A. The version of the executable run
B. The service name
C. The source IP address of the traffic
D. The destination IP address of the traffic
A
Susan wants to ensure that files containing credit card numbers are not stored in
her organization's cloud-based file storage. If she deploys a DLP system, what
method should she use to identify files with credit card numbers to have the best
chance of finding them, even if she may encounter some false positives?
A. Manually tag files with credit card numbers at creation.
B. Require users to save files containing credit card numbers with specific file-
naming conventions.
3|Page
, WGU D320 - Managing Cloud Security Exam Prep Test Bank
C. Scan for credit card numbers based on a pattern match or algorithm.
D. Tag files with credit card numbers at destruction.
C
Rhonda is outlining the threats to her cloud storage environment. Which of the
following is not a common threat to cloud storage?
A. Credential theft or compromise
B. Infection with malware or ransomware
C. Privilege reuse
D. Human error
C
Ben wants to implement tokenization for his organization's data. What will he
need to be able to implement it?
A. Authentication factors
B. Databases
C. Encryption keys
D. Personnel
B
Yasmine's organization has identified data masking as a key security control.
Which of the following functions will it provide?
A. Secure remote access
B. Enforcing least privilege
C. Testing data in sandboxed environments
D. Authentication of privileged users
C
Megan wants to improve the controls provided by her organization's data loss
prevention (DLP) tool. What additional tool can be combined with her DLP to most
4|Page