WGU D320 – Managing Cloud Security (2026) | Verified CCSP Exam Prep
Questions & Complete Study Guide
Study online at https://quizlet.com/_jm6a6x
1. Who is ultimately legally li- Cloud Customers are legally responsible for what?
able for any loss of data
even in the case of negli-
gence or malice?
2. This is considered an asset? Data is considered what?
3. What are the phases of the What process do these ordered steps constitute?
Data Life Cycle?
1. Create
2. Store
3. Use
4. Share
5. Archive
6. Destroy
4. Who is responsible for data What is the primary responsibility of the Data Owner
Categorization and Classifi-
cation during the Creation
Phase?
5. What is the preferred up- What are IPSec and TLS 1.2 (or higher version) VPNs used for?
load method to the Cloud
during the Store Phase?
6. What is the recommended Do not store crypto keys with the cloud provider whether or not
"Don't" of crypto key stor- the cloud customer chooses to use a CASB.
age?
7. What do Regulators do? Who arranges Cloud Services?
8. What is one of the main methods of addressing risks?
, WGU D320 – Managing Cloud Security (2026) | Verified CCSP Exam Prep
Questions & Complete Study Guide
Study online at https://quizlet.com/_jm6a6x
What is the role of Transfer-
ence in addressing risks?
9. what does Critique fall un- What is the "fair-use" exception for copyrighted material?
der for copyrighted materi-
al?
10. What is Anonymization in What is the technique used to obscure data stored in the cloud?
terms of cloud storage?
11. What 3 risks are associated What Cloud Service Model is associated with the following risks?
with IaaS (Infrastructure as
a Service)? 1. Personnel Threats
2. External Threats
3. Lack of Specific Skillsets
12. What 4 risks are associated What Cloud Service Model is associated with the following risks?
with PaaS (Platform as a Ser-
vice)? 1. Interoperability Issues
2. Persistent Backdoors
3. Virtualization
4. Resource Sharing
13. What 3 risks are associated What Cloud Service Model is associated with the following risks?
with SaaS (Software as a Ser-
vice)? 1. Proprietary Formats
2. Virtualization
3. Web Application Security
14. What kind of concern do What is a potential emergent business impact analysis (BIA)
New Dependencies intro- Concern?
duce?
, WGU D320 – Managing Cloud Security (2026) | Verified CCSP Exam Prep
Questions & Complete Study Guide
Study online at https://quizlet.com/_jm6a6x
15. What are the three kinds of What are these forms of?
Audits?
1. Internal
2. External
3. Audit Preparation
16. Who performs Internal Au- What kind of audit is performed by employees of the organiza-
dits? tion?
17. Who performs External Au- What kind of audit is performed by individuals outside of the
dits? organization?
18. What is Audit Preparation? What discusses and negotiates parameters of an audit prior to its
start?
19. What are the type of SOC Re- What are the following items types of?
ports?
1. SOC 1
2. SOC 2
3. SOC 3
20. What is the SOC 1 Report What report type is strictly for auditing the financial reporting
used for? instruments of a corporation?
21. What is the SOC 2 Report Whis report type is intended to report audits of any controls
used for? on an organization's security, availability, processing integrity,
confidentiality, and privacy? It includes two sub-types.
22. What is SOC 2 Type 1? What report reviews the design of controls, not how they are
implemented or maintained?
23. What is SOC 2 Type 2? What report is used for getting a true Assessment of an organi-
zation's security posture?
Questions & Complete Study Guide
Study online at https://quizlet.com/_jm6a6x
1. Who is ultimately legally li- Cloud Customers are legally responsible for what?
able for any loss of data
even in the case of negli-
gence or malice?
2. This is considered an asset? Data is considered what?
3. What are the phases of the What process do these ordered steps constitute?
Data Life Cycle?
1. Create
2. Store
3. Use
4. Share
5. Archive
6. Destroy
4. Who is responsible for data What is the primary responsibility of the Data Owner
Categorization and Classifi-
cation during the Creation
Phase?
5. What is the preferred up- What are IPSec and TLS 1.2 (or higher version) VPNs used for?
load method to the Cloud
during the Store Phase?
6. What is the recommended Do not store crypto keys with the cloud provider whether or not
"Don't" of crypto key stor- the cloud customer chooses to use a CASB.
age?
7. What do Regulators do? Who arranges Cloud Services?
8. What is one of the main methods of addressing risks?
, WGU D320 – Managing Cloud Security (2026) | Verified CCSP Exam Prep
Questions & Complete Study Guide
Study online at https://quizlet.com/_jm6a6x
What is the role of Transfer-
ence in addressing risks?
9. what does Critique fall un- What is the "fair-use" exception for copyrighted material?
der for copyrighted materi-
al?
10. What is Anonymization in What is the technique used to obscure data stored in the cloud?
terms of cloud storage?
11. What 3 risks are associated What Cloud Service Model is associated with the following risks?
with IaaS (Infrastructure as
a Service)? 1. Personnel Threats
2. External Threats
3. Lack of Specific Skillsets
12. What 4 risks are associated What Cloud Service Model is associated with the following risks?
with PaaS (Platform as a Ser-
vice)? 1. Interoperability Issues
2. Persistent Backdoors
3. Virtualization
4. Resource Sharing
13. What 3 risks are associated What Cloud Service Model is associated with the following risks?
with SaaS (Software as a Ser-
vice)? 1. Proprietary Formats
2. Virtualization
3. Web Application Security
14. What kind of concern do What is a potential emergent business impact analysis (BIA)
New Dependencies intro- Concern?
duce?
, WGU D320 – Managing Cloud Security (2026) | Verified CCSP Exam Prep
Questions & Complete Study Guide
Study online at https://quizlet.com/_jm6a6x
15. What are the three kinds of What are these forms of?
Audits?
1. Internal
2. External
3. Audit Preparation
16. Who performs Internal Au- What kind of audit is performed by employees of the organiza-
dits? tion?
17. Who performs External Au- What kind of audit is performed by individuals outside of the
dits? organization?
18. What is Audit Preparation? What discusses and negotiates parameters of an audit prior to its
start?
19. What are the type of SOC Re- What are the following items types of?
ports?
1. SOC 1
2. SOC 2
3. SOC 3
20. What is the SOC 1 Report What report type is strictly for auditing the financial reporting
used for? instruments of a corporation?
21. What is the SOC 2 Report Whis report type is intended to report audits of any controls
used for? on an organization's security, availability, processing integrity,
confidentiality, and privacy? It includes two sub-types.
22. What is SOC 2 Type 1? What report reviews the design of controls, not how they are
implemented or maintained?
23. What is SOC 2 Type 2? What report is used for getting a true Assessment of an organi-
zation's security posture?