Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 38 pages
Exam (elaborations)

WGU C838 Managing Cloud Security – Exam Questions & Answers (Latest 2025 Update, 1000+ Q&A Bank) Document 3: WGU C838 Managing Cloud Security – Exam Questions & Answers

Document preview thumbnail
Preview 4 out of 38 pages

WGU C838 Managing Cloud Security – Exam Questions & Answers (Latest 2025 Update, 1000+ Q&A Bank) Document 3: WGU C838 Managing Cloud Security – Exam Questions & Answers

Content preview

WGU C838 Managing Cloud Security – Exam Questions
& Answers (Latest 2025 Update, 1000+ Q&A Bank)
Document 3: WGU C838 Managing Cloud Security –
Exam Questions & Answers
Instructions: This practice exam contains 150 questions designed to assess your knowledge of cloud
security concepts, including the Shared Responsibility Model, cloud governance, risk management,
compliance, and security controls across IaaS, PaaS, and SaaS. Select the best answer. Answers are
in bold and rationales are in italic.



1. In the Shared Responsibility Model for IaaS, which of the following is the cloud provider's
responsibility?
A) Securing customer data stored in the cloud.
B) Patching the guest operating system.
C) Securing the physical data center and the underlying hypervisor.
D) Managing user access and identity.
Answer: C
Rationale: In the IaaS model, the cloud provider is responsible for the security "of" the cloud, which
includes physical security of data centers, network infrastructure, and the virtualization layer
(hypervisor). The customer is responsible for security "in" the cloud, including data, applications, and
guest OS.



2. What is the primary benefit of implementing a Cloud Access Security Broker (CASB)?
A) It provides encryption for all cloud data at rest.
B) It acts as a bridge between users and multiple cloud services, providing visibility and control.
C) It replaces the need for identity and access management.
D) It serves as a backup solution for cloud data.
Answer: B
Rationale: A CASB sits between an organization's users and the cloud service providers. Its primary
benefit is to provide visibility into cloud application usage and enforce security policies such as
authentication, encryption, and access control across multiple cloud services.



3. Which of the following is a key risk associated with cloud computing?
A) The inability to scale resources on demand.
B) Limited geographic reach.
C) The shared, multi-tenant environment, which can lead to data leakage or "noisy neighbor" issues.
D) The mandatory use of outdated hardware.
Answer: C

,Rationale: One of the significant risks in cloud computing is the shared, multi-tenant environment.
Without proper isolation, there is a risk of one tenant accessing another's data or a "noisy neighbor"
affecting performance. Scalability and geographic reach are benefits of the cloud.



4. Which cloud service model provides the highest level of customer control?
A) Software as a Service (SaaS)
B) Platform as a Service (PaaS)
C) Infrastructure as a Service (IaaS)
D) Function as a Service (FaaS)
Answer: C
Rationale: IaaS gives customers the most control, as they manage the operating systems, middleware,
data, and applications, while the provider manages the underlying hardware and virtualization. PaaS
offers less control (over the platform), and SaaS offers the least control (only the data and user access).



5. What is the purpose of a "Cloud Security Alliance" (CSA) Security Guidance document?
A) To provide a legal framework for cloud contracts.
B) To offer best practices and recommendations for securing cloud environments.
C) To serve as a mandatory compliance standard.
D) To define pricing models for cloud services.
Answer: B
Rationale: The CSA is a leading organization dedicated to promoting best practices for cloud security. Its
Security Guidance document provides comprehensive recommendations, not legal mandates, for
securing cloud environments across different service models.



6. In the context of cloud risk management, what is "Risk Transfer"?
A) Accepting the risk and not taking any action.
B) Reducing the risk by implementing controls.
C) Shifting the risk to a third party, such as through cyber insurance or contractual agreements with a
cloud provider.
D) Eliminating the activity that creates the risk.
Answer: C
Rationale: Risk transfer involves shifting the financial or operational impact of a risk to a third party. This
can be done by purchasing cyber insurance or using contractual agreements (like SLAs) to transfer some
liability to the cloud provider.



7. Which of the following is a primary concern regarding data residency in the cloud?
A) The cloud provider's data center color scheme.
B) The geographic location where the customer's data is stored and processed.
C) The brand of the storage hardware.
D) The programming language used by the cloud provider.

,Answer: B
Rationale: Data residency refers to the physical location of data storage. This is a critical concern
because data is subject to the legal, regulatory, and privacy requirements of the jurisdiction where it is
physically located.



8. What is the responsibility of the customer in the "Shared Responsibility Model" for SaaS?
A) Securing the underlying infrastructure.
B) Patching the operating system.
C) Securing the application itself.
D) Securing their data and managing user access.
Answer: D
Rationale: In the SaaS model, the provider is responsible for virtually everything (infrastructure, platform,
and the application itself). The customer's primary security responsibilities are securing their own data,
managing user identity and access, and configuring application security settings.



9. Which framework is specifically designed to address cloud governance, compliance, and risk
management?
A) COBIT
B) ISO 27001
C) NIST SP 800-53
D) CSA CCM
Answer: D
Rationale: The Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) is a specific framework
designed to provide a structured set of controls that address cloud-specific governance, compliance, and
risk management requirements.



10. What does "Vertical Scaling" in cloud computing refer to?
A) Adding more servers (instances) to handle increased load.
B) Increasing the computing power (CPU, RAM) of an existing server.
C) Distributing traffic across multiple data centers.
D) Moving workloads between different cloud providers.
Answer: B
Rationale: Vertical scaling (scaling up) involves increasing the capacity of a single server by adding more
CPU, memory, or storage. Horizontal scaling (scaling out) involves adding more servers.



11. Which of the following is a control implemented to protect data at rest in a cloud environment?
A) TLS/SSL encryption for data in transit.
B) Encryption of data stored in cloud databases and storage buckets.
C) Data Loss Prevention (DLP) policies.
D) Network Access Control Lists (NACLs).

, Answer: B
Rationale: Data at rest is protected primarily through encryption of the storage volumes, databases, and
file systems. TLS/SSL protects data in transit. DLP and NACLs are important controls but are not
specifically for data at rest encryption.



12. What is the main purpose of a "Service Level Agreement" (SLA) in a cloud context?
A) To define the pricing structure for cloud services.
B) To specify the performance and availability commitments from the cloud provider.
C) To act as a technical document for software development.
D) To outline the customer's security responsibilities.
Answer: B
Rationale: An SLA is a contract between the cloud provider and the customer that defines the level of
service expected, including metrics like uptime availability, performance, and support response times.
Security responsibilities are usually in a separate document or section.



13. In a "Private Cloud" deployment, the computing resources are:
A) Provisioned for exclusive use by a single organization.
B) Provisioned for use by the general public.
C) Shared between multiple organizations with similar interests.
D) Always located off-premises in a third-party data center.
Answer: A
Rationale: A private cloud is a cloud environment that is dedicated to a single organization. It can be
located on-premises or off-premises, and it offers the highest degree of control and privacy.



14. Which of the following is an example of a "Social Engineering" attack specific to cloud adoption?
A) A DDoS attack against the cloud provider.
B) A vulnerability in the cloud provider's API.
C) A phishing campaign targeting employees to steal their cloud credentials.
D) A misconfigured cloud storage bucket exposing data.
Answer: C
Rationale: Social engineering attacks, like phishing, target the human element. In the cloud context,
attackers might use phishing to trick employees into revealing their cloud login credentials or MFA codes.
(A) is a network attack, (B) is a technical vulnerability, and (D) is a misconfiguration.



15. What is the primary purpose of "Identity Federation" in cloud security?
A) To create a single, highly privileged account for all users.
B) To enable users from one organization to access applications and resources in another organization
using a single set of credentials.
C) To simplify the management of user passwords.
D) To provide a backup for user accounts.

Document information

Uploaded on
August 2, 2026
Number of pages
38
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$74.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
TUTORJUNIOUR
3.0
(1)
Sold
2
Followers
0
Items
1292
Last sold
4 weeks ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions