WGU E025
Cloud and Network Security Models
PERFORMANCE ASSESSMENT - TASK 2
Security Deployment and Cloud Verification
Executive Deployment Report - Azure Implementation Exemplar
Student Name [Insert Name]
Student ID [Insert ID]
Submission Date August 7, 2026
Organization MedCore Health Services
Cloud Platform Microsoft Azure (assumed)
Evidence status: This report contains complete configuration guidance and evidence specifications, but it is not
submission-ready until the three evidence placeholders are replaced by the student's own unaltered lab
screenshots. No evaluator outcome can be guaranteed.
, Executive Summary
This Executive Deployment Report documents an Azure security configuration for MedCore Health Services built around
three administrative outcomes: least-privilege access through group-based Azure RBAC, centralized cryptographic control
through Azure Key Vault and customer-managed keys, and automated recovery through Azure Backup. The configuration
supports the hybrid security architecture proposed in Task 1 while producing auditable evidence for identity, encryption, and
continuity controls.
The representative deployment uses resource groups to constrain scope, Microsoft Entra security groups to represent job
functions, Azure RBAC to separate management-plane and data-plane permissions, a production Key Vault with Azure
RBAC authorization, soft delete and purge protection, and a Recovery Services vault configured for geo-redundant backup.
All names, schedules, roles, and recovery objectives must be reconciled with the current WGU lab scenario before
submission.
Deployment Assumptions and Naming Standard
Item Representative value Reason
Subscription WGU Lab Subscription Use the subscription issued in the lab
Primary region East US 2 Replace with assigned/approved region
Security resource group rg-medcore-security-prod Separates security control-plane resources
Production workload rg-medcore-clinical-prod Limits role scope to clinical workloads
group
Key Vault kv-medcore-prod-[unique] Vault names must be globally unique
Recovery Services vault rsv-medcore-prod Central backup policy and protected items
Evidence timestamp Visible desktop clock/date Supports lab-evidence traceability
Predeployment Control Gates
• Confirm the exact users, departments, auditor role, target resources, backup time, retention duration, and region in the
official scenario.
• Use only the assigned lab tenant and subscription. Do not configure a personal or production tenant for this assessment.
• Record the original state before making changes and retain an activity log or deployment history.
• Never place passwords, secret values, recovery codes, tokens, connection strings, or patient information in screenshots.
• Capture evidence only after validation succeeds; keep the whole desktop visible if the rubric requires system clock, date,
and taskbar.
Cloud and Network Security Models
PERFORMANCE ASSESSMENT - TASK 2
Security Deployment and Cloud Verification
Executive Deployment Report - Azure Implementation Exemplar
Student Name [Insert Name]
Student ID [Insert ID]
Submission Date August 7, 2026
Organization MedCore Health Services
Cloud Platform Microsoft Azure (assumed)
Evidence status: This report contains complete configuration guidance and evidence specifications, but it is not
submission-ready until the three evidence placeholders are replaced by the student's own unaltered lab
screenshots. No evaluator outcome can be guaranteed.
, Executive Summary
This Executive Deployment Report documents an Azure security configuration for MedCore Health Services built around
three administrative outcomes: least-privilege access through group-based Azure RBAC, centralized cryptographic control
through Azure Key Vault and customer-managed keys, and automated recovery through Azure Backup. The configuration
supports the hybrid security architecture proposed in Task 1 while producing auditable evidence for identity, encryption, and
continuity controls.
The representative deployment uses resource groups to constrain scope, Microsoft Entra security groups to represent job
functions, Azure RBAC to separate management-plane and data-plane permissions, a production Key Vault with Azure
RBAC authorization, soft delete and purge protection, and a Recovery Services vault configured for geo-redundant backup.
All names, schedules, roles, and recovery objectives must be reconciled with the current WGU lab scenario before
submission.
Deployment Assumptions and Naming Standard
Item Representative value Reason
Subscription WGU Lab Subscription Use the subscription issued in the lab
Primary region East US 2 Replace with assigned/approved region
Security resource group rg-medcore-security-prod Separates security control-plane resources
Production workload rg-medcore-clinical-prod Limits role scope to clinical workloads
group
Key Vault kv-medcore-prod-[unique] Vault names must be globally unique
Recovery Services vault rsv-medcore-prod Central backup policy and protected items
Evidence timestamp Visible desktop clock/date Supports lab-evidence traceability
Predeployment Control Gates
• Confirm the exact users, departments, auditor role, target resources, backup time, retention duration, and region in the
official scenario.
• Use only the assigned lab tenant and subscription. Do not configure a personal or production tenant for this assessment.
• Record the original state before making changes and retain an activity log or deployment history.
• Never place passwords, secret values, recovery codes, tokens, connection strings, or patient information in screenshots.
• Capture evidence only after validation succeeds; keep the whole desktop visible if the rubric requires system clock, date,
and taskbar.