WGU D320 MANAGING CLOUD SECURITY OA EXAM PRACTICE | STUDY GUIDE |
COMPREHENSIVE TESTBANK | PRACTICE QUESTIONS & ANSWERS | LATEST UPDATE
2026/2027
I. Cloud Security Architecture and Shared Responsibility
II. Cloud Identity and Access Management (IAM)
III. Risk Management and Security Governance
IV. Cloud Threats, Vulnerabilities, and Incident Response
V. Data Protection, Encryption, and Key Management
VI. Compliance, Privacy, and Security Controls
VII. Security Monitoring, Logging, and Continuous Improvement
INTRODUCTION
This comprehensive WGU D320 Managing Cloud Security practice examination focuses
on advanced concepts in cloud IAM, risk management, shared responsibility,
governance, data protection, compliance, monitoring, and security architecture. The
questions are designed for the level of analysis expected in an objective assessment
(OA), emphasizing scenario-based decision-making rather than simple memorization.
Students should expect realistic cloud-security situations requiring evaluation of control
effectiveness, responsibility boundaries, access models, risk treatment, security policies,
and incident-response decisions. The practice set also tests the ability to distinguish
preventive, detective, and corrective controls and to apply security principles such as
least privilege, defense in depth, zero trust, separation of duties, and continuous
monitoring.
QUESTION 1
A company migrates its customer-facing application to a public cloud provider using
managed virtual machines. The cloud provider secures the physical data centers,
hypervisor, and underlying networking infrastructure. The company's security team
remains responsible for configuring operating-system security, application controls,
identity permissions, and data protection. Which concept BEST explains this
arrangement?
A. Complete outsourcing of security responsibility to the cloud provider
B. Shared responsibility for cloud security
C. Customer responsibility for all physical infrastructure
D. Provider responsibility for all guest operating-system controls
,🔴 Correct Answer: B. Shared responsibility for cloud security.
🔵 Explanation: In a shared-responsibility model, the provider secures infrastructure and
services within its control while the customer remains responsible for security
configurations and workloads that it controls. The exact boundary varies by cloud service
model.
QUESTION 2
A cloud administrator grants a developer permission to read and modify every storage
bucket in an organization's cloud environment because the developer occasionally
needs access to production data. Which security principle is MOST directly violated?
A. Availability
B. Least privilege
C. Nonrepudiation
D. Fault tolerance
🔴 Correct Answer: B. Least privilege.
🔵 Explanation: Least privilege requires users and workloads to receive only the
permissions necessary to perform authorized tasks. Broad access to unrelated production
resources unnecessarily increases the potential impact of credential compromise or
misuse.
QUESTION 3
A security architect wants administrators to authenticate using a centralized identity
provider and requires a second authentication factor before privileged cloud
operations can be performed. Which combination BEST strengthens the organization's
identity security?
A. Password-only authentication and shared administrator accounts
B. Multi-factor authentication and centralized identity federation
C. Static API keys distributed through email
D. Anonymous access combined with network segmentation
🔴 Correct Answer: B. Multi-factor authentication and centralized identity
federation.
🔵 Explanation: Federation centralizes identity management while MFA adds an
additional authentication factor, reducing dependence on passwords alone. Together,
,these controls significantly strengthen authentication and administrative access
governance.
QUESTION 4
A company uses a cloud-based application service. The provider manages the
application runtime and operating system, while the customer configures users, access
permissions, and the data stored in the application. A vulnerability is discovered in the
provider-managed operating system. Who would generally be responsible for
remediating that vulnerability?
A. The customer
B. The customer's application users
C. The cloud provider
D. The customer's network administrator
🔴 Correct Answer: C. The cloud provider.
🔵 Explanation: Under a managed application service model, the provider generally
assumes responsibility for the underlying platform and operating system. The customer
remains responsible for customer-controlled configurations, identities, and data.
QUESTION 5
During a risk assessment, an organization identifies a cloud database vulnerability with
a high likelihood of exploitation and severe potential business impact. Management
decides to redesign the application so the vulnerable database is no longer required.
Which risk treatment strategy is being used?
A. Risk acceptance
B. Risk transfer
C. Risk avoidance
D. Risk monitoring
🔴 Correct Answer: C. Risk avoidance.
🔵 Explanation: Risk avoidance eliminates the activity, technology, or condition that
creates the unacceptable risk. Redesigning the application to remove dependence on the
vulnerable database removes the underlying exposure rather than merely reducing or
transferring it.
QUESTION 6
, A cloud security engineer discovers that an employee's identity has permissions to
access resources belonging to several unrelated business units. The employee's job role
changed six months ago, but the old permissions were never removed. What control
would MOST directly address this problem?
A. Periodic access review and privilege recertification
B. Increasing password complexity
C. Expanding network bandwidth
D. Disabling encryption at rest
🔴 Correct Answer: A. Periodic access review and privilege recertification.
🔵 Explanation: Access reviews identify excessive, outdated, or inappropriate permissions
and allow resource owners or managers to recertify or revoke them. This is particularly
important after role changes.
QUESTION 7
An organization wants cloud users to access multiple approved applications using their
existing corporate credentials without maintaining separate passwords for every
application. Which technology BEST supports this requirement?
A. Identity federation
B. Data deduplication
C. Network address translation
D. Disk partitioning
🔴 Correct Answer: A. Identity federation.
🔵 Explanation: Identity federation allows an identity provider to authenticate users and
establish trusted relationships with other services. This enables centralized authentication
and reduces the need for separate credentials across applications.
QUESTION 8
A company discovers that a cloud storage resource was accidentally configured for
public access. No evidence indicates that the data was downloaded, but sensitive
information was exposed to an unauthorized audience for several hours. How should
the security team BEST classify this event?
A. It is irrelevant because no confirmed theft occurred
B. It represents a confidentiality exposure requiring investigation
COMPREHENSIVE TESTBANK | PRACTICE QUESTIONS & ANSWERS | LATEST UPDATE
2026/2027
I. Cloud Security Architecture and Shared Responsibility
II. Cloud Identity and Access Management (IAM)
III. Risk Management and Security Governance
IV. Cloud Threats, Vulnerabilities, and Incident Response
V. Data Protection, Encryption, and Key Management
VI. Compliance, Privacy, and Security Controls
VII. Security Monitoring, Logging, and Continuous Improvement
INTRODUCTION
This comprehensive WGU D320 Managing Cloud Security practice examination focuses
on advanced concepts in cloud IAM, risk management, shared responsibility,
governance, data protection, compliance, monitoring, and security architecture. The
questions are designed for the level of analysis expected in an objective assessment
(OA), emphasizing scenario-based decision-making rather than simple memorization.
Students should expect realistic cloud-security situations requiring evaluation of control
effectiveness, responsibility boundaries, access models, risk treatment, security policies,
and incident-response decisions. The practice set also tests the ability to distinguish
preventive, detective, and corrective controls and to apply security principles such as
least privilege, defense in depth, zero trust, separation of duties, and continuous
monitoring.
QUESTION 1
A company migrates its customer-facing application to a public cloud provider using
managed virtual machines. The cloud provider secures the physical data centers,
hypervisor, and underlying networking infrastructure. The company's security team
remains responsible for configuring operating-system security, application controls,
identity permissions, and data protection. Which concept BEST explains this
arrangement?
A. Complete outsourcing of security responsibility to the cloud provider
B. Shared responsibility for cloud security
C. Customer responsibility for all physical infrastructure
D. Provider responsibility for all guest operating-system controls
,🔴 Correct Answer: B. Shared responsibility for cloud security.
🔵 Explanation: In a shared-responsibility model, the provider secures infrastructure and
services within its control while the customer remains responsible for security
configurations and workloads that it controls. The exact boundary varies by cloud service
model.
QUESTION 2
A cloud administrator grants a developer permission to read and modify every storage
bucket in an organization's cloud environment because the developer occasionally
needs access to production data. Which security principle is MOST directly violated?
A. Availability
B. Least privilege
C. Nonrepudiation
D. Fault tolerance
🔴 Correct Answer: B. Least privilege.
🔵 Explanation: Least privilege requires users and workloads to receive only the
permissions necessary to perform authorized tasks. Broad access to unrelated production
resources unnecessarily increases the potential impact of credential compromise or
misuse.
QUESTION 3
A security architect wants administrators to authenticate using a centralized identity
provider and requires a second authentication factor before privileged cloud
operations can be performed. Which combination BEST strengthens the organization's
identity security?
A. Password-only authentication and shared administrator accounts
B. Multi-factor authentication and centralized identity federation
C. Static API keys distributed through email
D. Anonymous access combined with network segmentation
🔴 Correct Answer: B. Multi-factor authentication and centralized identity
federation.
🔵 Explanation: Federation centralizes identity management while MFA adds an
additional authentication factor, reducing dependence on passwords alone. Together,
,these controls significantly strengthen authentication and administrative access
governance.
QUESTION 4
A company uses a cloud-based application service. The provider manages the
application runtime and operating system, while the customer configures users, access
permissions, and the data stored in the application. A vulnerability is discovered in the
provider-managed operating system. Who would generally be responsible for
remediating that vulnerability?
A. The customer
B. The customer's application users
C. The cloud provider
D. The customer's network administrator
🔴 Correct Answer: C. The cloud provider.
🔵 Explanation: Under a managed application service model, the provider generally
assumes responsibility for the underlying platform and operating system. The customer
remains responsible for customer-controlled configurations, identities, and data.
QUESTION 5
During a risk assessment, an organization identifies a cloud database vulnerability with
a high likelihood of exploitation and severe potential business impact. Management
decides to redesign the application so the vulnerable database is no longer required.
Which risk treatment strategy is being used?
A. Risk acceptance
B. Risk transfer
C. Risk avoidance
D. Risk monitoring
🔴 Correct Answer: C. Risk avoidance.
🔵 Explanation: Risk avoidance eliminates the activity, technology, or condition that
creates the unacceptable risk. Redesigning the application to remove dependence on the
vulnerable database removes the underlying exposure rather than merely reducing or
transferring it.
QUESTION 6
, A cloud security engineer discovers that an employee's identity has permissions to
access resources belonging to several unrelated business units. The employee's job role
changed six months ago, but the old permissions were never removed. What control
would MOST directly address this problem?
A. Periodic access review and privilege recertification
B. Increasing password complexity
C. Expanding network bandwidth
D. Disabling encryption at rest
🔴 Correct Answer: A. Periodic access review and privilege recertification.
🔵 Explanation: Access reviews identify excessive, outdated, or inappropriate permissions
and allow resource owners or managers to recertify or revoke them. This is particularly
important after role changes.
QUESTION 7
An organization wants cloud users to access multiple approved applications using their
existing corporate credentials without maintaining separate passwords for every
application. Which technology BEST supports this requirement?
A. Identity federation
B. Data deduplication
C. Network address translation
D. Disk partitioning
🔴 Correct Answer: A. Identity federation.
🔵 Explanation: Identity federation allows an identity provider to authenticate users and
establish trusted relationships with other services. This enables centralized authentication
and reduces the need for separate credentials across applications.
QUESTION 8
A company discovers that a cloud storage resource was accidentally configured for
public access. No evidence indicates that the data was downloaded, but sensitive
information was exposed to an unauthorized audience for several hours. How should
the security team BEST classify this event?
A. It is irrelevant because no confirmed theft occurred
B. It represents a confidentiality exposure requiring investigation