Mastering Cloud Security: A
Comprehensive Implementation
Guide for WGU D485 DGN2 Task 1
Q1: Which cloud service model places the maximum amount of
operational and security responsibility on the customer?
A) Software as a Service (SaaS)
B) Platform as a Service (PaaS)
C) Infrastructure as a Service (IaaS)
D) Database as a Service (DBaaS)
Answer: C) Infrastructure as a Service (IaaS)
Rationale: In an IaaS model, the provider only secures the physical
infrastructure, virtualization layer, and hardware. The customer is
responsible for the operating system, middleware, runtime, data,
applications, and network controls. This gives customers maximum control
but also maximum responsibility .
Q2: Under the shared responsibility model, who is responsible for data
governance and classification in a public cloud environment?
A) The cloud service provider completely
B) The customer completely
C) The third-party auditor
D) Shared equally between provider and customer
Answer: B) The customer completely
,Rationale: Regardless of the cloud deployment model (IaaS, PaaS, or SaaS),
data ownership, governance, and classification always remain the sole
responsibility of the customer. The provider cannot classify or govern
customer data .
Q3: Which deployment model provides exclusive cloud resources to a
single organization but is hosted and managed by a third-party
provider off-premises?
A) Public Cloud
B) Hosted Private Cloud
C) Hybrid Cloud
D) Community Cloud
Answer: B) Hosted Private Cloud
Rationale: A hosted private cloud offers dedicated physical or logical
infrastructure to one specific organization while being physically located
and maintained within a provider's data center. This provides exclusive
resources with third-party management .
Q4: In a Platform as a Service (PaaS) model, which of the following is
typically managed by the cloud service provider?
A) Application code
B) Operating system patching
C) User access credentials
D) Data endpoints
Answer: B) Operating system patching
Rationale: PaaS abstracts the underlying operating system and
infrastructure away from the user, meaning the cloud provider handles OS
,security updates, maintenance, and patching. The customer focuses only on
application code and data .
Q5: What is the primary benefit of deploying workloads in Azure
Government compared to standard Azure commercial regions?
A) Lower subscription and compute costs
B) Dedicated physical isolation and strict US citizen screening requirements
C) Faster deployment of cutting-edge preview features
D) Global geographic availability across all continents
Answer: B) Dedicated physical isolation and strict US citizen screening
requirements
Rationale: Azure Government is physically isolated from commercial Azure
networks and enforces strict background checks on personnel to meet
stringent federal security requirements, including FedRAMP authorization
and DoD Impact Level 5 approval .
Q6: Which cloud security concept emphasizes that an organization
should not trust anything inside or outside its perimeters and must
verify every access request?
A) Defense in Depth
B) Zero Trust Architecture
C) Network Segmentation
D) Perimeter Defense
Answer: B) Zero Trust Architecture
Rationale: Zero Trust Architecture operates on the core principle of "never
trust, always verify," requiring explicit validation for every access attempt
regardless of origin. This includes continuous authentication, micro-
segmentation, least privilege, and monitoring of all traffic .
, Q7: When a customer shifts an application from on-premises to a SaaS
solution, what responsibility transfers entirely to the cloud provider?
A) Application security vulnerabilities and patching
B) Data access management and roles
C) Mobile device management configurations
D) Information asset classification
Answer: A) Application security vulnerabilities and patching
Rationale: In a SaaS model, the provider delivers the entire software stack.
The customer merely consumes the software, meaning application-level
patching and security are handled entirely by the provider .
Q8: Which concept describes the ability of a cloud infrastructure to
dynamically scale security controls and resources up or down based on
demand?
A) High Availability
B) Fault Tolerance
C) Elasticity
D) Redundancy
Answer: C) Elasticity
Rationale: Elasticity allows cloud computing resources to scale dynamically
to match demand, ensuring security appliances or firewalls can scale up to
handle sudden spikes in traffic. This is one of the five essential NIST
characteristics of cloud computing .
Q9: What is a primary security risk associated with "Shadow IT" in an
enterprise cloud environment?
Comprehensive Implementation
Guide for WGU D485 DGN2 Task 1
Q1: Which cloud service model places the maximum amount of
operational and security responsibility on the customer?
A) Software as a Service (SaaS)
B) Platform as a Service (PaaS)
C) Infrastructure as a Service (IaaS)
D) Database as a Service (DBaaS)
Answer: C) Infrastructure as a Service (IaaS)
Rationale: In an IaaS model, the provider only secures the physical
infrastructure, virtualization layer, and hardware. The customer is
responsible for the operating system, middleware, runtime, data,
applications, and network controls. This gives customers maximum control
but also maximum responsibility .
Q2: Under the shared responsibility model, who is responsible for data
governance and classification in a public cloud environment?
A) The cloud service provider completely
B) The customer completely
C) The third-party auditor
D) Shared equally between provider and customer
Answer: B) The customer completely
,Rationale: Regardless of the cloud deployment model (IaaS, PaaS, or SaaS),
data ownership, governance, and classification always remain the sole
responsibility of the customer. The provider cannot classify or govern
customer data .
Q3: Which deployment model provides exclusive cloud resources to a
single organization but is hosted and managed by a third-party
provider off-premises?
A) Public Cloud
B) Hosted Private Cloud
C) Hybrid Cloud
D) Community Cloud
Answer: B) Hosted Private Cloud
Rationale: A hosted private cloud offers dedicated physical or logical
infrastructure to one specific organization while being physically located
and maintained within a provider's data center. This provides exclusive
resources with third-party management .
Q4: In a Platform as a Service (PaaS) model, which of the following is
typically managed by the cloud service provider?
A) Application code
B) Operating system patching
C) User access credentials
D) Data endpoints
Answer: B) Operating system patching
Rationale: PaaS abstracts the underlying operating system and
infrastructure away from the user, meaning the cloud provider handles OS
,security updates, maintenance, and patching. The customer focuses only on
application code and data .
Q5: What is the primary benefit of deploying workloads in Azure
Government compared to standard Azure commercial regions?
A) Lower subscription and compute costs
B) Dedicated physical isolation and strict US citizen screening requirements
C) Faster deployment of cutting-edge preview features
D) Global geographic availability across all continents
Answer: B) Dedicated physical isolation and strict US citizen screening
requirements
Rationale: Azure Government is physically isolated from commercial Azure
networks and enforces strict background checks on personnel to meet
stringent federal security requirements, including FedRAMP authorization
and DoD Impact Level 5 approval .
Q6: Which cloud security concept emphasizes that an organization
should not trust anything inside or outside its perimeters and must
verify every access request?
A) Defense in Depth
B) Zero Trust Architecture
C) Network Segmentation
D) Perimeter Defense
Answer: B) Zero Trust Architecture
Rationale: Zero Trust Architecture operates on the core principle of "never
trust, always verify," requiring explicit validation for every access attempt
regardless of origin. This includes continuous authentication, micro-
segmentation, least privilege, and monitoring of all traffic .
, Q7: When a customer shifts an application from on-premises to a SaaS
solution, what responsibility transfers entirely to the cloud provider?
A) Application security vulnerabilities and patching
B) Data access management and roles
C) Mobile device management configurations
D) Information asset classification
Answer: A) Application security vulnerabilities and patching
Rationale: In a SaaS model, the provider delivers the entire software stack.
The customer merely consumes the software, meaning application-level
patching and security are handled entirely by the provider .
Q8: Which concept describes the ability of a cloud infrastructure to
dynamically scale security controls and resources up or down based on
demand?
A) High Availability
B) Fault Tolerance
C) Elasticity
D) Redundancy
Answer: C) Elasticity
Rationale: Elasticity allows cloud computing resources to scale dynamically
to match demand, ensuring security appliances or firewalls can scale up to
handle sudden spikes in traffic. This is one of the five essential NIST
characteristics of cloud computing .
Q9: What is a primary security risk associated with "Shadow IT" in an
enterprise cloud environment?