Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 63 pages
Exam (elaborations)

WGU C838 Managing Cloud Security – 200+ Q&A with Correct Answers | 2026/2027 | Rated A

Document preview thumbnail
Preview 4 out of 63 pages

WGU C838 Managing Cloud Security – 200+ Q&A with Correct Answers | 2026/2027 | Rated A Course: C838 – Managing Cloud Security Institution: Western Governors University (WGU) Level: Master's Degree Year: 2026/2027 Format: Digital Download (PDF/DOCX) Topics Covered: Cloud Computing Fundamentals: 4 characteristics of cloud computing (Broad network access, On-demand services, Resource pooling, Measured service), NIST 800-145, ISO/IEC 17788, Cloud bursting, Elasticity, Scalability, Simplicity, Cloud customer vs cloud user Cloud Service Models: IaaS, PaaS, SaaS – boundaries, responsibilities, examples Cloud Deployment Models: Public, Private, Community, Hybrid – ownership, usage, characteristics Cloud Security Concepts: CSA, CASB, regulators, CIA triad (Confidentiality, Integrity, Availability), Cloud architect, PaaS, FIPS 140-2, Vendor lock-in, Vendor lock-out, Cloud migration, Cloud portability, Encryption, BIA, Criticality, Risk appetite, Layered defense Risk Management: Avoidance, Acceptance, Transference, Mitigation, Risk appetite, BIA, Criticality, Assets (tangible/intangible/personnel) Data Lifecycle & Classification: Data owner, Data custodian, Data mining, 6 stages (Create, Store, Use, Share, Archive, Delete), Classification methods (regulatory compliance, business function, functional unit, by project), Discovery methods (label-based, metadata-based, content-based, data analytics) Intellectual Property & Legal: Copyright, Trademark, Patent, Trade secrets, DMCA, GLBA, SOX, HIPAA, FERPA, GDPR, EU Data Protection Directive (7 principles), PIPEDA, eDiscovery, ISO/IEC 27050-1 IAM & Federation: Identity and Access Management, Authentication, Authorization, Policy management, Federation, Identity repositories, Directory services (X.500, LDAP, Active Directory), SAML, OAuth, OpenID Connect, WS-Federation Threat Modeling: STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of privilege), SAST, DAST, White box testing, Black box testing, OWASP Top 10, XSS, SQL Injection, CSRF Encryption & Data Protection: Tokenization, Data masking, Hashing, Shuffling, Randomization, Nulls, Key recovery, Block storage, Volume storage, Object-based storage, Content Delivery Network, Database encryption (file-level, transparent, application-level), Whole-instance encryption, Volume encryption, TLS, SSL Monitoring & Logging: SIEM (Security Information and Event Management), DLP (Data Loss Prevention), DAM (Database Activity Monitoring), Real-user monitoring (RUM), Synthetic performance monitoring, CASB, Packet capture files, Debug messages SDLC & Secure Development: 4 phases (Define, Design, Develop, Test), ISO/IEC 27034-1, ONF, ANF, APSM, Secure code reviews, Runtime application self-protection, Approved APIs Datacenter & Infrastructure: Uptime Institute tiers (1-4), Power conditioning, Personnel redundancy, Clustering (tightly coupled, loosely coupled), Storage options (volume, object), Secure KVM, Maintenance processes (upgrade, update, date, implementation), Baseline, Change management (CMB meetings, testing, deployment, documentation) BCDR & Disaster Recovery: MAD (Maximum Allowable Downtime), RTO (Recovery Time Objective), RPO (Recovery Point Objective), Tabletop testing, Dry run, Full test, Joint operating agreements, Checklists Regulatory Compliance & Auditing: SOC 1, SOC 2 (Type 1, Type 2), SOC 3, SSAE 16, SAS 70, GAAP, PCI DSS, GLBA, SOX, HIPAA, FERPA, GDPR, EU Data Protection Directive (Notice, Choice, Purpose, Access, Integrity, Security, Enforcement), PIPEDA, ISO/IEC standards (27037:2012, 27041:2015, 27042:2015, 27043:2015, 27050-1:2016, 27018:2014, 27017, 31000:2009, 15408-1:2009, 28000:2007) CSA STAR Program: 3 levels (Self-assessment, Attestation, Continuous monitoring), CCM (Cloud Controls Matrix), CAIQ (Consensus Assessments Initiative Questionnaire) Risk Management Frameworks: ISO 31000:2009, NIST SP 800-37, ENISA, ENISA Top 8 risks Forensics & Incident Response: ISO/IEC 27050-1, ISO/IEC 27043:2015, eDiscovery, Forensic analysis, Competent authorities, Information Commissioner Supply Chain Risks: Financial instability, Single points of failure, Data breaches, Malware infestations, Data loss Personnel Controls: Background checks, Continuing monitoring, Cross-training, Separation of duties, Mandatory vacation, Least privilege Cloud Security Controls: Layered defense, Personnel controls, Technological controls, Physical controls, Governance mechanisms, Hardening, Strong authentication, VPN Includes: 200+ questions with correct answers. Perfect for: WGU C838 Managing Cloud Security final exam (OA), cloud security certification prep, and IT/cybersecurity courses.

Content preview

WGU C838
MANAGING CLOUD SECURITY

200+ Questions & Answers
with Correct Answers

★ 2026/2027 UPDATE ★
RATED A


Course: C838 – Managing Cloud Security
Institution: Western Governors University (WGU)
Level: Master's Degree
Year: 2026/2027




� TOPICS COVERED

✅Cloud Computing Fundamentals
✅Cloud Service Models (IaaS, PaaS, SaaS)
✅Cloud Deployment Models
✅IAM & Federation (SAML, OAuth, LDAP)
✅Threat Modeling (STRIDE, SAST, DAST)
✅Data Lifecycle & Classification
✅Encryption & Data Protection
✅Monitoring & Logging (SIEM, DLP, DAM)
✅Risk Management (ISO 31000, NIST)
✅BCDR & Disaster Recovery (RTO, RPO)
✅Regulatory Compliance (GDPR, HIPAA, SOX)
✅eDiscovery & Forensics
✅CSA STAR Program (CCM, CAIQ)
✅Intellectual Property (Copyright, Patents)
✅SDLC & Secure Development (ISO 27034)
✅Cloud Architecture & Infrastructure


✅200+ Questions with Correct Answers
✅Perfect for WGU C838 Final Exam OA




WGU C838 Managing Cloud Security – 200+ Questions &
Answers with Correct Answers (2026/2027 Updated) |
Rated A

,What are the 4 characteristics of cloud computing? ✔✔Broad network access

On-demand services

Resource Pooling

Measured or "metered" service




What NIST publication number defines cloud computing? ✔✔800-145




What ISO/IEC standard provides information on cloud computing? ✔✔17788




What is another way of describing a functional business requirement? ✔✔necessary




What is another way of describing a nonfunctional business requirement? ✔✔not necessary




What is the greatest driver pushing orgs to the cloud? ✔✔Cost savings




What is cloud bursting? ✔✔Ability to increase available cloud resources on demand




What are 3 characteristics of cloud computing? ✔✔Elasticity

Simplicity

,Scalability




What is a cloud customer? ✔✔Anyone purchasing cloud services




What is a cloud user? ✔✔Anyone using cloud services




What are the three cloud computing service models? ✔✔SaaS(Software as a service)

PaaS(Platform as a service)

IaaS(Infrastructure as a service)




What is IaaS (Infrastructure as a Service)? ✔✔Cloud provider provides all the physical capability
and administration, while the customer is responsible for logical resources.




What is PaaS (Platform as a Service)? ✔✔A cloud computing service that provides the hardware
and the operating system and is responsible for updating and maintaining both.




What is SaaS (Software As A Service)? ✔✔Cloud provider manages everything.




What are the four cloud deployment models? ✔✔Public

Private

Community

Hybrid

, What cloud model is owned by a single organization? ✔✔Private




What cloud model is an arrangement of two or more cloud servers? ✔✔Hybrid




What cloud model is a shared setup between orgs? ✔✔Community




What cloud model is open for free usage? ✔✔Public




What is a cloud service provider? ✔✔Cloud service provider manages and provides entire
hosting ability




What is a Cloud Access Security Broker? ✔✔Third-party acting as an intermediary for identity
and access management




What do regulators do? ✔✔Ensure organizations are in compliance with regulatory framework.




What word in the CIA triad describes: What protects information from unauthorized
access/dissemination? ✔✔Confidentiality




What word in the CIA triad describes: Ensuring that information is not subject to unauthorized
modification? ✔✔Integrity

Document information

Uploaded on
September 2, 2026
Number of pages
63
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$17.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
SUCCESSSTUDY
3.8
(33)
Sold
148
Followers
4
Items
1060
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions