Cloud Data Lifecycle - Chapter 4 Cloud Data Security
75 Questions • 6 Sections • Aligned to (ISC)2 CCSP Domain 3 (Cloud Data Security) • 2026/2027 Edition
Instructions: This exam contains 75 multiple-choice questions across 6 sections. Each question has exactly ONE correct
answer (A, B, C, or D). The correct answer is marked [CORRECT] and is followed by a detailed rationale citing NIST
SP 800-88, ISO/IEC 27018, CSA, and (ISC)2 CCSP references where applicable. Cognitive distribution: ~25% recall,
~55% application, ~20% analysis. Question style: ~78% scenario-based, ~22% direct recall.
WGU D320 / C838 - Cloud Data Security Exam Page 1
,WGU D320 / C838 - Managing Cloud Security Cloud Data Lifecycle - Chapter 4 Cloud Data Security
Section 1: Data Lifecycle Fundamentals and Governance
Lifecycle Phases, Data Roles, Information Governance, & Data Classification (Q1-Q15)
Q1: A cloud security architect is mapping security controls to the CSA cloud data lifecycle. Which of
the following sequences correctly lists ALL six phases in the proper order, beginning with data
origination?
A. Create -> Use -> Store -> Share -> Archive -> Destroy
B. Create -> Store -> Use -> Share -> Archive -> Destroy [CORRECT]
C. Store -> Create -> Use -> Share -> Destroy -> Archive
D. Create -> Store -> Share -> Use -> Archive -> Destroy
Correct Answer: B
Rationale:
The CSA cloud data lifecycle follows the canonical order Create -> Store -> Use -> Share -> Archive -> Destroy.
Create precedes Store because data must be generated before being persisted; Store precedes Use because data must be
at rest before it is consumed; Share follows Use because data is exposed to external parties after being processed
internally; Archive precedes Destroy because long-term retention is required before final disposition. Option A swaps
Use and Store, Option C begins with Store, and Option D swaps Share and Use, each misaligning the controls
applicable at each phase per WGU D320/C838 Chapter 4 guidance.
WGU D320 / C838 - Cloud Data Security Exam Page 2
,WGU D320 / C838 - Managing Cloud Security Cloud Data Lifecycle - Chapter 4 Cloud Data Security
Q2: An organization is implementing a data loss prevention (DLP) solution to scan data before it
leaves the company. According to the cloud data lifecycle, during which phase should the DLP
inspection control primarily be enforced?
A. Create
B. Store
C. Share [CORRECT]
D. Archive
Correct Answer: C
Rationale:
DLP egress controls are enforced during the Share phase of the cloud data lifecycle, when data is exposed to external
parties via email, APIs, or partner transfers. While creation-phase tagging supports DLP discovery, the actual
inspection and blocking of sensitive data movement occurs at Share. Option A is too early because data has not yet
been classified or staged for transmission; Option B protects data at rest but does not inspect outbound flows; Option D
relates to retention, not active sharing. CCSP Domain 3 aligns DLP with the Share phase.
WGU D320 / C838 - Cloud Data Security Exam Page 3
, WGU D320 / C838 - Managing Cloud Security Cloud Data Lifecycle - Chapter 4 Cloud Data Security
Q3: Within a shared-responsibility model, the data owner is accountable for which of the following in
a public cloud environment?
A. Patching the hypervisor hosting the customer's virtual machines
B. Defining data classification, access policy, and retention requirements [CORRECT]
C. Encrypting storage volumes at the physical disk controller level
D. Maintaining the physical security of the cloud region's data center
Correct Answer: B
Rationale:
The data owner is accountable for defining classification levels, who may access the data, retention requirements, and
the business impact of compromise -- all business-governance responsibilities that cannot be delegated to the provider.
Option A is the cloud provider's responsibility (hypervisor patching under IaaS shared responsibility). Option C may be
customer responsibility for application-level encryption but the underlying disk controller is provider-managed. Option
D is the provider's physical security obligation. WGU D320/C838 Chapter 4 emphasizes the data owner as the
business-side accountability role.
WGU D320 / C838 - Cloud Data Security Exam Page 4