• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 4 fuera de 39 páginas
Examen

WGU D320 MANAGING CLOUD SECURITY ACTUAL EXAM 2026/2027 | Questions with Complete Solutions | Verified Answers | Pass Guaranteed - A+ Graded

Document preview thumbnail
Vista previa 4 fuera de 39 páginas

Pass the WGU D320 Managing Cloud Security exam on your first attempt with this complete 2026/2027 questions and solutions guide. This A+ Graded resource contains complete verified solutions covering all core D320 domains including cloud security governance, risk management, compliance frameworks, data protection, identity and access management (IAM), incident response, and the shared responsibility model. Each answer includes detailed rationales to reinforce cloud security decision-making and scenario-based application of concepts. Aligned with the CCSP domains and the latest WGU D320 curriculum standards for 2026/2027. Perfect for WGU cybersecurity students preparing for the objective assessment. With our Pass Guarantee, you can confidently prepare for your WGU D320 exam. Download your complete questions and solutions guide instantly!

Vista previa del contenido

WGU D320 | Managing Cloud Security (YJ02) Edition




WGU D320 — Managing Cloud Security
Edition · Questions With Complete Solutions
Course Code: D320 (YJ02) | Competency: Managing Cloud Security | Cognitive Mix: 25% Recall · 55% Application ·
20% Analysis
Format: 110 Multiple-Choice Questions | 80% Scenario-Based · 20% Direct Recall | Time Allocated: 180 Minutes
Authoritative References: NIST SP 800-145, SP 800-53 Rev. 5, SP 800-207; ISO/IEC 17788/17789,
27017/27018/27701; CSA CCM v4 & STAR; AICPA SOC 1/2/3; GDPR, HIPAA, PCI DSS, FedRAMP


This examination measures competency in WGU D320 Managing Cloud Security (YJ02) across seven integrated domains:
cloud computing fundamentals and reference architecture; shared responsibility and cloud security architecture; identity,
access management, and data security; cloud network and infrastructure security; risk management, compliance, legal, and
auditing; security operations, incident response, and business continuity; and standards, Zero Trust, and emerging trends.
Each question is multiple-choice with one correct option and a rationale grounded in NIST, ISO/IEC, and CSA guidance.
Candidates should pay particular attention to the Shared Responsibility Model and how its boundaries shift across IaaS,
PaaS, and SaaS; the correct selection of cloud deployment models; IAM federation and cryptographic decision-making;
jurisdiction and data sovereignty; the proper alignment of recovery objectives (RTO/RPO) with disaster recovery
strategies; and the proper identification of compliance frameworks and SOC report types. Distractors are designed around
the most common D320 exam pitfalls and require applied cloud security knowledge, not rote memorization.
Answer each question by selecting the single best response. Rationales explain why the correct option is right and why
each distractor is wrong, with explicit reference to the applicable standard, control, or regulatory requirement where
applicable. Use this document for self-assessment, study group review, or final competency preparation prior to the WGU
D320 objective assessment.


Section 1 — Cloud Computing Fundamentals & Reference Architecture
(Q1–Q18)
NIST SP 800-145 Essential Characteristics · IaaS/PaaS/SaaS Service Models ·
Public/Private/Community/Hybrid/Multi-cloud Deployment Models · ISO/IEC 17788/17789 Reference
Architecture (Consumer, Provider, Auditor, Broker, Carrier)


Q1. A startup launches a SaaS analytics platform and advertises that customers can provision new tenants
"automatically within minutes, with no human intervention from the provider." Which NIST SP 800-145
essential characteristic is being described?
A. Broad network access
B. Resource pooling
C. On-demand self-service [CORRECT]
D. Rapid elasticity
Correct Answer: C
Rationale: NIST SP 800-145 defines on-demand self-service as the ability for a consumer to unilaterally provision computing
capabilities (server time, network storage) without requiring human interaction with the provider. Broad network access refers
to access over the network through standard mechanisms. Resource pooling describes multi-tenant sharing of physical
resources. Rapid elasticity refers to capabilities being elastically provisioned and released to scale rapidly. The key phrase "no
human intervention" uniquely identifies on-demand self-service.




Complete Solutions | 110 Questions | Aligned to NIST SP 800-145, ISO/IEC 17788/17789, CSA CCM, ISO/IEC 27017/27018/27701 Page 1

,WGU D320 | Managing Cloud Security (YJ02) Edition




Q2. An enterprise runs a private cloud on-premises and uses a cloud broker to aggregate two public SaaS
providers for redundancy. The customer accesses services through a single unified interface. Under ISO/IEC
17789 reference architecture, which actor is responsible for negotiating the relationships between the cloud
consumer and the two cloud providers?
A. Cloud Carrier
B. Cloud Auditor
C. Cloud Broker [CORRECT]
D. Cloud Service Partner (CSPartner)
Correct Answer: C
Rationale: Under ISO/IEC 17789, the Cloud Broker is an intermediary that manages the use, performance, and delivery of
cloud services and negotiates relationships between Cloud Consumers and Cloud Providers. A Cloud Carrier provides
connectivity and transport of cloud services (telecommunications). A Cloud Auditor conducts independent assessment of
services. A Cloud Service Partner supports the provider or consumer with value-added services but does not negotiate
brokered relationships. The unified-interface aggregation pattern is the canonical broker use case.


Q3. A company purchases an Office 365 tenant. The provider manages the underlying infrastructure,
operating systems, middleware, and the application itself; the customer only administers user accounts and
configures data-sharing policies. Which service model and customer responsibility boundary applies?
A. IaaS — customer is responsible for OS and above
B. PaaS — customer is responsible for applications and data only
C. SaaS — customer is responsible primarily for data and user access [CORRECT]
D. FaaS — customer is responsible for function code only
Correct Answer: C
Rationale: Office 365 is the canonical SaaS model. Under NIST SP 800-145 and the CSA Shared Responsibility Model, in
SaaS the provider manages infrastructure, OS, middleware, and application; the customer is responsible for data, identity and
access management, and configuration of the application. IaaS would require the customer to manage OS and above (e.g.,
EC2). PaaS has the customer managing applications and data (e.g., Heroku). FaaS has the customer managing only function
code (e.g., AWS Lambda).


Q4. A hospital, two insurance companies, and a research university jointly build a cloud that hosts shared
healthcare analytics workloads. The infrastructure is shared by the participating organizations and their
authorized users; it is not open to the general public. Which deployment model is described?
A. Public cloud
B. Private cloud
C. Community cloud [CORRECT]
D. Hybrid cloud
Correct Answer: C
Rationale: NIST SP 800-145 defines a community cloud as infrastructure provisioned for exclusive use by a specific
community of consumers from organizations that have shared concerns (e.g., mission, security requirements, compliance).
Public cloud is open to the general public; private cloud is provisioned for a single organization; hybrid cloud is a composition
of two or more distinct cloud infrastructures. The shared healthcare concern among distinct organizations is the textbook
community cloud signature.




Complete Solutions | 110 Questions | Aligned to NIST SP 800-145, ISO/IEC 17788/17789, CSA CCM, ISO/IEC 27017/27018/27701 Page 2

,WGU D320 | Managing Cloud Security (YJ02) Edition




Q5. A retail enterprise runs its customer-facing storefront on AWS (public) but keeps its payment card
processing database in an on-premises private cloud, with workload bursting between them during peak
shopping seasons. Which deployment model best describes this arrangement, and what is its key defining
characteristic?
A. Multi-cloud — workloads span two or more public providers simultaneously
B. Hybrid cloud — distinct infrastructures connected with load-balancing and orchestration [CORRECT]
C. Community cloud — shared by organizations with common compliance needs
D. Public cloud — services are delivered to the general public
Correct Answer: B
Rationale: NIST SP 800-145 defines hybrid cloud as a composition of two or more distinct cloud infrastructures (private,
community, or public) that remain unique entities but are bound together, offering application and data portability. The
defining trait is the orchestration and load-balancing between the constituent clouds. Multi-cloud is the use of two or more
public providers but typically without the tightly coupled orchestration. The burst pattern between public and private is the
classic hybrid signature.


Q6. A cloud consumer provisions 50 virtual CPUs during a marketing campaign and releases 40 of them three
hours later. The provider meter records only the 10 vCPUs that remain allocated, plus historical
consumption. Which NIST SP 800-145 essential characteristic does the metering reflect?
A. Resource pooling
B. Broad network access
C. Rapid elasticity
D. Measured service [CORRECT]
Correct Answer: D
Rationale: NIST SP 800-145 defines measured service as the cloud systems automatically controlling and optimizing resource
use by leveraging a metering capability that allows resource usage to be monitored, controlled, and reported, providing
transparency for both the provider and consumer. Rapid elasticity is the ability to provision and release resources to scale
rapidly (the action), while measured service is the metering/billing transparency (the accounting). The provider meter
recording actual consumption is the measured-service signature.


Q7. A provider operates a multi-tenant IaaS platform where customer VMs from different organizations
share the same physical hosts, with virtualization layer isolation. Workloads are dynamically assigned based
on demand. Which NIST essential characteristic is in evidence, and what is its principal security risk?
A. On-demand self-service — risk of unauthorized provisioning
B. Resource pooling — risk of side-channel and tenant data isolation failure [CORRECT]
C. Rapid elasticity — risk of license misuse
D. Measured service — risk of billing fraud
Correct Answer: B
Rationale: NIST SP 800-145 defines resource pooling as the provider computing resources being pooled to serve multiple
consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned. The
principal security risk is tenant data isolation failure, including side-channel attacks and VM escape via hypervisor
vulnerabilities. This is the basis for the Cloud Security Alliance emphasis on multi-tenancy isolation controls in CCM.




Complete Solutions | 110 Questions | Aligned to NIST SP 800-145, ISO/IEC 17788/17789, CSA CCM, ISO/IEC 27017/27018/27701 Page 3

, WGU D320 | Managing Cloud Security (YJ02) Edition




Q8. Under ISO/IEC 17789, which cloud actor is a party that conducts independent assessment of cloud
services against defined standards and publishes the results for the consumer or other interested parties?
A. Cloud Broker
B. Cloud Carrier
C. Cloud Auditor [CORRECT]
D. Cloud Service Partner
Correct Answer: C
Rationale: ISO/IEC 17789 defines the Cloud Auditor as a party that conducts independent assessment of cloud services,
information system operations, performance, and security of the cloud implementation, with the results published for the
consumer or other interested parties. A Cloud Broker intermediates service relationships, a Cloud Carrier transports services,
and a Cloud Service Partner provides value-added support to providers or consumers. The "independent assessment" keyword
uniquely identifies the Cloud Auditor role.


Q9. A consumer runs workloads across both AWS and Azure for vendor resilience and to avoid lock-in, with
each provider hosting different applications and no shared orchestration. Which deployment pattern is this,
and how does it differ from a hybrid cloud?
A. Hybrid cloud — both clouds are bound by orchestration
B. Multi-cloud — multiple public providers without tight orchestration [CORRECT]
C. Community cloud — shared by organizations with common mission
D. Private cloud — provisioned for a single organization
Correct Answer: B
Rationale: Multi-cloud is the deliberate use of cloud services from more than one public cloud provider to host distinct
workloads, typically for vendor diversification, geographic coverage, or cost optimization. The key distinction from hybrid
cloud is the absence of a tightly coupled orchestration layer between the providers; each is managed separately. NIST SP
800-145 does not formally define multi-cloud but treats it as a public-cloud composition pattern.


Q10. A security engineer must architect a cloud environment where the customer has full control over the
operating system, hypervisor-level configurations, and deployed applications, but does not own the physical
servers or networking. Which service model is the best fit?
A. SaaS
B. PaaS
C. IaaS [CORRECT]
D. Function-as-a-Service (FaaS)
Correct Answer: C
Rationale: In NIST SP 800-145 IaaS, the consumer provisions processing, storage, networks, and other fundamental
computing resources and can deploy and run arbitrary software, including OSs and applications. The consumer does not
manage or control the underlying cloud physical infrastructure but has control over OSs, storage, and deployed applications,
and sometimes limited control of selected networking components. The customer control over OS and applications without
owning physical hardware is the IaaS signature.




Complete Solutions | 110 Questions | Aligned to NIST SP 800-145, ISO/IEC 17788/17789, CSA CCM, ISO/IEC 27017/27018/27701 Page 4

Información del documento

Subido en
16 de septiembre de 2026
Número de páginas
39
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$26.50

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
NURSEEXAMITY
3.4
(108)
Vendido
577
Seguidores
275
Artículos
6778
Última venta
3 horas hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes