WGU D485 DGN2 TASK 1: Cloud Security
Implementation Plan Latest Update
with complete solution
Section A: Cloud Architecture & Service Models (Q1–Q20)
Q1. SWBTL LLC needs to maintain full control over its operating systems, network
configurations, and security settings while leveraging Azure's physical infrastructure. Which
cloud service model should be selected?
A. SaaS
B. PaaS
C. IaaS
D. FaaS
Correct Answer: C. IaaS
Rationale: IaaS provides the highest level of control over operating systems, network
configurations, and security settings among the three primary service models. SaaS offers the
least control, PaaS abstracts the OS layer, and FaaS (serverless) provides almost no configuration
control .
Q2. SWBTL LLC processes payment card transactions and holds government contracts requiring
FISMA compliance. Which Azure deployment model best meets these stringent regulatory
requirements?
A. Azure Commercial Public Cloud
B. Azure Government Cloud
C. Azure Community Cloud
D. Hybrid Cloud
Correct Answer: B. Azure Government Cloud
Rationale: Azure Government Cloud is purpose-built for U.S. government agencies and
contractors, offering FedRAMP authorization, DISA approval, and DoD IL5 compliance
certifications required for FISMA. Commercial Azure lacks these government-specific
certifications .
,Q3. In the IaaS shared responsibility model, which security component is the customer
responsible for?
A. Physical security of data centers
B. Hypervisor maintenance
C. Operating system patching and firewall configuration
D. Firmware updates for underlying storage hardware
Correct Answer: C. Operating system patching and firewall configuration
Rationale: In IaaS, the customer is responsible for "security in the cloud," including
operating systems, applications, data, and network controls. The provider is responsible for
"security of the cloud," including physical facilities, host infrastructure, and hypervisors .
Q4. SWBTL LLC is considering containerization to improve deployment efficiency. What is the
key difference between containers and virtual machines?
A. Each container instance requires a complete guest operating system
B. Containers share the host OS kernel, making them lighter than VMs
C. VMs always have better cross-cloud portability than containers
D. Containers cannot run in IaaS environments
Correct Answer: B. Containers share the host OS kernel, making them lighter than VMs
Rationale: Containers virtualize at the OS level, sharing the host kernel and eliminating the
overhead of multiple guest OS instances. This makes containers faster to start and less resource-
intensive. Option A describes virtual machines.
Q5. Which NIST SP 800-145 essential characteristic allows cloud consumers to automatically
provision computing capabilities without human interaction with the service provider?
A. Broad network access
B. On-demand self-service
C. Resource pooling
D. Rapid elasticity
Correct Answer: B. On-demand self-service
Rationale: On-demand self-service enables consumers to unilaterally provision and manage
resources (servers, storage, network) through self-service portals without provider intervention.
This is one of the five essential characteristics defined by NIST.
Q6. SWBTL LLC's microservices architecture consists of small, loosely coupled services
communicating via APIs. What is the primary security benefit of this architecture?
,A. Increased attack surface due to multiple entry points
B. Each service can be deployed independently, and security vulnerabilities can be contained
C. Requires unified monolithic security controls
D. Eliminates the need for API gateways
Correct Answer: B. Each service can be deployed independently, and security
vulnerabilities can be contained
Rationale: Microservices enable independent security updates, containment of
vulnerabilities within individual services, and fine-grained access control. Option A is a risk
rather than a benefit.
Q7. Which cloud deployment model provides dedicated resources to a single organization but is
hosted and managed by a third-party provider off-site?
A. Public Cloud
B. Hosted Private Cloud
C. Hybrid Cloud
D. Community Cloud
Correct Answer: B. Hosted Private Cloud
Rationale: A hosted private cloud offers dedicated physical or logical infrastructure to one
organization while being physically located and maintained within a provider's data center. This
combines the security of a private cloud with third-party management convenience .
Q8. In the PaaS model, which of the following is typically managed by the cloud service
provider?
A. Application code
B. Operating system patching
C. User access credentials
D. Data endpoints
Correct Answer: B. Operating system patching
Rationale: PaaS abstracts the underlying operating system and infrastructure from the user,
meaning the cloud provider handles OS security updates, maintenance, and patching.
Customers manage applications and data .
Q9. What is the primary benefit of deploying workloads in Azure Government compared to
standard Azure commercial regions?
, A. Lower subscription and compute costs
B. Dedicated physical isolation and strict U.S. citizen background screening
C. Faster deployment of cutting-edge preview features
D. Availability across all continents globally
Correct Answer: B. Dedicated physical isolation and strict U.S. citizen background
screening
Rationale: Azure Government is physically isolated from commercial Azure networks and
enforces strict background checks on personnel to meet federal security requirements. These
isolation measures are not available in commercial regions .
Q10. Which cloud security concept emphasizes that organizations should not trust anything
inside or outside their perimeters and must verify every access request?
A. Defense in Depth
B. Zero Trust Architecture
C. Network Segmentation
D. Perimeter Defense
Correct Answer: B. Zero Trust Architecture
Rationale: Zero Trust Architecture operates on the core principle of "never trust, always
verify," requiring explicit validation for every access attempt regardless of origin. This is a
foundational principle of modern cloud security .
Q11. SWBTL LLC's applications need to auto-scale to handle traffic spikes. Which cloud
characteristic enables dynamic resource adjustment?
A. High Availability
B. Fault Tolerance
C. Elasticity
D. Redundancy
Correct Answer: C. Elasticity
Rationale: Elasticity allows cloud computing resources to scale dynamically to match
demand, ensuring security appliances or firewalls can scale up to handle sudden spikes in traffic.
This differs from high availability (ensuring continuous operation) .
Q12. Which of the following is a security advantage of SaaS over IaaS?
A. Customers have more control over underlying infrastructure
B. Provider handles patching for the entire software stack
Implementation Plan Latest Update
with complete solution
Section A: Cloud Architecture & Service Models (Q1–Q20)
Q1. SWBTL LLC needs to maintain full control over its operating systems, network
configurations, and security settings while leveraging Azure's physical infrastructure. Which
cloud service model should be selected?
A. SaaS
B. PaaS
C. IaaS
D. FaaS
Correct Answer: C. IaaS
Rationale: IaaS provides the highest level of control over operating systems, network
configurations, and security settings among the three primary service models. SaaS offers the
least control, PaaS abstracts the OS layer, and FaaS (serverless) provides almost no configuration
control .
Q2. SWBTL LLC processes payment card transactions and holds government contracts requiring
FISMA compliance. Which Azure deployment model best meets these stringent regulatory
requirements?
A. Azure Commercial Public Cloud
B. Azure Government Cloud
C. Azure Community Cloud
D. Hybrid Cloud
Correct Answer: B. Azure Government Cloud
Rationale: Azure Government Cloud is purpose-built for U.S. government agencies and
contractors, offering FedRAMP authorization, DISA approval, and DoD IL5 compliance
certifications required for FISMA. Commercial Azure lacks these government-specific
certifications .
,Q3. In the IaaS shared responsibility model, which security component is the customer
responsible for?
A. Physical security of data centers
B. Hypervisor maintenance
C. Operating system patching and firewall configuration
D. Firmware updates for underlying storage hardware
Correct Answer: C. Operating system patching and firewall configuration
Rationale: In IaaS, the customer is responsible for "security in the cloud," including
operating systems, applications, data, and network controls. The provider is responsible for
"security of the cloud," including physical facilities, host infrastructure, and hypervisors .
Q4. SWBTL LLC is considering containerization to improve deployment efficiency. What is the
key difference between containers and virtual machines?
A. Each container instance requires a complete guest operating system
B. Containers share the host OS kernel, making them lighter than VMs
C. VMs always have better cross-cloud portability than containers
D. Containers cannot run in IaaS environments
Correct Answer: B. Containers share the host OS kernel, making them lighter than VMs
Rationale: Containers virtualize at the OS level, sharing the host kernel and eliminating the
overhead of multiple guest OS instances. This makes containers faster to start and less resource-
intensive. Option A describes virtual machines.
Q5. Which NIST SP 800-145 essential characteristic allows cloud consumers to automatically
provision computing capabilities without human interaction with the service provider?
A. Broad network access
B. On-demand self-service
C. Resource pooling
D. Rapid elasticity
Correct Answer: B. On-demand self-service
Rationale: On-demand self-service enables consumers to unilaterally provision and manage
resources (servers, storage, network) through self-service portals without provider intervention.
This is one of the five essential characteristics defined by NIST.
Q6. SWBTL LLC's microservices architecture consists of small, loosely coupled services
communicating via APIs. What is the primary security benefit of this architecture?
,A. Increased attack surface due to multiple entry points
B. Each service can be deployed independently, and security vulnerabilities can be contained
C. Requires unified monolithic security controls
D. Eliminates the need for API gateways
Correct Answer: B. Each service can be deployed independently, and security
vulnerabilities can be contained
Rationale: Microservices enable independent security updates, containment of
vulnerabilities within individual services, and fine-grained access control. Option A is a risk
rather than a benefit.
Q7. Which cloud deployment model provides dedicated resources to a single organization but is
hosted and managed by a third-party provider off-site?
A. Public Cloud
B. Hosted Private Cloud
C. Hybrid Cloud
D. Community Cloud
Correct Answer: B. Hosted Private Cloud
Rationale: A hosted private cloud offers dedicated physical or logical infrastructure to one
organization while being physically located and maintained within a provider's data center. This
combines the security of a private cloud with third-party management convenience .
Q8. In the PaaS model, which of the following is typically managed by the cloud service
provider?
A. Application code
B. Operating system patching
C. User access credentials
D. Data endpoints
Correct Answer: B. Operating system patching
Rationale: PaaS abstracts the underlying operating system and infrastructure from the user,
meaning the cloud provider handles OS security updates, maintenance, and patching.
Customers manage applications and data .
Q9. What is the primary benefit of deploying workloads in Azure Government compared to
standard Azure commercial regions?
, A. Lower subscription and compute costs
B. Dedicated physical isolation and strict U.S. citizen background screening
C. Faster deployment of cutting-edge preview features
D. Availability across all continents globally
Correct Answer: B. Dedicated physical isolation and strict U.S. citizen background
screening
Rationale: Azure Government is physically isolated from commercial Azure networks and
enforces strict background checks on personnel to meet federal security requirements. These
isolation measures are not available in commercial regions .
Q10. Which cloud security concept emphasizes that organizations should not trust anything
inside or outside their perimeters and must verify every access request?
A. Defense in Depth
B. Zero Trust Architecture
C. Network Segmentation
D. Perimeter Defense
Correct Answer: B. Zero Trust Architecture
Rationale: Zero Trust Architecture operates on the core principle of "never trust, always
verify," requiring explicit validation for every access attempt regardless of origin. This is a
foundational principle of modern cloud security .
Q11. SWBTL LLC's applications need to auto-scale to handle traffic spikes. Which cloud
characteristic enables dynamic resource adjustment?
A. High Availability
B. Fault Tolerance
C. Elasticity
D. Redundancy
Correct Answer: C. Elasticity
Rationale: Elasticity allows cloud computing resources to scale dynamically to match
demand, ensuring security appliances or firewalls can scale up to handle sudden spikes in traffic.
This differs from high availability (ensuring continuous operation) .
Q12. Which of the following is a security advantage of SaaS over IaaS?
A. Customers have more control over underlying infrastructure
B. Provider handles patching for the entire software stack