• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 4 fuera de 103 páginas
Examen

WGU D320 Managing Cloud Security Exam 2026 | 173 Most Tested Questions & Correct Answers | Latest Update | Graded A+

Document preview thumbnail
Vista previa 4 fuera de 103 páginas

WGU D320 Managing Cloud Security Exam Study Guide 2026 | Complete Review | Graded A+ 173 questions with the correct answer marked on every item, covering all the core content tested on the WGU D320 Managing Cloud Security Objective Assessment. Important — scope of this document: this set covers the OA content for WGU D320 Managing Cloud Security. It is a study aid designed to reinforce your understanding — not a brain dump or leaked exam. What's covered: Cloud service models – IaaS, PaaS, and SaaS definitions, service delivery differences, customer responsibility levels, risks unique to each model including interoperability, virtualization, resource sharing, and web application security Business Impact Analysis (BIA) – purpose, role in risk management, contribution to recovery planning, primary outcomes, prioritizing recovery strategies after disruption Risk management – risk appetite, transference, mitigation, quantitative vs qualitative risk assessment, gap analysis, risk transfer strategies Encryption and data protection – encryption at rest and in transit, decryption, crypto-shredding, key deletion, hashing vs encryption, data at rest definitions Data lifecycle – creation, storage, usage, sharing, archiving, and destruction stages, significance of each phase, archiving risks and compliance issues Data Loss Prevention (DLP) – purpose, how it mitigates unauthorized sharing, role in data security Compliance and legal frameworks – FERPA, HIPAA, SOX, GDPR, PIPEDA, FedRAMP, FISMA, PCI DSS, ISO 27001, NIST 800-92, SOC 1, SOC 2, SOC 3, CSA STAR program Data roles and governance – data custodian responsibilities, data owner vs steward, metadata-based discovery, content-based vs label-based vs extension-based discovery Threat modeling – purpose in application security, identifying vulnerabilities early, proactive security integration Defense in depth – multiple layers of security, information assurance approach, layered controls across physical, technical, and policy levels Zero-day vulnerabilities – definition, implications for organizations, immediate mitigation actions, difference from configuration vulnerabilities CSRF and web attacks – cross-site request forgery mechanics, CSRF vs XSS vs SQL injection, token-based mitigation, hidden field manipulation, command injection Cloud security testing – white-box testing (SAST), black-box testing, gray-box testing, pen testing, DAST, port scanning Hypervisors and virtualization – creating and managing virtual machines, multiple operating systems on one host, hardware abstraction, live migration Content Delivery Networks (CDN) – geographic content delivery, reducing latency, edge servers, cached content, load times Geofencing – virtual geographic boundaries, mobile application triggers, promotional use cases, risk management applications Audits and assessments – external vs internal vs operational vs compliance audits, SOC 1 report for financial reporting, auditor independence, gap analysis in strategic planning Software as a Service (SaaS) – subscription model, provider-managed maintenance, web application vulnerability risks, vendor risk management Platform as a Service (PaaS) – application development platform, third-party API and supply chain risks, virtualization concerns, resource sharing risks Infrastructure as a Service (IaaS) – virtualized computing resources, customer responsibility, personnel threats, misconfiguration accountability Security frameworks and standards – ISO 27001 ISMS framework, NIST 800-92 log management, FedRAMP standardized assessments, CSA STAR security evaluations, HIPAA privacy, PIPEDA Canadian law Risk assessment methods – quantitative risk assessment numerical values, qualitative risk assessment descriptive categories, risk appetite definitions Data destruction – crypto-shredding, degaussing, wiping, overwriting, irretrievable data, deletion of encryption keys

Vista previa del contenido

WGU D320 Exam Questions & Correct Answers 2026 |
Latest Update | Graded A+
1. What is the primary purpose of Business Impact Analysis (BIA)?

To create marketing strategies for business growth.

To identify and evaluate the potential effects of disruptions to
business operations.

To analyze financial statements for investment decisions.

To assess employee performance and productivity.

2. Describe the role of threat modeling in enhancing application security.

Threat modeling is used to create marketing strategies for
applications.

Threat modeling focuses solely on user experience design.

Threat modeling helps developers understand vulnerabilities and
implement appropriate security measures.

Threat modeling is irrelevant to application security.

3. What are the three primary cloud service models?

Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and
Software as a Service (SaaS)

Platform as a Service (PaaS), Network as a Service (NaaS), and
Software as a Service (SaaS)

Infrastructure as a Service (IaaS), Database as a Service (DBaaS), and
Software as a Service (SaaS)

Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and
Network as a Service (NaaS)

,4. If a company discovers a zero-day vulnerability in its software, what
immediate action should it take to mitigate potential risks?

Ignore the vulnerability until a patch is released.

Stop all operations until the vulnerability is fixed.

Implement temporary security measures and inform stakeholders
while working on a patch.

Publicly disclose the vulnerability to all users immediately.

5. is a way of temporarily converting data into an unreadable form in order
to protect that data from being viewed by unauthorized individuals.

Authentication

Decryption

Authorization

Encryption

6. What are the key stages of the data lifecycle?

Creation, storage, usage, sharing, archiving, and destruction.

Creation, processing, analysis, reporting, and deletion.

Creation, storage, sharing, and deletion.

Collection, storage, analysis, sharing, and disposal.

7. Describe the main purpose of FERPA in relation to student education
records.

FERPA requires schools to disclose all student records to the public.

FERPA protects the privacy of student education records and grants
rights to parents that transfer to students at age 18.

, FERPA only applies to students in higher education institutions.

FERPA allows schools to share student records with any third party
without consent.

8. Describe how web application security vulnerabilities can impact the SaaS
service model.

Web application security vulnerabilities only affect the performance
of the application.

Web application security vulnerabilities can be completely mitigated
by using encryption.

Web application security vulnerabilities can lead to unauthorized
access, data breaches, and loss of customer trust.

Web application security vulnerabilities are irrelevant in the SaaS
model.

9. Describe how Business Impact Analysis (BIA) contributes to effective risk
management in organizations.

BIA contributes to effective risk management by providing insights
that guide resource allocation and recovery strategies.

BIA focuses solely on financial risks without considering operational
impacts.

BIA is a tool for developing new product lines.

BIA is used to assess employee performance and productivity.

10. Describe how encryption methods contribute to data security.

Encryption methods are used to increase data storage capacity.

Encryption methods secure data by converting it into a coded
format that only authorized parties can read.

, Encryption methods are primarily for data backup purposes.

Encryption methods allow all users to access data freely.


11. What is the primary goal of a defense-in-depth strategy in cybersecurity?

To create a single layer of security defenses

To eliminate all security vulnerabilities

To provide multiple layers of security to mitigate risks

To rely solely on encryption for protection

12. What does the term 'data at rest' refer to?

Data that is transmitted over a network.

Inactive data stored physically in any digital form.

Data that is deleted from storage.

Data that is actively being processed.

13. Describe how personnel threats can impact the IaaS service model.

Personnel threats are mitigated by encryption methods in the IaaS
model.

Personnel threats can lead to unauthorized access and misuse of
resources in the IaaS model.

Personnel threats are irrelevant to the IaaS model as it is fully
automated.

Personnel threats only affect physical data centers, not cloud
services.

Información del documento

Subido en
5 de octubre de 2026
Número de páginas
103
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$14.00

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Vendido
1
Seguidores
0
Artículos
191
Última venta
2 semanas hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes