Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 31 pages
Exam (elaborations)

WGU D320 - MANAGING CLOUD SECURITY VERSION (JYO2) QUESTIONS AND ANSWERS 2024

Document preview thumbnail
Preview 4 out of 31 pages

WGU D320 - MANAGING CLOUD SECURITY VERSION (JYO2) QUESTIONS AND ANSWERS 2024

Content preview

WGU D320 - MANAGING CLOUD SECURITY
VERSION (JYO2)
SOC 1

SOC Report type: strictly for auditing the financial reporting instruments of a
corporation

SOC 2

SOC Report type: Intended to report audits of any controls on an organization's
security, availability, processing integrity, confidentiality, and privacy.

SOC 3

SOC Report type: Designed to be shared with the public.

Seal of approval. Does not contain any actual data about the security controls of
the audit target.

encrypted

Data at rest should be _________.

Defining

SDLC Phase focused on identifying the business requirements of the application,
such as accounting, database, or customer relationship management

Designing

SDLC Phase: Begin to develop user stories (what the user will want to accomplish,
what interface will look like and whether it will require the use or development of
any APIs)

Development

SDLC Phase where the code is written.

,Testing

SDLC Phase where activities such as initial pen testing and vulnerability scanning
against the application are performed. Will use both dynamic and static testing or
DSAT (Dynamic Application Security Testing) or SAST (Static Application Security
Testing).

Secure Operations

SDLC Phase where after testing, the application is deemed secure.

Disposal

SDLC Phase where app has reached end of life or has been replaced with a newer
or different application.

S (Spoofing)

T (Tampering)

R (Repudiation)

I (Information Disclosure)

D (Denial of Service)

E (Elevation of Privilege)

STRIDE

Graham-Leach-Bliley Act (GLBA)

Allow banks to merge with and own insurance companies. Included in the law
were stipulations that customer account information be kept secure and private,
and that customers be allowed to opt out of any information-sharing
arrangements the bank or insurer might engage in.

Sarbanes-Oxley Act (SOX)

,Law that increases transparency into publicly traded corporations' financial
activities.

HIPPA

Law that protects patient records and data.

FERPA

Law that prevents academic institutions from sharing student data with anyone
other than parents or students (after age 18)

DMCA

provisions to protect owned data; cracking of access controls on copyrighted
media a crime and enables holders to require any site to remove content

CLOUD Act

Allows US law enforcement and courts to compel American companies to disclose
data stored in foreign data centers.

GDPR

Most significant, powerful personal privacy law in the world. Describes the
appropriate handling of personal and private information of all EU citizens.

Crypto-shredding

The practice of 'deleting' data by deliberately deleting or overwriting the
encryption keys.



Business Impact Analysis (BIA)

A process that assesses and identifies the potential effects of disruptions to a
business operation.

SPOF

, A component or system that, if it fails, will cause the entire system to fail.

Quantitative

Risk assessment that uses specific numerical values

Qualitative

Risk assessment that uses non-numerical categories that are relative in nature,
such as high, medium, and low.

Risk appetite

level, amount, or type of risk that the organization finds acceptable

Residual risk

The remaining risk that exists after countermeasures have been applied.

IaaS

Service model where cloud customer has the most responsibility and authority.
Cloud provider is only liable for the underlying hardware.

PaaS

Service model where cloud customer loses more control because the cloud
provider is responsible for installing, maintaining, and administering the OS as
well as underlying hardware.

SaaS

Service model where cloud customer loses all control of the environment. Cloud
provider is responsible for all of the underlying hardware and software.

Homomorphic encryption

A method of processing data in the cloud while it remains encrypted.

Defense in depth

Document information

Uploaded on
September 11, 2024
Number of pages
31
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$13.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Teacher101
4.6
(277)
Sold
522
Followers
74
Items
11506
Last sold
4 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions