Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 35 pages
Exam (elaborations)

WGU D320 – Questions & Detailed Answers

Document preview thumbnail
Preview 4 out of 35 pages

WGU D320 – Questions & Detailed Answers

Content preview

WGU D320 – Questions & Detailed Answers

1: Implements Secure Solutions
Which technology should be implemented to ensure secure communication
between on-site enterprise systems and a cloud platform A. Domain
Name System Security Extensions (DNSSEC)
B. Internet Protocol Security (IPSec) VPN
C. Web Application Firewall (WAF)
D. Data Loss Prevention (DLP)
Right Ans - B. Internet Protocol Security (IPSec) VPN
Explanation:
• IPSec VPN is designed to secure communication over an IP network. It
encrypts the entire IP packet for secure transmission between on-site systems
and cloud platforms, ensuring data integrity and confidentiality.
• DNSSEC ensures the integrity of DNS responses but doesn't provide secure
communication between systems.
• WAF protects web applications by filtering and monitoring HTTP traffic but
is not used for secure communication between systems.
• DLP prevents data breaches by monitoring and controlling data flows, but it
doesn't establish secure communication channels.

2: Implements Operations
Which phase of the cloud data lifecycle is most likely to overlap with the
'Create' phase in terms of implementing security controls A. Share
B. Store
C. Use
D. Destroy
Right Ans - B. Store
Explanation:
• Store often overlaps with the Create phase because as soon as data is
created, it usually needs to be securely stored. Security controls, such as
encryption, should be implemented at this stage.
• Share and Use happen after data is stored.
• Destroy is the final stage in the lifecycle and typically occurs after data is no
longer needed.

3: Conducts Risk Management
Which risk management approach involves completely eliminating a risk
because it exceeds the organization's risk appetite A. Mitigation

,B. Avoidance
C. Transfer
D. Acceptance
Right Ans - B. Avoidance
Explanation:
• Avoidance involves eliminating the risk entirely, typically when the potential
impact is too great or when controls cannot adequately reduce the risk to an
acceptable level.
• Mitigation involves reducing the risk to an acceptable level.
• Transfer involves shifting the risk to a third party, such as through
insurance.
• Acceptance involves acknowledging the risk and choosing to bear it without
further action.

4: Identifies Legal, Compliance, and Ethical Concerns
Which United States law focuses specifically on the privacy of financial
information A. Health Insurance Portability and Accountability Act
(HIPAA)
B. Sarbanes-Oxley Act (SOX)
C. Gramm-Leach-Bliley Act (GLBA)
D. Safe Harbor
Right Ans - C. Gramm-Leach-Bliley Act (GLBA)
Explanation:
• GLBA is designed to protect consumer financial privacy by setting
regulations for how financial institutions handle private data.
• HIPAA focuses on healthcare information.
• SOX is concerned with corporate financial practices and reporting.
• Safe Harbor was an agreement between the US and EU for data transfers, not
specifically financial privacy.

1: Implements Secure Solutions
Which technology is most effective in preventing unauthorized access to
sensitive data by ensuring it is unreadable without proper decryption keys
A. Data Masking
B. Tokenization
C. Encryption
D. Obfuscation
Right Ans - C. Encryption

,Explanation: Encryption transforms readable data into an unreadable format
using cryptographic algorithms, making it inaccessible to unauthorized users.
Tokenization and data masking are also methods of protecting data, but they
do not provide the same level of security as encryption. Obfuscation is the
process of making data more difficult to understand but is not intended to
prevent access.

2: Implements Operations
Which of the following activities is essential during the Secure Operations
phase of the Software Development Lifecycle (SDLC) A. Static Analysis
B. Code Review
C. Dynamic Analysis
D. Acceptance Testing
Right Ans - C. Dynamic Analysis
Explanation: Dynamic Analysis is crucial during the secure operations phase
because it involves testing the software in a runtime environment, identifying
security vulnerabilities that might only become apparent during execution.
Static Analysis and Code Review are performed earlier in the SDLC, and
Acceptance Testing is typically done after secure operations to verify the
system meets the requirements.

3: Conducts Risk Management
Which risk management approach involves the transfer of risk to another
party, such as through insurance A. Risk Mitigation
B. Risk Avoidance
C. Risk Transference
D. Risk Acceptance
Right Ans - C. Risk Transference
Explanation: Risk Transference involves shifting the impact of a risk to a third
party, often by using insurance or outsourcing certain activities. Risk
Mitigation involves reducing the risk, Risk Avoidance involves eliminating the
risk, and Risk Acceptance involves acknowledging and accepting the risk
without further action.

4: Identifies Legal, Compliance, and Ethical Concerns
Which U.S. law focuses specifically on the protection of personal health
information A. Sarbanes-Oxley Act (SOX)
B. Health Insurance Portability and Accountability Act (HIPAA)
C. Gramm-Leach-Bliley Act (GLBA)

, D. Federal Information Security Management Act (FISMA)
Right Ans - B. Health Insurance Portability and Accountability Act (HIPAA)
Explanation: HIPAA sets standards for the protection of personal health
information. SOX is related to corporate financial practices, GLBA focuses on
financial privacy, and FISMA applies to federal information security
management.

5: Implements Secure Solutions
Which cloud service model requires the customer to manage the security of
the operating system, applications, and data A. Software as a Service
(SaaS)
B. Platform as a Service (PaaS)
C. Infrastructure as a Service (IaaS)
D. Containers as a Service (CaaS)
Right Ans - C. Infrastructure as a Service (IaaS)
Explanation: In IaaS, the provider manages the underlying infrastructure,
while the customer is responsible for managing the security of the operating
system, applications, and data. In SaaS, the provider manages everything,
including security. PaaS offers more management of security, but the
customer still handles application security.

6: Implements Operations
What is the primary goal of implementing a Disaster Recovery Plan (DRP) in
cloud operations A. Ensure high availability of cloud services
B. Recover operations after a catastrophic event
C. Perform routine backups of data
D. Prevent unauthorized access to cloud resources
Right Ans - B. Recover operations after a catastrophic event
Explanation: The main goal of a Disaster Recovery Plan is to recover business
operations as quickly as possible after a catastrophic event. High availability is
a separate concern, focusing on maintaining operations, while backups are
part of DRP but not the primary goal. Preventing unauthorized access is a
security concern, not specifically related to DRP.

7: Conducts Risk Management
Which risk management process involves determining the impact of potential
threats on business operations A. Risk Assessment
B. Business Impact Analysis (BIA)
C. Threat Modeling

Document information

Uploaded on
December 29, 2024
Number of pages
35
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$23.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
StudyHall
3.8
(231)
Sold
1348
Followers
825
Items
17221
Last sold
20 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions