WGU C838 EVALUATION EXAMS 2025 QUESTIONS AND
ANSWERS RATED A+
✔✔"Which risk is controlled by implementing a private cloud?
(A) Eavesdropping
(B) Physical security
(C) Unauthorized access
(D) Denial-of-service (DoS)" - ✔✔Physical security
✔✔"Which countermeasure enhances redundancy for physical facilities hosting cloud
equipment during the threat of a power outage?
(A) Tier 2 network access providers
(B) Multiple and independent power circuits to all racks
(C) Radio frequency interference (RFI) blocking devices
(D) Automated license plate readers (ALPR) at entry points" - ✔✔Multiple and
independent power circuits to all racks
✔✔"Which countermeasure helps mitigate the risk of stolen credentials for cloud-based
platforms?
(A) Host lockdown
(B) Data sanitization
(C) Key management
(D) Multifactor authentication" - ✔✔Multifactor authentication
✔✔"Which control helps mitigate the risk of sensitive information leaving the cloud
environment?
(A) Data loss prevention (DLP)
(B) Disaster recovery plan (DRP)
(C) Web application ?rewall (WAF)
(D) Identity and access management (IAM)" - ✔✔Data loss prevention (DLP)
✔✔"Which countermeasure mitigates the risk of a rogue cloud administrator?
(A) Data encryption
(B) Platform orchestration
(C) Logging and monitoring
(D) Multifactor authentication" - ✔✔Logging and monitoring
✔✔"Which consideration should be taken into account when reviewing a cloud service
provider's risk of potential outage time?
(A) The type of database
(B) The provider's support services
(C) The unique history of the provider
(D) The amount of cloud service offerings" - ✔✔The unique history of the provider
, ✔✔"Which cloud security control eliminates the risk of a virtualization guest escape from
another tenant?
(A) Dedicated hosting
(B) File integrity monitor
(C) Hardware hypervisor
(D) Immutable virtual machines" - ✔✔Dedicated hosting
✔✔"Which cloud security control is a countermeasure for man-in-the-middle attacks?
(A) Reviewing log data
(B) Backing up data offsite
(C) Using block data storage
(D) Encrypting data in transit" - ✔✔Encrypting data in transit
✔✔"Which data retention policy controls how long health insurance portability and
accountability act (HIPAA) data can be archived?
(A) Enforcement
(B) Maintenance
(C) Data classification
(D) Applicable regulation" - ✔✔Applicable regulation
✔✔"Which disaster recovery (DR) site results in the quickest recovery in the event of a
disaster?
(A) Hot
(B) Cold
(C) Passive
(D) Reserve" - ✔✔HOT
✔✔"Where should the location be for the final data backup repository in the event that
the disaster recovery plan is enacted for the CSP of disaster recovery (DR) service?
(A) Tape drive
(B) Local storage
(C) Cloud platform
(D) Company headquarters" - ✔✔Cloud platform
✔✔"Which technology should be included in the disaster recovery plan to prevent data
loss?
(A) Locked racks
(B) System patches
(C) Offsite backups
(D) Video surveillance" - ✔✔Offsite backups
✔✔"Which disaster recovery plan metric indicates how long critical functions can be
unavailable before the organization is irretrievably affected?
(A) Recovery time objective (RTO)
ANSWERS RATED A+
✔✔"Which risk is controlled by implementing a private cloud?
(A) Eavesdropping
(B) Physical security
(C) Unauthorized access
(D) Denial-of-service (DoS)" - ✔✔Physical security
✔✔"Which countermeasure enhances redundancy for physical facilities hosting cloud
equipment during the threat of a power outage?
(A) Tier 2 network access providers
(B) Multiple and independent power circuits to all racks
(C) Radio frequency interference (RFI) blocking devices
(D) Automated license plate readers (ALPR) at entry points" - ✔✔Multiple and
independent power circuits to all racks
✔✔"Which countermeasure helps mitigate the risk of stolen credentials for cloud-based
platforms?
(A) Host lockdown
(B) Data sanitization
(C) Key management
(D) Multifactor authentication" - ✔✔Multifactor authentication
✔✔"Which control helps mitigate the risk of sensitive information leaving the cloud
environment?
(A) Data loss prevention (DLP)
(B) Disaster recovery plan (DRP)
(C) Web application ?rewall (WAF)
(D) Identity and access management (IAM)" - ✔✔Data loss prevention (DLP)
✔✔"Which countermeasure mitigates the risk of a rogue cloud administrator?
(A) Data encryption
(B) Platform orchestration
(C) Logging and monitoring
(D) Multifactor authentication" - ✔✔Logging and monitoring
✔✔"Which consideration should be taken into account when reviewing a cloud service
provider's risk of potential outage time?
(A) The type of database
(B) The provider's support services
(C) The unique history of the provider
(D) The amount of cloud service offerings" - ✔✔The unique history of the provider
, ✔✔"Which cloud security control eliminates the risk of a virtualization guest escape from
another tenant?
(A) Dedicated hosting
(B) File integrity monitor
(C) Hardware hypervisor
(D) Immutable virtual machines" - ✔✔Dedicated hosting
✔✔"Which cloud security control is a countermeasure for man-in-the-middle attacks?
(A) Reviewing log data
(B) Backing up data offsite
(C) Using block data storage
(D) Encrypting data in transit" - ✔✔Encrypting data in transit
✔✔"Which data retention policy controls how long health insurance portability and
accountability act (HIPAA) data can be archived?
(A) Enforcement
(B) Maintenance
(C) Data classification
(D) Applicable regulation" - ✔✔Applicable regulation
✔✔"Which disaster recovery (DR) site results in the quickest recovery in the event of a
disaster?
(A) Hot
(B) Cold
(C) Passive
(D) Reserve" - ✔✔HOT
✔✔"Where should the location be for the final data backup repository in the event that
the disaster recovery plan is enacted for the CSP of disaster recovery (DR) service?
(A) Tape drive
(B) Local storage
(C) Cloud platform
(D) Company headquarters" - ✔✔Cloud platform
✔✔"Which technology should be included in the disaster recovery plan to prevent data
loss?
(A) Locked racks
(B) System patches
(C) Offsite backups
(D) Video surveillance" - ✔✔Offsite backups
✔✔"Which disaster recovery plan metric indicates how long critical functions can be
unavailable before the organization is irretrievably affected?
(A) Recovery time objective (RTO)