• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 22 pages
Exam (elaborations)

WGU PA D320 ACTUAL TEST||KEY EXAM QUESTIONS WITH CORRECT VERIFIED SOLUTIONS||A+ GRADED!!!UPDATED

Document preview thumbnail
Preview 3 out of 22 pages

WGU PA D320 ACTUAL TEST||KEY EXAM QUESTIONS WITH CORRECT VERIFIED SOLUTIONS||A+ GRADED!!!UPDATED 2025- 2026 1. Which type of management focuses on arranging all the elements needed to deploy new software, including QA testing and staging, before the software enters active maintenance? Availability management (AM) Release management (RM) Incident management (IM) Problem management (PM) - ANSWER Release management (RM) 2. A security analyst is tasked with collecting evidence related to a data breach involving monetary theft. Which action should the security analyst take when accessing the breached system? Create an unencrypted backup of all data Create an encrypted backup of all data Detail and replicate all activities taken Document and record all activities taken - ANSWER Document and record all activities taken 3. During an investigation, government agents asked a security professional to collect the records stored in a database and present them to the court. Which process should the security professional use to identify and obtain that information? Electronic communication Error correcting code (ECC) memory Cyclic redundancy check (CRC) Electronic discovery - ANSWER Electronic discovery 4. The service at a cloud provider has been interrupted. Which group should this cloud provider contact with information about the expected window for which the services will be down as per a contractual agreement? Customers Regulators Executives Employees - ANSWER Customers 5. An online store has declared a disaster situation because of a large storm in the area of its primary cloud data center location. The emergency plan has allowed the store to remain online and accept payments, but it has fallen out of compliance with its Payment Card Industry Data Security Standard (PCI DSS) practices. Which party should the store keep apprised of ongoing developments and the potential solutions being considered? Customers Developers Consumers Regulators - ANSWER Regulators 6. Which type of communication channel should be established between parties in a supply chain to be used in a disaster situation? Back Landline Satellite Secondary - ANSWER Secondary 7. An organization's engineers recently attended a training session designed to raise awareness of the dangers of using insecure direct object identifiers to view another user's account information. Which Open Web Application Security Project (OWASP) Top 10 vulnerability category did their training cover? Vulnerable and outdated components Identification and authentication failures Broken access control Security logging failures - ANSWER Broken access control 8. An organization's engineers recently attended a training session that raised their awareness of the dangers of using weak algorithms or protocols for data security. Which Open Web Application Security Project (OWASP) Top 10 vulnerability category did their training cover? Insecure design Hashing Sandboxing Cryptographic failures - ANSWER Cryptographic failures 9. A company plans to deploy a new application. Before the deployment, the company hires an IT security consultant to perform a zero-knowledge test to access the application as an external hacker would. Which testing technique applies to the work the consultant is performing? Black box White box Abuse case Static application - ANSWER Black box 10.Which concept refers to multiple teams and roles within an organization that perform testing on code from end to end to ensure that the code meets all standards and requirements? Quality assurance Identity assurance Full tests Tabletop tests - ANSWER Quality assurance 11.What is the purpose of implementing rate limiting in application programming interface (API) security? To reduce API response time To block unauthorized API access To prevent API overuse To increase API usage - ANSWER To prevent API overuse 12.An organization wants to ensure that untested software updates provided by a third-party vendor are not run in its mission-critical environment. What should the organization use in this scenario? Automatic updates Update notifications Update documentation Manual updates - ANSWER Manual updates 13.Which software development methodology is sequential, with each phase followed by the next phase and with no overlap between the phases? Scrum Lean Agile Waterfall - ANSWER Waterfall 14.Which phase of software design includes gathering customer input to determine a system's desired functionality? Ongoing operations Decommissioning Planning Requirements definition - ANSWER Requirements definition 15.Which technology is used to prevent cross-site request forgery (CSRF) attacks? Encoding Tokens Multifactor authentication (MFA) Identity-based encryption (IBE) - ANSWER Tokens 16.A project manager is working on a new software project for a customer. The project manager works closely with the customer to get input on the desired features and ranks them based on how critical they are for the project. Which phase of the software development life cycle (SDLC) is the project manager working on? Planning Requirements definition Development Ongoing operations - ANSWER Requirements definition 17.Which web application firewall (WAF) feature protects the application servers behind it from systems sending requests? Reverse proxy User-based filters Content-based filters Reverse IP lookup - ANSWER Reverse proxy 18.Which scheme would provide protection if an entire physical solid-state drive was lost or stolen? File-level encryption Transport Layer Security (TLS) Secure Socket Layer (SSL) Full-disk encryption - ANSWER Full-disk encryption 19.A small organization adopts a strategy to ensure that the cryptographic keys it uses in its cloud environment are securely stored and handled. Which third-party service should the organization leverage for key administration in the given scenario? Hardware security module (HSM) Cloud access security broker (CASB) Identity provider (IdP) Security information and event management (SIEM) - ANSWER Hardware security module (HSM) 20.An organization started the transition to using a public cloud service for a customer-facing application. The organization's security team has concerns about the application programming interface (API) tokens being lost or exposed to malicious actors. Which service do cloud providers offer that the organization should leverage to administer its API tokens? Secrets management Output encoding Gateway Sandbox - ANSWER Secrets management 21.What is the benefit of virtualization management tools with respect to the management plane? They provide insights into current bandwidth needs and traffic types. They allow more effective handling of resource demands. They protect cloud resources and data from threats and vulnerabilities. They enable the backup of data and applications. - ANSWER They allow more effective handling of resource demands. 22.Which component provides improved availability and path redundancy? Network interface card (NIC) teaming Virtual local area network (VLAN) Network access control list (NACL) Network security group (NSG) - ANSWER Network interface card (NIC) teaming 23.After an internal audit, an organization determined that its cloud deployment may be vulnerable to threats from external attackers. What should the organization implement to mitigate this risk? Hardened virtual machines with strong access controls Mandatory vacation and job rotation for employees Real-time video surveillance monitoring of physical access to devices USB-blocking software to prevent unauthorized devices from being used - ANSWER Hardened virtual machines with strong access controls 24.A group of colleges decided to pool their resources to create a community cloud. Which risk is associated with this type of cloud deployment? Proprietary data formats preventing data conversion A lack of compliance with relevant regulations Shared access and control mechanisms between members Decreased visibility of cloud performance and resource usage - ANSWER Shared access and control mechanisms between members 25.An organization believes that a man-in-the-middle attack is possible but unlikely to occur. However, if a successful attack occurs, the consequences will be serious. The cost estimate for reducing the risk of such an attack is much more than the organization wishes to pay. Which factor will determine whether the organization decides to pay the amount to mitigate the risk of an attack? Risk appetite Risk management Inherent risk Residual risk - ANSWER Risk appetite 26.Which tier of service is provided by a data center that is designed to have independent and physically isolated systems, multiple distribution paths, and fault tolerance for components? Tier 1 Tier 2 Tier 3 Tier 4 - ANSWER Tier 4 27.Which concept focuses on balancing virtual machines across clusters to ensure reliable and consistent performance? Ephemeral computing Distinct physical paths Distributed resource scheduling High availability - ANSWER Distributed resource scheduling 28.An organization exclusively uses Microsoft software and prefers to use tools that run natively on Windows whenever possible. Which tool should this organization use to provide remote access to machines over an encrypted channel? Remote Desktop Protocol (RDP) Secure Shell (SSH) Virtual clients Secure terminal access - ANSWER Remote Desktop Protocol (RDP) 29.An organization opens an office with a reception area. Visitors are required to sign in at the reception and collect a visitor's badge, which turns from white to red after eight hours. Which security concept is the organization employing? Controlled entry point Monitoring systems Vehicular approach controls Fire systems - ANSWER Controlled entry point 30.An organization wants to include a second factor of authentication in its authentication, authorization, and accounting scheme for its cloud environment. It wants to ensure that the additional authentication mechanism will not be compromised if an employee's laptop or smartphone is compromised. Which type of authentication token will meet the organization's requirements? Text messages with one-time passwords Applications such as password managers Hardware such as key fob devices Caller ID authe - ANSWER Hardware such as key fob devices 31.An organization deploying a greenfield cloud-based system wants to validate users' identities and access before they are allowed to interact with data. Which scheme should the organization leverage to ensure that users are properly validated? Security groups Zero trust Bastion hosts Traffic inspection - ANSWER Zero trust 32.An organization is taking part in a disaster recovery (DR) exercise that simulates a natural disaster. The key players are performing minimal actions that test the call tree to ensure that all the contact information is up to date. Which type of testing is the organization performing? Full Dry run Split Abuse case - ANSWER Dry run

Content preview

WGU PA D320 ACTUAL TEST||KEY
EXAM QUESTIONS WITH CORRECT
VERIFIED SOLUTIONS||A+
GRADED!!!<<UPDATED 2025-
2026>>


1. Which type of management focuses on arranging all the elements needed
to deploy new software, including QA testing and staging, before the
software enters active maintenance?

Availability management (AM)
Release management (RM)
Incident management (IM)
Problem management (PM) - ANSWER ✓ Release management (RM)

2. A security analyst is tasked with collecting evidence related to a data
breach involving monetary theft.
Which action should the security analyst take when accessing the breached
system?

Create an unencrypted backup of all data
Create an encrypted backup of all data
Detail and replicate all activities taken
Document and record all activities taken - ANSWER ✓ Document and record all
activities taken

3. During an investigation, government agents asked a security professional to
collect the records stored in a database and present them to the court.
Which process should the security professional use to identify and obtain
that information?

,Electronic communication
Error correcting code (ECC) memory
Cyclic redundancy check (CRC)
Electronic discovery - ANSWER ✓ Electronic discovery

4. The service at a cloud provider has been interrupted.
Which group should this cloud provider contact with information about the
expected window for which the services will be down as per a contractual
agreement?

Customers
Regulators
Executives
Employees - ANSWER ✓ Customers

5. An online store has declared a disaster situation because of a large storm in
the area of its primary cloud data center location. The emergency plan has
allowed the store to remain online and accept payments, but it has fallen
out of compliance with its Payment Card Industry Data Security Standard
(PCI DSS) practices.
Which party should the store keep apprised of ongoing developments and
the potential solutions being considered?

Customers
Developers
Consumers
Regulators - ANSWER ✓ Regulators

6. Which type of communication channel should be established between
parties in a supply chain to be used in a disaster situation?

Back
Landline
Satellite
Secondary - ANSWER ✓ Secondary

, 7. An organization's engineers recently attended a training session designed
to raise awareness of the dangers of using insecure direct object identifiers
to view another user's account information.
Which Open Web Application Security Project (OWASP) Top 10 vulnerability
category did their training cover?

Vulnerable and outdated components
Identification and authentication failures
Broken access control
Security logging failures - ANSWER ✓ Broken access control

8. An organization's engineers recently attended a training session that raised
their awareness of the dangers of using weak algorithms or protocols for
data security.
Which Open Web Application Security Project (OWASP) Top 10 vulnerability
category did their training cover?

Insecure design
Hashing
Sandboxing
Cryptographic failures - ANSWER ✓ Cryptographic failures

9. A company plans to deploy a new application. Before the deployment, the
company hires an IT security consultant to perform a zero-knowledge test
to access the application as an external hacker would.
Which testing technique applies to the work the consultant is performing?

Black box
White box
Abuse case
Static application - ANSWER ✓ Black box

10.Which concept refers to multiple teams and roles within an organization
that perform testing on code from end to end to ensure that the code
meets all standards and requirements?

Quality assurance

Document information

Uploaded on
June 26, 2025
Number of pages
22
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$13.29

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
SmartscoreAaron
3.1
(7)
Sold
90
Followers
6
Items
4131
Last sold
8 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions