SITUATIONAL ANALYSIS
Questions 1 – 150 + And 100% Correct
Answers 2026/2027 A+ Grade
1. What is the primary reason SWBTL LLC is migrating to the Microsoft Azure cloud
environment?
A) To reduce employee headcount
B) To comply with international data protection laws only
C) Due to costs, poor server availability, and cybersecurity concerns with its
leased data centers
D) To eliminate all on-premises infrastructure
Rationale: SWBTL LLC is transitioning to Microsoft's Azure cloud environment due to
escalating costs, service interruptions, and cybersecurity vulnerabilities with its existing
leased data centers . The company's growth has outpaced the capabilities of its legacy
infrastructure.
2. What event triggered the urgent need for a cloud security assessment at SWBTL
LLC?
A) A major data breach
B) An audit failure
C) The abrupt departure of the migration consultant without proper
documentation
D) A ransomware attack
Rationale: The consultant hired to manage the migration unexpectedly quit, leaving the
Azure environment with serious security gaps and no documentation. Data was exposed
,across teams, backups were unverified, and vulnerability scanning boundaries had not been
checked for two years .
3. Which compliance frameworks must SWBTL LLC adhere to based on its business
requirements?
A) HIPAA and SOX
B) GDPR and GLBA
C) FISMA and PCI DSS
D) ISO 27001 and SOC 2
Rationale: SWBTL LLC must comply with the Federal Information Security Modernization
Act (FISMA) due to its contracts with the U.S. government, and the Payment Card Industry
Data Security Standard (PCI DSS) because it processes a large volume of payment card
transactions daily .
4. What is the purpose of FISMA compliance for SWBTL LLC?
A) To secure healthcare information
B) To protect financial privacy
C) To maintain strong cybersecurity practices for federal data and contractors
D) To ensure environmental compliance
Rationale: FISMA requires federal agencies and contractors to maintain strong
cybersecurity practices, including continuous monitoring, risk assessments, security
controls, and secure information handling. SWBTL's government contracts make FISMA
compliance mandatory .
5. What is the purpose of PCI DSS compliance for SWBTL LLC?
A) To protect health information
B) To secure payment card information through encryption, access control,
and vulnerability assessments
, C) To ensure financial reporting accuracy
D) To protect intellectual property
Rationale: PCI DSS focuses on securing payment card information and requires companies
to maintain a secure environment through firewalls, encryption, access controls, and regular
vulnerability assessments .
6. Which regulatory assessment is SWBTL LLC preparing for in addition to FISMA
and PCI DSS?
A) ISO 27001 certification
B) NIST SP 800-53 assessment
C) SOC 2 Type II audit
D) GDPR compliance review
Rationale: SWBTL LLC's contractual obligations with the U.S. government and upcoming
NIST SP 800-53 assessment have driven the need for a secure cloud transition . NIST SP
800-53 provides security controls for federal information systems.
7. What specific security concerns did senior leadership identify as priorities for
SWBTL LLC?
A) Compliance, encryption of data at rest and in transit, proper RBAC, and
backup/recovery integrity
B) Employee training and hiring
C) Office space expansion
D) Marketing strategies
Rationale: The business requirements document identifies four main concerns: regulatory
compliance, encryption of data at rest and in transit, proper role-based access controls, and
integrity of backup and recovery systems .
8. What is the current state of file and system backups at SWBTL LLC?
, A) Backups are configured and verified daily
B) Backups have not been verified since the cloud was first implemented
C) Backups are not performed at all
D) Backups are only performed for the IT department
Rationale: Administrators have been unable to verify file and system backups since the
cloud was first implemented. The previous consultant left without completing configuration
of backup verification procedures .
9. What issue exists with vulnerability scanning boundaries in SWBTL LLC's Azure
environment?
A) They are configured but not monitored
B) They have not been validated in years and likely don't encompass the Azure
instance
C) They are only applied to on-premises resources
D) They are automatically updated
Rationale: Vulnerability scanning boundaries have remained unchecked for over two years,
potentially exposing the Azure instance to threats. This creates significant security gaps .
10. What is the goal of the cloud security implementation plan for SWBTL LLC?
A) To reduce IT staff
B) To migrate all applications to the cloud
C) To strengthen the company's cloud environment and bring it up to industry
security standards
D) To eliminate all security risks
Rationale: The implementation plan aims to bring SWBTL LLC's Azure environment into line
with business requirements, strengthen security posture, and ensure compliance with
regulations .