WGU D320 STUDY EXAMS GUIDE ALL QUESTIONS
AND ANSWERS SURE A+
✔✔IPSec - ✔✔Protocol suite securing IP communications at the network layer. Used in
VPNs. Includes AH (Authentication Header) and ESP (Encapsulating Security Payload).
✔✔HSM (Hardware Security Module) - ✔✔Physical device that manages and protects
cryptographic keys. Tamper-resistant. Preferred for key management in cloud
environments.
✔✔Crypto-Shredding - ✔✔Destroying the encryption key to render data permanently
unrecoverable. Preferred destruction method in cloud environments.
✔✔PKI (Public Key Infrastructure) - ✔✔Framework for managing digital certificates and
public-key encryption. Includes CAs (Certificate Authorities), certificates, and revocation
(CRL/OCSP).
✔✔Hashing - ✔✔One-way transformation used for integrity verification, not encryption.
SHA-256 and SHA-3 are current standards. MD5 and SHA-1 are deprecated.
✔✔Secret Lifecycle - ✔✔The four stages of a cryptographic secret: Creation > Rotation
> Revocation > Expiration.
✔✔Key Management Best Practice - ✔✔Never store crypto keys with the cloud
provider. Use CASB or dedicated KMS. Follow the secret lifecycle.
✔✔Type 1 Hypervisor (Bare Metal) - ✔✔Runs directly on physical hardware. No
underlying OS. Examples: VMware ESXi, Microsoft Hyper-V, Xen. More secure and
performant.
✔✔Type 2 Hypervisor (Hosted) - ✔✔Runs on top of an existing OS. Examples: VMware
Workstation, VirtualBox. Less secure due to host OS dependency.
, ✔✔VM Escape - ✔✔Attack where a VM breaks out of its isolated environment and
accesses the hypervisor or other VMs on the same physical host. Critical cloud threat.
✔✔VM Sprawl - ✔✔Uncontrolled proliferation of unused VMs still running. Increases
attack surface and resource waste.
✔✔Ephemeral Computing - ✔✔Infrastructure temporary by design — spun up for a task
and destroyed when done. Security must be baked into the image before deployment.
✔✔SAST (Static Application Security Testing) - ✔✔Analyzes source code or binaries
without executing the application. White-box testing. Used before deployment during
development. Finds issues early.
✔✔DAST (Dynamic Application Security Testing) - ✔✔Tests the running application
from the outside. Black-box — no source code needed. Used during or after deployment
at runtime.
✔✔IAST (Interactive Application Security Testing) - ✔✔Agents inside the application
monitor behavior during execution. Combines SAST and DAST. Used during
testing/runtime.
✔✔SCA (Software Composition Analysis) - ✔✔Scans third-party and open-source
dependencies for known CVEs. Used during development. Tools: Snyk, Dependabot.
✔✔High Availability (HA) - ✔✔Designing systems to remain operational with minimal
downtime through redundancy and failover. 99.9% = ~8.7 hrs downtime/year. 99.99% =
~52 min/year.
✔✔RTO (Recovery Time Objective) - ✔✔Maximum acceptable time to restore a system
after a disruption. How fast you need to recover.
✔✔RPO (Recovery Point Objective) - ✔✔Maximum acceptable amount of data loss
measured in time. How much data you can afford to lose.
✔✔Distributed Resource Scheduling - ✔✔Automatically balances workloads across
physical hosts based on CPU/memory utilization. VMware DRS is the classic example.
✔✔Distinct Physical Paths - ✔✔Separate independent physical network routes
eliminating single points of failure. Essential for HA and DR.
✔✔Cloud Data Lifecycle — Create Phase - ✔✔Data classification and categorization
happen here — data owner's responsibility. Encrypt before uploading via IPSec or TLS
VPN.
AND ANSWERS SURE A+
✔✔IPSec - ✔✔Protocol suite securing IP communications at the network layer. Used in
VPNs. Includes AH (Authentication Header) and ESP (Encapsulating Security Payload).
✔✔HSM (Hardware Security Module) - ✔✔Physical device that manages and protects
cryptographic keys. Tamper-resistant. Preferred for key management in cloud
environments.
✔✔Crypto-Shredding - ✔✔Destroying the encryption key to render data permanently
unrecoverable. Preferred destruction method in cloud environments.
✔✔PKI (Public Key Infrastructure) - ✔✔Framework for managing digital certificates and
public-key encryption. Includes CAs (Certificate Authorities), certificates, and revocation
(CRL/OCSP).
✔✔Hashing - ✔✔One-way transformation used for integrity verification, not encryption.
SHA-256 and SHA-3 are current standards. MD5 and SHA-1 are deprecated.
✔✔Secret Lifecycle - ✔✔The four stages of a cryptographic secret: Creation > Rotation
> Revocation > Expiration.
✔✔Key Management Best Practice - ✔✔Never store crypto keys with the cloud
provider. Use CASB or dedicated KMS. Follow the secret lifecycle.
✔✔Type 1 Hypervisor (Bare Metal) - ✔✔Runs directly on physical hardware. No
underlying OS. Examples: VMware ESXi, Microsoft Hyper-V, Xen. More secure and
performant.
✔✔Type 2 Hypervisor (Hosted) - ✔✔Runs on top of an existing OS. Examples: VMware
Workstation, VirtualBox. Less secure due to host OS dependency.
, ✔✔VM Escape - ✔✔Attack where a VM breaks out of its isolated environment and
accesses the hypervisor or other VMs on the same physical host. Critical cloud threat.
✔✔VM Sprawl - ✔✔Uncontrolled proliferation of unused VMs still running. Increases
attack surface and resource waste.
✔✔Ephemeral Computing - ✔✔Infrastructure temporary by design — spun up for a task
and destroyed when done. Security must be baked into the image before deployment.
✔✔SAST (Static Application Security Testing) - ✔✔Analyzes source code or binaries
without executing the application. White-box testing. Used before deployment during
development. Finds issues early.
✔✔DAST (Dynamic Application Security Testing) - ✔✔Tests the running application
from the outside. Black-box — no source code needed. Used during or after deployment
at runtime.
✔✔IAST (Interactive Application Security Testing) - ✔✔Agents inside the application
monitor behavior during execution. Combines SAST and DAST. Used during
testing/runtime.
✔✔SCA (Software Composition Analysis) - ✔✔Scans third-party and open-source
dependencies for known CVEs. Used during development. Tools: Snyk, Dependabot.
✔✔High Availability (HA) - ✔✔Designing systems to remain operational with minimal
downtime through redundancy and failover. 99.9% = ~8.7 hrs downtime/year. 99.99% =
~52 min/year.
✔✔RTO (Recovery Time Objective) - ✔✔Maximum acceptable time to restore a system
after a disruption. How fast you need to recover.
✔✔RPO (Recovery Point Objective) - ✔✔Maximum acceptable amount of data loss
measured in time. How much data you can afford to lose.
✔✔Distributed Resource Scheduling - ✔✔Automatically balances workloads across
physical hosts based on CPU/memory utilization. VMware DRS is the classic example.
✔✔Distinct Physical Paths - ✔✔Separate independent physical network routes
eliminating single points of failure. Essential for HA and DR.
✔✔Cloud Data Lifecycle — Create Phase - ✔✔Data classification and categorization
happen here — data owner's responsibility. Encrypt before uploading via IPSec or TLS
VPN.