WGU D320 CORRECT TEST PAPER QUESTIONS
AND ANSWERS SURE A+
✔✔Zero-Day Vulnerability - ✔✔- Unknown vulnerability that has yet been found and a
patch released
✔✔SOC Report - ✔✔- part of the SSSAE reporting format created by the AICPA.
Designed for compliance with the Sarbanes-Oxley Act
✔✔ISO/IEC 27034-1 - ✔✔Standards for Secure Application Development - Provides an
overview of application security.
✔✔Organization Normative Framework (ONF) - ✔✔- framework for all components of
application security controls and best practices
✔✔Application Normative Frameworks (ANF) - ✔✔- subset of the ONF for each specific
application.
✔✔Transport Layer Security (TLS) - ✔✔- Protocol designed to ensure privacy when
communicating between applications
✔✔Secure Socket Layer (SSL) - ✔✔- used to encrypt data transmissions between two
endpoints. Deprecated in 2015 and replaced with TLS
✔✔Whole-Instance Encryption - ✔✔- whole-disk encryption
✔✔Volume Encryption - ✔✔- Only encrypts a partition on a hard drive instead of the
whole disk
✔✔Cross-Site Scripting (XSS) - ✔✔- when an application allows untrusted data to be
sent to a web browser without proper validation or escaping
, ✔✔Injection - ✔✔- malicious user attempts to inject a string of some type into a field in
order to manipulate the application's actions to reveal unauthorized data. SQL, LDAP,
or OS injections
✔✔Cross-Site Request Forgery (CSRF) - ✔✔- manipulates a logged-on user's browser
to send a forged HTTP request along with cookies to generate a request that a
vulnerable application thinks is legitimate
✔✔White-Box Testing (Static Application Security Testing (SAST)) - ✔✔- reviewing the
source code
✔✔Black-Box Testing (Dynamic Application Security Testing (DAST)) - ✔✔- testing the
program functions, in runtime.
✔✔API - ✔✔- used to allow other applications to consume web services from the
application.
✔✔Nonrepudiation - ✔✔- no party to a transaction can later claim that they did not take
part.
✔✔ISO 31000 - ✔✔2018: - is an international standard that focuses on designing,
implementing, and reviewing risk management processes and practices ions in the
United States
✔✔NIST SP 800-37 - ✔✔is the Guide for Implementing the Risk Management
Framework (RMF).
✔✔The CSA STAR program - ✔✔, initiated in 2011, was created in response to market
demand for a single consistent framework for evaluating cloud providers
✔✔Metered Access - ✔✔Cloud systems automatically control and optimize resource
use by leveraging capability at some level of abstraction appropriate to the type of
service (e.g., storage, processing, bandwidth, and active user accounts). Resource
usage can be monitored, controlled, and reported, providing transparency for both the
provider and consumer of the utilized service.
✔✔On-demand self-service - ✔✔Consumer can unilaterally provision computing
capabilities as needed automatically
✔✔Resource Pooling - ✔✔The provider's computing resources are combined to serve
multiple consumers using a multi-tenant model, with different physical and virtual
resources dynamically assigned and reassigned according to consumer demand
AND ANSWERS SURE A+
✔✔Zero-Day Vulnerability - ✔✔- Unknown vulnerability that has yet been found and a
patch released
✔✔SOC Report - ✔✔- part of the SSSAE reporting format created by the AICPA.
Designed for compliance with the Sarbanes-Oxley Act
✔✔ISO/IEC 27034-1 - ✔✔Standards for Secure Application Development - Provides an
overview of application security.
✔✔Organization Normative Framework (ONF) - ✔✔- framework for all components of
application security controls and best practices
✔✔Application Normative Frameworks (ANF) - ✔✔- subset of the ONF for each specific
application.
✔✔Transport Layer Security (TLS) - ✔✔- Protocol designed to ensure privacy when
communicating between applications
✔✔Secure Socket Layer (SSL) - ✔✔- used to encrypt data transmissions between two
endpoints. Deprecated in 2015 and replaced with TLS
✔✔Whole-Instance Encryption - ✔✔- whole-disk encryption
✔✔Volume Encryption - ✔✔- Only encrypts a partition on a hard drive instead of the
whole disk
✔✔Cross-Site Scripting (XSS) - ✔✔- when an application allows untrusted data to be
sent to a web browser without proper validation or escaping
, ✔✔Injection - ✔✔- malicious user attempts to inject a string of some type into a field in
order to manipulate the application's actions to reveal unauthorized data. SQL, LDAP,
or OS injections
✔✔Cross-Site Request Forgery (CSRF) - ✔✔- manipulates a logged-on user's browser
to send a forged HTTP request along with cookies to generate a request that a
vulnerable application thinks is legitimate
✔✔White-Box Testing (Static Application Security Testing (SAST)) - ✔✔- reviewing the
source code
✔✔Black-Box Testing (Dynamic Application Security Testing (DAST)) - ✔✔- testing the
program functions, in runtime.
✔✔API - ✔✔- used to allow other applications to consume web services from the
application.
✔✔Nonrepudiation - ✔✔- no party to a transaction can later claim that they did not take
part.
✔✔ISO 31000 - ✔✔2018: - is an international standard that focuses on designing,
implementing, and reviewing risk management processes and practices ions in the
United States
✔✔NIST SP 800-37 - ✔✔is the Guide for Implementing the Risk Management
Framework (RMF).
✔✔The CSA STAR program - ✔✔, initiated in 2011, was created in response to market
demand for a single consistent framework for evaluating cloud providers
✔✔Metered Access - ✔✔Cloud systems automatically control and optimize resource
use by leveraging capability at some level of abstraction appropriate to the type of
service (e.g., storage, processing, bandwidth, and active user accounts). Resource
usage can be monitored, controlled, and reported, providing transparency for both the
provider and consumer of the utilized service.
✔✔On-demand self-service - ✔✔Consumer can unilaterally provision computing
capabilities as needed automatically
✔✔Resource Pooling - ✔✔The provider's computing resources are combined to serve
multiple consumers using a multi-tenant model, with different physical and virtual
resources dynamically assigned and reassigned according to consumer demand