WGU D320 CORRECT ALL QUESTIONS AND
ANSWERS SURE A+
✔✔31: Conducts Risk Management
Which of the following is a key consideration when conducting a Business Impact
Analysis (BIA) - ✔✔A. Identifying regulatory compliance requirements
B. Determining the criticality of business functions
C. Establishing risk appetite
D. Developing disaster recovery plans
Correct Answer: B. Determining the criticality of business functions
Explanation: A BIA is focused on determining the criticality of business functions to
prioritize recovery efforts. Regulatory compliance, risk appetite, and disaster recovery
are related but are not the primary focus of a BIA.
✔✔32: Identifies Legal, Compliance, and Ethical Concerns
Which of the following laws requires organizations to safeguard the personal information
of customers and notify them in the event of a data breach - ✔✔A. GDPR
B. HIPAA
C. SOX
D. CCPA
Correct Answer: D. CCPA
Explanation: The California Consumer Privacy Act (CCPA) requires organizations to
protect personal information and notify customers in the event of a breach. GDPR is a
broader European regulation, HIPAA focuses on health information, and SOX
addresses corporate financial practices.
✔✔33: Implements Secure Solutions
Which cloud security measure involves isolating applications and data from each other
within the same cloud environment - ✔✔A. Multi-Factor Authentication
B. Virtual Private Cloud (VPC)
C. Containerization
D. Encryption
Correct Answer: C. Containerization
,Explanation: Containerization isolates applications and their dependencies in separate
containers, providing security and preventing interference. A VPC isolates network
traffic, MFA strengthens user authentication, and Encryption protects data but doesn't
isolate it within the environment.
✔✔34: Implements Operations
Which of the following tools is most commonly used for monitoring and logging cloud
environments - ✔✔A. Puppet
B. Ansible
C. Nagios
D. Git
Correct Answer: C. Nagios
Explanation: Nagios is widely used for monitoring and logging in cloud environments.
Puppet and Ansible are primarily configuration management tools, and Git is used for
version control.
✔✔35: Conducts Risk Management
Which risk response strategy focuses on reducing the likelihood or impact of a risk
through preventive measures - ✔✔A. Risk Avoidance
B. Risk Mitigation
C. Risk Acceptance
D. Risk Transfer
Correct Answer: B. Risk Mitigation
Explanation: Risk Mitigation involves taking steps to reduce the likelihood or impact of a
risk. Risk Avoidance involves eliminating the risk, Risk Acceptance involves accepting
the risk without action, and Risk Transfer shifts the risk to another party.
✔✔36: Identifies Legal, Compliance, and Ethical Concerns
Which of the following is a primary consideration for cloud service providers in ensuring
compliance with data protection regulations - ✔✔A. Data Encryption
B. Data Localization
C. Multi-Factor Authentication
D. Virtualization
Correct Answer: B. Data Localization
Explanation: Data Localization refers to storing data within specific geographical
boundaries to comply with local data protection laws. Encryption and MFA are security
measures, and Virtualization is a technology, but Data Localization is directly tied to
compliance.
✔✔37: Implements Secure Solutions
Which security mechanism is used to ensure that an individual is who they claim to be
before granting access to cloud resources - ✔✔A. Authorization
B. Authentication
C. Encryption
D. Auditing
, Correct Answer: B. Authentication
Explanation: Authentication verifies the identity of a user before granting access to
cloud resources. Authorization determines what resources the user can access,
Encryption protects data, and Auditing tracks and records access and activity.
✔✔38: Implements Operations
Which type of cloud service is most likely to require ongoing patch management by the
customer - ✔✔A. Software as a Service (SaaS)
B. Platform as a Service (PaaS)
C. Infrastructure as a Service (IaaS)
D. Containers as a Service (CaaS)
Correct Answer: C. Infrastructure as a Service (IaaS)
Explanation: In IaaS, the customer is responsible for managing the operating system,
including patch management. In SaaS and PaaS, the cloud provider handles most of
the patching responsibilities, while CaaS involves managing containers, which may still
require some level of patching by the customer.
✔✔39: Conducts Risk Management
Which risk management approach is used when the cost of mitigation is higher than the
potential impact of the risk - ✔✔A. Risk Avoidance
B. Risk Acceptance
C. Risk Transference
D. Risk Mitigation
Correct Answer: B. Risk Acceptance
Explanation: Risk Acceptance is chosen when the cost of mitigating the risk exceeds
the potential impact, meaning the organization decides to accept the risk without further
action. Risk Avoidance eliminates the risk, Risk Transference shifts it, and Risk
Mitigation reduces it.
✔✔40: Identifies Legal, Compliance, and Ethical Concerns
Which of the following international regulations focuses on cross-border data transfers
and the protection of personal data - ✔✔A. GDPR
B. HIPAA
C. SOX
D. CCPA
Correct Answer: A. GDPR
Explanation: The General Data Protection Regulation (GDPR) focuses on the protection
of personal data and governs cross-border data transfers within the EU and beyond.
HIPAA, SOX, and CCPA have different focuses, such as health information, financial
transparency, and consumer privacy in California.
✔✔41: Implements Secure Solutions
Which technology is most effective for protecting data at rest in a cloud storage
environment - ✔✔A. SSL/TLS
B. VPN
ANSWERS SURE A+
✔✔31: Conducts Risk Management
Which of the following is a key consideration when conducting a Business Impact
Analysis (BIA) - ✔✔A. Identifying regulatory compliance requirements
B. Determining the criticality of business functions
C. Establishing risk appetite
D. Developing disaster recovery plans
Correct Answer: B. Determining the criticality of business functions
Explanation: A BIA is focused on determining the criticality of business functions to
prioritize recovery efforts. Regulatory compliance, risk appetite, and disaster recovery
are related but are not the primary focus of a BIA.
✔✔32: Identifies Legal, Compliance, and Ethical Concerns
Which of the following laws requires organizations to safeguard the personal information
of customers and notify them in the event of a data breach - ✔✔A. GDPR
B. HIPAA
C. SOX
D. CCPA
Correct Answer: D. CCPA
Explanation: The California Consumer Privacy Act (CCPA) requires organizations to
protect personal information and notify customers in the event of a breach. GDPR is a
broader European regulation, HIPAA focuses on health information, and SOX
addresses corporate financial practices.
✔✔33: Implements Secure Solutions
Which cloud security measure involves isolating applications and data from each other
within the same cloud environment - ✔✔A. Multi-Factor Authentication
B. Virtual Private Cloud (VPC)
C. Containerization
D. Encryption
Correct Answer: C. Containerization
,Explanation: Containerization isolates applications and their dependencies in separate
containers, providing security and preventing interference. A VPC isolates network
traffic, MFA strengthens user authentication, and Encryption protects data but doesn't
isolate it within the environment.
✔✔34: Implements Operations
Which of the following tools is most commonly used for monitoring and logging cloud
environments - ✔✔A. Puppet
B. Ansible
C. Nagios
D. Git
Correct Answer: C. Nagios
Explanation: Nagios is widely used for monitoring and logging in cloud environments.
Puppet and Ansible are primarily configuration management tools, and Git is used for
version control.
✔✔35: Conducts Risk Management
Which risk response strategy focuses on reducing the likelihood or impact of a risk
through preventive measures - ✔✔A. Risk Avoidance
B. Risk Mitigation
C. Risk Acceptance
D. Risk Transfer
Correct Answer: B. Risk Mitigation
Explanation: Risk Mitigation involves taking steps to reduce the likelihood or impact of a
risk. Risk Avoidance involves eliminating the risk, Risk Acceptance involves accepting
the risk without action, and Risk Transfer shifts the risk to another party.
✔✔36: Identifies Legal, Compliance, and Ethical Concerns
Which of the following is a primary consideration for cloud service providers in ensuring
compliance with data protection regulations - ✔✔A. Data Encryption
B. Data Localization
C. Multi-Factor Authentication
D. Virtualization
Correct Answer: B. Data Localization
Explanation: Data Localization refers to storing data within specific geographical
boundaries to comply with local data protection laws. Encryption and MFA are security
measures, and Virtualization is a technology, but Data Localization is directly tied to
compliance.
✔✔37: Implements Secure Solutions
Which security mechanism is used to ensure that an individual is who they claim to be
before granting access to cloud resources - ✔✔A. Authorization
B. Authentication
C. Encryption
D. Auditing
, Correct Answer: B. Authentication
Explanation: Authentication verifies the identity of a user before granting access to
cloud resources. Authorization determines what resources the user can access,
Encryption protects data, and Auditing tracks and records access and activity.
✔✔38: Implements Operations
Which type of cloud service is most likely to require ongoing patch management by the
customer - ✔✔A. Software as a Service (SaaS)
B. Platform as a Service (PaaS)
C. Infrastructure as a Service (IaaS)
D. Containers as a Service (CaaS)
Correct Answer: C. Infrastructure as a Service (IaaS)
Explanation: In IaaS, the customer is responsible for managing the operating system,
including patch management. In SaaS and PaaS, the cloud provider handles most of
the patching responsibilities, while CaaS involves managing containers, which may still
require some level of patching by the customer.
✔✔39: Conducts Risk Management
Which risk management approach is used when the cost of mitigation is higher than the
potential impact of the risk - ✔✔A. Risk Avoidance
B. Risk Acceptance
C. Risk Transference
D. Risk Mitigation
Correct Answer: B. Risk Acceptance
Explanation: Risk Acceptance is chosen when the cost of mitigating the risk exceeds
the potential impact, meaning the organization decides to accept the risk without further
action. Risk Avoidance eliminates the risk, Risk Transference shifts it, and Risk
Mitigation reduces it.
✔✔40: Identifies Legal, Compliance, and Ethical Concerns
Which of the following international regulations focuses on cross-border data transfers
and the protection of personal data - ✔✔A. GDPR
B. HIPAA
C. SOX
D. CCPA
Correct Answer: A. GDPR
Explanation: The General Data Protection Regulation (GDPR) focuses on the protection
of personal data and governs cross-border data transfers within the EU and beyond.
HIPAA, SOX, and CCPA have different focuses, such as health information, financial
transparency, and consumer privacy in California.
✔✔41: Implements Secure Solutions
Which technology is most effective for protecting data at rest in a cloud storage
environment - ✔✔A. SSL/TLS
B. VPN