WGU C838 MANAGING CLOUD SECURITY
ACTUAL OA FINAL EXAM LATEST 2023-
2026 QUESTIONS AND CORRECT DETAILED
ANSWERS (VERIFIED ANSWERS) ALREADY
GRADED A+ | QUESTIONS WITH
RATIONALES
QUESTION 1
You are the security subject matter expert (SME) for an organization considering a
transition from the legacy environment into a hosted cloud provider's data center.
One of the challenges you're facing is whether the cloud provider will be able to
comply with the existing legislative and contractual frameworks your organization
is required to follow. This is a ______ issue.
A. Resiliency
B. Privacy
C. Performance
D. Regulatory
Correct Answer: D. Regulatory
Rationale: This is a regulatory issue because the organization must ensure the
cloud provider can meet legislative and contractual requirements (e.g., GDPR,
HIPAA, PCI DSS). Regulatory compliance involves ensuring the provider can
adhere to laws and industry standards. Resiliency refers to disaster recovery,
privacy concerns data protection, and performance relates to service delivery
metrics.
QUESTION 2
You are the security subject matter expert (SME) for an organization considering a
transition from the legacy environment into a hosted cloud provider's data center.
,One of the challenges you're facing is whether the cloud provider will be able to
allow your organization to substantiate and determine with some assurance that all
of the contract terms are being met. This is a(n) ______ issue.
A. Regulatory
B. Privacy
C. Resiliency
D. Auditability
Correct Answer: D. Auditability
Rationale: This is an auditability issue because the organization needs to verify
that contract terms are being met through evidence and audit trails. Auditability
ensures that the cloud provider can provide logs, reports, and evidence of
compliance. Regulatory issues concern laws, privacy concerns data protection, and
resiliency concerns disaster recovery capabilities.
QUESTION 3
Encryption is an essential tool for affording security to cloud-based operations.
While it is possible to encrypt every system, piece of data, and transaction that
takes place on the cloud, why might that not be the optimum choice for an
organization?
A. Key length variances don't provide any actual additional security
B. It would cause additional processing overhead and time delay
C. It might result in vendor lockout
D. The data subjects might be upset by this
Correct Answer: B. It would cause additional processing overhead and time
delay
Rationale: Encrypting all data and transactions adds significant processing
overhead and latency, impacting performance. This is a cost-benefit decision
where the security benefit must be weighed against the operational impact. Not all
data requires encryption; sensitive data should be prioritized. Vendor lockout and
data subject concerns are not primary reasons to avoid encryption.
,QUESTION 4
Encryption is an essential tool for affording security to cloud-based operations.
While it is possible to encrypt every system, piece of data, and transaction that
takes place on the cloud, why might that not be the optimum choice for an
organization?
A. It could increase the possibility of physical theft
B. Encryption won't work throughout the environment
C. The protection might be disproportionate to the value of the asset(s)
D. Users will be able to see everything within the organization
Correct Answer: C. The protection might be disproportionate to the value of
the asset(s)
Rationale: Encryption adds overhead and cost that may be disproportionate to the
value of less sensitive data. Organizations should apply encryption based on data
classification and risk assessment. Encrypting all data regardless of value is
inefficient. Encryption does not increase theft risk, works throughout the
environment, and doesn't affect user visibility in this way.
QUESTION 5
Which of the following is NOT an element of the identification component of
identity and access management (IAM)?
A. Provisioning
B. Management
C. Discretion
D. Deprovisioning
Correct Answer: C. Discretion
Rationale: The identification component of IAM includes provisioning (creating
accounts), management (updating/overseeing accounts), and deprovisioning
(disabling/deleting accounts). "Discretion" is not a standard element of IAM
, identification. Discretionary access control (DAC) is a type of authorization, not
identification.
QUESTION 6
Which of the following entities is most likely to play a vital role in the identity
provisioning aspect of a user's experience in an organization?
A. The accounting department
B. The human resources (HR) office
C. The maintenance team
D. The purchasing office
Correct Answer: B. The human resources (HR) office
Rationale: HR is the primary entity responsible for initiating user identity
provisioning because they manage employee hiring, status changes, and
terminations. HR provides the trigger for creating, modifying, or deleting user
accounts. Accounting, maintenance, and purchasing are not typically involved in
identity provisioning.
QUESTION 7
Why is the deprovisioning element of the identification component of identity and
access management (IAM) so important?
A. Extra accounts cost so much extra money
B. Open but unassigned accounts are vulnerabilities
C. User tracking is essential to performance
D. Encryption has to be maintained
Correct Answer: B. Open but unassigned accounts are vulnerabilities
Rationale: Open but unassigned accounts (orphaned accounts) represent security
vulnerabilities because they can be exploited by attackers to gain unauthorized
access. Prompt deprovisioning of accounts when users leave the organization or
ACTUAL OA FINAL EXAM LATEST 2023-
2026 QUESTIONS AND CORRECT DETAILED
ANSWERS (VERIFIED ANSWERS) ALREADY
GRADED A+ | QUESTIONS WITH
RATIONALES
QUESTION 1
You are the security subject matter expert (SME) for an organization considering a
transition from the legacy environment into a hosted cloud provider's data center.
One of the challenges you're facing is whether the cloud provider will be able to
comply with the existing legislative and contractual frameworks your organization
is required to follow. This is a ______ issue.
A. Resiliency
B. Privacy
C. Performance
D. Regulatory
Correct Answer: D. Regulatory
Rationale: This is a regulatory issue because the organization must ensure the
cloud provider can meet legislative and contractual requirements (e.g., GDPR,
HIPAA, PCI DSS). Regulatory compliance involves ensuring the provider can
adhere to laws and industry standards. Resiliency refers to disaster recovery,
privacy concerns data protection, and performance relates to service delivery
metrics.
QUESTION 2
You are the security subject matter expert (SME) for an organization considering a
transition from the legacy environment into a hosted cloud provider's data center.
,One of the challenges you're facing is whether the cloud provider will be able to
allow your organization to substantiate and determine with some assurance that all
of the contract terms are being met. This is a(n) ______ issue.
A. Regulatory
B. Privacy
C. Resiliency
D. Auditability
Correct Answer: D. Auditability
Rationale: This is an auditability issue because the organization needs to verify
that contract terms are being met through evidence and audit trails. Auditability
ensures that the cloud provider can provide logs, reports, and evidence of
compliance. Regulatory issues concern laws, privacy concerns data protection, and
resiliency concerns disaster recovery capabilities.
QUESTION 3
Encryption is an essential tool for affording security to cloud-based operations.
While it is possible to encrypt every system, piece of data, and transaction that
takes place on the cloud, why might that not be the optimum choice for an
organization?
A. Key length variances don't provide any actual additional security
B. It would cause additional processing overhead and time delay
C. It might result in vendor lockout
D. The data subjects might be upset by this
Correct Answer: B. It would cause additional processing overhead and time
delay
Rationale: Encrypting all data and transactions adds significant processing
overhead and latency, impacting performance. This is a cost-benefit decision
where the security benefit must be weighed against the operational impact. Not all
data requires encryption; sensitive data should be prioritized. Vendor lockout and
data subject concerns are not primary reasons to avoid encryption.
,QUESTION 4
Encryption is an essential tool for affording security to cloud-based operations.
While it is possible to encrypt every system, piece of data, and transaction that
takes place on the cloud, why might that not be the optimum choice for an
organization?
A. It could increase the possibility of physical theft
B. Encryption won't work throughout the environment
C. The protection might be disproportionate to the value of the asset(s)
D. Users will be able to see everything within the organization
Correct Answer: C. The protection might be disproportionate to the value of
the asset(s)
Rationale: Encryption adds overhead and cost that may be disproportionate to the
value of less sensitive data. Organizations should apply encryption based on data
classification and risk assessment. Encrypting all data regardless of value is
inefficient. Encryption does not increase theft risk, works throughout the
environment, and doesn't affect user visibility in this way.
QUESTION 5
Which of the following is NOT an element of the identification component of
identity and access management (IAM)?
A. Provisioning
B. Management
C. Discretion
D. Deprovisioning
Correct Answer: C. Discretion
Rationale: The identification component of IAM includes provisioning (creating
accounts), management (updating/overseeing accounts), and deprovisioning
(disabling/deleting accounts). "Discretion" is not a standard element of IAM
, identification. Discretionary access control (DAC) is a type of authorization, not
identification.
QUESTION 6
Which of the following entities is most likely to play a vital role in the identity
provisioning aspect of a user's experience in an organization?
A. The accounting department
B. The human resources (HR) office
C. The maintenance team
D. The purchasing office
Correct Answer: B. The human resources (HR) office
Rationale: HR is the primary entity responsible for initiating user identity
provisioning because they manage employee hiring, status changes, and
terminations. HR provides the trigger for creating, modifying, or deleting user
accounts. Accounting, maintenance, and purchasing are not typically involved in
identity provisioning.
QUESTION 7
Why is the deprovisioning element of the identification component of identity and
access management (IAM) so important?
A. Extra accounts cost so much extra money
B. Open but unassigned accounts are vulnerabilities
C. User tracking is essential to performance
D. Encryption has to be maintained
Correct Answer: B. Open but unassigned accounts are vulnerabilities
Rationale: Open but unassigned accounts (orphaned accounts) represent security
vulnerabilities because they can be exploited by attackers to gain unauthorized
access. Prompt deprovisioning of accounts when users leave the organization or