WGU D315 QUESTIONS AND ANSWERS SURE A+
✔✔Audit Logs - ✔✔Detailed records of actions taken within a cloud system for
accountability and security monitoring
✔✔Private Cloud - ✔✔Scalable, single-tenant cluster of computing, storage, and
networking resources owned and maintained by a single company
✔✔Public Cloud - ✔✔Hosted by companies like AWS, Azure, and GCP, offering
scalable, multi-tenant solutions in data centers
✔✔Hybrid Cloud - ✔✔Combination of services running in both public and private clouds
✔✔Federated identity management - ✔✔Authentication service using identity servers at
Google, Facebook, etc.
✔✔Token - ✔✔Special value sent by federated identity services to identify a user
✔✔Access control - ✔✔Determining who has access to data and to what degree
✔✔Least privilege - ✔✔Assigning users the minimum access required
, ✔✔Group permissions - ✔✔Assigning permissions to groups instead of individual user
accounts
✔✔Internal security authorization controls - ✔✔Using file server permissions assigned
to users or groups in Active Directory
✔✔Public clouds - ✔✔Cloud storage locations with integrated authentication and
authorization systems
✔✔Private clouds - ✔✔Cloud storage locations with internal security authorization
controls
✔✔Hybrid cloud environments - ✔✔Combination of public and private clouds with
standardized IAM configuration
✔✔Network security - ✔✔Protecting servers from attacks and managing cloud-based
servers
✔✔Public-facing servers - ✔✔Servers accessible on the internet and exposed to attacks
✔✔Isolation - ✔✔Minimizing damage by hosting public-facing servers in a separate
environment
✔✔Extranet - ✔✔Secured region of a private network with firewalls and intrusion
prevention systems
✔✔Operating system firewall - ✔✔Configured firewall on servers to protect against
attacks
✔✔Layers of security - ✔✔Adding multiple barriers to protect against breaches
✔✔VPN - ✔✔Virtual private network for secure remote server management
✔✔WAN - ✔✔Wide area network for dedicated connection to public cloud provider
✔✔Data at rest - ✔✔Data stored on servers or storage hardware
✔✔Data encryption at rest - ✔✔Encrypting data stored on servers or storage hardware
✔✔Physical safeguard - ✔✔Protection of data even if server is stolen
✔✔Data encryption key (DEK) - ✔✔Key used to encrypt and decrypt data at rest
✔✔Key rotation - ✔✔Regularly changing the data encryption key
✔✔Audit Logs - ✔✔Detailed records of actions taken within a cloud system for
accountability and security monitoring
✔✔Private Cloud - ✔✔Scalable, single-tenant cluster of computing, storage, and
networking resources owned and maintained by a single company
✔✔Public Cloud - ✔✔Hosted by companies like AWS, Azure, and GCP, offering
scalable, multi-tenant solutions in data centers
✔✔Hybrid Cloud - ✔✔Combination of services running in both public and private clouds
✔✔Federated identity management - ✔✔Authentication service using identity servers at
Google, Facebook, etc.
✔✔Token - ✔✔Special value sent by federated identity services to identify a user
✔✔Access control - ✔✔Determining who has access to data and to what degree
✔✔Least privilege - ✔✔Assigning users the minimum access required
, ✔✔Group permissions - ✔✔Assigning permissions to groups instead of individual user
accounts
✔✔Internal security authorization controls - ✔✔Using file server permissions assigned
to users or groups in Active Directory
✔✔Public clouds - ✔✔Cloud storage locations with integrated authentication and
authorization systems
✔✔Private clouds - ✔✔Cloud storage locations with internal security authorization
controls
✔✔Hybrid cloud environments - ✔✔Combination of public and private clouds with
standardized IAM configuration
✔✔Network security - ✔✔Protecting servers from attacks and managing cloud-based
servers
✔✔Public-facing servers - ✔✔Servers accessible on the internet and exposed to attacks
✔✔Isolation - ✔✔Minimizing damage by hosting public-facing servers in a separate
environment
✔✔Extranet - ✔✔Secured region of a private network with firewalls and intrusion
prevention systems
✔✔Operating system firewall - ✔✔Configured firewall on servers to protect against
attacks
✔✔Layers of security - ✔✔Adding multiple barriers to protect against breaches
✔✔VPN - ✔✔Virtual private network for secure remote server management
✔✔WAN - ✔✔Wide area network for dedicated connection to public cloud provider
✔✔Data at rest - ✔✔Data stored on servers or storage hardware
✔✔Data encryption at rest - ✔✔Encrypting data stored on servers or storage hardware
✔✔Physical safeguard - ✔✔Protection of data even if server is stolen
✔✔Data encryption key (DEK) - ✔✔Key used to encrypt and decrypt data at rest
✔✔Key rotation - ✔✔Regularly changing the data encryption key