Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 10 pages
Exam (elaborations)

WGU C838 Managing Cloud Security Final Exam OA Questions, Answers and Rationales 2027

Document preview thumbnail
Preview 2 out of 10 pages

Study resource designed for WGU C838 – Managing Cloud Security Objective Assessment (OA). Includes exam-style practice questions, verified answers, and detailed rationales covering cloud architecture, shared responsibility model, cloud deployment and service models, identity and access management, encryption, key management, cloud data lifecycle, virtualization, containers, application security, cloud security operations, logging and monitoring, disaster recovery, business continuity, incident response, governance, risk management, compliance, legal frameworks, security controls, and best practices aligned with CCSP concepts. Organized to reinforce cloud security knowledge and support preparation for the WGU C838 Objective Assessment. The course focuses on designing secure cloud solutions that maintain confidentiality, integrity, and availability of information assets.

Content preview

WGU C838 MANAGING CLOUD SECURITY FINAL EXAM OA 100
QUESTIONS AND ANSWERS LATEST 2027|
AGRADE

You are the security subject matter expert (SME) f ̣or an organization considering a transition from ̣ the legacy environment into a hosted cloud provider 's data center. One of ̣ the challenges
you 're f ̣acing is whether the cloud provider will be able to comply with the existing legislative and contractual frameworks
̣ your organization is required to follow.
̣ This is a issue.

a. Resiliency
b. Privacy
c. Perf ̣ormance
d. Regulatory
D
76. You are the security subject matter expert (SME) f ̣or an organization considering a transition from ̣ the legacy environ ment into a hosted cloud provider 's data center. One of ̣ the
challenges you 're f ̣acing is whether the cloud provider will be able to allow your organization to substantiate and determine with some assurance that all of ̣ the contract terms are being met.
This is a(n)
issue.
a. Regulatory
b. Privacy
c. Resiliency
d. Auditability
D
77. Encryption is an essential tool f ̣or af ̣f ̣ording security to cloud-based operations. While it is possible to encrypt every system, piece of ̣ data, and transaction that takes place on the cloud,
why might that not be the optimum choice f ̣or an organization?
a. K ey length variances don 't provide any actual additional security.
b. It would cause additional processing overhead and time delay.
c. It might result in vendor lockout.
d. The data subjects might be upset by this.
B
78. Encryption is an essential tool f ̣or af ̣f ̣ording security to cloud-based operations. While it is possible to encrypt every system, piece of ̣ data, and transaction that takes place on the cloud,
why might that not be the optimum choice f ̣or an organization?
a. It could increase the possibility of ̣ physical thef ̣t.
b. Encryption won 't work throughout the environment.
c. The protection might be disproportionate to the value of ̣ the asset(s).
d. Users will be able to see everything within the organization.
C
79. Which of ̣ the f ̣ollowing is not an element of ̣ the identif ̣ication component of ̣ identity and access management (IAM)?
a. Provisioning
b. Management
c. Discretion
d. Deprovisioning
C
80. Which of ̣ the f ̣ollowing entities is most likely to play a vital role in the identity provisioning aspect of ̣ a user 's experience in an organization?
a. The accounting department
b. The human resources (HR) of ̣f ̣ice
c. The maintenance team
d. The purchasing of ̣f ̣ice
B
81. Why is the deprovisioning element of ̣ the identif ̣ication component of ̣ identity and access management (IAM) so important?
a. Extra accounts cost so much extra money.
b. Open but unassigned accounts are vulnerabilities.
c. User tracking is essential to perf ̣ormance.
d. Encryption has to be
maintained. B
82. All of ̣ the f ̣ollowing are reasons to perf ̣orm review and maintenance actions on user accounts except .
a. To determine whether the user still needs the same access
b. To determine whether the user is still with the organization
c. To determine whether the data set is still applicable to the user 's role
d. To determine whether the user is still perf ̣orming well
D
83. Who should be involved in review and maintenance of ̣ user
accounts/access?
a. The user 's manager
b. The security manager
c. The accounting department
d. The incident response team
A
84. Which of ̣ the f ̣ollowing protocols is most applicable to the identif ̣ication process aspect of ̣ identity and access management (IAM)?
a. Secure Sockets Layer (SSL)
b. Internet Protocol security (IPsec)
c. Lightweight Directory Access Protocol (LDAP)
d. Amorphous ancillary data transmission (AADT)
C
85. Privileged user (administrators, managers, and so f ̣orth) accounts need to be reviewed more closely than basic user accounts. Why is this?
a. Privileged users have more encryption keys.
b. Regular users are more trustworthy.
c. There are extra controls on privileged user accounts.
d. Privileged users can cause more damage to the
organization. D
86. The additional review activities that might be perf ̣ormed f ̣or privileged user accounts could include all of ̣ the following
̣ except .
a. Deeper personnel background checks
b. Review of ̣ personal f ̣inancial accounts f ̣or privileged users
c. More f ̣requent reviews of ̣ the necessity f ̣or access
d. Pat-down checks of ̣ privileged users to deter against physical
thef ̣t D
87. If ̣ personal f ̣inancial account reviews are perf ̣ormed as an additional review control for ̣ privileged users, which of ̣ the following
̣ characteristics is least likely to be a useful
̣ indicator for
̣
review purposes?
a. Too much money in the account
b. Too little money in the account
c. The bank branch being used by the privileged user
d. Specif ̣ic senders/recipients
C
88. How of ̣ten should the accounts of ̣ privileged users be reviewed?
a. Annually
b. Twice a year
c. Monthly
d. More of ̣ten than regular user account
reviews D
89. Privileged user account access should be .
a. Temporary
b. Pervasive
c. Thorough
d. Granular
A

, WGU C838 MANAGING CLOUD SECURITY FINAL EXAM OA 100
QUESTIONS AND ANSWERS LATEST 2027|
AGRADE

90. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of ̣ common threats to organizations participating in cloud computing. According to the CSA 's Notorious Nine list,
data breaches can be .
a. Overt or covert
b. International or subterranean
c. From internal or external sources
d. Voluminous or specif ̣ic
C
91. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of ̣ common threats to organizations participating i n cloud computing. According to the CSA, an organization
that operates in the cloud environment and suf ̣f ̣ers a data breach may be required to .
a. Notif ̣y af ̣f ̣ected users
b. Reapply f ̣or cloud service
c. Scrub all af ̣f ̣ected physical memory
d. Change regulatory f ̣rameworks
A
92. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of ̣ common threats to organizations participating in cloud computing. According to the CSA, an organization
that suf ̣fers
̣ a data breach might suf ̣f ̣er all of ̣ the following
̣ negative ef ̣f ̣ects except .
a. Cost of ̣ compliance with notif ̣ication laws
b. Loss of ̣ public perception/goodwill
c. Loss of ̣ market share
d. Cost of ̣ detection
D
93. The Cloud Security Alliance (CSA) publishes, the Notorious Nine, a list of ̣ common threats to organizations participating in cloud computing. According to the CSA, in the event of ̣ a
data breach, a cloud customer will likely need to comply with all the f ̣ollowing data breach notification ̣ requirements except .
a. Multiple state laws
b. Contractual notif ̣ication requirements
c. All standards-based notif ̣ication schemes
d. Any applicable f ̣ederal
regulations C
94. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of ̣ common threats to organizations participating i n cloud computing. According to the CSA, data loss can be
suf ̣fered
̣ as a result of ̣ activity.
a. Malicious or inadvertent
b. Casual or explicit
c. Web-based or stand-alone
d. Managed or
independent A
95. The Cloud Security Alliance (CSA) publishes, the Notorious Nine, a list of ̣ common threats to organizations participating in cloud computing. According to the CSA, all of ̣ the following ̣
activity can result in data loss except .
a. Misplaced crypto keys
b. Improper policy
c. Inef ̣f ̣ectual backup procedures
d. Accidental overwrite
B
96. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of ̣ common threats to organizations participating i n cloud computing. According to the CSA, service traff̣ ic ̣ high
jacking can af ̣fect ̣ all of ̣ the f ̣ollowing portions of ̣ the CIA triad except .
a. Conf ̣identiality
b. Integrity
c. Availability
d. None. Service traf ̣f ̣ic high jacking can 't af ̣f ̣ect any portion of ̣ the CIA
triad. D
97. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of ̣ common threats to organizatio ns participating in cloud computing. The CSA recommends the prohibition of ̣
in order to diminish the likelihood of ̣ account/service traf ̣f ̣ic high jacking.
a. All user activity
b. Sharing account credentials between users and services
c. Multif ̣actor authentication
d. Interstate commerce
B
98. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of ̣ common threats to organizations participating i n cloud computing. According to the CSA, which aspect of ̣
cloud computing makes it particularly susceptible to account/service traf ̣f ̣ic high jacking?
a. Scalability
b. Metered service
c. Remote access
d. Pooled resources
C
99. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of ̣ common threats to organizations participating i n cloud computing. According to the CSA, what is one reason
the threat of ̣ insecure interf ̣aces and APIs is so prevalent in cloud computing?
a. Most of ̣ the cloud customer 's interaction with resources will be perf ̣ormed through APIs.
b. APIs are inherently insecure.
c. Attackers have already published vulnerabilities f ̣or all known APIs.
d. APIs are known
carcinogens. A/B
100. .The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of ̣ common threats to organizations participating in cloud computing. According to the CSA, what is one reason
the threat of ̣ insecure interf ̣aces and APIs is so prevalent in cloud computing?
a. Cloud customers and third parties are continually enhancing and modif ̣ying APIs.
b. APIs can have automated settings.
c. It is impossible to uninstall APIs.
d. APIs are a f ̣orm of ̣ malware.
A
75. Sof ̣tware developers should receive cloud-specif ̣ic training that highlights the specific ̣ challenges involved with having a production environment that operates in the cloud. One of ̣
these challenges is .
a. Lack of ̣ management oversight
b. Additional workload in creating governance f ̣or two environments (the cloud data center and client devices)
c. Increased threat of ̣ malware
d. The need f ̣or process isolation
D
76. Which security technique is most pref ̣erable when creating a limited functionality ̣ for
̣ customer service personnel to review account data related to sales made to your clientele?
a. Anonymization
b. Masking
c. Encryption
d. Training
B
77. At which phase of ̣ the sof ̣tware development lif ̣e cycle (SDLC) is user involvement most crucial?
a. Def ̣ine
b. Design
c. Develop
d. Test
A
78. At which phase of ̣ the SDLC should security personnel f ̣irst be involved?
a. Def ̣ine

Document information

Uploaded on
July 21, 2026
Number of pages
10
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NABELLA
5.0
(4)
Sold
9
Followers
2
Items
1031
Last sold
22 hours ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions