Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 35 pages
Exam (elaborations)

WGU C838 Managing Cloud Security – Advanced Practice Exam & Study Guide (2025 Updated) Document 6: WGU C838 Managing Cloud Security – Advanced Practice Exam & Study Guide

Document preview thumbnail
Preview 4 out of 35 pages

WGU C838 Managing Cloud Security – Advanced Practice Exam & Study Guide (2025 Updated) Document 6: WGU C838 Managing Cloud Security – Advanced Practice Exam & Study Guide

Content preview

WGU C838 Managing Cloud Security – Advanced
Practice Exam & Study Guide (2025 Updated)
Document 6: WGU C838 Managing Cloud Security
– Advanced Practice Exam & Study Guide
Instructions: This comprehensive practice exam contains 150 questions covering advanced cloud
security concepts, including governance, compliance, risk management, and technical controls across
IaaS, PaaS, and SaaS. Select the best answer. Answers are in bold and rationales are in italic.



1. In the Shared Responsibility Model for IaaS, which security control is the customer's responsibility?
A) Physical security of data centers
B) Hypervisor security
C) Guest operating system patching
D) Network infrastructure security
Answer: C
Rationale: Under the IaaS shared responsibility model, the customer is responsible for securing the guest
operating system, applications, and data they deploy. The provider secures the physical infrastructure,
network, and hypervisor.



2. Which of the following is the primary purpose of a Cloud Access Security Broker (CASB)?
A) To provide encryption for cloud storage
B) To act as a security policy enforcement point between users and cloud providers
C) To manage cloud infrastructure provisioning
D) To monitor cloud billing and cost optimization
Answer: B
Rationale: A CASB serves as a security policy enforcement point that sits between cloud consumers and
providers, providing visibility, compliance, data security, and threat protection across multiple cloud
services.



3. What does the "A" in the CSA CCM (Cloud Controls Matrix) stand for?
A) Assessment
B) Architecture
C) Assurance
D) Accountability
Answer: C
Rationale: The CSA Cloud Controls Matrix (CCM) provides a framework for cloud security assurance. It is
a detailed list of controls designed to help organizations assess the security of cloud providers.

,4. Which of the following is a key risk associated with cloud vendor lock-in?
A) Increased security posture
B) Reduced operational costs
C) Difficulty migrating to another provider
D) Simplified compliance management
Answer: C
Rationale: Vendor lock-in creates dependency on a specific provider's APIs, services, and data formats,
making it costly and complex to migrate to another provider or back to on-premises infrastructure.



5. In cloud computing, what is "Data Sovereignty"?
A) The right to use data in any country
B) Data being subject to the laws of the country where it is physically stored
C) The ability to delete data at any time
D) The right to encrypt all data
Answer: B
Rationale: Data sovereignty is a legal concept that states data is subject to the laws and governance
structures of the country or jurisdiction in which it is physically located, impacting storage decisions.



6. Which of the following is a primary benefit of implementing Zero Trust in cloud environments?
A) Simplifies network management
B) Assumes all users are trustworthy
C) Minimizes lateral movement of threats
D) Eliminates the need for encryption
Answer: C
Rationale: Zero Trust's "never trust, always verify" principle, combined with micro-segmentation,
significantly reduces an attacker's ability to move laterally within the network after gaining initial access.



7. What is the responsibility of the customer in the SaaS Shared Responsibility Model?
A) Securing the underlying infrastructure
B) Patching the application
C) Securing their data and managing user access
D) Managing the hypervisor
Answer: C
Rationale: In SaaS, the provider is responsible for virtually everything (infrastructure, platform,
application). The customer's primary security responsibilities are securing their own data, managing user
identity and access, and configuring application security settings.

,8. Which cloud service model provides the highest level of customer control?
A) SaaS
B) PaaS
C) IaaS
D) FaaS
Answer: C
Rationale: IaaS gives customers the most control, as they manage the operating systems, middleware,
data, and applications. PaaS offers less control, and SaaS offers the least.



9. What is the purpose of a Service Level Agreement (SLA) in cloud contracts?
A) To define the pricing model
B) To specify performance and availability commitments
C) To outline the customer's security responsibilities
D) To define the data classification scheme
Answer: B
Rationale: An SLA defines the level of service expected, including metrics like uptime availability,
performance, and support response times, providing a contractual commitment from the provider.



10. Which of the following is a common cloud-specific supply chain risk?
A) Physical theft of hardware
B) Dependency on the provider's third-party components
C) Social engineering against employees
D) Malware on user endpoints
Answer: B
Rationale: Cloud providers rely on complex supply chains of third-party vendors for hardware, software,
and services. A compromise at any point in this chain can affect the security of the cloud service.



11. What is the purpose of data classification in the cloud?
A) To reduce storage costs
B) To organize data for better searchability
C) To determine sensitivity and apply appropriate security controls
D) To comply with naming conventions
Answer: C
Rationale: Data classification categorizes data based on its sensitivity, regulatory requirements, and
value, dictating the security controls (encryption, access, retention) that must be applied.



12. In cloud networking, what is a Virtual Private Cloud (VPC)?
A) A physical network segment
B) A logically isolated section of the cloud provider's network
C) A type of VPN connection

, D) A public network accessible to all users
Answer: B
Rationale: A VPC is a virtual network dedicated to a single customer within a public cloud, providing
logical isolation and allowing the customer to define their own IP address ranges, subnets, and routing.



13. What is the primary risk of Shadow IT in cloud environments?
A) Increased IT costs
B) Bypassing security and compliance controls
C) Improved employee productivity
D) Reduced cloud usage
Answer: B
Rationale: Shadow IT refers to the use of unauthorized cloud services without IT/security oversight. This
creates blind spots and bypasses established security policies, data governance, and compliance controls.



14. Which of the following is a key component of Cloud Governance?
A) Allowing all users to create any cloud resource
B) Defining and enforcing policies for resource provisioning and compliance
C) Using only one cloud provider
D) Eliminating all security controls
Answer: B
Rationale: Cloud governance involves establishing policies, procedures, and controls to manage cloud
usage, including resource provisioning, security, compliance, and cost management.



15. What is the primary purpose of Identity Federation in cloud security?
A) To create a single account for all users
B) To enable single sign-on across multiple organizations using a single set of credentials
C) To simplify password management
D) To provide backup for user accounts
Answer: B
Rationale: Identity federation allows organizations to establish trust relationships, enabling users to
authenticate once with their own identity provider and access resources in other federated
organizations.



16. In cloud security, what does "CASB" stand for?
A) Cloud Application Security Bridge
B) Cloud Access Security Broker
C) Centralized Authentication Security Base
D) Compliance and Security Audit Bureau
Answer: B

Document information

Uploaded on
August 2, 2026
Number of pages
35
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$75.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
TUTORJUNIOUR
3.0
(1)
Sold
2
Followers
0
Items
1297
Last sold
3 weeks ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions