WGU E025 Objective Assessment (OA) | 70 Scenario-Based Cloud Security
Questions with Verified Answers and Rationales | 2026 Update | 100% Correct.
Cloud Security Fundamentals and Architecture
Question 1
A company migrates an internally developed database application from its data center to virtual
machines in a public IaaS environment. A vulnerability is later discovered in the database
operating system.
Who is primarily responsible for installing the operating-system security patch?
A. Cloud provider
B. Customer
C. Database vendor only
D. Internet service provider
Correct answer: B. Customer
Rationale: In IaaS, the provider secures physical facilities, hardware, networking, and the
virtualization layer. The customer normally manages guest operating systems, applications,
identities, configurations, and data.
Question 2
A development team deploys an application using a managed PaaS offering. Which component
is typically secured and patched by the cloud provider?
A. Application source code
B. User-access permissions
C. Underlying runtime environment
D. Customer data classification
Correct answer: C. Underlying runtime environment
Rationale: In PaaS, the provider generally manages the infrastructure, operating system,
middleware, and runtime. The customer remains responsible for application code, data,
identities, and access configuration.
Question 3
,An organization adopts a SaaS customer-relationship management system. Which responsibility
ordinarily remains with the customer?
A. Securing the provider’s data center
B. Patching the hypervisor
C. Configuring user access and data-sharing permissions
D. Replacing failed storage devices
Correct answer: C. Configuring user access and data-sharing permissions
Rationale: SaaS transfers most technical infrastructure responsibilities to the provider, but the
customer must still govern accounts, permissions, data classification, and secure use of the
service.
Question 4
A company’s cloud storage bucket containing customer records becomes publicly accessible.
The cloud platform functioned as designed, but an administrator incorrectly enabled anonymous
access.
Which concept best explains the incident?
A. Provider hardware failure
B. Customer-side cloud misconfiguration
C. Hypervisor escape
D. Vendor lock-in
Correct answer: B. Customer-side cloud misconfiguration
Rationale: The customer is responsible for securely configuring the cloud resources it uses. A
service can operate correctly while exposing data because of an unsafe customer configuration.
Question 5
A business requires complete control of operating-system versions, host-based security software,
and database installation settings. Which cloud service model is most appropriate?
A. SaaS
B. PaaS
C. IaaS
D. Business process as a service
,Correct answer: C. IaaS
Rationale: IaaS provides the greatest customer control over guest operating systems,
applications, and virtual networking while the provider manages the physical infrastructure and
virtualization layer.
Question 6
A security architect wants to reduce the organization’s responsibility for operating-system
patching while allowing developers to deploy custom application code.
Which service model best meets this requirement?
A. On-premises infrastructure
B. IaaS
C. PaaS
D. Colocation
Correct answer: C. PaaS
Rationale: PaaS lets developers manage application code and data while the provider manages
the operating system, middleware, runtime, and infrastructure.
Question 7
A company uses services from two public cloud providers to reduce dependence on one vendor.
Which deployment strategy is this?
A. Private cloud
B. Community cloud
C. Multi-cloud
D. Edge computing
Correct answer: C. Multi-cloud
Rationale: Multi-cloud means using services from more than one cloud provider. A hybrid cloud
specifically integrates private or on-premises resources with public-cloud resources.
Question 8
, An organization connects its private data center to a public cloud and distributes workloads
across both environments.
Which architecture is being used?
A. SaaS
B. Hybrid cloud
C. Community cloud
D. Single-tenant public cloud
Correct answer: B. Hybrid cloud
Rationale: A hybrid cloud combines and integrates private or on-premises infrastructure with
public-cloud services.
Question 9
A regulated organization must keep sensitive workloads on dedicated infrastructure while
retaining cloud automation and self-service capabilities.
Which deployment model is most suitable?
A. Public cloud
B. Private cloud
C. Multi-cloud only
D. Unmanaged hosting
Correct answer: B. Private cloud
Rationale: A private cloud provides cloud-like automation and elasticity on infrastructure
dedicated to one organization.
Question 10
A company wants to verify that its cloud provider maintains appropriate physical and
environmental security controls.
Which document would provide the most relevant independent assurance?
A. Source-code repository
B. SOC audit report
Questions with Verified Answers and Rationales | 2026 Update | 100% Correct.
Cloud Security Fundamentals and Architecture
Question 1
A company migrates an internally developed database application from its data center to virtual
machines in a public IaaS environment. A vulnerability is later discovered in the database
operating system.
Who is primarily responsible for installing the operating-system security patch?
A. Cloud provider
B. Customer
C. Database vendor only
D. Internet service provider
Correct answer: B. Customer
Rationale: In IaaS, the provider secures physical facilities, hardware, networking, and the
virtualization layer. The customer normally manages guest operating systems, applications,
identities, configurations, and data.
Question 2
A development team deploys an application using a managed PaaS offering. Which component
is typically secured and patched by the cloud provider?
A. Application source code
B. User-access permissions
C. Underlying runtime environment
D. Customer data classification
Correct answer: C. Underlying runtime environment
Rationale: In PaaS, the provider generally manages the infrastructure, operating system,
middleware, and runtime. The customer remains responsible for application code, data,
identities, and access configuration.
Question 3
,An organization adopts a SaaS customer-relationship management system. Which responsibility
ordinarily remains with the customer?
A. Securing the provider’s data center
B. Patching the hypervisor
C. Configuring user access and data-sharing permissions
D. Replacing failed storage devices
Correct answer: C. Configuring user access and data-sharing permissions
Rationale: SaaS transfers most technical infrastructure responsibilities to the provider, but the
customer must still govern accounts, permissions, data classification, and secure use of the
service.
Question 4
A company’s cloud storage bucket containing customer records becomes publicly accessible.
The cloud platform functioned as designed, but an administrator incorrectly enabled anonymous
access.
Which concept best explains the incident?
A. Provider hardware failure
B. Customer-side cloud misconfiguration
C. Hypervisor escape
D. Vendor lock-in
Correct answer: B. Customer-side cloud misconfiguration
Rationale: The customer is responsible for securely configuring the cloud resources it uses. A
service can operate correctly while exposing data because of an unsafe customer configuration.
Question 5
A business requires complete control of operating-system versions, host-based security software,
and database installation settings. Which cloud service model is most appropriate?
A. SaaS
B. PaaS
C. IaaS
D. Business process as a service
,Correct answer: C. IaaS
Rationale: IaaS provides the greatest customer control over guest operating systems,
applications, and virtual networking while the provider manages the physical infrastructure and
virtualization layer.
Question 6
A security architect wants to reduce the organization’s responsibility for operating-system
patching while allowing developers to deploy custom application code.
Which service model best meets this requirement?
A. On-premises infrastructure
B. IaaS
C. PaaS
D. Colocation
Correct answer: C. PaaS
Rationale: PaaS lets developers manage application code and data while the provider manages
the operating system, middleware, runtime, and infrastructure.
Question 7
A company uses services from two public cloud providers to reduce dependence on one vendor.
Which deployment strategy is this?
A. Private cloud
B. Community cloud
C. Multi-cloud
D. Edge computing
Correct answer: C. Multi-cloud
Rationale: Multi-cloud means using services from more than one cloud provider. A hybrid cloud
specifically integrates private or on-premises resources with public-cloud resources.
Question 8
, An organization connects its private data center to a public cloud and distributes workloads
across both environments.
Which architecture is being used?
A. SaaS
B. Hybrid cloud
C. Community cloud
D. Single-tenant public cloud
Correct answer: B. Hybrid cloud
Rationale: A hybrid cloud combines and integrates private or on-premises infrastructure with
public-cloud services.
Question 9
A regulated organization must keep sensitive workloads on dedicated infrastructure while
retaining cloud automation and self-service capabilities.
Which deployment model is most suitable?
A. Public cloud
B. Private cloud
C. Multi-cloud only
D. Unmanaged hosting
Correct answer: B. Private cloud
Rationale: A private cloud provides cloud-like automation and elasticity on infrastructure
dedicated to one organization.
Question 10
A company wants to verify that its cloud provider maintains appropriate physical and
environmental security controls.
Which document would provide the most relevant independent assurance?
A. Source-code repository
B. SOC audit report