WGU D320 MANAGING CLOUD SECURITY
(JYO2) 80-QUESTION ACTUAL EXAM
PRACTICE TEST QUESTIONS AND CORRECT
ANSWERS (VERIFIED ANSWERS) PLUS
RATIONALES 2026/2027 Q&A | INSTANT
DOWNLOAD PDF.
Core Domains
• Cloud Computing Concepts, Service Models, and Deployment
Models
• Shared Responsibility Model and Cloud Security Architecture
• Data Lifecycle Management, Data Classification, and Privacy
• Identity and Access Management (IAM) and Federation
• Compliance, Legal, and Regulatory Frameworks (GDPR,
HIPAA, PCI DSS, FedRAMP, GLBA)
• Risk Management (Qualitative, Quantitative, Risk Treatment)
• Business Continuity and Disaster Recovery (BIA, RPO, RTO)
• Cloud Security Operations (Change Management, Incident
Response, Monitoring)
• Infrastructure as Code, DevSecOps, and Automation
• Encryption and Key Management
• Network Security (Zero Trust, VPNs, Firewalls, Segmentation)
Introduction
This comprehensive practice examination is designed to assess the
candidate's knowledge, analytical reasoning, and decision-making
skills essential for the WGU D320 Managing Cloud Security (JYO2)
Objective Assessment. The exam covers foundational principles of
cloud computing, shared responsibility, data protection, identity
and access management, compliance frameworks, risk
management, and business continuity. It integrates regulatory
standards with a strong emphasis on practical, manager-level
decision-making. Through 80 multiple-choice questions and
realistic scenarios, this assessment evaluates the candidate's ability
to apply theoretical knowledge to real-world cloud security
, situations, ensuring they are prepared for the demands of the WGU
D320 objective assessment. The content aligns with the WGU D320
course curriculum, the (ISC)² CCSP Common Body of Knowledge,
and the 2026/2027 exam objectives.
Section One: Questions 1–80
Question 1
Which cloud characteristic allows customers to rapidly provision
computing resources without requiring human interaction from the
service provider?
A. Broad network access
B. Measured service
C. Resource pooling
D. On-demand self-service
D. On-demand self-service
RATIONALE: On-demand self-service enables users to provision
computing capabilities automatically whenever needed without direct
interaction with the provider. This is one of the five essential cloud
computing characteristics defined by NIST.
Question 2
Which cloud service model gives customers the MOST responsibility for
managing operating systems and applications?
A. SaaS (Software as a Service)
B. PaaS (Platform as a Service)
C. IaaS (Infrastructure as a Service)
D. FaaS (Function as a Service)
C. IaaS (Infrastructure as a Service)
RATIONALE: In Infrastructure as a Service (IaaS), customers manage
operating systems, middleware, applications, and data, while the cloud
provider manages physical infrastructure. This gives the customer the
most control and responsibility.
,Question 3
What is the PRIMARY purpose of data classification in cloud security?
A. Reduce storage costs
B. Improve internet bandwidth
C. Determine appropriate security controls
D. Eliminate the need for encryption
C. Determine appropriate security controls
RATIONALE: Data classification identifies the sensitivity and value of
data so organizations can apply suitable protections such as encryption,
access controls, and retention requirements.
Question 4
In the AWS Shared Responsibility Model, which of the following is the
customer's responsibility when using Amazon EC2?
A. Physical security of data centers
B. Patching the underlying hypervisor
C. Operating system security patching and firewall configuration
D. Ensuring power and cooling for infrastructure
C. Operating system security patching and firewall configuration
RATIONALE: Under the AWS Shared Responsibility Model, when
using IaaS like EC2, AWS manages security of the cloud (physical
infrastructure, hypervisor, network), while the customer is responsible
for security in the cloud, including operating system patching,
application security, data encryption, and firewall configuration.
Question 5
Which encryption method protects data while it is being processed in
memory by a cloud application?
A. Data at rest encryption
B. Data in transit encryption
, C. Confidential computing / encryption in use
D. Tokenization
C. Confidential computing / encryption in use
RATIONALE: Confidential computing, also known as encryption in
use, protects data while it is being processed in memory using
hardware-based trusted execution environments (TEEs), ensuring that
data and code are isolated and encrypted even from the cloud
provider's hypervisor and operating system.
Question 6
Which cloud deployment model provides the highest level of control
and security for an organization with strict compliance requirements?
A. Public cloud
B. Private cloud
C. Community cloud
D. Hybrid cloud
B. Private cloud
RATIONALE: A private cloud deployment model provides dedicated
infrastructure for a single organization, offering the highest level of
control over security configurations, physical infrastructure, and
compliance implementations, making it ideal for organizations with strict
regulatory requirements.
Question 7
A security team needs to implement least privilege access across
multiple AWS accounts. Which AWS service enables centralized
management of permissions and policies?
A. AWS IAM basic edition
B. AWS Organizations with AWS IAM Identity Center (SSO)
C. Amazon CloudWatch
D. AWS Config
(JYO2) 80-QUESTION ACTUAL EXAM
PRACTICE TEST QUESTIONS AND CORRECT
ANSWERS (VERIFIED ANSWERS) PLUS
RATIONALES 2026/2027 Q&A | INSTANT
DOWNLOAD PDF.
Core Domains
• Cloud Computing Concepts, Service Models, and Deployment
Models
• Shared Responsibility Model and Cloud Security Architecture
• Data Lifecycle Management, Data Classification, and Privacy
• Identity and Access Management (IAM) and Federation
• Compliance, Legal, and Regulatory Frameworks (GDPR,
HIPAA, PCI DSS, FedRAMP, GLBA)
• Risk Management (Qualitative, Quantitative, Risk Treatment)
• Business Continuity and Disaster Recovery (BIA, RPO, RTO)
• Cloud Security Operations (Change Management, Incident
Response, Monitoring)
• Infrastructure as Code, DevSecOps, and Automation
• Encryption and Key Management
• Network Security (Zero Trust, VPNs, Firewalls, Segmentation)
Introduction
This comprehensive practice examination is designed to assess the
candidate's knowledge, analytical reasoning, and decision-making
skills essential for the WGU D320 Managing Cloud Security (JYO2)
Objective Assessment. The exam covers foundational principles of
cloud computing, shared responsibility, data protection, identity
and access management, compliance frameworks, risk
management, and business continuity. It integrates regulatory
standards with a strong emphasis on practical, manager-level
decision-making. Through 80 multiple-choice questions and
realistic scenarios, this assessment evaluates the candidate's ability
to apply theoretical knowledge to real-world cloud security
, situations, ensuring they are prepared for the demands of the WGU
D320 objective assessment. The content aligns with the WGU D320
course curriculum, the (ISC)² CCSP Common Body of Knowledge,
and the 2026/2027 exam objectives.
Section One: Questions 1–80
Question 1
Which cloud characteristic allows customers to rapidly provision
computing resources without requiring human interaction from the
service provider?
A. Broad network access
B. Measured service
C. Resource pooling
D. On-demand self-service
D. On-demand self-service
RATIONALE: On-demand self-service enables users to provision
computing capabilities automatically whenever needed without direct
interaction with the provider. This is one of the five essential cloud
computing characteristics defined by NIST.
Question 2
Which cloud service model gives customers the MOST responsibility for
managing operating systems and applications?
A. SaaS (Software as a Service)
B. PaaS (Platform as a Service)
C. IaaS (Infrastructure as a Service)
D. FaaS (Function as a Service)
C. IaaS (Infrastructure as a Service)
RATIONALE: In Infrastructure as a Service (IaaS), customers manage
operating systems, middleware, applications, and data, while the cloud
provider manages physical infrastructure. This gives the customer the
most control and responsibility.
,Question 3
What is the PRIMARY purpose of data classification in cloud security?
A. Reduce storage costs
B. Improve internet bandwidth
C. Determine appropriate security controls
D. Eliminate the need for encryption
C. Determine appropriate security controls
RATIONALE: Data classification identifies the sensitivity and value of
data so organizations can apply suitable protections such as encryption,
access controls, and retention requirements.
Question 4
In the AWS Shared Responsibility Model, which of the following is the
customer's responsibility when using Amazon EC2?
A. Physical security of data centers
B. Patching the underlying hypervisor
C. Operating system security patching and firewall configuration
D. Ensuring power and cooling for infrastructure
C. Operating system security patching and firewall configuration
RATIONALE: Under the AWS Shared Responsibility Model, when
using IaaS like EC2, AWS manages security of the cloud (physical
infrastructure, hypervisor, network), while the customer is responsible
for security in the cloud, including operating system patching,
application security, data encryption, and firewall configuration.
Question 5
Which encryption method protects data while it is being processed in
memory by a cloud application?
A. Data at rest encryption
B. Data in transit encryption
, C. Confidential computing / encryption in use
D. Tokenization
C. Confidential computing / encryption in use
RATIONALE: Confidential computing, also known as encryption in
use, protects data while it is being processed in memory using
hardware-based trusted execution environments (TEEs), ensuring that
data and code are isolated and encrypted even from the cloud
provider's hypervisor and operating system.
Question 6
Which cloud deployment model provides the highest level of control
and security for an organization with strict compliance requirements?
A. Public cloud
B. Private cloud
C. Community cloud
D. Hybrid cloud
B. Private cloud
RATIONALE: A private cloud deployment model provides dedicated
infrastructure for a single organization, offering the highest level of
control over security configurations, physical infrastructure, and
compliance implementations, making it ideal for organizations with strict
regulatory requirements.
Question 7
A security team needs to implement least privilege access across
multiple AWS accounts. Which AWS service enables centralized
management of permissions and policies?
A. AWS IAM basic edition
B. AWS Organizations with AWS IAM Identity Center (SSO)
C. Amazon CloudWatch
D. AWS Config