WGU D320 MANAGING CLOUD
SECURITY (JYO2): COMPLETE 200-
QUESTION EXAM STUDY GUIDE —
VERIFIED QUESTIONS & ANSWERS +
CHEAT SHEET | ALREADY GRADED
A+ | NEWEST
SECTION 1: RISK MANAGEMENT & BUSINESS
CONTINUITY
Question 1
Which process involves assessing and identifying the potential effects of disruptions
to a business operation?
A) Risk Appetite Analysis
B) Business Continuity Planning
C) Business Impact Analysis (BIA)
D) Disaster Recovery Planning
Correct Answer: C
Rationale: A Business Impact Analysis (BIA) is a process that assesses and identifies
the potential effects of disruptions to a business operation. It helps organizations
understand the consequences of interruptions to critical business functions and
informs recovery strategies .
,Question 2
What term describes a component or system that, if it fails, will cause the entire
system to fail?
A) Redundant System
B) Critical Path
C) Single Point of Failure (SPOF)
D) Bottleneck
Correct Answer: C
Rationale: A Single Point of Failure (SPOF) is a component or system that, if it fails,
will cause the entire system to fail. Identifying and eliminating SPOFs is a key goal in
designing resilient cloud architectures .
Question 3
Which type of risk assessment uses specific numerical values to evaluate risks?
A) Qualitative
B) Comparative
C) Subjective
D) Observational
E) Quantitative
Correct Answer: E
Rationale: Quantitative risk assessment uses specific numerical values (e.g.,
monetary values, probabilities) to measure and calculate risk .
,Question 4
A risk assessment method that uses non-numerical categories like high, medium, and
low is known as:
A) Predictive
B) Statistical
C) Subjective
D) Qualitative
E) Absolute
Correct Answer: D
Rationale: Qualitative risk assessment uses non-numerical categories that are
relative in nature, such as high, medium, and low. This approach is often faster and
easier to implement than quantitative assessments .
Question 5
What is the term for the level, amount, or type of risk that an organization finds
acceptable?
A) Risk Tolerance
B) Risk Mitigation
C) Risk Appetite
D) Risk Exposure
Correct Answer: C
Rationale: Risk appetite is the level, amount, or type of risk that the organization
finds acceptable. It represents the organization's willingness to take on risk in pursuit
of its objectives .
, Question 6
The remaining risk that exists after countermeasures have been applied is called:
A) Inherent Risk
B) Gross Risk
C) Acceptable Risk
D) Residual Risk
Correct Answer: D
Rationale: Residual risk is the remaining risk that exists after countermeasures have
been applied. No security control can eliminate all risk, so organizations must accept
or transfer residual risk .
Question 7
According to ISO 31000, what is the primary purpose of a risk management
program?
A) Eliminate all organizational risk
B) Protect value and mitigate uncertainty
C) Maximize profits at any cost
D) Transfer all risk to insurance providers
Correct Answer: B
Rationale: ISO 31000 outlines principles for risk management, including protecting
value, addressing all aspects of the organization, and mitigating uncertainty .
Question 8
SECURITY (JYO2): COMPLETE 200-
QUESTION EXAM STUDY GUIDE —
VERIFIED QUESTIONS & ANSWERS +
CHEAT SHEET | ALREADY GRADED
A+ | NEWEST
SECTION 1: RISK MANAGEMENT & BUSINESS
CONTINUITY
Question 1
Which process involves assessing and identifying the potential effects of disruptions
to a business operation?
A) Risk Appetite Analysis
B) Business Continuity Planning
C) Business Impact Analysis (BIA)
D) Disaster Recovery Planning
Correct Answer: C
Rationale: A Business Impact Analysis (BIA) is a process that assesses and identifies
the potential effects of disruptions to a business operation. It helps organizations
understand the consequences of interruptions to critical business functions and
informs recovery strategies .
,Question 2
What term describes a component or system that, if it fails, will cause the entire
system to fail?
A) Redundant System
B) Critical Path
C) Single Point of Failure (SPOF)
D) Bottleneck
Correct Answer: C
Rationale: A Single Point of Failure (SPOF) is a component or system that, if it fails,
will cause the entire system to fail. Identifying and eliminating SPOFs is a key goal in
designing resilient cloud architectures .
Question 3
Which type of risk assessment uses specific numerical values to evaluate risks?
A) Qualitative
B) Comparative
C) Subjective
D) Observational
E) Quantitative
Correct Answer: E
Rationale: Quantitative risk assessment uses specific numerical values (e.g.,
monetary values, probabilities) to measure and calculate risk .
,Question 4
A risk assessment method that uses non-numerical categories like high, medium, and
low is known as:
A) Predictive
B) Statistical
C) Subjective
D) Qualitative
E) Absolute
Correct Answer: D
Rationale: Qualitative risk assessment uses non-numerical categories that are
relative in nature, such as high, medium, and low. This approach is often faster and
easier to implement than quantitative assessments .
Question 5
What is the term for the level, amount, or type of risk that an organization finds
acceptable?
A) Risk Tolerance
B) Risk Mitigation
C) Risk Appetite
D) Risk Exposure
Correct Answer: C
Rationale: Risk appetite is the level, amount, or type of risk that the organization
finds acceptable. It represents the organization's willingness to take on risk in pursuit
of its objectives .
, Question 6
The remaining risk that exists after countermeasures have been applied is called:
A) Inherent Risk
B) Gross Risk
C) Acceptable Risk
D) Residual Risk
Correct Answer: D
Rationale: Residual risk is the remaining risk that exists after countermeasures have
been applied. No security control can eliminate all risk, so organizations must accept
or transfer residual risk .
Question 7
According to ISO 31000, what is the primary purpose of a risk management
program?
A) Eliminate all organizational risk
B) Protect value and mitigate uncertainty
C) Maximize profits at any cost
D) Transfer all risk to insurance providers
Correct Answer: B
Rationale: ISO 31000 outlines principles for risk management, including protecting
value, addressing all aspects of the organization, and mitigating uncertainty .
Question 8