1
WGU C838 MANAGING CLOUD SECURITY FINAL
EXAM OBJECTIVE ASSESSMENT / WGU C838 OA
PREPARATION/WGU C838 OA PRACTICE WITH
COMPLETE 100 QUESTIONS AND ANSWERS
LATEST |AGRADE
1.
A multinational organization is migrating several business-critical
applications from its privately managed data center to a public cloud
environment. During the planning phase, the security team discovers that
some responsibilities previously handled entirely by the organization's
infrastructure team will now be divided between the organization and
the cloud provider. Management wants to ensure that security
responsibilities are correctly assigned so that neither party assumes the
other is responsible for protecting a particular component of the
environment. Which concept BEST describes the security model that
should be used to determine these responsibilities?
A. Zero trust architecture
B. Shared responsibility model
C. Defense-in-depth model
D. Cloud bursting model
Answer: B. Shared responsibility model
2.
A company has deployed a customer-facing application using a cloud
provider's infrastructure-as-a-service offering. The cloud provider is
responsible for maintaining the physical servers, data-center facilities,
and underlying virtualization infrastructure, while the company's
security team is responsible for configuring operating systems,
,2
applications, identities, and access permissions. A newly hired
administrator incorrectly assumes that the provider automatically secures
all operating-system and application configurations. Which statement
BEST identifies the administrator's misunderstanding?
A. The organization has misunderstood the shared responsibility model
B. The organization has violated the principle of least privilege
C. The provider is required to manage all application-level security
D. The provider is responsible for all customer configurations
Answer: A. The organization has misunderstood the shared
responsibility model
3.
An organization wants to deploy virtual machines in a public cloud
while retaining responsibility for the operating system, middleware,
applications, and much of the network configuration. The organization
does not want the cloud provider to manage the application's source
code or operating-system configuration. Which cloud service model
BEST meets these requirements?
A. Software as a Service
B. Platform as a Service
C. Infrastructure as a Service
D. Function as a Service
Answer: C. Infrastructure as a Service
4.
A software development organization wants developers to concentrate
on writing application code without having to maintain operating
,3
systems, runtime environments, or underlying servers. The cloud
provider will supply the managed platform, while the organization
remains responsible primarily for application code and associated data.
Which cloud service model BEST describes this arrangement?
A. Infrastructure as a Service
B. Platform as a Service
C. Software as a Service
D. Colocation as a Service
Answer: B. Platform as a Service
5.
A company subscribes to a cloud-based customer relationship
management application. Employees access the application through a
web browser, while the provider manages the servers, operating system,
application software, patches, and most infrastructure components. The
organization primarily manages its users, data, and application-specific
settings. Which cloud service model is being used?
A. IaaS
B. PaaS
C. SaaS
D. Bare-metal hosting
Answer: C. SaaS
6.
A financial institution is evaluating whether to place sensitive customer
workloads into a cloud environment. The organization wants cloud
resources that are dedicated to its use rather than shared with unrelated
, 4
organizations, while still retaining some characteristics of cloud
computing. Which deployment model BEST satisfies this requirement?
A. Public cloud
B. Private cloud
C. Community cloud
D. Open cloud
Answer: B. Private cloud
7.
Several government agencies with similar regulatory and security
requirements want to share cloud infrastructure specifically designed to
meet their common compliance requirements. The infrastructure will not
be generally available to the public and will be jointly utilized by
participating organizations. Which cloud deployment model BEST
describes this environment?
A. Public cloud
B. Private cloud
C. Community cloud
D. Personal cloud
Answer: C. Community cloud
8.
An organization maintains sensitive databases on infrastructure it
controls but uses a public cloud provider for scalable web servers and
analytics workloads. The security architecture is designed so that
workloads can operate across both environments according to business
requirements. Which deployment model is being implemented?
WGU C838 MANAGING CLOUD SECURITY FINAL
EXAM OBJECTIVE ASSESSMENT / WGU C838 OA
PREPARATION/WGU C838 OA PRACTICE WITH
COMPLETE 100 QUESTIONS AND ANSWERS
LATEST |AGRADE
1.
A multinational organization is migrating several business-critical
applications from its privately managed data center to a public cloud
environment. During the planning phase, the security team discovers that
some responsibilities previously handled entirely by the organization's
infrastructure team will now be divided between the organization and
the cloud provider. Management wants to ensure that security
responsibilities are correctly assigned so that neither party assumes the
other is responsible for protecting a particular component of the
environment. Which concept BEST describes the security model that
should be used to determine these responsibilities?
A. Zero trust architecture
B. Shared responsibility model
C. Defense-in-depth model
D. Cloud bursting model
Answer: B. Shared responsibility model
2.
A company has deployed a customer-facing application using a cloud
provider's infrastructure-as-a-service offering. The cloud provider is
responsible for maintaining the physical servers, data-center facilities,
and underlying virtualization infrastructure, while the company's
security team is responsible for configuring operating systems,
,2
applications, identities, and access permissions. A newly hired
administrator incorrectly assumes that the provider automatically secures
all operating-system and application configurations. Which statement
BEST identifies the administrator's misunderstanding?
A. The organization has misunderstood the shared responsibility model
B. The organization has violated the principle of least privilege
C. The provider is required to manage all application-level security
D. The provider is responsible for all customer configurations
Answer: A. The organization has misunderstood the shared
responsibility model
3.
An organization wants to deploy virtual machines in a public cloud
while retaining responsibility for the operating system, middleware,
applications, and much of the network configuration. The organization
does not want the cloud provider to manage the application's source
code or operating-system configuration. Which cloud service model
BEST meets these requirements?
A. Software as a Service
B. Platform as a Service
C. Infrastructure as a Service
D. Function as a Service
Answer: C. Infrastructure as a Service
4.
A software development organization wants developers to concentrate
on writing application code without having to maintain operating
,3
systems, runtime environments, or underlying servers. The cloud
provider will supply the managed platform, while the organization
remains responsible primarily for application code and associated data.
Which cloud service model BEST describes this arrangement?
A. Infrastructure as a Service
B. Platform as a Service
C. Software as a Service
D. Colocation as a Service
Answer: B. Platform as a Service
5.
A company subscribes to a cloud-based customer relationship
management application. Employees access the application through a
web browser, while the provider manages the servers, operating system,
application software, patches, and most infrastructure components. The
organization primarily manages its users, data, and application-specific
settings. Which cloud service model is being used?
A. IaaS
B. PaaS
C. SaaS
D. Bare-metal hosting
Answer: C. SaaS
6.
A financial institution is evaluating whether to place sensitive customer
workloads into a cloud environment. The organization wants cloud
resources that are dedicated to its use rather than shared with unrelated
, 4
organizations, while still retaining some characteristics of cloud
computing. Which deployment model BEST satisfies this requirement?
A. Public cloud
B. Private cloud
C. Community cloud
D. Open cloud
Answer: B. Private cloud
7.
Several government agencies with similar regulatory and security
requirements want to share cloud infrastructure specifically designed to
meet their common compliance requirements. The infrastructure will not
be generally available to the public and will be jointly utilized by
participating organizations. Which cloud deployment model BEST
describes this environment?
A. Public cloud
B. Private cloud
C. Community cloud
D. Personal cloud
Answer: C. Community cloud
8.
An organization maintains sensitive databases on infrastructure it
controls but uses a public cloud provider for scalable web servers and
analytics workloads. The security architecture is designed so that
workloads can operate across both environments according to business
requirements. Which deployment model is being implemented?