Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 38 pages
Exam (elaborations)

WGU D485 DGN2 TASK 1: CLOUD SECURITY IMPLEMENTATION PLAN | COMPLETE PRACTICE EXAMINATION | LATEST 2026 UPDATE | 100 QUESTIONS & ANSWERS | VERIFIED SOLUTIONS

Document preview thumbnail
Preview 4 out of 38 pages

This comprehensive practice examination is meticulously designed for candidates preparing for the Western Governors University (WGU) D485 DGN2 Task 1: Cloud Security Implementation Plan. Aligned with the 2026/2027 curriculum, this document serves as a definitive study guide and exam review, featuring 100 questions that mirror the complexity and rigor of the actual performance assessment. It covers all essential domains, including cloud security fundamentals, identity and access management (IAM), data protection and encryption, network security, security monitoring and incident response, compliance and governance, and cloud-specific security services. Each question is accompanied by a detailed, verified solution and clinical rationale to ensure 100% correct answers and a deep, integrated understanding of cloud security principles, guaranteeing distinction-level preparation for this critical IT credential.

Content preview

WGU D485 DGN2 TASK 1: CLOUD
SECURITY IMPLEMENTATION PLAN

COMPLETE SOLUTION | LATEST 2026/2027
UPDATE | A+ GRADED | 100% PASS


MASTER STUDY GUIDE SUMMARY
Course: WGU D485 DGN2 – Cloud Security Implementation Plan
Task: Task 1 – Cloud Security Implementation Plan
Key Topics: Shared Responsibility Model, Identity and Access Management
(IAM), Multi-Factor Authentication (MFA), Encryption at Rest and in Transit, Key
Management (KMS), Network Security (VPC, Security Groups, NACLs), Web
Application Firewall (WAF), DDoS Protection, Security Monitoring (CloudWatch,
CloudTrail, GuardDuty), Incident Response, Compliance (PCI DSS, HIPAA,
GDPR), Cloud-Native Services, Zero Trust Architecture
Key AWS Services: IAM, KMS, S3, VPC, CloudTrail, CloudWatch, GuardDuty,
Inspector, Config, Security Hub, Shield, WAF, Macie, Secrets Manager
Key Azure Services: Azure AD, Azure Security Center, Azure Sentinel, Azure
Policy, Azure Key Vault

,SECTION 1: EXECUTIVE SUMMARY
SWBTL LLC is a nationwide logistics company that began as a local document and delivery
service in 1977. Since then, they have grown to provide nationwide services and employ over
2,000 professionals. The current IT model spans across four leased data centers in the United
States. Because of increased costs, service interruptions, and cybersecurity concerns, the
Microsoft Azure cloud deployment was implemented. However, during implementation, the
consultant responsible for the migration suddenly left, leaving the company in an insecure
position.
SWBTL LLC's IT infrastructure has several security challenges, including inadequate data
protection, unstable access controls, and noncompliance with FISMA and PCI DSS. These
gaps create major risks since the company handles sensitive government and payment card
data.
Critical Improvements Needed:
 Implementing RBAC (Role-Based Access Control)
 Enabling encryption and backup configurations
 Achieving alignment with FISMA, PCI DSS, and NIST 800-53 standards
The company has an upcoming NIST SP 800-53 assessment and must maintain compliance
with FISMA as well as PCI DSS standards because they hold government contracts and conduct
card payment transactions daily.


SECTION 2: PROPOSED SECURE AZURE CLOUD SOLUTION
Cloud Model: Infrastructure-as-a-Service (IaaS)

Aspect Details


Full Control Full control over VMs, OS, and configurations


Security Tools Integrated security and compliance tools


Justification Better suited than PaaS/SaaS for custom security management

Regulatory Compliance Frameworks

,Framework Description Key Requirements


Federal Information Security Continuous monitoring, RBAC,
FISMA
Modernization Act encryption


Payment Card Industry Data Cardholder data encryption, secure
PCI DSS
Security Standard access


NIST 800- Identity management, data protection,
Security & Privacy Controls
53 system availability

Benefits & Challenges

Benefits Challenges


Built-in encryption, patching, centralized monitoring Misconfiguration risks


Scalable resources Ongoing management


Simplified compliance alignment Migration complexity



SECTION 3: ROLE-BASED ACCESS CONTROL (RBAC)
Current Issue
Excessive access permissions across departments violate the principle of least privilege. Users
from multiple departments have been able to access data and assets that belong to other groups,
which they should not have access to.
Recommendations

Recommendation Implementation


Limit Access by Department Assign permissions by resource group


Just-In-Time Access (JIT) Temporary access for specific tasks

, Recommendation Implementation


Role-Specific Permissions Align roles to job responsibilities

Implementation Details
 Each department must have its own Azure Resource Group
 Each department must have its own Azure Key Vault with the principle of least privilege
enabled
 Strict rules must maintain the access capabilities of each department


SECTION 4: AZURE KEY VAULT & ENCRYPTION
Best Practices Implemented

Feature Purpose


Soft Delete & Purge Protection Prevents accidental deletions


Managed Identities Secure app authentication without stored secrets

Encryption Approach

Type Implementation


Data at Rest Use Key Vault with Disk Encryption + SQL Database


Data in Transit Enforce TLS for secure connections

Business Requirement
Data should be encrypted in use and at rest. Only users within that department should be
capable of accessing the encrypted data via their respective Key Vault.


SECTION 5: BACKUP POLICY CONFIGURATION

Document information

Uploaded on
September 3, 2026
Number of pages
38
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
2
Followers
0
Items
306
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions