1|Page
WGU D485 DGN2 TASK 1: SWBTL LLC CLOUD SECURITY
IMPLEMENTATION PLAN | 2026 UPDATE WITH COMPLETE
SOLUTIONS.
**1.** SWBTL LLC is migrating its workloads to Microsoft Azure after
experiencing increasing costs, service interruptions, and cybersecurity
concerns with its existing leased data centers. Which cloud service
model would provide the organization with the greatest control over
virtual machines, operating systems, networking, and application
infrastructure?
A. Software as a Service (SaaS)
B. Platform as a Service (PaaS)
C. Infrastructure as a Service (IaaS)
D. Function as a Service (FaaS)
**Answer: C**
**2.** SWBTL LLC must protect sensitive information while complying
with FISMA and PCI DSS requirements. Which security strategy provides
the strongest foundation for protecting data throughout its lifecycle?
A. Encrypt sensitive data at rest and in transit while implementing
appropriate access controls and monitoring
,2|Page
B. Encrypt data only when employees access it remotely
C. Depend exclusively on physical security provided by the cloud
provider
D. Permit unrestricted access to encrypted resources so applications
cannot be interrupted
**Answer: A**
**3.** SWBTL LLC discovers that employees have been assigned broad
permissions that exceed their actual job responsibilities. Which security
principle should guide the redesign of access privileges?
A. Defense by obscurity
B. Least privilege
C. Maximum availability
D. Open access
**Answer: B**
**4.** The accounting department requires access to financial
resources, while the marketing department should not have access to
those resources. Which Azure capability is MOST appropriate for
enforcing permissions according to organizational roles?
,3|Page
A. Role-Based Access Control (RBAC)
B. Network Address Translation
C. Blob lifecycle management
D. Azure DNS
**Answer: A**
**5.** A cloud administrator wants to assign permissions to a group of
employees based on their organizational responsibilities rather than
granting permissions individually. What is the BEST approach?
A. Assign appropriate Azure RBAC roles to security groups and manage
membership centrally
B. Give every employee Owner permissions
C. Share one administrator account among employees
D. Store permissions in an unencrypted spreadsheet
**Answer: A**
**6.** SWBTL LLC wants to reduce the risk associated with a
compromised administrator account. Which control would provide the
strongest improvement?
, 4|Page
A. Require multifactor authentication and restrict administrative
privileges according to least privilege
B. Give additional administrator privileges to the same account
C. Disable authentication logging
D. Allow administrators to share credentials
**Answer: A**
**7.** SWBTL LLC needs to protect cryptographic keys, certificates, and
secrets used by Azure applications. Which Azure service is MOST
appropriate?
A. Azure Key Vault
B. Azure Blob Storage
C. Azure Queue Storage
D. Azure DNS
**Answer: A**
**8.** An application stores database credentials in its source code
repository. What is the PRIMARY security concern with this design?
WGU D485 DGN2 TASK 1: SWBTL LLC CLOUD SECURITY
IMPLEMENTATION PLAN | 2026 UPDATE WITH COMPLETE
SOLUTIONS.
**1.** SWBTL LLC is migrating its workloads to Microsoft Azure after
experiencing increasing costs, service interruptions, and cybersecurity
concerns with its existing leased data centers. Which cloud service
model would provide the organization with the greatest control over
virtual machines, operating systems, networking, and application
infrastructure?
A. Software as a Service (SaaS)
B. Platform as a Service (PaaS)
C. Infrastructure as a Service (IaaS)
D. Function as a Service (FaaS)
**Answer: C**
**2.** SWBTL LLC must protect sensitive information while complying
with FISMA and PCI DSS requirements. Which security strategy provides
the strongest foundation for protecting data throughout its lifecycle?
A. Encrypt sensitive data at rest and in transit while implementing
appropriate access controls and monitoring
,2|Page
B. Encrypt data only when employees access it remotely
C. Depend exclusively on physical security provided by the cloud
provider
D. Permit unrestricted access to encrypted resources so applications
cannot be interrupted
**Answer: A**
**3.** SWBTL LLC discovers that employees have been assigned broad
permissions that exceed their actual job responsibilities. Which security
principle should guide the redesign of access privileges?
A. Defense by obscurity
B. Least privilege
C. Maximum availability
D. Open access
**Answer: B**
**4.** The accounting department requires access to financial
resources, while the marketing department should not have access to
those resources. Which Azure capability is MOST appropriate for
enforcing permissions according to organizational roles?
,3|Page
A. Role-Based Access Control (RBAC)
B. Network Address Translation
C. Blob lifecycle management
D. Azure DNS
**Answer: A**
**5.** A cloud administrator wants to assign permissions to a group of
employees based on their organizational responsibilities rather than
granting permissions individually. What is the BEST approach?
A. Assign appropriate Azure RBAC roles to security groups and manage
membership centrally
B. Give every employee Owner permissions
C. Share one administrator account among employees
D. Store permissions in an unencrypted spreadsheet
**Answer: A**
**6.** SWBTL LLC wants to reduce the risk associated with a
compromised administrator account. Which control would provide the
strongest improvement?
, 4|Page
A. Require multifactor authentication and restrict administrative
privileges according to least privilege
B. Give additional administrator privileges to the same account
C. Disable authentication logging
D. Allow administrators to share credentials
**Answer: A**
**7.** SWBTL LLC needs to protect cryptographic keys, certificates, and
secrets used by Azure applications. Which Azure service is MOST
appropriate?
A. Azure Key Vault
B. Azure Blob Storage
C. Azure Queue Storage
D. Azure DNS
**Answer: A**
**8.** An application stores database credentials in its source code
repository. What is the PRIMARY security concern with this design?