1|Page
WGU D485 DGN2 TASK 1: CLOUD SECURITY
IMPLEMENTATION PLAN LATEST UPDATE WITH
COMPLETE SOLUTION
1. SWBTL LLC is migrating its infrastructure to Microsoft Azure after
experiencing increasing costs, service interruptions, and cybersecurity concerns
with its existing data centers. Which security objective should be prioritized when
designing the new cloud environment?
A. Maximizing unrestricted employee access
B. Protecting confidentiality, integrity, and availability while supporting business
requirements
C. Eliminating all administrative accounts
D. Allowing every department to share the same resources
Answer: B
2. SWBTL LLC separates its Marketing, Accounting, and IT resources into
different Azure resource groups. Which security principle is most directly
supported by this architecture?
A. Least privilege and resource isolation
B. Open access
C. Single-factor authentication
D. Data duplication
Answer: A
3. An administrator discovers that Marketing employees can modify resources
belonging to Accounting and IT. Which remediation would most directly address
this security weakness?
A. Increase the number of shared accounts
B. Implement appropriately scoped Azure RBAC assignments based on job
responsibilities
C. Give all employees Owner permissions
D. Remove all resource groups
Answer: B
,2|Page
4. Which RBAC design best follows the principle of least privilege?
A. Assign every employee Contributor access at the subscription level.
B. Assign users only the permissions required for their specific responsibilities and
scope those permissions to the appropriate resources.
C. Give department managers Owner permissions across the entire Azure
subscription.
D. Allow users to request permanent administrative privileges whenever needed.
Answer: B
5. An IT administrator requires elevated privileges to perform a temporary
infrastructure change. Which approach provides the strongest security?
A. Permanent Global Administrator access
B. Shared administrator credentials
C. Time-limited privileged access with strong authentication and appropriate
approval
D. Anonymous administrative access
Answer: C
6. Why is multifactor authentication particularly important for privileged Azure
accounts?
A. It prevents users from ever forgetting passwords.
B. It provides an additional authentication factor, reducing the risk that a
compromised password alone will provide access.
C. It eliminates the need for authorization controls.
D. It automatically encrypts every database.
Answer: B
7. A cloud administrator assigns a user broad permissions because the user
occasionally needs access to a single storage account. What is the principal
security concern?
A. Excessive privilege increases the potential blast radius if the account is
compromised.
B. The user will be unable to access the storage account.
,3|Page
C. Encryption will automatically be disabled.
D. RBAC cannot be used with storage resources.
Answer: A
8. SWBTL LLC stores sensitive information in Azure Key Vault. Which security
objective is most directly supported by using Key Vault for secrets and
cryptographic keys?
A. Centralized protection and management of sensitive credentials and keys
B. Eliminating all network traffic
C. Increasing public accessibility
D. Replacing every RBAC assignment
Answer: A
9. A company stores encryption keys in application configuration files that are
accessible to multiple developers. What is the strongest recommendation?
A. Store the keys in source-control repositories.
B. Move sensitive secrets and keys into an appropriately secured key-management
service such as Azure Key Vault.
C. Email the keys to administrators.
D. Place the keys in publicly accessible storage.
Answer: B
10. Which statement best describes the purpose of encryption at rest?
A. Protecting information while it is stored on disks or other persistent storage
B. Protecting information only while it is being transmitted
C. Preventing users from authenticating
D. Controlling Azure resource permissions
Answer: A
11. Which control most directly protects sensitive information in transit?
A. Encryption using protected communication protocols
B. Resource tagging
, 4|Page
C. Storage quotas
D. Password expiration alone
Answer: A
12. SWBTL LLC must protect sensitive business information while it travels
between an application and an Azure service. Which approach is most appropriate?
A. Use encrypted communications such as TLS and properly validate certificates.
B. Transmit the information using unencrypted protocols.
C. Disable authentication to improve performance.
D. Store the information in a public container.
Answer: A
13. A security engineer is determining who should administer each department's
Azure resources. Which information is most important when creating the RBAC
model?
A. Job responsibilities and the specific resources each role must access
B. Employee age
C. Employee workstation manufacturer
D. Office seating assignments
Answer: A
14. Which RBAC configuration would provide the strongest departmental
separation?
A. Marketing users receive access only to Marketing resources, Accounting users
only to Accounting resources, and IT administrators receive appropriately scoped
infrastructure permissions.
B. Every department receives Owner permissions at the subscription level.
C. Every employee receives identical permissions.
D. All departments share a single administrator account.
Answer: A
15. A security engineer is asked to demonstrate that an Azure environment
complies with the organization's security requirements. Which evidence would be
most useful?
WGU D485 DGN2 TASK 1: CLOUD SECURITY
IMPLEMENTATION PLAN LATEST UPDATE WITH
COMPLETE SOLUTION
1. SWBTL LLC is migrating its infrastructure to Microsoft Azure after
experiencing increasing costs, service interruptions, and cybersecurity concerns
with its existing data centers. Which security objective should be prioritized when
designing the new cloud environment?
A. Maximizing unrestricted employee access
B. Protecting confidentiality, integrity, and availability while supporting business
requirements
C. Eliminating all administrative accounts
D. Allowing every department to share the same resources
Answer: B
2. SWBTL LLC separates its Marketing, Accounting, and IT resources into
different Azure resource groups. Which security principle is most directly
supported by this architecture?
A. Least privilege and resource isolation
B. Open access
C. Single-factor authentication
D. Data duplication
Answer: A
3. An administrator discovers that Marketing employees can modify resources
belonging to Accounting and IT. Which remediation would most directly address
this security weakness?
A. Increase the number of shared accounts
B. Implement appropriately scoped Azure RBAC assignments based on job
responsibilities
C. Give all employees Owner permissions
D. Remove all resource groups
Answer: B
,2|Page
4. Which RBAC design best follows the principle of least privilege?
A. Assign every employee Contributor access at the subscription level.
B. Assign users only the permissions required for their specific responsibilities and
scope those permissions to the appropriate resources.
C. Give department managers Owner permissions across the entire Azure
subscription.
D. Allow users to request permanent administrative privileges whenever needed.
Answer: B
5. An IT administrator requires elevated privileges to perform a temporary
infrastructure change. Which approach provides the strongest security?
A. Permanent Global Administrator access
B. Shared administrator credentials
C. Time-limited privileged access with strong authentication and appropriate
approval
D. Anonymous administrative access
Answer: C
6. Why is multifactor authentication particularly important for privileged Azure
accounts?
A. It prevents users from ever forgetting passwords.
B. It provides an additional authentication factor, reducing the risk that a
compromised password alone will provide access.
C. It eliminates the need for authorization controls.
D. It automatically encrypts every database.
Answer: B
7. A cloud administrator assigns a user broad permissions because the user
occasionally needs access to a single storage account. What is the principal
security concern?
A. Excessive privilege increases the potential blast radius if the account is
compromised.
B. The user will be unable to access the storage account.
,3|Page
C. Encryption will automatically be disabled.
D. RBAC cannot be used with storage resources.
Answer: A
8. SWBTL LLC stores sensitive information in Azure Key Vault. Which security
objective is most directly supported by using Key Vault for secrets and
cryptographic keys?
A. Centralized protection and management of sensitive credentials and keys
B. Eliminating all network traffic
C. Increasing public accessibility
D. Replacing every RBAC assignment
Answer: A
9. A company stores encryption keys in application configuration files that are
accessible to multiple developers. What is the strongest recommendation?
A. Store the keys in source-control repositories.
B. Move sensitive secrets and keys into an appropriately secured key-management
service such as Azure Key Vault.
C. Email the keys to administrators.
D. Place the keys in publicly accessible storage.
Answer: B
10. Which statement best describes the purpose of encryption at rest?
A. Protecting information while it is stored on disks or other persistent storage
B. Protecting information only while it is being transmitted
C. Preventing users from authenticating
D. Controlling Azure resource permissions
Answer: A
11. Which control most directly protects sensitive information in transit?
A. Encryption using protected communication protocols
B. Resource tagging
, 4|Page
C. Storage quotas
D. Password expiration alone
Answer: A
12. SWBTL LLC must protect sensitive business information while it travels
between an application and an Azure service. Which approach is most appropriate?
A. Use encrypted communications such as TLS and properly validate certificates.
B. Transmit the information using unencrypted protocols.
C. Disable authentication to improve performance.
D. Store the information in a public container.
Answer: A
13. A security engineer is determining who should administer each department's
Azure resources. Which information is most important when creating the RBAC
model?
A. Job responsibilities and the specific resources each role must access
B. Employee age
C. Employee workstation manufacturer
D. Office seating assignments
Answer: A
14. Which RBAC configuration would provide the strongest departmental
separation?
A. Marketing users receive access only to Marketing resources, Accounting users
only to Accounting resources, and IT administrators receive appropriately scoped
infrastructure permissions.
B. Every department receives Owner permissions at the subscription level.
C. Every employee receives identical permissions.
D. All departments share a single administrator account.
Answer: A
15. A security engineer is asked to demonstrate that an Azure environment
complies with the organization's security requirements. Which evidence would be
most useful?