WGU E025 Comprehensive Cloud and Network
Security Models Questions with Verified Correct
Answers
IaaS
Infrastructure as a Service: provider supplies compute, storage, networking, and
virtualization; customer manages guest OS, applications, data, identities, and many
configurations.
PaaS
Platform as a Service: provider manages infrastructure, OS, and runtime; customer focuses on
application code, data, and access.
SaaS
Software as a Service: provider delivers a complete hosted application; customer still
manages users, permissions, data, retention, and configuration.
FaaS/serverless
Event-driven code execution without managing servers; customer secures code, data,
permissions, and triggers.
Public cloud
Shared provider infrastructure delivered over a network with logical tenant isolation.
Private cloud
Cloud infrastructure dedicated to one organization, hosted internally or externally.
Hybrid cloud
,Combination of on-premises/private resources and public cloud services.
Multicloud
Use of services from more than one public cloud provider.
Elasticity
Ability to scale resources up or down rapidly according to demand.
Resource pooling
Provider resources are shared among tenants while logically isolated.
Measured service
Usage is monitored and billed by consumption.
On-demand self-service
Users provision resources without manual provider intervention.
Broad network access
Services are available over networks through standard mechanisms.
Shared responsibility
Provider secures the cloud; customer secures data, identities, configurations, and workloads
within the cloud.
Provider responsibility
Physical facilities, hardware, foundational networking, virtualization, and provider-managed
service infrastructure.
Customer responsibility
, Data, IAM, permissions, application settings, guest OS in IaaS, network rules, retention, and
monitoring configuration.
CSPM
Cloud Security Posture Management detects cloud misconfiguration, risky permissions,
public exposure, and policy violations.
Secure baseline
Approved standard configuration used before deployment.
Configuration drift
A system no longer matches its approved secure baseline.
Defense in depth
Multiple complementary control layers reduce reliance on any single safeguard.
Landing zone
Preconfigured cloud environment with baseline identity, networking, logging, security, and
governance.
Infrastructure as code
Provisioning infrastructure through versioned templates or code.
Least functionality
Enable only required ports, services, software, and features.
Attack surface
All reachable points that could be exploited, including identities, APIs, ports, services, and
configurations.
Security Models Questions with Verified Correct
Answers
IaaS
Infrastructure as a Service: provider supplies compute, storage, networking, and
virtualization; customer manages guest OS, applications, data, identities, and many
configurations.
PaaS
Platform as a Service: provider manages infrastructure, OS, and runtime; customer focuses on
application code, data, and access.
SaaS
Software as a Service: provider delivers a complete hosted application; customer still
manages users, permissions, data, retention, and configuration.
FaaS/serverless
Event-driven code execution without managing servers; customer secures code, data,
permissions, and triggers.
Public cloud
Shared provider infrastructure delivered over a network with logical tenant isolation.
Private cloud
Cloud infrastructure dedicated to one organization, hosted internally or externally.
Hybrid cloud
,Combination of on-premises/private resources and public cloud services.
Multicloud
Use of services from more than one public cloud provider.
Elasticity
Ability to scale resources up or down rapidly according to demand.
Resource pooling
Provider resources are shared among tenants while logically isolated.
Measured service
Usage is monitored and billed by consumption.
On-demand self-service
Users provision resources without manual provider intervention.
Broad network access
Services are available over networks through standard mechanisms.
Shared responsibility
Provider secures the cloud; customer secures data, identities, configurations, and workloads
within the cloud.
Provider responsibility
Physical facilities, hardware, foundational networking, virtualization, and provider-managed
service infrastructure.
Customer responsibility
, Data, IAM, permissions, application settings, guest OS in IaaS, network rules, retention, and
monitoring configuration.
CSPM
Cloud Security Posture Management detects cloud misconfiguration, risky permissions,
public exposure, and policy violations.
Secure baseline
Approved standard configuration used before deployment.
Configuration drift
A system no longer matches its approved secure baseline.
Defense in depth
Multiple complementary control layers reduce reliance on any single safeguard.
Landing zone
Preconfigured cloud environment with baseline identity, networking, logging, security, and
governance.
Infrastructure as code
Provisioning infrastructure through versioned templates or code.
Least functionality
Enable only required ports, services, software, and features.
Attack surface
All reachable points that could be exploited, including identities, APIs, ports, services, and
configurations.