QUESTIONS AND ANSWERS
SOLVED 100% CORRECT!!
Managing Cloud Security (YJ02)
Pre-Assessment Preparation | Competency-Aligned Practice Exam
NEW 2026/2027 UPDATE - Current Cloud Security Standards
EXAM OVERVIEW
Total Questions: 60 (Multiple Choice, 4 Options, One Correct)
Sections: 6 Domain Sections - Aligned to WGU D320 Blueprint
Cognitive Levels: 25% Recall | 55% Application | 20% Analysis
Question Style: 80% Scenario-Based | 20% Direct Recall
Recommended Time: 120 Minutes (2 minutes per question)
Passing Reference: WGU Pre-Assessment Competency Threshold
Aligned With Current Cloud Security Standards:
NIST SP 800-145 | NIST SP 800-53 Rev. 5 | NIST SP 800-190 | ISO/IEC 27017 | ISO/IEC 27018 | ISO/IEC 27701
CSA Cloud Controls Matrix v4 | GDPR | HIPAA | PCI DSS 4.0 | FedRAMP | SOC 1/2/3 | Zero Trust Architecture (NIST SP 800-207)
WGU D320 Managing Cloud Security (YJ02) | Pre-Assessment Practice Exam | Compiled for Educational Use
, WGU PRE D320 EXAM - QUESTIONS AND ANSWERS
Solved 100% Correct | Managing Cloud Security (YJ02) | Pre-Assessment Preparation
WGU PRE D320 EXAM
Exam Overview
QUESTIONS AND ANSWERS
This practice exam is structured to mirror the WGU D320 Managing Cloud Security (YJ02) Pre-Assessment blueprint. It evaluates a
SOLVED
candidate's mastery of cloud computing fundamentals, 100%architecture
cloud security CORRECT!! and the shared responsibility model, identity and access
management, data security and key management, cloud network and infrastructure security, risk and compliance, auditing, security
operations, incident response, business continuity, disaster recovery, and emerging cloud-native security trends. Each question is multiple
choice with one best answer, followed by a comprehensive rationale citing NIST, ISO/IEC, CSA, and major regulatory standards.
Section Title Managing Cloud
Questions Security (YJ02)
Topics
Section 1 Pre-Assessment
Cloud Computing Preparation
Fundamentals and Service
Q1 -Models
Q12 | Competency-Aligned Practice| IaaS
Definitions | Essential Characteristics Exam/ PaaS / SaaS | Deployment Models
Section 2 Cloud Security Architecture and Shared Responsibility
Q13 - Q22 Shared Responsibility Model | Security Domains | Design Principles | Virtualizatio
NEW 2026/2027 UPDATE - Current Cloud Security Standards
Section 3 Identity, Access Management, and Data Security
Q23 - Q34 IAM | Federation | SSO | MFA | PAM | Encryption | Key Management | Data Lifec
Section 4 Cloud Network and Infrastructure SecurityQ35 - Q43 VPC | Security Groups | NACLs | Segmentation | Microsegmentation | WAF | DD
Section 5 Risk, Compliance, Legal, and Auditing Q44 - Q52 Risk Management | Third-Party Risk | SOC Reports | CSA STAR | GDPR | HIPA
Section 6 Security Operations, Incident Response, BCDR,
Q53 - Q60
and Emerging
Monitoring
Trends
| Logging | SIEM | Incident Response | Forensics | RTO / RPO | DR |
EXAM OVERVIEW
Cognitive Level Distribution
Total Questions: 60 (Multiple Choice, 4 Options, One Correct)
Sections: 6 Domain Sections - Aligned to WGU D320 Blueprint
WGU D320 questions span Bloom's-style cognitive levels to align with Pre-Assessment competency weighting. The exam is intentionally
Cognitive Levels: 25% Recall | 55% Application | 20% Analysis
calibrated to 25% recall (remember / understand), 55% application (apply), and 20% analysis (analyze). Approximately 80% of items
Question Style:
are scenario-based, reflecting authentic cloud80% Scenario-Based | 20% Direct Recall
security decision-making situations, while 20% are direct recall or terminology
Recommended Time: 120 Minutes
identification. Distractors are constructed around the most (2 minutes
common per question)
WGU D320 Pre-Assessment pitfalls - confusion of shared
Passing
responsibility boundaries Reference:
across service models, WGU Pre-Assessment
deployment Competency ThresholdIAM versus federation confusion, at-rest versus
model mischaracterization,
in-transit encryption errors, misapplied compliance frameworks, wrong DR strategy for a given RTO/RPO, SOC report type confusion, and
jurisdiction or data sovereignty errors.
Standards & Frameworks Referenced
• NIST SP 800-145 - The NIST Definition of Cloud Computing
• NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems
• NIST SP 800-57 Part 1 - Recommendation for Key Management
• NIST SP 800-61 Rev. 2 - Computer Security Incident Handling Guide
• NIST SP 800-86 - Integrating Forensic Techniques into Incident Response
• NIST SP 800-137 - Information Security Continuous Monitoring (ISCM)
• NIST SP 800-190 - Application Container Security Guide
• NIST SP 800-204 - Security Strategies Aligned
for Microservices-Based Application
With Current Cloud Systems
Security Standards:
• NIST SP 800-207 - Zero Trust Architecture
NIST SP 800-145 | NIST SP 800-53 Rev. 5 | NIST SP 800-190 | ISO/IEC 27017 | ISO/IEC 27018 | ISO/IEC 27701
• NIST SP Cloud
CSA 800-218 - Secure
Controls Software
Matrix Development
v4 | GDPR Framework
| HIPAA | PCI DSS 4.0 (SSDF)
| FedRAMP | SOC 1/2/3 | Zero Trust Architecture (NIST SP 800-207)
• ISO/IEC 27017:2015 - Code of Practice for Information Security Controls for Cloud Services
• ISO/IEC 27018:2019 - Protection of PII in Public Clouds Acting as PII Processors
• ISO/IEC 27701:2019 - Privacy
WGU Information
D320 Managing CloudManagement
Security (YJ02) System (PIMS) Practice Exam | Compiled for Educational Use
| Pre-Assessment
• CSA Cloud Controls Matrix (CCM) v4 & CSA STAR Registry
,WGU D320 - Managing Cloud Security (YJ02) Pre-Assessment Solved 100% Correct | 2026/2027 Update
• GDPR (Regulation EU 2016/679) - General Data Protection Regulation
• HIPAA Privacy & Security Rules - 45 CFR Parts 160 and 164
• PCI DSS 4.0 - Payment Card Industry Data Security Standard
• SOX (Sarbanes-Oxley Act of 2002) - 17 CFR 240)
• FISMA + FedRAMP - 44 U.S.C. Chapter 35 + OMB Circular A-130
• AICPA SOC 1 / SOC 2 / SOC 3 Trust Services Criteria (TSC)
Confidential - WGU Pre-Assessment Preparation Page 3 60 Questions Total
, SECTION 1: Cloud Computing Fundamentals and Service Models
Questions Q1 - Q12 | Definitions | Essential Characteristics | IaaS / PaaS / SaaS | Deployment
Models | Reference Architecture
Q1. A startup deploys a customer-facing application to a public cloud. The cloud provider provisions
new virtual machines automatically within minutes whenever user traffic spikes, and deallocates them
when traffic subsides, with the customer paying only for the actual compute minutes consumed. Which
NIST SP 800-145 essential characteristic is the PRIMARY driver of this cost behavior?
A. On-demand self-service
B. Resource pooling
C. Rapid elasticity
D. Measured service [CORRECT]
Correct Answer: D
Rationale: NIST SP 800-145 defines measured service as the capability where cloud systems automatically
control and optimize resource use by leveraging a metering capability at some abstraction level
appropriate to the type of service (e.g., storage, processing, active users). The
billing-for-actual-consumption behavior described is the hallmark of measured service. Rapid elasticity (C)
describes the appearance of often-infinite, quickly provisioned capabilities, but the metering-and-billing
aspect is measured service. On-demand self-service (A) emphasizes unilateral provisioning without human
interaction with the provider. Resource pooling (B) refers to multi-tenant serving of multiple consumers
from a shared physical pool.
Q2. A multinational SaaS vendor serves customers in finance, healthcare, and retail from the same
physical server cluster, dynamically reassigning CPU and memory based on demand while keeping each
tenant's data logically isolated. Which NIST essential characteristic does this scenario BEST exemplify?
A. Broad network access
B. Resource pooling [CORRECT]
C. Rapid elasticity
D. Measured service
Correct Answer: B
Rationale: Resource pooling, per NIST SP 800-145, describes the provider's computing resources being
pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual
resources dynamically assigned and reassigned according to consumer demand. The multi-tenant
finance/healthcare/retail scenario directly demonstrates this. Broad network access (A) refers to
capabilities being available over the network and accessed through standard mechanisms. Rapid elasticity
(C) is about scaling out/in quickly. Measured service (D) deals with metering, not multi-tenancy.