WGU D320 MANAGING CLOUD SECURITY EXAM – QUESTIONS AND ANSWERS |
VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES | DOWNLOAD
AND PASS | LATEST EXAM UPDATE 2026/2027
Core Domains
Cloud Computing Fundamentals and Reference Architecture
Cloud Security Architecture and Shared Responsibility Model
Identity, Access Management, and Data Security
Cloud Network and Infrastructure Security
Cloud Risk Management, Compliance, and Legal Considerations
Cloud Security Operations, Incident Response, and Business Continuity
Standards, Governance, and Emerging Cloud Security Trends
Introduction
This comprehensive assessment is designed to evaluate mastery of essential cloud
security principles required for the WGU D320 Managing Cloud Security Objective
Assessment. The exam tests foundational knowledge of cloud architecture, shared
responsibility boundaries, identity management, data protection, risk mitigation, and
regulatory compliance. Through a combination of direct-recall and scenario-based
multiple-choice questions, candidates must demonstrate the ability to apply
theoretical concepts to real-world cloud security decisions. Emphasis is placed on
critical thinking, professional judgment, and the practical implementation of security
controls across diverse cloud service and deployment models. This assessment
ensures readiness for the challenges of securing modern cloud environments.
SECTION ONE: QUESTIONS 1–50
1. Which essential cloud characteristic allows a consumer to unilaterally provision
computing capabilities, such as server time and network storage, as needed
automatically without requiring human interaction with each service provider?
,A. Broad network access
B. Rapid elasticity
C. On-demand self-service
D. Measured service
🟢 Correct Answer: C. On-demand self-service
🔴 Explanation: NIST SP 800-145 defines on-demand self-service as the ability to
provision resources automatically without human intervention with the provider.
This enables agility and eliminates traditional provisioning delays .
2. A healthcare organization needs a cloud deployment model that is
provisioned for exclusive use by several hospitals that share common regulatory
and security concerns. Which model best fits this requirement?
A. Public cloud
B. Community cloud
C. Hybrid cloud
D. Private cloud
🟢 Correct Answer: B. Community cloud
🔴 Explanation: A community cloud is shared by organizations with common
concerns (e.g., mission, security, compliance), making it ideal for a group of
hospitals with shared healthcare regulations .
3. In which cloud service model does the customer retain the MOST
responsibility for managing the operating system, middleware, and applications?
A. Software as a Service (SaaS)
B. Platform as a Service (PaaS)
C. Infrastructure as a Service (IaaS)
D. Function as a Service (FaaS)
🟢 Correct Answer: C. Infrastructure as a Service (IaaS)
,🔴 Explanation: In IaaS, the provider manages the physical infrastructure and
hypervisor, while the customer is responsible for the guest OS, middleware,
runtime, applications, and data .
4. A financial services firm is migrating a transaction processing system to a
public IaaS environment. According to the shared responsibility model, which
security control remains the customer's primary responsibility?
A. Physical security of the data center
B. Patching the underlying hypervisor
C. Guest operating system hardening and application security
D. Compliance certifications for the underlying cloud infrastructure
🟢 Correct Answer: C. Guest operating system hardening and application security
🔴 Explanation: Under IaaS, the provider secures the physical facility and
hypervisor. The customer is responsible for securing the guest OS, applications,
identity management, and data .
5. Which cloud data lifecycle phase is primarily concerned with the enforcement
of Data Loss Prevention (DLP) egress controls?
A. Create
B. Store
C. Share
D. Archive
🟢 Correct Answer: C. Share
🔴 Explanation: The Share phase involves exposing data to external parties. DLP
inspection and blocking controls are enforced during this phase to prevent
unauthorized data exfiltration .
6. An organization requires a cloud solution that provides a complete application
accessed via a browser, with the provider managing all underlying infrastructure,
, OS, and application logic. Which service model is this?
A. IaaS
B. PaaS
C. SaaS
D. DaaS
🟢 Correct Answer: C. SaaS
🔴 Explanation: Software as a Service delivers a complete, provider-managed
application to end users. The customer only manages user access and data
configuration .
7. Which cloud deployment model is defined as a composition of two or more
distinct cloud infrastructures that remain unique entities but are bound by
technology enabling data and application portability?
A. Public cloud
B. Private cloud
C. Community cloud
D. Hybrid cloud
🟢 Correct Answer: D. Hybrid cloud
🔴 Explanation: A hybrid cloud combines private and public (or community) clouds
with orchestration between them, allowing workloads to move based on business
needs .
8. A cloud architect is designing a multi-region active-active architecture that
replicates customer PII across three geographic regions. What is the PRIMARY
security concern raised by this design?
A. Increased network latency
B. Higher inter-region bandwidth costs
VERIFIED AND WELL DETAILED ANSWERS | PLUS RATIONALES | DOWNLOAD
AND PASS | LATEST EXAM UPDATE 2026/2027
Core Domains
Cloud Computing Fundamentals and Reference Architecture
Cloud Security Architecture and Shared Responsibility Model
Identity, Access Management, and Data Security
Cloud Network and Infrastructure Security
Cloud Risk Management, Compliance, and Legal Considerations
Cloud Security Operations, Incident Response, and Business Continuity
Standards, Governance, and Emerging Cloud Security Trends
Introduction
This comprehensive assessment is designed to evaluate mastery of essential cloud
security principles required for the WGU D320 Managing Cloud Security Objective
Assessment. The exam tests foundational knowledge of cloud architecture, shared
responsibility boundaries, identity management, data protection, risk mitigation, and
regulatory compliance. Through a combination of direct-recall and scenario-based
multiple-choice questions, candidates must demonstrate the ability to apply
theoretical concepts to real-world cloud security decisions. Emphasis is placed on
critical thinking, professional judgment, and the practical implementation of security
controls across diverse cloud service and deployment models. This assessment
ensures readiness for the challenges of securing modern cloud environments.
SECTION ONE: QUESTIONS 1–50
1. Which essential cloud characteristic allows a consumer to unilaterally provision
computing capabilities, such as server time and network storage, as needed
automatically without requiring human interaction with each service provider?
,A. Broad network access
B. Rapid elasticity
C. On-demand self-service
D. Measured service
🟢 Correct Answer: C. On-demand self-service
🔴 Explanation: NIST SP 800-145 defines on-demand self-service as the ability to
provision resources automatically without human intervention with the provider.
This enables agility and eliminates traditional provisioning delays .
2. A healthcare organization needs a cloud deployment model that is
provisioned for exclusive use by several hospitals that share common regulatory
and security concerns. Which model best fits this requirement?
A. Public cloud
B. Community cloud
C. Hybrid cloud
D. Private cloud
🟢 Correct Answer: B. Community cloud
🔴 Explanation: A community cloud is shared by organizations with common
concerns (e.g., mission, security, compliance), making it ideal for a group of
hospitals with shared healthcare regulations .
3. In which cloud service model does the customer retain the MOST
responsibility for managing the operating system, middleware, and applications?
A. Software as a Service (SaaS)
B. Platform as a Service (PaaS)
C. Infrastructure as a Service (IaaS)
D. Function as a Service (FaaS)
🟢 Correct Answer: C. Infrastructure as a Service (IaaS)
,🔴 Explanation: In IaaS, the provider manages the physical infrastructure and
hypervisor, while the customer is responsible for the guest OS, middleware,
runtime, applications, and data .
4. A financial services firm is migrating a transaction processing system to a
public IaaS environment. According to the shared responsibility model, which
security control remains the customer's primary responsibility?
A. Physical security of the data center
B. Patching the underlying hypervisor
C. Guest operating system hardening and application security
D. Compliance certifications for the underlying cloud infrastructure
🟢 Correct Answer: C. Guest operating system hardening and application security
🔴 Explanation: Under IaaS, the provider secures the physical facility and
hypervisor. The customer is responsible for securing the guest OS, applications,
identity management, and data .
5. Which cloud data lifecycle phase is primarily concerned with the enforcement
of Data Loss Prevention (DLP) egress controls?
A. Create
B. Store
C. Share
D. Archive
🟢 Correct Answer: C. Share
🔴 Explanation: The Share phase involves exposing data to external parties. DLP
inspection and blocking controls are enforced during this phase to prevent
unauthorized data exfiltration .
6. An organization requires a cloud solution that provides a complete application
accessed via a browser, with the provider managing all underlying infrastructure,
, OS, and application logic. Which service model is this?
A. IaaS
B. PaaS
C. SaaS
D. DaaS
🟢 Correct Answer: C. SaaS
🔴 Explanation: Software as a Service delivers a complete, provider-managed
application to end users. The customer only manages user access and data
configuration .
7. Which cloud deployment model is defined as a composition of two or more
distinct cloud infrastructures that remain unique entities but are bound by
technology enabling data and application portability?
A. Public cloud
B. Private cloud
C. Community cloud
D. Hybrid cloud
🟢 Correct Answer: D. Hybrid cloud
🔴 Explanation: A hybrid cloud combines private and public (or community) clouds
with orchestration between them, allowing workloads to move based on business
needs .
8. A cloud architect is designing a multi-region active-active architecture that
replicates customer PII across three geographic regions. What is the PRIMARY
security concern raised by this design?
A. Increased network latency
B. Higher inter-region bandwidth costs