• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 103 pages
Exam (elaborations)

WGU D320 Managing Cloud Security Exam 2026 | 173 Most Tested Questions & Correct Answers | Latest Update | Graded A+

Document preview thumbnail
Preview 4 out of 103 pages

WGU D320 Managing Cloud Security Exam Study Guide 2026 | Complete Review | Graded A+ 173 questions with the correct answer marked on every item, covering all the core content tested on the WGU D320 Managing Cloud Security Objective Assessment. Important — scope of this document: this set covers the OA content for WGU D320 Managing Cloud Security. It is a study aid designed to reinforce your understanding — not a brain dump or leaked exam. What's covered: Cloud service models – IaaS, PaaS, and SaaS definitions, service delivery differences, customer responsibility levels, risks unique to each model including interoperability, virtualization, resource sharing, and web application security Business Impact Analysis (BIA) – purpose, role in risk management, contribution to recovery planning, primary outcomes, prioritizing recovery strategies after disruption Risk management – risk appetite, transference, mitigation, quantitative vs qualitative risk assessment, gap analysis, risk transfer strategies Encryption and data protection – encryption at rest and in transit, decryption, crypto-shredding, key deletion, hashing vs encryption, data at rest definitions Data lifecycle – creation, storage, usage, sharing, archiving, and destruction stages, significance of each phase, archiving risks and compliance issues Data Loss Prevention (DLP) – purpose, how it mitigates unauthorized sharing, role in data security Compliance and legal frameworks – FERPA, HIPAA, SOX, GDPR, PIPEDA, FedRAMP, FISMA, PCI DSS, ISO 27001, NIST 800-92, SOC 1, SOC 2, SOC 3, CSA STAR program Data roles and governance – data custodian responsibilities, data owner vs steward, metadata-based discovery, content-based vs label-based vs extension-based discovery Threat modeling – purpose in application security, identifying vulnerabilities early, proactive security integration Defense in depth – multiple layers of security, information assurance approach, layered controls across physical, technical, and policy levels Zero-day vulnerabilities – definition, implications for organizations, immediate mitigation actions, difference from configuration vulnerabilities CSRF and web attacks – cross-site request forgery mechanics, CSRF vs XSS vs SQL injection, token-based mitigation, hidden field manipulation, command injection Cloud security testing – white-box testing (SAST), black-box testing, gray-box testing, pen testing, DAST, port scanning Hypervisors and virtualization – creating and managing virtual machines, multiple operating systems on one host, hardware abstraction, live migration Content Delivery Networks (CDN) – geographic content delivery, reducing latency, edge servers, cached content, load times Geofencing – virtual geographic boundaries, mobile application triggers, promotional use cases, risk management applications Audits and assessments – external vs internal vs operational vs compliance audits, SOC 1 report for financial reporting, auditor independence, gap analysis in strategic planning Software as a Service (SaaS) – subscription model, provider-managed maintenance, web application vulnerability risks, vendor risk management Platform as a Service (PaaS) – application development platform, third-party API and supply chain risks, virtualization concerns, resource sharing risks Infrastructure as a Service (IaaS) – virtualized computing resources, customer responsibility, personnel threats, misconfiguration accountability Security frameworks and standards – ISO 27001 ISMS framework, NIST 800-92 log management, FedRAMP standardized assessments, CSA STAR security evaluations, HIPAA privacy, PIPEDA Canadian law Risk assessment methods – quantitative risk assessment numerical values, qualitative risk assessment descriptive categories, risk appetite definitions Data destruction – crypto-shredding, degaussing, wiping, overwriting, irretrievable data, deletion of encryption keys

Content preview

WGU D320 Exam Questions & Correct Answers 2026 |
Latest Update | Graded A+
1. What is the primary purpose of Business Impact Analysis (BIA)?

To create marketing strategies for business growth.

To identify and evaluate the potential effects of disruptions to
business operations.

To analyze financial statements for investment decisions.

To assess employee performance and productivity.

2. Describe the role of threat modeling in enhancing application security.

Threat modeling is used to create marketing strategies for
applications.

Threat modeling focuses solely on user experience design.

Threat modeling helps developers understand vulnerabilities and
implement appropriate security measures.

Threat modeling is irrelevant to application security.

3. What are the three primary cloud service models?

Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and
Software as a Service (SaaS)

Platform as a Service (PaaS), Network as a Service (NaaS), and
Software as a Service (SaaS)

Infrastructure as a Service (IaaS), Database as a Service (DBaaS), and
Software as a Service (SaaS)

Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and
Network as a Service (NaaS)

,4. If a company discovers a zero-day vulnerability in its software, what
immediate action should it take to mitigate potential risks?

Ignore the vulnerability until a patch is released.

Stop all operations until the vulnerability is fixed.

Implement temporary security measures and inform stakeholders
while working on a patch.

Publicly disclose the vulnerability to all users immediately.

5. is a way of temporarily converting data into an unreadable form in order
to protect that data from being viewed by unauthorized individuals.

Authentication

Decryption

Authorization

Encryption

6. What are the key stages of the data lifecycle?

Creation, storage, usage, sharing, archiving, and destruction.

Creation, processing, analysis, reporting, and deletion.

Creation, storage, sharing, and deletion.

Collection, storage, analysis, sharing, and disposal.

7. Describe the main purpose of FERPA in relation to student education
records.

FERPA requires schools to disclose all student records to the public.

FERPA protects the privacy of student education records and grants
rights to parents that transfer to students at age 18.

, FERPA only applies to students in higher education institutions.

FERPA allows schools to share student records with any third party
without consent.

8. Describe how web application security vulnerabilities can impact the SaaS
service model.

Web application security vulnerabilities only affect the performance
of the application.

Web application security vulnerabilities can be completely mitigated
by using encryption.

Web application security vulnerabilities can lead to unauthorized
access, data breaches, and loss of customer trust.

Web application security vulnerabilities are irrelevant in the SaaS
model.

9. Describe how Business Impact Analysis (BIA) contributes to effective risk
management in organizations.

BIA contributes to effective risk management by providing insights
that guide resource allocation and recovery strategies.

BIA focuses solely on financial risks without considering operational
impacts.

BIA is a tool for developing new product lines.

BIA is used to assess employee performance and productivity.

10. Describe how encryption methods contribute to data security.

Encryption methods are used to increase data storage capacity.

Encryption methods secure data by converting it into a coded
format that only authorized parties can read.

, Encryption methods are primarily for data backup purposes.

Encryption methods allow all users to access data freely.


11. What is the primary goal of a defense-in-depth strategy in cybersecurity?

To create a single layer of security defenses

To eliminate all security vulnerabilities

To provide multiple layers of security to mitigate risks

To rely solely on encryption for protection

12. What does the term 'data at rest' refer to?

Data that is transmitted over a network.

Inactive data stored physically in any digital form.

Data that is deleted from storage.

Data that is actively being processed.

13. Describe how personnel threats can impact the IaaS service model.

Personnel threats are mitigated by encryption methods in the IaaS
model.

Personnel threats can lead to unauthorized access and misuse of
resources in the IaaS model.

Personnel threats are irrelevant to the IaaS model as it is fully
automated.

Personnel threats only affect physical data centers, not cloud
services.

Document information

Uploaded on
October 5, 2026
Number of pages
103
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$14.00

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
1
Followers
0
Items
191
Last sold
2 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions