WGU C838 - Managing Cloud Security Quizlet by Brian MacFarlane
WGU C838 - Managing Cloud Security Quizlet by Brian MacFarlane. Which phase of the cloud data life cycle is associated with crypto-shredding? A Share B Use C Destroy D Store - Answer C Which cloud data storage architecture allows sensitive data to be replaced with unique identification symbols that retain all the essential information about the data without compromising its security? A Randomization B Obfuscation C Anonymization D Tokenization - Answer D Which methodology could cloud data storage utilize to encrypt all data associated in an infrastructure as a service (IaaS) deployment model? A Sandbox encryption B Polymorphic encryption C Client-side encryption D Whole-instance encryption - Answer D There is a threat to a banking cloud platform service. The developer needs to provide inclusion in a relational database that is seamless and readily searchable by search engine algorithms. Which platform as a service (PaaS) data type should be used? A Short-term storage B Structured C Unstructured D Long-term storage - Answer B Which platform as a service (PaaS) storage architecture should be used if an organization wants to store presentations, documents, and audio files? A Relational database B Block C Distributed D Object - Answer D Which technique scrambles the content of data using a mathematical algorithm while keeping the structural arrangement of the data? A Dynamic masking B Format-preserving encryption C Proxy-based encryption D Tokenization - Answer B Which encryption technique connects the instance to the encryption instance that handles all crypto operations? A Database B Proxy C Externally managed D Server-side - Answer B Which type of control should be used to implement custom controls that safeguard data? A Public and internal sharing B Options for access C Management plane D Application level - Answer D Which element is protected by an encryption system? A Ciphertext B Management engine C Data D Public key - Answer C A cloud administrator recommends using tokenization as an alternative to protecting data without encryption. The administrator needs to make an authorized application request to access the data. Which step should occur immediately before this action is taken? A The tokenization server returns the token to the application. B The tokenization server generates the token. C The application collects a token. D The application stores the token. - Answer D A company has recently defined classification levels for its data. During which phase of the cloud data life cycle should this definition occur? A Use B Create C Share D Archive - Answer B Which jurisdictional data protection includes dealing with the international transfer of data? A Financial modernization B Secure choice authorization (SCA) C Sarbanes-Oxley act (SOX) D Privacy regulation - Answer D Which jurisdictional data protection controls the ways that financial institutions deal with the private information of individuals? A Stored communications act (SCA) B Health insurance portability and accountability act (HIPAA) C Gramm-Leach-Bliley act (GLBA) D Sarbanes-Oxley act (SOX) - Answer C Which jurisdictional data protection safeguards protected health information (PHI)? A Directive 95/46/EC B Safe harbor regime C Personal Data Protection Act of 2000 D Health Insurance Portability and Accountability Act (HIPAA) - Answer D How is the compliance of the cloud service provider's legal and regulatory requirements verified when securing personally identifiable information (PII) data in the cloud? A Contractual agreements B Third-party audits and attestations C e-Discovery process D Researching data retention laws - Answer B Which security strategy is associated with data rights management solutions? A Unrestricted replication B Limited documents type support C Static policy control D Continuous auditing - Answer D Who retains final ownership for granting data access and permissions in a shared responsibility model? A Customer B Developer C Manager D Analyst - Answer A Which data retention solution should be applied to a file in order to reduce the data footprint by deleting fixed content and duplicate data? A Backup B Caching C Archiving D Saving - Answer C Which data retention method is stored with a minimal amount of metadata storage with the content? A File system B Redundant array C Object-based D Block-based - Answer D What is a key capability of security information and event management? A Intrusion prevention capabilities B Automatic remediation of issues C Centralized collection of log data D Secure remote access - Answer C Which data source provides auditability and traceability for event investigation as well as documentation? A Storage files B Packet capture C Network interference D Database tables - Answer B Which data source provides auditability and traceability for event investigation as well as documentation? A Network segmentation B Ephemeral storage C Database schema D Virtualization platform logs - Answer D Which technology is used to manage identity access management by building trust relationships between organizations? A Single sign-on B Multifactor authentication C Federation D Biometric authentication - Answer C Which term describes the action of confirming identity access to an information system? A Coordination B Concept C Access D Authentication - Answer D Which cloud computing tool is used to discover internal use of cloud services using various mechanisms such as network monitoring? A Data loss prevention (DLP) B Content delivery network (CDN) C Cloud access security broker (CASB) D Web application firewall (WAF) - Answer C Which cloud computing technology unlocks business value through digital and physical access to maps? A Multitenancy B Cloud application C Application programming interface D On-demand self-service - Answer C Which cloud computing tool may help detect data migrations to cloud services? A Uniform resource locator (URL) filtering B Cloud security gateways C Cloud data transfer D Data loss prevention - Answer D What is a key component of the infrastructure as a service (IaaS) cloud service model? A Allows choice and reduces lock-in B Supports multiple languages and frameworks C Ease of use and limited administration D High reliability and resilience - Answer D What is a key capability of infrastructure as a service (IaaS)? A Hosted application management B Converged network and IT capacity pool C Leased application and software licensing D Multiple hosting environments - Answer B Which option should an organization choose if there is a need to avoid software ownership? A Software as a service (SaaS) B Platform as a service (PaaS) C Containers as a service (CaaS) D Infrastructure as a service (IaaS) - Answer A Which cloud model offers access to a pool of fundamental IT resources such as computing, networking, or storage? A Infrastructure B Platform C Application D Data - Answer A In which situation could cloud clients find it impossible to recover or access their own data if their cloud provider goes bankrupt? A Vendor lock-in B Multitenant C Multicloud D Vendor lock-out - Answer D Which cloud deployment model is operated for a single organization? A Consortium B Hybrid C Public D Private - Answer D Which cloud model provides data location assurance? A Hybrid B Private C Community D Public - Answer B Which cloud model allows the consumer to have sole responsibility for management and governance? A Hybrid B Community C Private D Public - Answer C Which technology allows an organization to control access to sensitive documents stored in the cloud? A Digital rights management (DRM) B Database activity monitoring (DAM) C Identity and access management (IAM) D Distributed resource scheduling (DRS) - Answer A Which security technology can provide secure network communications from on-site enterprise systems to a cloud platform? A Domain name system security extensions (DNSSEC) B Internet protocol security (IPSec) virtual private network (VPN) C Web application firewall (WAF) D Data loss prevention (DLP) - Answer B How do immutable workloads effect security overhead? A They reduce the management of the hosts. B They automatically perform vulnerability scanning as they launch. C They restrict the amount of instances in a cluster. D They create patches for a running workload. - Answer A Which document addresses CSP issues such as guaranteed uptime, liability, penalties, and dispute mediation process? A General data protection regulation (GDPR) B Service organization control 3 (SOC 3) C Service level agreement (SLA) D Common criteria assurance framework (CC) - Answer C Which design principle of secure cloud computing ensures that the business can resume essential operations in the event of an availability-affecting incident? A Disaster recovery B Resource pooling C Access control D Session management - Answer A Which design principle of secure cloud computing ensures that users can utilize data and applications from around the globe? A Portability B Scalability C On-demand self-service D Broad network access - Answer D Which design principle of secure cloud computing involves deploying cloud service provider resources to maximize availability in the event of a failure? A Elasticity B Resiliency C Scalability D Clustering - Answer B Which item should be part of the legal framework analysis if a company wishes to store prescription drug records in a SaaS solution? A Sarbanes-Oxley Act B Health Insurance Portability and Accountability Act C Federal Information Security Modernization Act D U.S. Patriot Act - Answer B Which standard addresses practices related to acquisition of forensic artifacts and can be directly applied to a cloud environment? A NIST SP 500-291 B ISO/IEC 27001 C NIST SP 800-145 D ISO/IEC 27050-1 - Answer D Which regulation in the United States defines the requirements for a CSP to implement and report on internal accounting controls? A HIPAA B SOX C FERPA D GDPR - Answer B Which legislation must a trusted cloud service adhere to when utilizing the data of EU citizens? A GDPR B EMTALA C APPI D SOX - Answer A Which logical design decision can be attributed to required regulation? A Database writes/second B Retention periods C Retention formats D Database reads/second - Answer B Which service model influences the logical design by using additional measures in the application to enhance security? A Hybrid cloud B Public cloud C Software as a service (SaaS) D Platform as a service (PaaS) - Answer C Which environmental consideration should be addressed when planning the design of a data center? A Heating and ventilation B Utility power availability C Expansion possibilities and growth D Telecommunications connections - Answer A Which result is achieved by removing all nonessential services and software of devices for secure configuration of hardware? A Hardening B Maintenance C Patching D Lockdown - Answer A What is a component of device hardening? A Patching B Unit testing C Versioning D Configuring VPN access - Answer A Which technology typically provides security isolation in infrastructure as a service (IaaS) cloud computing? A Application instance B System image repository C Virtual machines D Operating systems - Answer C Which technology an administrator to remotely manage a fleet of servers? A KVM switch B VPN concentrator C Bastion host D Management plane - Answer D What part of the logical infrastructure design is used to configure cloud resources, such as launching virtual machines or configuring virtual networks? A Management orchestration software B Management plane C Identity access management D Database management - Answer B
Written for
- Institution
-
Western Governors University
- Course
-
WGU C838 (WGUC838)
Document information
- Uploaded on
- February 6, 2023
- Number of pages
- 149
- Written in
- 2022/2023
- Type
- Exam (elaborations)
- Contains
- Questions & answers
Also available in package deal