D320 Managing Cloud Security WGU: Questions With
Correct Solutions
Sarbanes-Oxley (SOX) Act Right Ans - increase transparency into publicly
traded corporations' financial activities
Gramm-Leach-Bliley Act (GLBA) Right Ans - allow banks to merge and own
insurance companies
Clarifying Lawful Overseas Use of Data (CLOUD) Act Right Ans - Allows US
law enforcement and courts to compel American companies to disclose data
stored in foreign data centers
FERPA Right Ans - prevent academic institutions from sharing student data
other than parents or student
Master service agreement (MSA) Right Ans - provide an umbrella contract
for the work that a vendor does with an organization over an extended period
of time
Service level agreement (SLA) Right Ans - written contracts that specify the
conditions of service that will be provided by the vendor and the remedies
available to the customer if the vendor fails to meet the SLA
Business partnership agreement (BPA) Right Ans - exist when two
organizations agree to do business with each other in a partnerhsip
memorandum of understanding (MOU) Right Ans - a letter written to
document aspects of the relationship to avoid future misunderstandings
OWASP Top Ten Right Ans - a standard awareness document for
developers and web application security, it represents a broad consensus
about the most critical security risks to web applications.
OWASP 1: Access Control Right Ans - enforces policy such that users
cannot act outside of their intended permissions
,OWASP 2: Cryptographic Failures Right Ans - focus is on failures related to
cryptography (or lack thereof), Which often lead to exposure of sensitive data.
OWASP 3: Injection Right Ans - an attacker's attempt to send data to an
application in a way that will change the meaning of commands being sent to
an interpreter
OWASP 4: Insecure Design Right Ans - focuses on risks related to design
and architectural flaws, with a call for more use of threat modeling, secure
design patterns, and reference architectures
OWASP 5: Security Misconfiguration Right Ans - occurs when system or
application configuration settings are missing or are erroneously
implemented, allowing unauthorized access
OWASP 6: Vulnerable and Outdated Components Right Ans - third-party
libraries or frameworks used in web applications that have known
vulnerabilities or are no longer supported by their developers
OWASP 7: Identification and Authentication Failures Right Ans - The
failure of a system to identify and/or authenticate leaves the application
susceptible to attacks and leaves user accounts/data at risk
OWASP 8: Software and Data Integrity Failures Right Ans - relate to code
and infrastructure that does not protect against integrity violations; occur
when an attacker can modify or delete data in an unauthorized manner
OWASP 9: Security Logging and Monitoring Failures Right Ans - this
category is to help detect, escalate, and respond to active breaches, without
logging and monitoring, breaches cannot be detected
OWASP 10: Server Side Request Forgery (SSRF) Right Ans - occur
whenever a web application is fetching a remote resource without validating
the user-supplied URL, allows an attacker to coerce the application to send a
crafted request to an unexpected destination, even when protected by a
firewall, VPN, or another type of network access control list (ACL).
data lifecycle Right Ans - Create, Store, Use, Share, Archive, Destroy
, SOC 1 Report Right Ans - strictly for auditing the financial reporting
instruments of a corporation
SOC 2 Report Right Ans - Intended to report audits of any controls on an
organization's security, availability, processing integrity, confidentiality, and
privacy
SOC 3 Report Right Ans - Designed to be shared with the public, does not
contain any actual data about the security controls of the audit target.
SOC 2 Type 1 Report Right Ans - Reviews the design of controls, not how
they are implemented or maintained
SOC 2 Type 2 Report Right Ans - Used for getting a true assessment of an
organization's security posture
IaaS risks Right Ans - 1. Personnel threats (insiders)
2. External threats (malware, hacking, DDoS, MITM)
3. Lack of specific skillsets
PaaS risks Right Ans - 1. Interoperability issues
2. Persistent backdoors, DevOps
3. Virtualization
4. Resource sharing
SaaS risks Right Ans - 1. Proprietary formats
2. Virtualization
3. Web app security
regulators Right Ans - involved in cloud service arrangements
critiques Right Ans - falls under the exceptions category for "fair-use"
copyrighted material
Cloud-Secure Software Deployment Lifecycle (SDLC) Right Ans - Defining,
Designing, Development, Testing, Secure Operations, Disposal
Correct Solutions
Sarbanes-Oxley (SOX) Act Right Ans - increase transparency into publicly
traded corporations' financial activities
Gramm-Leach-Bliley Act (GLBA) Right Ans - allow banks to merge and own
insurance companies
Clarifying Lawful Overseas Use of Data (CLOUD) Act Right Ans - Allows US
law enforcement and courts to compel American companies to disclose data
stored in foreign data centers
FERPA Right Ans - prevent academic institutions from sharing student data
other than parents or student
Master service agreement (MSA) Right Ans - provide an umbrella contract
for the work that a vendor does with an organization over an extended period
of time
Service level agreement (SLA) Right Ans - written contracts that specify the
conditions of service that will be provided by the vendor and the remedies
available to the customer if the vendor fails to meet the SLA
Business partnership agreement (BPA) Right Ans - exist when two
organizations agree to do business with each other in a partnerhsip
memorandum of understanding (MOU) Right Ans - a letter written to
document aspects of the relationship to avoid future misunderstandings
OWASP Top Ten Right Ans - a standard awareness document for
developers and web application security, it represents a broad consensus
about the most critical security risks to web applications.
OWASP 1: Access Control Right Ans - enforces policy such that users
cannot act outside of their intended permissions
,OWASP 2: Cryptographic Failures Right Ans - focus is on failures related to
cryptography (or lack thereof), Which often lead to exposure of sensitive data.
OWASP 3: Injection Right Ans - an attacker's attempt to send data to an
application in a way that will change the meaning of commands being sent to
an interpreter
OWASP 4: Insecure Design Right Ans - focuses on risks related to design
and architectural flaws, with a call for more use of threat modeling, secure
design patterns, and reference architectures
OWASP 5: Security Misconfiguration Right Ans - occurs when system or
application configuration settings are missing or are erroneously
implemented, allowing unauthorized access
OWASP 6: Vulnerable and Outdated Components Right Ans - third-party
libraries or frameworks used in web applications that have known
vulnerabilities or are no longer supported by their developers
OWASP 7: Identification and Authentication Failures Right Ans - The
failure of a system to identify and/or authenticate leaves the application
susceptible to attacks and leaves user accounts/data at risk
OWASP 8: Software and Data Integrity Failures Right Ans - relate to code
and infrastructure that does not protect against integrity violations; occur
when an attacker can modify or delete data in an unauthorized manner
OWASP 9: Security Logging and Monitoring Failures Right Ans - this
category is to help detect, escalate, and respond to active breaches, without
logging and monitoring, breaches cannot be detected
OWASP 10: Server Side Request Forgery (SSRF) Right Ans - occur
whenever a web application is fetching a remote resource without validating
the user-supplied URL, allows an attacker to coerce the application to send a
crafted request to an unexpected destination, even when protected by a
firewall, VPN, or another type of network access control list (ACL).
data lifecycle Right Ans - Create, Store, Use, Share, Archive, Destroy
, SOC 1 Report Right Ans - strictly for auditing the financial reporting
instruments of a corporation
SOC 2 Report Right Ans - Intended to report audits of any controls on an
organization's security, availability, processing integrity, confidentiality, and
privacy
SOC 3 Report Right Ans - Designed to be shared with the public, does not
contain any actual data about the security controls of the audit target.
SOC 2 Type 1 Report Right Ans - Reviews the design of controls, not how
they are implemented or maintained
SOC 2 Type 2 Report Right Ans - Used for getting a true assessment of an
organization's security posture
IaaS risks Right Ans - 1. Personnel threats (insiders)
2. External threats (malware, hacking, DDoS, MITM)
3. Lack of specific skillsets
PaaS risks Right Ans - 1. Interoperability issues
2. Persistent backdoors, DevOps
3. Virtualization
4. Resource sharing
SaaS risks Right Ans - 1. Proprietary formats
2. Virtualization
3. Web app security
regulators Right Ans - involved in cloud service arrangements
critiques Right Ans - falls under the exceptions category for "fair-use"
copyrighted material
Cloud-Secure Software Deployment Lifecycle (SDLC) Right Ans - Defining,
Designing, Development, Testing, Secure Operations, Disposal