WGU C838 EXAMS SET 2025 QUESTIONS AND ANSWERS
RATED A+
✔✔"Which technology typically provides security isolation in infrastructure as a service
(IaaS) cloud
(A) computing?
(B) Virtual machines
(C) Operating systems
(D) Application instance" - ✔✔Virtual machines
✔✔"Which technology can an administrator us to remotely manage a fleet of servers?
(A) Bastion host
(B) Management plane
(C) VPN concentrator
(D) KVM switch" - ✔✔(B) Management plane
✔✔"What part of the logical infrastructure design is used to configure cloud resources,
such as launching virtual machines or configuring virtual networks?
(A) Management plane
(B) Database management
(C) Identity access management
(D) Management orchestration software" - ✔✔Management plane
✔✔"Which action enhances cloud security application deployment through standards
such as ISO/IEC 27034 for the development, acquisition, and configuration of software
systems?
(A) Applying the steps of a cloud software development lifecycle
(B) Providing developer access to supporting components and services
(C) Outsourcing the infrastructure and integration platform management
(D) Verifying the application has an appropriate level of confidentiality and integrity" -
✔✔Applying the steps of a cloud software development lifecycle
✔✔"Which type of agreement aims to negotiate policies with various parties in
accordance with the agreed- upon targets?
(A) User license (ULA)
(B) Service-level (SLA)
(C) Privacy-level (PLA)
(D) Operation-level (OLA)" - ✔✔Service-level (SLA)
✔✔"Which regulation requires a CSP to comply with copyright law for hosted content?
(A) SOX
(B) SCA
(C) GLBA
(D) DMCA" - ✔✔DMCA
, Digital Millennium Copyright Act
✔✔"Which element is a cloud virtualization risk?
(A) Licensing
(B) Jurisdiction
(C) Guest isolation
(D) Electronic discovery" - ✔✔Guest isolation
✔✔"Which risk is related to interception of data in transit?
(A) Virtualization
(B) Traffic blocking
(C) Man-in-the-middle
(D) Software vulnerabilities" - ✔✔Man-in-the-middle
✔✔"Which method is being used when a company evaluates the acceptable loss
exposure associated with a cloud solution for a given set of objectives and resources?
(A) Risk appetite
(B) Risk management
(C) Business impact analysis
(D) Business continuity planning" - ✔✔Risk appetite
✔✔"The security administrator for a global cloud services provider (CSP) is required to
globally standardize the approaches for using forensics methodologies in the
organization.
Which standard should be applied?
(A) Sarbanes-Oxley act (SOX)
(B) Cloud controls matrix (CCM)
(C) International electrotechnical commission (IEC) 27037
(D) International organization for standardization (ISO) 27050-1" - ✔✔International
organization for standardization (ISO) 27050-1
✔✔"Which detection and analysis technique is performed to capture a point-in-time
picture of the entire stack at the time of an incident?
(A) Review data access logs
(B) Examine configuration data
(C) Collect metadata during alert
(D) Create a snapshot using API calls" - ✔✔Create a snapshot using API calls
✔✔"A CSP operating in Australia experiences a security breach that results in
disclosure of personal information that is likely to result in serious harm. Who is the CSP
legally required to notify?
(A) Cloud Security Alliance
(B) Information commissioner
(C) Australian privacy foundation
(D) Asian-Paci?c privacy control board" - ✔✔Information commissioner
RATED A+
✔✔"Which technology typically provides security isolation in infrastructure as a service
(IaaS) cloud
(A) computing?
(B) Virtual machines
(C) Operating systems
(D) Application instance" - ✔✔Virtual machines
✔✔"Which technology can an administrator us to remotely manage a fleet of servers?
(A) Bastion host
(B) Management plane
(C) VPN concentrator
(D) KVM switch" - ✔✔(B) Management plane
✔✔"What part of the logical infrastructure design is used to configure cloud resources,
such as launching virtual machines or configuring virtual networks?
(A) Management plane
(B) Database management
(C) Identity access management
(D) Management orchestration software" - ✔✔Management plane
✔✔"Which action enhances cloud security application deployment through standards
such as ISO/IEC 27034 for the development, acquisition, and configuration of software
systems?
(A) Applying the steps of a cloud software development lifecycle
(B) Providing developer access to supporting components and services
(C) Outsourcing the infrastructure and integration platform management
(D) Verifying the application has an appropriate level of confidentiality and integrity" -
✔✔Applying the steps of a cloud software development lifecycle
✔✔"Which type of agreement aims to negotiate policies with various parties in
accordance with the agreed- upon targets?
(A) User license (ULA)
(B) Service-level (SLA)
(C) Privacy-level (PLA)
(D) Operation-level (OLA)" - ✔✔Service-level (SLA)
✔✔"Which regulation requires a CSP to comply with copyright law for hosted content?
(A) SOX
(B) SCA
(C) GLBA
(D) DMCA" - ✔✔DMCA
, Digital Millennium Copyright Act
✔✔"Which element is a cloud virtualization risk?
(A) Licensing
(B) Jurisdiction
(C) Guest isolation
(D) Electronic discovery" - ✔✔Guest isolation
✔✔"Which risk is related to interception of data in transit?
(A) Virtualization
(B) Traffic blocking
(C) Man-in-the-middle
(D) Software vulnerabilities" - ✔✔Man-in-the-middle
✔✔"Which method is being used when a company evaluates the acceptable loss
exposure associated with a cloud solution for a given set of objectives and resources?
(A) Risk appetite
(B) Risk management
(C) Business impact analysis
(D) Business continuity planning" - ✔✔Risk appetite
✔✔"The security administrator for a global cloud services provider (CSP) is required to
globally standardize the approaches for using forensics methodologies in the
organization.
Which standard should be applied?
(A) Sarbanes-Oxley act (SOX)
(B) Cloud controls matrix (CCM)
(C) International electrotechnical commission (IEC) 27037
(D) International organization for standardization (ISO) 27050-1" - ✔✔International
organization for standardization (ISO) 27050-1
✔✔"Which detection and analysis technique is performed to capture a point-in-time
picture of the entire stack at the time of an incident?
(A) Review data access logs
(B) Examine configuration data
(C) Collect metadata during alert
(D) Create a snapshot using API calls" - ✔✔Create a snapshot using API calls
✔✔"A CSP operating in Australia experiences a security breach that results in
disclosure of personal information that is likely to result in serious harm. Who is the CSP
legally required to notify?
(A) Cloud Security Alliance
(B) Information commissioner
(C) Australian privacy foundation
(D) Asian-Paci?c privacy control board" - ✔✔Information commissioner