ANSWERS | 140 VERIFIED QUESTIONS & A+ CORRECT RESPONSES
Covering key concepts from the cloud data security lifecycle, this
WGU C838 pre-assessment guide includes essential topics such as
data use and processing phases, simultaneous storage events, use
of content delivery networks in sharing, and crypto-shredding in
data destruction. Each multiple-choice question is paired with the
correct response and reflects current industry practices in cloud
security. Perfect for quick review or in-depth study, this A+ verified
material supports fast and focused exam preparation for WGU
students.
"Which action enhances cloud security application deployment through standards such as ISO/IEC
27034 for the development, acquisition, and configuration of software systems?
(A) Applying the steps of a cloud software development lifecycle
(B) Providing developer access to supporting components and services
(C) Outsourcing the infrastructure and integration platform management
(D) Verifying the application has an appropriate level of confidentiality and integrity" - CORRECT
ANSWER-Applying the steps of a cloud software development lifecycle
"Which type of agreement aims to negotiate policies with various parties in accordance with the
agreed- upon targets?
(A) User license (ULA)
(B) Service-level (SLA)
(C) Privacy-level (PLA)
(D) Operation-level (OLA)" - CORRECT ANSWER-Service-level (SLA)
"Which regulation requires a CSP to comply with copyright law for hosted content?
(A) SOX
(B) SCA
(C) GLBA
,(D) DMCA" - CORRECT ANSWER-DMCA
Digital Millennium Copyright Act
"Which element is a cloud virtualization risk?
(A) Licensing
(B) Jurisdiction
(C) Guest isolation
(D) Electronic discovery" - CORRECT ANSWER-Guest isolation
"Which risk is related to interception of data in transit?
(A) Virtualization
(B) Traffic blocking
(C) Man-in-the-middle
(D) Software vulnerabilities" - CORRECT ANSWER-Man-in-the-middle
"Which method is being used when a company evaluates the acceptable loss exposure associated
with a cloud solution for a given set of objectives and resources?
(A) Risk appetite
(B) Risk management
(C) Business impact analysis
(D) Business continuity planning" - CORRECT ANSWER-Risk appetite
"The security administrator for a global cloud services provider (CSP) is required to globally
standardize the approaches for using forensics methodologies in the organization.
Which standard should be applied?
(A) Sarbanes-Oxley act (SOX)
(B) Cloud controls matrix (CCM)
(C) International electrotechnical commission (IEC) 27037
(D) International organization for standardization (ISO) 27050-1" - CORRECT ANSWER-International
organization for standardization (ISO) 27050-1
, "Which detection and analysis technique is performed to capture a point-in-time picture of the
entire stack at the time of an incident?
(A) Review data access logs
(B) Examine configuration data
(C) Collect metadata during alert
(D) Create a snapshot using API calls" - CORRECT ANSWER-Create a snapshot using API calls
"A CSP operating in Australia experiences a security breach that results in disclosure of personal
information that is likely to result in serious harm. Who is the CSP legally required to notify?
(A) Cloud Security Alliance
(B) Information commissioner
(C) Australian privacy foundation
(D) Asian-Paci?c privacy control board" - CORRECT ANSWER-Information commissioner
"A CSP provides services in European Union (EU) countries that are subject to the network
information security (NIS) directive. The CSP experiences an incident that significantly affects the
continuity of the essential services being provided.
Who is the CSP required to notify under the NIS directive?
(A) Competent authorities
(B) Data protection regulator
(C) Provider's services suppliers
(D) Personal Information Protection Commission" - CORRECT ANSWER-Competent authorities
"A cloud customer is setting up communication paths with the cloud service provider that will be
used in the event of an incident.
Which action facilitates this type of communication?
(A) Using existing open standards
(B) Incorporating checks on API calls
(C) Identifying key risk indicators (KRIs)
(D) Performing a vulnerability assessment" - CORRECT ANSWER-Using existing open standards
"Which security control does the software as a service (SaaS) model require as a shared
responsibility of all parties involved?