WGU D320 Managing Cloud Security
JYO2 200 Questions Exam Actual Exam
2026/2027 – Verified Answers – A+
Graded (Instant Download)
Section 1: Shared Responsibility Model & Cloud Deployment
Q1: In the AWS Shared Responsibility Model, which of the
following is the customer's responsibility when using Amazon
EC2?
A. Physical security of data centers
B. Patching the underlying hypervisor
C. Operating system security patching and firewall
configuration [CORRECT]
D. Ensuring power and cooling for infrastructure
Rationale: Under the AWS Shared Responsibility Model, when
using Infrastructure-as-a-Service (IaaS) like EC2, AWS manages
the security of the cloud (physical infrastructure, hypervisor,
network), while the customer is responsible for security in the
cloud, including operating system patching, application security,
data encryption, and firewall configuration.
,Q2: Which cloud deployment model provides the highest
level of control and security for an organization with strict
compliance requirements?
A. Public cloud
B. Community cloud
C. Private cloud [CORRECT]
D. Hybrid cloud
Rationale: A private cloud deployment model provides dedicated
infrastructure for a single organization, offering the highest level
of control over security configurations, physical infrastructure, and
compliance implementations, making it ideal for organizations
with strict regulatory requirements that cannot be met in multi-
tenant environments.
Q3: Which cloud service model gives customers the MOST
responsibility for managing operating systems and
applications?
A. SaaS
B. PaaS
C. IaaS [CORRECT]
D. FaaS
Rationale: In Infrastructure as a Service (IaaS), customers manage
operating systems, middleware, applications, and data, while the
cloud provider manages physical infrastructure. SaaS provides the
least customer responsibility, and PaaS falls in between.
,Q4: Which cloud service model provides complete
applications managed by the provider?
A. SaaS [CORRECT]
B. IaaS
C. Colocation
D. Bare metal
Rationale: Software as a Service (SaaS) delivers fully managed
applications accessible over the internet. The cloud provider is
responsible for all underlying hardware and software.
Section 2: Identity & Access Management (IAM)
Q5: In Google Cloud Platform (GCP), which IAM primitive role
provides full access to all resources in a project?
A. Viewer
B. Editor
C. Owner [CORRECT]
D. Browser
Rationale: The Owner primitive role in GCP IAM provides full
access to all resources in a project, including the ability to manage
IAM policies, set up billing, and delete the project. This role
should be restricted to the minimum number of individuals due to
its broad permissions.
, Q6: A security team needs to implement least privilege access
across multiple AWS accounts. Which AWS service enables
centralized management of permissions and policies?
A. AWS IAM basic edition
B. AWS Organizations with AWS IAM Identity Center
(SSO) [CORRECT]
C. Amazon CloudWatch
D. AWS Trusted Advisor
Rationale: AWS Organizations combined with IAM Identity Center
(formerly AWS SSO) enables centralized management of access
across multiple AWS accounts, allowing security teams to
implement least privilege through permission sets, attribute-
based access control, and centralized policy management.
Q7: Which identity management feature enables users to
access multiple systems with one login?
A. RBAC
B. SSO [CORRECT]
C. IDS
D. IPS
Rationale: Single Sign-On (SSO) allows users to authenticate once
and access multiple applications without re-entering credentials.
JYO2 200 Questions Exam Actual Exam
2026/2027 – Verified Answers – A+
Graded (Instant Download)
Section 1: Shared Responsibility Model & Cloud Deployment
Q1: In the AWS Shared Responsibility Model, which of the
following is the customer's responsibility when using Amazon
EC2?
A. Physical security of data centers
B. Patching the underlying hypervisor
C. Operating system security patching and firewall
configuration [CORRECT]
D. Ensuring power and cooling for infrastructure
Rationale: Under the AWS Shared Responsibility Model, when
using Infrastructure-as-a-Service (IaaS) like EC2, AWS manages
the security of the cloud (physical infrastructure, hypervisor,
network), while the customer is responsible for security in the
cloud, including operating system patching, application security,
data encryption, and firewall configuration.
,Q2: Which cloud deployment model provides the highest
level of control and security for an organization with strict
compliance requirements?
A. Public cloud
B. Community cloud
C. Private cloud [CORRECT]
D. Hybrid cloud
Rationale: A private cloud deployment model provides dedicated
infrastructure for a single organization, offering the highest level
of control over security configurations, physical infrastructure, and
compliance implementations, making it ideal for organizations
with strict regulatory requirements that cannot be met in multi-
tenant environments.
Q3: Which cloud service model gives customers the MOST
responsibility for managing operating systems and
applications?
A. SaaS
B. PaaS
C. IaaS [CORRECT]
D. FaaS
Rationale: In Infrastructure as a Service (IaaS), customers manage
operating systems, middleware, applications, and data, while the
cloud provider manages physical infrastructure. SaaS provides the
least customer responsibility, and PaaS falls in between.
,Q4: Which cloud service model provides complete
applications managed by the provider?
A. SaaS [CORRECT]
B. IaaS
C. Colocation
D. Bare metal
Rationale: Software as a Service (SaaS) delivers fully managed
applications accessible over the internet. The cloud provider is
responsible for all underlying hardware and software.
Section 2: Identity & Access Management (IAM)
Q5: In Google Cloud Platform (GCP), which IAM primitive role
provides full access to all resources in a project?
A. Viewer
B. Editor
C. Owner [CORRECT]
D. Browser
Rationale: The Owner primitive role in GCP IAM provides full
access to all resources in a project, including the ability to manage
IAM policies, set up billing, and delete the project. This role
should be restricted to the minimum number of individuals due to
its broad permissions.
, Q6: A security team needs to implement least privilege access
across multiple AWS accounts. Which AWS service enables
centralized management of permissions and policies?
A. AWS IAM basic edition
B. AWS Organizations with AWS IAM Identity Center
(SSO) [CORRECT]
C. Amazon CloudWatch
D. AWS Trusted Advisor
Rationale: AWS Organizations combined with IAM Identity Center
(formerly AWS SSO) enables centralized management of access
across multiple AWS accounts, allowing security teams to
implement least privilege through permission sets, attribute-
based access control, and centralized policy management.
Q7: Which identity management feature enables users to
access multiple systems with one login?
A. RBAC
B. SSO [CORRECT]
C. IDS
D. IPS
Rationale: Single Sign-On (SSO) allows users to authenticate once
and access multiple applications without re-entering credentials.