MANAGING CLOUD SECURITY – D320 (WGU) 2026 |
VERIFIED CCSP EXAM PREP QUESTIONS & COMPLETE
STUDY GUIDE | FROM QUESTION TO PERFECTION| STUDY
WITH CONFIDENCE!
Course Code:
Course Title:
Programme:
Academic Year: 2026/2027.
Duration: 2 Hours.
Total Marks: 70%.
Candidate Instructions:
1) Write your Registration Number on every answer booklet used.
2) Answer ALL questions in Section A and ANY TWO (2) questions in Section B.
3) Read each question carefully before answering.
4) Begin each question on a new page.
5) The marks for each question are indicated in brackets.
6) This paper consists of several printed pages, including this page.
7) Ensure your copy is complete before the examination begins.
8) Unauthorized materials and communication with other candidates are not permitted.
Turn Over.
APPHIA – Crafted with Care and Precision for Academic Excellence.
1
, International Standards Organization (ISO) Answer: is an international standards body
composed of representatives from various standards organizations.
ISO/IEC 27001 Answer: Standard on managing Information Security. It includes requirements
for establishing ,
implementing, maintaining, and continually improving information management.
ISO/IEC 27002 Answer: provides best practices on information security controls for those
attempting to be ISO/IEC 27001.
ISO/IEC 27017 Answer: created to supplement ISO/IEC 27002 to provide additional security
controls for the cloud.
ISO/IEC 27018:2014
ISO/IEC 27018:2019 Answer: IT Security techniques. Code of practice for protection of PII in
public clouds.
ISO/IEC 27034-1 Answer: mandates a framework for application security within an
organization.
ISO/IEC 28000:2007 Answer: standard for ensuring security assurance in the supply chain.
ISO/IEC 31000:2009 Answer: standard providing industry independent principles and
guidelines on risk management.
NIST Answer: National Institute of Standards and Technology is an agency of the Department
of Commerce whose mission is to promote innovation and industrial competitiveness. It also
creates numerous standard and requirements for the DoD, Federal Government, and government
contractors relating to Cyber security.
NIST SP 800-37 Answer: Risk Management Framework using a life cycle approach for security
and privacy.
NIST SP 800-53 Answer: provides security and privacy controls for information systems and
organizations.
NIST SP 800-92 Answer: Guide to Computer Security Log Management
ISO 27034 Answer: There is only one ONF for an organization but potentially as many ANF's
as applications.
- Application Normative Framework (ANF)
- Organizational Normative Framework (ONF)
ASHRAE - American Society of Heating, Refrigerating and Air-Conditioning Engineers
Answer: is an American professional association seeking to advance heating, ventilation, air
conditioning and refrigeration systems design and construction.
APPHIA – Crafted with Care and Precision for Academic Excellence.
2
VERIFIED CCSP EXAM PREP QUESTIONS & COMPLETE
STUDY GUIDE | FROM QUESTION TO PERFECTION| STUDY
WITH CONFIDENCE!
Course Code:
Course Title:
Programme:
Academic Year: 2026/2027.
Duration: 2 Hours.
Total Marks: 70%.
Candidate Instructions:
1) Write your Registration Number on every answer booklet used.
2) Answer ALL questions in Section A and ANY TWO (2) questions in Section B.
3) Read each question carefully before answering.
4) Begin each question on a new page.
5) The marks for each question are indicated in brackets.
6) This paper consists of several printed pages, including this page.
7) Ensure your copy is complete before the examination begins.
8) Unauthorized materials and communication with other candidates are not permitted.
Turn Over.
APPHIA – Crafted with Care and Precision for Academic Excellence.
1
, International Standards Organization (ISO) Answer: is an international standards body
composed of representatives from various standards organizations.
ISO/IEC 27001 Answer: Standard on managing Information Security. It includes requirements
for establishing ,
implementing, maintaining, and continually improving information management.
ISO/IEC 27002 Answer: provides best practices on information security controls for those
attempting to be ISO/IEC 27001.
ISO/IEC 27017 Answer: created to supplement ISO/IEC 27002 to provide additional security
controls for the cloud.
ISO/IEC 27018:2014
ISO/IEC 27018:2019 Answer: IT Security techniques. Code of practice for protection of PII in
public clouds.
ISO/IEC 27034-1 Answer: mandates a framework for application security within an
organization.
ISO/IEC 28000:2007 Answer: standard for ensuring security assurance in the supply chain.
ISO/IEC 31000:2009 Answer: standard providing industry independent principles and
guidelines on risk management.
NIST Answer: National Institute of Standards and Technology is an agency of the Department
of Commerce whose mission is to promote innovation and industrial competitiveness. It also
creates numerous standard and requirements for the DoD, Federal Government, and government
contractors relating to Cyber security.
NIST SP 800-37 Answer: Risk Management Framework using a life cycle approach for security
and privacy.
NIST SP 800-53 Answer: provides security and privacy controls for information systems and
organizations.
NIST SP 800-92 Answer: Guide to Computer Security Log Management
ISO 27034 Answer: There is only one ONF for an organization but potentially as many ANF's
as applications.
- Application Normative Framework (ANF)
- Organizational Normative Framework (ONF)
ASHRAE - American Society of Heating, Refrigerating and Air-Conditioning Engineers
Answer: is an American professional association seeking to advance heating, ventilation, air
conditioning and refrigeration systems design and construction.
APPHIA – Crafted with Care and Precision for Academic Excellence.
2