• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 4 fuera de 36 páginas
Examen

WGU C838 MANAGING CLOUD SECURITY FINAL EXAM OA 100 QUESTIONS AND ANSWERS LATEST |AGRADE

Document preview thumbnail
Vista previa 4 fuera de 36 páginas

WGU C838 MANAGING CLOUD SECURITY FINAL EXAM OA 100 QUESTIONS AND ANSWERS LATEST |AGRADE 1) You are the security subject matter expert (SME) for an organization considering atransitionfrom thelegacyenvironment intoahostedcloudprovider's data center. One of the challenges you 're facing is whether the cloud provider will be able to comply with the existing legislative and contractual frameworks yourorganization is requiredto follow.This is a issue. 2.Youare thesecuritysubject matterexpert (SME) foranorganizationconsideringa transition from the legacyenviron ment intoahosted cloudprovider 'sdata center. One of the challenges you 're facing is whether the cloud provider will be able to allow your organization to substantiate and determine with some assurance thatallof the contract terms are being met. This is a(n) issue. ulatory 3.Encryption is anessential tool foraffordingsecurity tocloud-basedoperations. While it is possible toencrypteverysystem,piece ofdata,and transactionthat takesplace onthe cloud, why might thatnotbe theoptimum choice foran organization? a.Key length variances don'tprovideanyactualadditionalsecurity. b. It would causeadditionalprocessingoverheadandtimedelay. a. Resiliency b. Privacy c. Performance d. Regulatory - ANSWER- D d. Encryption has to be maintained. - ANSWER- B c. User tracking is essential to performance. c. It might result in vendor lockout. d. The datasubjects might beupsetby this. - ANSWER- B 4.Encryption is anessential tool foraffordingsecuritytocloud-basedoperations. While it is possible toencrypteverysystem,piece ofdata,and transactiontha takesplace onthe cloud, why might thatnotbe theoptimum choice foran organization? a. It could increasethepossibility ofphysical theft. b.Encryption won 't work throughout theenvironment. c.Theprotection mightbedisproportionate tothe value of theasset(s). d. Users will be abletoseeeverything withintheorganization. - ANSWER- C 5. Whichof the following is notanelementof the identificationcomponentof identityandaccess management (IAM)? a. Provisioning b. Management c. Discretion d. Deprovisioning - ANSWER- C 6. Whichof the followingentities is most likely toplayavital role in the identity provisioningaspectofauser 's experience inanorganization? a. Theaccountingdepartment b. Thehumanresources (HR) office c. The maintenance team d. The purchasing office - ANSWER- B 7. Why is thedeprovisioningelementof the identificationcomponentof identityand access management (IAM) so important? a. Extra accounts cost so much extra money. b. Openbutunassignedaccounts arevulnerabilities. 8. Allof the followingare reasons toperform review and maintenanceactionsonuseraccounts except . a. Todetermine whether theuserstill needs thesameaccess c. The bank branch being used by d. Privileged users can cause more damage to the organization. - ANSWER- D c. There are extra controls on privileged user accounts. c. More frequent reviews of the necessity for access b. Review of personal financial accounts for privileged users 12. The additional review activities that might be performed for privileged user accounts could include all of the following except . a. Deeper personnel background checks b. Todetermine whether theuser is still withtheorganization c. Todetermine whether thedata set isstill applicable totheuser 's role d. Todetermine whether theuser is still performing well - ANSWER- D 9. Whoshouldbe involved inreview and maintenanceofuseraccounts/access? a. The user 's manager b.Thesecurity manager c. Theaccountingdepartment d. The incident responseteam - ANSWER- A 10. Which of the followingprotocols is mostapplicabletothe identification process aspectof identityand access management (IAM)? a. Secure Sockets Layer (SSL) b. Internet Protocolsecurity (IPsec) c.Lightweight Directory Access Protocol (LDAP) d. Amorphous ancillarydatatransmission (AADT) - ANSWER- C 11. Privilegeduser (administrators, managers,andsoforth)accountsneedtobereviewed more closely than basic user accounts. Why is this? a. Privileged usershave moreencryption keys. b. Regularusers are more trustworthy. d. Pat-down checks of privileged users to deter against physical theft - ANSWER-D 13. If personal financial account reviews are performed as an additional review control forprivileged users, whichof the following characteristics is least likely tobe a useful indicator for review purposes? a. Too much money intheaccount b. Too little money inthe account theprivileged use

Vista previa del contenido

WGU C838 MANAGING CLOUD SECURITY FINAL EXAM OA
100 QUESTIONS AND ANSWERS LATEST2023-2024
|AGRADE




1) You are the security subject matter expert (SME) for an organization considering a transition from
the legacy environment into a hosted cloud provider's data center. One of the challenges you 're facing
is whether the cloud provider will be able to comply with the existing legislative and contractual
frameworks your organization is required to follow. This is a issue.

a. Resiliency
b. Privacy
c. Performance
d. Regulatory - ANSWER- D

2. You are the security subject matter expert (SME) for an organization consideringa transition from the
legacy environ ment into a hosted cloud provider 's data
center. One of the challenges you 're facing is whether the cloud provider will be able to allow your
organization to substantiate and determine with some assurance that all of the contract terms are being
met. This is a(n) issue.
a. Regulatory
b. Privacy
c. Resilien cy
d. Auditability - ANSWER- D

3. Encryption is an essential tool for affording security to cloud-based operations.
While it is possible to encrypt every system, piece of data, and transaction that
takes place on the cloud, why might that not be the optimum choice for an
organization?
a. K ey length variances don 't provide any actual additional security.
b. It would cause additional processing overhead and time delay.

,c. It might result in vendor lockout.
d. The data subjects might be upset by this. - ANSWER- B

4. Encryption is an essential tool for affording security to cloud-based operations.
While it is possible to encrypt every system, piece of data, and transaction tha
takes place on the cloud, why might that not be the optimum choice for an
organization?
a. It could increase the possibility of physical theft.
b. Encryption won 't work throughout the environment.
c. The protection might be disproportionate to the value of the asset(s).
d. Users will be able to see everything within the organization. - ANSWER- C

5. Which of the following is not an element of the identification component of
identity and access management (IAM)?
a. Provisioning
b. Management
c. Discretion
d. Deprovisioning - ANSWER- C

6. Which of the following entities is most likely to play a vital role in the identity
provisioning aspect of a user 's experience in an organization?
a. The accounting department
b. The human resources (HR) office
c. The maintenance team
d. The purchasing office - ANSWER- B

7. Why is the deprovisioning element of the identification component of identityand access
management (IAM) so important? a. Extra accounts cost so much extra money.
b. Open but unassigned accounts are vulnerabilities.
c. User tracking is essential to performance.
d. Encryption has to be maintained. - ANSWER- B

8. All of the following are reasons to perform review and maintenance actions onuser accounts except
.
a. To determine whether the user still needs the same access

,b. To determine whether the user is still with the organization
c. To determine whether the data set is still applicable to the user 's role
d. To determine whether the user is still performing well - ANSWER- D

9. Who should be involved in review and maintenance of user accounts/access?
a. The user 's manager
b. The security manager
c. The accounting department
d. The incident response team - ANSWER- A

10. Which of the following protocols is most applicable to the identification
process aspect of identity and access management (IAM)?
a. Secure Sockets Layer (SSL)
b. Internet Protocol security (IPsec)
c. Lightweight Directory Access Protocol (LDAP)
d. Amorphous ancillary data transmission (AADT) - ANSWER- C

11. Privileged user (administrators, managers, and so forth) accounts need to bereviewed more
closely than basic user accounts. Why is this? a. Privileged users have more encryption keys.
b. Regular users are more trustworthy.
c. There are extra controls on privileged user accounts.
d. Privileged users can cause more damage to the organization. - ANSWER- D

12. The additional review activities that might be performed for privileged user
accounts could include all of the following except . a. Deeper
personnel background checks
b. Review of personal financial accounts for privileged users
c. More frequent reviews of the necessity for access
d. Pat-down checks of privileged users to deter against physical theft - ANSWER-D

13. If personal financial account reviews are performed as an additional review control for privileged
users, which of the following characteristics is least likely tobe a useful indicator for review purposes?
a. Too much money in the account
b. Too little money in the account
c. The bank branch being used by the privileged user

, d. Specific senders/recipients - ANSWER- C

14. How often should the accounts of privileged users be reviewed? a.
Annually
b. Twice a year
c. Monthly
d. More often than regular user account reviews - ANSWER- D

15. Privileged user account access should be .
a. Temporary
b. Pervasive
c. Thorough
d. Granular - ANSWER- A

16. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of common threats to
organizations participating in cloud computing. According tothe CSA 's Notorious Nine list, data
breaches can be . a. Overt or
covert
b. International or subterranean
c. From internal or external sources
d. Voluminous or specific - ANSWER- C

17. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of common threats to
organizations participating in cloud computing. According to the CSA, an organization that operates in
the cloud environment and suffers a databreach may be required to . a. Notify affected users
b. Reapply for cloud service
c. Scrub all affected physical memory
d. Change regulatory frameworks - ANSWER- A

18. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of common threats to
organizations participating in cloud computing. According tothe CSA, an organization that suffers a
data breach might suffer all of the following negative effects except . a. Cost of compliance with
notification laws
b. Loss of public perception/goodwill
c. Loss of market share

Información del documento

Subido en
11 de febrero de 2024
Número de páginas
36
Escrito en
2023/2024
Tipo
Examen
Contiene
Preguntas y respuestas
$18.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
laurenjames
3.7
(19)
Vendido
102
Seguidores
17
Artículos
1623
Última venta
6 días hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes