Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 2 fuera de 9 páginas
Examen

WGU D320 - Managing Cloud Security- Questions and Answers Latest Update 2024 (100% Correct)

Document preview thumbnail
Vista previa 2 fuera de 9 páginas

WGU D320 - Managing Cloud Security- Questions and Answers Latest Update 2024 (100% Correct) Infrastructure as a Service (IaaS) - Answers Allows the customer to install all software, including operating systems (OSs) on hardware housed and connected by the cloud vendor. Platform as a Service (PaaS) - Answers Contains everything included in IaaS, with the addition of OSs. This model is especially useful for software development operations (DevOps). Software as a Service (SaaS) - Answers Includes everything listed in the previous Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) models, with the addition of software programs. Encryption - Answers Offers a degree of assurance that nobody without authorization will be able to access your data in a meaningful way. Cloud Service Provider (CSP) - Answers Provides administrative assistance for the customer and the customer's data and processing needs. Examples include Amazon Web Services, Rackspace, and Microsoft's Azure. Virtualization - Answers A process of creating a virtual version of something, including virtual computer hardware platforms, operating systems, storage devices, and computer network resources. Vendor lock-in - Answers Occurs in a situation where a customer may be unable to leave, migrate, or transfer to an alternate provider due to technical or non-technical constraints. Cloud provider - Answers A service provider that offers customer storage or software solutions available via a public network, usually the Internet. Cloud portability - Answers The ability to move applications and associated data between one cloud provider and another, or between legacy and cloud environments. Cloud Access Security Broker (CASB) - Answers A third-party entity offering independent identity and access management (IAM) services to CSPs and cloud customers, often as an intermediary. We use what to determine the critical paths, processes, and assets of an organization? - Answers BIA (The business impact analysis is designed to ascertain the value of the organization's assets, and learn the critical paths and processes.) If a cloud customer wants a bare-bones environment in which to replicate their own enterprise for BC/DR purposes, which cloud service model would probably be best? - Answers IaaS - IaaS offers what is basically a hot/warm DR site, with hardware, connectivity, and utilities, allowing the customer to build out any kind of software configuration (including choosing OSs). If a service or solution does not meet all of the specified key characteristics listed below, it is said to be not true cloud computing. Please select the valid cloud computing characteristics out of the terms identified below. - Answers Here are the characteristics of cloud computing: Broad network access Resource pooling Measured service On demand self-service Rapid expansion The risk that a cloud provider might go out of business and the cloud customer might not be able to recover data is known as: - Answers Vendor lock-out Cloud Access Security Brokers (CASBs) might offer all the following services except: - Answers BC/DR/COOP (CASBs don't usually offer BC/DR/COOP services; that's something offered by cloud providers.) Mitigation - Answers A process of taking steps to decrease the likelihood or the impact of the risk. Transference - Answers A risk management strategy that involves the contractual shifting of a risk from one organization to another. Layered defenses - Answers The practice of having multiple overlapping means of securing the environment with a variety of methods. Risk appetite - Answers Refers to the level, amount, or type of risk that the organization finds acceptable. Avoidance - Answers Eliminating the risk that is simply too high and cannot be compensated for with adequate control mechanism. IaaS boundaries - Answers The cloud provider creates and administers the hardware assets on which the customer's programs and data will ride. PaaS boundaries - Answers The cloud provider is responsible for installing, maintaining, and administering the OS. In which cloud service model is the customer required to maintain and update only the applications? - Answers PaaS (In PaaS, the provider supplies the hardware, connectivity, and OS; the customer installs and maintains applications. In IaaS, the customer must also install the OS, and in SaaS, the provider supplies and maintains the applications.) In which cloud service model is the customer only responsible for the data? - Answers SaaS The cloud customer and provider negotiate their respective responsibilities and rights regarding the capabilities and data of the cloud service. Where is the eventual agreement codified? - Answers Contract Which of the following is considered a physical control? - Answers Fence (Fences are physical controls; carpets and ceilings are architectural features, and a door is not necessarily a control: the lock on the door would be a physical security control. Although you might think of a door as a potential answer, the best answer is the fence; the exam will have questions where more than one answer is correct, and the answer that will score you points is the one that is most correct.) What is an experimental technology that is intended to create the possibility of processing encrypted data without having to decrypt it first? - Answers Homomorphic encryption Jurisdiction - Answers The geophysical location of the source or storage point of the data might have significant bearing on how that data is treated and handled. Patent - Answers The legal mechanism for protecting intellectual property in the form of inventions, processes, materials, decorations, and plant life. Data audit - Answers A powerful tool to regularly review, inventory, and inspect usage and condition of the information that an organization owns. Cryptoshredding - Answers Involves encrypting the data with a strong encryption engine, and then taking the keys generated in that process, encrypting them with a different encryption engine, and destroying the keys. Retention period - Answers Defines how long the data should be kept by an organization and is often expressed in a number of years. Retention format - Answers A policy that contains a description of how the data is actually archived, that is, what type of media it is stored on. Data classification - Answers Refers to the responsibility of the data owner which takes place in the Create phase and is assigned according to an overall organizational motif based on a specific characteristic of the given dataset. Datamining - Answers Refers to a kind of data analysis which is an outgrowth of the possibilities offered by the regular use of the cloud, also known as "big data." Copyright - Answers The legal protection for expressions of ideas is known as "copyright" and it doesn't include ideas, specific words, slogans, recipes, or formulae. Trademark - Answers Protects the esteem and goodwill that an organization has built among the marketplace, especially in public perception. Degaussing - Answers Involves applying strong magnetic fields to the hardware and media

Vista previa del contenido

WGU D320 - Managing Cloud Security- Questions and Answers Latest Update 2024 (100% Correct)

Infrastructure as a Service (IaaS) - Answers Allows the customer to install all software, including
operating systems (OSs) on hardware housed and connected by the cloud vendor.

Platform as a Service (PaaS) - Answers Contains everything included in IaaS, with the addition of OSs.
This model is especially useful for software development operations (DevOps).

Software as a Service (SaaS) - Answers Includes everything listed in the previous Infrastructure as a
Service (IaaS) and Platform as a Service (PaaS) models, with the addition of software programs.

Encryption - Answers Offers a degree of assurance that nobody without authorization will be able to
access your data in a meaningful way.

Cloud Service Provider (CSP) - Answers Provides administrative assistance for the customer and the
customer's data and processing needs. Examples include Amazon Web Services, Rackspace, and
Microsoft's Azure.

Virtualization - Answers A process of creating a virtual version of something, including virtual computer
hardware platforms, operating systems, storage devices, and computer network resources.

Vendor lock-in - Answers Occurs in a situation where a customer may be unable to leave, migrate, or
transfer to an alternate provider due to technical or non-technical constraints.

Cloud provider - Answers A service provider that offers customer storage or software solutions available
via a public network, usually the Internet.

Cloud portability - Answers The ability to move applications and associated data between one cloud
provider and another, or between legacy and cloud environments.

Cloud Access Security Broker (CASB) - Answers A third-party entity offering independent identity and
access management (IAM) services to CSPs and cloud customers, often as an intermediary.

We use what to determine the critical paths, processes, and assets of an organization? - Answers BIA
(The business impact analysis is designed to ascertain the value of the organization's assets, and learn
the critical paths and processes.)

If a cloud customer wants a bare-bones environment in which to replicate their own enterprise for
BC/DR purposes, which cloud service model would probably be best? - Answers IaaS - IaaS offers what is
basically a hot/warm DR site, with hardware, connectivity, and utilities, allowing the customer to build
out any kind of software configuration (including choosing OSs).

If a service or solution does not meet all of the specified key characteristics listed below, it is said to be
not true cloud computing. Please select the valid cloud computing characteristics out of the terms
identified below. - Answers Here are the characteristics of cloud computing:

Broad network access

, Resource pooling

Measured service

On demand self-service

Rapid expansion

The risk that a cloud provider might go out of business and the cloud customer might not be able to
recover data is known as: - Answers Vendor lock-out

Cloud Access Security Brokers (CASBs) might offer all the following services except: - Answers
BC/DR/COOP (CASBs don't usually offer BC/DR/COOP services; that's something offered by cloud
providers.)

Mitigation - Answers A process of taking steps to decrease the likelihood or the impact of the risk.

Transference - Answers A risk management strategy that involves the contractual shifting of a risk from
one organization to another.

Layered defenses - Answers The practice of having multiple overlapping means of securing the
environment with a variety of methods.

Risk appetite - Answers Refers to the level, amount, or type of risk that the organization finds
acceptable.

Avoidance - Answers Eliminating the risk that is simply too high and cannot be compensated for with
adequate control mechanism.

IaaS boundaries - Answers The cloud provider creates and administers the hardware assets on which the
customer's programs and data will ride.

PaaS boundaries - Answers The cloud provider is responsible for installing, maintaining, and
administering the OS.

In which cloud service model is the customer required to maintain and update only the applications? -
Answers PaaS (In PaaS, the provider supplies the hardware, connectivity, and OS; the customer installs
and maintains applications. In IaaS, the customer must also install the OS, and in SaaS, the provider
supplies and maintains the applications.)

In which cloud service model is the customer only responsible for the data? - Answers SaaS

The cloud customer and provider negotiate their respective responsibilities and rights regarding the
capabilities and data of the cloud service. Where is the eventual agreement codified? - Answers Contract

Which of the following is considered a physical control? - Answers Fence (Fences are physical controls;
carpets and ceilings are architectural features, and a door is not necessarily a control: the lock on the

Información del documento

Subido en
14 de diciembre de 2024
Número de páginas
9
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas
$8.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
TutorJosh
3.5
(76)
Vendido
495
Seguidores
16
Artículos
32839
Última venta
8 horas hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes