WGU D320 Managing Cloud Security (Pre-Assessment)
– Questions With Complete Solutions
1. Which phase of the cloud data life cycle requires adherence to export and
import restrictions, including Export Administration Regulations (EAR) and
the Wassenaar Arrangement?
a. Create
b. Share
c. Use
d. Destroy Right Ans - b. Share
2. Why is the striping method of storing data used in most redundant array of
independent disks (RAID) configurations?
a. It prevents outages and attacks from occurring in a cloud environment.
b. It prevents data from being recovered once it is destroyed using crypto-
shredding.
c. It allows data to be safely distributed and stored in a common centralized
location.
d. It allows efficient data recovery as even if one drive fails, other drives fill in
the missing data. Right Ans - d. It allows efficient data recovery as even if
one drive fails, other drives fill in the missing data.
3. What is the purpose of egress monitoring tools?
a. They are used to convert a given set of data or information into a different
value.
b. They are used to prevent data from going outside the control of an
organization.
c. They are used to create data during the Create phase of the cloud data life
cycle.
d. They are used to remove data during the Destroy phase of the cloud data
life cycle. Right Ans - b. They are used to prevent data from going outside
the control of an organization.
,4. A company is looking at different types of cloud storage options. One of the
threats to cloud storage that the company foresees is the possibility of losing
forensic artifacts in the event of an incident response investigation.
Which type of cloud storage has the highest risk of losing forensic artifacts in
the event of an incident response investigation?
a. File-based
b. Long-term
c. Block
d. Ephemeral Right Ans - d. Ephemeral
5. A manager is made aware of a customer complaint about how an
application developed by the company collects personal and environmental
information from the devices it is installed on.
Which document should the manager refer to in order to determine if the
company has properly disclosed information about what data it collects from
this application's users?
a. Retention policy
b. Breach notification
c. Privacy notice
d. Denial of service Right Ans - c. Privacy notice
6. An organization needs to store passwords in a database securely. The data
should not be available to system administrators.
Which technique should the organization use?
a. Encryption
b. Hashing
c. Encoding
d. Masking Right Ans - b. Hashing
7. A company is looking to ensure that the names of individuals in its data in
the cloud are not revealed in the event of a data breach, as the data is sensitive
and classified.
, Which data masking technique should the company use to prevent attackers
from identifying individuals in the event of a data breach?
a. Crypto-shredding
b. Degaussing
c. Anonymization
d. Randomization Right Ans - c. Anonymization
8. An organization needs to quickly identify the document owner in a shared
network folder.
Which technique should the organization use to meet this goal?
a. Labeling
b. Classification
c. Mapping
d. Categorization Right Ans - a. Labeling
9. An organization plans to introduce a new data standard and wants to
ensure that system inventory data will be efficiently discovered and
processed.
Which type of data should the organization use to meet this goal?
a. Structured
b. Semi-structured
c. Annotated
d. Mapped Right Ans - a. Structured
10. An organization implemented an information rights management (IRM)
solution to prevent critical data from being copied without permission and a
cloud backup solution to ensure that the critical data is protected from storage
failures.
Which IRM challenge will the organization need to address?
a. Jurisdictional conflicts
b. Agent conflicts
c. Replication restrictions
– Questions With Complete Solutions
1. Which phase of the cloud data life cycle requires adherence to export and
import restrictions, including Export Administration Regulations (EAR) and
the Wassenaar Arrangement?
a. Create
b. Share
c. Use
d. Destroy Right Ans - b. Share
2. Why is the striping method of storing data used in most redundant array of
independent disks (RAID) configurations?
a. It prevents outages and attacks from occurring in a cloud environment.
b. It prevents data from being recovered once it is destroyed using crypto-
shredding.
c. It allows data to be safely distributed and stored in a common centralized
location.
d. It allows efficient data recovery as even if one drive fails, other drives fill in
the missing data. Right Ans - d. It allows efficient data recovery as even if
one drive fails, other drives fill in the missing data.
3. What is the purpose of egress monitoring tools?
a. They are used to convert a given set of data or information into a different
value.
b. They are used to prevent data from going outside the control of an
organization.
c. They are used to create data during the Create phase of the cloud data life
cycle.
d. They are used to remove data during the Destroy phase of the cloud data
life cycle. Right Ans - b. They are used to prevent data from going outside
the control of an organization.
,4. A company is looking at different types of cloud storage options. One of the
threats to cloud storage that the company foresees is the possibility of losing
forensic artifacts in the event of an incident response investigation.
Which type of cloud storage has the highest risk of losing forensic artifacts in
the event of an incident response investigation?
a. File-based
b. Long-term
c. Block
d. Ephemeral Right Ans - d. Ephemeral
5. A manager is made aware of a customer complaint about how an
application developed by the company collects personal and environmental
information from the devices it is installed on.
Which document should the manager refer to in order to determine if the
company has properly disclosed information about what data it collects from
this application's users?
a. Retention policy
b. Breach notification
c. Privacy notice
d. Denial of service Right Ans - c. Privacy notice
6. An organization needs to store passwords in a database securely. The data
should not be available to system administrators.
Which technique should the organization use?
a. Encryption
b. Hashing
c. Encoding
d. Masking Right Ans - b. Hashing
7. A company is looking to ensure that the names of individuals in its data in
the cloud are not revealed in the event of a data breach, as the data is sensitive
and classified.
, Which data masking technique should the company use to prevent attackers
from identifying individuals in the event of a data breach?
a. Crypto-shredding
b. Degaussing
c. Anonymization
d. Randomization Right Ans - c. Anonymization
8. An organization needs to quickly identify the document owner in a shared
network folder.
Which technique should the organization use to meet this goal?
a. Labeling
b. Classification
c. Mapping
d. Categorization Right Ans - a. Labeling
9. An organization plans to introduce a new data standard and wants to
ensure that system inventory data will be efficiently discovered and
processed.
Which type of data should the organization use to meet this goal?
a. Structured
b. Semi-structured
c. Annotated
d. Mapped Right Ans - a. Structured
10. An organization implemented an information rights management (IRM)
solution to prevent critical data from being copied without permission and a
cloud backup solution to ensure that the critical data is protected from storage
failures.
Which IRM challenge will the organization need to address?
a. Jurisdictional conflicts
b. Agent conflicts
c. Replication restrictions