STUDY | STANDARDS &
FRAMEWORKS | ISO/IEC
STANDARDS| WGU-C838 LATEST AND
COMPLETE VERSION WITH VERIFIED
SOLUTIONS
"What is a type of assessment that employs a set of methods, principles, or rules for assessing
risk based on nonnumerical categories or levels?
A.
Quantitative assessment
B.
Qualitative assessment
C.
Hybrid assessment
D.
SOC 2 - CORRECT ANSWER=> B"
"Which of the following best describes the Cloud Security Alliance Cloud Controls Matrix (CSA
CCM)?
A.
A set of regulatory requirements for cloud service providers
B.
A set of software development lifecycle requirements for cloud service providers
C.
A security controls framework that provides mapping/cross relationships with the main
industry-accepted security standards, regulations, and controls frameworks
D.
1|Page
,An inventory of cloud service security controls that are arranged into separate security domains
- CORRECT ANSWER=> C"
"When a conflict between parties occurs, which of the following is the primary means of
determining the jurisdiction in which the dispute will be heard?
A.
Tort law
B.
Contract
C.
Common law
D.
Criminal law - CORRECT ANSWER=> B"
"Which one of the following is the most important security consideration when selecting a new
computer facility?
A.
Local law enforcement response times
B.
Location adjacent to competitor's facilities
Your selection is incorrect
C.
Aircraft flight paths
D.
Utility infrastructure - CORRECT ANSWER=> D"
"Which of the following is always safe to use in the disposal of electronic records within a cloud
environment?
A.
Physical destruction
B.
Overwriting
C.
Encryption
D.
Degaussing - CORRECT ANSWER=> C"
"Which of the following does not represent an attack on a network?
2|Page
,A.
Syn flood
B.
Denial of service
C.
Nmap scan
D.
Brute force - CORRECT ANSWER=> C"
"Which of the following takes advantage of the information developed in the business impact
analysis (BIA)?
A.
Calculating ROI
B.
Risk analysis
C.
Calculating TCO
D.
Securing asset acquisitions - CORRECT ANSWER=> B"
"Which of the following terms best describes a managed service model where software
applications are hosted by a vendor or cloud service provider and made available to customers
over network resources?
A.
Infrastructure as a service (IaaS)
B.
Public cloud
C.
Software as a service (SaaS)
D.
Private cloud - CORRECT ANSWER=> C"
"Which of the following is a federal law enacted in the United States to control the way financial
institutions deal with private information of individuals?
A.
PCI
B.
ISO/IEC
3|Page
, C.
Gramm-Leach-Bliley Act (GLBA)
D.
Consumer Protection Act - CORRECT ANSWER=> C"
"The typical function of Secure Sockets Layer (SSL) in securing Wireless Application Protocol
(WAP) is to protect transmissions that exist:
A.
Between the WAP gateway and the wireless endpoint device
B.
Between the web server and the WAP gateway
C.
From the web server to the wireless endpoint device
D.
Between the wireless device and the base station - CORRECT ANSWER=> C"
"What is an audit standard for service organizations?
A.
SOC 1
B.
SSAE 18
C.
GAAP
D.
SOC 2 - CORRECT ANSWER=> B"
"What is a company that purchases hosting services from a cloud server hosting provider or
cloud computing provider and then resells to its own customers?
A.
Cloud programmer
B.
Cloud broker
C.
Cloud proxy
D.
VAR - CORRECT ANSWER=> B"
4|Page