Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which of the following is an iterative software development methodology that focuses on achieving customer satisfaction by delivering the software early in the process and welcoming changing requirements from the customer, even late in the process?
Agile is an iterative software development methodology designed to prioritize customer satisfaction, adaptability, and incremental delivery. Agile teams deliver small, working pieces of software frequently, ensuring feedback is incorporated throughout the process. This flexibility allows late-stage requirement changes to be accommodated without derailing the project.
Waterfall is a sequential approach with limited flexibility. Spiral combines iterative development with risk analysis, but it is not as customer-focused as Agile. Lean emphasizes efficiency and waste reduction but does not center on continuous delivery and adaptability.
Agile frameworks such as Scrum and Kanban embody this philosophy, supporting faster innovation, better collaboration, and responsiveness to evolving business needs.
Which term refers to taking an accurate account of a system's desired standard state so changes can be quickly detected for approval or remediation?
Baselining is the process of establishing a reference point for the standard configuration of systems, networks, or applications. This baseline represents the approved, secure state. By continuously comparing the current environment to the baseline, organizations can detect deviations, unauthorized changes, or misconfigurations.
Patch management involves updating systems, deployment refers to installing new systems, and capacity management focuses on resource planning. While important, these do not establish a standard state for comparison.
Baselining is essential for change management and security auditing. It supports configuration management databases (CMDBs), intrusion detection, and compliance requirements. When deviations are detected, they can be escalated for remediation or formally approved through change control processes.
Which testing standard is currently used to guide Service Organization Control (SOC) audits outside the United States?
Outside the United States, ISAE 3402 (International Standard on Assurance Engagements 3402) is the standard used for audits equivalent to SOC reports. It ensures that service organizations demonstrate adequate internal controls over financial reporting and operational processes.
SSAE 18 is the U.S. standard governing SOC audits. ISRE 2400 and SSARS 25 focus on accounting and review services, not assurance over service organizations.
ISAE 3402 provides assurance to international customers that cloud providers or service organizations meet rigorous standards for security, availability, processing integrity, confidentiality, and privacy. This builds global trust and interoperability in compliance frameworks.
Which concept focuses on operating highly available workloads in the cloud?
Reliability in cloud design ensures workloads can recover quickly from disruptions and continue operating as expected. This concept focuses on high availability, fault tolerance, and disaster recovery. Reliability requires implementing redundancy, backup strategies, and robust monitoring.
Security ensures data protection, operational excellence covers continuous improvement, and resource hierarchy refers to organizational structures, but none focus specifically on availability and resilience.
By prioritizing reliability, organizations design cloud architectures capable of withstanding failures at multiple layers---compute, storage, networking, and even regions. This design principle ensures customer trust and compliance with service-level agreements.
An organization is planning for an upcoming Payment Card Industry Data Security Standard (PCI DSS) audit and wants to ensure that only relevant files are included in the audit materials. Which process should the organization use to ensure that the relevant files are identified?
Categorization is the process of systematically identifying and classifying files according to content and relevance. In preparation for a PCI DSS audit, it is critical to identify which files fall within scope---those that contain cardholder data or impact its security.
Normalization adjusts data format, tokenization substitutes sensitive data with tokens, and anonymization removes identifiers. While useful, none directly address the task of isolating ''relevant files'' for audit. Categorization ensures that files are grouped correctly, allowing auditors to focus on the proper scope and preventing unnecessary exposure of unrelated data.
This step aligns with PCI DSS requirements that limit scope to systems and data directly affecting cardholder data security. Proper categorization streamlines audits and demonstrates effective data governance.
80 questions covering all exam domains, starting from $20
6 domains from the WGU Managing-Cloud-Security exam outline, with approximate weightings. Every sample question above is tagged with the domain it comes from
Carry out cloud security practices in real environments by completing routine tasks and supporting internal procedures. Well structured processes and proper training strengthen overall cloud security.
Identify security policies and processes required for cloud-based applications. Organizations design and apply rules that guide safe use of cloud services to ensure secure and consistent operations.
Understand main legal and ethical responsibilities involved in cloud security. Organizations follow regulatory expectations and industry standards when working with cloud systems and handle data responsibly.
Review and understand risks that affect cloud environments. Examine potential issues and connect security actions with disaster recovery strategies to maintain continuous operations and keep cloud services dependable.
Apply secure settings across different cloud service models to control access and reduce risks. Secure setup decisions help maintain resilient and well managed cloud services.
Protect cloud information by managing identities and access levels. User accounts are controlled and permissions restrict access to sensitive data to block unauthorized entry and promote a secure cloud environment.
Common questions about the exam itself