Free Practice Questions for the WGU Courses and Certificates Managing-Cloud-Security Exam (2026 Updated)
At Marks4sure, we are dedicated to providing IT professionals with the most accurate and reliable preparation materials for the WGU Managing-Cloud-Security exam. To support your certification journey, we have made a selection of our premium 2026 Courses and Certificates practice questions and answers available completely free. You can take this practice test as many times as you need. Every question includes a detailed, expertly verified explanation to ensure you fully grasp the core security concepts before test day.
Which jurisdictional data protection was enacted in the United States to avoid forced disclosure from ISPs?
Under which jurisdiction do General Data Protection Regulation (GDPR) guidelines apply?
Which phase of the cloud data life cycle involves the process of crypto-shredding?
Which phase of software design covers the combination of individual components of developed code and the determination of proper interoperability?
Which phase in secure application design and development includes threat modeling?
How does a cloud-based distributed denial-of-service (DDoS) protection strategy help in the event of an attack?
Which cloud model is owned and operated by a vendor and then sold, leased, or rented to someone else?
Which key management option typically needs to be on-premises and delivers the keys to the cloud over a dedicated connection?
Which strategy will reduce the impact of risk in the business continuity and disaster recovery planning process?
Which factor is a primary consideration when analyzing the legal and privacy implications of using cloud technologies?
Which device identifies and stops attack-based commands from executing on a structured query language (SQL) server?
An organization is considering using vendor-specific application programming interfaces (APIs) and internal tools to set up a new service. However, the engineers are against this plan and are advocating for a new policy to prevent issues that could arise. Which common concern in cloud applications are the engineers concerned about?
A customer requests that a cloud provider physically destroys any drives storing their personal data. What must the provider do with the drives?
Which design pillar encompasses the ability to support development and run workloads effectively, gain insights into operations, and continuously improve supporting processes to deliver business value?
Which cloud risk is associated with the supply chain due to dependency on legacy internal servers for application delivery to end users?
An organization is evaluating which cloud computing service model it should implement. It is considering either platform as a service (PaaS) or software as a service (SaaS). Which risk associated with SaaS can the organization avoid by choosing PaaS?
What is the definition of transportable as it relates to cloud contract design requirements?
Which regulation defines requirements for the electronic transfer of healthcare data to a cloud service provider?
An organization designing a data center wants the ability to quickly create and shut down virtual systems based on demand. Which concept describes this capability?
Which business continuity and disaster recovery consideration should be part of a cloud application architecture?
Which data retention policy addresses how long data must be retained to meet regulatory requirements?
Which cloud computing characteristic allows consumers to expand or contract required resources automatically?
A security analyst is tasked with compiling a report of all people who used a system between two dates. The thorough report must include information about how long and how often the system was used. Which information should the analyst ensure is in the report?
Which security risk is co-owned by the enterprise team and the cloud provider in the software as a service (SaaS) model?
Which setting ensures that an attacker cannot read the information stored temporarily for use by another virtual machine (VM)?
An organization is reviewing a contract from a cloud service provider and wants to ensure that all aspects of the contract are adhered to by the cloud service provider. Which control will allow the organization to verify that the cloud provider is meeting its obligations?
Which tier from Uptime Institute ' s Data Center Site Infrastructure Tier Standards is considered to be the most secure, reliable, and redundant in design and operational elements?
Which data retention method is used for business continuity and disaster recovery (BC/DR) backups?
A user creates new financial documents that will be stored in the cloud. Which action should the user take before uploading the documents to protect them against threats such as packet capture and on-path attacks?
Which type of data sanitization should be used to destroy data on a USB thumb drive while keeping the drive intact?
Which risk relates to the removal of a person’s information within the public cloud by legal authorities?
Which description characterizes the application programming interface (API) format known as Simple Object Access Protocol (SOAP)?
A governmental data storage organization plans to relocate its primary North American data center to a new property with larger acreage. Which defense should the organization deploy at this location to prevent vehicles from causing harm to the data center?
A breach caused by lack of security management resulted in a civil lawsuit. The organization must communicate with the entity that is responsible for performing adequate oversight. Who should be contacted?
Which risk may be faced by users when using software resources in the platform as a service (PaaS) cloud model?
An organization consists of many divisions. Its leadership team has gathered the managers and key team members in each division to help create a disaster recovery plan. It studies the type of natural events that commonly occur and the risk involved for each location in which the organization has a data center. What is the leadership team doing in this scenario?
Which design principle of secure cloud computing ensures that users have access to a large number of resources that grow based on user demand?
A network administrator is concerned about the loss of physical control when moving data to the cloud. Which countermeasure should be implemented to avoid this threat?
Which group should be notified for approval when a planned modification to an environment is scheduled?
An organization’s help desk receives a call from a person claiming to be an employee wanting to verify their home address on file. The caller answers the basic authentication questions, so the help desk employee provides them the sensitive information. The organization later discovers that this call was fraudulent. Which type of threat does this represent?
Which activity is within the scope of the cloud provider’s role in the chain of custody?
Which countermeasure should be taken during the preparation phase of the incident response lifecycle?
Which process involves identification and valuation of assets in order to determine their potential effect on cloud operations?
Which type of regulation governs credit card transactions as a part of cloud operations?
Which phase of the software development life cycle includes creating user stories?
Which of the following is an iterative software development methodology that focuses on achieving customer satisfaction by delivering the software early in the process and welcoming changing requirements from the customer, even late in the process?
Which service model requires the most consumer responsibility for security issues?
Which cloud computing service model allows customers to run their own application code without configuring the server environment?
Which management process involves multiple key holders, each with access to a portion of the information?
Which level of compliance is required by a cloud service provider to protect customer data at banks and insurance companies?
A cloud consumer is scheduling a vulnerability assessment of a cloud service procured through a cloud broker. Who should the cloud consumer notify before beginning the assessment?
Which process is implemented during the hardening of an operating system (OS) and its workloads?
Which security testing method requires compliance with the cloud service provider’s terms of service?
Which security control could be implemented as part of a layered physical defense at a cloud hosting site?
