Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

WGU D485 CLOUD SECURITY IMPLEMENTATION PLAN TASK 1 2026 | DGN2 Complete Solution | MSCSIA/BSCC | Pass Guaranteed - A+ Graded

Beoordeling
-
Verkocht
-
Pagina's
29
Cijfer
A+
Geüpload op
12-05-2026
Geschreven in
2025/2026

Complete WGU D485/DGN2 Cloud Security Implementation Plan Task 1 successfully with this latest update complete solution for the MSCSIA or BSCC program. This A+ Graded resource contains complete task solutions covering all key cloud security competency areas including **cloud architecture and design (cloud service models: IaaS, PaaS, SaaS; cloud deployment models: public, private, hybrid, community, multi-cloud; shared responsibility model across AWS, Azure, GCP; cloud reference architectures; microservices and containerization (Docker, Kubernetes) security implications; serverless computing security), identity and access management in cloud environments (IAM policies, role-based access control (RBAC), attribute-based access control (ABAC), least privilege principle, zero trust security model for cloud, identity federation (SAML, OAuth, OpenID Connect), multi-factor authentication (MFA), privileged access management (PAM), cloud entitlement management, service accounts security, just-in-time (JIT) access, and conditional access policies), data protection in the cloud (data classification schemes, encryption at rest using server-side encryption (SSE) and client-side encryption (CSE), encryption in transit TLS/mTLS, key management (bring your own key BYOK, hold your own key HYOK, cloud provider key management services KMS), hardware security modules (HSM), data loss prevention (DLP) strategies for cloud, object lock and immutable storage, backup and disaster recovery planning, data retention policies, and sensitive data discovery in multi-tenant environments), network security for cloud (virtual private cloud (VPC) design, subnet segmentation, security groups vs network ACLs, web application firewalls (WAF), distributed denial of service (DDoS) protection (AWS Shield, Azure DDoS Protection), cloud network firewall solutions, traffic inspection architectures (transit gateway, hub-spoke), VPN connectivity (IPsec, SSL VPN), cloud secure web gateway (SWG)/CASB integration, zero trust network access (ZTNA), and micro-segmentation), security monitoring and compliance in the cloud (cloud-native security tools (AWS Security Hub, Azure Security Center, Google Cloud Security Command Center), SIEM integration for cloud logs (AWS CloudTrail, Azure Monitor, Cloud Logging), cloud workload protection platforms (CWPP), cloud security posture management (CSPM), cloud infrastructure entitlement management (CIEM), compliance frameworks mapping (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP) for cloud workloads, continuous compliance monitoring, and automated remediation), incident response in cloud environments (cloud-specific IR challenges (lack of physical access, API-based forensics), incident response playbooks for cloud, forensic data acquisition in AWS/Azure/GCP, automation for containment using cloud functions and runbooks, evidence chain of custody in cloud, and integration with cloud service provider incident response teams), and compliance requirements for cloud security (regulatory considerations for data residency and sovereignty (GDPR), Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM), Sarbanes-Oxley (SOX) IT controls in cloud, Federal Risk and Authorization Management Program (FedRAMP) for government cloud, and Health Insurance Portability and Accountability Act (HIPAA) cloud safeguards). Each answer includes clear rationales to reinforce cloud security implementation planning concepts. Perfect for MSCSIA (Master of Science in Cybersecurity and Information Assurance) and BSCC (Bachelor of Science in Cloud Computing) students completing WGU D485/DGN2 Task 1. With our Pass Guarantee, you can confidently complete your Cloud Security Implementation Plan task. Download your complete WGU D485 Cloud Security Implementation Plan Task 1 solution instantly!

Meer zien Lees minder
Instelling
Vak

Voorbeeld van de inhoud

WGU D485 CLOUD SECURITY IMPLEMENTATION PLAN
TASK 1 2026 | DGN2 Complete Solution | MSCSIA/BSCC |
Pass Guaranteed - A+ Graded

Section 1: Cloud Shared Responsibility Model & Compliance
Frameworks (Questions 1-12)

Q1. A healthcare organization migrating its electronic health records (EHR) system to
AWS EC2 instances must determine which party is responsible for operating system
patching under the shared responsibility model. Which statement accurately
describes this responsibility?

A. AWS is responsible for patching the guest operating system on all EC2 instances
[CORRECT]

B. The customer is responsible for patching the guest operating system on EC2
instances

C. AWS and the customer share equal responsibility for OS patching regardless of
service model

D. The customer is only responsible for application-level patching, not the OS

Rationale: Under AWS IaaS (EC2), the customer manages the guest OS, applications,
and data security, while AWS secures the underlying infrastructure (hardware,
hypervisor, physical data centers). Option A confuses provider/customer roles;
Option C ignores service model differentiation; Option D incorrectly narrows
customer responsibility.

Correct Answer: B




Q2. A financial services firm using Microsoft Azure App Service (PaaS) to host its
trading application needs to implement TLS 1.3 for data in transit. According to the
Azure shared responsibility model, who is primarily responsible for configuring and
managing this encryption protocol?

,A. Microsoft Azure manages TLS configuration entirely; the customer has no
configuration role

B. The customer is responsible for configuring TLS 1.3 at the application layer and
managing certificate rotation

C. Microsoft manages the platform runtime TLS, while the customer manages
application-level TLS and certificate binding

D. TLS configuration is a shared responsibility with Microsoft handling inbound traffic
and the customer handling outbound traffic [CORRECT]

Rationale: In Azure PaaS, Microsoft manages the underlying platform including
runtime security, but the customer must configure application-level TLS settings,
certificate binding, and rotation. Option A is incorrect because customers retain
application-layer control; Option B overstates customer responsibility for platform
runtime; Option D creates an artificial split not reflected in the actual model.

Correct Answer: C




Q3. Under NIST CSF 2.0, a cloud security architect is developing a governance
framework for a multi-cloud environment spanning AWS, Azure, and GCP. Which
function should be the FIRST priority when establishing organizational context and
cybersecurity risk management strategy?

A. Identify (ID)

B. Protect (PR)

C. Govern (GV) [CORRECT]

D. Detect (DE)

Rationale: NIST CSF 2.0 added Govern as the sixth core function, establishing it as
the foundational element for organizational context, risk management strategy, and
policy oversight before implementing other functions. Options A, B, and D represent
operational functions that should be informed by governance decisions, not precede
them.

Correct Answer: C

, Q4. A SaaS-based customer relationship management (CRM) vendor claims SOC 2
Type II compliance. A prospective client must evaluate whether this certification
satisfies their PCI DSS requirements for storing customer payment card data within
the CRM. Which assessment is MOST accurate?

A. SOC 2 Type II automatically satisfies all PCI DSS requirements for cardholder data
environments

B. SOC 2 and PCI DSS are equivalent standards with identical control requirements

C. SOC 2 Type II demonstrates operational security controls but does NOT
automatically satisfy PCI DSS; additional PCI DSS-specific controls must be validated
[CORRECT]

D. Since the vendor is SaaS, PCI DSS responsibility shifts entirely to the vendor,
eliminating the need for client assessment

Rationale: SOC 2 focuses on trust services criteria (security, availability, processing
integrity, confidentiality, privacy), while PCI DSS has specific, mandatory requirements
for cardholder data protection. Option A and B conflate distinct frameworks; Option
D incorrectly assumes SaaS transfers all PCI DSS liability to the vendor—customers
must still verify vendor compliance and may retain responsibility depending on their
merchant level.




Q5. A federal agency is migrating workloads to AWS GovCloud (US) and must
achieve FedRAMP High authorization. Which NIST CSF 2.0 function category BEST
aligns with the FedRAMP requirement for continuous monitoring and ongoing
authorization?

A. GV.OC (Organizational Context)

B. ID.AM (Asset Management)

C. DE.CM (Continuous Monitoring) [CORRECT]

D. RS.AN (Analysis)

Geschreven voor

Instelling
Vak

Documentinformatie

Geüpload op
12 mei 2026
Aantal pagina's
29
Geschreven in
2025/2026
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$18.50
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
NURSEEXAMITY South University
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
425
Lid sinds
4 jaar
Aantal volgers
272
Documenten
5560
Laatst verkocht
1 dag geleden
Writing and Academics (proctoredbypassexam at gmail dot com)

I offer a full range of online academic services aimed to students who need support with their academics. Whether you need tutoring, help with homework, paper writing, or proofreading, I am here to help you reach your academic goals. My experience spans a wide range of disciplines. I provide online sessions using the Google Workplace. If you have an interest in working with me, please contact me for a free consultation to explore your requirements and how I can help you in your academic path. I am pleased to help you achieve in your academics and attain your full potential.

Lees meer Lees minder
3.4

83 beoordelingen

5
29
4
13
3
21
2
2
1
18

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen