pg. 1 WGU D487 Oa 2025 Test Bank 3 With 420 Questions And Correct Answers (100% Correct Verified Answers) D487 Secure Software Design Objective Assessment 2025 Test Bank V3
What do DevOps teams primarily focus on?
- Ensuring compliance with BSIMM metrics
- Collaboration for ongoing operations, enhancements, defect removal, and
- Automating the deployment of applications in cloud environments
- Streamlining legacy code to improve security
- Collaboration for ongoing operations, enhancements, defect removal, and
optimization of resources
optimization of resources How has cloud technology influenced software development?
- By replacing legacy systems entirely
- By enabling new approaches to building, deploying, and using applications
- By eliminating security risks in deployment environments
- By requiring the exclusive use of Agile methodologies
- By enabling new approaches to building, deploying, and using applications
Your company is transitioning to a public cloud service. What is a significant security challenge introduced by this move?
- Increased development cycle times
- Enhanced compliance with deployment standards
- New risks associated with shared infrastructure and misconfigurations
- Limited adoption of DevOps practices
- New risks associated with shared infrastructure and misconfigurations
- / 4
What are the four business functions defined in OpenSAMM?
pg. 2
- Governance, construction, verification, and deployment
- Planning, execution, reporting, and testing
- Threat assessment, architecture, testing, and delivery
- Agile, Cloud, DevOps, and Digital Enterprise
- Governance, construction, verification, and deployment
A DevOps team is tasked with optimizing software performance while addressing defects and implementing enhancements. What is their primary objective?
- Reducing the cost of cloud operations
- Balancing ongoing operations with continuous delivery and improvement
- Conducting penetration testing for new releases
- Automating code deployment to minimize human interaction
- Balancing ongoing operations with continuous delivery and improvement
How has cloud technology impacted software development and deployment?
- It has eliminated the need for traditional SDL processes.
- It has increased the complexity of compliance regulations.
- It has required a rethinking of how applications are built, deployed, and used.
- It has removed the need for deployment-specific practices.
- It has required a rethinking of how applications are built, deployed, and used.
What is a digital enterprise?
- A company that develops only cloud-native applications
- An organization using technology to enable and improve business activities
- A methodology for agile development
- A framework for implementing DevOps practices
- An organization using technology to enable and improve business activities
What is BSIMM, and how is it used?
- A tool for automating the vulnerability scanning process
- A study of existing software security initiatives for gathering data on security
practices 2 / 4
pg. 3
- A framework for transitioning legacy applications to cloud environments
- A set of standards for compliance testing
- A study of existing software security initiatives for gathering data on security
practices Which of the following is an example of a vulnerability that security testing aims to identify?
- Inefficient database queries
- Input validation flaws like SQL injection
- Poor user interface design
- Lack of mobile app compatibility
- Input validation flaws like SQL injection
What is the primary purpose of dynamic analysis?
- To identify vulnerabilities by executing the software in a runtime environment
- To validate software against corporate security policies
- To detect issues in the source code before deployment
- To optimize the software's performance metrics
- To identify vulnerabilities by executing the software in a runtime environment
What is a key advantage of dynamic analysis compared to static analysis?
- It requires no runtime environment.
- It identifies runtime vulnerabilities that static analysis cannot.
- It guarantees 100% detection of vulnerabilities.
- It eliminates the need for manual code reviews.
- It identifies runtime vulnerabilities that static analysis cannot.
What is a limitation of dynamic analysis?
- It requires source or binary code access.
- It cannot trace issues back to specific lines of code.
- It is less effective at detecting runtime vulnerabilities.
- It is only suitable for white box testing.
- It cannot trace issues back to specific lines of code. 3 / 4
pg. 4 Which of the following is NOT typically included in threat modeling artifacts?
- High-level executive threat modeling reports
- Detailed system architectural designs
- Data flow diagrams
- Metrics for evaluating success
- Metrics for evaluating success
Why is early stakeholder engagement important in Phase A3?
- To confirm deliverables align with future testing and compliance needs.
- To reduce the scope of development activities.
- To eliminate non-security related deliverables.
- To prioritize operational efficiency over compliance.
- To confirm deliverables align with future testing and compliance needs.
Which artifact focuses on breaking down an application to identify its key functions and data flows?
- Threat modeling artifacts
- Policy compliance analysis
- Application decomposition
- Security metrics documentation
- Application decomposition
What is the primary objective of documented metrics in Phase A3 deliverables?
- To establish baselines for ongoing security assessments.
- To determine project profitability.
- To analyze system user experience.
- To reduce the number of identified vulnerabilities.
- To establish baselines for ongoing security assessments.
What is a key reason for introducing security early in the SDL?
- It reduces overall project costs.
- It guarantees compliance with legal standards.
- / 4