WGU D487 SECURE SOFTWARE DESIGN EXAM

WGU EXAMS Aug 29, 2025
Loading...

Loading document viewer...

Page 0 of 0

Document Text

pg. 1

WGU D487 SECURE SOFTWARE DESIGN EXAM 2025/2026

ACTUAL EXAM| COMPLETE 200 ACCURATE EXAM

QUESTIONS WITH DETAILED VERIFIED ANSWERS (100%

CORRECT ANSWERS) ALREADY GRADED A+

What is the recommended way to mitigate a threat identified during threat modeling?-Apply a standard accepted countermeasure -Create a custom countermeasure specific to the new threat -Add low-risk, high effort to fix threats to the support team backlog -Log occurrences of the exploit for later mitigation - Correct Answer - -Apply a standard accepted countermeasure

Which security assessment deliverable defines milestones that will be met during each phase of the project, merged into the product development schedule?-Metrics template -Threat profile -Product risk profile -SDL project outline - Correct Answer - -SDL project outline

Which architecture deliverable identifies whether the product adheres to organization security rules?-Policy compliance analysis -Threat modeling artifacts -Business requirements -Risk mitigation plan - Correct Answer - -Policy compliance analysis

  • / 4

pg. 2 The organization's testing team has created a catalog of test cases using the source code and design documentation of the new product. Each test case will be executed for each user role in the new product. Which type of security testing technique is being performed?-gray-box -black-box -white-box -red-box - Correct Answer - -white-box

Security team members have been instructed to document which developers and analysts will perform product testing and which tools they will use. Which step of the security test plan is being performed?-Identify internal resources -Define test scripts -Identify external resources -Define the user community - Correct Answer - -Identify internal resources

Security team members have been instructed to document how many users will access the new product and what roles those users will play. Which step of the security test plan is being performed?-Define test scripts -Identify external resources -Identify internal resources -Define the user community - Correct Answer - -Define the user community

The project team received a SonarQube report of their most recent stage deployment that contains 15 vulnerabilities that must be fixed before the product may be released to production. Which security testing technique is being used?-Source-code analysis -Property-based testing -Source-code fault injection 2 / 4

pg. 3 -Dynamic code analysis - Correct Answer - -Source-code analysis

What is the application of multiple layers of protection so that, if one layer is breached, the next layer provides protection?-fail-safe -defense-in-depth -separation of duties -open design - Correct Answer - -defense in depth

Which design and development deliverable details the progress of personal information requirements created in earlier phases of the security development lifecycle?-Privacy compliance report -Security testing reports -Remediation report -Security test execution report - Correct Answer - -Privacy compliance report

Which design and development deliverable contains technical and executive level reports detailing any newly identified vulnerabilities?-Updated threat modeling artifacts -Privacy implementation assessment results -Security test plans -Design security review - Correct Answer - -Updated threat modeling artifacts

Which programming language is highly susceptible to buffer overflow vulnerabilities?-C++ -Javascript -C# -Java - Correct Answer - -C++

  • / 4

pg. 4 What is the first step of the SDLC/SDL code review process?-Identify security code review objectives -Perform preliminary scan -Review code for security issues -Review for security issues unique to the architecture - Correct Answer - -Identify security code review objectives

Which type of software testing is being performed when an analyst executes a series of test cases based on application requirements?-Unit testing -Regression testing -Integration testing -Functional testing - Correct Answer - -Functional testing

A potential threat was discovered during functional testing of a file upload component when a QA analyst was allowed to upload a shell script. Users should only be allowed to upload image files. How should existing security controls be adjusted to prevent this in the future?-Validate all user input -Enforce role-based authorization -Ensure all data is encrypted in transit -Force users to re-authenticate when accessing critical functionality - Correct Answer - - Validate all user input

An organizational security review discovered multiple database instances that were installed using publicly available default settings, including security and access. How should the organization remediate this vulnerability?-Ensure default accounts and passwords are disabled or removed -Ensure auditing and logging is enabled on all servers -Ensure access to configuration files is limited to administrators

  • / 4

Download Document

Buy This Document

$30.00 One-time purchase
Buy Now
  • Full access to this document
  • Download anytime
  • No expiration

Document Information

Category: WGU EXAMS
Added: Aug 29, 2025
Description:

pg. 1 WGU D487 SECURE SOFTWARE DESIGN EXAM ACTUAL EXAM| COMPLETE 200 ACCURATE EXAM QUESTIONS WITH DETAILED VERIFIED ANSWERS (100% CORRECT ANSWERS) ALREADY GRADED A+ What is the recommended way to m...

Get this document $30.00