1 / 50
WGU Master's Course C706 - Secure Software Design 1.Which due diligence activity for supply chain security should occur in the initiation phase of the software acquisition life cycle?A Developing a request for proposal (RFP) that includes supply chain secu- rity risk management B Lessening the risk of disseminating information during disposal C Facilitating knowledge transfer between suppliers D Mitigating supply chain security risk by providing user guidance (answer) A 2.Which due diligence activity for supply chain security investigates the means by which data sets are shared and assessed?A on-site assessment B process policy review C third-party assessment D document exchange and review (answer) D 3.Consider these characteristics -Identification of the entity making the access request -Verification that the request has not changed since its initiation -Application of the appropriate authorization procedures -Reexamination of previously authorized requests by the same entity Which security design analysis is being described?A Open design B Complete mediation C Economy of mechanism D Least common mechanism (answer) B 4.Which software security principle guards against the improper modifi- cation or destruction of information and ensures the nonrepudiation and authenticity of information? 1 / 4
2 / 50
A Quality B Integrity C Availability D Confidentiality (answer) B 5.What type of functional security requirement involves receiving, process- ing, storing, transmitting, and delivering in report form? 2 / 4
3 / 50
A Logging B Error handling C Primary dataflow D Access control flow (answer) C 6.Which nonfunctional security requirement provides a way to capture in- formation correctly and a way to store that information to help support later audits?A Logging B Error handling C Primary dataflow D Access control flow (answer) A 7.Which security concept refers to the quality of information that could cause harm or damage if disclosed?A Isolation B Discretion C Seclusion D Sensitivity (answer) D 8.Which technology would be an example of an injection flaw, according to the OWASP Top 10?
A SQL B API C XML D XSS (answer) A 9.A company is creating a new software to track customer balance and wants to design a secure application.Which best practice should be applied?A Develop a secure authentication method that has a closed design B Allow mediation bypass or suspension for software testing and 3 / 4
4 / 50
emergency planning C Ensure there is physical acceptability to ensure software is intuitive for the users to do their jobs
- / 4