1 | Page
WGU D487 OA 2026 TEST BANK WITH ALL QUESTIONS
AND CORRECT DETAILED ANSWERS ALREADY A GRADED
WITH EXPERT FEEDBACK | NEW AND REVISED
Science Compute r Science Software Enginee ring
D487 - Secure Software Design
Leave the first rating
Stude nts also studied
Terms in this set (1286)
,2 | Page
What is the study of real-world software A) Building Security in Maturity Model (BSIMM)
security initiatives organized so companies
can measure their initiatives and understand
how to evolve them over time?
A) Building Security in Maturity Model
(BSIMM)
B) Security features and design
C) OWASP Software Assurance Maturity
Model (SAMM)
D) ISO 27001
What is the analysis of computer software A) Static analysis
that is performed without executing
programs?
A) Static analysis
B) Fuzzing
C) Dynamic analysis
D) OWASP ZAP
What iso standard is the benchmark for A) iso 27001
information security today?
A) iso/iec 27001
B) iso/iec 7799
C) iso/iec 27034
D) iso 8601
what is the analysis of computer software thatA) dynamic analysis
is performed by executing programs on a
real or virtual processor in real time?
A) dynamic analysis
B) static analysis
C) fuzzing
D) security testing
,3 | Page
which person is responsible for designing, A) software security architect
planning, and implementing secure coding
practices and security testing
methodologies?
A) software security architect
B) product security developer
C) software security champion
D) software tester
A company is preparing to add a new featureA) Waterfall
to its flagship software product. The new
feature is similar to features that have been
added in previous years, and the
requirements are well-documented. The
project is expected to last three to four
months, at which time the new feature will be
released to customers. Project team
members will focus solely on the new feature
until the project ends.
Which software development methodology is
being used?
A) Waterfall
B) Agile
C) Scrum
D) Extreme programming
A new product will require an administration A) Principle of least privilege
section for a small number of users. Normal
users will be able to view limited customer
information and should not see admin
functionality within the application.
Which concept is being used?
A) Principle of least privilege
B) Privacy
C) Software security champion
,4 | Page
The software security team is currently A) Analyzing the target
working to identify approaches for input
validation, authentication, authorization, and
configuration management of a new software
product so they can deliver a security profile.
Which threat modeling step is being
described?
A) Analyzing the target
B) Drawing data flow diagram
C) Rating threats
D) Identifying and documenting threats
The scrum team is attending their morning A) Daily scrum
meeting, which is scheduled at the beginning
of the work day. Each team member reports
what they accomplished yesterday, what they
plan to accomplish today, and if they have
any impediments that may cause them to miss
their delivery deadline.
Which scrum ceremony is the team
participating in?
A) Daily scrum
B) Sprint review
C) Sprint retrospective
D) Sprint planning
WGU D487 OA 2026 TEST BANK WITH ALL QUESTIONS
AND CORRECT DETAILED ANSWERS ALREADY A GRADED
WITH EXPERT FEEDBACK | NEW AND REVISED
Science Compute r Science Software Enginee ring
D487 - Secure Software Design
Leave the first rating
Stude nts also studied
Terms in this set (1286)
,2 | Page
What is the study of real-world software A) Building Security in Maturity Model (BSIMM)
security initiatives organized so companies
can measure their initiatives and understand
how to evolve them over time?
A) Building Security in Maturity Model
(BSIMM)
B) Security features and design
C) OWASP Software Assurance Maturity
Model (SAMM)
D) ISO 27001
What is the analysis of computer software A) Static analysis
that is performed without executing
programs?
A) Static analysis
B) Fuzzing
C) Dynamic analysis
D) OWASP ZAP
What iso standard is the benchmark for A) iso 27001
information security today?
A) iso/iec 27001
B) iso/iec 7799
C) iso/iec 27034
D) iso 8601
what is the analysis of computer software thatA) dynamic analysis
is performed by executing programs on a
real or virtual processor in real time?
A) dynamic analysis
B) static analysis
C) fuzzing
D) security testing
,3 | Page
which person is responsible for designing, A) software security architect
planning, and implementing secure coding
practices and security testing
methodologies?
A) software security architect
B) product security developer
C) software security champion
D) software tester
A company is preparing to add a new featureA) Waterfall
to its flagship software product. The new
feature is similar to features that have been
added in previous years, and the
requirements are well-documented. The
project is expected to last three to four
months, at which time the new feature will be
released to customers. Project team
members will focus solely on the new feature
until the project ends.
Which software development methodology is
being used?
A) Waterfall
B) Agile
C) Scrum
D) Extreme programming
A new product will require an administration A) Principle of least privilege
section for a small number of users. Normal
users will be able to view limited customer
information and should not see admin
functionality within the application.
Which concept is being used?
A) Principle of least privilege
B) Privacy
C) Software security champion
,4 | Page
The software security team is currently A) Analyzing the target
working to identify approaches for input
validation, authentication, authorization, and
configuration management of a new software
product so they can deliver a security profile.
Which threat modeling step is being
described?
A) Analyzing the target
B) Drawing data flow diagram
C) Rating threats
D) Identifying and documenting threats
The scrum team is attending their morning A) Daily scrum
meeting, which is scheduled at the beginning
of the work day. Each team member reports
what they accomplished yesterday, what they
plan to accomplish today, and if they have
any impediments that may cause them to miss
their delivery deadline.
Which scrum ceremony is the team
participating in?
A) Daily scrum
B) Sprint review
C) Sprint retrospective
D) Sprint planning