WGU D385 OBJECTIVE ASSESSMENT 2 NEWEST 2026
ACTUAL EXAM| D385 SOFTWARE SECURITY AND
TESTING OA FINAL WITH COMPLETE 150 REAL
EXAM QUESTIONS AND CORRECT VERIFIED
ANSWERS/ ALREADY GRADED A+ (MOST RECENT!!)
OAuth 4 Phases - ANSWER - 1. requesting authorization
2. granting authorization
3. performing token exchange
4. accessing protected resources
What kind of attack does client testing seek to prevent? - ANSWER - -
HTML-injection Attack
Which security dimension involves determining who created which
data? - ANSWER - - data authentication
What is the preimage resistance property of a hash function? - ANSWER
- - one-way function
Which two safeguards does a digital signature guarantee? (Choose 2
answers.) - ANSWER - - nonrepudiation
- data integrity
pg. 1
,3 methods for protecting against XSS? - ANSWER - - validating input
- escaping output
- managing response headers
What vectors can malicious code arrive in? - ANSWER - - body
- URL
- header of an HTTP request
Which data structure does the frame-ancestors setting in the CSP header
take? - ANSWER - - tuple
Which preflight request property is triggered by the browser requesting
API data? - ANSWER - - Readablestream
Which setting allows for specifying permitted methods? - ANSWER - -
CORS-ALLOW-METHODS
Which request methods are considered to be "idempotent"? - ANSWER
- - PUT
- DELETE
Which request methods are considered to be "safe"? - ANSWER - - GET
- HEAD
pg. 2
, - OPTIONS
- TRACE
Common Status Codes? - ANSWER - - 200 = OK
- 201 = CREATED
- 400 = BAD REQUEST
- 401 = UNAUTHORIZED
- 404 = NOT FOUND
- 405 = METHOD NOT ALLOWED
- 500 = INTERNAL SERVER ERROR
Which value of the X-Frame-Options directive allows a page to be
displayed in a frame of another page? - ANSWER - - SAMEORIGIN
Which value for the X-Frame-Options directive will not allow any page
to be displayed in a frame of another page? - ANSWER - - DENY
Which setting can be used to configure the value of Access-Control-
Allow-Origin? - ANSWER - - CORS_ORIGIN_WHITELIST
Which setting allows the browser to send cookies? - ANSWER - -
CORS-ALLOW-CREDENTIALS
pg. 3
ACTUAL EXAM| D385 SOFTWARE SECURITY AND
TESTING OA FINAL WITH COMPLETE 150 REAL
EXAM QUESTIONS AND CORRECT VERIFIED
ANSWERS/ ALREADY GRADED A+ (MOST RECENT!!)
OAuth 4 Phases - ANSWER - 1. requesting authorization
2. granting authorization
3. performing token exchange
4. accessing protected resources
What kind of attack does client testing seek to prevent? - ANSWER - -
HTML-injection Attack
Which security dimension involves determining who created which
data? - ANSWER - - data authentication
What is the preimage resistance property of a hash function? - ANSWER
- - one-way function
Which two safeguards does a digital signature guarantee? (Choose 2
answers.) - ANSWER - - nonrepudiation
- data integrity
pg. 1
,3 methods for protecting against XSS? - ANSWER - - validating input
- escaping output
- managing response headers
What vectors can malicious code arrive in? - ANSWER - - body
- URL
- header of an HTTP request
Which data structure does the frame-ancestors setting in the CSP header
take? - ANSWER - - tuple
Which preflight request property is triggered by the browser requesting
API data? - ANSWER - - Readablestream
Which setting allows for specifying permitted methods? - ANSWER - -
CORS-ALLOW-METHODS
Which request methods are considered to be "idempotent"? - ANSWER
- - PUT
- DELETE
Which request methods are considered to be "safe"? - ANSWER - - GET
- HEAD
pg. 2
, - OPTIONS
- TRACE
Common Status Codes? - ANSWER - - 200 = OK
- 201 = CREATED
- 400 = BAD REQUEST
- 401 = UNAUTHORIZED
- 404 = NOT FOUND
- 405 = METHOD NOT ALLOWED
- 500 = INTERNAL SERVER ERROR
Which value of the X-Frame-Options directive allows a page to be
displayed in a frame of another page? - ANSWER - - SAMEORIGIN
Which value for the X-Frame-Options directive will not allow any page
to be displayed in a frame of another page? - ANSWER - - DENY
Which setting can be used to configure the value of Access-Control-
Allow-Origin? - ANSWER - - CORS_ORIGIN_WHITELIST
Which setting allows the browser to send cookies? - ANSWER - -
CORS-ALLOW-CREDENTIALS
pg. 3