WGU C706 SECURE SOFTWARE DESIGN
COMPREHENSIVE STUDY GUIDE 2026 FULL
QUESTIONS AND SOLUTIONS GRADED A+
◍ Which term describes a module's ability to perform its job without using
other modules?A low cohesionB high cohesionC high couplingD low
coupling.
Answer: D
◍ Which due diligence activity for supply chain security investigates the
means by which data sets are shared and assessed?.
Answer: A document exchange and review
◍ Which software testing approach can be used against an attacker who
manipulates input strings in banking software to gain access to another
individual's overdrawn account in order to withdraw funds?.
Answer: Misuse case testing
◍ Which technique should be used to detect a software vulnerability that
causes extra characters to appear in data fields of a front-facing web
application?A Static analysisB Dynamic analysisC Binary code analysisD
Property-based testing.
Answer: A
◍ Which item is a phase of the change management process?.
Answer: Communication planning
◍ Psychological Acceptability Design Principle.
Answer: Refers to security mechanisms not make resources more difficult to
access than if the security mechanisms were not present.
◍ Which software control test executes an application and then uses data that
, is designed to evaluate whether the values returned by the application match
a specified range of criteria?.
Answer: Reasonableness check
◍ An organization is in the process of building an application for its banking
software. Which security coding practice must the organization follow?.
Answer: Conduct data validation
◍ Which software security principle guards against the improper modification
or destruction of information and ensures the nonrepudiation and
authenticity of information?.
Answer: Integrity
◍ Separation Privilege Design Principle.
Answer: Requires that all resource approved resource access attempts be
granted based on more than a single condition. For example, a user should
be validated for active status and has access to the specific resource.
◍ Which cyber threats are typically surgical by nature, have highly specific
targeting, and are technologically sophisticated?.
Answer: Tactical attacks
◍ Your company decides you must purchase a new software product to help
the marketing staff manage their marketing campaigns and resources.
During which phase of the software acquisition process is the product
actually deployed?A Planning phaseB Monitoring phaseC Maintaining
phaseD Contracting phase.
Answer: B
◍ Which extensions are used for naming batch files in a Microsoft
environment? a. batb. cmdc. dlld. exeA option dB option cC option bD
option aE options a and b onlyF options c and d onlyG options b and c only.
Answer: E
◍ Which least privilege method is more granular in scope and grants specific
processes only the privileges necessary to perform certain required
functions, instead of granting them unrestricted access to the system?.
, Answer: Separation of privilege
◍ Which part of the change management process addresses the needs to
identify, understand, and help leaders manage opposition throughout the
organization?A Training developmentB Resistance managementC
Communication planningD Employee corrective action.
Answer: B
◍ A video company has installed new software. The developers need to
establish a defense against zero-day attacks. What is the best way to manage
this vulnerability?.
Answer: Install the latest patches
◍ An undocumented command sequence is allowing unauthorized access to a
software system. What type of software defect allows this vulnerability?.
Answer: Backdoor
◍ Which technique can be used by an attacker to compromise password
security when a password such as "123456" is used by an organization?.
Answer: Brute-force attack
◍ What is a known SDL metric used to measure protection against
vulnerabilities?.
Answer: The number of security defects found through static analysis tools
◍ Which type of application attack is used to harvest and steal sensitive
information?.
Answer: Remote access tool
◍ Which due diligence activity for supply chain security investigates the
means by which data sets are shared and assessed?.
Answer: A document exchange and review
◍ Which least privilege method is more granular in scope and grants specific
processes only the privileges necessary to perform certain required
functions, instead of granting them unrestricted access to the system?A
Entitlement privilegeB Separation of privilegeC Aggregation of privilegesD
COMPREHENSIVE STUDY GUIDE 2026 FULL
QUESTIONS AND SOLUTIONS GRADED A+
◍ Which term describes a module's ability to perform its job without using
other modules?A low cohesionB high cohesionC high couplingD low
coupling.
Answer: D
◍ Which due diligence activity for supply chain security investigates the
means by which data sets are shared and assessed?.
Answer: A document exchange and review
◍ Which software testing approach can be used against an attacker who
manipulates input strings in banking software to gain access to another
individual's overdrawn account in order to withdraw funds?.
Answer: Misuse case testing
◍ Which technique should be used to detect a software vulnerability that
causes extra characters to appear in data fields of a front-facing web
application?A Static analysisB Dynamic analysisC Binary code analysisD
Property-based testing.
Answer: A
◍ Which item is a phase of the change management process?.
Answer: Communication planning
◍ Psychological Acceptability Design Principle.
Answer: Refers to security mechanisms not make resources more difficult to
access than if the security mechanisms were not present.
◍ Which software control test executes an application and then uses data that
, is designed to evaluate whether the values returned by the application match
a specified range of criteria?.
Answer: Reasonableness check
◍ An organization is in the process of building an application for its banking
software. Which security coding practice must the organization follow?.
Answer: Conduct data validation
◍ Which software security principle guards against the improper modification
or destruction of information and ensures the nonrepudiation and
authenticity of information?.
Answer: Integrity
◍ Separation Privilege Design Principle.
Answer: Requires that all resource approved resource access attempts be
granted based on more than a single condition. For example, a user should
be validated for active status and has access to the specific resource.
◍ Which cyber threats are typically surgical by nature, have highly specific
targeting, and are technologically sophisticated?.
Answer: Tactical attacks
◍ Your company decides you must purchase a new software product to help
the marketing staff manage their marketing campaigns and resources.
During which phase of the software acquisition process is the product
actually deployed?A Planning phaseB Monitoring phaseC Maintaining
phaseD Contracting phase.
Answer: B
◍ Which extensions are used for naming batch files in a Microsoft
environment? a. batb. cmdc. dlld. exeA option dB option cC option bD
option aE options a and b onlyF options c and d onlyG options b and c only.
Answer: E
◍ Which least privilege method is more granular in scope and grants specific
processes only the privileges necessary to perform certain required
functions, instead of granting them unrestricted access to the system?.
, Answer: Separation of privilege
◍ Which part of the change management process addresses the needs to
identify, understand, and help leaders manage opposition throughout the
organization?A Training developmentB Resistance managementC
Communication planningD Employee corrective action.
Answer: B
◍ A video company has installed new software. The developers need to
establish a defense against zero-day attacks. What is the best way to manage
this vulnerability?.
Answer: Install the latest patches
◍ An undocumented command sequence is allowing unauthorized access to a
software system. What type of software defect allows this vulnerability?.
Answer: Backdoor
◍ Which technique can be used by an attacker to compromise password
security when a password such as "123456" is used by an organization?.
Answer: Brute-force attack
◍ What is a known SDL metric used to measure protection against
vulnerabilities?.
Answer: The number of security defects found through static analysis tools
◍ Which type of application attack is used to harvest and steal sensitive
information?.
Answer: Remote access tool
◍ Which due diligence activity for supply chain security investigates the
means by which data sets are shared and assessed?.
Answer: A document exchange and review
◍ Which least privilege method is more granular in scope and grants specific
processes only the privileges necessary to perform certain required
functions, instead of granting them unrestricted access to the system?A
Entitlement privilegeB Separation of privilegeC Aggregation of privilegesD