WGU D487 ACTUAL EXAM PAPER 2026
QUESTIONS WITH ANSWERS GRADED A+
◍ Functional Requirements.
Answer: describe what the system will do and its core purpose
◍ Final Security Review.
Answer: done in A5 - final review of compliance against all security
requirements identified during the SDL cycle - passed, passed with
exceptions, not passed and requires escalation
◍ SDLC Phase 4.
Answer: implementation - the resources involved in the application from a
known resource are determined
◍ Scrum.
Answer: framework for Agile that prescribes for teams to break work into
goals to be completed within sprints
◍ Product Risk Profile.
Answer: helps to determine the actual cost of the product from different
perspectives
◍ Requirement Traceability Matrix.
Answer: a table that lists all of the security requirements
◍ Gray Box Testing.
Answer: analyzes the source code for the software to help design the test
cases
◍ Agile Development.
Answer: software development methodology that delivers functionality in
rapid iterations called timeboxes, requiring limited planning but frequent
communication
, ◍ Iterative Waterfall Development.
Answer: each phase of a project is broken down into its own waterfall
phases
◍ Open-Source Licensing Review.
Answer: done in A5 - final review of open-source software used in the stack
◍ Phase A2.
Answer: Architecture - examines security from perspective of business risks
◍ Scrum Master (Scrum Role).
Answer: responsible for ensuring a Scrum team is operating as effectively as
possible by keeping the team on track, planning and leading meetings, and
working out any obstacles the team might face
◍ Policy Compliance Analysis.
Answer: done in A5 - final review of security and compliance requirements
◍ Alpha Level Testing.
Answer: testing done by the developers themselves
◍ Application Decomposition.
Answer: determining the fundamental functions of an app
◍ Software Security Champion.
Answer: an expert on promoting security awareness, best practices, and
simplifying software security
◍ Trike.
Answer: a unified conceptual framework for security auditing
◍ Fuzz Testing.
Answer: automated or semi-automated testing that provides invalid,
unexpected, or random data to the computer software program
◍ Static Analysis.
Answer: the analysis of computer software that is performed without
executing programs
QUESTIONS WITH ANSWERS GRADED A+
◍ Functional Requirements.
Answer: describe what the system will do and its core purpose
◍ Final Security Review.
Answer: done in A5 - final review of compliance against all security
requirements identified during the SDL cycle - passed, passed with
exceptions, not passed and requires escalation
◍ SDLC Phase 4.
Answer: implementation - the resources involved in the application from a
known resource are determined
◍ Scrum.
Answer: framework for Agile that prescribes for teams to break work into
goals to be completed within sprints
◍ Product Risk Profile.
Answer: helps to determine the actual cost of the product from different
perspectives
◍ Requirement Traceability Matrix.
Answer: a table that lists all of the security requirements
◍ Gray Box Testing.
Answer: analyzes the source code for the software to help design the test
cases
◍ Agile Development.
Answer: software development methodology that delivers functionality in
rapid iterations called timeboxes, requiring limited planning but frequent
communication
, ◍ Iterative Waterfall Development.
Answer: each phase of a project is broken down into its own waterfall
phases
◍ Open-Source Licensing Review.
Answer: done in A5 - final review of open-source software used in the stack
◍ Phase A2.
Answer: Architecture - examines security from perspective of business risks
◍ Scrum Master (Scrum Role).
Answer: responsible for ensuring a Scrum team is operating as effectively as
possible by keeping the team on track, planning and leading meetings, and
working out any obstacles the team might face
◍ Policy Compliance Analysis.
Answer: done in A5 - final review of security and compliance requirements
◍ Alpha Level Testing.
Answer: testing done by the developers themselves
◍ Application Decomposition.
Answer: determining the fundamental functions of an app
◍ Software Security Champion.
Answer: an expert on promoting security awareness, best practices, and
simplifying software security
◍ Trike.
Answer: a unified conceptual framework for security auditing
◍ Fuzz Testing.
Answer: automated or semi-automated testing that provides invalid,
unexpected, or random data to the computer software program
◍ Static Analysis.
Answer: the analysis of computer software that is performed without
executing programs