WGU D487 FINAL TEST 2026 QUESTIONS
WITH CORRECT ANSWERS GRADED A+
◍ STRIDE methodology.
Answer: A threat modeling framework that categorizes threats into
Spoofing, Tampering, Repudiation, Information Disclosure, Denial of
Service, and Elevation of Privilege.
◍ Server information exposure.
Answer: Ensure servers are configured to return as little information as
possible to network requests
◍ Database security.
Answer: A secure coding best practice that emphasizes the use of
parameterized queries, encrypted connection strings stored in separate
configuration files, and strong passwords or multi-factor authentication.
◍ software security architect.
Answer: Responsible for designing, planning, and implementing secure
coding practices and security testing methodologies.
◍ Data flow diagrams.
Answer: Visual representations of the flow of data within a system.
◍ Passed.
Answer: The result of the final security review when all security issues have
been resolved.
◍ Strong password complexity standards.
Answer: Enforce strong password complexity standards
◍ common computer vulnerabilities and exposures (CVE).
Answer: A list of information security vulnerabilities that aims to provide
names for publicly known problems.
, ◍ compliance requirement.
Answer: Specifies that file formats the application sends to financial
institutions must be certified every four years.
◍ DOM-based cross-site scripting vulnerability.
Answer: Enforce encoding of special characters
◍ Software developer.
Answer: A member of the scrum team responsible for writing feature logic
and attending sprint ceremonies.
◍ Security assessment.
Answer: An evaluation of a system's security measures and vulnerabilities.
◍ communication security.
Answer: The secure coding practice that ensures all traffic must be secure
and encrypted.
◍ scrum master.
Answer: The team member responsible for facilitating all scrum ceremonies
and ensuring the team communicates freely.
◍ Sprint planning.
Answer: A scrum ceremony that involves planning the work to be performed
in the upcoming sprint.
◍ POLP.
Answer: Principle of Least Privilege; a concept that restricts user access
rights to only what is necessary.
◍ Audit trails for sensitive transactions.
Answer: Ensure audit trails exist for all sensitive transactions
◍ Open-source licensing review.
Answer: The process of reviewing open-source components for compliance
with licensing requirements.
◍ Define the user community.
WITH CORRECT ANSWERS GRADED A+
◍ STRIDE methodology.
Answer: A threat modeling framework that categorizes threats into
Spoofing, Tampering, Repudiation, Information Disclosure, Denial of
Service, and Elevation of Privilege.
◍ Server information exposure.
Answer: Ensure servers are configured to return as little information as
possible to network requests
◍ Database security.
Answer: A secure coding best practice that emphasizes the use of
parameterized queries, encrypted connection strings stored in separate
configuration files, and strong passwords or multi-factor authentication.
◍ software security architect.
Answer: Responsible for designing, planning, and implementing secure
coding practices and security testing methodologies.
◍ Data flow diagrams.
Answer: Visual representations of the flow of data within a system.
◍ Passed.
Answer: The result of the final security review when all security issues have
been resolved.
◍ Strong password complexity standards.
Answer: Enforce strong password complexity standards
◍ common computer vulnerabilities and exposures (CVE).
Answer: A list of information security vulnerabilities that aims to provide
names for publicly known problems.
, ◍ compliance requirement.
Answer: Specifies that file formats the application sends to financial
institutions must be certified every four years.
◍ DOM-based cross-site scripting vulnerability.
Answer: Enforce encoding of special characters
◍ Software developer.
Answer: A member of the scrum team responsible for writing feature logic
and attending sprint ceremonies.
◍ Security assessment.
Answer: An evaluation of a system's security measures and vulnerabilities.
◍ communication security.
Answer: The secure coding practice that ensures all traffic must be secure
and encrypted.
◍ scrum master.
Answer: The team member responsible for facilitating all scrum ceremonies
and ensuring the team communicates freely.
◍ Sprint planning.
Answer: A scrum ceremony that involves planning the work to be performed
in the upcoming sprint.
◍ POLP.
Answer: Principle of Least Privilege; a concept that restricts user access
rights to only what is necessary.
◍ Audit trails for sensitive transactions.
Answer: Ensure audit trails exist for all sensitive transactions
◍ Open-source licensing review.
Answer: The process of reviewing open-source components for compliance
with licensing requirements.
◍ Define the user community.